There is a number that should unsettle every security executive investing in AI today: 71% of cybersecurity leaders believe AI has significantly improved their team’s productivity. But among the analysts who actually use those tools every day, only 22% agree. That gap, drawn from an Exabeam survey of 1,000 cybersecurity professionals worldwide, isn’t just an opinion split. It points to a structural problem that no amount of model improvement will solve on its own.
The AI-powered security operations center has moved from concept to procurement line item. According to SACR’s AI SOC Market Landscape 2025, 88% of organizations without an AI-driven SOC plan to evaluate or deploy one within the next year. The average enterprise already faces about 960 security alerts per day and roughly 40% of those alerts go uninvestigated. The case for automation isn’t theoretical anymore. It’s urgent.
But the returns so far have been mixed — and not for the reasons most people assume. A growing consensus among researchers and practitioners points to something more fundamental than model quality or algorithm design: The data itself was never built for machines to reason with.
The Foundation Problem
The 2025 SANS SOC Survey, one of the industry’s most closely watched benchmarks, found that 42% of SOCs send all incoming data to a SIEM with no defined strategy for management or retrieval. Another 42% deploy AI and machine learning tools in an out-of-the-box capacity, with zero customization to their environment. Christopher Crowley, the SANS Certified Instructor who led the survey, put it plainly: “If company leadership isn’t prepared to fully commit the resources to make a tool effective, it would be better not to deploy it at all.”
That finding tracks with what analysts and vendors across the industry are observing. SOCs have spent years optimizing for human workflows — dashboards, tables, log formats and rule sets designed for people to read and interpret. When AI agents are dropped into that same environment and asked to reason autonomously, they inherit data architectures that were never designed for machine consumption.
Asaf Weiner, CEO and co-founder of Mate Security, an AI agent security platform that just launched a security context graph to power trustworthy AI SOC agents, sees this mismatch as the central obstacle. “AI agents are fed data structured for humans,” Weiner explained. “SOC analysts work with tables, logs, and documents. They rely on their experience and common sense to connect the dots. But AI cannot do that. AI agents need more than the ‘what’ — they need the ‘why’: The operational context.”
Steve Wilson, Chief AI and Product Officer at Exabeam, has observed a similar pattern. “There’s no shortage of AI hype in cybersecurity,” he said. “But ask the people actually using the tools, and the story falls apart. Analysts are stuck managing tools that promise autonomy but constantly need tuning and supervision.”
Why Context Matters
Gartner, in its Top Strategic Technology Trends for 2026 report, identified context as a defining factor for the next wave of AI deployments. “Context is emerging as one of the most critical differentiators for successful agent deployments,” said Tori Paulman, VP Analyst at Gartner. The firm predicts that by 2028, more than half of enterprise GenAI models will be domain-specific — purpose-built around specialized data rather than general-purpose architectures.
In cybersecurity, that means AI agents need more than raw logs and alert feeds. They need to understand organizational realities, like which behaviors are routine for a specific user, which systems matter most during an incident and how past investigations shaped current policy.
Mate Security has built its approach around this premise. The company’s recently unveiled Security Context Graph is a new data architecture that restructures institutional knowledge into a continuously updated graph of operational memories, capturing the reasoning and conditions behind analyst decisions, not just the decisions themselves. In simpler terms, instead of just recording what is happening in an organization, the context graph preserves why it is happening, so AI agents can learn from that logic at scale.
Weiner noted that the company spent months building the context graph before releasing its first AI agent, a deliberate sequencing rooted in a conviction that has since become an industry theme. “Agents are only as effective as the data structure on which they are built,” he said. “This is the only way for AI to earn trust.”
That trust is being tested daily. Weiner says the pattern he encounters most often when meeting security leaders for the first time is skepticism born from experience. “I can feel the mistrust,” he said. “They have piloted AI in their SOC and were burned with a bad experience: agents taking months to learn, confidently generating wrong verdicts, and requiring more ‘babysitting’ than the SOAR they were meant to replace.”
Trust As The Operating Constraint
Forrester principal analyst Jeff Pollard has argued that the industry needs entirely new governance frameworks for autonomous AI agents — what Forrester calls “least agency” — because traditional security controls were never designed for systems that act on their own. But governance frameworks only work when the underlying data gives AI something reliable to reason with, which is exactly what Mate’s Context Graph is designed to provide.
Because the graph captures the logic behind each decision, AI agents can surface their reasoning in plain language and flag uncertainty when more data is needed. “The Security Context Graph is a living and breathing structure,” Weiner said. “It is dynamically rebuilding and optimizing with every investigation, every ownership change, every policy change, so decisions are made according to what’s relevant right now.”
That adaptability addresses another persistent industry challenge: Staff turnover. Cybersecurity analyst churn remains substantial — the 2025 SANS SOC Survey found that the most common tenure for SOC staff is just three to five years, with 62% of professionals saying their organization isn’t doing enough to retain top talent. Every analyst who walks out the door takes years of tribal knowledge with them. A data architecture that captures and preserves that knowledge means the organization’s intelligence isn’t lost every time someone leaves.
The Path Forward
None of this means AI in the SOC is failing. It means the industry is moving past the initial deployment phase and into the harder work of making these systems reliable at scale. The organizations seeing results are the ones treating data architecture, governance and analyst trust as first-order problems — not afterthoughts bolted on once the AI is already running.
The tools are here. But the big question, as the SANS survey concluded, is whether these tools are prepared with the data foundations, governance structures and trust frameworks that will allow them to finally deliver on their promise. The ones that do will have a significant head start.
