TL;DR: Legacy SOC tools leave 40% of alerts uninvestigated, while agentic AI systems can triage, enrich, and act on Tier-1 cases at machine speed, according to Torq and the SACR 2025 AI SOC Market Landscape report. The governance issue is no longer whether to automate, but how to constrain autonomous action with auditability, escalation thresholds, and human authority.
NHIMG editorial — based on content published by torq: agentic AI in security operations and hyperautomation in the SOC
Questions worth separating out
Q: How should security teams implement agentic AI in SOC workflows?
A: Start with low-risk, high-volume cases such as phishing triage, then define exactly which actions the system may take autonomously and which require human approval.
Q: Why do legacy SOAR playbooks fail as alert volumes rise?
A: Legacy SOAR depends on static, hand-coded logic that works only for known scenarios.
Q: What breaks when humans are not on the loop for SOC automation?
A: Response authority becomes implicit instead of governed, which can lead to over-automation, missed escalation, or account actions that no one can easily explain after the fact.
Practitioner guidance
- Implement staged autonomy for SOC workflows Classify cases by risk and allow autonomous action only where the blast radius is bounded, the evidence path is clear, and the response can be reversed.
- Define decision rights before enabling response automation Document which actions the AI may take without approval, which require human sign-off, and which always escalate.
- Measure autonomy with operational metrics Track Tier-1 auto-resolution rate, MTTR, analyst hours saved, false positive reduction, and escalation quality.
What's in the full article
Torq's full post covers the operational detail this analysis intentionally leaves for the source:
- The platform architecture behind AI-generated workflows, including how no-code orchestration is assembled across a SOC stack.
- Step-by-step implementation guidance for moving from legacy SOAR patterns to hyperautomation in production.
- Case-study detail on outcomes such as auto-investigation rates, analyst time savings, and MTTR reduction.
- The operational framing for deploying Socrates as an agentic SOC orchestrator across Tier-1 and Tier-2 work.
👉 Read torq's analysis of agentic AI and hyperautomation in the SOC →
Agentic AI in the SOC: are human-on-the-loop controls enough?
Explore further
Agentic SOCs create a governance problem before they create an efficiency problem. The main question is no longer whether AI can process alerts faster than analysts. It is whether the organisation has defined the authority to let a system make, execute, and document security decisions on its own. That makes policy, auditability, and accountability the primary control plane, not the orchestration layer. Practitioners should treat SOC autonomy as a governance design choice, not a productivity upgrade.
A question worth separating out:
Q: What do organisations get wrong about phishing triage when AI is involved?
A: They often treat triage as a manual review problem instead of a control-design problem. If analysts must inspect large volumes of believable mail, the programme is already absorbing the attacker's scale advantage. Effective triage should prioritise behavioural scoring and high-risk workflow protection, not only inbox review.
👉 Read our full editorial: Agentic AI in the SOC is shifting from automation to autonomy