TL;DR: AI-generated triage in security operations can look polished while missing attack context, mirroring the ‘vibe coding’ failure mode that has already driven production incidents, according to D3. The governance problem is not speed but unverifiable confidence: analysts need reasoning chains, ground truth, and review gates before AI output can shape response.
NHIMG editorial — based on content published by D3: SOC Alert Triage Slop, When AI-Generated Security Decisions Follow the Same Path as AI-Generated Code
By the numbers:
- The average enterprise SOC receives over 4,400 alerts per day.
Questions worth separating out
Q: What breaks when an AI analyst triages alerts without human review?
A: When an AI analyst triages alerts without human review, the main failure is not volume reduction, it is loss of inspectability.
Q: Why do AI-generated SOC recommendations increase risk in identity incidents?
A: Identity incidents depend on context such as account type, delegated permissions, session state, and whether access is standing or ephemeral.
Q: How do organisations know if AI triage is actually working?
A: Measure whether the AI improves high-fidelity detection, shortens time to verified response, and preserves reviewer trust in its decisions.
Practitioner guidance
- Require evidence-linked triage output Mandate that every AI-generated alert summary includes the underlying telemetry, correlated entities, and the reasoning steps used to reach the recommendation.
- Add human validation gates for identity-related decisions Block autonomous closure of alerts involving accounts, tokens, service identities, or delegated access until a human analyst confirms the interpretation against raw evidence.
- Test AI triage against known ground truth Use multi-stage attack simulations with verified outcomes to measure whether the system identifies the full attack path, not just the first alert.
What's in the full article
D3's full article covers the operational detail this post intentionally leaves for the source:
- How Morpheus AI is structured to expose reasoning chains across telemetry and response workflows
- The specific design choices behind contextual playbook generation and self-healing integrations
- The vendor's comparison of general-purpose LLMs versus cybersecurity-trained models in triage scenarios
- The implementation details for validating AI decisions against known ground truth
👉 Read D3's analysis of SOC alert triage slop and AI decision risk →
Triage slop in SOC operations: are your AI controls keeping up?
Explore further
Triage slop is a governance failure, not a model-output problem. The issue is the acceptance of machine-generated conclusions without the verification discipline that SOC work requires. In identity-heavy environments, that means analysts may accept AI assertions about accounts, tokens, or delegated access that have not been fully proven. Practitioners should treat AI triage as decision support only until the reasoning chain is inspectable.
A question worth separating out:
Q: Who is accountable when an AI triage system misses an incident?
A: The organisation remains accountable, even if software performed the first-pass analysis. Risk owners, SOC leadership, and the control owner for the workflow need to define approval rights, review obligations, and evidence retention before the system is relied upon.
👉 Read our full editorial: Triage slop in the SOC is the new AI decision risk