TL;DR: The 2026 SANS SOC Survey finds 79% of organisations using AI or machine learning, yet only 36% have integrated it into defined SOC workflows, while 24% of cyber leaders still name enterprise-wide visibility as their biggest barrier, according to Horizons.ai. The gap between adoption, workflow design, and measurable outcomes is now the central SOC governance problem.
NHIMG editorial — based on content published by Horizons.ai: 2026 SANS SOC Survey Insights: A Decade of Evolution in Cyber Defense
By the numbers:
- 79% of organizations are using AI or machine learning.
- Only 36% have integrated it into defined SOC workflows.
Questions worth separating out
Q: How should security teams govern AI-assisted actions in the SOC?
A: Security teams should treat AI-assisted SOC actions as policy-governed machine behavior, not informal automation.
Q: Why does visibility matter so much for SOC effectiveness?
A: Because the SOC cannot defend what it cannot see across identities, assets, telemetry, and response automation.
Q: What do security teams get wrong about GenAI in the SOC?
A: They often assume the model reduces the need for analyst judgment.
Practitioner guidance
- Define AI-assisted SOC workflows explicitly Document which triage, enrichment, escalation, and response steps AI may support, and require named approval points for any machine-generated recommendation or action.
- Map identity controls to SOC automation Inventory every service account, API token, and privileged role used by detection and response tooling, then scope each one to a single workflow boundary.
- Unify visibility across logs and identities Correlate telemetry from endpoints, cloud, IAM, and response platforms so analysts can see which identities acted, what triggered the action, and whether the action was authorised.
What's in the full report
Horizons.ai's full whitepaper covers the operational detail this post intentionally leaves for the source:
- Survey segmentation across 444 practitioners and 69 cyber leaders, useful for comparing how different roles view SOC maturity.
- The report's full breakdown of where executives and practitioners disagree on staffing, visibility, and investment priorities.
- Practical recommendations from SANS on how leading SOCs structure AI use, threat intelligence, and technology investment.
- The survey's complete benchmark data for organisations measuring themselves against peer SOC operating models.
👉 Read Horizons.ai's 2026 SANS SOC Survey insights on AI, visibility, and SOC maturity →
AI in the SOC: what practitioners need to do next?
Explore further
AI adoption without workflow governance creates security theatre. When organisations count AI usage but do not embed it into defined SOC processes, they confuse presence with control. The result is a tooling layer that looks modern but cannot support consistent triage, escalation, or evidence handling. For practitioners, the question is not whether AI is present, but whether it is operationally governed.
A question worth separating out:
Q: How do you measure whether causal AI is improving SOC outcomes?
A: Use metrics that show whether the team is finding the true root cause faster, choosing better interventions, and avoiding unnecessary response actions. Mean time to causal discovery and intervention efficacy are more useful than raw alert counts because they evaluate decision quality, not just activity volume.
👉 Read our full editorial: AI in the SOC is outpacing workflow integration