The security operations center is being rebuilt around software that does not wait for a human to click. In the space of two release cycles, the largest security platforms moved their AI from assistant to operator. Palo Alto Networks shipped Cortex AgentiX to build and govern autonomous security agents, SentinelOne made one-click agentic investigations generally available, and CrowdStrike extended Charlotte AI into an agentic workforce that coordinates with third-party agents. The SOC is becoming a place where agents triage, investigate and remediate, and the analyst job is shifting from doing the work to supervising the machines that do it.

What an agentic SOC actually does

The mechanism is a step beyond the AI copilots of the last two years. A copilot summarizes an alert and suggests a next step. An agent executes the investigation. Palo Alto’s Cortex AgentiX, built on its XSOAR automation engine, ships prebuilt agents for threat intelligence, email, endpoint, network and cloud investigation, wired to more than 1,000 integrations with native Model Context Protocol support so the agents can pull from the tools a SOC already runs. Palo Alto says the platform was trained on 1.2 billion real-world playbook executions and claims up to a 98 percent reduction in mean time to remediation and 75 percent less manual work for analysts. Whether those figures hold in production is the open question, but the architecture is unambiguous: the agent owns the workflow end to end, not just the summary.

The whole field moved at once

This is not one vendor’s bet. At RSAC 2026 SentinelOne made its Purple AI Auto Investigation generally available, letting an analyst launch a complete agentic investigation with a single click, and extended Purple AI to run on third-party data from Zscaler, Okta, Palo Alto, Proofpoint, Fortinet and Microsoft, so the agent reasons across the stack rather than one vendor’s telemetry. CrowdStrike, which used its Fal.Con stage to declare the agentic era, built Charlotte AI into an agentic security workforce that connects and collaborates with trusted third-party agents. Three of the largest platforms describing the same future in the same months is the signal: agentic operations is becoming the default architecture of the SOC, not a premium add-on.

Advertisement

CyberTech Your brand belongs here. Reach the decision-makers who read CyberTech every day. Premium placements across the site and newsletter. Advertise with us

Why the SOC was ready for this

The pull is structural. Security teams have faced the same two problems for a decade: too many alerts and too few analysts. Tier-1 triage is repetitive, well-documented work, exactly the kind of bounded task an agent can run against a playbook. The economics that made copilots attractive, fewer hours per investigation, become far more compelling when the agent closes the loop instead of handing it back. And as attackers automate, defenders adopting agents is partly a speed race, because a human-paced SOC cannot match a machine-paced adversary.

The control problem nobody is hiding

The honest part of these launches is that the vendors are selling control as loudly as autonomy. “Unleashing autonomous agents without tight control is a recipe for disaster,” said Gonen Fink, Palo Alto’s EVP of Cortex products, pitching AgentiX’s role-based access, human-in-the-loop approvals and full auditability. That framing is a tell. An agent that can remediate can also act on a poisoned signal, quarantine the wrong system, or be manipulated by an attacker who understands its playbook. The agents become part of the attack surface they defend. The danger is not that agentic tools do nothing, it is that they do something fast, at scale, on bad input, before a human notices. Governance, not capability, is the hard problem.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

What it means for the security leader

Treat agentic operations as a delegation decision, not a tooling upgrade. Three questions follow. First, where is the human-in-the-loop gate, and is it on the actions that are hard to reverse such as remediation, quarantine and account disable, rather than only the read-only steps? Second, can you audit every agent action after the fact, and is that audit trail itself protected from tampering? Third, what is the agent’s blast radius if it acts on a false or manipulated signal, and have you tested that case rather than only the happy path? Measure the vendors’ remediation claims against your own environment, and watch the agents as you would a new junior analyst with production access. The leverage is large, and so is the cost of an autonomous mistake. Track the shift in Threat Intelligence.

Related: Agentic AI Arrives in Security Operations as Vendors Ship Autonomous Investigation Tools