> ## Content Index
> Fetch the complete content index at: https://www.cybrsecmedia.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Agentic AI in the SOC: The Gap Between the Haves and the Have-Nots Is Already Widening
- URL: https://www.cybrsecmedia.com/agentic-ai-in-the-soc-the-gap-between-the-haves-and-the-have-nots-is-already-widening/
- Published: 2026-09-08T12:19:57.000Z
- Updated: 2026-09-08T13:29:55.000Z
- Description: Agentic AI is delivering sharper triage, faster investigations, and reduced analyst burnout at the organizations that have committed to production deployment. For everyone else, the gap is compounding, and the security implications are already visible.
- Author: George V. Hulme
- Tags: AI SOC, SOC, Article

The first wave of agentic AI applications within security operations focused on enriching alerts, reducing false positives, and absorbing the triage workload that has buried tier-one analysts for years. These efforts have produced measurable results at the organizations that have successfully deployed agentic AI. 

The problem? Most haven't. 

The market research firm Gartner estimates that only one to five  
percent of enterprises had deployed agentic AI in their security operations as of early this year. 

"We are still really early in this," said Benjamin Spencer,  
product director at cybersecurity services provider Optiv. "People are still figuring out how to do this in a way that's going to make sense." 

[Subscribe to the CYBR.SEC.Media newsletter](#/portal/signup/free)

That nascent state of agentic AI deployment in security operations  
is evident even though nearly four in five enterprises have adopted  
AI agents in some form, yet fewer than 25 percent are scaling an agentic system in production. 

For those that are, experts are citing real benefits when it comes to their cybersecurity efforts:

> **Sharper alert triage and fewer false positives**. Security leaders say agentic AI is finally cutting into the false‑positive problem that has overwhelmed SOCs for years. Caleb Sima, founding general partner at Whiterabbit and founder and chair of the CSA AI Security Alliance, noted that AI‑driven SOC tools can now "enrich detections and alerts to reduce false positives massively," and even "do the work of three or four people twenty-four-seven" at a quality comparable to senior analysts, he said. 

> **Faster investigations and response times**. Autonomous workflows are shrinking investigation times from hours to minutes. In describing his AI‑enabled SOC, Stephen Morrow, chief solution officer AirMDR said in his presentation, [Beyond the Hype, What it Really Takes to Build an AI Enabled SOC](https://www.cybrsecmedia.com/what-it-really-takes-to-build-an-ai-enabled-soc/), said they set a benchmark that "for 90% of every alert that comes in, we will fully investigate that within five minutes… fully correlated, fully enriched," and reported that they've actually achieved that in production, with remaining cases handled by humans.

> **Enterprise‑grade capabilities for smaller security teams**. Agentic AI is also being used to extend advanced SOC capabilities to organizations that can't staff large 24/7 teams. Optiv's Spencer observed that many customers are looking for workflows in which agents perform "light analysis" on threat intelligence and vulnerabilities because "the last three years have not been great for security budgets," and argued that this kind of automation "genuinely reduces the time" to handle high‑volume tasks like phishing analysis.

> **Beyond SOAR: more flexible, context‑aware automation.** Several experts frame agentic AI as delivering what SOAR (Security Orchestration, Automation, and Response) never quite did. "AI SOC has fully replaced \[SOAR\]; not only is it able to do that, but it has already done it," said Sima when contrasting brittle, hard‑coded playbooks with agents that can "reason and then make different decisions based on context," leading to playbooks that are "way more adaptive to the environment."

> **Reduced analyst burnout and a shift to higher‑value work**. AI is beginning to take over the most monotonous parts of SOC work, changing what human analysts spend their time on. Morrow says his goal is to "take the mundane, the things that we do repeatedly as SOC analysts, and automate that," training analysts not just to solve a case but to "teach the AI \[so they\] never work this case again, which he links directly to "reduced burnout" and more consistent investigations. Spencer similarly reported that his analysts are doing "a heck of a lot less… creating searches to go in there and double-check analysis," and more proactive work such as fixing systemic issues, he said.

> **Smarter exposure management and automated remediation.** In exposure management, agentic AI is being used to move beyond static CVSS scores. Terry O'Daniel, a longtime CISO and strategic security advisor to numerous startups, argued that continuous threat and exposure management (CTEM) can now be driven by agents that "just constantly test my environment… walk through how far you can actually get into my stack," providing realistic blast‑radius insight instead of just lists of bugs, O'Daniel said. 

> On remediation, he says teams are letting agents write and even open pull requests for "the dumb stuff," asking "what if, for 80% of those vulnerabilities, I could just have an agent write that code," with humans retaining review rights for higher‑risk changes, he said.

> **Improved detection engineering and coverage.** Detection engineering is emerging as a next frontier for agentic AI. Sima predicted that "the next wave that you're going to see this year and next year is going to be around detection and response, specifically detection engineering automation," and argued that most SOCs today "can't detect and respond to non‑sophisticated attacks," something he believes AI‑driven detection engineering can finally address.

