What Security Teams Are Saying About AI

Security leaders sound off on AI adoption in detection

5 min read
Chris Reuter
Chris ReuterLinkedIn

Over the past month we interviewed (synchronously or via email) 50 SOC and detection leaders across a variety of industries and company sizes. Below are their anonymized observations on AI adoption in detection: both vendors, and their own experience with homegrown AI solutions.

1. Everyone has already built something

Nearly half of the teams we talked to described AI or agents they built for detection and security operations work, the most common way AI came up.

A software company has a named internal project:

"We have a project that we're running right now called Bongo* that ... was an AI assistant that we use for development of instrumentation logic."

*Name changed to protect the innocent

A collaboration-software company has operational concerns about its agents, including provenance:

"We make sure the agents always have an audit trail of what they did."

A solution provider has built its practice around commercial models:

"We have heavily leaned in on Claude and Microsoft Security Copilot where appropriate in each section ... We are feeding a lot of data through AI and doing a lot of asking AI, hey, what stands out here?"

A global payments company has agents for tuning and for turning intelligence into detections.

An HR-software provider runs a homegrown agentic SOC and agentic hunting in production.

An MSSP is building AI across "everything from building detections to auto triage, escalate and then contain."

Slightly over half of companies have not started using agentic detection methods at all - still relying on deterministic processes.

Pull quote: "We make sure the agents always have an audit trail of what they did." — a collaboration-software company

2. The AI-SOC category is automation with a model on top

Seven teams volunteered a skeptical read of the AI-SOC market.

A technology distributor had done the survey:

"I think one person's tracking over 100 vendors now in AI SoC space."

"They're still just the old style SOAR platform with AI built on top of it.”

An HR-software provider named the gap:

"Every agentic AI security focused vendor is focused on the infrastructure but not the actual runtime of the agentic system."

A managed infrastructure provider, describing his own customer base, put it plainly: AI is
"lot of buzzword but I didn't see it in reality."

The same teams are buying anyway. The distributor has "just onboarded a pretty significant AI agent platform" for its automation stack.

Pull quote: "Every agentic AI security focused vendor is focused on the infrastructure but not the actual runtime of the agentic system." — an HR-software provider

3. Detection authoring is solved: everything before and after is not.

Ten teams said producing a detection with AI is no longer the hard part. The real challenge is keeping them maintained continuously, with the right infrastructure context.

A retail brokerage put it most economically:

"We already kind of have an AI detection writing flow, but we’re looking at how to solve maintenance of those.”

A security instructor described the failure mode this creates:

"You just ask AI for a rule now, and a lot of times it might be 95% correct, but it hasn't been run against your data set, your network to know maybe you have a custom application that will accidentally match what AI came up with."

A wealth-management firm had a settled position: "you're going to have to be able to have
somebody who can double check and verify and prove something out before you can actually trust the output of the models."

The key here is that without codified expertise and thoughtful guardrails in place, AI will still revert to the mean: what it is excellent at.

Pull quote: "We already kind of have an AI detection writing flow, but we’re looking at how to solve maintenance of those." — a retail brokerage

4. AI cost and policy now decide what can be adopted

Nine teams mentioned AI cost and governance as a major trend within their organizations, impacting how they adopted AI.

A managed infrastructure provider had done the arithmetic:

"If we need to deploy let's say 300 detection rules, it translates to certain amount of
input, output tokens."

A collaboration-software company has reached thestage where it shows up in budget review:

"When I asked for the budget they'd be like, what's the token cost?"

Policy is the other half.

A consumer bank: "We're financial institutions so there's a lot of restrictions on what we allow to go to like frontier models."

An AI-infrastructure company routes everything through its own internal inference hubs, and a payments company through internal proxies for model requests.

For much of this market the question is no longer whether AI is allowed, but which model, whose infrastructure, and at what metered cost.

Pull quote: "When I asked for the budget they’d be like, what’s the token cost?" — a collaboration-software company

What this adds up to

The takeaway?

Everyone we asked was aware of AI, but formal adoption differed for security teams. The basics had extensive adoption (i.e. using ChatGPT to generate SPL), but real SOC expertise did not appear to be baked into AI in a thoughtful way yet.

Generating a detection is no longer difficult. Knowing whether it works in your environment, and still works next month, is. It is no surprise that was true before AI arrived. AI made detections faster to produce but did nothing to make them trustworthy, which is why the teams furthest ahead are shifting their focus from adoption to outcomes.

Do you have a take about AI? Let us know!