AI's Double-Edged Sword: Surging SOC Alerts Mask Real Risks Amidst a Flood of Noise
The integration of AI tools within enterprises is rapidly transforming the security landscape, generating a massive surge in alerts for Security Operations Centers (SOCs). While the majority of these alerts are classified as noise, a critical but often overlooked segment represents genuine security risks and even a small fraction of actual attacks. This report delves into the evolving nature of AI-related alerts, highlighting the challenges and true threats facing security professionals.
Over the past year, enterprise **Security Operations Centers (SOCs)** have witnessed an unprecedented rise in alerts triggered by **AI tools and agents**. This isn't about attacks *against* AI, but rather the everyday operational footprint of AI within organizations β from developers leveraging coding agents to non-technical staff integrating consumer AI tools into corporate accounts.
While **AI-related alerts** currently constitute a modest 0.43% of all SOC alerts, this figure is far from static. Between February and June 2026, this share skyrocketed by an astonishing 685%, indicating a rapidly escalating trend.
### The New Shape of the Alert Stream
The real challenge for security teams lies not in the volume of these alerts, but in their composition. Our analysis categorizes AI agent triggers into three distinct buckets: real attacks, genuine risks, and noise. The overwhelming majority, 94.1%, is classified as noise, legitimate activity that inadvertently trips pre-AI detection engines. A smaller, yet significant, 5.8% represents genuine security risks, while actual attacks make up a minute 0.02%.
This distribution reveals a critical insight: the primary cost of AI in the SOC, thus far, is not direct breaches. Instead, it's a rising tide of seemingly alarming alerts that rarely signify a true threat, effectively burying a small, critical set of genuine exposures.
AI adoption within an enterprise manifests in two distinct behaviors:
1. **Technical Use:** Developers utilize coding agents that perform actions like spawning shells, reading credential stores, opening network tunnels, downloading packages, and running security tools. While legitimate, these actions are often indistinguishable from the early stages of an intrusion to traditional detection engines. This constitutes the 'loud' half of AI activity.
2. **Non-Technical Use:** Employees grant **OAuth** consent to third-party AI applications, sharing sensitive information and pasting documents into generative AI tools. This is the 'quiet' half, rarely triggering endpoint detections but posing a significant risk for data exfiltration.
Both types of activity land in the SOC, initially appearing as potential threats. The crucial task is to effectively distinguish signal from noise.
### By the Numbers
Out of approximately 16.9 million SOC alerts reviewed, about 73,000 (0.43%) were AI-related. While seemingly small, the growth trajectory is steep and consistent. Every month sees an increase, with a sharp acceleration in May 2026. This means the 0.43% figure is a floor, not a ceiling; SOCs must anticipate being under-provisioned within a quarter if they size their AI-alert handling to current volumes.

The composition of these alerts is heavily skewed. Our investigation into the AI-related population revealed:
* **Noise:** 94.1% (legitimate activity misidentified by pre-AI detections)
* **Security Risks:** 5.8% (genuine exposures, e.g., coding agents operating without proper permission safeguards)
* **Real Attacks:** 0.02% (confirmed compromises or attacker operations leveraging AI adoption)

Automated triage platforms typically make two decisions:
* **Verdict:** 79.8% received a benign verdict.
* **Response:** 81.7% were automatically suppressed, meaning no analyst ever saw them.
Only 5.4% of AI-related alerts were escalated to a human analyst, with the remainder flagged for follow-up. It's crucial for SOC teams to approach high-severity labels on AI activity with skepticism, as they often do not indicate actual threats. For example, a single detection flagging **Windows** binary **Expand.exe** as a lateral-tool-transfer accounted for 55% of all 'critical' verdict alerts at one customer, but was later determined to be legitimate developer activity.
### Category 1: Real Attacks
Real attacks, defined as actual compromises or attacker operations enabled by AI adoption, are the smallest category, representing roughly 0.02% of AI-generated alerts. Interestingly, none of the detected compromises in this class were caused by an organization's *own* AI agent. Alerts like "AI agent running **mimikatz**" or "reverse shell from a coding tool" were, upon inspection, resolved as legitimate developer work or detection misfires.
The genuine threats observed were attacks that *ride on* AI, rather than *through* it. This primarily manifests as sophisticated phishing campaigns that weaponize popular AI brand names as lures. Attackers exploit the familiarity and routine notifications associated with brands like **Anthropic**, **Google/Gemini**, and **OpenAI** to increase the success rate of their phishing attempts.
Examples of such incidents include:
* An email using **Anthropic** as bait in a business context, with a subject like "RE: Anthropic Engagement approval & payment," referencing a supposed contract to make a large payment request appear legitimate. **Anthropic** is not the sender, but part of the pretext for invoice fraud.
* A phishing email impersonating a **Google/Gemini Ads** invitation, using the suspicious domain `gemini-advertisers[.]com` to drive users to a malicious site.
* An email impersonating **OpenAI** for an "OpenAI Partner Summit 2026," originating from `[email protected]`. While using legitimate **Zoom** infrastructure, the content and registration flow were leveraged to lend credibility to a fraudulent invitation.