Summary

On July 20, 2026, Google Threat Intelligence moved its agentic AI capabilities from public preview to general availability for Enterprise and Enterprise+ customers. Analysts can run natural-language threat hunting, incident response, and daily alert triage; a Malware Analysis Agent activates automatically to inspect suspicious files in a secure cloud sandbox; and a Prompt Library ships predefined investigative workflows, with inline citations back to underlying threat-intelligence data.

What changed

Google Threat Intelligence made its agentic AI generally available to Enterprise and Enterprise+ customers, adding natural-language threat hunting, an auto-activating Malware Analysis Agent that sandboxes files, a Prompt Library of investigative workflows, and inline source citations.

Why it matters

GA moves agentic security operations from experiment to supported product for a major SOC platform, automating the highest-volume analyst work (triage, hunting, malware inspection) while keeping citations for verifiability. It intensifies the agentic-SOC race and gives enterprises a credible alternative to Microsoft's newly launched Project Perception, signaling that autonomous detection-and-response, not copilots, is the emerging security baseline.

Evidence excerpt

Google Threat Intelligence has moved its agentic AI capabilities from public preview to general availability for Enterprise and Enterprise+ customers ... threat hunting, incident response and daily alert triage ... A dedicated Malware Analysis Agent can automatically activate when deeper inspection is required and can analyze suspicious files within a secure cloud sandbox ... inline citations connected to underlying threat intelligence data.

Sources