ZscalerAIAgentic AISecurity Operations

Zscaler's Agentic SOC Bet: Stop Hiring Humans to Read Logs at Robot Speed

September 22, 2026 · Brian Deitch

Zscaler announced Zscaler Agentic SOC on September 9, a new approach to security operations built to reduce exposures, scale up human analysts with AI agents, and contain AI-driven attacks at machine speed. Standard disclosure applies: I work at Zscaler, so read the enthusiasm as informed, not neutral.

The pitch is not "we bolted a chatbot onto your SIEM." It's a rebuild of the SOC workflow itself, from the ground up, with an AI-first architecture instead of AI sprinkled on top of the same stack that was already struggling to keep up.

The Problem Is Speed, Not Volume

Security operations has always had an alert-volume problem. That's old news. What's new, according to Zscaler's own threat research team, ThreatLabz, is a rise in evasive tactics: attackers hosting malicious activity on trusted sites, abusing legitimate remote management tools, and running attacks through the browser where they blend into normal traffic. None of that is loud. All of it is fast.

A human analyst triaging alerts by hand was already outmatched by volume. Now the attacks themselves move faster than a person can manually correlate, investigate, and respond, which means the old model of "detect, then have a human decide what to do about it" has a built-in lag that attackers are learning to exploit.

What Agentic SOC Actually Does

Zscaler is building this on telemetry it already has: its Zero Trust Exchange sees network, identity, endpoint, cloud, and AI traffic across what the company says is 750 billion daily zero trust transactions. Layered on top of that is what Zscaler calls the world's largest decoy mesh network, plus specialized AI agents that handle specific jobs, triage, root-cause investigation, assigning verdicts, and triggering response, rather than one generalized AI trying to do everything at once.

The part I find more interesting than the telemetry is who Zscaler partnered with to power the reasoning layer: Anthropic and OpenAI, integrated alongside Zscaler's own threat intelligence. That's a company betting that frontier AI labs plus proprietary security telemetry beats either one alone. It also means the agents aren't starting from a blank slate. Zscaler says they've been trained and tuned on more than 10 years of frontline SOC, managed detection and response, and threat-hunting experience, plus continuous human backup from Zscaler and Red Canary security experts.

The other half of the pitch is closed-loop remediation. Detection without action is just a fancier alert. Agentic SOC ties directly into Zscaler's inline zero trust controls, so it can isolate a compromised user, block command-and-control traffic, or cut off lateral movement automatically, instead of routing everything through a human who has to click approve at 3am.

"AI-driven attacks are moving faster than traditional SOC models were ever designed to handle. Agentic SOC is a fundamental rethinking of security operations, built with agentic capabilities at its core to reduce exposures proactively, extend human expertise with AI agents and contain threats at machine speed."

— Deepen Desai, Executive Vice President of Cybersecurity, Zscaler

A Customer's Actual Complaint

The quote in the release I trust the most is the one from a customer describing the problem, not the vendor describing the solution. Andrea Licciardi, Senior Cybersecurity Manager at Maire Tecnimont, said his team was "drowning in alert noise, forcing top analysts into triage instead of proactive threat hunting." That's the real cost of an overloaded SOC. You hire people for judgment and pattern recognition, then bury them in a queue where all they have time to do is close tickets. Licciardi says Agentic SOC gave his team full attack-path context from telemetry they already had, which moved them from chasing fragmented signals to making faster, more informed calls.

Industry analyst Allie Mellen, who covers this space closely, made the point that AI-driven attacks now operate at a speed and adaptability that looks nothing like traditional human-led activity, and that the fundamentals, Zero Trust principles, limiting access, and making attacks expensive to run, matter more than ever as a result. That's the right framing. Agentic SOC isn't a replacement for zero trust discipline. It's what you get when you point AI agents at the telemetry that discipline already produces.

Bottom Line

The interesting bet here isn't "AI can read logs faster than a human," which nobody disputes. It's that specialized agents, trained on over a decade of real SOC and threat-hunting work and backed by frontier models from Anthropic and OpenAI, can do the triage and containment fast enough that human analysts get their actual job back: hunting for what the automation missed, instead of drowning in what it flagged. Whether that holds up at scale in messy real-world environments is the thing to watch over the next year. But the diagnosis, that the SOC's biggest problem is a speed mismatch between attacker and defender, is correct, and it's the same problem I keep writing about in a dozen different disguises.

Zscaler Agentic SOC is available globally now.

Full release: Zscaler launches Agentic SOC to contain AI-Driven Threats

zscaleragentic-socsecopsai-agentsthreat-detectionanthropicopenaired-canary
All postsDiscuss on LinkedIn