Skip to content

Security1 publisher2 min readPublished

AI agents are filling SOC queues faster than any other alert class

Enterprise AI tooling now trips about one SOC alert in 230, the fastest-growing class in the stream, and 94.1% of what it fires is legitimate work hitting detection rules written before agents existed. The bill is tuning and triage capacity.

The Watch · Security desk

Illustration accompanying AI agents are filling SOC queues faster than any other alert class

What happened

  • A review of roughly 16.9 million enterprise SOC alerts found about 73,000 triggered by AI tools and agents rather than by attacks against them.
  • That volume grew 685% between February and June 2026, with every full month higher than the previous one and growth accelerating sharply in May.
  • Automated triage gave 79.8% a benign verdict and suppressed 81.7% outright, with only 5.4% ever escalated to a human analyst.
  • One detection at one customer generated 55% of every alert that carried a critical verdict across the reviewed population.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • cost At about 67% compound monthly growth, a queue provisioned for today's AI alert volume runs short inside a quarter, and the money goes to analyst hours and detection engineering.
  • decision With roughly 15 confirmed compromises in the whole set, the funding choice sits between rewriting pre-agent detections and buying AI-attack detection, and the data supports the first.
  • exposure The OAuth-consent side of adoption barely registers on endpoint telemetry, so a programme that measures AI risk by SOC alert count is counting agent noise while the half that moves documents out stays off the tally.
  • constraint Severity counts cannot be used to size the problem or compare environments while a single detection at a single customer dominates the critical tier.

The rules that fire were written before AI agents existed [7]. Coding agents spawn shells, read credential stores, open network tunnels, download packages and run security tooling. All of it is legitimate developer work, and all of it is indistinguishable to a detection engine from the opening moves of an intrusion, according to the analysis published on The Hacker News [8].

685% from February to June is four monthly steps [3]. June volume is therefore 7.85 times February's, a compound rate of about 67% a month [1]. Hold that rate for three more months, with total alert volume flat, and the AI share moves from 0.43% to roughly 2% [2]. The authors describe 0.43% as today's floor and say a team that sizes its AI-alert handling to current volume will be under-provisioned within a quarter [10].

In absolute numbers, the 73,000 AI-related alerts break down to about 68,700 noise, roughly 4,200 genuine exposures, and about 15 confirmed compromises [3][4][5].

Automation absorbed most of the queue. Verdict and response are separate decisions on the same population [13], and 81.7% were suppressed against 79.8% given a benign verdict [5], so at least 1.9 percentage points of the population, about 1,400 alerts, closed automatically without a benign verdict [6]. Another 12.9% were flagged for follow-up [7]. Add the 5.4% escalated and about 18.3% of the population, near 13,400 alerts, stayed on a human list [8].

The escalated count works out at about 3,900 [9], slightly under the 4,200 genuine exposures [4]. For a SOC manager, the overlap between those two sets decides whether suppression is buying analyst time or burying the 5.8%. The post does not say how much they overlap, or how many enterprise environments the dataset covers [12].

Severity does not rank usefully inside this population. One detection at a single customer produced 55% of all critical-verdict alerts [6].

The other half of enterprise adoption is employees granting OAuth consent to third-party AI applications and pasting documents into generative-AI tools. That behaviour rarely trips an endpoint detection, and it is the path by which data leaves the organisation [9].

What to watch

  • Whether July to September volume holds near 67% a month or flattens after the May acceleration.
  • Whether the 5.8% genuine-risk share holds as agent permission defaults change, or misconfigured agents outgrow the noise.
  • Whether OAuth-grant telemetry enters the same count; adding it would move the 0.43% baseline.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories