Databricks Unveils Lakewatch: AI-Driven Security Lakehouse Revolutionizing Threat Detection and Response

March 24, 2026
Databricks Unveils Lakewatch: AI-Driven Security Lakehouse Revolutionizing Threat Detection and Response
  • The launch comes as SIEM market consolidation accelerates, with AI-enabled security becoming a competitive differentiator among major players.

  • Databricks promises petabyte-scale SecOps with decoupled storage/compute, full telemetry in cloud storage, serverless on-demand compute, long-term retention, and data ownership.

  • Key capabilities include Genie Code, Genie Spaces, Detection-as-Code, Custom ML Detections, and AI-enhanced dashboards to support ingestion, detection authoring, and threat hunting.

  • The platform enables automated detection and response through defense agents, aiming to reduce mean time to detect and respond without vendor lock-in.

  • Databricks is launching Lakewatch, an AI-driven security lakehouse, anchored by acquisitions of Antimatter and SiftD.ai to fuse SIEM-like detection with conversational AI powered by Claude through Anthropic.

  • Lakewatch ingests, retains, and analyzes multimodal security data at scale on open formats to cut costs, avoid vendor lock-in, and deploy defender agents for automated threat detection and response.

  • The move signals a shift toward a scalable, open security ecosystem that could become a durable revenue stream and deepen Databricks’ role in enterprise data and AI architectures.

  • CEO Ali Ghodsi argues current SIEM pricing incentivizes limited data ingestion, hindering defense against AI-driven threats.

  • Executives believe large language models are mature enough to automate portions of threat detection, investigation, and remediation, with some features still under development.

  • The private-preview Lakewatch focuses on ingesting and analyzing large volumes of multi-modal data, including unstructured formats, for comprehensive enterprise visibility.

  • The initiative aligns with trends of data platform companies expanding into security and AI-powered tools, with market forecasts of AI-enhanced security operations investments rising toward 40% by 2026.

  • SiftD.ai’s notebook-centric workflow supports human-on-the-loop operations for faster triage and formal post-incident reviews.

Summary based on 18 sources


Get a daily email with more Startups stories

More Stories