VendorResearch

Recorded Future Introduces AI Infrastructure Indicator Lists, Strengthening AI Governance


Today, Recorded Future is announcing AI Infrastructure Indicator Lists, curated datasets for security teams to identify, monitor, and implement controls for AI-related network traffic. AI Infrastructure Indicator Lists are included for free for Recorded Future customers with a Cyber Operations license.

Artificial intelligence has increasingly become enterprise infrastructure and organizations are now confronting unsanctioned tool use (also known as shadow AI), data exposure, and autonomous behavior that their controls cannot always see.

Recorded Future’s AI Infrastructure Indicator Lists focus on closing this gap across risk, IT, and GRC teams whether the goal is policy enforcement, data loss prevention, or detecting shadow AI.

AI is accumulating security debt

The hidden risks of an abundance of AI within an organization are often overshadowed by the daily threats that have to be prioritized by a security team. Last year, we reported on how security debt has been accrued by almost every organization, and the unaddressed risks are piling up faster than teams can service them. As a result, blind spots in AI governance are also increasing.

Take, for example, agentic AI. Its adoption is accelerating rapidly and agents are operating across interconnected systems, giving threat actors more room to exploit vulnerabilities at the organizational level and across supply chains.

Consider a free, viral AI assistant that an employee discovers on social media and installs on their own machine to boost productivity. No procurement process, no security review, no IT visibility.

That’s not a hypothetical. OpenClaw, a free open-source AI assistant, saw explosive adoption earlier this year with almost no organizational oversight. Multiply that across a workforce and security teams left trying to govern tools they don’t know exist.

By 2027, an estimated 75% of employees are expected to adopt or build technology outside IT governance. As agents become more ubiquitous, defenders need to ensure they can identify which technologies are living on their networks, and begin to track and manage access permissions for autonomous processes in the same way they manage permissions for human users.

Introducing AI Infrastructure Indicator Lists

While many threat feeds give you a wall of indicators and leave you to figure out what they are and whether to trust them, Recorded Future’s AI Infrastructure Indicator Lists do the opposite.

AI Infrastructure Indicator Lists are curated, regularly refreshed datasets that map the AI infrastructure your users, developers, and adversaries are actually reaching for. Indicators include IP addresses, CIDR ranges, and domains, carrying their own Risk Scores and comment fields with service attribution.

Recorded Future provides two distinct AI-related lists: the AI infrastructure list and the Chinese AI infrastructure list. The lists cover a comprehensive range of tools, including general-purpose AI assistants, AI coding assistants, vibe-coding tools, AI search tools, voice and audio AI tools, AI video tools, Chinese-domiciled AI tools, and autonomous AI agents.


Figure 1: List of AI tools monitored in AI Infrastructure Indicator Lists

Each indicator follows a consistent structure — Entity / Risk Score / Comment — where the Comment is the analyst’s answer key. Comments include the provider the indicator belongs to, the date it was last verified, and how the indicator was attributed to the service (referred to as association methods). An example indicator may read Anthropic, Verified 2026-09-16, Live JSON.

AI Infrastructure Indicator Lists are built to drop straight into existing tooling with the three fields mapping cleanly to SIEM lookups, firewall imports, and TIP feeds. However, there are a few principles to follow for an effective rollout:

  • Discover before you block. The highest-value first move is visibility, not enforcement. Run the full List against 30–90 days of historical DNS and proxy logs to baseline what your environment already reaches. Vibe-coding deployment domains and Chinese AI tools are consistently the most-undiscovered categories in the first pass.
  • Filter on domains, not IPs. Most AI services sit behind shared CDN infrastructure, so IP-only rules cause collateral damage. SNI- or DNS-based domain filtering is the primary control while IP and CIDR entries supplement.
  • Let the Comment field drive the action. The service provider in the comment field lets you build a per-vendor policy rather than a flat rule set. The verification date flags entries to revalidate (anything over 90 days) and the association method tells you how confident to be before enforcing.

