Deep in the security operations center of a Fortune 500 firm, an agentic AI named Sentinel, powered by advanced algorithms, identifies an endpoint breached when an employee clicks on a link in a phishing email. Sentinel also instantly spots anomalous logins from Eastern Europe and signs that data exfiltration is underway. Sentinel dispatches Hunter to trace and isolate the intrusion.
Meanwhile, the agent Defender recognizes the malware as a ransomware variant of the cybergang LockBit, and it closes the vulnerabilities the attackers used to gain entry. Within minutes, human analysts receive an after-action report for review, and a breach that could have cost millions in downtime and lost data is mitigated by a trio of AI systems, backed by vast analytic engines and a decade’s worth of security event and attack data.
Full disclosure: Those AI agents (Sentinel, Hunter, Defender) are fictional, and the incident is hypothetical. But the promise of this new agentic cybersecurity world is real and coming—very soon, say industry experts—to a security operations center (SOC) near you. And they are expected to arrive in a big way: By next year, around 86% of organizations expect to be using AI agents, according to the recent PagerDuty Agentic AI Survey.
Unlike the rule-based tools that have existed in the forms of robotic-process automation or security orchestration automation and response (SOAR) tools, AI agents in the spirit of Sentinel, Hunter, and Defender promise to learn from their environments, predict, make decisions and execute responses within specified tasks like isolating compromised devices, patching vulnerabilities, taking compromised systems offline, and seeking help from additional agents and human security pros when needed.
Some contend that these agents will transform security operations; others remain skeptical about the level of change possible in the near future given the current state of the art.
For security managers, the benefits are compelling: According to vendor reports, 24/7 threat monitoring slashes response times by up to 90%, reduces alert fatigue, and addresses talent shortages by automating repetitive and mundane tasks. Agentic AI also enables proactive defense, using behavioral analytics to preempt exploits and enforce security policies.
"I was initially skeptical about agentic AI, but seeing it used in business applications and then in security operations changed my views,” said Wim Remes, principal consultant at security consultancy Toreon, based in Antwerp, Belgium. “Agentic AI has strong application for gathering and contextualizing information for SOC analysts as well as automating incident response."
Promising assessments, to be sure. But before you build those autonomous workflows, enjoy faster patch cycles, and create overall business value, you need to understand the plusses and pitfalls of agentic AI.
What follows is a valuable primer with expert guidance on what you should know for the coming year—and the best ways to start the process of incorporating agentic AI into your business model and enterprise architecture.
The rise of agentic AI: your (semi) autonomous defender
Traditional AI gives you answers. Agentic AI executes decisions without—if you so choose—waiting for your approval.
“I was initially skeptical about agentic AI, but seeing it used in business applications and then in security operations changed my views.”Wim Remes, principal consultant at security consultancy Toreon
It’s the natural extension of robotic process automation, traditional AI, and other deterministic processes that require some level of judgment and decision-making, rather than following strict playbooks filled with pre-canned workflows triggered by predefined scenarios. "Agentic AI promises to eventually close the gaps that current automation cannot close," said Scott Crawford, information security research head at S&P Global Market Intelligence.
The key word there? “Eventually.”
While analysts agree that agentic AI will give these systems more "agency," debates abound on how quickly agentic AI in SecOps will prove to be a game changer.
The motivation to move to agentic AI is high. For years, cybersecurity teams have fought a losing battle against an avalanche of system alerts, and their adversaries—growing faster, more automated, and increasingly creative—have forced defenders to constantly adapt. And fight alert fatigue. And struggle with career burnout. Traditional, rule-based tools, with their static playbooks and brittle logic, simply couldn't keep up. "That's the real value here," Remes added. "Reducing cognitive load for analysts, such as pulling together information about an alert, related assets, past incidents, and vulnerability scans—rather than simply automating actions like account lockouts and such," he said.
[Read also: 4 critical leadership priorities for CISOs in the AI era]
Here's how agentic AI could help turn that around:
- From alert fatigue to autonomous action—The average enterprise security operations team faces thousands of alerts daily, with the majority being false positives or of low risk. Human analysts, already stretched thin by staffing shortages, are forced to triage, investigate, and respond—often missing the subtle signals of a real breach. Agentic AI's analytics capabilities and autonomous response promise a new calculus.
