AI in the SOC: How Much Autonomy Can You Give Up Without Losing Control?
AI agents are already investigating alerts in the SOC, but giving them autonomy raises control concerns. We analyze what it means for your SMB and what we recommend.

Alert management in a security operations center (SOC) has been a headache for years. The volume of signals generated by a mid-sized company's systems far exceeds the capacity of any human team. The proposal that is gaining ground is to let AI agents investigate some of those alerts on their own: cross-referencing signals from different systems, analyzing suspicious activity, and proposing next steps to the responsible people. According to The New Stack, this is already happening in security teams experimenting with AI to assist in investigations, and the debate is now shifting to how much control organizations are willing to give up.
From assistance to autonomy: the new dilemma
The leap from AI as an assistant to AI as an agent with a certain degree of autonomy is not trivial. When a model is limited to summarizing alerts or suggesting queries, the risk is low: the human decides. But when the agent starts executing actions—isolating an endpoint, blocking an IP, closing a ticket—the question changes: who is responsible if it makes a mistake? What oversight mechanisms exist? How do you audit a decision made by a system that does not follow explicit rules?
The New Stack addresses this issue in a live session on October 8 titled Running an AI-Powered SOC: How to Match AI-Speed Attacks Without Losing Control, where the question is precisely how to give agents more autonomy without losing the control and oversight that security operations require. The event includes a platform demonstration and a survey on the current level of adoption: from those exploring AI without deploying anything to those already automating significant parts of their investigation process.
What this means for an SMB
In an SMB, the SOC often does not exist as such: there is an IT team juggling security, infrastructure, and support. The promise that an AI agent will investigate alerts and propose actions is attractive because it eases the load. But it also introduces risks that should be understood before buying into the promise.
- Lack of context: an agent may misinterpret an alert if it does not know your network's real topology, critical assets, or business patterns. Without that context, an automatic action can cause more damage than the original threat.
- Traceability: if the agent decides something, you need to know why. An action log is not enough; you need to understand the reasoning chain or, at least, the signals that motivated it.
- Responsibility: delegating to an agent does not exempt you from legal or contractual responsibility. Someone on your team must remain ultimately responsible.
Practical recommendations before increasing the level of autonomy
It is not about giving up AI in the SOC, but about scaling autonomy with judgment. These are the guidelines we suggest at ForgeNEX:
- Start with observability, not action. Before letting an agent execute, use it to correlate signals and recommend. Tools like those we discussed in Cortex XCOR: observability with AI that investigates and recommends follow that line: they investigate and propose, but do not act on their own.
- Define clear thresholds. Establish what types of actions the agent can take without human intervention (for example, enriching a ticket) and which require explicit approval (isolating a production server).
- Implement a “shadow” mode. For a period, let the agent propose actions but not execute them. Compare its decisions with those your team would have made. Adjust before giving it free rein.
- Audit and review. Every autonomous action must be recorded with enough context to reconstruct it. Periodically review whether the agent's decisions remain aligned with your policy.
- Do not delegate responsibility. Designate a person on the team as responsible for supervising the agent. AI does not sign, does not declare, and does not assume consequences.
The balance is not binary
The question is not whether AI should have total control or none. Autonomy is a spectrum and each organization must find its point. For an SMB with limited resources, the temptation to automate everything is understandable, but the cost of a mistake can be high. The key is to move forward in phases, measuring the impact and always keeping a human in the loop for critical decisions.
The debate raised by The New Stack is not new, but it is urgent: the speed of AI-driven attacks demands rapid responses, and agents can help match that pace. The condition is not to lose sight of who is in charge. As we discussed in AI accelerates exploits: your CVE spreadsheet is no longer useful, defense also needs to accelerate, but with control.
Source: The New Stack. Analysis and adaptation: ForgeNEX.