The AI SOC pitch quotes one Gartner document. Read the other one

By Rob Smith, CEO of Lionfish Tech Advisors [ Join Cybersecurity Insiders ]
29

A prediction that 70% of large security operations centers will pilot AI agents by 2028 is doing heavy lifting in vendor decks this quarter. Gartner’s own Hype Cycle, published eight months after that prediction, rates the category embryonic and five to ten years from mainstream adoption. Both documents are Gartner. Only one of them is in the deck.

The prediction is real and the note it came from is a good piece of work. “Validate the Promises of AI SOC Agents With These Key Questions,” by Craig Lawson and Andrew Davies, document G00836750, gives buyers seven sections of evaluation questions covering use-case fit, outcome measurement, pricing and vendor viability, analyst upskilling, autonomy boundaries, integration and governance. A security team that works through all seven will buy better than one that does not. I would ask most of them myself.

I spent a long stretch of thirty-five years in this industry writing Gartner Magic Quadrants and Hype Cycles, so here is the part that gets lost between the research and the sales call.

What the number is, and when it was written Gartner labels that sentence a Strategic Planning Assumption. That is the firm’s own term for a forward-looking planning input, and it is a deliberate distinction from a research finding. The note carrying it was published on October 28, 2025.

So a planning assumption written in October 2025 is being circulated in September 2026 as though it described the market this quarter.

Now open the second document. The Hype Cycle for Security Operations, 2026, by Darren Livingstone and Jonathan Nunez, published June 5, 2026, places AI SOC agents at the Peak of Inflated Expectations. The profile, written by Eric Ahlm, rates market penetration at 1% to 5% of the target audience and maturity as embryonic. Benefit rating: moderate. Years to mainstream adoption: five to ten. Five to ten years. Moderate benefit. From the same firm, eight months after the prediction.

Those two documents are not in conflict, and anyone who tells you they are has not read either. A pilot is not an adoption. Seventy percent of large SOCs can run a pilot by 2028 and the category can still be a decade from mainstream, because that is what a peak of inflated expectations is. The problem is that only one of those documents gets quoted, and it happens to be the older one with the bigger number.

The recommendations nobody puts on a slide Read the Hype Cycle profile and Gartner tells buyers, in plain language, to consult their incumbent SIEM and XDR vendors first, because many already have workflow augmentation agents on the roadmap. It tells them to baseline their own operations before defining evaluation criteria. The evaluation note goes further and suggests waiting for AI features from existing providers, improving basic automation, or prototyping something in-house if the resources exist.

That is an analyst firm telling you the answer might be no, or not yet, or not from a startup.

It also says full autonomy is not viable today, warns that pricing may be tied to token consumption, and tells buyers to expect acquisitions in the category and to treat that as third-party risk. Every one of those is a caution. None of them travels with the 70% figure.

The question the seven sections do not ask I read all seven. They cover explainability, audit trails and how an analyst feeds accuracy corrections back into tuning. What none of them asks is whether identical input produces identical output, or how the agent’s knowledge of a threat disclosed last week actually reaches it.

That gap matters more here than in most categories. These systems are frozen at a training cutoff and they are non-deterministic. Ask the same thing twice, phrased two ways, and you can get two different answers. For most work that is tolerable. For an investigation record that has to hold up in front of a regulator, an insurer or opposing counsel, it is disqualifying.

An investigation you cannot reproduce is an opinion with a timestamp.

Auditability and reproducibility are different tests, and vendors are answering the easy one. A system can log every step it took and still take different steps tomorrow on the same alert. You need the trace and the guarantee that the trace is stable.

Four things to put in front of the vendor Run the same alert twice, a week apart, on the same data, and put both outputs side by side. Not the demo. Your alert, your environment, two runs. Then compare.

Ask how the agent learns about a threat disclosed since its knowledge cutoff. Retrieval, retraining and a rules layer are three different answers with three different failure modes. Make them pick one.

Ask your incumbent SIEM or XDR vendor what ships in the next two release cycles before you sign with anyone else. Gartner recommends this and almost nobody does it, because the incumbent conversation is boring and the startup demo is not.

Ask what happens to your investigation records when you leave. If the reasoning lives in the vendor’s model rather than in your case files, you rented your audit trail.

Those four take one meeting. None require you to understand how the model works.

Where this lands I am not arguing against AI in the SOC, and neither is Gartner. Lawson, Davies and Ahlm all describe a category with real augmentation value and unproven delivery, which is an honest description of where it sits. The evaluation note is worth reading in full, and the buyers who read it will do better than the buyers who read the headline.

But the headline is what is moving. A number written in October 2025 is being sold as a description of September 2026, attached to a category its own author rates embryonic and five to ten years out. That is not a vendor lying. It is what happens to every figure once it leaves the report, because a number stops carrying its confidence rating the moment somebody puts it on a slide, and nobody ever reattaches it.

Check the date on the note. Then ask for the other one.

______

About Rob Smith 

Rob Smith is CEO of Lionfish Tech Advisors, an independent research firm that works for technology buyers rather than technology sellers. Prior to this, Rob spent eight years as a Gartner analyst covering endpoint management, remote access and enterprise security, with 35 years in IT and cybersecurity behind that.

 

 

Join our LinkedIn group Information Security Community!

No posts to display