Only 10% of SOCs Say They’re Getting Excellent Value From AI. Here’s What the Second Wave Has to Deliver
Only 10% of SOCs say AI delivers excellent value. The article says the winners are using connected, lifecycle-wide AI instead of siloed point features.
Intelligence analysis by GPT-5.4 Mini

The article argues that AI adoption in SOCs is racing ahead, but value is lagging badly: most teams are getting only limited or no benefit. It says the gap comes from fragmented tools and immature workflows, while the best performers use AI across the whole security operation.
The article says most security teams bought smart helpers, but those helpers work alone like kids passing notes in a broken chain. The best teams make the helpers work together, so each one remembers what the last one learned.
Analysis
What the data says
The article cites the SOC-CMM 2026 Maturity Report, based on survey data from roughly 200 SOCs gathered between late January and mid-March 2026. In that data, only about 10% of respondents said AI delivered excellent value to their SOC, while about 19% said it delivered good value. The remaining majority reported only some value or none at all.
Adoption, however, is rising quickly across the board. The article says off-the-shelf large language models grew 55% year over year, AI co-pilots grew 145%, AI agents grew 118%, supervised machine learning grew 96%, and customized LLMs grew 64%.
Why the first wave fell short
The central criticism is that early AI tools were bolted onto existing products. SIEMs got AI triage, EDR got AI investigation, SOAR got AI playbook generation, and ticketing tools got AI summaries. Each feature helped a narrow step, but the handoffs between steps stayed broken.
The article says that created a situation where analysts had several AI assistants, but no shared context. One tool did not know what another tool had already learned, so the workflow stayed fragmented even as individual tasks got faster.
What the better SOCs do differently
The small group reporting excellent value is described as using AI as part of a connected fabric across threat intelligence, hunting, detection, investigation, and remediation. In that model, each step informs the next one, so the system improves over time instead of speeding up isolated tasks.
The article also says the strongest teams are not just buying generic AI. They are using AI that understands the environment it operates in, because normal behavior in one organization can look very different in another.
The core takeaway
The report’s signal is not that AI is useless in SOCs. It is that buying more AI features does not fix a broken operating model. The next wave has to connect context across the whole security lifecycle if it wants to produce durable value.
Key points
- Only about 10% of SOCs say AI has delivered excellent value.
- AI adoption is rising quickly, but outcomes are lagging behind.
- The article blames fragmented, point-feature deployments for much of the disappointment.
- High-value SOCs use AI across the full lifecycle, not inside isolated stages.
- The report says the real gap is operational maturity and best practices, not budget.
If SOCs connect AI across the full workflow, the article suggests each investigation, hunt, and remediation could improve the next one. That could turn AI from a set of handy shortcuts into a system that compounds value over time.
If teams keep adding disconnected AI features, they may just create more handoffs and more complexity. The article warns that spending can keep rising while outcomes stay stuck at the same mediocre level.



