Torq Named a Leading Innovator in SACR 2026 AI SOC Market Report

Contents

Get a Personalized Demo

See how Torq harnesses AI in your SOC to investigate, prioritize, and respond to threats faster.

Request a Demo

Software Analyst Cyber Research (SACR) just published its 2026 AI SOC Market Report, offering an independent assessment of vendors competing in what has rapidly become the most consequential category in enterprise security. Torq features prominently, and the report’s framing is worth unpacking because it illuminates what makes the AI SOC category hard to evaluate and why Torq’s approach is consequential.

Torq’s AI SOC: From Alert Triage Through Remediation

SACR’s most pointed observation about Torq is definitional. The firm writes:

“Torq is best understood less as a conventional SOAR vendor with AI features and more as an AI SOC operating layer that can ingest alerts, classify triage outcomes, construct cases, assign work to Socrates, and route remediation through deterministic or agentic workflows depending on the use case.”

That distinction matters. Much of what gets marketed as AI SOC today amounts to copilot functionality that surfaces recommendations and draft summaries, and stops at basic triage that simply moves the bottleneck down the SOC line by an increment. SACR cuts through that framing: 

“Torq is trying to own high-volume alert triage and response closure, not simply accelerate analyst review.”

Owning closure requires a different architecture than assisting analysts. It requires accurate alert classification at scale, a context layer deep enough to support trustworthy, autonomous verdicts, case management that carries investigations forward, and response automation that can act, not just advise. But let’s circle back and dwell a bit on the first phase: autonomous alert triage.

Auto Triage: Context Is the Differentiator

Torq Auto Triage classifies incoming alerts as false positive, benign, or malicious, enriches them with threat intelligence and business context, and routes them accordingly, all before a human analyst is involved. True positives become cases automatically. False positives are fed back into the per-tenant AI model.

SACR called out the quality of Torq’s context layer directly: 

“Torq is not treating alerts as isolated artifacts. It is building a context pipeline around entities, access history, business role, device state, SaaS activity, and related evidence before determining whether an alert should be closed, escalated, or remediated.”

Three underlying capabilities power that context pipeline.

  1. Torq Reflex is a per-tenant ML model trained continuously on your team’s confirmed verdicts.
  2. Torq Recall retrieves the most relevant prior cases from your environment’s history and applies an LLM to determine how those precedents apply to the current alert.
  3. Torq Context Graph provides the unified substrate both depend on: a continuously updated map of identities, assets, networks, policies, and analyst decisions, normalized across your entire security stack.

The results speak volumes. On average, large enterprises achieve a mean time to triage (MTTT) of 1 minute, a 60x improvement over manual triage. A global biotech titan cites a 97% reduction in noise entering the SOC; imagine how much better their security analysts can focus. A well-known financial services enterprise achieved 99% faster threat triage after deploying Torq.

Case Management: The Operating Unit

When Auto Triage surfaces a true positive, it flows directly into Torq Case Management, where analysts inherit the full verdict, enrichment context, and proposed next steps. They do not reconstruct context from scratch.

From within the case interface, analysts collaborate with Torq Socrates™, trigger automated response actions, and track investigation continuity across shift handoffs. Each confirmed verdict and analyst correction flows back into Reflex as a training signal, compounding accuracy over time. 

This is the mechanism behind what SACR identifies as Torq’s stronger-than-expected investigation story: the platform captures and encodes analyst judgment, rather than relying on individual expertise to repeat the same reasoning shift after shift. The machine clears the noise. The analysts focus on the highest priority items.

Socrates: Reasoning and Orchestration

Torq Socrates is the agentic reasoning and orchestration layer at the center of the platform. It can be used interactively by analysts, embedded in investigation templates, or assigned cases autonomously. Once on a case, Socrates plans investigations, delegates tasks to specialized Torq HyperAgents™, and coordinates response actions across the security stack.

SACR characterizes Socrates as “the reasoning and planning layer that decides how much work should be agentic, how much should be deterministic, and where the human should approve or intervene.” As SACR notes, “autonomy is a dial, not a binary switch,” and Torq’s model lets security organizations operationalize that dial gradually: starting with triage and recommendation, moving into human-approved action, and eventually automating higher-confidence alert classes.

One Torq customer on PeerSpot describes the cumulative impact: Torq handles a large volume of their alerts autonomously, fundamentally changing the burden placed on their security team.

Hyperautomation: Execution Depth

Torq Hyperautomation is the execution layer that connects AI decisions to real action, supporting both agentic and deterministic workflows across the full security stack. SACR identifies this automation heritage as a structural advantage: 

“Compared with AI SOC point solutions, Torq’s advantage is the ability to connect AI decisioning to actual workflow execution.”

That advantage compounds. The same platform that classifies an alert, builds the case, and assigns it to Socrates is the platform that executes containment and remediation at machine speed. Customers have measured a 94% reduction in mean time to respond (MTTR), a metric that requires the full chain, not just faster triage at the front end.

What SACR’s Assessment Means for Buyers

SACR closes its Torq vendor profile with a synthesis that applies beyond Torq specifically: 

“Autonomous SOC value will be measured by closed-loop operating capability rather than AI summarization.” 

Verdict quality matters. But a verdict quality that does not connect to case construction, investigation, response, and organizational learning is an incomplete story. Torq’s architecture is designed around that full loop.

SEE TORQ IN ACTION

Ready to automate everything?

“Torq takes the vision that’s in your head and actually puts it on paper and into practice.”

Corey Kaemming, Senior Director of InfoSec

“Torq offers unprecedented protection and drives extraordinary efficiency for RSM and our customers.”

Todd Willoughby, Director

Compuquip logo in white

“Torq saves hundreds of hours a month on analysis. Alert fatigue is a thing of the past.”

Phillip Tarrant, SOC Technical Manager

Fiverr logo in black

“The only limit Torq has is people’s imaginations.”

Gai Hanochi, VP Business Technologies

Carvana logo in black

“Torq Agentic AI now handles 100% of Carvana’s Tier-1 security alerts.”

Dina Mathers, CISO

Riskified logo in white

“Torq has transformed efficiency for all five of my security teams and enabled them to focus on much more high-value strategic work.”

Yossi Yeshua, CISO

Turning On Torq Mode

Contents

Get a Personalized Demo

See how Torq harnesses AI in your SOC to investigate, prioritize, and respond to threats faster.

Request a Demo

Dima Kogan is Director of Product Design at Torq, where he leads the design team building Torq’s AI-powered cybersecurity products. Over 15 years in product design, including design leadership at monday.com, he’s spent his career making complex systems feel simpler to use. He writes regularly about product design, leadership, and designing in the age of AI.

Most enterprise cybersecurity products focus on functionality. That’s fine. It’s the job. But enterprise security teams spend hours inside their core products — real humans, doing really important work, seeing the same thing day after day after day.

As our platform grew, we started asking ourselves a simple question: why should powerful software have to look so…generic? We’d spent years making The Torq AI SOC Platform smarter, faster, and more capable. But visually, it still felt like it could belong to almost anyone.

Torq is known for being bold and fun — and that distinctiveness carries weight. Wear a Torq hat at a security conference, and people stop you to talk. But inside The Torq AI SOC Platform, that personality wasn’t there. We’d poured everything into functionality, and at first, the interface wasn’t really us.

Why So Serious?

Consumer software figured this out a long time ago: how a product feels is a big part of whether people stick with it. Enterprise software has been slower to catch on, and security software slowest of all.

The assumption in security has always been that personality is frivolous, or worse, unprofessional. The work is high-stakes, so the tools are built to be serious and nothing else. The result is a whole category of products that look interchangeable and feel clinical.

Our design mission made the goal clear: build products that are powerful, category leaders, and unmistakably Torq. The harder part was execution. How do you bring skeletons, lasers, and monster trucks into the leading AI SOC platform without getting in the way of the work?

Introducing Torq Mode

We started with the people who use Torq: security analysts working under real pressure, and engineers building complex workflows. The work is serious, which is exactly why the experience matters. As one engineer at AppsFlyer put it, “SecOps is a tedious, tiring job. It’s important to have some fun.”

So we got specific about how we wanted them to feel: in control, eager to build, and confident in the system, with a real sense of mastery in what they’d built. One rule anchored everything: Torq is where analysts handle critical incidents all day, so anything we added had to reinforce the experience without interrupting the work.

