[{"data":1,"prerenderedAt":705},["ShallowReactive",2],{"uc-security-alert-triage-and-investigation":3,"uc-regulations":504},{"useCase":4,"evidence":210,"blitsAiDeployments":390,"benchmarks":391,"indicative":420,"related":423,"indexability":502,"includeUnpublished":216},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":18,"functions":24,"patterns":27,"channels":32,"audience":36,"autonomy":37,"adoptionStage":38,"problem":39,"problemStats":40,"howItWorks":41,"valueDrivers":42,"kpis":47,"indicativeValue":55,"macroEstimates":91,"feasibility":92,"implementation":108,"risk":154,"blitsAi":187,"faq":189,"related":202,"datePublished":205,"dateModified":205,"lastVerified":205,"changelog":206,"slug":209},"AI for security alert triage and investigation in the SOC","Security alert triage","AI SOC alert triage and phishing investigation","AI triage of SOC alerts and reported phishing. St. Luke's says its agent saves nearly 200 hours monthly; Google Cloud reports 97% less triage time at Human Managed.","published","An AI agent in the security operations centre that picks up each new alert or user reported phishing email, gathers the evidence from the SIEM, endpoint, identity and threat intelligence tools, gives a verdict with its reasoning and a draft incident summary, and closes clear false positives while an analyst approves every containment action.",[12,13,14,15,16,17],"AI SOC analyst","agentic SOC","security alert triage agent","phishing triage agent","reported phishing email analysis","AI incident investigation copilot",[19,20,21,22,23],"cross-industry","healthcare","technology","government","professional-services",[25,26],"security-operations","it-and-engineering",[28,29,30,31],"agentic-workflow","classification-and-routing","summarization","rag-knowledge-assistant",[33,34,35],"internal-tools","microsoft-teams","api","employee-facing","supervised-agent","early-adopters","A security operations centre lives on alerts: from the SIEM, the endpoint and email protection\ntools, identity systems and cloud platforms, plus the suspicious emails that staff report with a\nbutton in their mail client. Many of these alerts are false positives (St. Luke's University Health\nNetwork describes finding the true threats \"amidst a sea of false positives\"), but each one has to\nbe opened, enriched and judged, because the one real intrusion hides among them.\n\nThe judgment is not the slow part; the legwork is. An analyst checks the sender and the links,\nlooks up the IP address and the file hash, pulls the sign in history of the user, compares the\nevent with earlier incidents and writes up what they found. Before AI, that legwork took up to 20\nminutes per event at SEP2 and up to 30 minutes per alert at Human Managed, and 10 to 77 minutes per\nidentity investigation at Avanade. Most alerts take far less, but at St. Luke's triaging hundreds of\nalerts a day still took hours every day. At that volume the queue wins:\nalerts wait, analysts burn out and real threats are found late.\n\nSecurity teams also struggle with consistency. No two analysts document an investigation the same\nway, which makes handovers between shifts, escalations to forensics and reports to leadership\nslower than they need to be.",[],"1. **Pick up the alert.** The agent is triggered by a new alert in the SIEM or extended detection\n   and response (XDR) console, or by an email a user reported as suspicious.\n2. **Gather the evidence.** It queries the connected tools the way an analyst would: email\n   headers, URLs and attachments, endpoint and firewall logs, identity sign ins, threat\n   intelligence on indicators, and similar past incidents.\n3. **Reason to a verdict.** It classifies the alert (malicious, suspicious, benign, false\n   positive) with a confidence level and writes down the evidence and the reasoning behind it, so\n   an analyst can check the verdict in a minute instead of rebuilding it.\n4. **Act within limits.** Clear false positives, such as a reported marketing email, are closed\n   with the reasoning attached. Anything malicious or uncertain is escalated with a draft incident\n   summary; containment actions such as isolating a device or disabling an account are proposed,\n   and an analyst approves them.\n5. **Learn from feedback.