Source: Unite.AI
I have spent 25 years on the buyer’s side of security operations, and I have never once lost sleep over a firewall rule. However, I have lost sleep over AI. Traditional automation, no matter how complex, follows logic you can trace. However, in this unprecedented scale of agentic AI, systems are being trusted to make judgement calls that engineers aren’t always able to fully explain – this loss of transparency is precisely why so many CISOs are stuck.
97% of security leaders are confident AI can handle triage, yet only 35% are actually using it there. This inflection point is a trust problem, and trust can only be solved the way it always has, through structure, evidence, and time.
You Can See the Automation, but Can You Trust the AI?
With traditional automation, practitioners are able to know with certainty what will happen before it happens. This transparency is why SOC teams have spent a decade building trust in automated workflows without much internal debate, however, agentic AI has broken the mold by introducing a learned judgement layer – a system that weighs context, makes predictive calls, and arrives at conclusions through a process that isn’t always fully legible, even to the people who built it.
Only 21% of organizations say they have a mature governance model in place for agentic AI, even though 74% expect to be using AI agents at least “moderately” by 2027. When security practitioners are not able to transparently explain this type of “black box AI,” it is a testament to the difficulty of governing AI tools. It’s not because the tools aren’t being secured properly, but because the inner workings of the AI tool is based on judgement rather than a flowchart.
In boardrooms, leaders are evaluating AI the way they’d evaluate automation, asking “can I see the logic,” rather than asking, “how do I earn confidence in a decision-maker whose logic evolves?” Most CISOs likely already know the answer, but the challenge is applying it in practice.
Treating AI like a high-stakes hire
Think about onboarding a new senior analyst. A CISO wouldn’t hand a brand-new analyst the keys to production on day one, no matter how strong their resume looked. They would start them on low-risk work, watch how they handle ambiguity, and expand their authority as they earn it. AI deserves the same onboarding, fostered in evidence-based trust that builds over time.
We’ve already seen the effects play out in action when an autonomous Meta AI agent triggered a company-wide security incident after taking action without human approval, exposing sensitive company and user data to unauthorized employees for roughly two hours before the issue was contained. The root cause was a lack of human-in-the-loop oversight at the decision point where explicit approval should have been required. That is the exact failure mode rigid guardrails are designed to prevent, and it is a reminder that scope discipline matters more than model sophistication.
AI deserves the same attention, and we can think about it as an evidence-based ramp:
- Understand the decision logic before you deploy it. You don’t need to see every weight in the model, but you need to know what data it’s reasoning over, what outcomes it’s optimizing for, and where its blind spots are likely to sit.
- Set rigid guardrails on day one. Define exactly what the system can act on independently and what requires a human hand. Narrow scope is the foundation that trust gets built on.
- Expand boundaries only as evidence accumulates. Every correct decision is a data point, and every miss is a data point too. Widen the aperture in proportion to the track record, not in proportion to vendor enthusiasm or budget cycles.
Following these as a protocol will help guard against CISO fears, including preventing an autonomous system operating past the point where anyone actually verified it deserved to be trusted.
The Three-Layer Model: Where AI Earns Its Place
SANS’ Secure AI Blueprint lays out a governance structure built around three tracks, protect AI, utilize AI, govern AI, spanning six control categories including access, data, deployment, inference, monitoring, and model security. This is a useful starting point, and to go one step further, it’s helpful to structure this relationship by breaking the SOC into three layers to resolve the AI trust problem.
- Outcome. This is the layer where business risk lives. What does the organization consider an acceptable result? What’s the tolerance for false negatives versus false positives? This is a human call, full stop. No model gets a vote on what the organization is willing to risk.
- Judgment. This is where priorities get set and trade-offs get made under ambiguity. Should this alert get escalated now or held for more context? Is this anomaly worth interrupting someone’s night for? Judgment can be informed by AI, and increasingly it should be, but final authority stays human. This is the layer most organizations are tempted to hand over too early, and it’s the one that will burn them if they do.
- Execution. This is where AI should be doing the heavy lifting, and doing it at a speed no human team can match. Enriching an alert, correlating signals across a dozen tools, drafting a containment action, running the playbook once a human or a trusted judgment layer has approved the path. Machine speed, deterministic once triggered, no ego about it.
Maturing the Partnership, Not Just Managing the Tool
When the relationship of AI within the SOC is built as a partnership rather than overseeing a tool, CISOs are able to begin thinking of AI as a developing teammate, which leads to a fundamental shift in how the CISO spends their time.
The SOCs that are able to balance this relationship are those with the most disciplined trust-building process. That discipline is what lets a security operation scale at machine speed at the execution layer without losing the human judgment that outcome-level decisions still demand, and always will.
We’ve passed the moment of AI being seen as the shiny new tool to impress boardrooms. AI’s capabilities and potential have earned the authority to be treated the way everyone in a SOC always has treated advanced technology, one verified decision at a time.
