TL;DR: 97% of security leaders trust AI in the SOC, yet 90% report challenges with AI triage and 80% still rely on multiple point tools, according to Torq’s 2026 AI SOC Leadership Report. The real governance issue is not prioritising alerts faster, but deciding whether AI can investigate, contain, and remediate without leaving the SOC at human speed.
NHIMG editorial — based on content published by torq: the AI SOC land grab and the case for end-to-end response
By the numbers:
- 90% reported challenges with AI Triage
- 80% rely on multiple point-specific tools
- 92% of security leaders cite at least one factor actively reducing their trust in AI in the SOC today
Questions worth separating out
Q: How can teams tell whether AI triage is actually improving SOC operations?
A: Look for lower manual processing time, fewer duplicate reviews, shorter disposition cycles, and faster removal of related malicious messages.
Q: Why do triage-only tools fail to reduce SOC workload in practice?
A: They remove some queue noise but leave the hardest work untouched.
Q: What do security teams get wrong about agentic AI security tools?
A: The most common mistake is treating agentic AI security as an extension of an existing category such as NHI, endpoint, or DSPM.
Practitioner guidance
- Define the minimum response lifecycle you will automate Set a baseline that includes triage, investigation, containment, remediation, and case closure.
- Test decision traceability before granting autonomous response Require the system to show alert enrichment, evidence sources, rule triggers, and analyst feedback history.
- Bound autonomous actions with policy and rollback controls Limit automatic containment, quarantine, and account actions to pre-approved scenarios, and maintain a clear rollback path.
What's in the full article
Torq's full article covers the operational detail this post intentionally leaves for the source:
- The specific Torq Auto Triage workflow and how its verdicting logic is described
- Customer examples showing 60x triage velocity and 97% EDR noise reduction in operational terms
- The architecture Torq uses for Context Graph, Recall, and Reflex memory functions
- Gartner and KuppingerCole references that the source uses to position its AI SOC category claim
👉 Read Torq's analysis of why AI SOC needs to go beyond triage →
AI SOC triage versus end-to-end response: what teams need?
Explore further
Triage-only AI is not an AI SOC, it is alert prioritisation with a marketing label. The article correctly distinguishes verdict generation from investigation and response. In operational terms, the control gap is the absence of action closure: if the machine can rank risk but not contain it, the SOC still runs at human speed. That distinction matters for governance because the real risk is not bad triage, but false confidence in incomplete automation.
A question worth separating out:
Q: Who is accountable when an unsanctioned AI agent causes an incident?
A: Accountability should sit with the business and technical owner who allowed the agent to connect to enterprise systems, plus the control owners responsible for approval and monitoring. If no owner is named, accountability is already broken and incident response will be slower than it should be.
👉 Read our full editorial: AI SOC triage is not enough when response must follow