From signals to systemic risk: Building Risk AI
Blog post from Datadog
Datadog’s Risk Engineering team is developing a Systemic Risk Detection Pipeline and Risk AI Agents to help security teams prioritize organizational exposure by correlating vulnerabilities, incidents, misconfigurations, identities, permissions, asset criticality, and other signals rather than assessing findings in isolation. The approach identifies “risk paths,” where interconnected conditions—such as an internet-facing vulnerable application, excessive workload privileges, and access to sensitive production data—can combine into a more serious threat than any individual finding suggests. Deterministic systems detect known patterns consistently, while AI agents investigate relationships, collect evidence, evaluate contextual factors, map risks to security domains, and suggest mitigations under practitioner oversight. Risks are prioritized using factors including exploitability, internet exposure, privilege levels, potential blast radius, business importance, existing controls, and related incidents, with explainable evidence provided for AI-generated assessments. Datadog also integrates this process with Work Management, Workflow Automation, and Agent Observability to route remediation work, track resolution, and evaluate AI output quality over time.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Agents | 9 | 5,780 | 1,243 | 245 | -15% |
| Observability | 2 | 3,175 | 737 | 186 | -24% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.