Over the previous yr, we watched a brand new class of alert seem in enterprise safety operations facilities and develop sooner than anything within the stream: alerts that have been triggered by AI instruments and brokers. Not assaults towards AI, however the bizarre, on a regular basis footprint of a corporation utilizing it, from builders operating coding brokers and non-technical employees signing client AI instruments into company accounts.
We reviewed AI-related exercise throughout quite a few enterprise environments. Two numbers body all the things that follows. AI-related alerts nonetheless account for less than 0.43% of all SOC alerts. And that share is climbing each single month, up 685% between February and June 2026. AI is a small slice of the alert stream right this moment and the fastest-growing slice on the similar time.
What makes these alerts value a safety staff’s consideration will not be their quantity however their composition. We type all the things an AI agent triggers in a SOC into three buckets: actual assaults, dangers, and noise, with the break up being 94.1% noise, 5.8% real danger, and 0.02% actual assaults. Which means that throughout the info we investigated, actual assaults that use AI brokers are a drop within the ocean. The price of AI within the SOC, up to now, will not be breaches. It’s a rising tide of alerts that look alarming and nearly by no means are, and a small, quiet set of real exposures that these alarms are likely to bury.
This put up walks via every of the three classes with anonymized examples. All buyer names, hostnames, usernames, and identifiers have been eliminated; indicators are defanged.
The New Form of the Alert Stream
AI adoption inside an enterprise will not be one conduct it’s two very totally different ones arriving on the similar time.
The primary is technical. Builders set up coding brokers that spawn shells, learn credential shops, open community tunnels, obtain packages, and run safety tooling all as legit work, and all of it indistinguishable to a detection engine from the early phases of an intrusion. That is the loud half, and it dominates the info.
The second is when staff grant OAuth consent to third-party AI functions, share data, and paste paperwork into generative-AI instruments. That is the quiet half. It hardly ever journeys an endpoint detection, however it’s the place information leaves the constructing.
Each halves land in the identical place, the SOC, and each look, at first look, like one thing to fret about. Sorting the sign from the noise is the complete job.
By the Numbers
AI accounts for a small share of the quantity however is fast-growing**.** Of the roughly 16.9 million SOC alerts we reviewed, about 73,000 (0.43%) have been AI-related. Learn by itself, that’s reassuringly small.
![]() |
| Variety of AI-related alerts per thirty days as seen in our system. |
The rise is monotonic. Each full month is greater than the one earlier than, and progress accelerated sharply in Might 2026. Over the window when reporting is secure throughout areas (February to June), quantity grew by 685%. The 0.43% determine is finest understood as right this moment’s ground, not a ceiling. A staff that sizes its AI-alert dealing with to present quantity will likely be under-provisioned inside 1 / 4.
The composition is as lopsided because the development is steep. Almost the entire AI-generated alerts are noise.
For this analysis, we investigated the AI-related inhabitants and sorted every alert by the underlying exercise. An actual assault is a confirmed compromise. A safety danger will not be a compromise however a real publicity (for instance, a coding agent operating with its permission safeguards disabled). Noise is legit exercise that tripped a detection written earlier than AI brokers existed. By that measure, almost the entire AI-related alerts are noise (94.1%), a small portion are real safety dangers (5.8%), and actual assaults are a sliver (0.02%).
![]() |
| The breakdown of the AI-related alerts based mostly on the ultimate classification of every alert. |
The second measurement is how those self same alerts have been dealt with in manufacturing with out a human within the loop. When an alert reaches an automatic triage platform, two separate choices are made about it.
- The decision states how harmful the exercise appears: it may be benign, suspicious, or malicious.
- 79.8% obtained a benign verdict.
- The response states what occurs subsequent: the alert could be suppressed (closed mechanically, so no analyst ever sees it), flagged for follow-up, or escalated to a human.
- 81.7% have been mechanically suppressed.
Of the AI-related inhabitants, solely 5.4% have been ever escalated to a human analyst; the rest have been flagged for follow-up.
A high-severity alert doesn’t essentially imply an precise risk. For instance, a single detection at a single buyer accounted for 55% of all “vital” verdict alerts flagging a Home windows binary (Increase.exe) as a lateral-tool-transfer. Upon inspection, it was discovered {that a} developer’s coding agent was organising a shell atmosphere, and the conduct was regular for the sort of work.
