Attend our live Black Hat session
SOC AI agent adoption is accelerating rapidly, with many organizations already piloting AI for triage, investigations, and response. Yet analysts predict up to 30% of these initiatives will fail—not because of the AI itself, but because of the foundation beneath it.
When AI runs on fragmented telemetry, inconsistent context, or disconnected workflows, it doesn’t improve decisions—it amplifies the same operational challenges that led SOC teams to AI in the first place.
In this session, we’ll explore the most common pitfalls in adopting AI for security operations, and what it takes to build an SOC where AI actually delivers.
Attendees will learn:
- The data and telemetry challenges that prevent successful AI adoption
- Why many AI tools struggle inside real-world SOC workflows
- How to introduce agentic AI safely, with guardrails that maintain analyst control and accountability
- The architectural foundations required to make AI a reliable force multiplier for security teams

Schedule time with Sumo Logic to learn how to find and mitigate threats faster with industry-leading MITRE ATT&CK coverage, advanced UEBA, and enhanced threat intel feeds.
Additional resources
Governing AI in the age of agentic systems and Model Context Protocol
The rise of shadow AIT
Cloud SIEM evaluation guide
Claude Code is running bash commands on your infrastructure
Ep 30: What is data pipeline management, and why does it matter for security?
