TL;DR: Legacy SOAR has not solved Tier 1 overload, while AI SOC approaches can cut triage, investigation, and response time by correlating alerts, identity logs, cloud activity, and threat intelligence at machine speed, according to torq. The real shift is from brittle playbooks to agentic automation that reduces noise without removing human oversight.
NHIMG editorial — based on content published by torq: AI SOC benefits and the case for agentic incident response
By the numbers:
- 59% of security teams report being overwhelmed by too many alerts, and 55% waste precious hours chasing false positives.
- 52% are considering leaving the field entirely due to stress.
- 78% of organizations are fighting with dispersed, disconnected tools.
Questions worth separating out
Q: How should security teams use AI in the SOC without losing human control?
A: Use AI to remove repetitive work, enrich alerts, and accelerate triage, but keep humans accountable for escalation, containment, and exception handling.
Q: Why do identity logs matter so much in AI-driven incident response?
A: Because many modern attacks use valid credentials, tokens, or service identities instead of obvious malware.
Q: What breaks when AI SOC automation is built on static playbooks?
A: Static playbooks break when the alert does not match expected branches or when new attack patterns require context the script cannot infer.
Practitioner guidance
- Define autonomy boundaries for incident response Map which alert classes, identity events, and containment actions the AI SOC can close without human review, and which require analyst approval before termination of access or isolation of a host.
- Prioritise identity telemetry in triage logic Ensure authentication logs, privilege changes, and service account activity are part of the primary correlation path, not a late-stage enrichment step.
- Test playbooks against identity-led attack paths Run exercises where the attack begins with compromised credentials, token abuse, or delegated access so you can see where static workflows fail to branch correctly.
What's in the full article
Torq's full article covers the operational detail this post intentionally leaves for the source:
- Day-by-day implementation examples showing how the SOC automation matures over a 90-day deployment window
- Detailed descriptions of the multi-agent investigation flow across SIEM, EDR, cloud, and identity tools
- Customer case examples that show how automated containment and remediation are operationalised in live SOC environments
- The comparison table that contrasts legacy SOAR with AI-enhanced and true AI SOC capability models
👉 Read Torq's analysis of AI SOC benefits and agentic incident response →
AI SOC benefits: are your incident workflows keeping up?
Explore further
AI SOC is becoming an identity governance problem as much as a detection problem. The article focuses on speed, but the deeper issue is which signals the automation is trusted to act on. Identity logs, privilege context, and workload access patterns determine whether an AI SOC can make safe decisions. For practitioners, that means SOC modernisation and IAM governance now intersect directly.
A question worth separating out:
Q: Who is accountable when AI suppresses or mishandles an alert?
A: Accountability sits with the organisation that defined, approved, and operated the workflow, not with the model itself. If no human decision point exists, the failure becomes a governance failure as well as an operational one, and auditors will look for the missing control.
👉 Read our full editorial: AI SOC benefits depend on agentic automation and human oversight