Background

Closing the Gap Between Detection and Protection with AI-Assisted Custom Rules

August 24, 2026 by Danielle Walter

Share

Key takeaways

While security teams have become better at detecting threats, turning those insights into active protections often creates bottlenecks due to syntax complexity, manual effort, and tool-switching.

Our new Custom Rule Builder AI Assistant (within Akamai App & API Protector) lets security teams generate custom security rules directly from plain text prompts, allowing analysts to focus on intent rather than manual syntax or JSON/XML logic.

By reducing the technical expertise needed to write custom rules, broader security teams can operationalize insights more efficiently, freeing senior experts to handle higher-value tasks.

Generated rules are not automatically deployed to production or staging environments; users review, validate, and edit the AI-generated logic in a familiar interface before activation.

Security teams are getting better at detecting threats. The challenge is acting on them quickly enough.

As applications, APIs, and AI-driven services continue to expand, the volume of security insights continues to grow. The next challenge isn't simply identifying threats; it's reducing the time and effort required to turn those insights into effective protections. That's why we're focused on making security operations more intuitive. 

To help security teams convert threat insights into active defenses faster and more confidently, Akamai has introduced the Custom Rule Builder AI Assistant within Akamai App & API Protector. This generative AI feature allows security analysts to convert natural language prompts directly into enforceable custom security rules with minimal manual effort — so your teams can respond faster to evolving threats.

The insight-action gap

Whether identifying suspicious activity during an investigation, reviewing recommendations from a security assessment, or responding to an emerging attack pattern, translating those insights into active protections often requires specialized expertise and time that teams don't always have. 

Even experienced users can find themselves switching between tools, reconstructing filters, and manually authoring increasingly sophisticated logic to achieve the desired outcome.

The result is an insight-action gap: Organizations know what they need to stop but face friction when turning that knowledge into enforceable protections.

To address this gap, we designed the Custom Rule Builder AI Assistant to help customers move from detection to protection faster and more confidently.

Turning natural language into security outcomes

The Custom Rule Builder AI Assistant enables users to create custom protections using natural language prompts. 

The assistant generates the underlying rule logic, which allows analysts to focus on intent rather than manual rule syntax or condition logic . So, instead of manually translating attack patterns and investigative findings into JSON or XML logic, users can simply describe what they want to achieve. For example: “Create a rule based on the current dashboard filter for top attack payload to block this attack pattern.” 

Reducing the effort required to create protections

The Custom Rule Builder AI Assistant operates within two primary Akamai workflows:

  • Custom Rule Builder: Enables analysts to author, edit, and optimize rule logic using natural language prompts

  • Akamai Web Security Analytics: Allows analysts to convert event investigation context and active dashboard filters directly into active mitigation rules

By reducing the effort required to author protections, organizations can respond more quickly while improving consistency across security operations (Figures 1 and 2).

By reducing the effort required to author protections, organizations can respond more quickly while improving consistency across security operations (Figures 1 and 2).
Fig. 1: Web Security Analytics dashboard
By reducing the effort required to author protections, organizations can respond more quickly while improving consistency across security operations (Figures 1 and 2).
By reducing the effort required to author protections, organizations can respond more quickly while improving consistency across security operations (Figures 1 and 2).
Fig. 2: Custom rule creation using AI Assistant
By reducing the effort required to author protections, organizations can respond more quickly while improving consistency across security operations (Figures 1 and 2).

Making expertise more accessible

Custom rules are among the most powerful capabilities available to security teams, but they have traditionally required a level of familiarity that can create bottlenecks. As a result, services teams, partners, and highly specialized administrators often become the intermediaries between insight and action. 

By lowering the barrier to creating effective protections, the Custom Rule Builder AI Assistant empowers more teams to operationalize security insights independently while allowing experts to focus on higher-value activities.

AI designed with guardrails

Security teams should be able to take advantage of AI without sacrificing oversight. That's why AI-generated rules are not automatically deployed to staging or production environments. 

Instead, they are presented in the familiar editable interface, allowing users to review, refine, and validate recommendations before choosing to save and activate them. This human-in-the-loop approach helps organizations move faster while maintaining confidence in the protections they deploy.

Helping security teams move from insight to action 

The promise of AI in security isn't simply automation for automation's sake. It's helping security teams spend less time translating intent into syntax and more time focusing on the decisions that matter most.

The faster organizations can move from insight to action, the more resilient they become. 

Try it yourself

To see the Custom Rule Builder AI Assistant in action, start a free trial of App & API Protector.

About the Author(s)

Danielle Walter

Danielle Walter

Danielle Walter is an active advocate of IT professionals worldwide, leading their organizations’ growth through innovative IT transformation. She was a subject matter expert on messaging/branding for cloud providers before specializing in security. She enjoys collaborating on thought leadership within the industry and speaking at events. As a certified sommelier, Danielle savors her free time by exploring new wine, food, and destinations.