TL;DR: KuppingerCole Analysts’ April 2026 Leadership Compass retired SOAR in favour of an Emerging AI SOC category, arguing that rule-based workflows have hit an efficiency and implementation ceiling while agentic AI, contextual enrichment, and adaptive decision support reshape security automation, according to Torq. The category shift matters because it changes how teams should evaluate automation, governance, and explainability across SOC operations and identity-linked response paths.
NHIMG editorial — based on content published by torq: The Emerging AI SOC and KuppingerCole Analysts’ April 2026 Leadership Compass
By the numbers:
- Torq’s 2026 survey of 450 security leaders found that 97% are confident AI can handle triage, but only 35% have deployed it there.
- Torq reports that 94% are already using AI in the SOC.
- The vendor says 92% of security leaders cited at least one factor that reduces their trust in AI.
Questions worth separating out
Q: How should security teams govern AI-assisted actions in the SOC?
A: Security teams should treat AI-assisted SOC actions as policy-governed machine behavior, not informal automation.
Q: Why do AI SOC platforms raise IAM and PAM concerns?
A: Because the moment a SOC platform can change access, terminate sessions, or trigger containment across systems, it is exercising identity authority.
Q: What do security teams get wrong about SOAR versus AI SOC?
A: Teams often assume AI SOC is just faster SOAR.
Practitioner guidance
- Define AI response boundaries Classify which containment and remediation steps AI may execute automatically, which require human approval, and which remain manual.
- Review identity-linked automations Inventory SOC automations that touch IAM, PAM, NHI, endpoint isolation, or cloud access.
- Test explainability under incident pressure Validate whether analysts can understand why the platform chose a particular action when signals are noisy or conflicting.
What's in the full article
Torq's full article covers the operational detail this post intentionally leaves for the source:
- How the KuppingerCole evaluation broke down product, innovation, market, and overall leadership criteria.
- The vendor's own explanation of its AI SOC architecture, including RAG, MCP, and agent-to-agent collaboration.
- Specific customer examples and stated automation outcomes from production SOC deployments.
- The full list of strengths KuppingerCole identified across integrations, explainability, and governance.
👉 Read torq's analysis of the Emerging AI SOC and KuppingerCole evaluation →
Emerging AI SOC: what it means for SecOps, IAM, and governance?
Explore further
Emerging AI SOC is now a governance category, not just a tooling label. The retirement of SOAR as a category signals that security automation is being judged on reasoning, adaptability, and operational trust rather than playbook count. That matters because AI-driven response now touches identity, privilege, and human oversight at the same time. For practitioners, the buying decision is increasingly about whether the platform can be governed under real-world conditions, not whether it can trigger actions.
A question worth separating out:
Q: How do organisations know if AI triage is actually working?
A: Measure whether the AI improves high-fidelity detection, shortens time to verified response, and preserves reviewer trust in its decisions. A system that merely closes more alerts is not enough. The right signal is whether the SOC can validate its conclusions quickly and use them in real investigations without rework.
👉 Read our full editorial: Emerging AI SOC is replacing SOAR as security automation shifts