The four-second keyhole
The reasoning was never the hard part. The context was.
- An AI security agent spends its first few seconds assembling context, pulling live from your tools, under rate limits, in whatever order they answer. Then it reasons over that snapshot. That snapshot is improvised context.
- Modern models can be useful investigators when they are given a complete, current picture. The weak layer is often the picture underneath.
- Improvised context is partial by construction and stale the instant it is built. It looks like understanding until the part of your environment it never saw is the part that mattered.
- It comes out that way because the agent is a tourist: it visits your environment to answer a question and leaves, holding no standing model between visits. Call it context tourism.
- The asymmetry: an attacker studies your environment for weeks. A defending agent reasoning from a four-second sketch was never in a fair fight.
- The answer is not only a better model. It is context that already exists before the question: connected, reconciled, and current. We call it Live Security Context.
Watch an AI security agent work and it looks remarkable for about four seconds.
Those few seconds are the tell. Sometimes it is four seconds, sometimes longer; the exact number is not the point, the pattern is. That is the window it spends, right after you ask, assembling the context it is about to reason over. It reaches into your EDR, your cloud, your identity provider, your ticketing system. Live. All at once. Tools that were never built to answer the question it is asking, queried under rate limits, returning whatever they return in whatever order they return it.
Then it reasons. And the reasoning is genuinely good, good enough that the four seconds before it are easy to forgive, or to miss entirely.
I want to talk about those four seconds, because that is where the real problem lives, and almost nobody is looking at it.
And it is about to be everyone's problem, not just the problem of teams already running agents today. This is the direction the entire industry is moving. Whatever you are evaluating now, or will be next year, is going to reason over context it got from somewhere. The only question that matters is where.
The four seconds you are forgiving
So look again at those four seconds. The agent is building a picture of your environment on the spot, from a keyhole. It gets one narrow, time-boxed look through whatever APIs answer fastest, assembles a rough model of how your systems relate, and reasons over that model as if it were the truth. It is not lying. It is doing its best with what it could grab in the moment. But what it grabbed is partial by construction, and stale the instant it was built.
I call this improvised context. Context assembled at the moment of the question, from whatever is reachable, arranged into something coherent enough to reason over. It looks like understanding right up until the part of your environment it never saw is the part that mattered.
There is a reason it comes out this way. The agent is a tourist in your environment. It shows up when you ask a question, photographs whatever happens to be in front of it, and is gone before it understands what it saw. It never lived there. It could not tell you what is around the next corner, because it was never there long enough to learn. Call it context tourism. Improvised context is what a tourist inevitably produces: a confident account of a place they visited for four seconds.
What that looks like in practice
A simplified example makes this concrete.
An analyst points the agent at a finding on prod-web-07, an internet-facing host, and asks the obvious question: is this one worth worrying about?
The agent does its four-second sweep. It pulls the CVE, inspects the host, checks the cloud configuration, and comes back fast and confident: medium severity, no direct route to anything sensitive, safe to deprioritize.
Here is what those four seconds could not see. The service account on prod-web-07 can assume a role. That role, through two more hops nobody had documented, reaches a critical business system. The path from a forgettable internet-facing host to something that matters was real and sitting right there. It just was not reachable through the APIs the agent happened to query, in the order they answered, in the time it had.
The context that would have flipped the answer existed. It simply could not be improvised in four seconds. An attacker who had mapped the environment for a week would have found that path early, because finding that path is the entire job. The agent, reasoning flawlessly over a keyhole, waved it through.
This is not an exotic failure mode. It is how the finding that becomes the incident gets deprioritized: not by a careless analyst, but by a confident system reasoning over the slice of your environment it could see in the time it had.
The wrong layer
The instinct across the industry right now is to make the reasoning better. Bigger models, better prompts, more elaborate agent loops. I think it is aimed at the wrong layer. Better reasoning helps. But better reasoning does not recover relationships that were never in the picture. Give a modern model a complete, current view of an environment and it has a much better chance of getting the exposure right. Give it a keyhole and it will reason flawlessly to the wrong conclusion, because you cannot reason your way out of a picture that was already wrong when you started.
That is the asymmetry that should bother anyone building defensive AI. An attacker is not a tourist. An attacker moves in. They learn the layout, the shortcuts, the doors nobody locks, over days and weeks, because that patience is the whole job. The defending agent, meanwhile, is taking photos at the entrance. When those two meet, the quality of the defender's reasoning was never going to be the deciding factor. It was decided earlier, by who lived in the environment and who was just passing through.
Context is the intelligence
This is the part I most want security teams to sit with, because it reframes what AI in security is actually for. The intelligence people are excited about is not the reasoning. It is the context. A model reasoning over improvised context is a very articulate guess. A model reasoning over a real, current, connected picture of your environment is something else entirely, and the difference between them is not the model. It is what the model was standing on.
This is why we built the environment picture first, and the reasoning second.
Building that picture is the actual work. The hard part is not collecting the signals. Most teams already have them somewhere. The hard part is resolving them: recognizing that two tools are describing the same asset by different names, telling a stale host from a live one, knowing that an identity seen in one system can assume a role in another.
Collection gives you a bigger pile. Resolution gives you a model you can reason over.
Before any agent reasons about anything at Unizo, that resolved picture is already there: connected into a live model of how your environment actually relates, kept current, present before the question is ever asked rather than scrambled together after. We call it Live Security Context. The agent does not go discover your environment while it is deciding what to do. It reasons over an environment it already understands.
The attacker did their homework in advance. The defending system has to have done the same.
Context is not the setup for the intelligence. It is the intelligence.
Sudhanva Gnaneshwar, Co-founder & CTO, Unizo