Logo
FrontierNews.ai

15 Security Companies Just Agreed on How AI Agents Should Run Your SOC. Here's Why That Matters.

Fifteen major security and AI companies have banded together to define a shared blueprint for how artificial intelligence agents should operate in security operations centers, marking a significant shift toward standardized autonomous defense. The Agentic SOC Alliance, launched by ExtraHop, includes CrowdStrike, LangChain, Torq, Intezer, and twelve other industry players working to establish common architectural standards before any single vendor's approach becomes dominant.

Why Are Security Teams Suddenly Rethinking How AI Agents Work?

The core problem is simple but urgent: attackers now operate at machine speed, automating reconnaissance, exploit development, and lateral movement across networks. Yet most security operations centers still rely on workflows designed for human analysts, where teams queue alerts, enrich them, triage them, investigate them, and escalate them one by one. That model is too slow.

ExtraHop's Chief Executive Officer Greg Clark explained the stakes: "Post-Mythos AI has fundamentally changed cyber defense. Adversaries now operate at machine speed, yet most security operations are still built on architectures designed for a human-paced world." He added that the industry needs "a blueprint for how autonomous security should operate that combines real-time context, intelligent orchestration, and specialized AI agents into a new operating model".

The challenge isn't just deploying AI agents; it's deploying them in ways that actually reduce analyst workload rather than simply generating more alerts and false positives. Many current AI systems in security operations still force analysts to verify questionable outputs and chase dead ends. The alliance's model is intended to prevent that by ensuring agents work from richer evidence and within clearer controls.

What Does This Three-Layer Architecture Actually Do?

The Agentic SOC Alliance is built around three interconnected layers that members say should underpin any autonomous security operation:

  • Context: The real-time evidence an AI system uses to make decisions, combining data from networks, endpoints, identities, and threat intelligence into a structured representation that agents can query directly rather than relying on fragmented logs alone.
  • Harness: The orchestration and governance layer that manages workflows, tool use, memory, permissions, human approval, and audit trails, allowing customers to swap underlying AI models without rebuilding the governance around them.
  • Model: The reasoning engine that can be swapped as systems evolve, meaning organizations aren't locked into a single vendor's AI approach.

This separation is intentional. By decoupling governance from the underlying AI model, customers could theoretically change models without redesigning their entire security operations from scratch. Karan Singh, Head of Partnerships at LangChain, explained the practical benefit: "Better models alone don't get an agent to production. The harness does. We built LangGraph to govern what an agent can do with its evidence, which context it reads, which actions it takes, when a human signs off, and LangSmith to test its trajectory before it goes live".

Karan Singh, Head of Partnerships at LangChain

How to Evaluate an Agentic AI System for Your Security Operations

  • Error Handling and Transparency: Understand how the platform handles failures mid-task. Does it stop and ask for input, retry automatically, or log failures in a way your team can audit? Robust error handling is non-negotiable for production deployments where mistakes can cascade across your entire network.
  • Permissions and Access Control: Confirm exactly what permissions each agent requires, how credentials are managed, and whether the platform supports role-based access control. For regulated industries, verify compliance with relevant frameworks like SOC 2, GDPR, or HIPAA before deployment.
  • Real-Time Evidence Integration: Evaluate whether the platform can ingest and process network and endpoint telemetry in real time rather than relying on slower, batch-oriented data pipelines that create delays in detection and response.

Jason Dewez, Chief Information Security Officer at Fiserv, emphasized the importance of real-time data: "In the modern SOC, the turning point is recognizing that real-time ingest from network and endpoint telemetry has to become the primary substrate for how AI agents operate. Post-Mythos-level models can reason at remarkable speed, but only when they are fed live evidence from the environment instead of waiting on slower, batch-oriented pipelines".

Jason Dewez, Chief Information Security Officer at Fiserv

Who Are the 15 Founding Members, and What Do They Bring?

The alliance spans network monitoring, endpoint security, orchestration software, AI-native security operations platforms, and agent frameworks. The founding members are AuthMind, Armadin, Command Zero, CrowdStrike, Dropzone AI, Exaforce, ExtraHop, Fig, Intezer, Kindo, LangChain, Prophet Security, ReversingLabs, TENEX.AI, and Torq.

ExtraHop contributes network telemetry, which provides real-time evidence for AI systems investigating threats. LangChain focuses on the harness layer that governs what an agent can access and do. Kindo has highlighted governed runtimes and deployment choices, while CrowdStrike, Intezer, Torq, and others have pointed to the need for richer network context to support automated triage and response. This mix reflects a broader shift in cybersecurity, where suppliers increasingly need to show their products can work within a larger automated workflow rather than in isolation.

The effort has drawn support from outside the founding group. Dr. Edward G. Amoroso, Chief Executive Officer at TAG Infosphere and Research Professor at NYU, stated: "Cybersecurity has reached the point where human-speed defense is no longer sufficient against machine-speed attacks. The Agentic SOC Alliance represents one of the industry's first serious efforts to define an open operational architecture for autonomous security operations, bringing together trusted context, governed AI, and coordinated response so enterprises can finally begin defending at the speed of their adversaries".

Why Does an Open Standard Matter More Than You Might Think?

The alliance's success depends less on rhetoric than on whether the group can demonstrate that a shared architecture cuts errors, speeds investigations, and preserves human oversight across tools from multiple vendors. Several members presented the alliance as an effort to define an open architecture before one vendor's approach becomes dominant. For customers, that could matter significantly if they want to change models or tools without redesigning security operations from the ground up.

This is not a finished blueprint. Greg Clark emphasized that the alliance is "a starting point, not a finished one," and invited "the rest of the industry to join the Alliance and help us refine, validate, and perfect this operating model, because outpacing a machine-speed adversary is a challenge no single company can solve alone".

Greg Clark

The launch comes as security suppliers race to position AI as a response to increasingly automated cyber attacks. The Agentic SOC Alliance represents one of the industry's first serious attempts to move beyond vendor-specific solutions toward a shared operating model that could reshape how enterprises defend themselves at machine speed.