AI GovernanceAI agents
AI Governance · AI Agents

Can AI agents run security operations?

The short answer

Yes — for triage, investigation legwork, evidence gathering and first-pass verdicts, under supervision and with every action logged. No — for accountability, which stays human: someone owns the verdict, the response and the answer the auditor gets. Secure60 runs AI workers in production on exactly those terms, alongside human analysts.

What “AI SOC analyst” actually means in practice

Strip the demos away and agentic AI in security does a specific set of jobs. Some it does well today. Some it must never hold. The split is cleaner than the marketing suggests:

Security operations work Can an agent do it? What that looks like
Alert triage and first-pass verdicts Yes, supervised Reads the alert, checks history and context, proposes a verdict with reasoning attached
Investigation legwork Yes Pulls related logs across sources, builds the timeline, maps which hosts, users and accounts are involved
Evidence gathering Yes Assembles the log excerpts and artefacts a human needs to decide in minutes instead of an hour
Response and containment actions Only behind approval gates Proposes the action; a human approves before anything changes
Accountability for the outcome No A person owns the verdict, the response, and the answer the auditor gets

The pattern: agents are strong where the work is retrieval, correlation and write-up across large volumes of data, which is most of the hours in a SOC shift. Humans hold the calls that carry consequences.

The two conditions that make “yes” honest

Supervision. An agent’s verdict is a proposal until your process says otherwise. Early on, a human reviews everything. As trust builds against your own alert mix, you widen what the agent closes on its own — deliberately, category by category, with override always available. What never widens on its own is action: anything that changes a system waits for approval.

A full audit trail. Every input the agent received, every tool call it made, every output it produced, and who authorised each step — recorded, retained and searchable. Without that trail, you can’t review the agent’s work, can’t answer a customer’s “does AI act autonomously in your environment?”, and can’t reconstruct an incident it was involved in. How do you prove what an AI system actually did? sets out exactly what to record.

Meet both conditions and an agent is a supervised, evidenced part of your operation. Miss either and it’s an unaccountable actor with production access.

This is running in production, not on a roadmap

Secure60 ships AI workers that investigate and triage alongside human analysts — we call them digital workers, and they run in our platform today. A new threat comes in; a worker picks it up, pulls the related logs, builds the timeline, gathers the evidence and attaches a first-pass verdict with its reasoning. A human analyst reviews, agrees or overrides. Every session is logged end to end, so any verdict can be traced back through exactly what the worker saw and did.

Two things we learned running this for real. First, the win isn’t a headline verdict: it’s that every alert arrives at the human with the investigation already done, so the human decision takes minutes. Second, the audit trail earns its keep long before any audit: you review the worker’s cases the way you’d review a junior analyst’s, and you widen its remit on evidence rather than on faith.

What most people get wrong

Evaluating AI SOC products on verdict accuracy first. Accuracy quoted on a vendor’s own benchmark tells you little about your alert mix, and it isn’t the property that fails you. The property that fails you is invisibility. A wrong first-pass verdict that’s logged and reviewable costs an analyst minutes to catch and correct. An unlogged agent fails your customer’s security review, leaves your incident reconstruction blind, and hands your auditor a finding — even on the days it was right. The first question to ask any vendor isn’t “how accurate is it?” It’s “show me the complete log of what your agent did last Tuesday.” If that log is thin, accuracy is beside the point.

How Secure60 handles this

Tools hand you a to-do list. We do the list — and run the security behind it. Increasingly, “we” includes AI workers: they run triage and investigation under supervision inside our platform, with human analysts accountable for every outcome, and every action logged, attributable and reviewable as part of our AI Security capability. You get the throughput of agents and evidence of how they behaved, in one place. If a customer or auditor asks how AI operates in your security stack, the answer is already written down.

Frequently asked questions

Will AI agents replace SOC analysts?

No. They take the legwork — pulling logs, building timelines, assembling evidence, proposing first-pass verdicts — so analysts spend their time on judgement instead of retrieval. The accountable decision stays with a person.

What is an AI SOC analyst?

The market’s name for an AI agent that does first-pass alert work: it reads an alert, gathers the related evidence across your logs, and proposes a verdict with its reasoning attached. The useful ones run under supervision and log every step; the risky ones do the same work invisibly.

Is it safe to let an AI agent take response actions?

Only behind approval gates. Investigation and evidence gathering are read operations and low-stakes to automate. Containment and response change systems, so a human approves before the agent acts — and the request, approval and action are all logged.

How do we evidence AI agent activity to an auditor or a customer?

Log the agent’s inputs, every tool call, its outputs, and who or what authorised each action, then retain and search those records like any other log stream. How do you prove what an AI system actually did? covers the full structure.

Do we need our own AI team to use agents in security operations?

No. Platforms ship the agents. What you need to supply is the governance: defined supervision, approval gates for anything that changes a system, and an audit trail you control. Evaluate vendors on those three things before accuracy claims.

Watch an AI worker triage a real alert.

Run a pilot on your own data: our AI workers investigate and triage alongside your team, supervised and logged end to end.

Book a readiness call Run a pilot