A new Omdia survey commissioned by Rapid7, polling 500 security professionals, confirms what many of us in security operations have been watching unfold over the past two years: AI is no longer a pilot program in the SOC — it is the operating model. But buried under the headline numbers is a finding that should shape how every CISO structures their security program in 2026.
What the Data Actually Says
The consensus numbers are striking:
- 97% of security professionals report positive outcomes from AI in security operations
- 98% say AI reduces alert fatigue
- 95% say AI is helping address staffing shortages
If the story ended there, this would be a victory lap for SOC automation. It doesn't end there. The more consequential finding is the confidence gap between frontline practitioners and executive leadership. Analysts and engineers working hands-on with AI-assisted triage, enrichment, and investigation report strong confidence in the tooling. Executive security leaders — CISOs, VPs of security — are measurably more worried than they were before AI arrived.
Why the Confidence Gap Exists (And Why It's Rational)
After 15 years of running and advising SOCs, I can tell you this gap isn't executive paranoia — it's structural. Three dynamics drive it:
1. Executives own outcomes they can't directly observe. An analyst sees the AI correlate a phishing alert with an anomalous O365 login and close the loop in four minutes. A CISO sees a dashboard metric and a quarterly risk statement. When the board asks "how do we know the AI isn't silently missing things?", the analyst has an answer grounded in daily experience. The executive often doesn't.
2. Speed of adoption outpaced governance. Most organizations deployed AI-assisted SOC capabilities — triage copilots, automated enrichment, AI-driven detection tuning — faster than they built the validation frameworks around them. AI was adopted to solve a staffing crisis, not as a governed engineering change. That creates a legitimate accountability problem: who verifies the machine's verdicts, and against what ground truth?
3. The adversary is using the same technology. Attackers are using AI to scale phishing, accelerate reconnaissance, and generate polymorphic lure content. Executives correctly reason that if AI made their SOC faster, it made the threat actor faster too — and they're not sure which side of that equation they're on.
The Real Risk: Ungoverned Automation Becomes a Blind Spot
The operational danger isn't that AI fails loudly. It's that it fails quietly. An AI triage layer that systematically deprioritizes a class of low-fidelity alerts — say, anomalous Kerberos ticket requests or rare parent-child process relationships — doesn't generate an error. It generates silence. Frontline confidence stays high because the alerts analysts see are handled well. The alerts nobody sees never existed, as far as the metrics are concerned.
This is precisely why executive anxiety is a useful signal rather than a problem to dismiss. It's the governance instinct firing.
Executive Takeaways
Based on what we're seeing across our managed SOC engagements, here is how to close the gap without slowing down the genuine operational gains:
1. Institute AI output validation as a standing control. Sample a fixed percentage of AI-closed alerts every week for human review — including the ones closed as false positives. Measure the AI's false-negative rate the same way you'd measure a junior analyst's. If you can't state your AI triage layer's miss rate with evidence, that's the gap your CISO is worried about.
2. Build an AI decision audit trail. Every automated triage, escalation, or suppression decision needs a retrievable rationale. When an incident does occur, your IR team and your board will both ask the same question: did the machine see this, and what did it conclude? If the answer isn't logged, you're doing forensics on your own tooling mid-incident.
3. Keep human judgment on the irreversible decisions. AI should accelerate triage, enrichment, and correlation — the high-volume, reversible work. Containment actions that isolate production systems, disable executive accounts, or block business-critical network segments should retain a human approval step until your validation data justifies otherwise. Speed matters, but an erroneous automated containment of a revenue system is the kind of event that ends an AI program entirely.
4. Re-baseline your detection coverage against AI-era threats. Adversaries are generating more voluminous, better-written, and faster-moving campaigns. Validate that your detections hold up against AI-generated phishing (which defeats the classic "bad grammar" heuristics your users were trained on) and that your mean-time-to-detect is improving at least as fast as attacker dwell time is shrinking. Report both sides of that equation to leadership.
5. Close the loop between executives and the console. The confidence gap narrows fastest when CISOs get structured exposure to what the SOC actually sees — a monthly review of AI-handled incidents, including near-misses, with an analyst walking the timeline. Confidence built on proximity to the work is durable. Confidence built on vendor slideware is not.
6. Don't let staffing relief become staffing elimination. AI is absorbing alert volume, not replacing adversary intuition. The organizations getting the best outcomes are reinvesting the reclaimed analyst hours into threat hunting, detection engineering, and purple-team validation — the work AI can't yet do reliably. The 95% reporting staffing relief should translate into higher-value human work, not smaller teams.
The Bottom Line
AI in the SOC is working — the 97% number is real, and it matches what we see operationally. But the executive anxiety documented in the Omdia/Rapid7 data is not a communications problem to be managed away. It's a governance gap to be engineered away. The organizations that treat AI as a powerful but unproven analyst — one that requires supervision, audit, and measurable validation — will keep the operational gains while closing the confidence gap. The ones that treat near-unanimous positive sentiment as proof of safety are building their next incident's forensics puzzle.
Read the full report analysis at the Rapid7 blog.
Related Resources
Security Arsenal Managed SOC Services AlertMonitor Platform Book a SOC Assessment soc-mdr Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.