LLM
A Large Language Model (LLM) is an AI model trained on vast amounts of text to understand and generate language.
A Large Language Model (LLM) is an AI model trained on very large amounts of text. It understands and generates language and can summarise, translate and classify texts and write code.
How it works
An LLM predicts the most likely continuation of a text token by token (mostly word fragments). It learns knowledge and language patterns from training on large datasets. Instructions, examples and tools can direct it for specific tasks. The model only knows its training data or what it currently receives. It can produce convincing but incorrect statements.
A practical example: an Alert contains a long, obfuscated PowerShell command line. An LLM decodes and deobfuscates it and describes what the command does in three sentences. The analyst verifies the statement using the EDR data. This saves several minutes of manual analysis.
What to look out for
- LLMs can invent false information. Important statements require verification against data.
- Inputs can be manipulated. Prompt injection is a real risk.
- Clarify where the model runs and if inputs are used for training.
- Limit the permissions of systems that an LLM can control.
- Measure the quality for your tasks with a fixed test set.
Switzerland and regulation
Switzerland has no specific law for LLMs. The revFADP (revised Federal Act on Data Protection) applies when personal data is processed. The FDPIC (Federal Data Protection and Information Commissioner) has clarified that data protection law applies to AI applications. Companies with EU ties must also consider the EU AI Act.
Use in the SOC
In a SOC, LLMs are suitable for summaries, analysing unstructured data, and preparing reports. Decisions with operational impact should remain tied to rules and human approval.
How we implement it
Our Agentic AI uses LLMs for the analysis of Cases. Interventions on your systems only occur within the agreed mandate.