AI and the defender: augmentation, not replacement
The promise sold at every vendor stand is the autonomous SOC. The work that actually keeps an organisation standing still runs through a person reading the screen at midnight.
A SOC analyst picks up a Tuesday night shift. The board lights up at 23:40 with an alert the triage model has already scored as high risk: an account that authenticated from a new device, then started pulling files it had never touched. The model has written a tidy summary. It has even drafted the containment steps. Everything points one way.
She does not click approve. She reads the account name again, checks the rota, and remembers that the person it belongs to flew out for a conference yesterday, on a new work laptop the service desk issued in a hurry. The new device is real. The file access is the person doing their job from a hotel. The model was confident and wrong, and a confident, wrong containment action would have locked out a colleague mid-presentation and started a 2am incident bridge over nothing.
This is the actual shape of AI in cyber security in 2026. Not a machine that defends on its own. A machine that gets the analyst to the right question faster, and a person who decides what the answer means.
What the models are genuinely good at
The honest case for AI in defence is narrow and real. Large parts of security work are reading. Reading logs, reading alerts, reading malware that has been deliberately obfuscated, reading a thousand near-identical phishing reports to find the three that matter. People are slow at this and get tired. Models are fast and do not.
Triage is the clearest win. A model that clusters related alerts, drops the obvious false positives, and writes a first-pass summary gives an analyst back the scarcest thing she has, which is attention. The annual breach reporting from Verizon (the DBIR) has shown for years that attackers move quickly once inside, often within hours, so anything that shortens the time a defender spends orienting is time taken straight off the attacker’s lead.
Detection of anomalies at scale is the second. A person cannot watch every endpoint. A model can hold a baseline of normal behaviour across thousands of them and flag the drift. The NCSC has written plainly that AI lowers the barrier to entry for attackers and raises the volume of plausible attacks, which means the defender’s side needs the same force multiplier just to stay level.
Drafting is the quiet third. The detection engineer who writes a rule, the responder who writes the incident note, the leader who writes the board summary: a model that produces a competent first draft of any of these frees an expert to do the part only an expert can do, which is check it.
Where it fails, and why that matters
The failures are not edge cases. They are structural, and the analyst on the night shift met all three at once.
A model is confident in the same tone whether it is right or wrong. It does not know what it does not know. The summary that named her colleague as a threat was written with exactly the same assurance it would have used for a genuine intrusion. A defender has to read the output as a hypothesis to test, never as a verdict to action.
A model has no memory of your organisation that you did not give it. It did not know about the conference, the rushed laptop, or the fact that this person changes devices twice a year. ENISA’s threat reporting keeps returning to context as the thing that separates a real signal from noise, and context is precisely what lives in people, rotas, and corridor conversations rather than in the logs.
A model cannot be held to account. When a containment action takes down a production system, a regulator, a board, and an affected customer all want a named human who decided and who can explain. Accountability does not delegate to software. That alone keeps a person in the loop on anything that carries weight.
And the same capability runs the other way. The attacker now has the drafting engine too, writing cleaner phishing in flawless English and adapting malware faster. The arms race did not pause for the defender to catch up.
The skill that AI makes more valuable, not less
If the model handles the reading, what is left for the person? Judgement. The exact thing the night-shift analyst used. Knowing which alert is worth a phone call. Knowing when a confident summary smells wrong. Knowing the difference between a breach and a colleague at a conference.
That skill gets more valuable as the volume rises, not less. The defenders who thrive in an AI-heavy SOC are the ones who treat the model as a very fast, very literal junior who has never met anyone in the building. They take its speed and supply the judgement it cannot have. The skills reporting we publish each year points the same way: organisations are not short of tooling, they are short of people who can decide.
So the question for any leader is not whether to adopt AI. The volume of attacks settles that. The question is whether the people in the loop are given the time, the training, and the standing to overrule the machine when it is wrong, because that override is where the defending actually happens.
Naming the people the machine cannot
A model will never put a name on the work. It cannot tell you who stayed calm when the board lit up, who made the unpopular call to wait, who read the summary twice and saved a colleague from a 2am lockout. Those decisions leave almost no trace in a log, which is exactly why they go unrecognised by the systems built to read logs.
That is the gap a merit-based award is built to close. We read the work a person did, not the volume of alerts their tooling processed. We score it against published criteria, judged by an independent panel, never bought. The analyst on the Tuesday night shift is the archetype of everyone this programme exists to find.
If you work alongside a defender whose judgement holds when the machine gets it wrong, you can put their name forward for recognition that is earned and never purchased.
AI in cyber security
Will AI replace cyber security analysts?
No. AI handles the reading and drafting at speed, but it is confident even when wrong, lacks the context a person holds about their own organisation, and cannot be held accountable for a decision. The analyst’s judgement becomes more valuable as alert volume rises, not less.
How do attackers use AI in cyber security?
Attackers use the same models to write more convincing phishing in fluent language, to adapt malware faster, and to lower the skill needed to run an attack. The NCSC has described this as raising both the volume and the plausibility of threats, which is why defenders need comparable tooling to stay level.
What should a security team keep humans in the loop for?
Any consequential or irreversible action: containment that could take down production, account lockouts, and anything a regulator or board would later expect a named person to explain. A model can recommend; a trained defender should decide.
Where does AI add the most value in a SOC?
Triage, anomaly detection at scale, and drafting routine writing such as detection rules and incident notes. Each gives the analyst back attention, which is the scarcest resource on a busy shift.