Blog

What Changed Between RSAC and Black Hat 2026: Agentic SOC Moves from Vision to Governed Execution

Five shifts show how the Agentic SOC conversation moved from promising demos to production operations governed by evidence, permissions, cost, and accountability.

What Changed Between RSAC and Black Hat 2026: Agentic SOC Moves from Vision to Governed Execution

At RSAC 2026, the Agentic SOC was still largely a vision taking shape. Vendors showed how AI agents could investigate alerts, gather context, and recommend next steps. The demonstrations were compelling, but the operating model remained incomplete.

By Black Hat 2026, the conversation had changed. The central question was no longer whether an AI agent could complete an impressive investigation in a controlled demo. It was whether AI could perform trustworthy security work every day, within clear boundaries for evidence, permissions, cost, and accountability.

That change in emphasis matters. Security operations cannot be evaluated on intelligence alone. A production system must also be reliable, auditable, controllable, and economical. Across the two conferences, five shifts made that transition visible.

1. From Previews to Production

At RSAC, many agentic capabilities were still previews, trials, or one-click investigations. By Black Hat, several product announcements pointed toward production deployment, including generally available releases, scheduled workflows, Model Context Protocol (MCP) connectors, and stronger operational controls.

The distinction is more than a product label. A demo asks whether an agent can complete a task once. Production asks whether an enterprise can operate it reliably every day.

That means security teams need answers to practical questions. What happens when a connector fails? Can the agent retry safely? Which tools is it allowed to use? How much can a long-running investigation cost? Who receives a receipt for every action? Production readiness turns agent performance into an operational discipline.

From previews to production

2. From Static Alerts to Living Investigations

Traditional SOC workflows often treat alerts as isolated events. An alert arrives, an analyst investigates it, and the case is closed or escalated. But attackers do not organize their behavior around individual alerts, and evidence rarely arrives all at once.

AI is beginning to connect evidence across time. Elastic's expanded Attack Discovery, for example, uses AI to connect alerts into attacks and can draft detection rules for analyst approval. Command Zero's Throughline takes another approach: new alerts can join existing investigations, extend their timelines, and reopen resolved cases when new evidence appears.

The important shift is from a fixed alert record to a living investigation. As new telemetry arrives, the system can revise its hypothesis, connect related activity, and preserve the history of how its understanding changed. This gives analysts a more complete narrative while reducing the repetitive work of rebuilding context from scratch.

From static alerts to living investigations

3. From Siloed Data to Connected Security Operations

Security data already spans SIEM platforms, data lakes, object stores, identity systems, endpoint tools, cloud services, and operational applications. Agentic security operations are beginning to work across those environments directly, without requiring every source to be migrated into a single platform first.

This changes the integration challenge. The question becomes less about where all data must live and more about how access to distributed data is governed.

An agent performing federated search needs consistent schemas, stable entity identifiers, controlled access, reliable query execution, traceable evidence, and clear cost attribution. Without those foundations, cross-platform reasoning can create a convincing answer that is incomplete, unauditable, or unnecessarily expensive.

Connected operations therefore do not eliminate the need for a control plane. They make that control plane more important.

From siloed data to connected security operations

4. From “Agent vs. Workflow” to “Agent + Workflow”

Agents will not simply replace playbooks. A more practical architecture is emerging: agents provide the reasoning layer, while deterministic workflows provide the execution layer.

The agent can gather context, form hypotheses, explore alternatives, and select an appropriate path. The workflow can enforce approvals, execute known actions, handle retries, verify outcomes, preserve receipts, and support rollback.

This division of responsibility matches the strengths of both approaches. Agents are useful when an investigation is ambiguous and the next step depends on context. Workflows are useful when an action must be predictable and repeatable.

The result is not autonomy for its own sake. It is adaptive investigation connected to controlled execution.

Agent reasoning plus deterministic workflow

5. From Trusting Agents to Governing Their Actions

Once agents can search sensitive data, create detection logic, or trigger response actions, identity and governance become core product requirements.

Maturity depends on least-privilege access, tool allowlists, evidence trails, approval boundaries, kill switches, and spending controls. Every action should have an attributable identity. Every conclusion should point back to evidence. Every high-impact step should pass through an explicit policy boundary.

This also changes the role of SIEM. In this operating model, SIEM does not disappear. It increasingly serves as the data, policy, evidence, and audit control plane for the Agentic SOC. It provides the context agents need while preserving the record organizations need to understand and govern their behavior.

From maximum autonomy to governed autonomy

What the Next Agentic SOC Will Be Measured By

The next competitive advantage will not come from collecting more logs or writing more rules alone. It will come from enabling AI to complete more trustworthy security work.

That requires a different scorecard. Instead of measuring only alerts processed or automations triggered, teams should track outcomes such as:

• Investigations completed with verified evidence
• Time to analyst decision
• High-impact actions approved before execution
• Response actions with confirmed outcomes
• Cost per completed investigation

These measures connect AI activity to operational value. They also expose failure modes that a polished demonstration can hide: missing evidence, excessive tool use, unclear authorization, uncontrolled cost, or actions without a verifiable outcome.

The Takeaway

Between RSAC and Black Hat 2026, Agentic SOC moved from a conversation about possibility to a conversation about operations.

Real progress is not simply more autonomous AI. It is governed autonomy: AI that can reason across connected evidence, work with deterministic processes, and act within visible limits.

The organizations that define those limits well will be able to give agents more responsibility with greater confidence. The question is no longer whether we should trust agents. It is how well we can manage them.

Explore how SecNova AI enables governed, evidence-backed security operations.