The first wave of agentic AI applications within security operations focused on enriching alerts, reducing false positives, and absorbing the triage workload that has buried tier-one analysts for years. These efforts have produced measurable results at the organizations that have successfully deployed agentic AI.
The problem? Most haven't.
The market research firm Gartner estimates that only one to five
percent of enterprises had deployed agentic AI in their security operations as of early this year.
"We are still really early in this," said Benjamin Spencer,
product director at cybersecurity services provider Optiv. "People are still figuring out how to do this in a way that's going to make sense."
That nascent state of agentic AI deployment in security operations
is evident even though nearly four in five enterprises have adopted
AI agents in some form, yet fewer than 25 percent are scaling an agentic system in production.
For those that are, experts are citing real benefits when it comes to their cybersecurity efforts:
Sharper alert triage and fewer false positives. Security leaders say agentic AI is finally cutting into the false‑positive problem that has overwhelmed SOCs for years. Caleb Sima, founding general partner at Whiterabbit and founder and chair of the CSA AI Security Alliance, noted that AI‑driven SOC tools can now "enrich detections and alerts to reduce false positives massively," and even "do the work of three or four people twenty-four-seven" at a quality comparable to senior analysts, he said.
Faster investigations and response times. Autonomous workflows are shrinking investigation times from hours to minutes. In describing his AI‑enabled SOC, Stephen Morrow, chief solution officer AirMDR said in his presentation, Beyond the Hype, What it Really Takes to Build an AI Enabled SOC, said they set a benchmark that "for 90% of every alert that comes in, we will fully investigate that within five minutes… fully correlated, fully enriched," and reported that they've actually achieved that in production, with remaining cases handled by humans.
Enterprise‑grade capabilities for smaller security teams. Agentic AI is also being used to extend advanced SOC capabilities to organizations that can't staff large 24/7 teams. Optiv's Spencer observed that many customers are looking for workflows in which agents perform "light analysis" on threat intelligence and vulnerabilities because "the last three years have not been great for security budgets," and argued that this kind of automation "genuinely reduces the time" to handle high‑volume tasks like phishing analysis.
Beyond SOAR: more flexible, context‑aware automation. Several experts frame agentic AI as delivering what SOAR (Security Orchestration, Automation, and Response) never quite did. "AI SOC has fully replaced [SOAR]; not only is it able to do that, but it has already done it," said Sima when contrasting brittle, hard‑coded playbooks with agents that can "reason and then make different decisions based on context," leading to playbooks that are "way more adaptive to the environment."
Reduced analyst burnout and a shift to higher‑value work. AI is beginning to take over the most monotonous parts of SOC work, changing what human analysts spend their time on. Morrow says his goal is to "take the mundane, the things that we do repeatedly as SOC analysts, and automate that," training analysts not just to solve a case but to "teach the AI [so they] never work this case again, which he links directly to "reduced burnout" and more consistent investigations. Spencer similarly reported that his analysts are doing "a heck of a lot less… creating searches to go in there and double-check analysis," and more proactive work such as fixing systemic issues, he said.
Smarter exposure management and automated remediation. In exposure management, agentic AI is being used to move beyond static CVSS scores. Terry O'Daniel, a longtime CISO and strategic security advisor to numerous startups, argued that continuous threat and exposure management (CTEM) can now be driven by agents that "just constantly test my environment… walk through how far you can actually get into my stack," providing realistic blast‑radius insight instead of just lists of bugs, O'Daniel said.
On remediation, he says teams are letting agents write and even open pull requests for "the dumb stuff," asking "what if, for 80% of those vulnerabilities, I could just have an agent write that code," with humans retaining review rights for higher‑risk changes, he said.
Improved detection engineering and coverage. Detection engineering is emerging as a next frontier for agentic AI. Sima predicted that "the next wave that you're going to see this year and next year is going to be around detection and response, specifically detection engineering automation," and argued that most SOCs today "can't detect and respond to non‑sophisticated attacks," something he believes AI‑driven detection engineering can finally address.
Upstream software and AppSec gains that ease SOC pressure. Agentic workflows are also being applied earlier in the software lifecycle, reducing downstream load on security operations. Andrew Storms, security engineering at Kilo Code, described an internal "soft agent" that drafts engineering proposals and reviews them so thoroughly that "by the time you're ready to vibe code it, it's going to do what you expect it to do." Still, it is done with guardrails such as "always check for user input" and mandatory security review triggers for risky moves.
More on AI in the SOC:




Wim Remes, principal consultant at Toreon, agreed and added that one of the "best things you can use AI for right now is to have it look at all your legacy code and make it make sense," with automatic documentation finally giving security teams context they never had time to write by hand.
These early deployments suggest agentic AI is less a sci‑fi SOC replacement than a force multiplier that quietly reshapes how security work gets done. By shouldering the grunt work of triage, enrichment, documentation, and routine remediation, these systems are beginning to close long‑standing gaps in coverage and capacity, especially for under‑resourced teams, while freeing human analysts to focus on harder problems that still demand judgment and context.
For security teams that haven't yet figured out how to bring agentic AI into their security operations, the experts don't paint a rosy picture: these organizations are locking in today's already‑insufficient status quo, including false-positive overload, missed straightforward attacks, and operating at a capacity deficit as attackers move faster. As AI‑driven triage and investigation become the new baseline, the laggards are likely to fall further behind, with longer dwell times, more preventable incidents, and reduced ability to adapt.
Specifically in security operations, Gartner repeatedly warned in its 2026 Hype Cycle for Security Operations report about AI washing. Those organizations that have turned their agentic AI security operations features on for evaluation and left them there have yet to reach the operational confidence or the data foundations that successful security operations deployments require. A 2026 SANS AI Survey estimated that of the 78 percent of organizations now using AI in cybersecurity, only 27 percent describe their deployments as mature production environments. The other 73 percent are somewhere between evaluation and aspiration.
That cohort that is getting agentic AI right shares several characteristics:
They committed early, ran agents in production through failures, and built
institutional knowledge. Still, most security programs are not positioned for agentic AI yet because they are working to put the foundations in place.



