AIToday
Large Language ModelsAI Safety & AlignmentITmedia AI+Published: Sep 20, 2026, 10:00 JST

Zscaler unveils Agentic SOC with AI agents

Zscaler unveils Agentic SOC with AI agents

3 Key Points

  1. What happened

    Zscaler introduced "Zscaler Agentic SOC," which embeds AI agents into security operations to support detection, investigation, judgment, and response, not merely alert analysis.

  2. Why it matters

    With AI speeding up attacks, having humans check every alert and gather information from multiple systems can become the bottleneck, so automating this work could ease that constraint.

  3. What to watch

    The test is whether AI agents handle the full detection-to-response chain reliably, and the article gives no date or availability detail to track yet.

WHO IT HITSCorporate security operations center (SOC) analysts stand to be affected, since their routine alert-checking and investigation work is what Zscaler is aiming to offload to AI agents.

Not sure about something? Ask the AI

Summaries like this, in your inbox every morning.

Context & Analysis

In a typical corporate SOC, alerts flow in from networks and endpoints, and humans work through them: pulling related logs, checking devices, users, and destinations, judging whether it is an attack, and then isolating infected machines or cutting off communication if it is. This involves multiple stages — detection, investigation, judgment, and response — and not every alert turns out to be a serious incident.

Zscaler's answer is to embed AI agents into each of those stages. The point it stresses is that the goal is not simply having AI analyze alerts; it is using AI agents to support the entire sequence and thereby speed up the response itself. That mirrors the broader shift in the security field, where AI's ability to find vulnerabilities, generate attack code, and build attack paths lets attackers compress work that used to be manual.

The stakes here hinge on whether the agents hold up across all four stages rather than just the analytical part — because if they do, the response side could move at a pace closer to the attacks. For SOC teams, the near-term question is how this overlaps with existing workflows and tooling, which is likely to shape adoption as much as the technical results.

FAQ
What does Zscaler Agentic SOC actually do?
It embeds AI agents into security operations to support the whole chain from detection through investigation, judgment, and response. The stated aim is speeding up security response itself, not just analyzing alerts.
Why is a human-driven SOC seen as a bottleneck?
In typical corporate security operations, people check each alert, gather information from multiple systems, and judge whether it is an attack before responding. If attacks get faster, this human investigate-and-decide step itself can become the bottleneck.
How does AI factor into the attacks themselves?
AI can potentially be used to find vulnerabilities, generate attack code, and assemble attack paths, letting attackers do work in a short time that previously required manual effort.

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • Abeam and Notion target enterprise knowledge for AI agentsITmedia AI+ · 1h ago
  • Generative Partners launches "AX BPO" for work AI alone can't finishITmedia AI+ · 1h ago
  • Gemini Hacked Three Companies in First Known Breakout by Google's AITop Companies AI · 5h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleOracle's AI data centers need power; Vertiv, Caterpillar step up