Thus, a third mode was born alongside Light and Dark modes. Users can choose the standard experience in Light or Dark, or the fully brand-connected one: Torq Mode.

We chose specific flows and interactions where a moment could land: places to encourage someone, mark a win, or draw attention to what matters. A few of them:

  • Switch to Torq Mode, and a pterodactyl flies across the screen to welcome you in.
  • Create your first workflow, and a skeleton fires a laser to draw it into being.
  • Close a case, and a monster truck rolls across the screen, pulling a “DONE AND DUSTED!” flag.
  • Flag a case as urgent, and the label catches fire on hover.

The Outcome

Two months of thinking, two weeks of building, and then we launched. The results surprised us: 81% of users who turned on Torq Mode kept it on, month after month. 

Customers started bringing it up in demos. One wrote: “The animations bring a lot of energy to the interface and make the experience feel more alive… a strong personality that’s instantly recognizable and memorable.” An engineer even spent his own time extending Torq Mode into more of the product, and a customer asked us to add sound effects. When people ask for more personality, not less, you’ve built something they connect with.

Beyond Functionality

Enterprise products already look alike, and the AI era will only push them closer together. AI will build faster than ever, but it won’t decide how people should feel. That part is still on us. Solving the user’s problem is the baseline; building an experience they remember is the craft. 

Torq Mode: on.

SEE TORQ IN ACTION

Ready to automate everything?

“Torq takes the vision that’s in your head and actually puts it on paper and into practice.”

Corey Kaemming, Senior Director of InfoSec

“Torq offers unprecedented protection and drives extraordinary efficiency for RSM and our customers.”

Todd Willoughby, Director

Compuquip logo in white

“Torq saves hundreds of hours a month on analysis. Alert fatigue is a thing of the past.”

Phillip Tarrant, SOC Technical Manager

Fiverr logo in black

“The only limit Torq has is people’s imaginations.”

Gai Hanochi, VP Business Technologies

Carvana logo in black

“Torq Agentic AI now handles 100% of Carvana’s Tier-1 security alerts.”

Dina Mathers, CISO

Riskified logo in white

“Torq has transformed efficiency for all five of my security teams and enabled them to focus on much more high-value strategic work.”

Yossi Yeshua, CISO

Torq SOC Brain™: The AI SOC That Learns, Not Just Remembers

Contents

Get a Personalized Demo

See how Torq harnesses AI in your SOC to investigate, prioritize, and respond to threats faster.

Request a Demo

Back in June, I wrote a blog making the case that agentic triage alone isn’t an AI SOC. The way I see it, that’s like saying triage is the only responsibility of a SOC team. But as we know, the SOC’s responsibilities extend far beyond that, and these triage-only solutions don’t investigate threats, contain them, or close cases. That work is still left to the SOC team; the bottleneck is just shifting. 

The argument is that the bar should be higher, and Torq is setting that bar. Full lifecycle coverage — across triage, investigation, threat hunting, containment, and remediation — enterprise scale within some of the largest Fortune 100 SOCs in the world, and transparent, defensible AI agents grounded in your organization’s business context all point to why Forbes, KuppingerCole Analysts, and Gartner have recognized Torq’s position at the top of the AI SOC market.

That argument still stands, but today… We’re raising the bar again. 

Introducing: Torq SOC Brain™ — the memory layer that makes Torq the only AI SOC platform that genuinely learns.

The Self-Learning Torq SOC Brain

For most “AI SOC” platforms, learning simply means that when an alert fires, the system searches through past cases, finds one that looks similar, and feeds that example into an LLM to help it make a decision. This is more retrieval than actual learning. A system that retrieves past cases from weeks ago has no memory of what decisions were made yesterday, or understands that your senior analyst treats certain scenarios differently than your Tier 1 team does. It doesn’t get better or adapt because it’s pattern matching. And that approach is going to hit the same efficiency wall every single time. 

“With Torq SOC Brain and its Torq Recall, Torq Reflex, and Torq Retrospect capabilities, the Torq AI SOC Platform truly learns how a SOC thinks, even from the years of history that predate a Torq deployment. That’s the difference between automation that treats every investigation as if it were on its own and the industry’s first SOC that gets smarter and more accurate with each completed investigation.”

– Ofer Smadari, Torq Co-Founder & CEO

Torq SOC Brain is the learning layer of the Torq AI SOC Platform… that actually learns. Every customer has it built directly into their private workspace, exclusively for their organization. It never pools customer data, never shares model parameters, and never trains one customer’s AI on another customer’s experience. It is a private intelligence layer that ensures your Torq AI SOC Platform becomes your judgment, your model, your intelligence.

Torq SOC Brain is the reason every Torq Auto Triage verdict, every Torq Socrates™  investigation, and every Torq HyperAgents™ response action gets more accurate as your team uses the platform. It’s built on three interconnected capabilities: Torq Recall, Torq Reflex, and Torq Retrospect. Together, they do something no other AI SOC platform can: turn your resolved cases, analyst decisions, and years of institutional history into a model that thinks like your team. 

Torq Recall: Memory That Actually Works

The most common form of memory in AI SOC tools is a search interface, powered by an agentic chatbot that runs stateless queries to find semantic similarities. In security, just because something looks roughly similar doesn’t mean anything; to an AI model, two hash values might look semantically close, but point to two completely different files. In a high-stakes environment, “close enough” can be catastrophic. 

Recall instead relies on structured retrieval, looking for exact, deterministic overlaps of specific security observables — IPs, file hashes, URLs, hostnames, or emails. If your team has seen an exact indicator before and documented their conclusion, Recall finds it. 

If historical cases aren’t automatically fed back into agentic decisions, institutional knowledge stays buried in closed tickets, and verdicts quickly become outdated. A case closed last week tells a very different story than one closed last year. What makes Recall truly game-changing is the understanding of the signal strength, so the AI stays focused on entities that matter. 

Recall analyzes analyst notes, weights precedents by recency, and understands that different conclusions hold different weights. And if it finds contradicting records, Recall knows when to say it’s sure and when it isn’t, rather than force an answer it cannot justify. That honesty is what builds trust in agentic decisions at scale. Triage verdicts and response actions are not based on last month’s playbook; they are grounded in how your SOC operates today and automatically applied to every alert.

Torq Reflex: Your Team’s Judgment Applied 

Often, when AI decision-making misses the mark, it simply lacks the correct context. Recall solves that problem. But research conducted by Torq Labs found that, even with all the context, all the memory, and the same facts a human analyst has, an AI model can make an incorrect decision or even contradict an earlier decision. This isn’t a data gap; it is a judgment gap between humans and machines. While Recall allows agentic verdicts to be based on your most accurate case history (i.e., the data), Torq Reflex gives the AI model access to your team’s judgment. 

Reflex is a per-tenant model that trains continuously on your team’s confirmed verdicts and corrections, engineered to operate under asymmetric risk where missing a malicious threat is considered far more costly than mislabeling a benign alert. When an alert fires, Reflex assigns a verdict and, most importantly, a calibrated confidence score — a real mathematical probability that builds trust in verdicts and makes the system safe to run.  

When confidence is high, the verdict drives automated output (e.g., filtration, case creation, prioritization, or autonomous remediation). If it isn’t high, the full analysis still runs, the agentic reasoning is documented, and the case is escalated to a human analyst for confirmation. As a result, Reflex helps improve agentic decision making with each alert, because any alert that it’s uncertain about routes back through the human-on-the-loop process you already trust. 

Whatever the analyst decides retrains the model, so every correction is worth a little more, and every verdict becomes more trustworthy. Reflex is the key to how the Torq SOC Brain actually learns and becomes more accurate over time. The longer you use Torq, the smarter the Torq SOC Brain gets.  

“The longer Torq runs in our environment, the more it sounds like our best analysts. That’s the part no other AI SOC platform delivers.”

– Director of Security Operations, Fortune 500 Financial Services

Torq Retrospect: Informed Decisions From Day Zero

Recall and Reflex drive the Torq SOC Brain to truly learn over time, becoming your own SOC model based on your own SOC judgment. But given today’s AI-augmented threat landscape, time works against SOC teams in identifying and responding to attacks now more than ever. They need an AI SOC solution that drives value now, today, not 6 months down the road. Enter Retrospect. 

