Machine learning systems could help alleviate the chronic alert fatigue plaguing security operations centers, yet the question of governance looms large. The New Stack will host a CISO roundtable on September 15 to examine this tension. Interested participants can apply for one of the limited seats available.

For years, SOCs have grappled with overwhelming volumes of alerts. Artificial intelligence presents a potential solution: letting automated systems handle portions of the investigative workload themselves.

This shift is already underway. Security teams are piloting AI systems capable of aggregating data from multiple sources, analyzing anomalous behavior, and proposing remediation steps while keeping humans involved in decision-making.

The rationale is straightforward. Human analysts possess limited capacity, yet the stream of potential incidents grows without restraint. Simultaneously, adversaries are leveraging AI to accelerate their own attack cycles. Providing analysts with improved tools may prove insufficient to manage the expanding threat landscape.

Yet empowering AI systems to act with greater independence introduces a fundamental challenge: determining what degree of decision-making authority organizations should delegate to machines.

This dilemma forms the centerpiece of The New Stack's AI-Speed SOC CISO Roundtable scheduled for September 15. Security executives will deliberate on the appropriate scope for AI agent capabilities and identify scenarios requiring human judgment.

A critical distinction separates having an AI system flag a suspicious login from permitting it to deactivate the associated account. The same principle applies to endpoint isolation, traffic filtering, or other actions with immediate operational consequences. Autonomous systems could execute such responses faster and across larger environments than human teams.

Trust extends beyond the underlying algorithm. Organizations must maintain visibility into agent behavior, understand when human approval is required, and possess the ability to reverse problematic actions. This may necessitate imposing strict boundaries on what agents can do independently, including emergency shutdown capabilities if systems deviate from intended behavior.

Expanding agent responsibilities transforms the analyst role fundamentally. When AI manages routine investigative tasks, security personnel can redirect effort toward proactive threat hunting, strategic decision-making, and oversight of automated systems. The SOC analyst transitions from investigator to coordinator.

The transformation could eventually reshape the SOC's operational structure entirely. While "continuous detection and response" has become standard terminology, AI agents could make this concept tangible. Rather than treating detection, investigation, and response as discrete phases, agents could flow between them dynamically, with insights from one incident directly informing how subsequent threats are identified.

This represents more than simply layering AI onto existing infrastructure—it signals a fundamental shift in how security operations function. However, CISOs face a recurring obstacle: technology sprawl. With security teams already managing complex tool ecosystems, vendors are rushing to embed agents and AI into their platforms. Organizations risk accumulating yet another set of disconnected products rather than achieving the integrated continuous system they seek.

Join us on September 15, 2026

The roundtable will bring together Jami Hughes, deputy CISO at Zions Bancorporation, and Oren Saban, co-founder and CPO of Mate Security and former Microsoft Defender XDR and Security Copilot product lead, to examine alert fatigue, agent autonomy, the evolving SOC analyst position, and what genuine continuous security entails.

Participation is capped at 20–25 security leaders, with applications screened to maintain a focused, relevant group. This differs from standard webinar formats with large passive audiences; all attendees will actively contribute. Chatham House Rule governs the discussion, enabling participants to share perspectives openly about successes, shortcomings, and lingering uncertainties.

Apply for a seat at the table

As adversaries increasingly harness AI to accelerate their operations, security organizations must determine which response functions they're comfortable delegating to automated systems.

Source: The New Stack