- Automated threat detection and response—Agentic AI systems ingest data from cloud, network, and endpoint sources, identifying abnormal patterns that signal potential threats. Upon detection, they can autonomously isolate compromised devices, block malicious traffic, or revoke credentials—actions that once took hours now happen in seconds.
- Dynamic playbooks—Static incident-response plans often break, which is why many security pros hope they will soon become relics. Agentic AI crafts dynamic, context-aware playbooks that adapt responses to the evolving threat landscape. It can prioritize incidents, investigate anomalies, and even orchestrate multi-step containment strategies—perhaps without waiting for human approval.
- Continuous learning, an elephant's memory—Every interaction, every incident, becomes training data—and like the internet's memory, AI never forgets. Agentic AI refines its models with each encounter, improving detection rates and reducing false positives over time. The SOC gets faster as it gets smarter.
- Proactive defense and zero-trust enforcement—Agentic AI leverages behavioral analytics to spot deviations from baseline activity, flagging zero-day exploits and insider threats before they escalate. By continuously monitoring user behavior and asset criticality, it enforces zero trust policies, ensuring that access is always contextually justified and dynamically adjusted.
[Read also: What you need to know about South Korea’s new AI law]
Agentic AI’s pitfalls and perils
Agentic AI enthusiasts acknowledge that, despite such potential, it won’t all be security nirvana, and getting to agentic AI–powered SOCs won't be as simple as flipping a switch.
“This technology isn’t necessarily easy to implement.”David Marcus, federal senior security technologist and principal engineer, Intel
"This technology isn't necessarily easy to implement and will also create its share of new challenges," said David Marcus, federal senior security technologist and principal engineer at chipmaker Intel.
Such challenges include integration with legacy systems, due to their proprietary formats and obsolete programming languages, as well as a lack of support for modern AI frameworks that require application programming interfaces (APIs) for real-time data exchange. Without these capabilities, agentic AI in the SOC won't have the data needed to make informed, timely actions.
Those challenges are in addition to standard data-related hurdles, such as data quality and preparation issues, including normalizing data formats, cleaning outdated logs, and removing inaccurate data or data lacking necessary metadata.
Additionally, all the challenges associated with humans also apply to AI agents, due to their elevated access to tools, data, and ability to function autonomously. This makes them susceptible to privilege compromise and credential theft. This is the same as it is for human staff members, where attackers can impersonate agents and perform unauthorized tasks that damage, disrupt, and expose sensitive data.
At scale, these risks compound as organizations deploy more agents across teams and workflows, often leading to agentic AI sprawl—where autonomous systems proliferate faster than governance, visibility, and accountability mechanisms can adapt.
[Read also: How AI is redefining data loss prevention]
There's also the risk of over-reliance on AI, which could create "alert blindness" if human oversight wanes as trust increases too much and human checks slip. "Full automation without process maturity is risky," added Remes. "You want to start with manual processes, then move to human-controlled automation, and then human-supervised automation, and only finally to full automation. Organizations should introduce agentic AI as processes mature."
5 steps to safer agentic AI
Security leaders learn how to attain the right level of autonomy with control over these agents as they leverage agentic AI's speed, but without ceding critical judgments.
“This is one of the problems we see with each of these big technology waves. We discuss the upside, but we don't spend enough time discussing the downside.”Scott Crawford, information security research head, S&P Global Market Intelligence
"There's a balance needed here,” said Crawford. “This is one of the problems we see with each of these big technology waves. We often discuss the upside, but we don't spend enough time discussing the downside to create a healthy balance in the conversation. Unfortunately, what that does is get people incredibly excited about the potential, but then they don't think about the ramifications of what they could be stepping into.”
There are several steps enterprises can take to ensure they meet that balance:
1. Establish robust agentic AI governance frameworks
Begin by creating clear policies and guidelines that outline how agentic AI will be used in your security operations, including decision-making rules and compliance with industry standards. This ensures everyone in the organization understands the boundaries and responsibilities, including properly registering agents being deployed, and reducing the risk of misuse or legal issues. Regularly review and update these frameworks to adapt to new threats or regulations, fostering a culture of accountability.
