
AI adoption is moving faster than traditional threat intelligence models were designed to handle. As organizations deploy increasingly capable AI systems, defenders must develop an intelligence operation built for the speed, complexity, and distinct risk profiles that AI models, applications, and agents introduce. To meet that challenge, the AI Threat Intelligence and Security Research team within Cisco is operationalizing threat intelligence as a core AI security capability, integrating those protections directly into products like AI Defense to protect their customers. Cisco is bringing that model to life, with Morado helping make the underlying workflows more connected, structured, and actionable through its Threatnote platform.
Threatnote is Morado’s unified threat management platform for threat intelligence teams. It provides a central operational environment for collecting, enriching, correlating, reporting, and disseminating intelligence across internal and external sources. For AI-focused threat intelligence work, Threatnote helps analysts organize emerging threat data, map findings to relevant AI security taxonomies, manage intelligence requirements, and turn fragmented information into structured outputs that can support security teams, product teams, and executive stakeholders.
At the center of this work is Cisco's AI Threat Intelligence and Security Research team. Cisco has built a dedicated capability to collect, track, analyze, and disseminate intelligence on emerging AI threats, turning fragmented signals into insight that can inform research priorities, strengthen defenses, and accelerate response. This work connects what Cisco observes in the threat landscape with the security and safety innovations it has built to protect AI systems, infrastructure, and customers.
As part of this effort, Morado’s Threatnote platform enables the aggregation and correlation of intelligence across unique and diverse data sources, bringing together information that would otherwise remain fragmented across the threat intelligence ecosystem. By unifying this intelligence within a single operational environment and applying AI-specific threat taxonomies, including Cisco’s Integrated AI Security and Safety Framework, alongside other taxonomies such as MITRE ATLAS, the OWASP Top 10 for LLM Applications and Agentic Applications, and the NIST AI Risk Management Framework, Threatnote allows analysts to consistently classify, enrich, and map intelligence to structured frameworks. This approach enables more efficient reporting, clearer risk alignment, and improved communication across both technical and executive stakeholders.
Structured intelligence is what turns awareness into action. By connecting AI threat research, standardized taxonomies, and operational workflows, Cisco can more consistently move from emerging signals to analysis, prioritization, and defensive innovation. This collaboration strengthens the intelligence foundation behind Cisco AI Defense and helps Cisco translate what it learns about evolving attack methods into more resilient AI systems and infrastructure, and stronger protections for customers.