TL;DR: Based on 450 CISOs and security leaders across four countries, 94% of teams use AI in the SOC, 80% say it adds complexity, and only 35% let AI handle triage, according to torq. The governance problem is no longer adoption, but deciding where automation can operate safely without weakening control.
NHIMG editorial — based on content published by torq: RSAC 2026 recap and the 2026 AI SOC Leadership Report
By the numbers:
- 94% of teams use it.
- 80% say it’s adding complexity, not reducing it.
Questions worth separating out
Q: How should security teams govern agentic triage in the SOC?
A: Treat the agent as an operational system with scoped access, documented decision boundaries, and mandatory logging.
Q: When does AI in the SOC become a governance risk rather than an efficiency gain?
A: It becomes a governance risk when it changes decision timing, action sequencing, or approval boundaries without clear policy.
Q: What do security teams get wrong about autonomous SOC maturity?
A: They often confuse feature depth with operational maturity.
Practitioner guidance
- Define AI decision boundaries in SOC workflows Separate advisory use cases from actions that can suppress alerts, open cases, isolate hosts, or revoke access.
- Require evidence trails for every AI action Preserve reasoning logs, input sources, and action traces for each automated triage or response decision so analysts can reconstruct why the system acted and whether it stayed within policy.
- Treat automated response as privileged operational access Review which identities, tokens, and service connections the AI uses to take action, and apply the same lifecycle controls you would expect for privileged tooling.
What's in the full article
Torq's full article covers the operational detail this post intentionally leaves for the source:
- The live RSAC demo sequence showing how Torq ingests, normalises, and correlates alerts across multiple security tools.
- The agentic response workflow behind HyperAgents and Socrates, including how investigation and remediation steps are chained together.
- The full 2026 AI SOC Leadership Report findings from 450 CISOs and security leaders across four countries.
- The specific reasoning-log and transparency claims demonstrated to booth visitors during the show.
👉 Read torq's RSAC 2026 recap and AI SOC Leadership Report findings →
AI SOC adoption is everywhere, but why does complexity keep rising?
Explore further
AI SOC governance debt is now a first-class security issue: the article shows that teams are adopting AI faster than they are defining decision rights. That creates governance debt, where the organisation cannot easily explain what the AI was allowed to do, what it actually did, and who owns the outcome. In practice, that debt becomes visible in triage, response, and escalation workflows that touch identities and credentials.
A question worth separating out:
Q: Who is accountable when an AI SOC platform takes the wrong action?
A: The organisation remains accountable, because delegation does not transfer responsibility. Security, risk, and control owners need clear approval rules, logging, and override authority so each action can be traced back to a human governance decision. Without that, the control environment is not defensible.
👉 Read our full editorial: AI in the SOC is adding complexity faster than it reduces it