Most AI SOC platforms arrive knowing nothing about the environment or how your SOC operates. Deployment is an uphill battle, early verdicts are incorrect, and analysts lose trust before the system has a chance to earn it. Retrospect makes sure you don’t start from scratch. Before Torq sees a single live alert, Retrospect normalizes all your external cases and observables, imports them from your existing case management tool, and makes that history immediately available to Recall and Reflex. Years of analyst decisions, closed cases, and documented outcomes become the foundation of the Torq SOC Brain. 

The result is an AI SOC that doesn’t just arrive informed; it’s already smarter than most deployments will hope to achieve after 6 months of production. The learning curve that kills early adoption of agentic decision making collapses entirely. Your SOC’s institutional knowledge doesn’t start accumulating on Day One; it’s already there.

What The Torq SOC Brain Looks Like In Practice

In an enterprise SOC, accuracy is dynamic. Your environment changes. AI models are upgraded. Threat actors adapt. New attack patterns emerge. Your team’s risk posture evolves with every incident you close. 

A static AI model calculates the same confidence against the same signal regardless of how many times your team has overridden it on that exact attack pattern. There is no “getting better”; it simply is what it is, never earning the trust of the human analysts responsible for defending and justifying every decision made in the SOC. 

In the 2026 AI SOC Leadership Report, 97% of respondents reported confidence in AI’s ability to address alert triage, but only 37% applied AI to the use case. The gap between confidence and adoption, the report found, is largely driven by trust. SOC leaders reported they don’t have full transparency into agentic decision-making, and therefore, can’t defend a missed alert or a false verdict. Analysts find themselves re-checking the agent’s conclusions, doubling the work, and leaving them right back where they started: buried in alerts.    

On the other hand, Torq Auto Triage has maintained 100% usage retention across all customers and a steady average MoM increase of 144% in alert volume fed into the system. Torq Auto Triage customers report a 97% reduction in alert noise, a 60x increase in triage velocity, and an improvement in accuracy score from 94% to 99% over an average three-month period. 

“Torq Auto Triage was ready for an enterprise of our scale, where a competing solution was not.”

– Global FinTech Enterprise

The Torq SOC Brain drives accuracy in agentic verdicts, acting as the primary engine and memory layer behind Torq Auto Triage. The Torq SOC Brain justifies each Torq Auto Triage verdict with crystal clear evidence and reasoning, documented and cited in the historical truth of how your SOC operates. Those verdict decisions improve in accuracy with every alert and are treated as first-class data, stored in the Torq Context Graph. This, in turn, grounds every agentic decision across the entire Torq AI SOC Platform in your organization’s most accurate and up-to-date truth. Every triage verdict becomes more confident, every investigation becomes more precise, and every autonomous threat remediation becomes more trustworthy. 

Most importantly, the Torq SOC Brain is what allows some of the largest enterprise SOCs in the world to achieve such rapid time-to-value with the Torq AI SOC Platform: 

  • “We use Torq to automate triage across multiple attack surfaces. It performs better than other solutions. [Torq’s] AI capabilities provide immediate ROI by reducing manual effort and significantly improving operational efficiency.” – Senior Cybersecurity Engineer, Tech Vendor (10,001+ employees)

Most recently, the InfoSec Director of a Fortune 100 Global Retail Enterprise, who completed a full Torq AI SOC Platform migration in only two weeks, reported: “In just three months, we’ve already accomplished so much more than we ever did in five years with [previous solution].”

Your Judgment. Your Model. Your Intelligence.

Torq has been widely recognized as a leading innovator and a dominant force in the AI SOC landscape (see Forbes, KuppingerCole Analysts, and Gartner). We set the bar for end-to-end threat lifecycle coverage, while others simply triaged threats and shifted the SOC bottleneck further down the line. 

Today, the bar is even higher. The question isn’t just whether your AI SOC completes the threat lifecycle; it’s whether it learns how your team wants it done. 

Your AI SOC should handle every alert the way your team would, and get better at it over time. That’s the Torq SOC Brain. That’s why Torq Auto Triage is the only agentic triage engine that actually learns. And that’s why the Torq AI SOC platform isn’t just the most complete AI SOC on the market; it’s the only one that becomes your organization’s own AI model. 

See it live at Black Hat at Booth #4935, or request a demo today.

SEE TORQ IN ACTION

Ready to automate everything?

“Torq takes the vision that’s in your head and actually puts it on paper and into practice.”

Corey Kaemming, Senior Director of InfoSec

“Torq offers unprecedented protection and drives extraordinary efficiency for RSM and our customers.”

Todd Willoughby, Director

Compuquip logo in white

“Torq saves hundreds of hours a month on analysis. Alert fatigue is a thing of the past.”

Phillip Tarrant, SOC Technical Manager

Fiverr logo in black

“The only limit Torq has is people’s imaginations.”

Gai Hanochi, VP Business Technologies

Carvana logo in black

“Torq Agentic AI now handles 100% of Carvana’s Tier-1 security alerts.”

Dina Mathers, CISO

Riskified logo in white

“Torq has transformed efficiency for all five of my security teams and enabled them to focus on much more high-value strategic work.”

Yossi Yeshua, CISO

The 2026 AI SOC Roadmap: Where SOC Teams Are Headed and How to Get There

Contents

Get a Personalized Demo

See how Torq harnesses AI in your SOC to investigate, prioritize, and respond to threats faster.

Request a Demo

Every conversation our team has with security leaders begins the same way. Nobody is backing off on AI in the SOC. The direction of the lean is what’s shifting.

Torq’s 2026 AI SOC Leadership Report surveyed more than 450 CISOs and SOC leaders. The data confirms what those conversations were already telling me. We’ve left the adoption phase. The market is now in the architecture phase and the implications for how teams plan, buy, and build are significant.

The first wave of AI in the SOC came down to a few questions: Does it work? Can a large language model read an alert? Can an agent investigate a case? Can autonomous reasoning extend triage without breaking trust? All three are answered. Answered well enough that 94% of security leaders now use AI in at least one SOC function, and the report found that the average SOC runs more than seven AI-powered tools at once.

The architecture phase is about different questions. Which platform anchors the operation? What gets consolidated, and what gets replaced? Where does AI extend next, and what kind of trust framework lets it? The teams moving fastest right now aren’t running more AI experiments. They’re making architectural commitments — commitments that will shape the SOC through 2026 and beyond.

Where Teams Are Expanding AI in the Next 12 Months

Two expansion frontiers stand out in the data. Both are large, both are intentional, and both point in the same architectural direction.

  1. Cloud security: 40% of security leaders plan to expand AI here in the next 12 months — the largest expansion category in the report, and it’s not close. Cloud security is the cleanest use case for AI in the SOC because it’s the area where manual coverage has fallen furthest behind operational reality.
  2. Incident response automation: 28% of leaders plan to expand AI into response. Detection automation has been broadly accepted. Response automation is the next earned step — extending AI from “tell me what happened” to “act on what happened.” It’s a smaller percentage because it’s a higher-stakes commitment, but the direction is clear.

Underneath those headline numbers is a more telling pattern. Security leaders said they want 51% of daily SOC tasks automated on average — and the teams furthest along on AI deployment are also the teams setting the highest targets for the next 12 months. That correlation is the architectural payoff. Early adopters who built on the right foundation are now expanding from it.

Why Cloud Security Leads the Expansion

Cloud security generates orders of magnitude more telemetry than legacy infrastructure. The volume problem alone forces the issue: a team that can only review a small fraction of cloud signals manually needs AI to handle the rest. Hiring doesn’t close that gap, and CISOs know it.

The second reason cloud leads AI expansion plans is configuration drift. Cloud environments change continuously — new services spun up, identities rotated, workloads scaled across regions overnight. A static playbook for cloud detection is obsolete the moment the environment changes beneath it. AI that reasons across the current state of the environment adapts in ways static logic cannot.

The third reason is that in the cloud, finding a problem and fixing it are two different jobs owned by two different teams. Security can embed control points in the delivery pipeline and continuously scan cloud assets, but it can’t remediate unilaterally — the production environment belongs to DevOps and engineering. So every finding kicks off a lifecycle: detect the issue, identify the owner, get them to commit to a fix, and validate that the fix actually resolved it. That coordination loop, not the detection, is where the enormous operational load of cloud security comes from, and it’s exactly the kind of multi-step, multi-owner work AI orchestration is built to carry.

