Darktrace

Darktrace

Autonomous cyber AI that detects and responds to threats by learning normal behaviour.

Security & Identity AI Active #Security#AIforCybersecurity#AutonomousResponse#Enterprise

In short

Network and endpoint security that builds a model of normal behaviour for every device and user, then detects and responds to deviations autonomously. The autonomous-response capability is both the product's main differentiator and the clearest governance challenge.

What it is best at

  1. Detecting novel attacks that signature-based tools miss
  2. Autonomous containment of active threats without waiting for analyst action
  3. Continuous monitoring across network, cloud, email, and identity

Built for: Enterprise Operations · Compliance/Audit Professionals

Technical foundation

Base model
Proprietary unsupervised machine learning. Not an LLM product; it learns patterns rather than reasoning in language.
Context and file handling
Network traffic, endpoint telemetry, email, cloud, and identity logs.
Latency
Continuous real-time monitoring. Autonomous response triggers within seconds.
Output quality and limits
Sensitive detection across subtle behavioural deviation. False positive rate management is the primary implementation challenge.

Pricing and access tiers

TierModelKey inclusionsLimits
Enterprise licenceCapacity-based, annualDetection, investigation, and response modulesContract-based

Pricing, version numbers, context-window sizes, and compliance certifications change frequently. Where stated they are accurate as of the as_of date and should be confirmed with the vendor before any procurement or compliance decision. Where they could not be stated confidently they are omitted rather than guessed.

Security, privacy and governance

Training data opt-out
The model learns your environment. Darktrace's terms govern what they retain. Autonomous action is taken on your infrastructure, which is the salient governance point.

The governance question this raises

Autonomous response is where AI governance and security governance converge. Darktrace can act: it can isolate a device, block a connection, or quarantine a user account without human approval, in seconds. That capability prevents damage, and it also carries risk if a false positive triggers it on a critical system during peak hours. The governance requirement is explicit policy on which autonomous actions are approved, under which conditions, with what notification, and who has the authority to override. Those decisions belong in a human-reviewed policy document, not in the tool's default settings.

No compliance certifications are listed here. Certification status is vendor-specific and time-specific, so it is stated only where verified rather than assumed. Check the vendor’s trust centre and confirm it covers the specific tier you are buying.

Integrations and ecosystem

  • SIEM and SOAR platforms
  • Cloud providers
  • Email and identity systems

API and SDKs: Darktrace API for SIEM integration and management.

The verdict

Strengths

  • Detects novel threats that rules miss
  • Sub-second autonomous response
  • Broad coverage across network, cloud, and identity

Drawbacks

  • Autonomous action requires explicit policy governance
  • False positive management is ongoing work
  • Premium pricing

Consider instead: CrowdStrike Charlotte AI, SentinelOne Purple AI, Microsoft Copilot

Frequently asked questions

What is Darktrace used for?

Network and endpoint security that builds a model of normal behaviour for every device and user, then detects and responds to deviations autonomously. The autonomous-response capability is both the product's main differentiator and the clearest governance challenge.

What model does Darktrace run on?

Proprietary unsupervised machine learning. Not an LLM product; it learns patterns rather than reasoning in language.

Does Darktrace train on your data?

The model learns your environment. Darktrace's terms govern what they retain. Autonomous action is taken on your infrastructure, which is the salient governance point.

What are the alternatives to Darktrace?

The closest comparable tools are CrowdStrike Charlotte AI, SentinelOne Purple AI, Microsoft Copilot. Which fits depends on where the work already lives and what the organization's data terms require.

Listing a tool is not governing it

The AI Business Enablement Audit™ builds the inventory, measures your organization against every framework in the AI Governance Reference Library, and delivers a defensible governance dossier.

Start or finish your AI Audit →