
AI is arriving in security operations as a productivity story: faster triage, better investigations, fewer alerts, and more automation.
That is real. But the larger change is that AI creates new actions, attack paths, and evidence that security teams need to capture and understand. The question is no longer only whether an endpoint or identity behaved suspiciously. It is also: what did an agent know, which tools did it call, under whose authority did it act, what did it change, and what happened next?
AI will not eliminate the SIEM or security data platform. It may make the traditional SIEM UI less important, but it makes trusted data more important. If telemetry is incomplete, identity and asset context is inconsistent, or detections are weak, AI simply reaches conclusions faster on top of uncertain inputs.
A modern SIEM should therefore be more than a log store and search interface. It should be an evidence and control layer: a place where data is reliable, context is preserved, access is governed, and consequential actions can be explained.
There may be an opportunity for the SIEM to become the authoritative home of the security context graph: not merely a visualization, but the maintained relationship between identities, devices, workloads, applications, data, permissions, ownership, and policy. AI agents need that context before they can safely reason or act.
Traditional telemetry tells us what happened on a system or network. AI systems require us to capture part of the decision path as well. For consequential agent activity, organizations will need to know:
This is not only an incident-response requirement. It matters for audit, compliance, and accountability. If an agent changes data that feeds financial reporting, accesses sensitive information, or takes a production action, an application log saying “completed successfully” is not enough. Sarbanes-Oxley may not mention agents by name, but the underlying internal-control and evidence problem is obvious.
New endpoint vendors including Neo, Glow, Ent, and others are focusing on a different layer of the endpoint: observing user and agent behavior, then inferring intent. That is worth watching closely. Ent explicitly frames its approach as intent-aware security across human, AI, and application activity, while Neo and Glow are pursuing AI-era endpoint control and prevention from adjacent angles. Ent, Neo, and Glow are useful examples of the emerging category.
Traditional EDR is still needed for attacks that reveal themselves in low-level evidence: process execution, network activity, and known attacker techniques. But those signals can be insufficient when developers, administrators, and AI-enabled workers legitimately perform highly variable and sensitive work. We can find many attacks at the system layer, while insider-risk activity or misuse of legitimate access may remain hard to distinguish.
Intent signals can add context. Is a sequence of actions consistent with a developer deploying software, an administrator performing maintenance, or an agent moving outside its mandate?
But intent is a probabilistic signal, not a verdict. It should complement evidence from endpoints, identity, cloud, applications, data, and agents—not replace it. That is another reason we need a central correlator or analytics platform. Let’s keep calling that a SIEM.
The need to correlate all of that evidence creates a timing problem.
An endpoint or identity control may see a risky action immediately, but the evidence needed to understand it may be spread across cloud systems, containers, SaaS applications, sandboxes, and downstream tool calls. Some context arrives seconds later. Some appears only after an agent has completed a chain of work. Some only matters when an investigator or auditor returns months later.
Security therefore needs to work across three clocks:
The point is not to delay every decision. It is to recognize that the best immediate decision and the best informed decision may occur at different times—and both need to be explainable.
This need to capture agent actions, join them with broader context, and preserve reliable evidence across all three clocks changes MDR too. The future MDR is not simply an AI SOC that processes alerts with fewer analysts. It has to operate the telemetry, detection, context, and accountability loop around AI-enabled environments.
That means ensuring the right telemetry is collected, maintaining the context graph that makes it useful, testing detections, defining which actions can be automated, preserving approvals and exceptions, and proving later what the system saw and did.
AI may reduce manual work in the SOC. It does not remove the need for a trusted security operating layer. When AI acts, security has to remember not only what happened, but why.
No comments yet.