Most security product research answers one question: can analysts find and triage an alert, run a query, or investigate an endpoint? Most mature products have solved this.
AI changes the question. When an analyst dismisses an alert because the AI flagged it low-priority, did they evaluate it independently or accept the recommendation? Defer too readily and you miss what the model wasn't trained on. Ignore the recommendations and you've bought automation you don't use.
Both look the same from the outside - an analyst made a call and moved on. Neither shows up until something is missed.
Research on human-AI collaboration has established methods for studying this - trust calibration, appropriate reliance, confidence elicitation - and applied them in clinical contexts. They haven't been applied to SOC workflows. AI triage platforms are scaling now. Radiology went through this - AI-assisted image reading raised the same question: when does the radiologist trust the flag, when do they override it? That's now an active research area with published methods.
If security vendors are doing this work, they're not publishing it. Which means it's a competitive edge - or a gap. Probably both.
13 May 2026
AI changes the question
First posted on LinkedIn, 13 May 2026 — reproduced here as written