** Analysts correct wrong verdicts in plain language, and the agent's\n   instructions, allow list and examples are updated, so the same mistake is not repeated.",[43,44,45,46],"employee-productivity","risk-reduction","speed","compliance",[48,49,50,51,52,53,54],"handling-time-reduction","mttr-reduction","productivity-gain","hours-saved","alert-volume-reduction","false-positive-reduction","accuracy",{"referenceOrg":56,"inputs":57,"formula":86,"currency":87,"period":88,"resultLabel":89,"caveat":90},"An enterprise security operations centre that triages 50,000 to 100,000 alerts and reported emails a year",[58,65,72,79],{"key":59,"label":60,"low":61,"high":62,"unit":63,"note":64},"alertsPerYear","Alerts and reported emails triaged by analysts per year",50000,100000,"alerts per year","Editorial assumption for a large enterprise SOC. Replace with the count from your SIEM or case management system.",{"key":66,"label":67,"low":68,"high":69,"unit":70,"note":71},"minutesPerAlert","Average analyst minutes per alert before AI",3,10,"minutes per alert","An average across the alert mix, well below the upper bounds on this page (up to 20 minutes at SEP2 and up to 30 minutes at Human Managed for a single alert), because most alerts are closed quickly. St. Luke's says triaging hundreds of alerts a day took hours, and its nearly 200 hours saved a month across thousands of closed false positives implies a few minutes per reported email. Even the high case (about 10,000 hours a year) is roughly four times St. Luke's 2,400 hours a year from phishing alone, for a SOC that covers every alert type.",{"key":73,"label":74,"low":75,"high":76,"unit":77,"note":78},"timeSavedShare","Share of triage time the agent saves",0.3,0.6,"fraction of triage time","Conservative against the evidence on this page, because a first deployment covers only part of the alert types. Google Cloud reports that manual triage at Human Managed was reduced by more than 60%. TÜV SÜD reports analysis about 60% to 70% faster; if faster means more analyses per hour, that is roughly 40% less time per analysis, and if it means 60% to 70% less time, it sits above this range.",{"key":80,"label":81,"low":82,"high":83,"unit":84,"note":85},"costPerHour","Fully loaded cost of a SOC analyst hour",60,100,"USD per hour","Editorial assumption, replace with your own fully loaded cost or your managed security provider's rate.","alertsPerYear * minutesPerAlert / 60 * timeSavedShare * costPerHour","USD","per year","Analyst triage time released, valued at cost","Counts analyst time released on triage only. It leaves out the cost of the AI and the security tools it calls, the integration work, the value of finding real incidents sooner and the cost of a wrong verdict, which the guardrails on this page are meant to keep rare.",[],{"complexity":93,"complexityNote":94,"dataPrerequisites":95,"integrations":101},"medium","The model work is modest; the integrations and the trust are the work. The agent needs read access to many security tools, a clear policy on what it may close on its own, and weeks of side by side running before analysts stop double checking every verdict.",[96,97,98,99,100],"Alerts and reported emails available through the SIEM, XDR or email security API","Read access to logs from endpoints, identity, email, firewalls and cloud platforms","Threat intelligence feeds for indicators such as IP addresses, domains and file hashes","Past incidents with their outcomes, to calibrate verdicts and write examples","Written triage runbooks per alert type",[102,103,104,105,106,107],"SIEM and XDR platform (alerts, queries, incident updates)","Email security gateway and the user reporting mailbox","Identity provider for sign in history and account actions","Endpoint detection and response for device context and isolation","Security orchestration (SOAR) or case management for tickets and playbooks","Collaboration tool such as Microsoft Teams for analyst notifications",{"steps":109,"guardrails":128,"humanInTheLoop":134,"kpisToInstrument":135,"failureModes":141},[110,113,116,119,122,125],{"title":111,"detail":112},"Start with the noisiest, best understood alert type","User reported phishing is the usual first choice: high volume, mostly benign, and the evidence (headers, links, attachments, sender history) is well defined. Measure the current volume, handling time and false positive share before you begin.",{"title":114,"detail":115},"Write the triage runbook down","Turn the senior analysts' practice into explicit steps and decision rules per alert type, including which evidence decides the verdict. The agent follows this, and it is what you audit against later.",{"title":117,"detail":118},"Connect read only first","Give the agent read access to the tools it needs and nothing else. Let it produce verdicts and summaries next to the analysts for several weeks without closing anything.",{"title":120,"detail":121},"Compare verdicts and calibrate","Compare the agent's verdicts with the analysts' on the same alerts, per alert type. Only where agreement is consistently high, and the misses are understood, allow the agent to close false positives on its own.",{"title":123,"detail":124},"Keep humans on containment","Isolating devices, disabling