TLDRocket
Sign in

How much control should AI get? A CISO roundtable takes on SOC autonomy

The New Stack Carly Page

AI agents are moving into security teams to investigate alerts and maybe act on them. The hard part isn’t speed; it’s how much control humans are willing to give up.

Based on reporting by The New Stack, Carly Page — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Security teams have spent years drowning in alerts, and AI agents are now being pitched as a way out. The pitch is simple: let machines pull signals from different systems, investigate suspicious activity, and hand humans a cleaner set of next steps. That appeal is obvious when analysts have finite time and attackers are using AI too.

But the shift from help to autonomy is where things get uncomfortable. There’s a big difference between asking an AI to look into a strange login and letting it disable the account behind it. The same goes for isolating an endpoint or blocking traffic. Those actions can happen faster at machine speed, and they can hit the business just as fast if they’re wrong.

That’s why trust is no longer just about the model itself. Security teams need to know what the agent is doing, when a human still has the final say, and whether a bad call can be undone. In practice, that means putting hard limits around autonomy and keeping a way to shut the system down if it goes off course.

The role of the analyst would change too. If AI handles the routine investigation work, people can spend more time threat hunting, making judgment calls, and supervising the agents that are doing the repetitive stuff. The analyst starts to look less like a detective and more like an orchestrator.

The bigger shift may be the SOC itself. AI agents could blur detection, investigation, and response into one continuous loop, with what they learn in one case feeding the next. But there’s a familiar catch: security teams already live with sprawling tool stacks, and vendors are racing to add more agents to them. The promise is continuous security. The risk is just another pile of products to babysit.

My take — AI-written commentary, not fact-checked reporting

This is the right fight to have, because “autonomous security” sounds elegant right up until it has to undo a mistake at 3 a.m. Security vendors love to sell speed; security leaders should be asking about brakes, audit trails, and the big red off switch. AI can take the queue, but it shouldn’t get a blank check.

Read more about this at: The New Stack

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.