Research from Gartner
Innovation Insight: AI SOC Agents
Cybersecurity leaders must closely monitor the evolution of AI SOC agents, a group of technologies designed to augment common security operations tasks. AI SOC agents present an opportunity to transform security operations by using AI to assist human operators in performing common tasks.
Overview
Key Findings
- AI security operations center (SOC) agents have various capabilities that can assist cybersecurity analysts in performing a wide range of tasks associated with security operations.
- The market of AI SOC vendors is emerging rapidly, with new startup companies entering the market; however, there are alternate means to bring augmented workflows into security operations that do not require an AI SOC agent.
- The landscape of AI SOC agents is split between providers aiming at fully automating entire workflows and providers purposefully designed to augment existing staff.
- Today’s capabilities of AI SOC agents are not a replacement for human operators, but they can support common use cases such as alert triage, investigation, threat hunting, and more, by creating AI-augmented workflows.
Recommendations
In order to evaluate AI SOC agents, cybersecurity leaders must:
- Determine if their security operations organization has enough headcount to warrant augmentation technology, and which specific activities or functions would be ideal primary candidates for AI SOC agents.
- Identify success metrics that determine how the capabilities of AI SOC agents can improve on specific objectives and provide enough operational gains to offset the cost of the solution.
- Evaluate AI SOC agents based on their ability to improve existing workflows and SOC functions, rather than evaluate product features and functions.
- Minimize the risks of vendor lock-in by favoring a one-year subscription and ensuring that the AI SOC agent initiative is not tied to staff cost cutting.
Introduction
his document was revised on 20 October 2025. The document you are viewing is the corrected version. For more information, see the Corrections page on gartner.com.
Since its inception, the number of AI SOC agent market players has grown significantly, and the applications of AI SOC agents have expanded. This innovation insight seeks to better define AI SOC agents and its use cases for security operations to assist CISOs in defining their strategy.
CISOs must scale operations to keep pace with the ever-changing threat landscape. Workflow augmentation, or performing more operational tasks without hiring new team members is the prevailing strategy to scale. Although still emerging, AI SOC agents hold promise as a method to improve workflow augmentation in security operations.
Workflow augmentation in security operations starts with understanding the limitations of your existing operations, and which activities are volumetric, troublesome, or low-performing, and which would benefit the most from augmentation with the application of AI.
AI SOC agent vendors build and optimize their solutions around specific use cases, often offering multiple use cases as add-on or feature license options. Knowing beforehand your specific uses requiring augmentation helps you best align with vendors that support those use cases.
Figure 1 below shows the logical usage of AI SOC agents as they interact with SOC operators and data sources to support various use cases.
Figure 1: Usage of AI SOC agents

Description
AI SOC agent solutions use AI to help augment many of the common activities found within security operations. AI SOC agents can be used to augment investigation through natural language queries, false positive reduction, alert enrichment, attack path contextualization, reporting summarization, and next step advisory.
AI SOC agents have varying methods of deployment that they can use to support a variety of use cases. Here are the top methods observed from the field of providers:
AI SOC Agents’ Methods of Deployment
Simplified Common Knowledge Access
In this method of deployment, AI SOC agent vendors have taken large, and often disparate bodies of common knowledge and simplified the ability to gain insights quickly. This simplified approach to accessing bodies of knowledge can assist in augmenting security operations tasks that require lookups, analysis, and correlation through manual efforts. They generally require no organizational learning to be useful.
Simplified Systems Interface
AI SOC agents can use natural language to simplify human interactions with various systems involved in security operations. This allows a human operator to perform tasks on systems without detailed knowledge of system-specific syntax. This method of deployment is also rather canned, requiring the AI SOC agent vendor to know system-specific syntax and less about organization-specific learning.
Generative
AI SOC agents can generate useful content for a variety of use cases for security operations such as reporting, incident summarization, and response playbook code. Although the language of the content is known and universal, this deployment method does require the AI SOC agent to have the ability to learn organization details for accuracy, as well as the usability of the content generated.
Observational
In this deployment method, AI SOC agents are designed to learn details about organizational specifics such as desired outcomes, processes, operator accuracy, or even changes in exposure or other cybersecurity-related dependencies. Although the insights from this deployment model are slower to realize and require more tuning with the tool, they can help support a variety of use cases beneficial to oversight and management.
