There has been growing pressure in both the public and private sectors to adopt AI-based tools in workflows, and the Security Operations Center (SOC) has been no exception. Enterprise security teams are increasingly expected to deploy AI to improve speed and efficiency, yet doing so introduces uncertainty about how these systems will behave in real-world environments. To test the efficacy of AI in a security environment, two cybersecurity leaders overseeing large-scale enterprise environments decided to initiate six-month trials of AI deployment in the SOC. These leaders, Ankit Gupta and Shilpi Mittal, who oversee cybersecurity for a major food manufacturing firm and a major financial company respectively, presented their findings at the RSAC 2026 conference in San Francisco this week under the title “We Put AI in Our SOC — Here’s What Worked and What Didn’t.”
During the pilot study, Mittal deployed an LLM-powered tool as a “read-only triage assistant,” intended to collate data from multiple sources and perform rapid analysis based on rules assigned to it. In that sense, it operated similarly to any algorithmic filter utilized in SOC assessment, only with greater agency. Mittal gave a specific instance of the AI tool autonomously detecting a suspicious file and initiating automatic quarantine, demonstrating proactive threat prevention. Their findings suggest that AI performs well when handling clearly defined, repetitive tasks such as alert triage and basic investigation workflows. In these contexts, AI can significantly reduce analyst workload and accelerate response times by processing large volumes of data more quickly than human operators. Specifically, the use of the AI tools significantly improved the SOC team’s mean time to discovery (MTD) and mean time to response (MTTR). This makes it a useful augmentation tool, particularly in environments where alert fatigue and staffing shortages are persistent challenges.
However, the systems were not without their drawbacks. While AI is capable of assisting humans, Gupta found that AI was totally incapable of operating in an autonomous capacity in a SOC environment. “SOC reality is messy — alerts arrive with incomplete fields, inconsistent identifiers, and ambiguous signals,” Gupta explains, adding, “AI incorrectly removed users from the system.” In such situations, where the data is not standardized and cannot be algorithmically processed, tasks such as nuanced threat analysis, incident correlation across disparate systems, and strategic decision-making will remain difficult for current AI implementations. In these situations, AI may produce incomplete or misleading conclusions, requiring human analysts to step in and validate outputs. This limitation underscores that AI is not yet capable of replacing experienced analysts in higher-order investigative functions.
Another key issue identified is the risk associated with overreliance on AI-generated outputs. The researchers observed that analysts may begin to trust AI recommendations without sufficient scrutiny, potentially allowing errors to propagate through the investigation process. This introduces new operational risks, particularly if AI systems generate false positives or overlook subtle indicators of compromise. As a result, maintaining human oversight and implementing validation mechanisms is critical to prevent automation from introducing additional vulnerabilities into SOC workflows. The overall conclusion of the study suggests that while AI can enhance SOC efficiency, it is not a comprehensive solution and should be deployed cautiously. Organizations must clearly define where AI adds value and where human expertise remains essential, ensuring that automation complements rather than replaces analysts.