TL;DR: MDR providers and AI SOC startups are converging on the same customer problem: organisations want AI to speed up security operations, but they still want humans making decisions, according to Expel. The result is likely market consolidation, because trust, not tooling labels, will determine which models survive.
At a glance
What this is: Expel argues that MDR and AI SOC are becoming one customer problem, with AI handling speed and humans retaining final judgement.
Why it matters: For IAM, NHI, and broader security teams, this matters because operational trust is shifting toward hybrid models that still need clear identity, access, and decision accountability.
👉 Read Expel's analysis of the MDR and AI SOC market convergence
Context
MDR and AI SOC are often discussed as separate categories, but the operational question is the same: how much security work should be automated, and where must human judgement remain in the loop? In practice, security teams are not buying labels, they are buying response quality, trust, and a workable operating model for detection and triage.
That tension matters because security operations already rely on identity-driven controls for analysts, tooling, and automation accounts. As AI takes on more investigation and enrichment work, IAM, PAM, and governance teams have to think about who or what is authorised to act, approve, and escalate inside the SOC.
The market dynamic described in the source is typical of a broader platform cycle. Consolidation follows expansion, but specialist capability still reappears when platform coverage lags the threat environment.
Key questions
Q: How should security teams govern AI-assisted actions in the SOC?
A: Security teams should treat AI-assisted SOC actions as policy-governed machine behavior, not informal automation. Define which tools the system may access, which actions require approval, and what must be logged for later review. The goal is to keep investigation speed while preserving human accountability and least privilege across prompts, queries, and remediation steps.
Q: Why do MDR and AI SOC categories keep converging?
A: They converge because customers want the same outcome: faster triage, better prioritisation, and fewer missed incidents. The label matters less than whether the service combines effective automation with accountable human judgement. As a result, vendors are competing inside one operating model rather than two separate markets.
Q: What breaks when SOC teams automate without identity visibility?
A: When SOC teams automate without identity visibility, they lose context about which identities moved, what privileges changed, and whether an access path was legitimate. AI may still prioritise alerts, but it cannot reliably distinguish benign activity from attacker movement. The result is faster triage built on incomplete evidence.
Q: Should teams keep best-of-breed tools or consolidate around a platform?
A: Most teams will need a hybrid answer. Consolidation reduces operational overhead, but specialist tools still matter when platforms lag new threat patterns or complex identity-driven workflows. The right test is whether the stack can maintain coverage, accountability, and response speed without creating blind spots.
Technical breakdown
Why MDR and AI SOC are converging
MDR and AI SOC sit on the same workflow: ingest alerts, enrich context, prioritise events, and decide what gets escalated. The difference is not the problem they solve, but the operating mix they use. MDR usually packages human-led investigation with tooling, while AI SOC pushes more triage and summarisation into automation. In both cases, the real constraint is decision confidence, not raw alert volume. If the system cannot explain why it reached a conclusion, analysts still end up rechecking the work.
Practical implication: measure SOC automation by decision quality and analyst time saved, not by the number of AI features deployed.
Human-in-the-loop security operations and accountability
Human-in-the-loop security operations means AI can assist with detection, enrichment, and recommendation, but a person retains responsibility for final action on high-impact cases. That matters because SOC actions often affect production systems, credentials, and access paths. The control problem is therefore not just technical accuracy, but accountability. When automation can trigger containment, account disablement, or playbook execution, identity controls on analyst accounts and automation service identities become part of operational risk management.
Practical implication: separate advisory automation from action-taking automation and govern each with distinct approval and access boundaries.
Platformization, best-of-breed, and security operations drift
Platformization consolidates tools into fewer vendors, but security operations drift happens when a platform lags new attack techniques or response workflows. Teams then patch coverage with point tools or specialist services, which is why best-of-breed keeps returning. The pattern is cyclical: consolidation reduces complexity until capability gaps reappear. In SOC terms, the issue is not ideology, it is whether the control stack can keep pace with changes in attacker behaviour, telemetry volume, and response expectations.
Practical implication: reassess platform coverage whenever new attack paths or new identity-heavy workflows create blind spots in detection or response.
NHI Mgmt Group analysis
MDR and AI SOC are converging because customers buy outcomes, not category labels. Security leaders do not care whether triage is branded as MDR or AI SOC if it reduces dwell time and improves containment decisions. The market will consolidate around operating models that combine machine speed with human accountability. Practitioners should evaluate providers on decision quality, escalation logic, and response governance, not on how neatly they fit a marketing category.
The named concept here is decision-trust compression. As AI accelerates SOC workflows, the time between signal, judgement, and action shrinks, which increases the value of clear accountability chains. That creates pressure on IAM and PAM controls for analyst access, automation privileges, and break-glass workflows. Teams should treat SOC identity governance as part of response quality, not as a back-office admin task.
