AIgenerative AISOCAI governance

Generative AI in the SOC: where agents truly help and where it's still a risk

August 3, 2026 · 5 min read · Intelliway Team

Generative AI in the SOC: where agents truly help and where it's still a risk

Every week brings a new model, a new agent platform, a new promise that generative AI will rewrite security operations. SOC teams in Brazil feel this pressure twofold: on top of keeping up with technical developments, they also need to answer to the board about why they haven't adopted this or that yet. The result is usually hasty, uncritical adoption, driven by fear of falling behind rather than a real assessment of risk and return.

This pattern has a name: organizational FOMO. And it's particularly dangerous in security, because the environment where these agents operate deals with credentials, sensitive data, and decisions that can affect business continuity. The question security leaders should be asking isn't "which generative AI platform is the best," but "for which specific task, at what level of autonomy, does this tool make sense in my SOC."

What generative AI already does well in the SOC

Generative AI platforms applied to security have shown consistent value in well-defined tasks, where the cost of an error is low and there's human review built into the workflow:

In all these cases, the pattern is the same: AI speeds up the cognitive work of preparation and synthesis, but the final decision still rests with the analyst. This is exactly the design behind ISA Cyber, Intelliway's AI agent layer for SOCs: the agents take on repetitive investigation and signal correlation, freeing up the human team for higher-judgment decisions and effective incident response.

Where autonomy is still a risk

The other side of the coin is where these same platforms shouldn't yet operate without strict oversight:

This point became more concrete with a recent vulnerability found in a widely used library for loading AI models from public repositories. The flaws allowed a malicious model repository to execute arbitrary code on the machine that loaded it, bypassing the very mechanism designed to prevent unreviewed code execution. In other words: the AI supply chain, the models, packages, and integrations that underpin these agents, is now as real an attack surface as any traditional software dependency. Adopting a generative AI platform without taking inventory of where the models come from, who maintains them, and how they're loaded is like opening a new door without changing the locks on the old ones.

A simple framework for deciding

Before approving the use of a generative AI agent at any stage of the SOC, it's worth answering four questions:

  1. What is the scope of the task? Drafting, summarizing, and enrichment carry a very different risk profile than direct execution on systems.
  2. Is there human review before any action with real effect? If the answer is no, the level of autonomy needs explicit guardrails.
  3. Where do the models and integrations come from? Third-party models, plugins, and public repositories require the same level of scrutiny as any external vendor software.
  4. Is there an audit trail? Every agent action needs to be traceable, with a log of what was decided, why, and based on what data.

This framework isn't bureaucracy: it's what separates AI adoption that reduces risk from adoption that simply moves the risk to a less visible place. It's also the reasoning behind Intelliway's AI governance work: before letting an agent operate with autonomy, map out the data it accesses, the tools it can trigger, and the decision boundaries it cannot cross.

The role of corporate generative AI outside the SOC

The same caution applies to generative AI use in other areas of the company, not just security. Compliance, legal, and customer service teams already use generative AI assistants to synthesize documents and answer questions based on internal knowledge bases. When this use runs on a proprietary corporate platform, such as EvaGPT, the company retains control over where data resides, who accesses what, and how responses are generated, instead of relying on external tools with no visibility into the model's supply chain.

Practical conclusion

There's no single answer to "which AI platform should I use in the SOC." What exists is a methodology for deciding where it fits in: start with high-volume, lower-risk tasks like triage and summarization, measure the actual time savings, keep human review in place for any action with practical effect, and treat the AI supply chain with the same rigor as any other critical software. FOMO leads to shortcuts. A mature SOC adopts generative AI at the pace of evidence, not market pressure.

If your company wants to assess where generative AI truly adds value to security operations, with governance and guardrails built in from the start, the Intelliway team can help. Reach out to us at /empresa#contato.

Sources and further reading

Read also

Want to apply this in your business?

Talk to Intelliway's Cyber and AI specialists.

Book a conversation
Generative AI in the SOC: where agents truly help and where it's still a risk | Intelliway