This is the structural reason cloud security is the strongest signal in the expansion data. The architecture that handles it has to orchestrate the full remediation lifecycle across teams, not just detect within a single team.

Why Incident Response Is the Trust Frontier

Detection automation was adopted broadly because it keeps a human in the loop: the AI surfaces risk, and a person still decides what to do about it. It’s the most common error, a false positive, that costs little more than analyst time. Response automation removes that buffer — the AI acts on the environment itself, so a wrong call doesn’t just waste time, it hits production. A contained endpoint that shouldn’t have been contained breaks a workflow, a revoked credential disrupts a legitimate session, and an auto-blocked IP can take down a production service. The stakes move outside the SOC, and the trust required to cross that threshold rises with them.

The data shows leaders are ready to cross it, but only on specific terms. The conversations behind the 28% expansion number make those terms clear.

  • Transparent reasoning: Every action an AI takes must be supported by a documented chain of reasoning. Black-box decisions don’t earn trust in response, and they shouldn’t.
  • Configurable autonomy: The team decides which actions AI can take autonomously, which require human approval, and which never run without analyst sign-off. The trust model is set by the operator, not by the platform vendor.
  • Continuous learning: Actions taken under AI direction are logged, auditable, and recoverable. When an agentic verdict is overturned, the decision becomes precedent, and the system improves. 

This is the architecture we built at Torq for response automation. Agentic action earns the right to expand into incident response when the decisions behind it are grounded in organizational context, not just a siloed signal triggering a cookie-cutter response workflow. 

The Torq Context Graph makes that trust possible, giving Torq AI Agents a single source of truth to reason over before any runbook planning or execution. What is true about the environment now? What exceptions have been made since this response plan was first crafted? Every response is executed exactly as an analyst would — with context, without improvisation. 

Socrates, Torq’s AI SOC orchestrator, makes the trust boundary visible: when it encounters a step it can’t perform, it stops, names the limitation in plain language, and routes the work to a human. That’s the architecture that earns the right to expand AI into response.

What the Architecture Phase Requires

The teams that will win the next 12 months won’t be the teams with the most AI tools. They’ll be the teams with the best-architected AI platform. Three commitments separate the platforms that will define the AI SOC from the vendors that will get stuck.

1. A platform, not a stack. The report found that 80% of security leaders say their SOC is still fragmented across too many tools. The architecture phase rewards unification. The teams that pick a single platform to anchor the AI SOC and start unifying around it will move faster than the teams continuing to stitch together point solutions.

2. Trust by design. 90% of security leaders want explainable AI decisions before they’ll trust AI with more autonomy. The platforms that make AI reasoning visible — every step, every decision, every action documented — will earn the trust required to keep extending. The platforms that don’t, won’t.

3. Learning that compounds. The AI you deploy today should be measurably better six months from now, and it should be better because of your team’s specific corrections. Static AI plateaus, but adaptive AI compounds. The architectural commitment is to a platform whose returns scale with the team using it.

These are the foundations on which the architecture phase is built on. Platforms that ship them as design principles will define the AI SOC through the next few years. Platforms that bolt them on later won’t. 

The 12-Month AI SOC Playbook

Below is some concrete guidance for the security leaders reading this with a budget cycle ahead of them.

Audit the gap. Map your current AI  coverage against the end-to-end SecOps lifecycle that 89% of respondents identified as a key factor to increasing agentic trust, producing better-informed conclusions, and higher-confidence recommendations. Does your architecture cover triage, investigation, threat hunting, and response? Most AI point solutions are missing coverage, claiming to be something they are not. 

Choose your unification anchor. If your stack runs more than seven different AI-powered tools (and the data says it probably does), pick one as the unification anchor and start measuring the others against it. The architecture phase rewards conviction. Indecision rewards no one.

Extend AI into response on your terms. Pick the two highest-volume response workflows your team handles manually today. Move them to AI-led execution, with analyst oversight for actions that require it. Measure the trust gap and the operational impact over 30 days. Expand or roll back based on the data. That’s how trust gets built — case by case, with the operator in control.

The AI SOC Roadmap Through 2026 and Beyond

The architecture phase isn’t a single year of work. It’s the foundation for what the AI SOC looks like by 2026 and beyond. The decisions made over the next 12 months compound — which platform anchors the SOC, which workflows get extended into AI, which trust framework earns the team’s confidence.

The teams that get this right won’t be the teams with the most AI tools. They’ll be the teams whose AI gets measurably better the longer it runs, on a platform built for that trajectory. The 2026 AI SOC Leadership Report has the full data behind where 450 security leaders are headed — what they’re prioritizing, what they’re walking away from, and what the architecture phase looks like across industries and team sizes.

SEE TORQ IN ACTION

Ready to automate everything?

“Torq takes the vision that’s in your head and actually puts it on paper and into practice.”

Corey Kaemming, Senior Director of InfoSec

“Torq offers unprecedented protection and drives extraordinary efficiency for RSM and our customers.”

Todd Willoughby, Director

Compuquip logo in white

“Torq saves hundreds of hours a month on analysis. Alert fatigue is a thing of the past.”

Phillip Tarrant, SOC Technical Manager

Fiverr logo in black

“The only limit Torq has is people’s imaginations.”

Gai Hanochi, VP Business Technologies

Carvana logo in black

“Torq Agentic AI now handles 100% of Carvana’s Tier-1 security alerts.”

Dina Mathers, CISO

Riskified logo in white

“Torq has transformed efficiency for all five of my security teams and enabled them to focus on much more high-value strategic work.”

Yossi Yeshua, CISO

20 Questions Every Security Leader Should Ask Before Buying an AI SOC

Contents

Get a Personalized Demo

See how Torq harnesses AI in your SOC to investigate, prioritize, and respond to threats faster.

Request a Demo

Most “AI SOC” demos out there can look great. The polished dashboard, the confident verdict, the slide that says “autonomous.” A demo is built to show the platform at its best, on clean data, in a controlled environment, answering a question the vendor already knew was coming. The differences only show up after you’ve signed, when the platform meets your real stack, alert volume, and compliance requirements.

That’s why your AI SOC evaluation can’t end at the demo. The questions below are designed to surface what a polished walkthrough may hide. They’re grouped by what each cluster actually tests, with the kind of answer that should reassure you and the kind that should worry you. 

If a vendor dodges, over-promises, or answers a different question than the one you asked, you’ve learned something the demo wouldn’t have told you.

Integration and Context

A SOC doesn’t run on one tool. It runs on a stack — SIEM, EDR, identity, cloud, email, ticketing — and an AI SOC is only as good as its ability to reason across the whole stack. A platform that can’t see your whole environment will make confident decisions on partial information, which is worse than no decision at all. 

Context is what separates a verdict that’s right in general from one that’s right for you: the same login anomaly is benign for a contractor on a known VPN and critical for a finance director near the M&A data room. Ask:

  1. Does the platform integrate with your existing stack as a unified orchestration and case management layer, instead of forcing a rip-and-replace?
  2. Can it correlate signals, context, threat intelligence, and historical activity across SIEM, EDR, identity, cloud, email, and your other systems?
  3. Does it maintain a continuously updated context model, a single source of truth for your environment?
  4. Does it provide native case management, investigation timelines, and cross-tool evidence correlation?

What a strong answer sounds like: The platform layers on top of what you own, builds a living model of your environment, and continuously improves its understanding as more systems are connected.

Red flag: The vendor wants to replace tools you just bought, or treats “integration” as a one-way alert feed with no context flowing back.

Memory and Learning

When a senior analyst leaves, their judgment usually walks out with them. The same is true of most “AI SOC” tools: every alert is evaluated from scratch, and the hard-won verdict your team reached last week is buried in a closed ticket. 

A real AI SOC turns past decisions into precedent, so the platform gets sharper the longer it runs, rather than repeating the same mistakes at machine speed. If a vendor can’t explain how their system learns from your analysts specifically, what you’re buying is static automation with a better logo. Ask:

  1. Can the AI reference prior investigations, analyst decisions, and case outcomes when evaluating a new alert?
  2. Does it maintain persistent organizational memory, so analyst decisions improve future verdicts?
  3. Can it explain which prior cases, decisions, or patterns influenced a recommendation?
  4. Does it learn from analyst feedback, verdict changes, and case resolutions to calibrate confidence over time?

