
Source: S&P Global Media Portal via S&P Global.
Attackers need only one weakness to gain entry to critical systems, whereas defenders must focus on protecting the highest-value assets. Already-thin security operations center teams are losing the battle against AI-powered attackers, which now need AI-powered defenses, creating a prime use case for agentic AI in the organization: accelerating threat detection and response. Today, organizations have a dizzying array of choices.
The Take
Cybersecurity remains an asymmetric challenge. Attackers can focus on narrow objectives and require only a single weakness to compromise systems, while defenders must protect high-value assets across an expanding attack surface. Security teams are constrained by limited staffing and specialized expertise, and these constraints are amplified by increasing alert volumes and attacker sophistication. Adversaries are rapidly adopting AI to accelerate reconnaissance and exploitation activities, forcing organizations to respond by deploying AI-driven approaches to threat detection and response, as manual processes alone are no longer sufficient to keep pace.
Context
A survey conducted by 451 Research by S&P Global illustrate the scale of alert overload. In 2020, respondents reported being unable to investigate 37% of daily security alerts. That figure increased steadily through 2023, when it exceeded half of alerts (54%). Although 2024 showed a temporary decline to 43%, the proportion rose again in 2025 to 45%.
In 2025, nearly one-fifth of respondents reported being unable to investigate more than 75% of alerts.
Respondents commonly attribute this challenge to rising volumes of low-fidelity alerts and limitations in legacy security tooling. Generative and agentic AI are increasingly positioned as mechanisms to address these constraints, although questions remain around organizational readiness, acceptable automation levels and cost.

The rapidly advancing state of intelligent SOC automation
Not long after GenAI’s advent in late 2022, chat-oriented security “chatbots,” “co-pilots” and “assistants” were launched, seeking to apply insight at scale to the increasing volume of threat data and accelerate security operations (SecOps) processes. And if that wasn’t enough, the next major AI advance emerged in 2025 — extending GenAI by adding the capability to reason, reach independent decisions, use tools, and take actions in response to inputs and findings. This is “agentic AI,” empowering the substantial gains of GenAI with agency and the ability to act. Not surprisingly, many well-funded startups have emerged. Early market messaging emphasized fully autonomous security operations centers (SOCs), but buyer caution has shifted emphasis toward “human in the loop” deployment models. At the same time, distinctions between assistant-based and agentic functionality are narrowing as vendors increasingly integrate agentic capabilities directly into their core platforms. Even so, SOC AI use cases fall into two categories: analyst-assistive and agentic.
Chatbot/assistant/co-pilot use cases
- Natural language query/SIEM search: Analysts describe what they’re looking for in natural language, and AI translates it into complex query languages like KQL, SPL and Yara-L and executes the search. Results can be interpreted and correlated with other security signals, saving research time.
- Alert summarization and contextualization: Analysts open an alert and have AI summarize it; the assistant pulls in related signals, enriches it with threat intelligence and other sources, and produces a plain language explanation of what happened and the risks involved. This reduces initial analysis time and the requirement to pivot between multiple tools, while keeping human analysts clearly in the center of the investigation.
- Incident timeline reconstruction: Analysts ask the AI assistant to reconstruct an attack chain, which correlates events across endpoints, applications, networks, identity logs, etc., creating a coherent, natural language and chronological narrative that could take hours if attempted manually.
- Security reporting and summaries: AI automatically creates incident summaries, executive briefings and compliance reports tailored to the audience (e.g., executives, technical staff, legal, etc.).
- Guided incident response: The AI assistant provides potential next steps, which the analyst then executes either manually or by approving AI actions.
- Upskilling and on-the-job training: Junior analysts interact with the AI assistant to get explanations of complex topics or signals that they don’t recognize, using the AI as a senior-level mentor during live investigations. This is a highly practical application of AI assistants, given the current security skills shortages and need to quickly upskill junior staff without burdening senior resources.
Agentic AI use cases
While the agentic AI market is still relatively new, several key SOC use cases have emerged:
- Alert triage and noise reduction: This aims to solve one of the most pressing problems in the SOC today: high alert quantities. Agentic AI continuously scores, filters, clusters and escalates alerts with (or without) human prompting, freeing humans to focus on higher-priority incidents and proactive tasks.
