Authored by: Rob Demain, Founder & CEO
While building the offensive and defensive test infrastructure for Cumulo, I observed something that changed how we approached the detection problem. Given a structured analysis framework and access to a modern frontier model, AI independently generated command-and-control channels, reverse shells, and functional attack code. Not as a directed task. As a natural output of what it had learned about how those systems work.
That observation is not a warning about AI in general. It is a specific data point about what the threat model looks like right now, and it is directly relevant to why agentic AI in the SOC matters. If AI can reason its way to a working attack, the defences that will catch it are the ones that reason back.
‘Agentic AI’ is a term that has entered the security market quickly enough that its meaning has already started to blur. This article sets out what it actually means in a SOC context, what changes when it is implemented well, and what organisations should require before trusting it with operational decisions.
What makes AI ‘agentic’ in a security context
The word ‘agentic’ describes AI that does not simply respond to input: it reasons through a problem, plans a sequence of steps, and acts to complete a goal. Standard AI models produce outputs when prompted. Agentic AI systems pursue outcomes, using tools, taking intermediate steps, and adapting their approach based on what they find.
In a security context, this distinction maps onto three generations of detection capability.
Reactive AI operates on rules and known signatures. A SIEM alert fires when log data matches a pre-written condition. This model is fast and predictable, but it only catches what the rules anticipated. It is still the dominant architecture in most deployed SOC tools.
Responsive AI applies machine learning to flag anomalies: behaviour that deviates from a learned baseline. It detects more than rule-based systems, but it still responds to what it observes rather than reasoning about what it has not yet seen.
Agentic AI reasons. It takes a set of signals, develops hypotheses about what they mean, tests those hypotheses against additional data sources, and produces a prioritised conclusion with a documented chain of reasoning. It does not wait to be asked. In a SOC context, that means an agentic system can initiate a threat investigation, correlate signals across IT and OT environments simultaneously, and surface a structured incident assessment before a human analyst has seen a single alert.
The operational difference is significant. The question is whether the system is genuinely agentic or whether that word is being used to describe a responsive AI with a better UI.
How agentic AI changes detection and response timelines
The speed argument for agentic AI in the SOC is well-made but often stated in abstract terms. The concrete version is worth spelling out.
A sophisticated attack on a complex environment generates signals across multiple tools. Endpoint telemetry shows unusual process behaviour. The network monitoring platform logs connections to unfamiliar external addresses. Identity logs record authentication anomalies. In an OT environment, there may be additional signals from industrial control systems that sit behind a separate monitoring layer.
In a SOC that relies on human-first triage, those signals arrive as separate alerts in a queue. An analyst processes them in sequence. Correlating them — recognising that the endpoint, network, identity, and OT signals are part of the same attack — requires manual investigation that takes time. If the queue is busy, that correlation may not happen for hours.
An agentic SOC runs that correlation in parallel. Cumulo deploys a council of specialist agents on every live analysis. Each agent assesses a specific dimension of the incoming signals simultaneously: endpoint behaviour, network patterns, identity data, threat intelligence context, OT telemetry. The agents share findings. A synthesised incident assessment is available to an SC-cleared analyst within minutes of the first signal. Our mean time to detect across the customer base is 13 minutes. That figure is a product of parallel agentic reasoning, not faster human analysts.
The response implication follows. An analyst receiving a structured, correlated incident assessment can make an informed containment decision in minutes. An analyst receiving a queue of separate alerts has to build that picture first. The difference in mean time to respond reflects the same underlying dynamic.
The risk of ungoverned AI autonomy in the SOC
Agentic AI that operates without governance is not a security asset. It is a risk. Three specific failure modes matter in a SOC context.
Hallucination in high-stakes decisions. Agentic AI systems can produce reasoning chains that are internally coherent but factually wrong. In a security context, that means an agent could conclude, with apparent confidence, that an indicator of compromise is present when it is not, or recommend a remediation step that causes more disruption than the threat. The mitigation is a structured validation layer between agent output and human action. Every AI conclusion should be checked before it is presented as a recommendation. Building that validation into the platform architecture is not optional: it is a design requirement.
Autonomous response with incomplete context. Agentic AI can be configured to initiate response actions: isolating endpoints, blocking connections, terminating processes. In an OT environment, autonomous response carries additional risk. Isolating a component that is part of a running industrial process may have physical consequences that a security-focused AI agent is not equipped to assess. The scope of autonomous action must be explicitly defined, environment-specific, and subject to human override. An agentic SOC that acts without clear guardrails in an OT context is not fit for purpose.
Opacity in the reasoning chain. If an analyst cannot understand why an agentic system reached a particular conclusion, they cannot verify it. An agentic SOC should produce a documented reasoning trail for every significant output: what signals were assessed, what hypotheses were considered, what evidence supported the conclusion. Without that, the analyst is being asked to trust an output they cannot interrogate. That is the wrong model.
What a well-governed agentic SOC looks like
The design principles for a well-governed agentic SOC are not complicated, but they are often not fully implemented in platforms that carry the agentic label.
- Human analysts retain decision authority on escalation and response. The AI layer triage, correlates, and recommends. SC-cleared analysts validate and decide. That division of labour should be explicit in the platform architecture, not a policy document.
- Every AI output passes through a validation step before it reaches a person as a recommendation. This is not a performance penalty: a well-designed validation layer adds seconds, not minutes. What it removes is the risk of an analyst acting on a hallucinated conclusion.
- The scope of autonomous action is explicitly defined and auditable. What the AI can act on without human approval should be written down, agreed with the customer, and logged on every execution. Actions outside that scope require analyst sign-off.
- The reasoning chain is accessible. Analysts reviewing an AI-generated incident assessment should be able to see the evidence it is based on, the hypotheses it considered, and why it reached the conclusion it did. A black-box conclusion is not a useful operational tool.
What UK organisations should look for
The agentic AI SOC market is developing quickly and the vendor claims are running ahead of the implementations. For UK organisations, particularly those in regulated sectors, several additional requirements apply beyond the general design principles above.
Data sovereignty on AI processing. Agentic AI systems process security telemetry in order to reason about it. That processing happens somewhere. For UK critical national infrastructure and government organisations, the requirement is that AI inference runs on UK-hosted infrastructure, under UK jurisdiction, with PII sanitised before data leaves a local perimeter. A vendor that cannot describe precisely where their agentic reasoning runs is not meeting that bar.
SC-cleared human oversight. The human analysts reviewing agentic AI outputs and making escalation decisions in a government or defence-adjacent environment need to be appropriately cleared. SC or NPPV3 clearance at scale is not a capability all managed SOC providers have built. It should be a stated requirement, not an assumption.
Alignment with NCSC guidance on AI in critical systems. The NCSC has published guidance on the secure deployment of AI in high-assurance environments. Any agentic SOC platform deployed in a UK regulated sector context should be assessed against that guidance. Ask vendors specifically how their platform addresses NCSC’s principles on AI transparency, human oversight, and incident response in AI-enabled systems.
Agentic AI in the SOC is not a future capability. It is operational in deployments protecting UK critical infrastructure now. The question for security leaders is not whether to engage with it, but how to evaluate it rigorously and deploy it with the governance that the environment requires.
Further reading
AI Accelerated Cyber Attacks: Six Ways the Threat Model Has Changed e2e-assure.com/ai/ai-accelerated-cyber-attacks
Mythos Defence: Why SecOps Must Move Beyond the Patch Race e2e-assure.com/ai/mythos-defence
OT Security Services e2e-assure.com/services/ot-security