By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: Horizons.aiPublished July 16, 2026

TL;DR: The 2026 SANS SOC Survey finds 79% of organisations using AI or machine learning, yet only 36% have integrated it into defined SOC workflows, while 24% of cyber leaders still name enterprise-wide visibility as their biggest barrier, according to Horizons.ai. The gap between adoption, workflow design, and measurable outcomes is now the central SOC governance problem.


At a glance

What this is: This is a research summary of the 2026 SANS SOC Survey, which finds AI adoption in security operations is far ahead of workflow integration and visibility maturity.

Why it matters: It matters because SOC leaders, IAM teams, and security architects need operational controls, not just tooling uptake, to keep AI-assisted detection, access, and response accountable.

By the numbers:

👉 Read Horizons.ai's 2026 SANS SOC Survey insights on AI, visibility, and SOC maturity


Context

AI adoption in the SOC is no longer the issue. The governance gap is whether that adoption is actually embedded into repeatable workflows, measurable decisions, and accountable response paths. In practice, many programmes add AI to existing processes without redesigning how detection, triage, and escalation are authorised or audited.

That matters for identity as much as for operations. SOC tooling increasingly touches privileged analyst access, service account use, automation tokens, and machine-driven response, so weak workflow integration can become an IAM and PAM problem as well as an operations problem.


Key questions

Q: How should security teams govern AI-assisted actions in the SOC?

A: Security teams should treat AI-assisted SOC actions as policy-governed machine behavior, not informal automation. Define which tools the system may access, which actions require approval, and what must be logged for later review. The goal is to keep investigation speed while preserving human accountability and least privilege across prompts, queries, and remediation steps.

Q: Why does visibility matter so much for SOC effectiveness?

A: Because the SOC cannot defend what it cannot see across identities, assets, telemetry, and response automation. Visibility is what lets teams separate real incidents from noise, confirm which identity performed an action, and decide whether the control worked. Without it, AI simply accelerates confusion.

Q: What do security teams get wrong about GenAI in the SOC?

A: They often assume the model reduces the need for analyst judgment. In practice, GenAI reduces reading and writing time, but the analyst still owns interpretation, prioritisation, and escalation. If the team uses the model to replace verification, it will amplify mistakes instead of reducing workload.

Q: How do you measure whether causal AI is improving SOC outcomes?

A: Use metrics that show whether the team is finding the true root cause faster, choosing better interventions, and avoiding unnecessary response actions. Mean time to causal discovery and intervention efficacy are more useful than raw alert counts because they evaluate decision quality, not just activity volume.


Technical breakdown

Why AI adoption without workflow integration fails in the SOC

AI in the SOC only creates value when it is wired into defined workflows, decision thresholds, and audit trails. If analysts use AI tools informally, the programme may gain speed but lose repeatability, making it hard to prove what changed, who approved it, or whether a machine-assisted decision was reliable. This is a governance problem, not just a tooling problem. It also affects identity controls when automation uses shared credentials or privileged access paths that are not separately governed.

Practical implication: tie AI-assisted actions to approved workflows, named owners, and auditable identity controls before scaling use cases.

Enterprise-wide visibility and the control plane problem

Visibility in SOC terms means seeing across logs, endpoints, cloud workloads, identities, and response automation well enough to correlate evidence and act on it. The main failure mode is fragmented control planes. When teams cannot see which identities, tokens, or automations are active, they cannot reliably distinguish signal from noise or determine whether a response action is safe. This becomes more acute as AI systems generate summaries, recommendations, and even actions that depend on broad telemetry access.

Practical implication: map data, identity, and response visibility into one operational view before introducing more AI-driven triage.

Why practitioner and leadership views diverge on SOC effectiveness

The survey shows a common pattern in security programmes: leadership often measures confidence, while practitioners experience operational friction. That gap usually reflects different reference points. Executives see investment and intent; operators see missing coverage, poor workflow fit, and manual workarounds. In an AI-enabled SOC, that divergence can hide real risk because a tool that looks deployed may still be under-governed in practice. The programme may be active, but not integrated.

Practical implication: measure SOC effectiveness using workflow completion, detection coverage, and response quality instead of confidence surveys alone.


NHI Mgmt Group analysis

AI adoption without workflow governance creates security theatre. When organisations count AI usage but do not embed it into defined SOC processes, they confuse presence with control. The result is a tooling layer that looks modern but cannot support consistent triage, escalation, or evidence handling. For practitioners, the question is not whether AI is present, but whether it is operationally governed.

Visibility debt is now a first-order SOC risk. If 24% of leaders still see enterprise-wide visibility as the main barrier, the underlying issue is that SOCs are operating with incomplete control-plane awareness. That weakness affects detection, but it also affects identity governance because privileged analyst access, automation accounts, and response tokens all depend on trustworthy visibility. Practitioners should treat visibility as a prerequisite control, not a reporting metric.

