The new category defined by Gartner as 'AI SOC Agents'. Analyzing massive overseas investments and primary sources to understand why the true essence of AI adoption is not workforce reduction.

If you want to research AI SOC basics, please refer to How it works and the difference from traditional SOCs. If you are comparing implementations, see PoC Evaluation Items & Fill-in-the-Blank Checklist. We have also outlined the steps to evaluate cost and structure. In this article, we examine how the role of the analyst is changing.
"If security operations become AI-driven, will SOC analysts lose their jobs?" This concern is frequently heard from both executive management and frontline staff. Some industry media outlets present the narrative that "AI agents will replace Tier-1 analysts," even framing security investment decisions solely as a "means for headcount reduction."
However, a close look at primary industry data reveals the exact opposite trend. AI is handling the mechanical primary investigation and triage—areas where human analysts have historically faced continuous burnout. Final judgment and accountability remain, and indeed are more than ever, human responsibilities. This article outlines this structural shift to a "Human-led, AI-driven" model using public data and international case studies.
The Reality of the SOC: The Exhausting Human-Centric Structure Has Reached Its Limit
First, we must acknowledge that traditional SOC operations are losing sustainability.
According to the 2025 edition of the "Voice of the SOC Analyst" survey by security automation company Tines, 71% of SOC analysts experience burnout, and 64% are considering changing jobs. Furthermore, a report from the SANS Institute indicates that 62% of organizations face challenges with retention, taking an average of 7 months to hire for a SOC role, with 15% of leaders stating it takes "more than 2 years."
Thus, the question is not "Will AI steal human jobs?" The real issue is that humans can no longer endure the work of processing massive amounts of alerts 24/7/365. Sifting through mountains of false positives, correlating logs, and closing most as "no anomaly"—this repetitive cycle exhausts talented staff, creating a high-turnover loop where hired talent does not stay. The debate around AI must be understood as a response to this structural deadlock.
How the Industry is Moving: Gartner's Definition and Massive Investments
The product category "AI SOC Agents" emerged in this context.
In its October 2025 report, "Innovation Insight: AI SOC Agents" (by Eric Ahlm and Jeremy D'Hoinne, analyzing over 25 vendors), Gartner defined AI SOC Agents as "AI software that assists analysts in executing common SOC workflows, such as alert triage, alert enrichment, guided investigation, timeline reconstruction, attack path mapping, and executive/audit incident summarization." Notably, major use cases include "operational oversight"—which is human operational oversight itself. Right from the definition stage, the category assumes human involvement.
Market movement is rapid. Funding for agentic AI startups reached $2.66 billion across 44 deals from January to April 2026 alone, up over 140% year-on-year. Looking at specific examples, 7AI (founded by the creators of Cybereason) raised a $130 million Series A led by Index Ventures in December 2025—one of the largest in cybersecurity history. According to their announcement, 7AI uses over 60 autonomous AI agents to achieve a "95–99% reduction in false positives" and an "80% reduction in Tier-1 response time." Similarly, Dropzone AI (which raised a $37 million Series B in July 2025) reported reducing alert investigation times from 25 minutes to between 3 and 10 minutes, autonomously closing 90% of Tier-1 tickets.
An important detail here is the philosophy of these pioneering vendors. 7AI clearly states its product philosophy: "AI agents augment, rather than replace, humans." It is no coincidence that the players driving the most radical AI implementations champion "augmentation" rather than "replacement."
A Frank Answer to "Can We Cut Headcount?"
Some readers may think, "Ultimately, that is vendor sales talk, and the executive goal is headcount reduction." We must address this concern directly.
First, AI does not replace judgment. Technical explanations from multiple vendors, including Intezer, BlueVoyant, and Panther, agree on this point. High-impact actions such as wiping endpoints, disabling accounts, and escalating major incidents to executives have severe business consequences if executed incorrectly, and should never bypass human-in-the-loop approval. Humans must pull the trigger based on the evidence rapidly gathered by AI.
Second, there is the issue of accountability. If the AI's reasoning remains a black box, you cannot explain "why this alert was closed" or "why this response was chosen" during audits or compliance reporting. This is why Gartner's definition includes "executive/audit incident summarization" and "oversight." Reviewing AI findings, translating them into organizational context, and explaining them to management and auditors becomes even more critical after implementing AI.