The lesson for any SOC is similar: severity labels on AI exercise should be learn with suspicion, not taken at face worth.
Class 1: Actual Assaults
An actual assault is an precise compromise or an attacker operation enabled by, or using on, AI adoption. That is the class each govt asks about first, and it’s the smallest, accounting for roughly 0.02% of AI-generated alerts.
With regards to precise threats that have been detected on this class of alerts, none was a compromise attributable to a corporation’s personal AI agent. Each alert titled “AI agent operating mimikatz,” “reverse shell from a coding instrument,” or “credential theft” was resolved, on inspection, to a developer doing legit work or to a detection misfiring. We return to these within the Noise part.
What was actual is an assault that rides on AI fairly than via it: a reside phishing marketing campaign that weaponizes AI model names as lures. Throughout a number of prospects, and as we expanded to new ones in the course of the window we studied, we noticed malicious emails with AI-themed topic traces that includes the largest names in AI. The lure works exactly as a result of AI adoption has made these manufacturers acquainted and their notifications routine. Staff now anticipate e mail from these merchandise, which is precisely what the attacker is relying on.
Listed here are some examples of incidents the place we noticed the execution of instruments or instructions that often point out actual assaults (or penetration testing), solely in these circumstances they have been invoked by Claude, Codex, and many others. So the investigator additionally must query why the brokers have been operating these instruments and whether or not it was a part of an actual assault that exploited the agent.
- Anthropic is used as bait within the enterprise context. In that alert, the e-mail topic is RE: Anthropic Engagement approval & fee, and the evaluation says the sender references a supposed contract/bill with Anthropic to make a big fee request seem legit. So Anthropic will not be the sender or the risk supply, it’s a part of the pretext used to assist the bill fraud story.
- An e mail makes use of a pretend Google/Gemini Advertisements invitation lure to look legit and reliable. It presents itself as a business-related workspace invitation, encouraging the recipient to attach or be a part of what appears like an official Gemini Advertisements atmosphere, however the sender and reply-to infrastructure are usually not related to Google and as an alternative depend on the suspicious area gemini-advertisers[.]com, indicating a model impersonation try designed to drive the person to a malicious web site.
- The e-mail impersonates OpenAI (“OpenAI Associate Summit 2026”) however originates from noreply-zoomevents@zoom.us. Though the URLs use legit zoom.us infrastructure, the content material and registration move are getting used to lend credibility to a fraudulent invitation.
![]() |
| Phishing e mail impersonating OpenAI |
![]() |
| Machine code phishing |
- The AI IDE Cursor appears to have moved from regular coding exercise into unsafe low-level system actions: whereas possible trying to finish a debugging or troubleshooting job, the agent used a recognized credential-dumping method (MiniDump through comsvcs.dll) that may expose secrets and techniques from course of reminiscence. The parent-child chain Cursor.exe → powershell.exe → rundll32.exe, the temp .ps1 scripts, and the memory-dump instructions present the IDE initiating an automatic motion sequence that will have been meant to assist growth, however did so in a approach that created a severe credential-access danger on the endpoint.
The sample throughout all three is value stating plainly: the nearer we seemed, the extra the “assault” dissolved into context. That’s the defining attribute of AI-era triage.
Class 2: Unsafe Use
About 5.8% of the AI-related alerts are those we expect deserve probably the most consideration. These alerts detect an unsafe use of AI instruments, not essentially a compromise (but). It’s the second when an agent, behaving precisely as instructed and with no attacker concerned, does one thing that materially exposes the group or the person.
The primary danger is brokers operating with a permission-bypass flag, the choice that tells the agent to cease asking the person earlier than it acts. Many customers select to belief the agent to not destroy their machines or execute harmful instructions, however as expertise and, now, the info present us, in lots of circumstances, brokers will try, and principally reach executing instructions that expose the group and the person to nice dangers. It’s value noting that, particularly when operating the agent with the permission-bypass flag, it’s endorsed to make use of extra configurations, often known as harnesses, to programmatically stop the agent from trying to execute dangerous instructions.
