TL;DR: AI can reduce breach lifecycle and costs while 42% of SOCs still deploy out-of-the-box AI and ML tools that score low on satisfaction, underscoring a gap between automation promise and operational reality, according to Panther. The real issue is not replacement but whether teams can supervise AI, tune detections, and preserve human judgment where context matters.
NHIMG editorial — based on content published by Panther: Will AI Replace SOC Analysts? The Honest Answer Is More Complicated
By the numbers:
- 42% of SOCs deploy AI/ML tools out-of-the-box without customization, and those tools consistently receive low satisfaction.
Questions worth separating out
Q: How should security teams use AI in the SOC without losing human control?
A: Use AI to remove repetitive work, enrich alerts, and accelerate triage, but keep humans accountable for escalation, containment, and exception handling.
Q: Why do identity signals matter in AI-driven SOC investigations?
A: Identity signals matter because many security decisions depend on who acted, from where, with what access, and whether the behaviour fits the user's normal pattern.
Q: What do security teams get wrong about GenAI in the SOC?
A: They often assume the model reduces the need for analyst judgment.
Practitioner guidance
- Separate repetitive triage from judgment calls Use AI for alert prioritisation, enrichment, and first-pass summarisation, but require human review for privileged access events, production-impacting actions, and ambiguous identity activity.
- Adopt detection-as-code for AI-supervised workflows Version-control detection logic, test changes in staging, and peer-review rule updates so AI output can be validated against known cases.
- Normalise identity telemetry before scaling AI Ensure login events, privilege changes, cloud actions, and endpoint logs share consistent timestamps and identifiers so correlation is reliable.
What's in the full article
Panther's full blog covers the operational detail this post intentionally leaves for the source:
- Cresta-style workflow examples showing how Panther AI reduced triage time in a live SOC setting.
- The specific detection engineering examples behind AI-assisted investigation summaries and alert tuning.
- Data architecture guidance on normalising cloud, identity, and endpoint telemetry for better AI correlation.
- The practical comparison between high-volume triage automation and human-led validation in ambiguous cases.
👉 Read Panther's analysis of how AI is changing SOC analyst roles →
AI in the SOC: what it automates, what it cannot replace?
Explore further