Expel announced the first MDR solution that reaches across the full AI attack surface. Expel Managed Detection and Response (MDR) coverage now extends to threats attackers launch with AI, the risk employees create if they misuse it, and the exposure inside the AI systems organizations are building and running.
AI moves faster than most teams can see the risk
AI is both a new attack surface and a moving target. Addressing AI risk also stalls inside most organizations, often due to a lack of visibility into AI use within the organization, and agreement on where AI risk is most prevalent. Additionally, most teams lack the expertise to accurately determine whether threats are AI-related. Rather than adding new budget or headcount to address AI security risk, most organizations are finding a faster path to coverage by extending the detection and response resources they already have. Expel is covering the full AI attack surface by incorporating its history and breadth of detection expertise, and using that foundation to build new skills, new models, and new telemetry to address emerging threats.
Expel extends its trusted MDR to the full AI attack surface
Expel is extending its MDR across the different elements of the AI attack surface. Expel operators run the coverage, accelerated by AI, not handed to it. Three capabilities are live at launch:
- Anthropic Claude integration: The integration pulls Claude Enterprise Compliance signals, including usage activity and prompt content, into Expel’s detection pipeline. Where most integrations stop at activity logs, Expel’s operators work the prompt content itself to surface intent, not just activity. It’s the first in a growing lineup of AI-native integrations planned through 2026.
- Detections mapped to MITRE ATLAS: Expel’s detection library is labeled where AI is a factor, mapped to MITRE ATLAS, and is available to customers. Coverage today includes 13 of 16 tactics.
- AI-focused threat hunting: Expel’s threat hunters run structured hunts built for AI-augmented attack patterns and AI exposure.
Expel analyzes AI risk across the full attack lifecycle, enhancing existing detections to flag where AI is a factor. From there, it surfaces AI-driven activity in context with signals from identity, cloud, and other layers attackers exploit, and correlates those signals across the entire environment.
“You can’t out-automate an attacker who’s using the same AI you are,” said Justin Bajko, Expel’s Chief Strategy Officer and co-founder. “The models change weekly. What doesn’t change is the judgment call in the middle of an incident, because that’s still where human expertise is critical. We built this so our operators own that call across the whole AI attack surface.”





