Databricks completes acquisition of AI security platform Panther
Databricks has completed its acquisition of Panther, an AI-powered security operations platform, folding Panther's detection and triage engine into Databricks' Lakewatch security lakehouse product. Financial terms of the deal were not disclosed.
What's new
Panther brings a mature set of security operations center (SOC) workflows to Databricks: more than 100 out-of-the-box data integrations, a software-driven detection engine, and support for "detections-as-code," where security rules are written, versioned, and tested like software rather than configured through a legacy SIEM console. The combined product pairs that detection layer with Lakewatch's own open, petabyte-scale data foundation.
Databricks framed the deal as a direct response to the limits of legacy security tooling, writing that "legacy SIEMs were built more than a decade ago around limited data ingestion, strict sampling trade-offs, rigid compute architectures, and manual alert triage." The pitch for the combined platform is that "security teams can now retain petabytes of telemetry in open formats, deploy autonomous AI agents for real-time triage, and execute detections-as-code."
Databricks describes the split of responsibilities plainly: "Lakewatch provides the open, petabyte-scale data foundation, while Panther delivers the agentic automation engine to act on it." In practice, that means security teams can keep years of raw log and telemetry data queryable in open formats instead of paying to ingest and retain it inside a traditional SIEM, while still getting Panther's existing detection rules and AI-driven triage on top.
Context
The deal was first announced in mid-June 2026 as a signed agreement, and this completion marks the close of that transaction. It is Databricks' third security-focused acquisition, part of a broader push by the company to build out a "security lakehouse" category that competes with incumbent SIEM vendors by combining its existing data-platform strength with purpose-built security automation. Panther's existing customer base includes security teams at AI-native companies, including Anthropic, which the company points to as evidence the platform holds up in demanding, high-velocity environments.
Why it matters
Security operations is becoming one of the more concrete enterprise proving grounds for agentic AI — SOC teams generate enormous volumes of telemetry and alerts, exactly the kind of high-volume, well-structured data that AI agents can triage faster than human analysts working a legacy SIEM queue. By acquiring rather than building that detection and triage layer, Databricks is betting that owning the data platform underneath security operations is more defensible long-term than owning the automation layer on top of it, and that bundling both will pull SOC workloads away from incumbent SIEM vendors that don't have a comparable open data foundation to build on.
Corroborating sources
- Databricks
https://www.databricks.com/blog/databricks-completes-acquisition-panther-accelerating-security-lakehouse-era
“Lakewatch provides the open, petabyte-scale data foundation, while Panther delivers the agentic automation engine to act on it.”