Security and engineering teams contend with a constant stream of signals about vulnerabilities, incidents, misconfigurations, identity risks, control gaps, and other findings across their environments. But an individual finding’s severity does not always reflect its potential organizational impact. For example, a critical finding on an isolated resource with limited permissions may represent less risk than a medium-severity finding on an internet-facing production service that can access sensitive data. The challenge is understanding how those signals interact, which combinations of conditions create the greatest exposure, and what findings teams should address first.

Datadog’s Risk Engineering team has been working on this problem by building a Systemic Risk Detection Pipeline and Risk AI Agents that correlate signals across our environment to evaluate risk beyond individual findings. The pipeline detects patterns across multiple conditions to identify potential systemic risks. The Risk AI Agents then help security practitioners investigate the relationships, context, and potential impact associated with those risks.

We think of Risk AI as an approach that combines deterministic risk detection with AI-assisted investigation to identify, contextualize, and prioritize systemic risk. Our approach employs deterministic systems where consistency and repeatability matter, and AI agents where flexible investigation and interpretation add value. Security practitioners remain in the loop to validate agent-generated findings and retain ownership of next steps.