The Agentic SOC Alliance is trying to answer a question cybersecurity companies have mostly skipped in their rush to sell artificial intelligence: What should an agent actually be trusted to do? The recently announced Agentic SOC Alliance is trying to bring order to one of cybersecurity’s fastest growing categories. Announced ahead of Black Hat USA 2026 with 15 founding members, including ExtraHop, CrowdStrike, TENEX.AI, Torq, Dropzone AI and LangChain, the group wants to define and test a common operating model for agentic security operations. The group plans to test a common operating model for agentic security operations built around three layers called Context, Harness and Model.

Security vendors are already asking companies to trust AI agents with increasingly sensitive work. Some agents summarize alerts. Others investigate incidents, query systems and recommend containment. The most ambitious can act inside live environments. Without common standards for evidence, permissions and accountability, buyers may struggle to tell the difference between useful autonomy and risky automation.

The bigger question is whether the industry can agree on what a trustworthy agentic SOC should look like before the term becomes just another marketing label. The alliance is betting that shared architecture, clearer benchmarks and better controls can give CISOs a way to judge which systems deserve more authority and which ones do not.

What Counts As An Agentic SOC?

Richard Rogers, chief marketing officer of TENEX.AI, said the biggest problem may be that vendors are using the same label for products with very different capabilities.

“There’s no real definition of an Agentic SOC,” Rogers said at Black Hat. One goal of the alliance, he said, is establishing “what the bar is to call yourself” an agentic security operation.

A product that summarizes alerts is different from one that investigates an incident. An agent that can disable an account or isolate a machine creates another level of risk entirely.

ExtraHop’s proposed architecture tries to separate those jobs. Context supplies information about identities, devices, workloads and network activity. The Harness controls what an agent can access and which tools it can use. The Model is focused on doing the reasoning.

Rogers said autonomous security needs “one good source of truth for identity,” coupled with reliable information from the network and endpoints. The goal is to give agents an auditable factual base rather than asking a model to reconstruct attacks from disconnected evidence. The problem is familiar to anyone who has seen good quality security tools work with a broken dashboard. Better models and tools do not fix bad gauges.

Changes In Cybersecurity’s Speed Limit

“We believe we’re in a new paradigm in cybersecurity,” said Eric Foster, CEO and Founder of TENEX.AI. After 34 years in the industry, he still sees the old contest between attackers and defenders. What changed, he said, is “the exponential speed of change.”

Foster pointed to a recent exercise with Armadin, the company founded by former Mandiant CEO Kevin Mandia. TENEX executives said the test deployed 20,000 agents and generated roughly 231 billion logs. Rogers said the broader exercise involved about 1.3 million attack attempts. Foster said the data from the exercise could have taken a typical organization months to work through manually.

While there haven’t yet been independent benchmarks or audits on this sort of activity, the underlying point is that automated attacks can create more activity than a human security team can investigate one alert at a time. Foster thinks that same automation could help smaller companies close part of the defensive gap with enterprises that spend tens or hundreds of millions of dollars on security.

“How does the 10 person credit union accomplish some of those things?” he asked. “Artificial intelligence is shrinking the gap.”

That could become one of the more significant economic arguments for the agentic SOC. AI is not merely a way for a large bank to make a sophisticated security operation faster. It could give a manufacturer, regional business or credit union access to investigation capabilities it could never afford to staff around the clock.

Foster said emerging companies like theirs aim to make cyber defense “better, faster, and more cost effective,” with all three conditions required.

The Alliance Is Entering A Crowded Race

The AI markets are getting increasingly crowded and noisy. Gartner has explicitly warned about “agent washing,” where vendors relabel assistants, chatbots or conventional automation as agentic AI. Gartner analyst Anushree Verma said, “Most agentic AI projects right now are early stage experiments or proof of concepts that are mostly driven by hype.” Gartner predicts more than 40% of agentic AI projects will be canceled by the end of 2027, citing costs, unclear value or weak risk controls.

That problem is already showing up in analyst research. “It’s difficult to trust a technology that won’t always answer in the same way,” Forrester principal analyst Allie Mellen wrote. She argues that buyers should scrutinize accuracy, repeatability, explainability and how vendors validate their systems.

ExtraHop and TENEX are hardly alone in the objectives to put AI and agentic operations at the center of security operations. CrowdStrike launched its Charlotte AI AgentWorks ecosystem in March, letting customers build and manage security agents on the Falcon platform. CrowdStrike described the goal as an agentic SOC where humans are amplified by agents rather than replaced by them.

CrowdStrike and IBM announced a separate collaboration around Charlotte AI and IBM’s Autonomous Threat Operations Machine, aimed at coordinating machine speed investigation and containment. That still leaves substantial room for the Agentic SOC Alliance. Its members include companies that may eventually fight for the same security budgets.

Governments are reaching a similar conclusion. In May, CISA, the NSA and other Five Eyes cyber agencies issued joint agentic AI guidance calling for human control points around high-risk actions. The agencies acknowledged that methods for evaluating agentic systems are still developing.

Useful standards such as those proposed by the Agentic SOC Alliance fit this gap by telling buyers how often an agent reaches the right conclusion, how much evidence supports its decision, when a human intervenes and what happens after the machine makes a mistake. Cybersecurity vendors have spent the past year proving they can build agents, but now they need to prove those agents deserve authority and provide lasting business value.