What a strong answer sounds like: The platform shows you the past cases behind a verdict and measurably improves as your team corrects it. 

Red flag: “It learns from feedback” with no explanation of how, or learning that lives in prompts rather than a model that actually remembers.

Action and Autonomy

This is the line most “AI SOCs” can’t cross, and it’s the one that matters most. Triage prioritizes risk; it tells you what’s real and what’s next. But if the platform then hands a to-do list to a human, it hasn’t reduced the workload. The investigation still happens by hand, the response still requires logging into another tool, and the case still closes on human time. 

A true AI SOC carries the alert through to resolution and escalates to a person only when judgment is genuinely required. Ask:

  1. Does the platform go beyond triage to autonomously investigate, contain, remediate, and close incidents?
  2. Can it update cases in real time, adapting from autonomy to escalation the moment a threshold is met?
  3. Does it support human-on-the-loop operations, where analysts step in only when needed instead of driving every workflow?
  4. Can you set adjustable autonomy levels based on severity, confidence, business context, and risk tolerance?

What a strong answer sounds like: The platform closes a meaningful share of cases end-to-end, and you control where it acts versus escalates. 

Red flag: “Autonomy” that stops at a recommendation, or an all-or-nothing switch with no dial for severity and confidence.

Customization and Control

No vendor’s out-of-the-box agents know your policies, your escalation paths, or your risk tolerance on day one. The platforms that work are the ones you can shape to your environment without a team of engineers babysitting them. 

This is also where the trust conversation lives: security leaders are right to be cautious about handing authority to a system, and the answer isn’t less automation, it’s more control over what the automation is allowed to do. Ask:

  1. Can analysts customize agent behavior, workflows, permissions, escalation boundaries, and objectives?
  2. Can they do it in natural language, without weeks of engineering?
  3. Can agents access only the systems, data, and tools an administrator explicitly authorizes?
  4. Does the platform include enterprise-grade RBAC, governance controls, approval workflows, and policy guardrails?

What a strong answer sounds like: You define each agent’s role, scope, and authority, and you can adjust it as trust grows. 

Red flag: Agents that can only be tuned by the vendor, or broad access with no granular permission model.

Transparency and Accountability

In the SOC, trust isn’t automatic… It’s earned. According to Torq’s 2026 AI SOC Leadership Report, 92% of security leaders cite at least one factor reducing their trust in AI, and black-box reasoning ranked among the top concerns, and was the number-one concern for SOC directors specifically. 

An AI that hands down a verdict without showing its work doesn’t solve the trust problem. It defers it until the first false positive takes down a production system at 2am. Transparency is also what makes the platform defensible to auditors and boards. Ask:

  1. Can the AI explain its reasoning for every verdict, recommendation, escalation, and action?
  2. Are all actions, reasoning chains, overrides, and outputs captured in immutable audit logs?

What a strong answer sounds like: Every decision comes with its reasoning and evidence, and nothing happens that isn’t logged. 

Red flag: “Trust the model” with no inspectable reasoning, or audit trails that capture outcomes but not the why behind them.

Scale and Proof

A demo runs in a sandbox. Your SOC runs in the complex real world at volume, under compliance requirements, with multiple business units and data residency rules. Plenty of new entrants look impressive on stage and fall apart on contact with that reality. 

The only real proof is production: named customers, hard numbers, and metrics a CISO can take upstairs without a caveat. Ask:

  1. Can the platform operate reliably at enterprise scale, with high alert volumes, real-time response, multi-tenancy, segmentation, and data residency support?
  2. Can it prove operational impact — MTTR reduction, case closure rates, analyst time recovered, false positives eliminated — with the metrics a CISO can take to the board?

What a strong answer sounds like: Referenceable enterprise customers and specific, verifiable outcomes. 

Red flag: Logos with no numbers, or numbers with no named customers behind them.

It All Comes Down to One Question

Read them together, and a single question emerges: Can the platform take action across your stack with reasoning you can see and controls you can govern, at the scale you actually operate? A triage-only tool answers “no” to half of these. A repackaged legacy product answers “no” to the rest.

If it can’t take action, it’s not an AI SOC. It’s one more thing to manage.

The Torq AI SOC Platform was built to answer yes to all 20. Auto Triage increases verdict velocity 60x, cutting MTTR and exposure time. Socrates builds, deploys, and orchestrates Torq HyperAgents™ across triage, investigation, response, and remediation, with transparent reasoning, adjustable autonomy, and enterprise-grade governance, all grounded in the Torq Context Graph. The platform runs more than one billion automated actions a week and is trusted in Fortune 500 production, with native metrics that a CISO can take to the board.

Ask any competitor to answer all 20. Torq does.

Survive the AI SOC Apocalypse. Read the blog series.

SEE TORQ IN ACTION

Ready to automate everything?

“Torq takes the vision that’s in your head and actually puts it on paper and into practice.”

Corey Kaemming, Senior Director of InfoSec

“Torq offers unprecedented protection and drives extraordinary efficiency for RSM and our customers.”

Todd Willoughby, Director

Compuquip logo in white

“Torq saves hundreds of hours a month on analysis. Alert fatigue is a thing of the past.”

Phillip Tarrant, SOC Technical Manager

Fiverr logo in black

“The only limit Torq has is people’s imaginations.”

Gai Hanochi, VP Business Technologies

Carvana logo in black

“Torq Agentic AI now handles 100% of Carvana’s Tier-1 security alerts.”

Dina Mathers, CISO

Riskified logo in white

“Torq has transformed efficiency for all five of my security teams and enabled them to focus on much more high-value strategic work.”

Yossi Yeshua, CISO

The Four Biggest Gaps in Today’s AI SOC Vendor Market

Contents

Get a Personalized Demo

See how Torq harnesses AI in your SOC to investigate, prioritize, and respond to threats faster.

Request a Demo

A year ago, a handful of vendors called themselves an “AI SOC.” Today, more than 100 do. The label now means whatever the person selling it needs it to mean, leaving security teams to buy very different products under the same two words.

So let’s sort the market. Beneath the “agentic” branding, most AI SOC vendors fall into one of four categories, and none of them clears the bar. Each can look capable in a demo. Each shares the same flaw: it can tell you what’s happening, but it can’t actually do anything about it.

Here’s how to spot all four, and what you should be getting instead.

1. The Triage-Only Tool

This is the most common type. A lot of “AI SOC” startups focus almost entirely on triage, and to be fair, triage is a great fit for AI. It’s repetitive, high-volume, around-the-clock work that burns analyst time and attention.

But the job doesn’t end at triage. If your AI surfaces a verdict and then hands a to-do list to a human, it hasn’t reduced the workload. It’s just reorganized it. The investigation still happens by hand, the response still requires someone to log into another tool, and the case still closes on human time.

What you actually need: End-to-end lifecycle automation that carries an alert through investigation, remediation, and closure, with native case management and autonomous resolution for the cases that don’t need a human.

2. The Legacy Tool With Bolt-On AI

A legacy product wrapped in a chatbot and a few generative copilots is still a legacy product. Layering AI on top of an aging architecture can improve the experience at the surface, but it doesn’t remove the scalability and complexity limits that were there before. The same bottlenecks remain. They just have nicer branding.

What you actually need: A platform built for agentic SecOps from the ground up, designed not only to generate insights but to take action, coordinate workflows, and drive resolution autonomously, and built for enterprise scale from day one.

3. The Black Box

Too many AI SOC vendors expect teams to trust decisions they can’t inspect, tune, or control. In the SOC, trust isn’t automatic. It has to be earned. According to Torq’s 2026 AI SOC Leadership Report, black-box reasoning ranked among the top concerns for security leaders considering AI adoption, and for SOC directors specifically, it was the number-one concern.

If analysts can’t see why the AI reached a verdict or what data it touched, adoption stalls. Opaque reasoning breeds hesitation, double-checking, and operational risk, and out-of-the-box agents have limited value if teams can’t adapt them to their own workflows, policies, and risk tolerance.

