---
title: "Built in, not bolted on: What AI-native actually means in cybersecurity"
description: "The discussion defines AI-native cybersecurity applications as systems architected with intelligence at their core, rather than traditional products with AI added later. It links tool sprawl to slower threat detection and response and argues that proprietary, context-rich security telemetry is the foundation for adaptive defense. Barracuda uses Databricks to consolidate fragmented data, normalize schemas, support real-time streaming detection, run ML operations through MLflow, and power natural-language log search across billions of security events with strict data isolation. The work began by defining customer outcomes, then progressed through incremental delivery; normalized data enabled models and agents to use cross-domain context. This approach extended across WAF-as-a-service, automated configuration, API security, and bot protection while shared outcomes aligned product, data science, engineering, and business teams."
---

# Built in, not bolted on: What AI-native actually means in cybersecurity

[Databricks](https://yomu.fyi/company/databricks) · Aly McGue · Apr 28, 2026

**Type:** Explainer

## Summary

The discussion defines AI-native cybersecurity applications as systems architected with intelligence at their core, rather than traditional products with AI added later. It links tool sprawl to slower threat detection and response and argues that proprietary, context-rich security telemetry is the foundation for adaptive defense. Barracuda uses Databricks to consolidate fragmented data, normalize schemas, support real-time streaming detection, run ML operations through MLflow, and power natural-language log search across billions of security events with strict data isolation. The work began by defining customer outcomes, then progressed through incremental delivery; normalized data enabled models and agents to use cross-domain context. This approach extended across WAF-as-a-service, automated configuration, API security, and bot protection while shared outcomes aligned product, data science, engineering, and business teams.

## Context

Security organizations are adding more tools while facing slower threat detection and response, and attackers are using AI to operate at scale. The discussion presents proprietary security telemetry and adaptive, customer-specific intelligence as responses to this environment.

## Approach / What changed

Barracuda organized fragmented security data on Databricks, normalized its schema, and built AI-native capabilities through incremental delivery. The platform supports real-time streaming detection, ML operations with MLflow, machine learning models, natural-language log search, and extensions across several security products.

## Takeaways

- AI-native products are expected to adapt to each customer's risk profile, changing data, needs, and goals instead of following one deterministic path.
- Normalizing a shared schema gave ML models and agents full context across domains; the managed XDR implementation used 30-plus features that continuously improve.
- Building on unified proprietary telemetry supports targeted recommendations and customer-specific behavior that external, one-size-fits-all SaaS models cannot replicate, according to Bradbury.

**Tags:** [AI](https://yomu.fyi/topic/ai), [Databricks](https://yomu.fyi/topic/databricks), [MLflow](https://yomu.fyi/topic/mlflow), [Security](https://yomu.fyi/topic/security)

- Source: [Databricks](https://www.databricks.com/blog/built-not-bolted-what-ai-native-actually-means-cybersecurity)
- Source URL: https://www.databricks.com/blog/built-not-bolted-what-ai-native-actually-means-cybersecurity
- Ingested by Yomu: 2026-08-31T03:40:46.363Z

[Read original post](https://www.databricks.com/blog/built-not-bolted-what-ai-native-actually-means-cybersecurity)
