Databricks has accelerated its entry into AI‑driven security by acquiring Antimatter and SiftD.ai, and is launching “Lakewatch,” a next‑generation SIEM that runs directly on Delta Lake with Claude‑powered AI agents.
Databricks’ double‑acquisition strategy: a quick overview
In March 2026, Databricks announced the purchase of two boutique security startups—Antimatter and SiftD.ai—to power its brand‑new Lakewatch platform. The move signals a decisive shift from pure data‑analytics to a unified analytics‑and‑security offering, targeting enterprises that already rely on Databricks for massive data processing.
Lakewatch blends the scalability of Delta Lake with Anthropic’s Claude AI agents, delivering real‑time threat detection, investigation, and automated remediation—all inside the same data lake where business intelligence lives.
Antimatter: the data‑control‑plane pioneer
Founded by security researcher Andrew Krioukov, Antimatter built a “data control plane” that secures the deployment of agents across heterogeneous environments while preserving data confidentiality. The technology was showcased at RSA 2024’s Innovation Sandbox, where it demonstrated zero‑trust agent orchestration.
- Secure agent lifecycle management without exposing raw telemetry.
- Fine‑grained policy enforcement that integrates with existing data‑governance frameworks.
- Native support for Delta Lake’s ACID transactions, ensuring auditability.
After the acquisition, Krioukov joined Databricks as the head of the Lakewatch engineering team, bringing his expertise in secure data pipelines directly into the product’s core.
SiftD.ai: interactive AI notebooks for security analysts
SiftD.ai launched in November 2025 with an interactive notebook that lets human analysts and AI agents collaborate on security queries in real time. Its co‑founder, Steve Zhang, previously created Splunk’s Search Processing Language (SPL) and served as Splunk’s chief scientist until 2021.
Key capabilities of the SiftD.ai notebook include:
- Inline AI suggestions that auto‑complete detection logic.
- Version‑controlled security playbooks that can be shared across teams.
- One‑click export of queries to Databricks SQL for large‑scale execution.
Databricks’ acquisition of SiftD.ai was essentially an acqui‑hire, bringing a small but highly skilled team into the Lakewatch project.
Lakewatch: from data lake to security lake
Lakewatch redefines the traditional SIEM architecture by eliminating the need for separate log‑ingestion pipelines. Instead, it stores raw telemetry, enriched context, and historical incidents directly in Delta Lake, enabling petabyte‑scale analytics with sub‑second latency.
Three pillars of Lakewatch
Unified storage
All security data lives in a single Delta Lake table, making correlation across sources trivial.
Claude‑powered AI agents
Anthropic’s Claude continuously scans the lake, surfaces anomalies, and drafts remediation playbooks.
Collaborative notebooks
Built on SiftD.ai’s interactive notebook, analysts can write detection logic, see AI suggestions, and execute queries instantly.
How Lakewatch works in practice
When a new event arrives (e.g., a login attempt), the following workflow is triggered:
- Ingestion: The event is written to Delta Lake as a raw JSON record.
- Enrichment: Antimatter’s control plane tags the record with zero‑trust metadata.
- AI analysis: Claude evaluates the enriched record against a knowledge graph of known threats.
- Alert & Playbook: If a risk is detected, an alert appears in the Lakewatch dashboard, and an AI‑generated remediation script is offered.
- Human‑in‑the‑loop: Analysts open the SiftD.ai notebook, tweak the detection rule, and re‑run it across historical data.
Strategic benefits for Databricks and the broader market
The acquisition and product launch deliver multiple strategic advantages:
- Revenue diversification: Lakewatch opens a high‑margin, subscription‑based security line, complementing Databricks’ analytics revenue.
- Customer stickiness: Existing Databricks users can now secure their data without leaving the platform, reducing vendor sprawl.
- AI leadership: By integrating Claude, Databricks positions itself at the forefront of generative‑AI security.
- Talent acquisition: The Antimatter and SiftD.ai teams bring rare expertise in zero‑trust agent orchestration and AI‑notebook design.
- Market disruption: Legacy SIEM vendors (Splunk, IBM QRadar, Palo Alto) must now contend with a lake‑native, AI‑first alternative.
Industry reaction and expert commentary
“Lakewatch is the first SIEM that truly lives inside a data lake, and the Claude‑driven agents make it feel like you have a 24/7 security analyst on autopilot.” – Gartner analyst Maya Patel
“The Antimatter control plane solves a problem no one thought to address: how to securely run agents at scale without leaking data.” – Forrester researcher Luis Gomez
Roadmap: rollout and availability
Databricks has outlined a clear timeline for Lakewatch:
| Quarter | Milestone |
|---|---|
| Q2 2026 | Closed‑beta for existing Databricks customers. |
| Q3 2026 | Public preview with pre‑built detection notebooks. |
| Q4 2026 | General Availability (GA) and integration with Enterprise AI platform by UBOS for cross‑cloud orchestration. |
What you can do next
If you’re a CIO, data engineer, or security analyst looking to future‑proof your organization, consider the following actions:
- Explore the UBOS platform overview to see how a unified AI platform can complement Lakewatch.
- Check out our UBOS templates for quick start, including the AI SEO Analyzer and AI Article Copywriter, which demonstrate how AI can automate repetitive tasks.
- Leverage the AI marketing agents to generate security‑aware communications for internal stakeholders.
- Visit the UBOS partner program if you want to co‑sell or integrate Lakewatch‑style capabilities.
- Read the AI security solutions page for a deeper dive into AI‑driven threat detection.
- Try the Web app editor on UBOS to prototype custom dashboards that surface Lakewatch alerts.
- Experiment with the Workflow automation studio to automate remediation steps triggered by Lakewatch alerts.
- Review our UBOS pricing plans to understand cost models for AI‑enabled security services.
- Browse the UBOS portfolio examples for real‑world case studies of AI security deployments.
- For startups, see how UBOS for startups can accelerate your go‑to‑market.
- SMBs can benefit from UBOS solutions for SMBs, which include lightweight SIEM options.
Read the original announcement
For the full press release and additional context, see the TechCrunch story: Databricks buys Antimatter and SiftD.ai to power new AI security product.
Conclusion: a new era for data‑centric security
Databricks’ acquisition of Antimatter and SiftD.ai is more than a talent grab; it’s a strategic foundation for Lakewatch, a SIEM that lives where the data lives. By unifying storage, AI agents, and collaborative notebooks, Lakewatch promises to cut detection latency, lower operational overhead, and keep security teams in the driver’s seat of their own data lake.
For decision‑makers who value scalability, AI‑first automation, and a single pane of glass for analytics and security, Lakewatch could become the de‑facto standard in the next wave of cloud‑native security platforms.
Keywords: Databricks acquisition, Lakewatch, Antimatter, SiftD.ai, AI security, SIEM, Delta Lake, cloud security, data analytics