What you actually need: Transparent agent reasoning, fully customizable agents, and user-defined logic and control, so every verdict is something your team can verify, tune, and govern.

4. The Shallow Newcomer

The newest vendors flooding the market can look slick in a demo, only to fall apart under the compliance requirements and complexity of a real enterprise environment. Most operate with shallow case memory, weak organizational context, and no ability to learn from analyst decisions. Every case starts from scratch, and the judgments your team has already made get buried in tickets and Slack threads instead of informing the next verdict.

What you actually need: Decisions grounded in your organizational context, memory that improves every verdict over time, native model context protocol (MCP) support, and an enterprise-grade platform proven in Fortune 500 production, not just a demo.

The One Question That Exposes All Four

The test is simple: Can it take action? A triage-only tool, a repackaged legacy product, a black box, and a shallow newcomer all stop at the same place. They analyze, they recommend, and then they hand the real work back to your team.

If it can’t take action, it’s not an AI SOC. It’s one more tool to manage.

A true AI SOC platform runs the complete threat lifecycle — triage, investigation, response, and case closure — with the transparency, context, control, and scale that enterprise operations demand. That’s the bar. Most AI SOC vendors don’t clear it.

Survive the AI SOC Apocalypse. Read the blog series.

SEE TORQ IN ACTION

Ready to automate everything?

“Torq takes the vision that’s in your head and actually puts it on paper and into practice.”

Corey Kaemming, Senior Director of InfoSec

“Torq offers unprecedented protection and drives extraordinary efficiency for RSM and our customers.”

Todd Willoughby, Director

Compuquip logo in white

“Torq saves hundreds of hours a month on analysis. Alert fatigue is a thing of the past.”

Phillip Tarrant, SOC Technical Manager

Fiverr logo in black

“The only limit Torq has is people’s imaginations.”

Gai Hanochi, VP Business Technologies

Carvana logo in black

“Torq Agentic AI now handles 100% of Carvana’s Tier-1 security alerts.”

Dina Mathers, CISO

Riskified logo in white

“Torq has transformed efficiency for all five of my security teams and enabled them to focus on much more high-value strategic work.”

Yossi Yeshua, CISO

Surviving the AI SOC Apocalypse

SEE TORQ IN ACTION

Ready to automate everything?

“Torq takes the vision that’s in your head and actually puts it on paper and into practice.”

Corey Kaemming, Senior Director of InfoSec

“Torq offers unprecedented protection and drives extraordinary efficiency for RSM and our customers.”

Todd Willoughby, Director

Compuquip logo in white

“Torq saves hundreds of hours a month on analysis. Alert fatigue is a thing of the past.”

Phillip Tarrant, SOC Technical Manager

Fiverr logo in black

“The only limit Torq has is people’s imaginations.”

Gai Hanochi, VP Business Technologies

Carvana logo in black

“Torq Agentic AI now handles 100% of Carvana’s Tier-1 security alerts.”

Dina Mathers, CISO

Riskified logo in white

“Torq has transformed efficiency for all five of my security teams and enabled them to focus on much more high-value strategic work.”

Yossi Yeshua, CISO

Torq Reflex: Teaching the AI SOC Judgment

Contents

Get a Personalized Demo

See how Torq harnesses AI in your SOC to investigate, prioritize, and respond to threats faster.

Request a Demo

Noam Cohen is a serial entrepreneur building seriously cool data and AI companies since 2018. Noam’s insights are informed by a unique combination of data, product, and AI expertise — with a background that includes winning the Israel Defense Prize for his work in leveraging data to predict terror attacks. As the Head of Artificial Intelligence at Torq, Noam is helping build truly next-gen AI capabilities into Torq’s autonomous SOC platform.

Your analyst tells the AI that the alert is just the red team running a scheduled pen test. They told it the same thing yesterday, and the day before. It works, then it doesn’t, then it does — and that flakiness is harder to live with than a tool that’s simply, predictably wrong.

This is happening in almost every SOC that runs AI triage, and the AI isn’t broken. It just has no memory of its own decisions. It looks at each alert individually, with no idea that your team has already settled this question a dozen times over. Every shift, it starts from scratch.

We tend to file the result under alert fatigue, but that undersells it. The higher cost is what happens to trust. Once analysts stop believing what the AI tells them, they treat it as one more box to click, and the money you spent on AI triage quietly buys you nothing. Earning that trust back is the problem the whole category has to solve next, and it’s the problem the learning layer of the Torq AI SOC Platform was built for.

Where First-Generation AI Triage Stops

The first wave of “AI SOC” tools proved that a large language model can read an alert and produce a credible analysis on day one, with no prior training on your environment. That breakthrough was great (at the time), and the day-one analysis it unlocked is part of the foundation Torq builds on. But it isn’t enough. A capable AI SOC has to keep learning, and the first generation treats day one as the ceiling.

That’s because the trouble starts after day one. The model judges every alert from scratch, and when an analyst corrects it, that correction is added to the prompt rather than the model itself. So the false positive your team carefully explained on Monday comes back looking brand new on Tuesday. Researchers call this self-inconsistency, an inherent failure mode of LLMs. Your analysts call it the reason they stopped trusting the tool.

We reviewed more than 1,000 real analyst corrections across four customer environments to understand why the AI and the analyst kept disagreeing. The reasons split cleanly into two groups.

  1. About half the time, the AI was simply missing context. It flagged an admin who was authorized to do exactly what they did, or a piece of software the team already knew was safe, because nobody had told it who does what inside your walls. That kind of gap has a clear fix, described in the first two posts in our series: the Torq Context Graph and Torq Recall feed that organizational knowledge straight into the model. Together with Reflex, they form the memory and learning layer beneath every agent in the Torq AI SOC Platform.
  2. The other half of disagreements are harder to reconcile, and they’re exactly what Torq Reflex was built for. In these cases, the AI wasn’t missing information. It had access to everything the analyst did, but still landed somewhere the team wouldn’t. Sometimes it contradicted its own earlier verdicts. Other times, it just read a borderline call differently than the team did, treating a contained threat as resolved when the team’s policy was to escalate it anyway, or accepting a thin set of signals as proof when the analysts wanted more. No amount of extra data closes a gap like that, because the gap is about judgment.

Why “Learning AI” From Other Vendors Often Isn’t

Everyone in this space says their AI “learns” now, and they rarely mean the same thing by it. Usually, it comes down to one of two moves: the tool rewrites its own prompt based on your feedback, or it saves your past corrections and pulls up similar ones when a new alert looks familiar. Both are useful. Both run into the same wall.

You can’t prompt your way to consistency. There’s no instruction that makes a model with no memory return the same verdict it gave yesterday; that takes a model that actually remembers what it decided.

Your team’s risk tolerance has the same problem. Something like “we treat blocked executions as malicious” isn’t really a rule. It’s a pattern that only becomes visible once you’ve watched the team rule the same way across a pile of messy edge cases. Calibration works like that, too. Analysts learn how much evidence is enough by being wrong and adjusting, not by being told to relax.

Prompts and lookups can describe your team’s judgment well enough. But they can’t absorb it; they’re limited and inconsistent, and they offer no real confidence in the answer. That’s the line Reflex crosses.

There’s a quieter problem, too: model swapping. As providers upgrade and retire the underlying LLMs, behavior shifts beneath you. Our research shows you have to tune both the prompt and the model, but when the model changes, customer instructions rarely get retuned along with it, which creates more inconsistency and less confidence at the worst possible time. Because Reflex is a stateful model trained on your team’s own calls, it stays resilient to those model changes.

How Torq Reflex Works

The easiest way to picture it is Spotify. Out of the box, Spotify plays music that appeals broadly to everyone: the hits and the editorial playlists. That’s the equivalent of the LLM baseline, and every AI SOC ships with a version of it. Discover Weekly is the part makes Spotify feel personal, built from what you play and what you skip.

Reflex plays the role of Discover Weekly. The general model is the editorial playlist that works for any customer, while Reflex is a model trained on how your team specifically makes decisions, learning more every time an analyst corrects it. It isn’t pulling the nearest past case off a shelf. It’s a classifier that has taken your patterns on board well enough to judge alerts it has never seen before.