![]() |
| The break up of permission-bypass flags as seen in our system. |
On each pattern we examined, the invocation was legit developer work. That’s precisely why it issues. This is similar precondition abused in a publicly documented supply-chain assault, the place an attacker’s malicious code executed freely as a result of a coding agent had been launched with its permission prompts disabled. The publicity will not be intent; it’s that the rail is off, throughout many shoppers and at scale, ready for the one time the code the agent is requested to run will not be benign. Notably, these similar permission-bypassed invocations are additionally the one largest supply of false positives.
Different cases of unsafe use we surfaced:
- A reverse tunnel opened by an AI IDE**:** In one of many environments, an AI code editor spawned PowerShell, which launched ngrok and opened a named reverse tunnel to the general public web utilizing the person’s personal auth token. Whereas the intent is benign, it’s a actual danger and publicity.
- An agent dumping the complete macOS keychain to learn one token: To retrieve its personal and cloud providers’ saved credentials. An agent ran safety dump-keychain > /tmp/, which writes each saved secret to a temp file, briefly exposing all of them.
- Granting OAuth entry to AI brokers implies that staff may share delicate data with third-party service suppliers. However on prime of that, it will increase the chance of unauthorized information entry through immediate injection or a compromised AI account. We noticed a number of alerts for OAuth utility consent granted to ChatGPT throughout tenants, “first sign-in to a brand new utility: OpenAI” occasions, and, at one buyer, a sizeable cluster of data-protection alerts for generative-AI uploads. Most are benign. However that is the floor the place company information is distributed to a third-party mannequin, and it’s nearly invisible to endpoint tooling.
Class 3: Noise
Noise is the biggest class by an order of magnitude, 94.1% of the AI-generated, and it’s the one which immediately determines whether or not a SOC drowns. Noise right here will not be random. It’s particular and diagnosable: detections written earlier than AI brokers existed, now firing at excessive severity on routine agent work. This isn’t a brand new tendency within the SOC, as Sophos beforehand reported.
The clearest instance is the AI distributors’ personal software program. The real Anthropic Claude Desktop installer, verified by its code signature, triggers main EDR guidelines equivalent to “Ransomware Operations detected” and “Encoded PowerShell Obtain and Run” throughout a number of prospects. The installer is legit. The detection describes installer conduct within the ransomware vocabulary.
Beneath that sit the agent-behavior false positives, all confirmed on inspection to be builders utilizing instruments as meant:
- The replace of a coding agent and the builders’ use of the agent triggered a “Ransomware Operations detected”. The binary that triggered the alert is a legit, signed software program package deal. The conduct that seemed “ransomware-like” got here from regular Electron/Squirrel installer exercise and developer instrument utilization.
Claude Setup.exe
Path: DeviceHarddiskVolume3Users{REDACTED}DownloadsClaude Setup.exe
CMD: "C:Customers{REDACTED}DownloadsClaude Setup.exe"
Replace.exe
Path: DeviceHarddiskVolume3Users{REDACTED}AppDataLocalSquirrelTempUpdate.exe
CMD: --install .
Mum or dad: Claude Setup.exe
Mum or dad Path: DeviceHarddiskVolume3Users{REDACTED}DownloadsClaude Setup.exe
Mum or dad CMD: "C:Customers{REDACTED}DownloadsClaude Setup.exe"
squirrel.exe
Path: DeviceHarddiskVolume3Users{REDACTED}AppDataLocalAnthropicClaudeapp-1.1.1093squirrel.exe
CMD: --updateSelf=C:Customers{REDACTED}AppDataLocalSquirrelTempUpdate.exe
Mum or dad: Replace.exe
Mum or dad Path: DeviceHarddiskVolume3Users{REDACTED}AppDataLocalSquirrelTempUpdate.exe
Mum or dad CMD: --install .
codex.exe
Path: C:Customers{REDACTED}AppDataRoaming...bincodex.exe
CMD: codex.exe --yolo
Mum or dad: node.exe
Mum or dad Path: ...Program Filesnodejsnode.exe
Mum or dad CMD: "node" "C:Customers{REDACTED}AppDataRoaming...codexbincodex.js" --yolo
The false-positive charges are the story. Throughout the noisiest AI exercise detections, the benign share ranges from 77% to 99%. A number of detections are flawed on the AI-generated greater than 4 instances out of 5:
![]() |
| View of the detection that was triggered on benign AI-related conduct. |
The one exception proves the rule. The ClickFix detection is the one cluster that leans genuinely extreme, solely 37% benign, and it does so exactly as a result of it collides with the permission-bypass danger from the earlier part: it fires on coding brokers launched with –yolo. Even the “real-looking” noise traces again to legit AI use.
