Skip to main content
Home / Blog / AI Industry
AI Industry

AI Fixed SOC Burnout. The People Doing the Work Disagree.

RRogue AI··8 min read
A security analyst at a night-shift desk reviewing a wall of machine-generated verdicts, one of them flagged for a human decision

Both surveys are right, which is the uncomfortable part. Ask security leadership whether AI helped the security operations centre, and 90 percent say workload improved while 85 percent say stress and burnout fell. Ask the floor in the same year, and 28 percent of alerts still go uninvestigated, 60 percent of teams have watched an ignored alert turn into a real incident, and every analyst carries 8.6 hours a week of checking what the machine produced. Nobody is lying. The work did not shrink. It changed shape, and only one of those two groups is standing where the new shape landed.

The numbers come from two independent 2026 surveys that never contradict each other because they never measure the same thing. Torq surveyed more than 450 CISOs and SOC leaders across four countries with Sapio Research and published in March 2026. Prophet Security surveyed 250 security leaders and practitioners through ViB and published on 3 August 2026. Read them side by side and the pattern is not a disagreement, it is a handoff: leadership tracks the metrics AI genuinely improved, and analysts live in the residue those metrics never captured. That gap is now the most expensive thing in the SOC, because next year’s headcount and budget decisions are being made from the half of the picture that looks solved.

The one number both sides agree on is zero

In the Prophet Security survey, not a single respondent grants AI full unsupervised autonomy. Not one. Forty-four percent let AI recommend while a human executes, and 30 percent auto-execute only the low-risk actions. That is the most honest figure in the entire debate, and it settles what AI in the SOC actually is in 2026: every deployment in the field is a supervised deployment, and supervision is labour.

Hold that against the Torq finding that 72 percent of leaders say they are comfortable with fully autonomous AI on medium-severity incidents and below. Comfort in a survey, zero in production. The distance between what leaders say they would allow and what their own organisations actually permit is the tell, and it is the same collision described in AI agents with money: every proposed control for an autonomous system reduces to a human in the loop, which is precisely the thing autonomy was supposed to remove. A SOC that keeps a human on every consequential decision has not automated the decision. It has automated the paperwork around it and kept the decision.

The supervision shift nobody put on the org chart

Torq measured analysts spending an average of 8.6 hours a week overseeing AI output. That is more than a full working day, every week, doing a job that has no title, no headcount line, and no metric on any dashboard. It arrived silently alongside the tooling. The same survey found the average SOC now runs seven AI-powered tools, with 80 percent relying on fragmented point solutions rather than one platform, so that day is spread across seven different output formats with seven different failure modes.

Consider what the job became. The old task was: read the alert, form a judgment. The new task is: read the alert, read the verdict the machine already reached, then judge whether the machine was right. That is not a lighter cognitive load, it is a different and arguably heavier one, because evaluating someone else’s reasoning is harder than forming your own when the reasoning itself is not visible. One line from Torq’s own respondents captures the whole problem: “I’d let AI do more if I could see why it’s doing what it’s doing.” Ninety-two percent named at least one trust barrier, and in the Prophet data 41 percent named explainability specifically as the blocker. The industry built a colleague whose work you must check but whose thinking you cannot read.

The remainder did not go anywhere

Prophet Security put hard numbers on what is left after the tooling did its work. An average of 28 percent of alerts go uninvestigated, with 39 percent of organisations leaving more than 30 percent untouched. Sixty percent have had an ignored alert become a material incident, and 34 percent had three or more of those in a year. Alerts sit an average of 55 minutes between firing and an analyst picking them up. The median organisation handles roughly 100 alerts a day, while 27 percent handle more than 500.

One figure should end any conversation about whether the workload problem is solved: 40 percent of teams have disabled detection rules because they lacked the capacity to investigate what those rules produced. That is not a tuning decision. It is silent risk acceptance, executed at the config level by people with no authority to accept risk, and it never appears on the slide that says AI reduced burnout. A SOC that switches off its own eyes to keep the queue survivable has a capacity problem that no productivity percentage can describe.

