BlogsElasticAgentic AI Context Layer

Agentic AI Context Layer

Agentic AI Context Layer

10
posts
2024–2026

Elastic Security continues to evolve its agentic AI capabilities, integrating with AWS services like Amazon Bedrock and GuardDuty. The platform now features Elastic Workflows for automated triage, enrichment, and response, alongside Agent Builder for AI-driven reasoning. New Entity Analytics capabilities enhance context for AI agents, improving accuracy and proactive threat hunting. This builds upon the foundation of providing AI-specific security for AWS infrastructure and AI applications. This post emphasizes the critical role of trusted context, governance, and observability for enterprise-scale Agentic AI in financial services, highlighting the need for unified data, observability as an AI control plane, and evolving security practices to manage AI-driven actions.

2026

Building trusted agentic AI in financial services: From data to autonomous action

8/6/2026

This post details the challenges and requirements for building trusted agentic AI in financial services, focusing on the foundational elements of trusted context, governance, and observability. It highlights the shift from generative AI to agentic AI, the increased risk equation, and the importance of rich, unified data for AI agents. The post emphasizes that observability (metrics, traces, logs) becomes the control plane for governing AI, and that security must evolve to monitor and validate AI actions. It also stresses the role of enterprise search in providing current, permission-aware, and governed knowledge to AI agents. Finally, it poses five key questions for financial institutions to consider before deploying agentic AI.

Closing the AI gap in government: Next-gen knowledge access | Elastic

7/31/2026

This post details how next-generation knowledge access, specifically a governed retrieval layer, is crucial for scaling AI in government. It contrasts legacy data warehouses with this new approach, emphasizing hybrid search, open integration protocols (like MCP), and security/risk controls (permission filtering, redaction, audit logs) as key architectural components. It also discusses the importance of data readiness, sovereignty by design, and choosing platforms on open standards for successful AI deployment in public sector environments.

Elastic and OpenAI collaborate to bring frontier intelligence to unstructured enterprise data

7/30/2026

This post details the technical collaboration between Elastic and OpenAI to create an 'Agentic AI Context Layer' using Elasticsearch. It explains how Elasticsearch's combined lexical and vector search, semantic reranking, and access controls provide a robust retrieval mechanism for AI agents. The post also introduces Elastic Agent Builder and Agent Skills as tools for exposing Elastic's capabilities to OpenAI models, and discusses optimizations like precomputed Knowledge Indicators to reduce token usage and improve accuracy in Retrieval Augmented Generation (RAG) scenarios. Furthermore, it outlines how Elastic Observability and Elastic Security are being enhanced with agentic capabilities to correlate AI signals with operational and security telemetry for improved investigations and threat response.

Rethinking the SOC: From tool procurement to platform architecture

7/27/2026

This post details the architectural shift required for Security Operations Centers (SOCs) to effectively handle AI-speed threats. It outlines the 'fragmentation tax' imposed by traditional tool-procurement models and explains why AI cannot fix a fragmented foundation. The post proposes an open, unified security architecture with key requirements: unified telemetry, native support for open standards (OpenTelemetry, Elastic Common Schema), query-in-place across data tiers, model-agnostic AI with transparent reasoning, native automation, and flexible deployment options. It introduces the concept of 'agentic operations' where AI assists analysts rather than operating autonomously, leading to faster attack neutralization.

Elastic and Deductive AI join forces to accelerate agentic incident investigation for engineering teams

7/22/2026

This post announces the acquisition of Deductive AI by Elastic. Deductive AI's platform features an AI SRE agent that connects to code, telemetry sources, and organizational knowledge to assist engineering teams in investigating alerts and production issues. The agent performs root cause analysis by gathering evidence, forming and testing hypotheses, and reasoning across multiple context sources. Successful investigation paths are continuously refined and reused. The acquisition will integrate Deductive AI's knowledge graph and investigation engine with Elastic's AI capabilities for enhanced incident investigation.

Elastic achieves the AWS AI Security Distinction, securing AI-specific risks

7/16/2026

This post details the general availability of Elastic Workflows, which combine scripted automation and agentic reasoning for AI agents to act on findings within Elastic Security. It also introduces four new Entity Analytics capabilities: Precision Entity Identification, Entity Resolution, Dynamic Watchlists, and Entity-Driven Hunting Leads, designed to provide AI agents with more accurate context for security data analysis.

The future of governing AI agents

7/8/2026

Introduces a 4-layer architecture (Skills, Reasoning, Models, Context) for governing AI agents, emphasizing the extraction of reasoning into an explicit, testable layer independent of LLMs. Proposes progressive trust as an operating model, where trust is earned through accumulated evidence of agent performance. Defines four key evaluation dimensions: classification accuracy, planning quality, retrieval quality, and grounding quality, to measure agent reliability and consistency.

Elastic and Cursor partner to accelerate context engineering with coding agents

4/13/2026

Introduces the Elastic plugin for the Cursor Marketplace, enabling AI coding agents to leverage Elastic's capabilities for context engineering. This includes providing access to live production logs, security alerts, and Elasticsearch data through Agent Skills and an Elastic Docs MCP server. Specific functionalities enabled are semantic hybrid search, ES|QL query execution, Kibana dashboard surfacing, and security alert triage.

2024

Understanding the approximate nearest neighbor (ANN) algorithm

4/17/2024

This post provides a detailed explanation of Approximate Nearest Neighbor (ANN) algorithms, which are fundamental to efficient vector search. It covers the definition of ANN, how it works through dimensionality reduction and indexing, and when it's most applicable (large datasets, high-dimensional data, real-time applications). The post also discusses the importance of ANN in vector search for enabling fast retrieval and scalability. It then delves into specific ANN algorithm types: KD-trees, Locality-Sensitive Hashing (LSH), Annoy, and Linear Scan, outlining their characteristics, advantages, and disadvantages. This technical deep dive into ANN algorithms directly supports the underlying search capabilities required for the Agentic AI Context Layer by explaining how to efficiently find similar data points in large, high-dimensional vector spaces.

How Elastic AI Assistant for Security and Amazon Bedrock can empower security analysts for enhanced performance

1/25/2024

This post details the integration of Elastic AI Assistant for Security with Amazon Bedrock, enabling the use of LLMs like Anthropic Claude 2 for security operations. It explains how prebuilt prompts and organizational context are used to enhance tasks such as alert summarization, workflow suggestions, query conversion, and agent integration advice. The integration aims to improve security analyst performance by providing accurate, contextually relevant AI-driven assistance.