2025 Conference on International Cyber Security | 4-5 November 2025
Register now

Callum Harvey

Mapping Information Asymmetries in Cyber Threat Intelligence – The Role of AI Firms

The use of artificial intelligence (AI) by threat actors raises pressing questions about the role of AI firms in cyber threat intelligence (CTI). While substantial attention has been paid to the application of AI tools in CTI, there has been little academic examination of how AI firms function as producers and gatekeepers of CTI or how intelligence about AI-enabled threat actor tactics, techniques and procedures are shared with other stakeholders across government and civil society. In particular, the lack of critical engagement with information asymmetries benefiting AI firms investigating the misuse of their own systems warrants closer examination.This article presents a systematic literature review drawing on CTI literature, approaches from critical intelligence studies and critical data studies, and considerations of information asymmetry in cybersecurity. It identifies four themes: contested terminology describing non-state gatekeepers of online services, including AI; tension in how those gatekeepers are treated as intelligence producers within a broader environment of security privatisation; a focus in CTI literature on AI as a capability enhancing tool rather than on AI firms as intelligence producers; and vertical integration of data ownership, analytic capabilities and dissemination control influencing the transaction cost of sharing intelligence. In doing so, this paper identifies a significant gap in how literature accounts for AI firms as a distinct class of actor in CTI, and provide one of the first review analyses of the role of AI firms in cybersecurity.