Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI in the SOC: are trust and control keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: A survey of 450 CISOs and cybersecurity leaders found that nearly four in five organisations now use AI in their SOCs, yet 97% trust it to analyse alerts while only 35% use it for triage, according to Torq's 2026 AI SOC Leadership Report. The real constraint is not model capability but explainability, governance, and controllable autonomy.

NHIMG editorial — based on content published by torq: 2026 AI SOC Leadership Report

By the numbers:

Questions worth separating out

Q: How should security teams use AI in the SOC without losing human control?

A: Use AI to remove repetitive work, enrich alerts, and accelerate triage, but keep humans accountable for escalation, containment, and exception handling.

Q: Why do fragmented AI tools create trust problems in the SOC?

A: Fragmented AI tools create trust problems because each one sees only part of the workflow, so analysts cannot reconstruct a single decision chain.

Q: What breaks when AI outputs cannot be explained to analysts?

A: When outputs are opaque, humans cannot challenge errors, compare confidence, or determine whether a recommendation is safe to act on.

Practitioner guidance

  • Map AI decision boundaries in the SOC Define exactly which incident types AI may triage, which it may recommend on, and which always require human review.
  • Treat AI access as governed operational privilege Review what data sources, case systems, and response tools each AI workflow can reach, then limit those permissions to the minimum needed for the workflow.
  • Reduce overlap between AI-powered SOC tools Inventory the point solutions that generate alerts, enrich events, or recommend actions, then remove redundant decision layers that force analysts to reconcile competing outputs.

What's in the full report

Torq's full report covers the operational detail this post intentionally leaves for the source:

  • The survey methodology behind responses from 450 CISOs and cybersecurity leaders, useful for evaluating how the findings were framed.
  • The full breakdown of analyst priorities across workload, trust, autonomy, and platform cohesion, which is where implementation decisions become clearer.
  • The underlying data on AI adoption, oversight time, and confidence gaps that can support internal SOC planning and board reporting.
  • The report's own recommendations for building a unified AI SOC operating model, which practitioners can compare against their current stack.

👉 Read Torq's 2026 AI SOC Leadership Report on trust, control, and automation →

AI in the SOC: are trust and control keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

AI SOC governance is now an identity problem as much as an automation problem. Once AI systems can access telemetry, open cases, and recommend or execute response actions, they need bounded permissions, traceability, and reviewable authority. That places them inside the governance perimeter normally associated with privileged humans and NHIs. The implication for practitioners is that SOC AI should be governed like a high-risk identity layer, not treated as a generic productivity feature.

A question worth separating out:

Q: Who is accountable when an AI SOC platform takes the wrong action?

A: The organisation remains accountable, because delegation does not transfer responsibility. Security, risk, and control owners need clear approval rules, logging, and override authority so each action can be traced back to a human governance decision. Without that, the control environment is not defensible.

👉 Read our full editorial: AI in the SOC is creating a trust and control gap



   
ReplyQuote
Share: