# Investigate every security event with an AI agent, without the frontier bill

DevFeed: [Investigate every security event with an AI agent, without the frontier bill](<https://devfeed.tech/articles/investigate-every-security-event-with-an-ai-agent-without-the-frontier-bill-2230.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/ai/ai-security-detection-pipeline/>)

Author: Nicolas Grislain

Published: 2026-07-28T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [AI Bots](<https://devfeed.tech/topics/ai-bots.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [ai-research](<https://devfeed.tech/tags/ai-research.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [bits-ai](<https://devfeed.tech/tags/bits-ai.md>), [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [llm](<https://devfeed.tech/tags/llm.md>), [logs](<https://devfeed.tech/tags/logs.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

Datadog describes a two-stage security detection pipeline in which Mambark scores audit-log events and routes only the most suspicious ones to an AI agent for deeper investigation.

## Source excerpt

Learn how Datadog built Mambark, a small state-space model that scores every security event and enables heavier AI agents to investigate only the events that matter.