Google Deploys Gemini to Monitor the Dark Web
Google Threat Intelligence is running Gemini agents across 8-10 million dark web posts daily to surface threats specific to individual organizations - initial access broker listings, stolen credentials, data leaks, insider threat activity. The system builds organization profiles from public data, then uses vector comparisons against dark web content to filter signal from noise. Google claims 98% accuracy, compared to the 80-90% false positive rate that keyword-matching tools typically produce. The module is now in public preview and pairs with Google Security Operations for autonomous investigation and MCP server support for custom enterprise security agents. Microsoft, CrowdStrike, and Recorded Future have all been layering LLMs into threat intelligence workflows over the past year, but Google processing the full daily volume of dark web posts through Gemini is a different scale of commitment.