Methodology

How The AI Wire is made

The AI Wire is the public product name. The masthead uses The Wire as shorthand for the same machine-curated AI security wire.

Severity rubric

The 0-1 score is an impact signal for threats

Severity is a model's structured judgment, reviewed by no human by default. It is not a CVSS score, a confidence score, or a promise that the item was manually validated.

  • 0 means not applicable, or low or neutral impact.
  • 1 means a high-impact threat, especially one reported as actively exploited.
  • Threat-class items use impact as the driver. Working proof-of-concept exploits and actively-exploited threats score higher than commentary or opinion.
  • News, research, analysis, and tool items carry low or neutral severity by design because severity is not used to rank or lead non-threat classes.
  • Out-of-scope items are excluded, not down-scored. Items judged outside the feed's AI and agentic-security focus are dropped during curation rather than published with a reduced severity, so every score you see is on an in-scope item.

Example: a threat item describing an actively exploited agent tool-abuse flaw with a working proof of concept can land near the high end of the scale; a general AI security commentary item should not.

How items are made

Poll, cluster, curate

Poll & cluster

Internet sources are crawled for AI security coverage, then near-duplicate coverage is embedded and grouped into durable items.

Curate

AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threat-class items, and writes the summary.

Every item here is one machine-curated intelligence object, not a headline.

Corroboration & provenance

Sources, references, and reports mean different things

  • The dateline count — shown as "N reports" beside "First reported" — is the deduped tally of dated coverage, the distinct reports behind an item.
  • The source rail's "Contributing sources · N" is a different, larger-or-equal count: it merges polled sources with admitted reference links.
  • References are provenance links to original, vendor, or other authoritative records when the source-trust pipeline admits them.

Cue labels link source rows to their handling: PRIMARY, UNVERIFIED, and FLAGGED.

  • PRIMARY marks a trusted primary source or authoritative original selected from the item's references.
  • UNVERIFIED marks reference-only material whose source tier is still unknown.
  • FLAGGED marks a source whose cached reputation verdict currently says malicious; public rows keep context while avoiding direct endorsement.
  • Single-source marks indicate that the item currently rests on one contributing source or one deduped report, so corroboration is thin.

Timestamps are scoped: first reported is when the clustered coverage first appeared; updated is the most recent source publication time, shown when an item has more than one source; curated is when the machine-curation record was emitted. Material later changes are recorded in the dossier changelog described below.

Corrections & change policy

Items can be corrected and re-curated

When clustering, source attribution, or relevance is wrong, merged dossiers can be corrected and re-curated. The dossier changelog records material updates so a corrected item can show how the public record changed.

To report wrong clustering or source attribution to the feed operator, include the item URL, the source row involved, and what should be split, merged, removed, or relabeled. Human review can happen for corrections, but it is not guaranteed by default for every machine-curated item.