Analysis of more than 25 million security alerts processed during 2025 found that nearly 1% of confirmed incidents originated from low-severity or informational alerts. That single figure reframes a familiar tension: important threats can begin in the quiet parts of the alert stream, yet most teams lack the capacity to chase everything.
Two kinds of AI and the three-layer SOC
The source lays out a simple architecture for modern security operations: a bottom layer of existing security tools (SIEM, EDR, cloud security, identity and email security), a middle layer it calls an “autonomous AI SOC,” and a top layer populated by AI platforms such as Claude, Codex, and Cursor. Each layer has a distinct job.
AI platforms at the top are described as collaboration tools for analysts, detection engineers, and incident responders — places to write detections, investigate alerts on demand, summarize incidents, and automate repetitive work. The autonomous AI SOC in the middle is responsible for continuous, automated investigation: integrating with tools, applying organizational context, correlating findings, and determining which alerts need human attention.
The tokenomics problem
There is an economic constraint built into how large language models consume information. Every investigation starts with context: endpoint telemetry, process trees, authentication logs, email history, threat intelligence, prior investigations, detection rules, and organizational knowledge. Each piece of that context consumes tokens.
When a human analyst asks Claude to explain suspicious PowerShell activity or draft a Sigma rule, the token cost is reasonable. But treating every single alert as a fresh LLM conversation — in environments that produce thousands of alerts per day — multiplies those token costs dramatically. The article uses two analogies to make the point: asking Claude to investigate every alert is like asking a brilliant consultant to answer every phone call in a busy call center; and like using a Formula 1 car to deliver packages — engineering marvels designed for specific tasks, not uninterrupted, high-volume logistics.
Enterprises, the piece argues, need an architecture that combines deterministic workflows, cached context, forensic analysis, and selective AI reasoning so LLMs are invoked where they add value, not for every step of every investigation. That design keeps costs predictable while allowing continuous investigation.

Built by Nubivance.
OSINTSights' secure edge-first architecture, AI content pipeline, and serverless ops are designed by Nubivance. We do this for clients too.
Talk to us →The MDR reality
Many organizations do not operate their own SOC; they rely on a managed detection and response (MDR) provider. In those setups the MDR usually owns the investigation workflow, the case management system, the investigation history, and the enriched telemetry collected during response. Customers typically receive only escalated incidents and periodic reports, not the full set of evidence gathered during investigations.
That creates a practical barrier to using AI platforms like Claude for independent, full-scope investigations: the platform cannot reason over data it does not have. The article argues autonomous AI SOCs are a pragmatic architectural layer because they sit alongside an organization’s security tools, investigate alerts as they arrive, retain organizational context, and make that knowledge available both to human analysts and to AI platforms.
Where Claude, Codex and Cursor actually deliver value
Once an autonomous AI SOC has done the heavy lifting of triage and evidence gathering, AI platforms shift from being primary investigators to knowledge and productivity multipliers. The source lists concrete tasks where these platforms “shine”:
- Ask questions about completed investigations
- Draft and refine detection rules
- Hunt for emerging threats
- Summarize investigations for stakeholders
- Generate incident reports
- Explore new hypotheses
- Make final decisions on complex cases
The framing is clear: autonomous systems handle the repetitive grind of triage and continuous investigation; AI platforms help people think, create, and decide using the consolidated context the AI SOC provides.
What this means for security teams, MDR providers, and procurement leaders
Security teams: Expect to combine tools. The recommended model is not a single, do-it-all AI but a layered approach where an autonomous AI SOC continuously investigates alerts and hands distilled cases to human analysts using AI platforms for judgment, rule-building, and reporting.
MDR providers: The article highlights a coordination problem. Because many MDRs retain investigation artifacts inside their platforms, customers who want AI-assisted workflows must first ensure the raw alerts, telemetry, and history are accessible outside the MDR environment.
Procurement leaders: Be alert to “tokenomics.” Buying an LLM-heavy solution without considering token consumption and the architecture that minimizes per-alert LLM calls risks rapidly growing costs as alert volumes scale.
Bottom line: the piece argues organizations do not need to choose between autonomous AI SOCs and AI platforms like Claude — they need both. Machines can scale continuous investigation; platforms like Claude, Codex, and Cursor can then focus human effort where judgment, creativity, and rule-writing matter. For a practical conversation on how to put those pieces together, the source invites readers to join Intezer’s Co‑Founder and CEO, Itai Tevet, and CMO Lital Asher‑Dotan.
Source: FOMO in the SOC: Where AI Platforms like Claude Actually Fit — The Hacker News