> **Upstream software and AppSec gains that ease SOC pressure**. Agentic workflows are also being applied earlier in the software lifecycle, reducing downstream load on security operations. Andrew Storms, security engineering at Kilo Code, described an internal "soft agent" that drafts engineering proposals and reviews them so thoroughly that "by the time you're ready to vibe code it, it's going to do what you expect it to do." Still, it is done with guardrails such as "always check for user input" and mandatory security review triggers for risky moves.

**More on AI in the SOC:**

[SOC AI Guardrails: Control What Agents Can Touch and DoAgentic AI is closing the SOC automation gap that SOAR never did, whether the guardrails around it are explicit enough to stop a breach, survive a regulatory audit or a court case is a different question.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-88710a21-8916-4cd4-9a54-9fa3e64a5084.jpg)CYBR.SEC.MediaGeorge V. Hulme![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/2a218920-81db-474d-bba8-fe2b6579f0aa-436fbbd1-e1c8-4394-8ea8-978a7161c0f1.png)](https://www.cybrsecmedia.com/soc-ai-guardrails-how-to-define-what-agents-can-touch-and-do/)

[AI SOC Buying Guide: What CISOs Need to KnowAI-driven SOC platforms promise faster investigations, lower costs and fewer repetitive tasks for security analysts. But before CISOs buy in, they need to understand the baselines, business context, pricing and access controls. (Sponsored by Command Zero)![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-f06a8e50-21ab-4b09-bb9b-905417a5eec0.jpg)CYBR.SEC.MediaBill Brenner![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/2cd4abc7-31d9-452e-92fd-54e8a29fe56e-d72ab309-2f91-4870-b9c2-31105dab35d5.png)](https://www.cybrsecmedia.com/the-ai-soc-buying-guide-nobody-has-yet/)

[CISA’s Two SOCs Show Why AI Guardrails Need HumansCISA’s “Tale of Two SOCs” red team research shows why SOC automation, AI guardrails and human authority to contain attacks must evolve together.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-332fc331-bf88-42ec-a9d2-511dd73160f9.jpg)CYBR.SEC.MediaBill Brenner![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/406e4b0b-6209-4f4d-8429-bbcb35f95407-92f256a8-07e7-43fb-b982-989e0a91b530.png)](https://www.cybrsecmedia.com/cisas-tale-of-two-socs-shows-why-ai-guardrails-need-humans-in-the-loop/)

[AI Attacks Are Closing the SOC’s Human Oversight WindowAs attackers automate cyberattacks at machine speed, SOC teams may soon have to let AI agents act without human approval — making RBAC, business context and autonomous-response guardrails critical security controls. (Sponsored by Command Zero)![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-b40c2891-e2a5-49a6-beba-b9701b3d6d30.jpg)CYBR.SEC.MediaBill Brenner![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/0bb5d8af-8521-4443-a06f-52d51a32fc36-9b190974-4ba2-438a-90e6-73180c46157a.png)](https://www.cybrsecmedia.com/ai-attacks-are-closing-the-socs-human-in-the-loop-window/)

Wim Remes, principal consultant at Toreon, agreed and added that one of the "best things you can use AI for right now is to have it look at all your legacy code and make it make sense," with automatic documentation finally giving security teams context they never had time to write by hand.

These early deployments suggest agentic AI is less a sci‑fi SOC replacement than a force multiplier that quietly reshapes how security work gets done. By shouldering the grunt work of triage, enrichment, documentation, and routine remediation, these systems are beginning to close long‑standing gaps in coverage and capacity, especially for under‑resourced teams, while freeing human analysts to focus on harder problems that still demand judgment and context.

For security teams that haven't yet figured out how to bring agentic AI into their security operations, the experts don't paint a rosy picture: these organizations are locking in today's already‑insufficient status quo, including false-positive overload, missed straightforward attacks, and operating at a capacity deficit as attackers move faster. As AI‑driven triage and investigation become the new baseline, the laggards are likely to fall further behind, with longer dwell times, more preventable incidents, and reduced ability to adapt.

Specifically in security operations, Gartner repeatedly warned in its 2026 Hype Cycle for Security Operations report about AI washing. Those organizations that have turned their agentic AI security operations features on for evaluation and left them there have yet to reach the operational confidence or the data foundations that successful security operations deployments require. A 2026 SANS AI Survey estimated that of the 78 percent of organizations now using AI in cybersecurity, only 27 percent describe their deployments as mature production environments. The other 73 percent are somewhere between evaluation and aspiration.

That cohort that is getting agentic AI right shares several characteristics:  
They committed early, ran agents in production through failures, and built  
institutional knowledge. Still, most security programs are not positioned for agentic AI yet because they are working to put the foundations in place.

[ ![HOU.SEC.CON CTA](https://s3.us-east-1.amazonaws.com/assets.cybersecmedia.com/HSC+CTA.jpg) ](https://houstonseccon.com/?ref=cybrsecmedia.com)