Independent AI threat intelligence

Building objective,
empirical data
for AI policy.

Continuous, independent threat intelligence on AI agent activity in the wild.

Abstract data landscapes connected by fine lines and a teal path.

Our publications

Every technical report
comes with a policy brief.

01 / For researchers

Technical Research

Detailed reports on AI agent activity we find in the wild, with our sources and methods so others can check the work.

Explore technical research →

Publications will appear here as they are released.

02 / For policymakers & journalists

Policy Briefs

Shorter briefings on each finding, written for policymakers and journalists rather than other researchers.

Read policy briefs →

Publications will appear here as they are released.

01 / What we do

Tracking AI agents
on the open internet.

Noetic Research finds AI incidents in the wild, builds clear technical research, and gets the evidence to the people who can act.

01 / Detect

Detect agent activity at scale.

Prometheus, the system we’re building, hunts for agentic activity across threat intelligence and open-source data, and pivots from each finding to the infrastructure around it.

What Prometheus pulls from today

Sources integrated so far:

  • Public URL and page scans, and URL analysis logs.
  • Paste sites and leak data.
  • Container images that agents publish.

We plan to add more through licenses and partnerships with threat intelligence companies.

Open the Agentic Activity Explorer →

02 / Draw out · planned

Draw agents out with honeypots.

Sites, servers, and agent-facing message boards that record what agents do when they show up. We’ll share the data with other AI safety organizations.

Why honeypots

Public logs usually only show us pieces of what an agent did.

  • On infrastructure we run, we can record the whole sequence of what an agent does.
  • Every visit gives us new leads to pivot on, like the accounts, domains, and servers involved.
  • We’ll be upfront about what a honeypot can and can’t tell us.

03 / Publish

Write detailed technical reports.

Full write-ups of what happened, with our methods and sources, so others can check the work and cite it.

Explore technical research →

04 / Brief

Brief policymakers and journalists.

Policymakers and journalists rarely read technical reports, so every report gets a shorter briefing written for them.

Read policy briefs →

02 / Our approach

Investigate from
the outside in.

Agentic activity on the internet gives us a rare window into AI behavior outside of internal lab reports.

Execution trace / Observable actionsIllustrative example

01 / Observe

Start with what
we can see.

We start with the traces an agent leaves behind, like pages visited, tools called, and files or messages left. We keep the original records.

What did the agent actually do?

03 / Why now

AI incidents are
coming to light late.

In 2026, AI incidents came to light late, and often through someone other than the developer.

Agents from evaluations reached production systems and real organizations’ infrastructure, and were caught by outside monitoring, code reviewers, or public scan logs, sometimes months later.

As capability spreads beyond the frontier labs, we expect these incidents to grow in size, scale, and sophistication. Building transparency into how these systems affect the internet needs to start now.

04 / About us

Independent capacity is the bottleneck.

Noetic Research applies threat intelligence and OSINT methods to AI safety.

Independent evidence can move policy quickly. METR’s independent incident report reached Senate testimony in five weeks. But very few organizations without a commercial interest are set up to do this work, and most don’t have a threat intelligence background.

We want to catch warning signs while the stakes are still low, and build a public record that labs, governments, and the public can act on.

Founded by Eric Clay, who spent four years leading threat intelligence research at a dark web threat intelligence company and has worked on AI policy with Senate and House offices.

See what we’re building

How we work

How we handle what we find.

01

No commercial motives.

We don’t sell a product or a data feed. Our job is to report what happened accurately.

02

Developers hear first.

When we find activity tied to a developer’s systems, we tell them before we publish.

03

We show our work.

Every report includes our methods and sources, and says what the evidence can’t tell us.

Noetic Research

Transparency into AI agents
needs to start now.

Explore our work