Why leadership is not wrong

AI did fix real things. First-pass enrichment, the fortieth identical phishing triage of the day, the copy-paste between console and ticket: that work was genuinely miserable and it is genuinely lighter now. Leadership dashboards measure exactly those things, because time-to-triage, alert throughput and closure rate are the numbers a SOC has always reported upward. Those numbers improved, and the improvement is real.

What analysts experience is the composition of what remains. Strip the routine work out of a job and you do not make the job easier, you concentrate it. Every remaining hour is now a judgment call, an escalation, or a supervision task, with none of the low-effort work that used to sit between the hard ones and let a brain recover. Density went up while the hour count stayed flat, and density is what burnout actually tracks. This is the same measurement failure taken apart in why AI projects fail in production: the pilot metric and the production experience diverge, and only the pilot metric ever reaches the board.

Belief is running well ahead of deployment

The clearest evidence that this is an expectations problem rather than a capability one sits inside the Torq data. Ninety-seven percent of leaders are confident AI can handle triage. Only 35 percent actually have it doing triage. A 62-point gap between conviction and practice is a belief that has outrun its own evidence base.

Prophet found the same pattern in the build-versus-buy data: 72 percent of AI users attempted to build their own SOC tooling, and 46 percent of those builds were deprecated, replaced, or never deployed at all. Nearly half the internal attempts did not survive contact with production. Practitioner scepticism about this category is pattern recognition. As one analyst put it in an r/cybersecurity thread this month, the more they deal with these tools in practice, the more it feels like standard security hygiene still does 95 percent of the heavy lifting. That is one voice rather than a groundswell, but it rhymes precisely with what the survey data shows. Anyone deploying here should read how to evaluate an LLM system in production before believing a vendor benchmark, because the agreement rate between machine verdict and analyst verdict is the only number that matters and almost nobody tracks it.

The mechanism, in one sentence

Here is the machinery behind the paradox. AI accelerated detection. Response still terminates at a human, because nobody grants autonomy. So the industry sped up the half of the pipeline that produces work and left the half that consumes it exactly as it was. Faster detection against an unchanged human gate does not clear a queue, it lengthens the line in front of the gate.

A practitioner on r/AskNetsec described the operational version of this without naming it: everything they tried detects fast, but the response step is still manual review or a playbook, so the actual block lags well behind the detection, and the gap between seeing something bad and stopping it is exactly where the damage happens. That is the correct diagnosis. It is also why the honest advice in when not to use an AI agent applies with unusual force in security operations: if the decision at the end of the workflow must be human, automating everything upstream of it moves the bottleneck rather than removing it.

What the perception gap actually costs

If leadership believes burnout has been handled, the staffing case dies quietly. Meanwhile 63 percent of security practitioners report burnout, 81 percent report a heavier workload than a year ago, and half say their team is understaffed. The 2026 State of the Cybersecurity Workforce report put the overage at 10.8 extra hours a week, effectively a sixth working day. None of that is visible on a dashboard reporting improved mean time to triage.

The failure mode here is not that AI failed. It is that AI succeeded on the measured axis while the unmeasured axis got worse, and only one of the two has a budget owner. Attrition, the 28 percent remainder, and 40 percent of teams quietly switching off detections are all real costs being carried on a page nobody reads. Worth noting too: an AI system acting inside your SOC is itself an account with standing access to your most sensitive telemetry, which is a governance question covered in every AI agent is a non-human identity, and one that most SOC deployments have not answered either.

Measure the things that would have caught this

The two surveys diverged because they asked different rooms. Any organisation can close that gap in a quarter by tracking five things it almost certainly does not track today.

  • Supervision hours as a capacity line.If analysts spend a day a week checking machine output, that day belongs in the capacity plan with a name against it, not absorbed as a rounding error inside “other duties”.
  • The uninvestigated percentage, published monthly. Not mean time to resolve. The share of alerts nobody looked at is the single number that describes whether your capacity matches your detection surface.
  • Disabled detection rules on the risk register. Every rule switched off for capacity reasons gets an owner, a date, and a review, because that is an accepted risk regardless of what the change ticket called it.
  • Machine-to-analyst agreement rate, per detection type. Twenty-two percent of organisations sit at 50 to 69 percent agreement, which is close enough to a coin flip that you are paying twice: once for the tool, once for the human checking it.
  • Ask analysts separately from their managers. The entire paradox in this article exists because two surveys asked two different populations. Your internal survey has the same flaw unless you deliberately design it out.

