Security1 publisher2 min readPublished
AI agents are filling SOC queues faster than any other alert class
Enterprise AI tooling now trips about one SOC alert in 230, the fastest-growing class in the stream, and 94.1% of what it fires is legitimate work hitting detection rules written before agents existed. The bill is tuning and triage capacity.
The Watch · Security desk

What happened
- A review of roughly 16.9 million enterprise SOC alerts found about 73,000 triggered by AI tools and agents rather than by attacks against them.
- That volume grew 685% between February and June 2026, with every full month higher than the previous one and growth accelerating sharply in May.
- Automated triage gave 79.8% a benign verdict and suppressed 81.7% outright, with only 5.4% ever escalated to a human analyst.
- One detection at one customer generated 55% of every alert that carried a critical verdict across the reviewed population.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- cost At about 67% compound monthly growth, a queue provisioned for today's AI alert volume runs short inside a quarter, and the money goes to analyst hours and detection engineering.
- decision With roughly 15 confirmed compromises in the whole set, the funding choice sits between rewriting pre-agent detections and buying AI-attack detection, and the data supports the first.
- exposure The OAuth-consent side of adoption barely registers on endpoint telemetry, so a programme that measures AI risk by SOC alert count is counting agent noise while the half that moves documents out stays off the tally.
- constraint Severity counts cannot be used to size the problem or compare environments while a single detection at a single customer dominates the critical tier.
The rules that fire were written before AI agents existed [7]. Coding agents spawn shells, read credential stores, open network tunnels, download packages and run security tooling. All of it is legitimate developer work, and all of it is indistinguishable to a detection engine from the opening moves of an intrusion, according to the analysis published on The Hacker News [8].
685% from February to June is four monthly steps [3]. June volume is therefore 7.85 times February's, a compound rate of about 67% a month [1]. Hold that rate for three more months, with total alert volume flat, and the AI share moves from 0.43% to roughly 2% [2]. The authors describe 0.43% as today's floor and say a team that sizes its AI-alert handling to current volume will be under-provisioned within a quarter [10].
In absolute numbers, the 73,000 AI-related alerts break down to about 68,700 noise, roughly 4,200 genuine exposures, and about 15 confirmed compromises [3][4][5].
Automation absorbed most of the queue. Verdict and response are separate decisions on the same population [13], and 81.7% were suppressed against 79.8% given a benign verdict [5], so at least 1.9 percentage points of the population, about 1,400 alerts, closed automatically without a benign verdict [6]. Another 12.9% were flagged for follow-up [7]. Add the 5.4% escalated and about 18.3% of the population, near 13,400 alerts, stayed on a human list [8].
The escalated count works out at about 3,900 [9], slightly under the 4,200 genuine exposures [4]. For a SOC manager, the overlap between those two sets decides whether suppression is buying analyst time or burying the 5.8%. The post does not say how much they overlap, or how many enterprise environments the dataset covers [12].
Severity does not rank usefully inside this population. One detection at a single customer produced 55% of all critical-verdict alerts [6].
The other half of enterprise adoption is employees granting OAuth consent to third-party AI applications and pasting documents into generative-AI tools. That behaviour rarely trips an endpoint detection, and it is the path by which data leaves the organisation [9].
What to watch
- Whether July to September volume holds near 67% a month or flattens after the May acceleration.
- Whether the 5.8% genuine-risk share holds as agent permission defaults change, or misconfigured agents outgrow the noise.
- Whether OAuth-grant telemetry enters the same count; adding it would move the 0.43% baseline.