When the Whole Company Adopts AI: What It Does to Your SOC
AI adoption within enterprises is creating a surge in security alerts, but the vast majority of these alerts are ‘noise’ – existing detection rules triggered by AI agents performing their intended functions. While a small percentage represents genuine security risks (around 6%), a significant portion (around 94%) are simply old alerts that now fire due to AI agent activity. The key takeaway is that SOC teams need to shift their focus from simply reacting to volume to understanding the context of these alerts and recognizing that many are benign, even as they grow. A small number of alerts represent real, emerging threats, primarily related to permission-bypassed agent behavior and the sharing of sensitive data through AI tools.
Over the past year, a new class of alerts has emerged in enterprise security operations centers – alerts triggered by AI tools and agents. We reviewed AI-related activity across numerous enterprise environments, and the numbers paint a striking picture. AI-related alerts now account for only 0.43% of all SOC alerts, but that share is climbing rapidly, up 685% between February and June 2026.
What makes these alerts worth a security team’s attention is not their volume, but their composition. We categorized all AI agent-triggered activity into three buckets: real attacks, risks, and noise. Nearly all of the AI-generated alerts are noise – detections written before AI agents existed, now firing at high severity on routine agent work. This is not a new trend; Sophos previously reported similar findings.
The New Shape of the Alert Stream reveals two distinct behaviors arriving at the SOC simultaneously. The first is technical – developers installing coding agents that spawn shells, read credential stores, open network tunnels, download packages, and run security tooling, all indistinguishable to a detection engine from the early stages of an intrusion. The second is when employees grant OAuth consent to third-party AI applications, sharing information and pasting documents into generative-AI tools. Both halves land in the same place, the SOC, and both look, at first glance, like something to worry about.
By the Numbers, 16.9 million SOC alerts were reviewed, and only 73,000 (0.43%) were AI-related. However, the trend is steep, and the composition is lopsided: 94.1% are noise, 5.8% are genuine security risks, and 0.02% are real attacks.
Within these alerts, 79.8% received a benign verdict, and 81.7% were automatically suppressed. Only 5.4% were escalated to a human analyst, with the remainder flagged for follow-up. The largest category of alerts – noise – is driven by AI vendors’ own software, such as the legitimate Anthropic Claude Desktop installer triggering ransomware detection rules.
Beyond the noise, a small percentage (5.8%) represent genuine security risks. These include permission-bypassed agent behavior, such as a reverse tunnel opened by an AI IDE, or an agent dumping the entire macOS keychain to read one token. Granting OAuth access to AI agents also increases the risk of unauthorized data access via prompt injection or a compromised AI account.
Real attacks, representing a tiny fraction (0.02%), are emerging, primarily related to brand impersonation. For example, emails using AI-themed subject lines featuring the biggest names in AI, leveraging the familiarity created by AI adoption to trick recipients into clicking malicious links or providing sensitive information. These attacks ride on AI rather than through it, exploiting the increased trust and recognition of AI brands.
To summarize, SOC teams need to shift their focus from simply reacting to volume to understanding the context of these alerts and recognizing that many are benign, even as they grow. A small number of alerts represent real, emerging threats, primarily related to permission-bypassed agent behavior and the sharing of sensitive data through AI tools.