Benefits and Uses
The goal of the AI SOC agent is to augment various security operations activities and tasks by applying artificial intelligence.
Benefits:
- Workload reduction — AI SOC agents seek to drive efficiencies in common security operations use cases. Workload reduction is achieved by having AI perform tasks which is normally done by human operators. AI SOC agents do not unilaterally reduce workload on all security operations tasks, and must be selected and implemented per desired use case.
- Consistency in process — AI SOC agents bridge the skill gap between human operators and their knowledge of operating various cybersecurity systems and processes. This allows more junior security analysts to perform some tasks without dedicated systems training and certification, and creates more consistency in processes.
- Improved alert quality — AI SOC agents have the ability to pull in supplemental context from a variety of external sources such as threat intelligence, other cybersecurity controls, or asset information. AI SOC agents seek to enrich and add context dynamically based on their models rather than a static approach based on playbooks.
- Quicker decision making — AI SOC agents can provide insights in many forms such as attack timelines, attack path maps, or other such aids that allow investigators to more quickly identify root issues, scope, impact, and develop accurate containment and remediation plans.
- Reinvest human talent — When successful, a byproduct of reducing workloads is freed-up time and bandwidth for security operations team members. This allows security operations leaders to grow their practice or add new activities without the need for hiring additional headcount.
- Organizational knowledge retention — By combining “human-in-the-loop” and “human-on-the-loop” with learning capabilities, AI SOC agents help organizations acquire and retain operational knowledge that stays in the AI systems, even if some staff leave.
Models and other techniques used by AI SOC agent vendors must be trained and developed according to specific activities in order to be effective. The type of activities they perform is best described as use cases for security operations.
Common Use Cases for AI SOC Agents:
- Alert triage — AI SOC agents can be trained (either externally by the provider, or internally using client-unique data) to triage the incoming flow of raw alerts. Often, external context is used to assist in triage such as relating the alert to threat intelligence, exposure data, or cybersecurity controls data. Additionally, data such as asset use or prior asset event handling can impact how the system attempts to prioritize alert importance or dismiss false positives.
- Augmented investigations — AI SOC agents can augment investigations performed by more senior analysts in various ways such as dynamic alert enrichment, attack path mapping based on known threat patterns, attack timeline generation, and natural language query and/or suggestive query syntax generation.
- Detection content recommendations — AI SOC agents have the ability to ingest raw threat intelligence reports, summarize the indicators of interest, and then suggest tool-specific detection content that would generate an alert based on the initial threat intelligence report.
- Threat hunting augmentation — AI SOC agents develop threat hunting hypotheses by analyzing broad data sources such as client-unique security events, threat intelligence, and system exposure and logs. The AI SOC agent will propose a threat hunting hypothesis based on observed client-unique data and provide a transparent analysis of why the theory was formed. Human threat hunters can then continue the hunt to either confirm or deny the AI-derived analysis.
- Incident or case summarization — AI SOC agents can summarize datasets for reporting purposes. A common application is using the AI SOC agent to ingest all details in an incident investigation, and produce an incident summary report for senior management. Other similar use cases for summarization include report generation for other objectives such as GRC or overall cybersecurity operations performance.
- Operational oversight — AI SOC agents can learn standard or desired operating procedure through training or observations of human operators over time. The AI SOC agent provides insights into process deviations or areas of human operator error or underperformance.
- Collaboration assistance — AI SOC agents can collaborate with human security operations team members or with external teams. For security operations team members, AI SOC agents can provide collaboration in many ways, such as a chatbot or advisory aide, to take in learning or exceptional information, or to take tasks in or out of its job list. AI SOC agents can also be used to collaborate with end user or external team members when human-gathered context is required for investigations.
- Response recommendations or execution — AI SOC agents can use the information gained by summarizing an incident and client environmental data to generate client-unique containment advice. Some AI SOC agents can take this advisory a step further and generate playbook context to execute the response action, and then use API connections to carry out the commands on external systems.
Risks
Using AI SOC agents is not an instant journey to an autonomous SOC. Strategies for augmenting security operations must be specific to align AI SOC capabilities that provide operational gains toward your objectives. Organizations must also have enough investments in existing security operations, where gains found would be of significant benefit to offset the investments in AI SOC agents. This poses a risk to organizations with little or no investments in SOC operations, or those unsure which objectives are most conducive to optimization.
