What happened
On Sept 28, 2026, Recorded Future announced general availability of its Model Context Protocol (MCP) server, giving AI agents/LLMs (Claude, ChatGPT, Copilot, Cursor, Gemini CLI) OAuth-authenticated access to 80+ intelligence tools — threat actor profiles, Risk Scores, ransomware metadata, malware sandbox and dark-web data — plus write-capable tools for Watch Lists and Analyst Notes, after a year-long pilot with 100+ enterprise customers.
Why it matters
This is the first major threat-intel vendor to productize agent-native intelligence access at GA scale, addressing a core failure of agentic SOCs (unreliable, unauditable LLM decisions). It lets detection engineering, triage and IR agents pull trusted intelligence at machine speed on the same trusted data layer that drives human analyst decisions, closing the loop from analysis to configuration.
Applicability
Security teams building SOC copilots/agentic detection workflows should evaluate Recorded Future MCP to ground agent decisions in scored intelligence; relevant for existing Recorded Future customers and any org wiring agents into SIEM/SOAR enrichment.