Left Arrow Icon
All articles

AI Agents Handle SOC Triage And Gain More Freedom As They Build A Proven Track Record

The Security Digest - News Team
Published
October 5, 2026

Georges Kaddoum explains why critical SOC actions still require human approval as AI takes on more of the detection and triage work.

Credit: The Security Digest

Make The Security Digest one of your go-to sources on Google

Google Icon
Add The Security Digest on Google
Quote Icon
Attackers are taking AI very seriously and relying on it heavily. From a defense and response perspective, we need to leverage AI as well.

Georges Kaddoum

Senior Manager

Georges Kaddoum

Senior Manager
IT Security & Operations

AI agents now handle much of the routine work in security operations centers, including alert triage and threat analysis. The access that work requires also makes them a target. Attackers can hijack an agent by hiding commands in a website or document it reads, and the agent carries them out as if they came from legitimate sources. Until defenses catch up, some security leaders want agents to monitor and recommend, with a person approving any action before it runs.

Georges Kaddoum is Senior Manager of IT Security and Operations at a private research university, where he oversees cybersecurity across both, including the SOC and organization-wide incident response. He has more than 20 years of experience in IT and previously served as the institution's IT Operations Manager, leading its information security and risk management unit and contributing to the medical center's electronic medical record rollout. He sees AI as a necessary part of how a SOC defends itself today.

"Attackers are taking AI very seriously and relying on it heavily. From a defense and response perspective, we need to leverage AI as well," says Kaddoum. Over the past year, AI-powered attacks have hit companies across nearly every sector and disrupted daily operations. The tools behind those attacks are affordable and easy to find. Kaddoum doesn't think a SOC can keep up using traditional methods alone. Deciding how far to trust agents once they're inside the environment takes more care.

Agents take the first pass

AI-powered SOC platforms can now handle the first-line review and escalation work that level one analysts have traditionally done. Those analysts are often recent graduates who need weeks or months to build confidence on the job. An agent trained on a team's established procedures can start on well-defined tasks much sooner. Kaddoum sees agents taking over that work. They move quickly and surface useful insights, though their analysis goes only so far without context. Most alerts a SOC receives depend on the specific infrastructure being monitored, so an agent has to learn that environment to judge them well.

Building that knowledge means charting every system, including the weakest points. Attackers do the same groundwork before they strike. Once that picture exists, teams need tight limits on who and what can reach it. If the agent is compromised, an intruder inherits everything it knows. "AI should be very controlled from a roles perspective and from an exposure perspective on the environment being monitored," he adds.

People make the call

Someone in the organization has to decide how much risk it's willing to accept, and that person answers for what happens next. Kaddoum doesn't think an agent can carry that responsibility. In some models, agents handle detection and forensics. "Agents should play the role of recommending actions. The action always needs a human approval or rejection in order to run," he says.

Kaddoum is most cautious in critical sectors. At a hospital or a power utility, one wrong automated step can put lives at risk. He holds agents to the same zero trust rules that govern users and devices, where nothing is trusted by default.

Outside those sectors, he's more flexible. For well-defined, low-risk work, he sees a place for agents to take predefined, tightly controlled actions against known threats. "In a few weeks, things might change due to the fast evolution of most AI platforms. We might identify other controls that can help give agents the right privileges, including action privileges," he notes.

Keeping approvals moving

Cost is speeding up adoption. An AI-driven SOC is much cheaper to run than a fully staffed one, and Kaddoum expects agents to reach into level two analyst work as well. That frees analysts to move into higher-value roles. He wants organizations to help them get there quickly while keeping the effect on their people in view.

Agents can surface recommendations far faster than a team can review them, which puts pressure on the approval step. "With AI providing a huge amount of recommendations, decision making at the human level will become a bottleneck. We need to find solutions at this level so the operation can run more smoothly," Kaddoum says.

Kaddoum expects agents to earn more responsibility as they prove themselves. He measures them against the analysts doing the work today. "A human actor can also commit mistakes. Once an agent's errors reach the same level as a human's, I believe we can trust these agents more," he adds.

The views and opinions expressed are those of Georges Kaddoum and do not represent the official policy or position of any organization.