AI SOC agents pose other risks to organizations such as:
- Uncertain AI oversight and management processes. It’s unclear how much operational overhead is required to maintain quality and consistency in processes where AI workflows are involved.
- The measurable gains desired by using AI SOC agents vary greatly based on your organizational structure and tools.
Measuring the gains achieved can also be problematic where data on the current state of operations is not well-documented.
- AI SOC agents are prone to hallucinations or incorrect assumptions. Safeguards and oversight must be established to ensure that incorrect results produced by the AI are identified.
- AI SOC agent tools are still emerging, and claimed benefits are mostly unproven. Diligence is required to ensure any hype is debunked. Specifically, scalability of the solution and sustainable adoption by the security operation teams beyond the first few weeks are key elements to evaluate.
- Vendors in this space license agents aligned to specific SOC activities. Cost models limit the widespread use of AI SOC agents across entire team functions.
- Cost justification for AI SOC agents is difficult for smaller teams, as the real value of the solution is providing measurable gains in the operational cycle over the current team baseline.
- Most AI SOC agent vendors are in an early and volatile stage of development. AI SOC agent vendor attrition due to acquisition by larger cybersecurity platform players is a notable risk.
Alternatives
There are alternatives to AI SOC agents that offer some or all of the benefits provided by AI SOC agents to security operations teams. Organizations evaluating AI SOC agent vendors should consider some of the alternative solutions to see if there is a more preferable route to realizing these benefits.
Here are three alternative paths that offer AI SOC agent-type benefits:
- Service providers such as MDR. Gartner is seeing a trend of MDR providers boosting their service delivery with AI SOC capabilities. It’s worth noting, some of the major benefits provided by AI SOC agents, such as alert triage, are services generally covered by MDR providers. Using an MDR provider with extensive AI SOC capabilities is an alternate way to bring the benefits of AI SOC agents into your organization without having to buy additional stand-alone technology.
- SIEM and XDR are now offering native AI capabilities that help augment common workflow tasks and daily operations. Depending on your existing security operation providers and operational areas needing the most improvement, using native AI capability on your existing Cybersecurity technologies can be an alternative to purchasing AI SOC agent technology.
- Larger organizations may wish to standardize AI technology for a broader range of operational functions beyond security operations. For those organizations with the AI development expertise in-house, using a more generalized AI platform and developing your own agents for security operations can be an alternative to purchasing AI SOC agents. Drivers such as better control over data to limit privacy risks, additional contextualization by plugging cybersecurity systems with assets from other departments, and an internal culture of building rather than buying are frequent reasons for these custom-built agentic initiatives.
Recommendations
Cybersecurity experts evaluating AI SOC agents should do the following:
- Determine if their security operations organization has enough headcount to warrant augmentation technology, and which specific activities or functions would be ideal primary candidates for AI SOC agents.
- Identify success metrics that determine how the capabilities of AI SOC agents can improve on specific objectives and provide enough operational gains to offset the cost of the solution.
- Evaluate AI SOC agents based on their ability to improve existing workflows and SOC functions, rather than evaluating product features and functions.
- Minimize the risks of vendor lock-in by favoring a one-year subscription and ensuring that the AI SOC agent initiative is not tied to staff cost-cutting.
Representative Providers
- 7AI
- AiStrike
- Arcanna.ai
- BlinkOps
- Bricklayer AI
- Conifers.ai
- Crogl
- Command Zero
- Culminate Security
- Dropzone AI
- Embed Security
- Exaforce
- Intezer
- Imperum
- Legion Security
- Mate Security
- Prophet Security
- Qevlar AI
- Radiant Security
- Salem Cyber
- Simbian.ai
- Stream security
- SOC Jedi
- Torq.io
- Tuskira
Evidence
During the research period for this note, in addition to hundreds of interactions with organizations considering or evaluating AI SOC agents, several AI SOC agent vendors provided supporting points on their areas of security operations improvements. These supporting elements included product demos showing conceptual problems related to security operations and their application for improvement. AI SOC agent vendors were also challenged to show customer case studies that showed the areas of measurement for gains they used, and typical improvements achieved.
Source: Gartner Research Note G00837043, 16 October 2025, Eric Ahlm, Jeremy D'Hoinne