Walk an alert through it, and the flow is simple. The alert arrives, and Reflex — a trained language model — assigns the most likely verdict along with a calibrated confidence score. If that confidence is high, its verdict shapes the output. If it isn’t, the full LLM analysis runs, and the case goes to an analyst, just as it would if Reflex weren’t there at all. Whatever the analyst decides flows back in and retrains the model, so each correction is worth a little more than the last.

And because Reflex lives inside the Torq AI SOC Platform, a confident verdict doesn’t just label an alert and stop. It feeds Auto Triage and case creation, and then orchestrates the response from Socrates across Torq HyperAgents™. So the judgment your team teaches Reflex makes every downstream action across the full threat lifecycle more trustworthy.

That confidence number is the advantage of training a model instead of running a search. A lookup can tell you an alert resembles something a human fixed once. Reflex gives you a real, calibrated probability, which is what makes the whole arrangement safe to run. It weighs in when it’s sure and holds its tongue when it isn’t, so it can only help: anything it’s uncertain about goes right back to the pipeline you already trust.

Reflex is a purpose-built language-model design, engineered to learn from a small number of samples and to operate under asymmetric risk, where missing a malicious verdict is far more dangerous than mislabeling a benign one. The same math lets you set your own tolerance for the two kinds of mistakes. Missing a real threat hurts more than chasing a false alarm, so by default, Reflex treats a missed malicious error as the costlier one, and you can dial that weighting to match how your organization actually thinks about risk. It beats typing “THIS IS VERY CRITICAL” into a prompt and hoping the model takes the hint.

What the Data Shows

We ran Reflex against the semantic-similarity approach most “learning” platforms lean on, across those same three environments.

The number we care about most is the performance on alerts where the AI was wrong and a person had to step in. Reflex matched the analyst’s corrected verdict 92% of the time and held within about three points of that across folds. The similarity approach managed 78%. On overall accuracy, the trained model came out roughly 11 points ahead, and on the call that carries the most weight — confirming a real threat — it gained around 22 points over the baseline.

A tight spread means the result isn’t a fluke, and Reflex gets there in roughly two weeks of normal analyst feedback. The early weeks are bumpier while the model finds its feet, then it sharpens with every retraining pass. Most AI triage systems perform exactly the same on day 100 as they did on day one. Reflex draws a curve you can put in front of your board.

What It Means for Your Team

  • Fewer repeat corrections: Your analysts stop re-teaching lessons that the system should already know. A correction made once carries forward to every alert like it.
  • Consistency across shifts: The same alert lands on the same verdict, whether it’s a senior analyst at 2pm or a newer one at 3am.
  • Real confidence scores: You get a calibrated probability instead of hedge language, so high-confidence cases move fast while the genuinely uncertain cases land in front of a person for judgment.
  • Error trade-offs you control: You decide how much worse a missed threat is than a false alarm, and the model enforces it.
  • A curve you can measure: The system improves in ways you can actually report on, quarter after quarter.
  • Built for oversight: The EU AI Act‘s high-risk rules take effect in August 2026. Reflex’s confidence-based routing with a human fallback already aligns with the Act’s oversight and transparency requirements.

Your Data, Your Model

Your model is yours and no one else’s. We don’t pool training data across customers, nor do we share parameters between them. Your red team’s patterns and your policy calls never leave your tenant or quietly shape a competitor’s experience. The model works for you because you’re the one who trained it.

That’s what this series has been building toward. That same data discipline is what makes a genuine human-on-the-loop model possible. Most SOCs run human-in-the-loop out of necessity. An analyst checks the AI on nearly every alert, because there’s no reliable way to know which verdicts to trust. 

Reflex changes that calculation because it produces a calibrated confidence score grounded in your team’s own calls, it can act on the cases it’s sure about and send the uncertain ones to a person. Your analysts shift from reviewing everything to supervising the system and stepping in where their judgment actually counts. They stay on the loop, with an auditable record of what the model decided and why.

This is the final piece of our series, Context, Memory, and Learning in the AI SOC: context grounds the agents, memory gives them precedent, and learning teaches them your team’s judgment. Together, they’re the layer that makes an autonomous AI SOC something you can actually trust.

SEE TORQ IN ACTION

Ready to automate everything?

“Torq takes the vision that’s in your head and actually puts it on paper and into practice.”

Corey Kaemming, Senior Director of InfoSec

“Torq offers unprecedented protection and drives extraordinary efficiency for RSM and our customers.”

Todd Willoughby, Director

Compuquip logo in white

“Torq saves hundreds of hours a month on analysis. Alert fatigue is a thing of the past.”

Phillip Tarrant, SOC Technical Manager

Fiverr logo in black

“The only limit Torq has is people’s imaginations.”

Gai Hanochi, VP Business Technologies

Carvana logo in black

“Torq Agentic AI now handles 100% of Carvana’s Tier-1 security alerts.”

Dina Mathers, CISO

Riskified logo in white

“Torq has transformed efficiency for all five of my security teams and enabled them to focus on much more high-value strategic work.”

Yossi Yeshua, CISO

Claude Mythos Broke the SOC. Agentic AI Fixes It.

The rules of offensive security just changed. Here's what every SecOps leader needs to do about it.

Contents

Get a Personalized Demo

See how Torq harnesses AI in your SOC to investigate, prioritize, and respond to threats faster.

Request a Demo

When Anthropic unveiled Claude Mythos Preview in April 2026, the security industry felt the ground shift. First, in a controlled research environment, Mythos autonomously discovered thousands of previously unknown vulnerabilities spanning every major operating system and web browser, including flaws that had survived decades of expert human review. And perhaps most impactfully, it then developed working exploits, without human guidance, at a rate no team of human researchers could match.

At first, Anthropic withheld Mythos from public release, channeling it instead through Project Glasswing to focus the model’s capabilities on defense. Since then, on June 9, 2026, Anthropic released a public version as Claude Fable 5. Even though the full Mythos 5 model remains restricted, the implications were already clear to security leaders. The economics of finding and exploiting software flaws have collapsed. This capability, in the hands of attackers, has fundamentally altered defenders’ collective calculus.

Manual SOC processes architected in an era that predates agentic AI now teeter on the precipice of obsolescence. The urgency shifts from detection to containment and remediation. Machine-speed threats demand machine-speed response. And SOC practices must be reborn and embrace agentic AI if they are to respond at the pace this new reality demands.

The Economics Collapsed. You Know This. So Do Attackers.

Claude Mythos is remarkable not only for its detection capability, but also, and especially, what that capability means in the wrong hands. We want to be clear: this is not fear-mongering. It is a call to action.

Historically, sophisticated cyberattacks required sophisticated attackers. Identifying a zero-day vulnerability in a major browser, chaining it with a privilege-escalation flaw, and building a working exploit required years of experience, deep technical knowledge, and significant time. That barrier kept the most dangerous attacks in the hands of nation-state actors and elite criminal groups.

Mythos obliterates that barrier. Detection is now commoditized. 

Security analysts have characterized it plainly: tasks that once required specialist skills (ie, writing exploit code, understanding system architecture, using advanced attack tooling) can increasingly be automated using AI. What once separated a script kiddie from an elite threat actor was expertise. Mythos-class AI can supply that expertise on demand.

The AI-augmented low-skill attacker is born. Someone with minimal technical background can now point a capable AI at a target, receive a map of exploitable vulnerabilities, and get working attack code in return. What once took a nation-state months can now take an amateur hours. One security researcher put it starkly: handing a similarly capable model to bad actors would be “like giving script kiddies a nuclear weapon.”

We think that analogy appropriately frames the urgency. The democratization of exploitation capability is unfolding before our eyes in real time. We are asking you to break the glass and give this the attention it deserves. Now.

Manual SOC Practices Are Already Obsolete

The traditional Security Operations Center was built for a different threat landscape. Analysts triaged alerts manually, investigated incidents by hand, and escalated through human decision chains. Even as SIEM and SOAR tools added automation, the core model remained human-paced: see, think, act.

That model cannot survive in a world shaped by Mythos-class adversaries.

When attackers can generate targeted, sophisticated exploits at machine speed, the attack chain evolves faster than any human-centric operation can run. Vulnerabilities are identified, weaponized, and exploited in cycles measured in hours, perhaps even minutes, but certainly not weeks. The attacker’s tempo has permanently outpaced manual response.