- Autonomous incident investigation: Agents gather evidence, correlate signals across systems, build attack timelines and render a verdict, reducing long, manual investigations from hours to a few minutes. Humans can then pick up the investigation.
- Automated incident response and investigation: Agents take containment actions, such as isolating endpoints, blocking malicious IPs, revoking credentials or disabling accounts based on investigation outcomes — either autonomously or with human approval. Existing SOAR (security, orchestration, automation and response) workbooks and workflows can be used to train the agents in organizational best practices.
- Malware and script analysis: Agents autonomously reverse-engineer suspected malicious files and obfuscated scripts, producing human-readable summaries without requiring senior-level analysts.
- Threat hunting: Agents proactively search organizational environments for indicators of compromise, suspicious behavioral patterns and attacker TTPs (tactics, techniques and procedures), and even correlate dark web data, finding potential issues before an alert is created.
- Phishing and business email compromise detection: Agents autonomously scan and triage emails, detonating links and attachments in sandboxes, assessing potential user impacts and initiating response actions like quarantining messages.
- Vulnerability prioritization and exposure management: Agents analyze vulnerability scan results, correlating them with real-world exploitation data and internal security signals, prioritizing patching and remediation actions by actual risk.
Agentic models and workflow design
Agentic models are typically implemented as task-focused agents rather than monolithic platforms. This modular approach reduces agent training requirements and allows agents to be combined into sequential or parallel workflows. Some workflows rely on “chained agents” that pass outputs downstream, while others use multiple agents operating concurrently to analyze the same environment from different perspectives.
As workflow complexity increases, supervisory agents may be engaged to oversee more involved processes or to engage additional agents or workflows as needed in more comprehensive task sets. We expect to see patterns emerge in SecOps that clarify where the elaboration of agentic workflows yields the greatest benefit. In more than a few cases, we expect providers to shield users from unnecessary complexity, giving them insight into overall progress and steps toward results as needed to meet their requirements for visibility and human engagement, as well as action.
We expect to see such innovations combined with other advances in process and workflow automation for security, taking advantage of achievements in robotic process automation and engaging emerging disciplines such as detection engineering in SecOps where appropriate. This larger trend is often referred to as “hyper-automation,” applied as an overall term to highlight how advances in intelligent security automation are changing the nature of SecOps tech.
AI readiness, organizational maturity and cost remain key roadblocks
Despite the high interest in SOC automation, many organizations are not ready to implement complex AI on their own due to a lack of skill, budget or technical readiness. A separate study conducted by 451 Research shows that about half of AI projects in the proof-of-concept stage are abandoned before production, driving demand for vendor- or service-provider-led implementations. Cost uncertainty remains a major barrier. Few organizations can quantify the cost of advanced AI and worry about cost overruns. Vendors providing AI SOC solutions and services are in an equally intractable situation, as many have expressed a lack of visibility into the long-term cost. This creates pricing pressure as many intentionally subsidize their offerings to encourage adoption.
There is also a tradeoff to be considered with autonomous automation: Organizations must relinquish some level of control for this to function effectively. Agentic technology dynamically produces and executes a plan given the information with which it has been equipped, requiring leaps of faith to fully automate these systems. We expect this to be an iterative process, beginning with simple automation and progressing as trust is established.
This highlights the human role of guidance and influence over agentic actions. Regulations such as data privacy, for example, may require the need to audit, review and validate agentic functionality in ways that AI may not be equipped to incorporate without human involvement. Even when agentic or “hyper-automated” functionality can adapt to such new or emerging situations, it may still take unnecessary steps in processes that humans can identify and optimize. What organizations realize in return should, in the aggregate, be outcomes that are at least directionally correct — and they will generate future knowledge that the organization will retain.
We expect intelligence and agentic SOC automation to significantly influence SecOps technology evolution in 2026 and beyond. We will be covering these trends in detail this year, researching specific technology and service-provider offerings as they develop.
Want insights on Infosec trends delivered to your inbox? Join the 451 Alliance.