Platform consolidation will keep happening, but it will not eliminate specialist demand. When general-purpose platforms cannot absorb new telemetry, identity-heavy attack paths, or AI-assisted investigation patterns fast enough, specialist vendors reappear. That is not a failure of consolidation, it is a sign that attack evolution outpaces integration cycles. Practitioners should expect hybrid stacks to persist and plan governance accordingly.
AI in security operations increases the importance of provenance and approval boundaries. Once AI starts summarising incidents or recommending containment, teams need to know which actions were machine-generated, which were analyst-approved, and which were executed automatically. This is where governance meets operational resilience. Practitioners should insist on auditable human decision points before any high-impact response.
The market signal is clear: security operations are moving toward managed autonomy, not full automation. Organisations want AI to multiply analyst capacity, but they are not ready to delegate final judgement entirely to machines. That makes the governance model more important than the category name. Practitioners should design for supervised automation with explicit identity and privilege controls.
What this signals
The next pressure point for security programmes is not whether AI appears in operations, but whether governance can keep pace with machine-assisted decisions. Decision-trust compression: as response cycles shorten, IAM and PAM teams need auditable approval chains for analysts, SOAR actions, and any AI-assisted containment path.
For identity teams, the lesson is that operational automation still depends on identity hygiene. If access paths for analysts, service accounts, and orchestration tools are not separated, AI simply amplifies existing governance weaknesses. That is why identity controls for operations should be reviewed alongside SOC tooling changes, not after them.
The market will continue to reward hybrid models that combine automation with human accountability, but programme owners should expect more scrutiny of who approved what, when, and under which privilege boundary. The tighter the loop, the more important provenance becomes for compliance and incident review.
For practitioners
- Define decision boundaries for AI-assisted SOC workflows Classify which actions remain advisory, which require analyst approval, and which can execute automatically. Tie those boundaries to specific response types such as isolation, account disablement, or case closure, then review them alongside IAM and PAM controls for analyst and automation identities.
- Separate identities for analysts and automation Use distinct accounts, privileges, and logging for human analysts, SOAR playbooks, and AI-driven tooling. That separation makes it possible to prove who approved a response and prevents automation from inheriting broader access than its task requires.
- Measure SOC value by containment quality Track the speed, accuracy, and reversibility of AI-assisted decisions rather than the number of alerts processed. Include rework rates, false containment actions, and analyst override frequency so you can see whether automation is improving outcomes or simply accelerating noise.
- Reassess platform coverage when specialist gaps appear Review whether your current stack still covers new identity-heavy attack paths, AI-assisted investigation needs, and response workflows. If not, decide whether to extend the platform, add a specialist control, or keep a hybrid model with clear governance.
Key takeaways
- MDR and AI SOC are collapsing into one operational question about speed, trust, and accountability.
- The enduring constraint is not tooling alone, but whether human approval and identity governance remain clear as automation expands.
- Security teams should judge these offerings by decision quality, auditability, and containment outcomes rather than by category labels.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Access control governance matters as SOC automation expands. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is central when AI and analysts share operational tooling. |
| CIS Controls v8 | CIS-6 , Access Control Management | SOC identity and privilege boundaries depend on disciplined access management. |
| ISO/IEC 27001:2022 | A.5.15 | Access control policy is relevant to human-in-the-loop security operations. |
| MITRE ATT&CK | TA0003 , Persistence; TA0006 , Credential Access | SOC compromise often starts with credential abuse and privilege misuse. |
Use ATT&CK to test whether automation and analyst access paths increase credential exposure.
Key terms
- Human-in-the-loop security operations: A security operations model where AI assists with triage, enrichment, or recommendation, but a person remains responsible for high-impact decisions. The model aims to improve speed without surrendering accountability, especially where containment or access changes can affect production systems.
- Decision-trust compression: The shrinking time between detection, judgement, and action as automation takes on more of the SOC workflow. It increases the need for clear approval boundaries, auditability, and identity governance because speed alone does not prove a decision was trustworthy.
- Platformization: The process of expanding a product into a broader integrated platform with shared data, logic, and workflows. In security terms, platformization concentrates authority and integrations, which can improve visibility but also increase the blast radius of a compromised credential or over-scoped role.
What's in the full article
Expel's full article covers the market discussion and analyst context this post intentionally leaves for the source:
- The full conversation on how MDR providers are adding AI capabilities while AI SOC vendors hire human analysts to backstop automation.
- Direct quotes from Expel leaders on the customer trust problem that shapes security operations buying decisions.
- The analyst framing behind the Gartner MDR timing and the broader market consolidation thesis.
- The practical discussion of how security teams are balancing platform consolidation against specialist coverage needs.
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, IAM, and secrets management for practitioners who need a stronger control foundation. It helps security teams connect identity governance to the operational systems that depend on it.
Published by the NHIMG editorial team on August 18, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org