AI Security

Machine Speed Has to Be Earned

September 29, 2026

Every federal SOC leader has heard the pitch. Put AI in the SOC so you can defend at machine speed. The pitch skips the hard part. Speed is the easy thing to buy, trust is what agencies have to build. Without being able to trust the AI solutions, an agent moving at machine speed becomes a faster way to cause an outage. 

The pressure to get this right has never been higher. Adversaries armed with generative AI now move from reconnaissance to breach faster than any analyst can triage an alert. In June, Executive Order 14412 started a second clock, requiring agencies to move high-value systems to post-quantum key establishment by the end of 2030 and post-quantum digital signatures by the end of 2031. SOC leaders now face the demands of meeting both deadlines, but without additional resources and budgets. 

That tension framed the latest GIST 360 webinar, Defending at Machine Speed and Building the AI-Ready Federal SOC, where Swish CTO Sean Applegate hosted Thomas Dempsey, director of the Security Operations Division at U.S. Customs and Border Protection, Jay Rekhi, who leads the Hardware Security Group at NIST, and Jignesh Gandhi, CIO and CISO of FedTec around a discussion on the complexities and challenges of building an AI-powered SOC.  

HUMAN TIME TO REACT AND CORRELATE HAS NEARLY DISAPPEARED 

The shift did not arrive with a single breach. It was built from the nation-state campaigns of the SolarWinds era through the generative AI surge that multiplied threat vectors after 2020. Alert queues and backlogs assumed defenders had time to detect, investigate, contain, and learn before the situation changed. That assumption no longer holds. AI systems are now both the target and the source of incidents, and an agent can observe, decide, and act across multiple systems in milliseconds. 

The first thing to break in this new paradigm is correlation. Network, cloud, endpoint, and identity telemetry already strains the largest SOCs, and AI platforms stack prompts, agent actions, and model activity on top. Rules and compute can trim the volume, but teams still cannot trace the blast radius of an event as fast as it unfolds. One of the answers has been to hand correlation to AI reasoning and move analysts up the value chain, from working playbooks, to hunting adversaries before an alert ever surfaces. When individual alerts roll up into a single incident or an attributed campaign, teams act before an event becomes a crisis. That demands a different skill set, and reskilling belongs in the plan alongside the tooling. 

AUTONOMY HAS TO BE ENGINEERED 

Handing AI more of the work raises the obvious question of who governs the agent. NIST’s emerging answer is laid out in an National Cybersecurity Cetner of Excellence concept paper that Rekhi walked through, and rests on four requirements. Every agent needs its own verifiable identity rather than borrowing the identity of whoever launched it. Authorization stays granular and contextual, because access to an API should never grant every operation that API exposes. Every significant decision must be attributable and auditable, which forces agencies to rethink logging. Finally, high-impact or irreversible actions need a hard safety boundary. If a team cannot identify, constrain, observe, attribute, and stop an agent, that agent is not ready for the SOC. 

CBP shows what that discipline looks like inside one of the largest SOCs in civilian government. Within the agency, AI operates and has only “read-only” privileges. AI agents triage, gather context, and return findings, while human analysts make every determinative call, because an agent follows instructions without understanding what happens when the wrong system goes down. Having a human in an AI loop will come, but only as governance matures across the enterprise, including every place an agent might reach, such as EDR platforms that touch endpoints directly. Restraint matters as well. Deterministic playbooks still handle well-understood tasks at low cost, and not every problem needs an agent. 

TRUST IS BUILT ONE PLAYBOOK AT A TIME 

The biggest gap to an AI-powered SOC is rarely technology, but rather organizational readiness. Agencies that skip governance, from which LLMs they trust to what data feeds them, end up with tools analysts never fully use. The agencies that have succeeded start with a human fully in the loop and prove value immediately, collapsing dozens of related alerts into one enriched incident. As patterns emerge, they automate a handful of alert types at a time, and every determination and action flows into the ITSM platform so the audit trail holds. Well-understood IT operations tasks, such as port flapping and Wi-Fi tuning, offer another lower-risk proving ground for AI agents. 

The onslaught of AI-generated attacks have resulted in SOC engineers caught between chasing alerts and building new capability. The result? Burnout. In deployments of AI-ready SOC platform tools that Gandhi cited, alert volume fell roughly 80 percent, response times dropped from hours to under a minute, and one organization was able cut analyst workload in half without cutting staff. The platform paid for itself in under a year, and engineers moved to the work the mission actually needs from them. 

TWO CLOCKS, ONE ARCHITECTURE 

Interestingly, post-quantum readiness does not compete with AI adoption, but rather depends on the same modernization. Every new AI-enabled investment should be PQC-ready and cryptographically agile, with FIPS 203 and its ML-KEM key establishment standard setting the near-term priority and FIPS 204 and 205 covering digital signatures. Modernization is the moment to write PQC into architecture and procurement baselines rather than retrofit it later. 

Agencies behind on cryptographic inventory should stop waiting for a perfect list. Start with the highest-value assets holding sensitive, long-lived data, prioritize by risk and mission impact, and plan systematic migration of legacy systems over the next three years. AI accelerates that work too. Existing SOC tools already see much of the cryptographic landscape, and AI-enabled platforms can now flag which devices support PQC and confirm whether it is actually enabled, replacing the manual data call that once moved through an organization one team at a time. Harvest now, decrypt later means data stored today becomes tomorrow’s breach, and the NIST NCCoE migration project gives agencies a place to work through the problem with peers. 

THE GAP WILL BE OBVIOUS IN A YEAR 

Presenters felt that within the next year, the agentic AI hype cycle will settle, and the difference between agencies will be clear. Those that bought another tool with AI on the label will have little to show. Those that changed people, process, and governance together will show measurable gains in speed, workload, and response. Integration separates the two. New capabilities must work with existing SIEMs, firewalls, and cloud platforms rather than wait for them to be replaced, and agencies that deploy while modernizing in parallel see value quickly. Measurement keeps everyone honest. DORA metrics transformed how DevOps teams prove speed and quality, and AI-augmented SOCs need the same discipline. 

WATCH IT. SHARE IT. THEN ACT ON IT. 

Machine speed is no longer optional, but it has to be earned. Watch the full Defending at Machine Speed session on-demand, and bring SOC leaders, security architects, and governance owners into the conversation. Explore the podcast, blogs, and recordings at gist360.com, and tell us what to cover next. When the time comes to benchmark SOC readiness for agentic operations or map a post-quantum migration against the EO 14412 timeline, reach out to the team at Swish.