Wait, Did We Just Invent Classifiers Again? Introducing Jev, a new way to do AI.
For the last few years, when somebody says “AI,” what they are usually referring to is a Large Language Model, or LLM for short. You chuck some text in, it has a think, and it gives you some more text back. This is brilliant if you want code written, documents summarised, or quantum physics explained to you in a limerick, but while this is great for humans, most software doesn’t actually want a beautifully written paragraph. Software just wants an answer so it can make a decision. Is this event suspicious? Should I escalate it? Is this high risk? Which workflow should deal with it? For this, LLMs aren’t really the ideal tool of choice. This is all about to change.
This week TypeSafe AI launched a new kind of model, called Jev, and it’s very interesting. This AI model doesn’t want to have a conversation with you – you cannot use it conversationally. Jev is just trying to do one thing, and it wants to do that one thing well: It’s trying to decide.
So, what is Jev exactly?
Jev is what TypeSafe calls a “System One” model. Rather than primarily generating a sequence of tokens like a traditional LLM, you give Jev some state (think datapoints), define questions about that state (what you want to know), and tell it what valid answers look like (to format the output). Jev then interprets all your inputs, does some smart things, and returns probabilistic decisions. So rather than asking an LLM, “Can you analyse this security event and tell me what you think?,” you can ask Jev for substantially more specific things like: Is this likely malicious? Does this warrant investigation? Is credential compromise likely? How severe is it? What is great is that you can define those outputs beforehand. You’re asking for a decision, rather than hoping the model eventually buries one somewhere inside three paragraphs of text.
Now before anybody says anything, I know what you’re thinking: “Hang on, haven’t we just invented classifiers again?” I had the same reaction. If you’ve never head of a classifier, this is what we used to use before everybody decided their product desperately needed a chatbot glued to the side of it. Machine learning was full of classifiers: Spam or not spam? Fraud or legitimate? Malware or benign? Cat or, tragically, not cat? Classifiers were incredibly useful, but normally quite narrow. You needed training data, labels, pipelines, and usually a model built specifically for that problem. Generative AI gave us something far more flexible because we could suddenly describe what we wanted in natural language. Jev feels a bit like taking that semantic understanding and putting it back inside the old classifier model, but with significantly more accessibility.
The real-world approach: Jev in action with Cato
Let’s use Jev for something a little more interesting than asking whether an ice cream sandwich is technically a sandwich, using the the TypeSafe Playground. Let’s use Jev to interpret data taken from the Cato Management Application via the EventsFeed API.
We will start with a deliberately boring question: a finance employee in the UK, using their normal managed laptop, was successfully authenticating with MFA and downloading four files from SharePoint during the working day. All this extracted information from our API will populate the ‘State’ field – this is the current state of the query, and it should represent what we want to interpret. We then can add a few “Questions” to the field below, as we want to specify a formatted output:
The questions asked were not difficult for a human, but very difficult for a traditional LLM to give a succinct answer due to generative analysis:
- Does this require investigation?
- Is it likely malicious?
- Is credential compromise likely?
- What should the security response be?
- How severe is the risk?
Instead of producing a 300-page AI slop security report, Jev instead evaluates those individual decisions and responds with probabilities of likelihood. After clicking the “Run” button to process the query, Jev outputted the following:
So far, lovely. This event doesn’t need investigation, and Jev believes that there should be a 100% probability that this incident should be closed. There is a 5% chance that this could be likely malicious, but the correlated signals overall indicate that the current state of the event is benign. Fantastic – but what if we did something a little more interesting, like changing the state of the event? After all, the state of your users (and network) is always changing.
We will now use the same user, application, and questions. Except now the device state has changed. The device is now unknown and unmanaged, the connection is coming from Russia (22 minutes after a UK session), it’s 3:17 in the morning, there are impossible-travel indicators, and instead of downloading four files from SharePoint, our finance user has just hoovered up 1,847 documents from Finance and M&A folders. In technical security terminology: that looks a bit dodgy, but these are all parameters we can extract via the Cato API to help Jev make a judgement call.
After hitting Run again, Jev reprocessed the input and a different decision was output based on the evidence provided. This model was able process the data feed and reclassify this not as a benign event that should be instantly closed, but instead the user should be “Contained” as there’s enough evidence to imply a device compromise with 99% certainty.
This capability is incredibly awesome. We have given it the same questions and same output structure, but with a different state of the world and different decisions. I haven’t overcomplicated the process by asking the model to become my SOC analyst 0; instead it’s just used the power of AI to help me accelerate my business decisions. ChatGPT would attempt write an incident report, create a ticket, isolate the device, burn $40k in tokens, and notify somebody on Slack, but this isn’t what most companies want. I’ve asked Jev to perform the fuzzy bit: make a semantic judgement. This output can then actually drive business decisions.
Normal software can then do the boring bit, and boring is rather lovely (and desired) when it comes to security. Imagine a world where a Jev decision greater than 90% confidence automatically creates an investigation. Perhaps 60–90% confidence rate automatically triggers a human review. Perhaps a combination of credential compromise and high severity triggers another workflow; the model provides the judgement and deterministic controls decide what that judgement is actually allowed to do.
Models like Jev are the next logical evolution in business process automation – where we start to leverage AI not to just provide a fuzzy output, but instead provide an actionable decision and output to accelerate your business. The probability percentage could drive accountability, while also retaining control. This is very important when we consider the current “rogue” nature of AI we hear in the news.
Secure, Contain, Protect.
If you’re still reading, I believe that what we are seeing here goes beyond Jev itself, but Jev is the starting point of re-taking control from the chaos of our current software landscape. AI is starting to disappear inside applications, with embedded AI being the bane of most organisations. It won’t always announce itself with a giant “Ask AI” button. Models today increasingly make tiny decisions inside APIs, workflows, agents, and applications, often without the end user even realising an AI model was involved. For security teams, that should set a few alarm bells ringing, as you are no longer in the driving seat when it comes to your applications and their output.
Today if organisations only monitor visits to ChatGPT, Claude, or Gemini, they’re going to miss a huge part of what AI adoption is becoming. You need to understand where AI is being used, which models and services your organisation is communicating with, what data is being sent to them, and what those AI-driven decisions can cause downstream.
The classifier might be back. But this time it could be buried absolutely everywhere. Your job now is to make sure you can see it, govern it, and apply controls without impacting your user experience. For this, Cato Networks can help.



