Product1 distinct publisher3 min readUpdated
Its CEO puts AI investigations at $5 to $10 each, which makes the new triage layer's real job deciding which alerts never touch a model at all.
The Product Desk · Product desk
Compiled by The Product DeskSomething wrong?How this is made
Its CEO puts AI investigations at $5 to $10 each, which makes the new triage layer's real job deciding which alerts never touch a model at all.
Swimlane has expanded its AI security operations centre to automatically route incoming alerts down one of three paths: deterministic automation, AI-assisted investigation, or agentic automation [1][2]. The interesting part is not the routing. It is that the company is willing to say out loud why routing is needed: co-founder and chief executive Cody Cornell put the cost of an AI investigation at $5 to $10, and noted that at the scale of hundreds of thousands of investigations that piles up quickly [4].
That is a concession most agentic security vendors avoid. The pitch for the category has been capability; Swimlane's pitch here is restraint. A front-end triage layer assesses how complex the work is and how much AI involvement it needs, rather than defaulting every task to expensive models [3]. Cornell's framing: the next generation of the SOC "will not be able to run every task through AI by default. It will know which work actually needs AI" [5].
The company's diagnosis of the current state is specific enough to be checkable. AI-driven platforms, it says, send work to generative models that deterministic scripts could handle, so an expensive model ends up crunching something as simple as a text search, or doing what a six-line Python script would do [6]. Swimlane describes that as a potential cost tradeoff of several thousand percent, for an outcome where the model could return a wildly different answer [7].
The unit economics do the arguing. Swimlane cites one healthcare customer investigating more than 180 threats a day that reported 90% cost savings from intelligent routing, reserving agentic evaluation for only the most complex 10% of threats [8][9]. Run the arithmetic on Cornell's own price band and that volume implies $900 to $1,800 a day, or roughly $329,000 to $657,000 a year, if every one of those threats went through an AI investigation [1]. Note also that the claimed 90% saving is the exact complement of the 90% of threats diverted away from agentic evaluation, which means the comparison is treating the non-AI paths as effectively free [2]. That is a modelling choice, not a measurement.
Two design details matter more than the headline number. If the router sends what looked like a simple alert to deterministic automation and it turns out to be the tip of the iceberg, the team can still push it to a higher-reasoning model [10]. And when the agent does act, Swimlane says the system learns which alerts the team wants evaluated and turns those into repeatable playbooks [11]. That is the mechanism by which a cost-control layer either improves or quietly ossifies into a set of rules nobody revisits.
Cornell's summary of the goal is the sentence operators should hold the product to: customers should be able to expand what their SOC handles "without replacing an analyst-capacity problem with an AI-spend problem" [12].
What to watch: the announcement carries no figure for router accuracy, no cost for the routing layer itself, and no per-path pricing, so the $5 to $10 band and the 90% saving both rest on the vendor's own account [3]. Watch whether buyers start demanding cost per closed alert as a contractual metric, and whether competitors follow Swimlane in publishing a price per investigation at all.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Swimlane Inc., an agentic AI cybersecurity automation company, announced the expansion of its AI security operations centre to support automatic routing for security investigations.
The new capability routes incoming alerts to different paths: deterministic automation, AI-assisted investigation or agentic automation.
Swimlane said the front-end triage capability allows the system to quickly assess the complexity of the work and the level of AI involvement needed for the alert, without defaulting every task to expensive AI models.
Cornell said: "As AI consumption continues to rise, the next generation of the SOC will not be able to run every task through AI by default. It will know which work actually needs AI."
If the router sends what looked like a simple alert to deterministic automation but it was actually the tip of the iceberg, the security team can still route it to a higher-reasoning model, keeping the team in control.
Swimlane said the SOC learns which alerts the team wants evaluated and turns these into repeatable playbooks, creating a continuous, adaptable and configurable cycle.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single-source vendor announcement
Everything rests on one trade-press write-up of a Swimlane announcement, with all quantitative content attributed to the company or its CEO. The product mechanics are credibly reported as vendor descriptions, but the load-bearing economic claims — $5 to $10 per investigation, several-thousand-percent overspend, 90% savings — have no methodology, baseline, or independent corroboration, and no router accuracy or per-path cost is published.
One unnamed reference customer at launch
Observed adoption is a product release plus a single anonymised healthcare customer described as running routing at 180-plus threats a day. There are no customer counts, no general-availability or pricing details, and no third-party deployment reports, so real-world uptake beyond one reference account is unevidenced.
Savings headline outruns the disclosed measurement
The framing — thousands of percent of waste avoided, 90% cost savings — is materially stronger than what is shown. The 90% figure mirrors the 10% agentic routing share and implicitly treats deterministic and AI-assisted paths as free, while the router's own cost and error rate go unquantified. The underlying observation that per-alert model spend is a real constraint is sound, which keeps the gap moderate rather than extreme.
Vendor launch narrative, single trade outlet
Every substantive claim originates with the company launching the feature and its co-founder CEO, whose interest is in positioning routing as a differentiator against rival agentic SOC products. The publisher item is a launch write-up carrying no competing or independent voice, and closes with its own audience-network and AWS Marketplace solicitations, so nothing in the cluster is structured to test the vendor's numbers.
Direction credible, magnitudes unverified
It is well supported that Swimlane shipped a triage router with three execution paths and that it is marketing per-alert AI cost as the binding constraint. Confidence in the magnitudes — the cost band, the waste multiplier, the 90% saving — is low given one vendor-sourced item, one anonymous customer, and derived arithmetic showing the saving is a share complement.
product
Anthropic nudges its own agent-tampering risk from 'very low' to 'low'1 distinct publisher
build
The $559M-versus-$12.3B quarter matters more than the $65B run rate4 distinct publishers
product
APIs built for human judgment now answer to agents that have none1 distinct publisher
product
A $90M seed says robotics' scarce input is now the environment, not the robot1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026