TL;DR: 90% of security leaders prioritize explainable AI decisions, while 85% of analyst time still goes to contextualization, underscoring that AI SOC adoption hinges on grounded context rather than faster models, according to Torq’s 2026 AI SOC Leadership Report. The acquisition of Jit reflects a broader shift toward decision traceability, current-state context, and auditable agentic response.
NHIMG editorial — based on content published by torq covering its acquisition of Jit and AI SOC context graphs: LLMjacking: How Attackers Hijack AI Using Compromised NHIs
By the numbers:
- 90% of security leaders said explainable AI decisions matter most to an AI SOC platform.
- 85% of security analysts’ triage time goes to contextualization.
- The State of Non-Human Identity Security found that 85% of organisations lack full visibility into third-party vendors connected via OAuth apps.
Questions worth separating out
Q: How should security teams govern AI-assisted actions in the SOC?
A: Security teams should treat AI-assisted SOC actions as policy-governed machine behavior, not informal automation.
Q: Why do identity and privilege signals matter so much in AI threat detection?
A: Because many real incidents move through valid credentials, delegated access, and over-privileged accounts rather than obvious malware.
Q: What breaks when AI systems reuse stale context after an error?
A: The main failure is loss of conversation isolation.
Practitioner guidance
- Map AI SOC decisions to identity-aware context inputs Ensure the SOC reasoning layer receives current identity, privilege, asset sensitivity, and policy data before any automated verdict or response executes.
- Require decision traces for every automated containment action Log the verdict, the data available at decision time, the policy applied, and any override that changed the outcome.
- Curate context graph inputs as a governed data product Assign ownership for source quality, provenance, refresh cadence, and policy mapping so the graph does not drift from operational reality.
What's in the full article
Torq’s full article covers the operational detail this post intentionally leaves for the source:
- How the context graph is structured across temporal, provenance, semantic, governance, and decision-trace dimensions
- How Torq describes the workflow impact across build, triage, investigate, and respond stages
- How the acquisition narrative is positioned in relation to the company’s AI SOC roadmap and product architecture
- How the article explains customer-specific learning, data isolation, and the role of grounded decisions in agentic response
👉 Read Torq’s analysis of the Jit acquisition and AI SOC grounding →
AI SOC grounding and context graphs: what changes for practitioners?
Explore further
Context, not model performance, is becoming the decisive control plane for AI SOC adoption. Better reasoning models do not solve stale or incomplete security truth. If the agent cannot see current privilege, policy, ownership, and sensitivity, then its answer may be fluent but still operationally wrong. The implication for practitioners is to govern AI SOC platforms as context systems first and automation systems second.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, according to The State of Non-Human Identity Security.
A question worth separating out:
Q: Who is accountable when an AI SOC platform takes the wrong action?
A: The organisation remains accountable, because delegation does not transfer responsibility. Security, risk, and control owners need clear approval rules, logging, and override authority so each action can be traced back to a human governance decision. Without that, the control environment is not defensible.
👉 Read our full editorial: Torq’s Jit acquisition shows why AI SOC needs grounding