Expel now covers the full AI attack surface

By Sarah Crone

August 4, 2026  •  3 minute read



Placeholder image for Expel now covers the full AI attack surface

TL;DR

  • Expel is the only MDR provider covering the full AI attack surface: attacks launched with AI, employee AI misuse, and exposure inside the AI systems you build and run.
  • Three capabilities are live now: an integration with Anthropic Claude, new detections mapped to MITRE ATLAS, and AI-focused hunt techniques—all run by human operators, accelerated by AI.
  • It extends the MDR you already trust—same experts backed by 10+ years of SOC data, and the same AI-accelerated SecOps platform (Expel Workbench™).

 

AI security has an ownership problem: everyone agrees it’s a risk, but there’s disagreement on who owns it. Ask five people at the same company where AI risk lives and you’ll get five different answers—meanwhile, attackers aren’t waiting for you to sort it out. They’re already using AI to move faster, and your employees are already using it in ways that create risk you can’t see yet.

Today, Expel is closing that gap. Expel Managed Detection and Response (MDR) is launching MDR for AI, which monitors the full AI attack surface: threats attackers launch with AI, the risk employees create when they misuse it, and the exposure inside the AI systems your organization is building right now. 

 

Why this matters now

Most security teams aren’t struggling with AI risk because they don’t care; it’s because they don’t have the expertise to define and map where AI risk lives in their environment or the budget and headcount to build a new program from scratch. Extending the detection and response you already run is a faster (and more secure) path than starting from scratch.

That’s the bet we’re making with this launch. We took our decade of detection experience and pointed it at three fronts of AI risk at once, and we are building it the way we built everything else: human-led, with AI accelerating our operators instead of replacing them.

 

Three capabilities, live now

  1. Anthropic Claude integration: We now pull Claude Enterprise Compliance signals—including usage activity and prompt content—directly into our detection pipeline. Most integrations stop at activity logs. Our operators go further, working the prompt content itself to surface intent, not just activity. It’s the first of a growing lineup of AI-native integrations we’re rolling out through 2026.
  2. Detection coverage labeled and mapped: Expel’s detection library is labeled where AI is a factor, mapped to MITRE ATLAS (Adversarial Threat Landscape for Artificial Intelligence Systems), and is available to customers. Coverage today includes 13 of the 16 tactics. 
  3. AI-focused hunt techniques: Our threat hunters are running structured hunts built specifically for AI-augmented attack patterns and AI exposure, available now to our threat hunting customers.

Because we run across 160+ integrations spanning endpoint, identity, cloud, SaaS, network, and more, this coverage applies across your entire environment. Platform vendors can tell you what’s happening, but just in their own tools. We’re running human-led AI coverage across your entire tech stack.

 

Human-led, AI-accelerated—not the other way around

“You can’t out-automate an attacker who’s using the same AI you are,” said Justin Bajko, Expel’s Chief Strategy Officer (CSO) and co-founder. “The models change weekly. What doesn’t change is the judgment call in the middle of an incident, because that’s still a human thing. We built this so our operators own that call across the whole AI attack surface.”

Plenty of vendors are racing to hand AI security over to autonomous agents. Our operators run the watching, triaging, and responding instead—the same people, the same platform, the same accountability you already trust, just extended to cover an attack surface that didn’t exist a few years ago.

 

Just the beginning of a new chapter

This is just the start of how we’re protecting you with and against AI. Because it’s a new attack surface, we’ve mapped out what’s to come on top of what we’re launching today. While we don’t want to spoil all the fun yet, we can offer you a few sneak peeks. 

Anthropic Claude is the first of several AI-native integrations we’re adding to our list this year (the work is already happening behind the scenes now). You can also expect our custom detections library to keep growing to complement how our skills and your growing tech stack already work, AI detections included. (Did you know we already create or modify an average of 50+ detections each week?) We’re not just covering what’s known today—we’re built to stay ahead of what’s coming next. Looking forward, that includes ongoing expansion of our detection library, adding more threat hunting techniques, and more. 

Attackers are moving faster because they can, employees are experimenting because nobody told them not to, and the AI systems your team is building today are already part of your attack surface, whether or not anyone’s been assigned to watch them.

Extending the MDR you already trust to cover AI shaped security incidents isn’t flashy. It’s the same discipline we’ve applied to identity, cloud, and endpoint for years, aimed at a target that happens to be new. Our operators are already running it, accelerated by AI and accountable the whole way through.

 

Looking for more? Join us in our next democast or Nerdy 30 live session on how you should be thinking about AI risk.