{"id":135047,"date":"2026-08-10T14:53:18","date_gmt":"2026-08-10T14:53:18","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/135047\/"},"modified":"2026-08-10T14:53:18","modified_gmt":"2026-08-10T14:53:18","slug":"agentic-soc-alliance-wants-to-set-rules-for-ai-cyber-defense","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/135047\/","title":{"rendered":"Agentic SOC Alliance Wants To Set Rules For AI Cyber Defense"},"content":{"rendered":"<p><img decoding=\"async\" class=\" top-image\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/08\/1786373598_349_0x0.jpg\" alt=\"Agentic SOC\" data-height=\"1415\" data-width=\"4530\" fetchpriority=\"high\" style=\"position:absolute;top:0\"\/><\/p>\n<p>The Agentic SOC Alliance is trying to answer a question cybersecurity companies have mostly skipped in their rush to sell artificial intelligence: What should an agent actually be trusted to do? The recently announced Agentic SOC Alliance is trying to bring order to one of cybersecurity\u2019s fastest growing categories. Announced ahead of Black Hat USA 2026 with 15 founding members, including ExtraHop, CrowdStrike, TENEX.AI, Torq, Dropzone AI and LangChain, the group wants to define and test a common operating model for agentic security operations. The group plans to test a common operating model for agentic security operations built around three layers called Context, Harness and Model.<\/p>\n<p>Security vendors are already asking companies to trust AI agents with increasingly sensitive work. Some agents summarize alerts. Others investigate incidents, query systems and recommend containment. The most ambitious can act inside live environments. Without common standards for evidence, permissions and accountability, buyers may struggle to tell the difference between useful autonomy and risky automation.<\/p>\n<p>The bigger question is whether the industry can agree on what a trustworthy agentic SOC should look like before the term becomes just another marketing label. The alliance is betting that shared architecture, clearer benchmarks and better controls can give CISOs a way to judge which systems deserve more authority and which ones do not.<\/p>\n<p>What Counts As An Agentic SOC?<\/p>\n<p>Richard Rogers, chief marketing officer of TENEX.AI, said the biggest problem may be that vendors are using the same label for products with very different capabilities.<\/p>\n<p>\u201cThere\u2019s no real definition of an Agentic SOC,\u201d Rogers said at Black Hat. One goal of the alliance, he said, is establishing \u201cwhat the bar is to call yourself\u201d an agentic security operation.<\/p>\n<p>A product that summarizes alerts is different from one that investigates an incident. An agent that can disable an account or isolate a machine creates another level of risk entirely.<\/p>\n<p>ExtraHop\u2019s proposed architecture tries to separate those jobs. Context supplies information about identities, devices, workloads and network activity. The Harness controls what an agent can access and which tools it can use. The Model is focused on doing the reasoning.<\/p>\n<p>Rogers said autonomous security needs \u201cone good source of truth for identity,\u201d coupled with reliable information from the network and endpoints. The goal is to give agents an auditable factual base rather than asking a model to reconstruct attacks from disconnected evidence. The problem is familiar to anyone who has seen good quality security tools work with a broken dashboard. Better models and tools do not fix bad gauges.<\/p>\n<p>Changes In Cybersecurity\u2019s Speed Limit<\/p>\n<p>\u201cWe believe we\u2019re in a new paradigm in cybersecurity,\u201d Foster said. After 34 years in the industry, he still sees the old contest between attackers and defenders. What changed, he said, is \u201cthe exponential speed of change.\u201d<\/p>\n<p>Foster pointed to a recent exercise with Armadin, the company founded by former Mandiant CEO Kevin Mandia. TENEX executives said the test deployed 20,000 agents and generated roughly 231 billion logs. Rogers said the broader exercise involved about 1.3 million attack attempts. Foster said the data from the exercise could have taken a typical organization months to work through manually.<\/p>\n<p>While there haven\u2019t yet been independent benchmarks or audits on this sort of activity, the underlying point is that automated attacks can create more activity than a human security team can investigate one alert at a time. Foster thinks that same automation could help smaller companies close part of the defensive gap with enterprises that spend tens or hundreds of millions of dollars on security.<\/p>\n<p>\u201cHow does the 10 person credit union accomplish some of those things?\u201d he asked. \u201cArtificial intelligence is shrinking the gap.\u201d<\/p>\n<p>That could become one of the more significant economic arguments for the agentic SOC. AI is not merely a way for a large bank to make a sophisticated security operation faster. It could give a manufacturer, regional business or credit union access to investigation capabilities it could never afford to staff around the clock.<\/p>\n<p>Foster said emerging companies like theirs aim to make cyber defense \u201cbetter, faster, and more cost effective,\u201d with all three conditions required.<\/p>\n<p>The Alliance Is Entering A Crowded Race<\/p>\n<p>The AI markets are getting increasingly crowded and noisy. Gartner has explicitly warned about \u201cagent washing,\u201d where vendors relabel assistants, chatbots or conventional automation as agentic AI. Gartner analyst Anushree Verma said, \u201cMost agentic AI projects right now are early stage experiments or proof of concepts that are mostly driven by hype.\u201d Gartner predicts more than 40% of agentic AI projects will be canceled by the end of 2027, citing costs, unclear value or weak risk controls.<\/p>\n<p>That problem is already showing up in analyst research. \u201cIt\u2019s difficult to trust a technology that won\u2019t always answer in the same way,\u201d Forrester principal analyst Allie Mellen wrote. She argues that buyers should scrutinize accuracy, repeatability, explainability and how vendors validate their systems.<\/p>\n<p>ExtraHop and TENEX are hardly alone in the objectives to put AI and agentic operations at the center of security operations.  CrowdStrike launched its Charlotte AI AgentWorks ecosystem in March, letting customers build and manage security agents on the Falcon platform. CrowdStrike described the goal as an agentic SOC where humans are amplified by agents rather than replaced by them.<\/p>\n<p>CrowdStrike and IBM announced a separate collaboration around Charlotte AI and IBM\u2019s Autonomous Threat Operations Machine, aimed at coordinating machine speed investigation and containment. That still leaves substantial room for Agentic SOC Alliance. Its members include companies that may eventually fight for the same security budgets.<\/p>\n<p>Governments are reaching a similar conclusion. In May, CISA, the NSA and other Five Eyes cyber agencies issued joint agentic AI guidance calling for human control points around high-risk actions. The agencies acknowledged that methods for evaluating agentic systems are still developing.<\/p>\n<p>Useful standards such as those proposed by the Agentic SOC Alliance fit this gap by telling buyers how often an agent reaches the right conclusion, how much evidence supports its decision, when a human intervenes and what happens after the machine makes a mistake. Cybersecurity vendors have spent the past year proving they can build agents, but now they need to prove those agents deserve authority and provide lasting business value.<\/p>\n","protected":false},"excerpt":{"rendered":"The Agentic SOC Alliance is trying to answer a question cybersecurity companies have mostly skipped in their rush&hellip;\n","protected":false},"author":2,"featured_media":135048,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[179,7493,67011,24,330,67015,67016,67012,67014,21767,67013],"class_list":["post-135047","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-agentic-ai","tag-agentic-artificial-intelligence","tag-agentic-soc-alliance","tag-ai","tag-crowdstrike","tag-eric-foster","tag-extrahop","tag-foster","tag-richard-rogers","tag-soc","tag-tenex-ai"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/135047","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=135047"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/135047\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/135048"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=135047"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=135047"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=135047"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}