Insights

    ai-security

    Your SOC's fastest-growing alert source is not an attacker. It is your own staff.

    Devence Lab

    · 2 min read

    Share
    Illustration · Devence Lab

    A new class of alert is growing faster than any other in enterprise security operations centres, and it isn't triggered by attacks on AI. It's the ordinary footprint of an organisation using it, and most detection rules aren't built to tell the difference.

    On 12 September, researchers published an account on The Hacker News of a new class of alert that has appeared in enterprise security operations centres over the past year and grown faster than anything else in the stream. The alerts are triggered by AI tools and agents, but not by attacks against them. They register the ordinary, everyday footprint of an organisation using AI: developers running coding agents, and non-technical staff signing consumer AI tools into corporate accounts.

    The received reading is the wrong fix

    The obvious response is to build better AI-specific threat detection: classifiers tuned to catch prompt injection, model exfiltration, or agent misuse. That work matters, but it treats the alert flood as a detection gap. It isn't one. The alerts are firing correctly. Automated, high-volume, machine-speed activity is exactly the signature every SOC playbook was built to flag as suspicious, and an employee's coding agent making hundreds of API calls a minute produces that signature as reliably as an attacker's script does.

    The baseline moved, not the threat model

    What actually changed is what counts as normal traffic inside the organisation. A SOC calibrated on last year's baseline reads this year's routine agent usage as anomalous by default, because nothing in that baseline accounted for a marketing analyst's AI tool making a thousand small requests to a SaaS API overnight. The volume is real. The alert is not evidence of compromise. Most teams are currently triaging that gap one ticket at a time.

    An alert that fires correctly on your own employees' normal behaviour is not a detection success. It is a baseline nobody has rebuilt yet.

    What changes for the SOC

    Rebuilding detection rules to catch smarter attacks will not fix a false-positive rate driven by legitimate usage. What fixes it is an inventory of every agent and AI tool operating with organisational credentials, a baseline of what normal behaviour looks like for each one, and an explicit allow-list separate from the general anomaly model. Treat agentic AI usage as a new traffic class to be modelled on its own terms, the way VPN traffic or scheduled batch jobs already are, rather than as a variant of the attack traffic your rules were written to catch.

    Sources

    1. When the Whole Company Adopts AI: What It Does to Your SOCThe Hacker News

    Written by the Devence Lab research team.

    Share

    Collaborate

    We share findings with partners operating in the same constraint space.

    Get in touch