TL;DR: AI-native MDR is emerging as a response to rising alert volume, expanding tooling sprawl, and analyst scarcity, with AirMDR describing AISOC as a model where machine-led investigation handles triage, enrichment, and response recommendations while humans retain approvals and accountability. The real shift is not more automation, but a SOC operating model that can scale investigation quality without depending on linear headcount growth.
NHIMG editorial — based on content published by Airmdr: SACR Analyst Report, AI-SOC for MDR and the structural evolution of managed detection and response
By the numbers:
- AirMDR says only ~3% of alerts require human touch in its service model, enabling 24/7 coverage without human fatigue.
Questions worth separating out
Q: How should security teams govern AI-led MDR when investigation is partly automated?
A: Teams should treat AI-led MDR as a governed decision system, not just an efficiency layer.
Q: Why do identity signals matter in AI-driven SOC investigations?
A: Identity signals matter because many security decisions depend on who acted, from where, with what access, and whether the behaviour fits the user's normal pattern.
Q: What breaks when AI SOC tools cannot explain their reasoning?
A: Case quality breaks first, then trust, then operational accountability.
Practitioner guidance
- Define machine decision boundaries Document which SOC actions AI can recommend, which it can execute, and which require human approval before any account, token, or access action is taken.
- Correlate identity telemetry with SOC cases Ensure authentication logs, cloud audit trails, SaaS activity, and EDR events are available in the same investigation path so the SOC can separate routine automation from compromise.
- Test explainability on identity-linked incidents Review whether the platform can show evidence sources, reasoning steps, and confidence levels for sign-in anomalies, privileged access events, and token misuse.
What's in the full article
AirMDR's full report covers the operational detail this post intentionally leaves for the source:
- Case-by-case explanation of how AI SOC handles detection, triage, investigation, and escalation in production.
- Examples of what the platform records for audit trails, reasoning traces, and case evidence.
- Implementation detail on how the service connects SaaS, SIEM, EDR, cloud logs, and identity signals.
- Operational distinctions between the platform model and the managed service model.
AI-native MDR and AISOC: what changes for SOC teams now?
Explore further
AI-native MDR is not just automation, it is governance of machine-led judgement. Once a platform begins making investigative decisions, the question shifts from workflow efficiency to control design. Security leaders must decide where the machine can conclude, where it can only recommend, and where it must stop. That is especially relevant in identity-heavy investigations, where account context and privilege scope drive response decisions. The practitioner conclusion is simple: AI SOC needs a governance model, not only a detection model.
A question worth separating out:
Q: Should organisations replace human SOC analysts with AI-native MDR?
A: No. The better model is split accountability, where AI handles repeatable investigation work and humans retain judgement, approvals, and exception handling. That preserves governance while reducing fatigue and improving consistency. Organisations should replace manual process, not human responsibility.
👉 Read our full editorial: AI-native MDR is reshaping SOC delivery around machine-led investigation