Third, handle metrics with caution. While there are reports of a "60% reduction in MTTR" or cases where response times dropped from 75–90 hours down to 18–25 hours, these are primarily vendor-published figures and are highly subject to environmental variables. Any purchasing decision requires verification of whether similar results can be achieved within your own alert environment.
Redesigning Roles: AI for Exploration, Humans for Judgment
Based on the above, the true value of AI SOC Agents is not just an extension of automation tools, but a redesign of role distribution within the SOC.
AI-driven domains: Primary investigation, alert enrichment (correlating threat intel and asset data), gathering evidence for hypothesis testing, and timeline reconstruction. This handles the fast, high-volume, and repetitive tasks that wear down humans.
Human-led domains: Final judgment, strategic prioritization of responses, approval of critical actions, and communication with auditors and management. This handles tasks requiring context and accountability.
This is the hybrid operating model of "Human-led, AI-driven." From an analyst career perspective, it marks a shift from processing tickets to a higher-level role of validating AI findings, making decisions, and directing organizational action. It represents a realistic solution to the talent retention crisis in the industry.
The Yagura Approach
The design philosophy of Yagura's AI SOC is centered on this "Human-led, AI-driven" model.
Yagura includes its own SIEM data lake platform, on top of which AI agents automatically run primary alert investigations. From detection to evidence gathering, log correlation, and investigation summary generation, the process is completed in about 10 minutes. This allows analysts to begin their work directly from the decision-making stage based on pre-investigated materials. If containment is deemed necessary, account suspension or endpoint isolation can be executed in seconds via APIs across various security products, though high-impact actions still require human approval. Furthermore, the system continuously learns from analyst feedback to adapt its investigation accuracy to environment-specific false positive patterns.
While the metrics of overseas vendors mentioned earlier are case studies based on their respective announcements, the direction is shared. Entrust exploration and evidence gathering to AI, and keep judgment and accountability in human hands. We believe maintaining this boundary is key to balancing security outcomes with operational control.
Conclusion: The Real Question is Not "Can We Cut Headcount?"
The question to ask in the age of AI agent SOCs is not "How many people can we cut?" but "How should we allocate the limited time of our security talent?"
By delegating the repetitive tasks that cause burnout to AI, humans can focus on areas where their expertise counts: judgment, strategy, and communication. This is not a story of headcount reduction, but a structural shift that makes unsustainable SOC operations sustainable. As symbolized by Gartner's inclusion of "oversight" in its category definition, humans are integrated into the final design of the AI SOC from the start.
When reviewing your SOC and security operations, we recommend designing "where to keep human judgment and how to ensure explainability" at the same time you decide "what to automate with AI." That design will make or break security operations in the AI era.
Related Service: Augment rather than replace analysts. Click here for details on the AI SOC agent Yagura AI SOC.
References
Gartner, "Innovation Insight: AI SOC Agents" (October 16, 2025): https://www.gartner.com/en/documents/7075998
Calcalist Tech, 7AI Series A Funding Report: https://www.calcalistech.com/ctechnews/article/sj2b4zkzzx
7AI Blog, Funding Announcement: https://blog.7ai.com/citing-the-agentic-security-inflection-point-7ai-raises-largest-cybersecurity-a-round-in-history-to-bring-ai-security-agents-to-enterprises
7AI Blog, "The Future of Security Operations: Understanding AI SOC Agents": https://blog.7ai.com/the-future-of-security-operations-understanding-ai-soc-agents
GeekWire, Dropzone AI Series B Funding Report: https://www.geekwire.com/2025/seattle-startup-dropzone-raises-37m-to-supercharge-its-ai-soc-analyst-security-software/
Gravity, AI Agent Funding Tracker: https://gravity.fast/blog/ai-agent-funding-tracker-q3-2026/
Tines, "Voice of the SOC Analyst" (2025): https://www.tines.com/reports/voice-of-the-soc-analyst/
SANS Institute, "It's Time to Break the SOC Analyst Burnout Cycle": https://www.sans.org/blog/it-s-time-to-break-the-soc-analyst-burnout-cycle
Gruve, "Reducing MTTR with AI": https://gruve.ai/blog/reducing-mttr-with-ai-the-soc-automation-imperative/



