Overview
A few years ago the pitch was everywhere. AI would read the queue, clear the noise, surface the handful of alerts that actually mattered, and give analysts their nights back. With staffing pressure mounting, it was an appealing promise, and much of the security industry repeated some version of it to receptive boards.
The short version
What adoption says
- Many SOCs have bought or deployed AI and ML tooling.
- Security leaders still expect AI to absorb a major share of SOC work.
- AI has become a common response to staffing pressure and queue fatigue.
What operations reports
- Analyst satisfaction stays low where tools are inaccurate or unowned.
- The hardest alerts still require human judgment.
- A tool that is not trusted becomes another console to supervise.
The problem is not that AI has no value in the SOC.
The problem is that many teams bought it as a finished product, skipped the integration work, and then expected analysts to rely on it during the most demanding hours of the shift.
What the numbers actually say
In the SANS 2025 SOC Survey, roughly 40% of security operations centers reported using AI and machine learning tools. Yet in the same survey, those tools ranked at the bottom of the technology satisfaction list, below well-established tools that have been in use for years. High adoption, low confidence, and that split aligns with what we see on engagements: the teams that buy AI for the SOC and the analysts who operate it often describe very different tools.
Expectations have not yet adjusted to match. Prophet Security's 2025 work on the state of AI in the SOC found that leaders still expect AI to handle around 60% of SOC workloads within three years, a significant gap between what leadership anticipates and what operations teams experience today. Nor is this unique to security: MIT's Project NANDA found that roughly 95% of enterprise generative AI pilots in 2025 returned nothing measurable.
In a security context the stakes are higher. A tool that is not trusted does not only waste budget; it can create a false sense that something is being monitored when it is not.
Why the value has not materialized
“AI is overhyped” is a popular conclusion, but a more useful observation to question is why the value rarely moves from the strategy deck to daily operations.
In the environments we have examined closely, the shortfalls were more often organizational than technical.
The capability was bought and the work was skipped
Many of these tools were deployed straight out of the box, with no tuning, no customization, and no clear owner. AI was often treated the way antivirus is treated: license it, install it, and move on.
A model that has no knowledge of the environment, its naming conventions, or what normal looks like will tend to produce confident but unreliable results.
The easy part was automated and the rest went unowned
The premise was that AI would clear the low-value alerts so people could focus on the ones that matter. Sometimes it does. But the alerts it cannot resolve do not disappear; they accumulate.
That introduces a second task that is rarely budgeted for: deciding whether the AI reached the right conclusion.
Analysts tend to recognize this quickly. Once they find the tool is wrong often enough that verifying its output costs more than doing the work directly, they stop relying on it. The licence renews regardless, and the tool goes largely unused.
In some cases, teams finish an AI rollout with more work than before. They continue their existing responsibilities while also reviewing the output of a tool that does not improve on its own.
Trust is earned in operation, not in procurement
A tool that raises too many false alarms is eventually ignored. It is a familiar pattern, and the same reason a SIEM rule that fires thousands of times a day stops being read.
Every inaccurate summary, and every incorrect “this is benign” verdict on something that was not, erodes trust that is difficult to rebuild.
SOC analysts are skeptical by profession; scrutiny is part of the role. Their confidence is not won through a demonstration but through consistent accuracy over time, particularly in the moments when they are least able to double-check. Many current tools have not yet met that bar.
The value is unrealized, not unrealizable
It is worth qualifying the argument here, because the distinction matters.
There are narrow tasks where AI already earns its place in a SOC:
- Collapsing a long incident timeline into something a human can read in thirty seconds.
- Writing the first draft of a report that would otherwise take significant time.
- Pulling context from multiple consoles so the analyst is not switching between them manually.
- Identifying a pattern across more telemetry than a person can reasonably hold in mind.
This is not 60% of the workload. It is closer to 10%, but it is a meaningful 10% that can make the rest of the shift more manageable.
The teams seeing real value from AI share a common approach, and it is not defined by the vendor they selected. They treat the tool as something that supports their people rather than replaces them.
They give it an owner. They tune it to their environment. They confirm that it is accurate before trusting it with anything significant. In short, they evaluate it the way a well-run team evaluates an MSSP or an MDR: with clear questions and with someone accountable for the outcome.
What to do about it
For organizations reviewing an AI line item and wondering why the SOC is no calmer than it was last year, a few direct questions will often reveal more than another pilot.
Ask the analysts, rather than the vendor or the dashboard, whether the tool improves their work. If they have quietly stopped using it, that is a clear signal about its return on investment.
Ask whether the tool was ever tuned to the environment or whether it is still running in its default configuration. If it has not been adapted, the issue is more likely an incomplete implementation than the technology itself.
Focus on the smaller tasks, such as summarizing, enrichment, and first drafts, and measure their impact directly rather than forecasting a future in which AI runs the floor. Establish trust on these tasks before relying on it for anything larger.
Finally, deployment should not be treated as the measure of success.
“We rolled it out” is not an outcome. A tool that is widely deployed but not trusted can be worse than having no tool at all, because it creates the appearance of coverage over a workload that remains unaddressed.
AI is not underdelivering in the SOC because the technology lacks merit, it is underdelivering because it is often purchased as a finished product and never developed into something the team genuinely owns.
Sources
- SANSSANS 2025 SOC Survey
- Prophet Security6 Key Takeaways from the AI in SOC Survey Report
- MIT Project NANDAThe GenAI Divide: State of AI in Business 2025