What Safety Groups Ought to Do
From our evaluation, step one for each SOC is evident: tune the noisiest legacy detections, those firing at excessive severity on routine agent work. Subsequent, outline insurance policies on what data could be shared with third-party AI platforms (as with all third-party platform) and, based mostly on these insurance policies, proactively hunt for permission-bypass flags, unauthorized tunnels, and dangerous OAuth grants fairly than ready to be alerted.
The second step is more durable, as a result of it touches how triage itself works. AI instruments execute instructions on the person’s machine, with the person’s credentials, basically performing on the person’s behalf. Alerts are due to this fact triggered by actions attributed to the person, and in lots of circumstances the person was not conscious these actions passed off. Earlier than AI, suspicious exercise executed on a person’s machine with out their information often indicated a excessive chance that an attacker had taken over the machine. Now SOC groups face a brand new layer of complexity: first decide whether or not the motion in query was executed by an AI agent or instrument.
To separate the person’s context from the agent’s, and to maintain the agent away from credentials and delicate data it shouldn’t have, we recommend operating AI instruments in an remoted atmosphere with restricted entry, equivalent to a Docker container or a digital machine. Isolation limits what the agent can attain, and it makes the agent’s conduct simpler to tell apart from the person’s personal exercise.
What This Means for the SOC
Pulling the three classes collectively, the operational actuality of enterprise AI adoption appears like this:
- Actual assaults (0.02%): not one of the confirmed assaults we investigated have been carried out by a corporation’s personal brokers. The real assault exercise we discovered rides on AI adoption from the surface, phishing lures constructed on model names staff now belief, not on the brokers themselves.
- Safety dangers (5.8%): actual, standing, and largely invisible to alerting. Brokers run with their permission safeguards disabled, open tunnels to the general public web, over-expose saved secrets and techniques, and ship company information to third-party fashions. None of that is an incident, and all of it’s publicity.
- Noise (94.1%): the dominant value. The only highest-value motion accessible to most SOCs right this moment will not be a brand new detection. It’s tuning the legacy ones so {that a} developer operating a coding agent doesn’t generate a maximum-severity alert.
The uncomfortable synthesis is that AI adoption has not, up to now, introduced a wave of AI-enabled breaches. It has introduced a wave of alerts, small as a share of whole quantity right this moment, which have grown 18-fold in six months and are overwhelmingly false, alongside a smaller, quieter set of real exposures that the alerts are likely to bury. A SOC that treats each agent motion as a possible intrusion will exhaust itself on false positives and, in doing so, will likely be much less prone to discover the ngrok tunnel or the keychain dump that truly issues.
The work forward is due to this fact much less about detecting AI assaults and extra about educating detection engines what regular AI conduct appears like earlier than the quantity that’s doubling and tripling month over month makes that work unavoidable. Understanding this distinction is what separates a SOC that scales with AI adoption from one that’s buried by it.
About Intezer
Intezer is an autonomous AI SOC platform constructed to unravel precisely the issue this information illustrates: the rising hole between alert quantity and analyst capability. Slightly than tuning particular person detections one after the other, Intezer investigates each alert mechanically, making use of forensic-level evaluation to find out what’s really occurring on an endpoint or in an e mail, then delivers a verdict a human can belief. Meaning 100% alert protection — together with the AI-related noise — with out the SOC drowning in it.
Should you’re seeing the identical shift in your personal alert stream, go to intezer.com to see how Intezer’s platform handles it.
Observe: This text has been expertly written and contributed by Nicole Fishbein. Senior Safety Researcher and Malware Analyst at Intezer.















