Independent AI threat intelligence
Building objective,
empirical data
for AI policy.
We are building continuous, independent threat intelligence on AI agent activity in the wild.
Explore our publications
Technical depth.
Public understanding.
01 / For researchers
Technical Research
Detailed investigations of AI agent activity in the wild, with source evidence, methods, and limitations that others can examine.
Explore technical research →Publications will appear here as they are released.
02 / For policymakers & journalists
Policy Briefs
Accessible briefings for policymakers and journalists: what happened, why it matters, and what remains uncertain.
Read policy briefs →Publications will appear here as they are released.
01 / What we do
From AI incidents
to public evidence.
Noetic Research finds AI incidents in the wild, builds clear technical research, and gets the evidence to the people who can act.
01 / Detect
Find agent activity in the wild.
Prometheus brings external data sources into one investigation workspace. We are developing scalable detection methods to turn traces of agent activity into leads that researchers can examine.
How detection supports investigation
A signal starts an investigation; it does not settle it.
- Compare observations across sources and over time.
- Trace messages, published artifacts, and infrastructure back to their supporting records.
- Separate signs of automation from evidence about a model, operator, or outcome.
02 / Draw out · planned
Build sensors for agent behavior.
Our planned honeypots are sites and agent-facing message boards designed to record how agents behave on infrastructure we control. We aim to share the resulting methods and data with AI safety researchers.
What these sensors would reveal
Observe behavior in context, within systems we operate.
- Preserve the sequence of messages, actions, and resulting artifacts.
- Study coordination and behavior that public logs alone may not explain.
- Publish the limits of what a sensor can establish alongside its findings.
03 / Publish
Make the technical evidence public.
We investigate what happened, explain the methods, and build detailed reports that others can inspect and cite. The aim is a shared public record of AI incidents, independent of developer reporting.
Explore technical research →04 / Brief
Get findings to people who can act.
Our plan pairs each technical report with accessible briefing material for policymakers and journalists: what the evidence shows, why it matters, and what remains uncertain.
Read policy briefs →02 / Our approach
Investigate from
the outside in.
Agent activity on the internet offers a window into AI behavior beyond internal lab reports. We connect the records, test explanations, and show what the evidence can support.
01 / Observe
Reconstruct
what happened.
Begin with a record of actions: the sequence, the tools used, and the artifacts left behind. Preserve the context that makes each observation meaningful.
What do we actually know?
03 / Why Noetic
Independent evidence.
Time to act.
Noetic Research brings threat intelligence and open-source investigation to AI safety.
As increasingly capable agents operate on the internet, we need independent evidence of their behavior, misuse, and failures. Our work is designed to complement lab evaluations, developer investigations, and incident databases with original evidence from the outside in.
Our theory of change is practical: detect warning signs, establish a shared public record, and help labs, governments, journalists, and the public act on evidence. Better understanding today can give society more time to respond before the stakes become catastrophic.
Founded by Eric Clay, drawing on experience in threat intelligence, investigations, engineering, and AI policy.
See what we are buildingHow we work
Independent research. Public-interest evidence.
Evidence before inference.
Distinguish observed behavior from claims about identity, intent, or impact. Test alternative explanations and keep uncertainty explicit.
A record others can examine.
Make the path from source material to conclusions visible. Share methods and supporting evidence so others can assess and build on the work.
Research people can use.
Translate technical findings into clear briefings for policymakers and journalists, preserving the context and limits that make the evidence useful.