Security/ ai agents · cybersecurity · soc automation · enterprise ai

SOC Analysts Reused AI Companion Output 90% of the Time

A year-long field study inside a real security operations center found analysts kept an AI companion's drafts in more than 90 percent of closed tickets.

A year embedded inside a security operations center turned into a case study for how AI tools actually earn trust from the people using them.

Researchers built an agentic AI companion powered by large language models and deployed it inside a real SOC for more than a year, shaping its design through direct participation in the team's daily ticket queue. SOC analysts spend most of their time triaging low-interest tickets, the kind of repetitive pattern-matching that makes a natural target for automation. The team opened the tool to working analysts for the fieldwork's final four months and tracked how they actually used it. In over 90 percent of cases, analysts kept the companion's output and folded it into their ticket-closing reports.

That reuse rate matters because most enterprise AI rollouts get built by a vendor or central team, shipped finished, and then quietly ignored by the people expected to use them daily. Here, analysts customized the companion's behavior as they went; the more they shaped it, the more they trusted its output, a pattern the researchers frame as co-evolution rather than simple adoption. That's a different claim from accuracy; it's a claim about how a tool earns a place in someone's actual workflow.

A 90 percent reuse rate is a good adoption number, but it is not an accuracy number, and one SOC's yearlong pilot is a long way from a template every security team can copy.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →