| published by | Carly Page |
|---|---|
| in blog | The New Stack |
| published date | 2026-10-06 |
| original entry | How much control should AI get? Inside the SOC autonomy question |
Security operations centers have struggled with alerts for years, and AI agents offer a new way to tackle it: let machines investigate some of those alerts themselves.
That’s already starting to happen. Security teams are experimenting with AI that can pull together signals from different systems, investigate suspicious activity, and recommend next steps to humans in the loop. But moving from AI-assisted security to increasingly autonomous security creates a new problem: how much control are organizations actually prepared to hand over?
On October 8, The New Stack is hosting Running an AI-Powered SOC: How to Match AI-Speed Attacks Without Losing Control, a live session that tackles this question head-on with a candid conversation and a live platform demonstration.
REGISTER NOW FOR THIS WEBINAR
There’s an obvious appeal to AI agents in the SOC: analysts have finite time and attention, while the volume of potential threats does not come with the same constraint. Attackers are also getting access to AI tools that can accelerate parts of their own operations. Simply giving analysts better ways to work through an ever-growing queue may only get security teams so far.
There is a big difference between asking an AI agent to investigate a suspicious login and allowing it to disable the account responsible for it. The same goes for isolating an endpoint, blocking network traffic, or making other changes that could immediately impact the business. An autonomous agent could potentially make those decisions much faster and at much greater scale than a human analyst — but as recent reporting has shown, agents operating without proper guardrails can create new risks of their own.
The model is only part of the trust equation. Security teams also need to know what an agent is doing, when a human gets the final say and, crucially, whether they can undo a bad decision. That could mean putting some fairly hard limits on autonomy, including a way to shut the whole thing down if an agent goes off course. The emerging consensus across the industry is that the harness — the control layer governing what agents can and can’t do — matters as much as the agent itself.
Giving agents more responsibility also changes the role of the people working alongside them. If AI handles a large chunk of routine investigation, analysts could spend less time working through queues and more time threat hunting, making judgment calls, and overseeing the agents doing the repetitive work. The SOC analyst starts to look less like an investigator and more like an orchestrator.
Eventually, the bigger change may be to the SOC itself. “Continuous detection and response” has become familiar security language, but AI agents could make it something more literal. Instead of detection, investigation, and response being separate steps, an agent could move between them, with what it learns during one investigation feeding directly into how the next threat is detected. The infrastructure required to manage these agents at enterprise scale is already becoming its own category.
That starts to look less like AI bolted onto the existing SOC and more like a different operating model altogether. It also presents security leaders with a familiar problem: tooling. Security teams already have sprawling stacks, and vendors are racing to add agents and AI capabilities to them. Organizations risk ending up with another collection of products to manage rather than the continuous system they were promised.
On October 8 at 8:30am PT / 11:30am ET, The New Stack be sitting down with Oren Saban, co-founder and CPO of Mate Security and former Microsoft Defender XDR and Security Copilot product lead, for a candid conversation about what security leaders are actually prioritizing when it comes to AI in the SOC — and where they’re holding back. Then Zach Christensen, founding solutions engineer at Mate Security, will put those decisions into practice with a live platform demonstration: triaging an alert, building context, resolving a case, and showing exactly where the human stays in the loop.
This isn’t a slide deck walkthrough. You’ll see AI agents handle a real investigation end to end and leave with a practical framework for evaluating which of your SOC workflows are ready for agent handoff and which ones still need human control.
Register for the October 8 webinar →
Because if attackers increasingly operate at AI speed, security teams need to work out how much of the response they’re willing to hand to AI and what it actually looks like when they do.
YOUTUBE.COM/THENEWSTACK
Tech moves fast, don't miss an episode. Subscribe to our YouTube channel to stream all our podcasts, interviews, demos, and more.