Open sources can take you a long way toward naming an adversary — and they can take you confidently to the wrong name. The discipline is not in the collection; it is in what you are willing to claim from it.
Threat intelligence is not a feed of indicators. It is a decision-support product with a consumer, a question, and a stated confidence — and most of what is sold under the name fails all three tests.
Language models are useful in intelligence work in proportion to how rigorously you measure them. Without a baseline, a confidence contract, and an audit trail, an AI pipeline does not produce intelligence — it produces fluent, unfalsifiable assertions at scale.