“We have plenty of our staff that are creating their own agentic agents—which is fantastic. But we need to … make sure they're written and developed using proper guardrails.”Jeffrey DiMuro, deputy CISO, ServiceNow
This is one of the reasons why Jeffrey DiMuro, deputy CISO of ServiceNow, who formerly ran data governance, security risk and third-party risk at the company, warns of agentic AI proliferating without such governance.
“We have plenty of our staff that are creating their own agentic agents—which is fantastic,” he said. “But we need to … make sure they're written and developed using proper guardrails, and we need to register those [agents], and we need to make sure we're not duplicating efforts so that everybody across our environment has access to tools that have been validated.”
2. Set agentic AI boundaries via granular access control
Apply detailed controls on what AI agents can access and do, utilizing models such as role-based permissions and zero-trust principles to limit exposure. This prevents unauthorized actions and protects critical assets from potential threats. Such controls provide peace of mind, ensuring AI enhances security without introducing new vulnerabilities.
For example, a security agent might have read-only access to investigate alerts and query logs but cannot execute remediation—it flags a suspicious account for human review rather than disabling it. Another agent might auto-isolate a compromised endpoint but cannot access the identity management system to reset credentials. A third can patch vulnerable applications but cannot modify firewall rules.
3. Fuel agentic AI teamwork with defense in depth
Build multiple layers of safeguards around AI systems so that if one fails, others can step in to maintain protection.
A SOC agent might detect and isolate a compromised endpoint, but a separate network segmentation layer prevents that endpoint from lateral movement. An automated patch management agent applies updates, but a separate rollback system can revert changes if the patches break critical applications. This layered approach mitigates the impact of any single compromise, keeping operations stable. It promotes a resilient security posture that aligns with business continuity goals.
4. Combine agentic AI with human oversight
Maintain experienced personnel's involvement in monitoring and approving key AI decisions, particularly in high-stakes situations. This hybrid model leverages human judgment to complement AI strengths, thereby reducing errors and enhancing reliability. Oversight ensures ethical alignment and enables swift interventions when necessary.
“It still requires a human in the loop. And that's your trust-but-verify.”DiMuro
“If you're going to allow an assistant—I'll call the agentic AI an assistant that has access to more information than I've ever had before—[to] correlate that and help me go faster, it still requires a human in the loop. And that's your trust-but-verify,” DiMuro advised.
5. Implement continuous testing and validation of agentic AI
Regularly simulate attacks and scenarios to test AI performance and uncover weaknesses before they affect real operations. This ongoing process keeps the system robust against evolving threats.
Of course, the golden rule of computing—garbage in, garbage out—applies. Organizations need to focus on ensuring the data they feed into AI systems is accurate and secure.
The agentic AI triad: transparency, trust, and team-building
It is also crucial to make AI decision-making processes more understandable by using tools that explain how outcomes are reached and logging all actions for easy review.
“While agentic AI can be effective today, adequate levels of transparency and explainability are crucial for trust and good governance.”Michael Farnum, CEO, Cybr.SEC.Community
This builds confidence among teams and stakeholders, allowing for the quick identification of any issues or anomalies. Transparent systems also facilitate better audits and help demonstrate the ethical use of AI to regulators and partners.
"While agentic AI can be effective today, adequate levels of transparency and explainability are crucial for trust and good governance," said Michael Farnum, former advisory CISO at technology consultancy Trace3 and now CEO of Cybr.SEC.Community, a Houston-based cyber events company.
[Read also: When AI agents and automated workflows can finally be trusted]
Finally, the SOC team must be prepared for AI, and staff must receive proper training. Leaders should evaluate their organization's current infrastructure, data readiness, team skills, and culture to identify gaps before deploying AI, ensuring a smooth rollout. Providing training programs helps employees collaborate effectively with AI tools, shifting their focus to higher-value tasks. This preparation aims to minimize resistance and maximize the productivity gains from AI integration.
Whether agents like our fictitious Sentinel, Hunter, and Defender find permanent placement as team members among modern security operations teams remains to be seen. But they’re here for now and seem to be helping, so security leaders must make their acquaintance, come to understand their strengths and weaknesses, and make the most of them.
Their overstressed security teams could certainly use the help.
