When Should AI Make Security Decisions? A CISO Roundtable Examines SOC Autonomy
As AI agents begin handling security alert investigations, technology leaders face a critical question: how much decision-making authority should machines have in security operations centers?
For years, security operations centers have grappled with the sheer volume of alerts flooding their systems. Artificial intelligence now presents a potential solution: allowing automated agents to examine certain alerts and surface findings for human review rather than requiring analysts to manually investigate every signal.
This shift is already underway. Security teams are deploying AI systems capable of aggregating data across multiple platforms, analyzing questionable behavior patterns, and proposing actions back to human operators who retain final authority.
The rationale is straightforward. Analysts operate within fixed time constraints, yet the volume of potential security incidents continues to expand without similar limitations. Simultaneously, threat actors themselves are gaining access to AI capabilities that can accelerate their attack methodologies. Equipping defenders with improved tools for processing an expanding workload may prove insufficient as a long-term strategy.
Yet transitioning from AI-supported security operations to genuinely autonomous systems introduces a fundamental challenge: the question of how much authority organizations should delegate to machines.
This dilemma forms the centerpiece of The New Stack's AI-Speed SOC CISO Roundtable scheduled for September 15, where senior security executives will examine the appropriate boundaries for AI agent autonomy and where human judgment must remain decisive.
The autonomy spectrum
A meaningful distinction exists between tasking an AI agent with analyzing a questionable login attempt versus empowering it to deactivate the associated user account. The same principle applies to endpoint isolation, network access restrictions, or other interventions that could immediately disrupt business operations. An autonomous system could execute such decisions far more rapidly and across much larger environments than any human analyst could manage.
Beyond the underlying model itself, establishing trust requires additional safeguards. Organizations must maintain visibility into agent activities, establish clear protocols for human override, and ensure the ability to reverse problematic decisions. This frequently necessitates imposing strict constraints on what agents can do independently, including mechanisms to halt operations if an agent behaves unexpectedly.
Reshaping the analyst role
Expanding agent responsibilities fundamentally transforms the work of security personnel. When AI manages substantial portions of routine investigative tasks, analysts can shift away from processing endless alert queues toward proactive threat research, strategic decision-making, and supervision of the automated systems handling repetitive work. The SOC analyst transitions from investigator to coordinator.
The implications may ultimately extend beyond individual roles to reshape the SOC itself. Security professionals frequently reference "continuous detection and response" as an operational ideal, yet AI agents could render this concept more tangible. Rather than treating detection, investigation, and response as distinct sequential phases, an agent could flow between them, with insights from one investigation directly informing threat detection strategies in subsequent incidents.
This represents something beyond simply grafting AI capabilities onto existing security infrastructure—it suggests a fundamentally different operational framework. However, CISOs confront a persistent challenge: the proliferation of tools. Security organizations already manage complex vendor ecosystems, and technology providers are aggressively incorporating agent and AI features into their offerings. Organizations face the risk of accumulating yet another set of disconnected products rather than achieving the integrated continuous security system they envision.
Join us on September 15, 2026
The roundtable will bring together Jami Hughes, deputy CISO at Zions Bancorporation, and Oren Saban, co-founder and Chief Product Officer of Mate Security and former product lead for Microsoft Defender XDR and Security Copilot, to examine alert fatigue, autonomous agent capabilities, the evolving role of SOC analysts, and what genuine continuous security entails.
Participation is capped at 20–25 security leaders, with applications screened to maintain a focused, relevant group. Unlike conventional webinars accommodating hundreds of passive listeners, this session expects active engagement from all attendees. The Chatham House Rule will govern discussions, enabling participants to speak openly about successes, challenges, and remaining uncertainties.
Apply for a seat at the table
As adversaries increasingly leverage AI to accelerate their operations, security organizations must determine which response functions they can responsibly delegate to automated systems.
Source: The New Stack