The modern SOC problem is increasingly an identity problem. As AI systems help drive triage and response, the identities behind automation matter more than the feature set itself. Shared credentials, unmanaged tokens, and poorly scoped machine access turn operational efficiency into latent privilege risk. Practitioners should evaluate SOC AI through the lens of IAM, PAM, and machine identity governance.

Defined workflows are the missing control boundary for AI-assisted operations. The survey’s split between broad AI usage and limited workflow integration shows that many SOCs have adopted capability without adopting control boundaries. That creates inconsistent response paths and weak accountability. Practitioners should insist that every AI-assisted SOC use case has a named owner, a decision rule, and an audit trail.

Security leaders should stop treating SOC maturity as a volume problem. Incident counts alone do not tell you whether the SOC is effective, especially when AI is compressing detection and response timelines. The right question is whether the organisation can detect, decide, and act consistently across identities, assets, and automation. Practitioners should shift programme oversight toward measurable operational outcomes.

What this signals

Workflow integration will become the real SOC maturity marker. As AI usage rises, boards and security leaders will increasingly ask whether AI is embedded in repeatable response paths or just layered on top of existing work. That shift aligns with a broader governance trend, where operational control matters more than adoption headlines. Teams that cannot show workflow-level accountability will struggle to defend their SOC maturity claims.

Identity governance now extends into security operations tooling. Once AI influences triage or response, the identities behind automation become part of the control surface. That means service accounts, tokens, and analyst privileges need the same scrutiny traditionally reserved for production access paths. For teams looking to align with broader control frameworks, NIST SP 800-53 Rev 5 Security and Privacy Controls remains a useful reference point for access control, auditability, and configuration discipline.

Visibility debt is likely to widen before it narrows. Organisations adding AI to the SOC without rationalising telemetry, identity, and response data will create more operational ambiguity, not less. The practical signal is whether leaders can trace a machine-assisted decision back to a specific workflow, identity, and evidence set. If not, the SOC is scaling complexity faster than control.


For practitioners

  • Define AI-assisted SOC workflows explicitly Document which triage, enrichment, escalation, and response steps AI may support, and require named approval points for any machine-generated recommendation or action.
  • Map identity controls to SOC automation Inventory every service account, API token, and privileged role used by detection and response tooling, then scope each one to a single workflow boundary.
  • Unify visibility across logs and identities Correlate telemetry from endpoints, cloud, IAM, and response platforms so analysts can see which identities acted, what triggered the action, and whether the action was authorised.

Key takeaways

  • The survey shows AI adoption in the SOC is ahead of workflow integration, which leaves control and accountability behind.
  • Visibility remains the core operational constraint because SOC teams cannot govern what they cannot correlate across identities, assets, and response automation.
  • The next SOC maturity step is not more AI, but more disciplined workflow design, identity governance, and measurable response outcomes.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0DE.CM-1Continuous monitoring and visibility are central to the SOC maturity gap discussed here.
NIST SP 800-53 Rev 5AU-6AI-assisted SOC workflows need reviewable event analysis and traceable decision records.
CIS Controls v8CIS-8 , Audit Log ManagementThe article’s visibility problem maps directly to log collection and review discipline.
ISO/IEC 27001:2022A.8.15Logging and monitoring controls underpin the visibility challenge highlighted by the survey.

Use DE.CM-1 to assess whether SOC telemetry actually covers identities, assets, and response actions.


Key terms

  • SOC Workflow Integration: SOC workflow integration is the process of embedding tools, automation, and analyst tasks into defined operational steps with clear ownership and auditability. It matters because AI can increase speed without improving control unless the workflow shows who approved, reviewed, and executed each action.
  • Enterprise-wide Visibility: Enterprise-wide visibility is the ability to correlate signals across identities, endpoints, cloud workloads, and response systems in one operational view. In security operations, it is the difference between isolated alerts and an evidence-based picture of what actually happened, who acted, and whether the response was safe.
  • AI-assisted Response: AI-assisted response is the use of machine-generated recommendations or automated actions to help containment, triage, or remediation. It is only safe when the organisation defines the permitted actions, the evidence required, and the identity controls that govern the automation path.

What's in the full report

Horizons.ai's full whitepaper covers the operational detail this post intentionally leaves for the source:

  • Survey segmentation across 444 practitioners and 69 cyber leaders, useful for comparing how different roles view SOC maturity.
  • The report's full breakdown of where executives and practitioners disagree on staffing, visibility, and investment priorities.
  • Practical recommendations from SANS on how leading SOCs structure AI use, threat intelligence, and technology investment.
  • The survey's complete benchmark data for organisations measuring themselves against peer SOC operating models.

👉 Horizons.ai's full whitepaper includes the benchmark detail and practitioner recommendations behind the findings.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps practitioners connect identity control to broader security operations and governance programmes.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 1, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org