
- 01AI telemetry should be tiered. Raw interaction logs go to cold storage. Anomaly signals go to the SIEM. High confidence detections go to the analyst queue.
- 02The four detection rules with the highest signal value for AI systems are tenant token velocity anomaly, tool call scope violation, retrieval boundary crossing, and model output to a privileged system.
- 03Context enrichment transforms an AI alert from a raw log entry into an actionable finding. The SIEM rule should join on the launch gate registry to surface the feature name, tool list, and isolation design.
- 04False positive tuning for AI detection rules requires a feedback loop with the feature team, because normal behavior for one AI feature looks like an attack in another.
Security information and event management platforms were designed for a world where events are discrete, structured, and relatively low volume compared to the assets generating them. An enterprise LLM platform can generate millions of interactions per day, each with a large context window, a list of tool calls, and retrieval results. Sending all of this to a SIEM at full fidelity is technically feasible and operationally ruinous.
The design challenge is not getting data into the SIEM. It is getting the right signals into the SIEM while keeping raw log volume in cold storage where it can be retrieved for reconstruction without cluttering detection pipelines.
A tiered telemetry model for AI systems
Three tiers serve different purposes and should flow to different destinations.
/AI_TELEMETRY_TIERS
| Tier | Content | Destination | Retention |
|---|---|---|---|
| Tier 1. Raw interaction log | Full input context, output, tool calls, retrieval chunks | Write once object storage | 12 to 24 months depending on regulatory requirements |
| Tier 2. Anomaly signals | Token velocity, tool call scope, retrieval boundary events, policy decisions | SIEM with medium priority ingestion | 90 days in hot storage |
| Tier 3. High confidence detections | Alerts generated by Tier 2 signals that cross a detection threshold | SIEM analyst queue with enrichment | Retained per your incident record policy |
Four detection rules worth building first
Build these four rules before any others. They cover the threat patterns that appear most frequently in AI production systems and generate the fewest false positives when tuned correctly.
- 01Tenant token velocity anomaly. Fire when a single tenant token count for the day exceeds 3x the rolling 14 day baseline for that tenant. This rule catches both runaway agent loops and token amplification attacks.
- 02Tool call scope violation. Fire when a tool call involves a resource identifier that does not belong to the calling tenant. Requires the tool call log to include the tenant scoped resource list at call time.
- 03Retrieval boundary crossing. Fire when a retrieval chunk returned to one identity contains a document identifier that is tagged to a different identity in the ownership registry.
- 04Model output to privileged system. Fire when the model response is passed to a privileged downstream system (database write, shell execution, email send) without passing through an output validation gate.
Context enrichment for AI alerts.
Every AI SIEM alert should be enriched with the feature name, the launch gate date, the tool list the feature was authorized to use, and the isolation design documented at gate time. Without this context, the analyst cannot determine in under 5 minutes whether the alert represents a deviation from designed behavior.
Metrics that indicate effective AI detection coverage
- 01AI alert to incident ratio. Percentage of AI SIEM alerts that escalate to confirmed incidents. A ratio below 10 percent indicates excessive noise.
- 02Mean time to context. Time from alert creation to the analyst having the enriched feature context. Target is under 2 minutes with automated enrichment.
- 03Detection rule coverage. Percentage of AI incident categories from the IR playbook that have at least one associated SIEM rule. Target is 100 percent.
- 04False positive acknowledgment time. Time from a false positive identification to the detection rule being updated. Target is under 48 hours.
Avoiding alert fatigue in AI detection programs
Alert fatigue is the primary failure mode for AI detection programs. The root cause is almost always the same. Teams route raw AI telemetry to the SIEM without a detection strategy, every interaction generates an alert, and analysts begin ignoring the queue. The damage from this failure is not just analyst burnout. It is that real AI incidents are missed because they are indistinguishable from the noise.
The solution is to start with two or three high confidence rules and measure the alert to incident ratio before adding more. A ratio above 20 percent means the rules are well tuned. A ratio below 5 percent means the rules are too broad and should be tightened before expanding coverage. Treat the SIEM rule backlog for AI the same way you treat a vulnerability backlog. Prioritize by signal quality, not by completeness.