The consequences are predictable: alert fatigue intensifies as detection volume spikes, critical signals get buried in noise, and analysts face an impossible triage workload. The attackers overwhelm the defenders. Triage becomes the bottleneck at exactly the moment that speed matters most.

Enterprise defenders have no choice but to adapt. The organizations that recognize this shift and act now to restructure their operations amidst this new normal will be the ones that contain Mythos-era attacks. Those who don’t will find themselves perpetually responding to breaches they could not prevent.

The Bottleneck Has Moved

Detection is no longer the hard part.

Modern threat detection has matured considerably. EDR, NDR, SIEM, and cloud security tools collectively generate enormous signal fidelity. Seeing a threat does not mean automatically neutralizing it. The bottleneck has shifted from detection to response action.

An alert fires. A SOC Analyst pulls context from five different tools, assesses scope and severity, and decides on containment. They document the recommended response action and initiate communication and coordination with the security control owner. All of this, to say nothing about whether they chose the alert that represents the greatest threat to the enterprise. Because let’s face it, the threat needle resides in an alert haystack. Maybe multiple haystacks. Meanwhile, the attacker has pivoted, moving laterally and establishing persistence. More alerts, more noise, more pressure.

Even for experienced analysts, response time falls off the adversary’s pace set by an automated, focused attack moving at machine speed. The detection sensor is not the SOC’s critical constraint; the gap between detection and action most certainly is.

Machine-Speed Threats Demand Machine-Speed Response

If the attacker is operating at machine speed, the defender must too. Easier said than done? Perhaps not as difficult as you imagine. Stay with me.

Machine-speed response does not mean removing humans from the loop entirely. Nor does it mean turning the keys entirely over to AI. It does mean restructuring operations so that humans provide critical oversight, define guardrails, and review high-stakes actions, while AI handles the high-volume, time-sensitive work that comprises a large share of security operations.

Agentic AI makes this new SOC architecture possible. Hence the term, “AI SOC.” Unlike traditional automation, which executes static playbooks, agentic AI reasons through novel situations, plans multi-step response actions, and executes across integrated systems without requiring human intervention at every step. It can triage an alert, enrich it with threat intelligence, correlate it against historical activity, determine the appropriate response, and execute containment — in seconds, at any hour, across unlimited concurrent incidents.

In a post-Mythos world, the most successful SecOps leaders will (1) structure their operations to use agentic AI to augment their human staff, (2) combine agentic AI and automation to slash MTTR, (3) balance agentic and deterministic automation for economic investment horizon optimization, and (4) build trust in agentically augmented systems through strategic scoping and small wins that build momentum.

How Torq Helps: The AI SOC Platform Built for This Moment

Torq built its AI SOC Platform for exactly the threat environment that Mythos crystallized. Recognized by Gartner® as the Company to Beat in AI SOC Agents for Threat Investigation (May 2026), Torq’s platform is purpose-engineered to close the gap between detection and response at the speed this era demands.

Multi-Agent Architecture 

The Torq AI SOC Platform runs a multi-agent system (MAS), with Socrates serving as the agentic orchestrator, overseeing specialized AI agents that work in parallel across triage, investigation, containment, and case management. Each agent accesses only the data you specify and takes only the actions you authorize, within the scope you define. All agentic reasoning and actions are documented, transparent, and auditable.

Autonomous Triage

Torq Auto Triage is the agentic engine that stops noise before it floods your SOC. Auto Triage is fully integrated with the Torq AI SOC Platform and your security stack, to (1) ingest, normalize, and analyze telemetry at machine speed, (2) reveal your biggest risks, and (3) automatically open cases for true positives. Torq has some compelling tech under the hood that learns and adapts to how your SOC operates, so our model becomes your model. Where manual triage took 60 minutes, Auto Triage completes in seconds. 

Investigation at Machine Speed. 

Cases are automatically opened within Torq Case Management. Agentic insights, timelines, and evidentiary artifacts are automatically added to each case, which serves as the single source of truth for analysts and stakeholders. Socrates leads machine-speed investigation, tasking the specialized Torq HyperAgents™ to offload gruntwork from human analysts and get to the recommended course of action quickly, in minutes, not hours.

Autonomous Response with Guardrails

With Torq, autonomous response is a controlled dial, not a binary decision of human or agent. With recommended containment and remediation plans in hand, you decide what level of automation and under what conditions makes the most sense for your enterprise. Start small, build trust, and expand as you go. We have Fortune 500 enterprises using Torq to autonomously handle 100% of Tier 1 incidents. Mean time to respond (MTTR) is reduced by an average of 94% in our enterprise installed base

Imagine what a 94% improvement in MTTR would mean for your SOC and your enterprise.

Agentic Builder for Continuous Adaptation

As the threat landscape rapidly evolves post-Mythos, Torq’s Agentic Builder enables security teams to translate human natural-language intent into production-grade AI agents and dynamic business logic. Simply, easily. What once took months is now done literally in minutes.

  • A Fortune 500 Retailer transferred four years of legacy SOAR to the Torq AI SOC Platform in days, freeing time to develop new use cases they never had bandwidth to get to before. Fully operational and deployed in under three weeks.
  • A Global Hospitality Enterprise ripped out SOAR, upgraded to the Torq AI SOC Platform, and was fully operational and deployed in six weeks.
  • A Commercial Real Estate Firm realized instantaneous value on Day 1, and now 60% of phishing cases are handled fully autonomously

New attack patterns demand new responses; Agentic Builder makes that adaptation achievable.

The Mythos moment dramatically reduced the barrier to entry to sophisticated attacks, compressed timelines, and raised the volume of what defenders must handle. The Torq AI SOC Platform was built to absorb that pressure, so your analysts can focus on what AI cannot replicate: human judgment, strategy, and context-aware oversight at the edge of the unknown.

The Clock Is Running

Claude Mythos is a preview of the threat environment that is coming. In some ways, this threat environment is already here. Attackers with AI assistance can already find, weaponize, and deploy exploits at a pace that manual SOC operations never anticipated and simply cannot match. The organizations that respond by building agentic defense capabilities that now work alongside their human experts will be significantly better positioned than those waiting for the next incident to prompt action.

The bottleneck has moved from detection to response. The economics of sophisticated attacks have collapsed. The SOC clock is running. The right time to build a machine-speed defense was before Mythos. The second-best time is now.

To learn more about how Torq’s AI SOC Platform can help your team meet the Mythos moment, get a demo.

SEE TORQ IN ACTION

Ready to automate everything?

“Torq takes the vision that’s in your head and actually puts it on paper and into practice.”

Corey Kaemming, Senior Director of InfoSec

“Torq offers unprecedented protection and drives extraordinary efficiency for RSM and our customers.”

Todd Willoughby, Director

Compuquip logo in white

“Torq saves hundreds of hours a month on analysis. Alert fatigue is a thing of the past.”

Phillip Tarrant, SOC Technical Manager

Fiverr logo in black

“The only limit Torq has is people’s imaginations.”

Gai Hanochi, VP Business Technologies

Carvana logo in black

“Torq Agentic AI now handles 100% of Carvana’s Tier-1 security alerts.”

Dina Mathers, CISO

Riskified logo in white

“Torq has transformed efficiency for all five of my security teams and enabled them to focus on much more high-value strategic work.”

Yossi Yeshua, CISO

Context, Memory, and Learning in the AI SOC

SEE TORQ IN ACTION

Ready to automate everything?

“Torq takes the vision that’s in your head and actually puts it on paper and into practice.”

Corey Kaemming, Senior Director of InfoSec

“Torq offers unprecedented protection and drives extraordinary efficiency for RSM and our customers.”

Todd Willoughby, Director

Compuquip logo in white

“Torq saves hundreds of hours a month on analysis. Alert fatigue is a thing of the past.”

Phillip Tarrant, SOC Technical Manager

Fiverr logo in black

“The only limit Torq has is people’s imaginations.”

Gai Hanochi, VP Business Technologies

Carvana logo in black

“Torq Agentic AI now handles 100% of Carvana’s Tier-1 security alerts.”

Dina Mathers, CISO

Riskified logo in white

“Torq has transformed efficiency for all five of my security teams and enabled them to focus on much more high-value strategic work.”

Yossi Yeshua, CISO