Enterprise security teams are facing a surge in AI-related alerts, which grew 685% between February and June 2026, though most remain benign noise rather than actual security breaches.
Key Points
- AI-related activity currently accounts for 0.43% of all security operations center (SOC) alerts.
- Analysis shows 94.1% of AI-generated alerts are noise, 5.8% represent genuine security risks, and only 0.02% are confirmed attacks.
- Common security risks include coding agents running with permission-bypass flags, unauthorized reverse tunnels, and excessive credential access.
- Phishing campaigns are increasingly weaponizing trusted AI brand names to deceive employees into clicking malicious links.
- Automated triage systems currently suppress 81.7% of AI-related alerts, with only 5.4% requiring human analyst intervention.