Databricks Unveils Lakewatch: AI-Driven Security Lakehouse Revolutionizing Threat Detection and Response
March 24, 2026
The launch comes as SIEM market consolidation accelerates, with AI-enabled security becoming a competitive differentiator among major players.
Databricks promises petabyte-scale SecOps with decoupled storage/compute, full telemetry in cloud storage, serverless on-demand compute, long-term retention, and data ownership.
Key capabilities include Genie Code, Genie Spaces, Detection-as-Code, Custom ML Detections, and AI-enhanced dashboards to support ingestion, detection authoring, and threat hunting.
The platform enables automated detection and response through defense agents, aiming to reduce mean time to detect and respond without vendor lock-in.
Databricks is launching Lakewatch, an AI-driven security lakehouse, anchored by acquisitions of Antimatter and SiftD.ai to fuse SIEM-like detection with conversational AI powered by Claude through Anthropic.
Lakewatch ingests, retains, and analyzes multimodal security data at scale on open formats to cut costs, avoid vendor lock-in, and deploy defender agents for automated threat detection and response.
The move signals a shift toward a scalable, open security ecosystem that could become a durable revenue stream and deepen Databricks’ role in enterprise data and AI architectures.
CEO Ali Ghodsi argues current SIEM pricing incentivizes limited data ingestion, hindering defense against AI-driven threats.
Executives believe large language models are mature enough to automate portions of threat detection, investigation, and remediation, with some features still under development.
The private-preview Lakewatch focuses on ingesting and analyzing large volumes of multi-modal data, including unstructured formats, for comprehensive enterprise visibility.
The initiative aligns with trends of data platform companies expanding into security and AI-powered tools, with market forecasts of AI-enhanced security operations investments rising toward 40% by 2026.
SiftD.ai’s notebook-centric workflow supports human-on-the-loop operations for faster triage and formal post-incident reviews.
Summary based on 18 sources
Get a daily email with more Startups stories
Sources

TechCrunch • Mar 24, 2026
Databricks bought two startups to underpin its new AI security product
Yahoo Finance • Mar 24, 2026
Databricks bought two startups to underpin its new AI security product
Databricks • Mar 24, 2026
Databricks Enters Security Market with Launch of Lakewatch: New Open, Agentic SIEM