Large language models (LLMs) are increasingly applied in Cyber Threat Intelligence (CTI) to analyse security data and support threat report interpretation, anomaly detection, and detection rule generation. Deploying LLMs in operational CTI environments raises challenges related to reliability, governance, and regulatory compliance within the European framework shaped by AI Act, GDPR, NIS2, and the Cyber Resilience Act. This survey analyses current applications of LLMs in CTI and evaluates nine representative use cases. To enable trustworthy deployment, we propose a regulation-aware reference architecture integrating data governance, intelligence processing, compliance orchestration, and human oversight, providing a design framework for compliant AI-enabled ICT.
No takes yet. Share an insight, caveat, or question.
Ekelhart et al. (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: