Security1 distinct publisher2 min readPublished
The vendor reports an average 63% cut in alert volume from its new relevance classifier, publishes no accuracy figure for it, and switches it on by default for new customers.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The classifier weighs the default intent that Recorded Future authors into each alert rule alongside any custom intent the customer adds, then the reference itself, metadata and image-derived signal included [6]. Custom intent is written in prose. The vendor's own example is "this is for ACME Bank, not ACME Center" [9]. So tuning a detection now happens in two languages: the rule, and a sentence a model interprets on your behalf.
References that survive arrive with a one-line explanation of why they were kept, under a generated title and summary of the alert [15][14]. That is a rationale for what got through. The announcement describes no equivalent rationale for what was sorted downward, and no accuracy, precision or false-negative measurement for the classifier at all [11].
The residue is the number worth holding onto. An average 63% cut leaves roughly 37% of fired alert volume in the default view, about one alert in three [12]. Volume reduction is a measure of how much was removed, not of whether the right material was removed, and it is maximised by aggressiveness: a filter that dropped every reference would report a 100% reduction and look like a triumph on that one axis [13]. Recorded Future says an ambiguous but plausibly threat-related reference is kept rather than filtered [7]. That is the correct bias to state. It is still a statement of intent, not a recall figure, and the gap between the two is where a post-incident review lives.
This is where detection-coverage assurance quietly changes hands. The old sentence was "the rule fired and an analyst read it." The new one is "the rule fired, a vendor-side model judged the contents relevant, and the analyst read what it kept" [1][3]. Both may be defensible. Only one of them can be tested by the customer, and the post offers no method for testing the other beyond opening the unfiltered payload in the Portal after you already suspect a miss [5][11].
Recorded Future frames the whole thing as turning AI back on a problem AI made worse, pointing at attackers moving faster on vulnerability discovery and phishing setup [10]. The volume pressure is real, and 63% of a queue is a serious amount of analyst time [2]. But the trade on offer has a number on one side only: hours saved today, measured and marketed, against a miss rate that nobody has published and the buyer cannot compute [11]. Filtering that is free, default-on for new accounts and reversible only by someone who knows to look for the switch is not a small operational dependency [8].
Ranked by verification strength, evidence, and original report placement.
Recorded Future says customers with early access saw an average reduction in alert volume of around 63%, though results may vary based on rule configuration and use case.
Recorded Future states there is no data loss: the original, unfiltered Alert details are always available in the Portal.
The launch post justifies the feature by citing threat actors using AI to find vulnerabilities, stand up phishing infrastructure and harvest credentials at a speed and scale not previously possible.
The launch post publishes no accuracy, precision or false-negative measurement for the relevance classifier, describes no sampling or validation method for filtered-out material, and gives no rationale for items sorted into Low Relevance; the only stated recourse is reviewing the unfiltered payload in the Portal.
Each Alert is delivered with an AI-generated title and summary describing what came through.
Each reference kept in the High Relevance section carries a one-line explanation of why the AI kept it.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
First-party product documentation, no verification
Everything known comes from one vendor launch post. It is authoritative on product mechanics and rollout policy, and those claims are internally consistent and specific. But the only efficacy figure is a self-reported average volume reduction with no sample size, baseline or window, and the post publishes no accuracy, precision or false-negative measurement and no validation or sampling method for filtered-out material. No independent test, customer account, or third-party report is present in the cluster.
Shipped to the full base, default-on, usage uncounted
Adoption signal is real but shallow: the feature is generally available to all customers at no additional cost, on by default for new customers, and per-rule enablable by existing ones, and an unnamed early-access cohort is referenced. Availability to a whole customer base is not measured usage — there are no customer counts, no enablement rates, no named references, and rule-type support is still limited to classic and custom rules.
Headline efficacy metric outruns published proof
The launch leads with a 63% volume reduction and 'a clear rationale for every relevance call', while publishing no accuracy figure, no false-negative rate, no validation method, and no rationale for demoted or auto-dismissed items. Volume reduction is monotonic in aggressiveness and independent of correctness, so the headline number cannot support the reliability implied by turning the filter on by default. The gap is overstatement of assurance rather than fabrication: the mechanics, retention of unfiltered payloads and per-rule controls are concretely documented.
Vendor announcing and defaulting on its own product
The sole source is the vendor's marketing blog for its own feature, closing with demo and account-team calls to action. Recorded Future selects which metric to publish, benefits from framing volume reduction as the success measure, and gains stickiness from enabling the feature by default for new customers at no incremental price. No independent or customer voice offsets that positioning in the cluster.
Solid on mechanics, weak on efficacy
Confidence is moderate: first-party statements about what shipped, how it is configured, and how it is defaulted are reliable and unlikely to be contradicted. Confidence in the performance and safety of the relevance decision is low, because a single self-interested source supplies one unaudited number and no correctness measurement, and nothing in the cluster can be cross-checked.
security
Influence Operations Now Target Construction Schedules, Not Just Elections1 distinct publisher
security
Mexico's cyber plan puts the phone number in 2026 and the scoreboard in 20301 distinct publisher
product
Gemini reads your Workspace by default, and the off switch is in the admin console1 distinct publisher
security
North Korea's hiring funnel: 60 applications a day, 22 personas, ten jobs landed1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 25, 2026