Start your day with intelligence. Get The OODA Daily Pulse.
The Agentic SOC Alliance is trying to answer a question cybersecurity companies have mostly skipped in their rush to sell artificial intelligence: What should an agent actually be trusted to do? The recently announced Agentic SOC Alliance is trying to bring order to one of cybersecurity’s fastest growing categories. Announced ahead of Black Hat USA 2026 with 15 founding members, including ExtraHop, CrowdStrike, TENEX.AI, Torq, Dropzone AI and LangChain, the group wants to define and test a common operating model for agentic security operations. The group plans to test a common operating model for agentic security operations built around three layers called Context, Harness and Model. Security vendors are already asking companies to trust AI agents with increasingly sensitive work. Some agents summarize alerts. Others investigate incidents, query systems and recommend containment.