Figma's AI Agents: Supercharging Security Investigations

Alps Wang

Alps Wang

Sep 6, 2026 · 1 views

AI Agents: Figma's Security Revolution

Figma's implementation of AI agents for security represents a compelling advancement in leveraging AI for operational efficiency and threat detection. The reported 70% reduction in resolution time for complex alerts and a 20% decrease in on-call pages are significant metrics, demonstrating tangible benefits. The system's ability to learn from past incidents, query diverse data sources (AWS, Okta, GitHub, GCP, osquery), and even suggest code fixes highlights a sophisticated approach to automating laborious security tasks. The emphasis on separate memory types (past alerts, behavioral guidance, learned database structures) is a crucial detail, underscoring the importance of robust AI architecture for sustained performance and improvement. Furthermore, the proactive discovery of over 100 previously unknown vulnerabilities, including critical flaws, showcases the potential of AI to augment, and in some cases surpass, traditional security tools.

However, the article implicitly raises important considerations regarding the evolving role of human oversight in AI-driven security. While Figma maintains strict controls and human review, the broader industry trend towards greater AI autonomy necessitates a deeper discussion on trust boundaries and potential vulnerabilities, as hinted at by external reports on AI coding assistants. The authors' caution about the context-dependency of their approach (company size, risks, feedback loops) is also a vital caveat, suggesting that widespread adoption will require tailored strategies. The technical details, while informative, could benefit from more depth on the specific LLM integrations beyond mentioning Claude Opus and the exact nature of the 'steering memory' to provide a more complete picture for practitioners aiming to replicate such systems. The balance between precision and recall in vulnerability detection is a well-articulated challenge, and Figma's focus on precision first is a sound strategy, though the long-term implications of prioritizing precision over recall in certain security contexts warrant continued observation.

Key Points

  • Figma employs AI agents to automate security investigations, significantly reducing alert resolution time by approximately 70%.
  • The agents query over 100 data sources, including AWS, Okta, GitHub, GCP, and osquery, to analyze alerts and audit logs.
  • Key components of the system include Panther SIEM, AWS Bedrock Knowledge Bases, Amazon Kendra, Tines, and a Snowflake-based tool.
  • Memory management is crucial, with separate types for past alerts, behavioral guidance, and learned database structures enhancing agent performance.
  • AI agents have identified over 100 previously unknown vulnerabilities, including critical flaws missed by traditional tools.
  • The system also improves detection of known bugs and reduces coding errors through automated guidance.
  • Safety controls are integrated, with agent-created PRs defaulting to draft and prompts designed to prevent sensitive data leakage.
  • The article stresses the importance of improving precision before recall in vulnerability detection.
  • The balance between AI automation and human oversight remains an evolving challenge, acknowledging that AI is not perfect but neither are humans.

Article Image


📖 Source: How Figma Uses AI Agents for Security

Related Articles

Comments (0)

No comments yet. Be the first to comment!