TL;DR: AI-assisted phishing attacks have surged 1,265% and AI-generated emails now achieve a 54% click-through rate, while organisations using AI and automation extensively cut breach costs by $1.9 million and shortened breach lifecycles by 80 days, according to Torq and IBM. The security value has moved from summarisation to governed execution, because the real operational gap is not insight but action.
NHIMG editorial — based on content published by torq: Generative AI in cybersecurity and the move toward an AI SOC
By the numbers:
- AI-generated phishing emails now achieve a 54% click-through rate.
- Organizations that extensively use AI and automation saved an average of $1.9 million per breach and reduced their breach lifecycle by 80 days.
Questions worth separating out
Q: How should security teams govern AI-assisted actions in the SOC?
A: Security teams should treat AI-assisted SOC actions as policy-governed machine behavior, not informal automation.
Q: Why do AI phishing attacks create more risk than traditional phishing?
A: AI lowers the cost, time, and skill needed to produce personalised lures, so attackers can run more campaigns and iterate faster.
Q: What breaks when generative AI is allowed to execute security actions without governance?
A: The organisation loses traceability, consistent decision boundaries, and clear accountability for remediation steps.
Practitioner guidance
- Implement governed tool access for AI workflows Restrict which systems an AI SOC workflow can query, modify, or remediate.
- Require human-on-the-loop approval for high-impact actions Define which response steps may run automatically and which must pause for analyst confirmation, especially quarantine, account disablement, ticket closure, and external notifications.
- Harden phishing workflows with identity-aware verification Treat suspicious requests as an identity validation problem as well as a content problem.
What's in the full article
Torq's full article covers the operational detail this post intentionally leaves for the source:
- Step-by-step SOC workflow examples for AI-assisted triage and response
- Specific guidance on where agentic AI differs from generative AI in operational execution
- Implementation detail on human-on-the-loop controls and auditability
- Torq's own architecture framing for AI SOC orchestration and case handling
👉 Read Torq's analysis of generative AI, agentic AI, and the AI SOC →
Generative AI in the SOC: what changes when execution becomes automated?
Explore further
Generative AI has become a force multiplier for identity abuse, not just a content engine. The article correctly shows that attackers are using AI to make phishing more convincing and faster to deploy. The governance lesson is that identity verification controls are being tested at the point where human judgment meets synthetic persuasion, which creates a boundary problem for IAM, fraud, and SOC teams. Practitioners should treat AI-assisted social engineering as an identity assurance issue, not only an email security issue.
A question worth separating out:
Q: What should organisations test before adopting agentic AI in security operations?
A: Organisations should test whether the agent can act safely under failure, whether its actions are traceable, and whether an incorrect decision can be rolled back. The key question is not only what the agent can do, but what happens when upstream telemetry is wrong or incomplete. Without that test, automation can spread error faster than humans can correct it.
👉 Read our full editorial: Generative AI is shifting cybersecurity from summaries to execution