None of this argues for pulling AI out of the SOC. The triage-and-enrichment case is genuinely good, in the same way the document and service-desk automation described in AI automation for the IT service desk is genuinely good. It argues for describing honestly what you bought: a system that removes a category of work and creates a smaller category of harder work, with a net that is probably positive and definitely not what the vendor slide said.

The quick test, before you sign next year’s headcount plan: ask your SOC leadership what AI changed, then ask an analyst on shift the same question, and compare the two answers. If they do not match, you do not have an AI problem. You have a measurement problem, and it becomes a retention problem roughly one resignation later.

Related reading

Quick Reference

Same year, same rooms, two different answers about AI in the SOC

The questionWhat leadership reportsWhat the floor reports
Did AI reduce the workload?90% say workload improved81% report a heavier workload than last year
Did burnout improve?85% say stress and burnout fell63% of practitioners report burnout
Is AI handling triage?97% are confident it can35% actually have it doing triage
Does AI act on its own?72% are comfortable with autonomy0% grant unsupervised autonomy
What happens to the remainder?Not measured28% of alerts go uninvestigated
The hidden line itemNot on any dashboard8.6 hours a week supervising AI output

Frequently Asked Questions

Did AI actually reduce SOC burnout in 2026?

It depends entirely on who you ask, and both answers are supported by data. Torq's March 2026 survey of more than 450 CISOs and SOC leaders found 90 percent reporting improved workload and 85 percent reporting reduced stress and burnout. Practitioner-level data from the same year shows 63 percent of security practitioners experiencing burnout, 81 percent reporting a heavier workload than the previous year, and half saying their team is understaffed. The most likely explanation is not that one group is wrong, but that AI removed the routine work and concentrated what was left, so hours stayed flat while cognitive density rose.

How many organisations let AI act autonomously in the SOC?

None, according to Prophet Security's August 2026 survey of 250 security leaders and practitioners. Zero respondents grant AI full unsupervised autonomy. Forty-four percent allow AI to make recommendations that a human then executes, and 30 percent auto-execute only low-risk actions. This sits against Torq's finding that 72 percent of leaders say they are comfortable with fully autonomous AI on medium-severity incidents and below, which makes the gap between stated comfort and actual production practice one of the clearest signals in the data.

What is the supervision cost of AI in a security operations centre?

Torq measured an average of 8.6 hours per analyst per week spent overseeing AI output, which is more than a full working day. The average SOC in that survey runs seven AI-powered tools, with 80 percent using fragmented point solutions rather than a single platform, so the supervision load is spread across seven output formats. This work typically has no job title, no headcount allocation and no dashboard metric, which is why it rarely appears in any assessment of whether AI reduced the team's workload.

Why do leadership and analyst surveys disagree about AI in the SOC?

They measure different things. Leadership dashboards track mean time to triage, alert throughput and closure rate, all of which genuinely improved when AI absorbed first-pass enrichment and repetitive triage. Analysts experience the composition of what remains after that work is removed: judgment calls, escalations and supervision tasks, with none of the low-effort work that used to sit between the hard ones. The measurement gap matters because staffing and budget decisions are made from the leadership view, while attrition risk accumulates in the view nobody is measuring.

What should a SOC measure to see the real picture?

Five things most teams do not currently track. Supervision hours as an explicit capacity line rather than absorbed overhead. The percentage of alerts nobody investigated, published monthly, instead of mean time to resolve. Detection rules disabled for capacity reasons, entered on the risk register with an owner and a review date, since 40 percent of teams have switched rules off for exactly that reason. The agreement rate between machine verdict and analyst verdict, tracked per detection type. And an analyst survey run separately from the management survey, because asking one room and generalising to the other is the flaw that produced the paradox in the first place.

Related Articles

AI Industry

AI Agents With Money: Nobody Shipped the Spending Limits

9 min read

AI Industry

The US Wrote Secret Rules for Frontier AI. Open Weights Walk Free.

9 min read

← All articles