About this watch

AI Threat Watch follows two questions. How are attackers using AI? How are AI systems being attacked?

What an entry is

One entry is a short summary and a direct link to the original article or report. There are no article pages here: the title and the thumbnail take you to the source in one click. When several outlets cover the same event, the entry points to the most original source and lists the others under “Also covered by”.

How entries get here

The pipeline runs every six hours, with no human in the loop. It reads a curated bookmark collection, keeps English-language items that pass a relevance threshold, merges duplicates, looks for the original source behind secondary coverage, then writes the summary and the tags with a language model.

That has a cost you should know about. Summaries can be wrong, incomplete or miss the nuance of the source. Treat every entry as a pointer, read the source, and do not cite a summary as if it were the report.

Attribution

This site never attributes activity on its own. When a country appears, it is the attribution as stated by the source, with the name of the organisation making the claim and the confidence level it gave. When the source gives no confidence level, the entry says so.

Two categories

Every entry carries exactly one of two categories. Each has its own colour, and the name is always written next to it.

AI-Enabled

Attackers using AI

Threat actors using AI models, agents or AI-built tooling to plan, scale or run offensive operations.

AI-Targeted

Attacks on AI

Attacks against AI systems: models, agents, the applications built on them and their supply chain.

A report that covers both sides is filed under the side its main finding belongs to. Entries also record a source type (vendor report, research, news, government, academic).

Must-reads

A few entries are marked Must-read: the reports the field keeps citing and that anyone following this topic should have read. This marker is the only part of the site chosen by hand. The pipeline never sets it. The timeline shows must-reads first.

Feeds

Feed items link straight to the source, like the site does.

Who runs it

A personal project by a threat intelligence practitioner. It is not affiliated with any employer or vendor, and it carries no advertising and no analytics.