Today’s security operations center (SOC) teams are dealing with threats where the window to detect and stop an attack is less than half a minute, faster than human analysts can realistically work. At the same time, AI is compressing the time and expertise required to launch sophisticated attacks. Tasks that once required specialized operators can now be automated or accomplished in seconds.
In this reality, security operations cannot rely solely on humans to defend against AI-powered attacks. The modern SOC will need to evolve to a hybrid model where humans and AI systems work together to detect, analyze, and remediate issues at the speed of these attacks.
Why the SOC Was Broken Long Before AI
The traditional SOC model already had its challenges before AI accelerated the threat landscape. Enterprise SOCs receive hundreds of thousands of alerts annually, and human analysts cannot realistically investigate all of them, forcing organizations to aggressively prioritize threats based on severity scores. This often means a large volume of informational or low-severity alerts is dismissed by Tier 1.
But severity doesn’t always equal risk. Our research has found that around 1% of incidents began as low-severity or informational alerts that were dismissed. For an organization generating half a million alerts annually, that equates to roughly one real threat per week that slipped through unnoticed.
For years, organizations accepted that a large percentage of alerts would never be investigated because there was no financially viable alternative. AI changes that assumption, allowing us to finally redefine acceptable risk.
How AI Is Being Incorporated Into the SOC
AI is reducing the need for traditional Tier 1 operations by automating much of the repetitive triage work that those analysts historically handled manually. In our customer environments that have implemented AI in their SOC, an average of 2% of the original alert volume was escalated by AI for human review.
AI systems can add context and correlate behavior across signals to determine whether a low-severity alert should be flagged for a Tier 2 or 3 analyst. The ability to connect alerts in this way is key because modern attacks don’t often reveal themselves through a single high-severity alert; instead, they are a culmination of multiple low-severity activities across endpoints, cloud infrastructure, identities, and networks over time. A failed login attempt isn’t necessarily malicious, but it becomes more suspicious if it is also tied to a privilege change or an unusual login location.
This problem is becoming even more pressing as AI models like Anthropic’s Mythos are being developed. Mythos has been shown to chain multiple vulnerabilities together to create more impactful attacks.
Since Mythos was first announced, Anthropic revealed preliminary results from a small number of partners that were granted access. Collectively, they’ve found over 10,000 high- or critical-severity vulnerabilities, and several have said their bug-finding rate improved by more than 10x.
Even though Mythos isn’t currently broadly publicly available, soon after its announcement, there was a report of unauthorized access. OpenAI also announced a similarly capable model called Daybreak, which it released to a much larger subset of companies and researchers than Anthropic did with its model. Anthropic is now also allowing vetted customers to request access to Mythos Preview, which was initially invite-only.
Given these developments, it’s not outside the realm of possibility that an attacker could gain access to these models, or that another AI company could develop and publicly release a model like these down the line, potentially giving bad actors easy access to powerful capabilities.
The capabilities being developed today, combined with the existing problems with SOC triage, prove the urgency of shifting to an AI SOC model.
The Role of Cybersecurity Professionals in the AI SOC
In the AI SOC model, AI collects evidence, investigates, analyzes, correlates, and reasons through the process, while human analysts supervise the outcomes.
AI isn’t going to fully take over the SOC anytime soon. Humans still need to be in the picture, defining risk appetite, providing high-level guidance, and overseeing the autonomous infrastructure. Rather, the addition of AI to security operations will allow human analysts to expand their roles and take on more meaningful work. They’ll be there to steer the AI in the right direction, while having more time to strategize and think instead of grinding through tickets all day long.
Humans are much better suited for strategic thinking than they are for continuously reviewing millions of repetitive signals across disconnected systems, exactly the type of work that AI excels at.
This evolution should ultimately improve both security outcomes and analyst burnout. Today, many SOC teams spend enormous amounts of time performing repetitive triage work that provides little opportunity for growth or strategic thinking. AI allows humans to spend less time on work better suited for AI and more time on deep-thinking work necessary to improve the organization’s security posture.
The Human-Only SOC Is Over
The transition to the AI SOC isn’t happening because it’s trendy, but because it has to. The future SOC will still need people, but the scale, speed, and complexity of today’s attacks also require AI systems capable of continuously investigating, reasoning across signals, and operating at the same speed as AI attackers.
The organizations that adapt will not just respond faster, but will fundamentally reduce the amount of risk they are forced to ignore.