Figure 2: Domain with recently suspected phishing techniques linked to AI Infrastructure

Addressing key issues with AI governance

Behind every indicator is a potentially solvable AI governance issue. For shadow AI discovery, seeing unknown AI traffic is simply not enough. By knowing which service is running, who runs it, and the level of risk and confidence behind that call, security teams get visibility and intelligence they can actually act upon.

When it comes to policy enforcement, the indicator lists turn static blocklists into a more precise workflow. Empower teams to block the risky vendors, monitor any products that fall within a grey-zone, and permit sanctioned AI tools all within the same feed.

AI Infrastructure Indicator Lists help establish boundaries on the products and services that could be unknowingly carrying corporate data out of your environment. By knowing exactly which endpoints carry this risk, indicator lists can help enforce data loss prevention.

Finally, indicator lists help companies maintain their data sovereignty by flagging traffic headed to foreign-domiciled services, where data may fall under a jurisdiction’s compelled disclosure laws.

Getting started

Start simple. Run the AI Infrastructure Indicator Lists against your historical logs to see what’s already there. Then use the attribution in every row to decide what to block, monitor, or allow. The value doesn’t stop there.

With Recorded Future’s Attack Surface Intelligence, organizations can get outside-in discovery that extends to this emerging class of AI and MCP infrastructure, surfacing exposed control panels, open proxies, and unauthenticated endpoints before an attacker finds them first. Pair this with AI Infrastructure Indicator Lists’ visibility into which AI services your network is already talking to, this provides security teams coverage on both sides of the problem – what’s exposed and reachable from the outside, and what’s already in use from the inside.

Learn more about Recorded Future’s Cyber Operations or request a demo to see it in action.

Frequently Asked Questions

How to retrieve the AI Infrastructure Indicator Lists?

The AI Infrastructure and Chinese AI Infrastructure Indicator Lists can be accessed directly in the platform or via API. The recommended retrieval time is daily.

Who gets access to AI Infrastructure Indicator Lists and when are they available?

Recorded Future customers who have a Cyber Operations or Threat Intelligence Module license will have access to the AI Infrastructure Indicator Lists at no additional cost. The AI Infrastructure Indicator Lists are available now.

How often are the lists updated, and how often should I pull it?

The lists are refreshed on a regular cadence — typically weekly. We recommend retrieving it daily via the List API. Daily retrieval minimizes the lag between publish and ingestion without adding meaningful processing overhead. The freshness of any individual indicator is visible in the verification date inside the Comment field.

Run the full entity list against 30–90 days of historical DNS and proxy logs for a shadow IT baseline, then segment by service provider and Risk Score to prioritize. Vibe-coding deployment domains and Chinese AI tools are consistently the most-undiscovered categories in that first pass.

Why do some AI tools have a low Risk Score?

The Risk Score reflects the standard threat-intelligence score, which is weighted toward cyber attack indicators. For most AI tools the real risk is policy, compliance, and data exposure so a low score is not uncommon, but does not mean the indicator is unimportant. Consider prioritizing by service provider and use case, not the score alone.

What are the association methods and their levels of confidence?

Each entry is attributed using one of four methods, listed from highest to lowest confidence:

  • Live JSON — Pulled directly from a vendor-published, machine-readable IP feed. Highest confidence; safe to use in enforcement.
  • Official documentation — Documented by the vendor in a security, trust, or network configuration page. Highest confidence; generally usable for enforcement.
  • BGP / WHOIS — Attributed to the vendor via BGP routing registry and WHOIS records.
  • Community / OSINT — Derived from public security research, third-party network intelligence, or community investigation. Medium confidence; validate ownership (reverse DNS, TLS cert, BGP/WHOIS) before blocking, and revalidate any entry whose verification date is older than 90 days.

Why does a single connection to one entity seem to hit multiple AI providers?

Some entities are proxies or gateways. For example, Vercel’s AI Gateway routes to OpenAI, Anthropic, and Google from one endpoint. A single connection can represent calls to any number of underlying providers, so apply policy at the proxy domain with that in mind.

Where can I find more information?

More information can be found in the accompanying support article or contact us with any questions.



Source link