accounts, blocking senders and deleting emails stay proposed actions that an analyst approves, with the agent's evidence attached, until the organization has a documented reason to automate a specific action.",{"title":126,"detail":127},"Extend alert by alert","Add alert types one at a time (identity, endpoint, data loss prevention), each with its own runbook, test set and agreement threshold, and keep sampling closed alerts every week. Alert types that watch individual employees, such as data loss prevention and insider risk, need a fresh legal and works council review first.",[129,130,131,132,133],"The agent closes only the alert types and verdicts it has been cleared for; everything else goes to an analyst","Containment and account actions require analyst approval, logged with the evidence behind them","Content from emails, attachments and web pages is treated as untrusted input, so instructions hidden in a phishing email cannot steer the agent","Read only, least privilege service accounts for every connected tool","Every verdict carries its evidence and reasoning, stored with the incident record","Analysts own every containment decision and every escalation. They review a random sample of alerts the agent closed each week, correct wrong verdicts, and approve each new alert type or automated action before it goes live. The agent prepares; the analyst decides.",[136,137,138,139,140],"Mean time to triage per alert type, before and after","Share of alerts closed by the agent, and the share of those later reopened","Agreement rate between agent and analyst verdicts on a weekly sample","Missed true positives found in sampling or later investigations","Analyst hours spent on triage versus threat hunting and response",[142,145,148,151],{"title":143,"detail":144},"A confident false negative","The agent closes a real phishing email or intrusion as benign. Limit autonomous closure to well calibrated alert types, sample closed alerts every week and treat every miss as an incident with a root cause.",{"title":146,"detail":147},"Prompt injection through the evidence","Attackers write text into emails or files that tells the model to mark them safe. Separate instructions from evidence, and test the agent with adversarial samples before and after every change.",{"title":149,"detail":150},"Automation without the runbook","The agent is switched on without written triage rules, so nobody can say whether a verdict was right. Write the runbook first; it is also what auditors and new analysts need.",{"title":152,"detail":153},"Analysts stop looking","Once the agent is usually right, reviews become rubber stamps. Keep a structured sample review and rotate who does it.",{"euAiAct":155,"regulations":158,"guidance":167,"controls":180,"incidents":186},{"tier":156,"basis":157},"context-dependent","Triage of phishing, endpoint, network and cloud alerts for an organization's own cyber defence is not listed in Annex III. Recital 55 of the AI Act says that components intended to be used solely for cybersecurity purposes should not qualify as safety components, so the agent does not fall under Annex III point 2 (critical infrastructure), and for this scope the tier is minimal. The design changes that when the agent triages identity, data loss prevention, insider risk or user behaviour alerts in a way that scores or monitors individual employees: monitoring and evaluating the behaviour of persons in a work relationship falls under Annex III point 4(b), so that scope needs its own high risk assessment before it goes live. The Article 50(1) duty to disclose AI interaction does not apply because it is obvious to a reasonably well informed analyst that they are working with an AI agent. An operator that lets AI act autonomously on network or operational technology controls should assess that design separately, and reading employees' emails and sign in data remains subject to data protection law.",[159,160,161,162,163,164,165,166],"eu-ai-act","gdpr","nis2","dora","nist-ai-rmf","iso-42001","hipaa","pci-dss",[168,174],{"title":169,"issuer":170,"region":171,"url":172,"note":173},"NIST SP 800-61 Rev. 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile","NIST","north-america","https://csrc.nist.gov/pubs/sp/800/61/r3/final","The US reference for incident detection, analysis and response, mapped to the NIST Cybersecurity Framework 2.0; a useful baseline for the runbooks an agent follows.",{"title":175,"issuer":176,"region":177,"url":178,"note":179},"OWASP Top 10 for LLM Applications","OWASP","global","https://genai.owasp.org/llm-top-10/","Lists prompt injection and excessive agency among the main risks of LLM applications, both directly relevant when an agent reads attacker controlled emails and can act in security tools.",[181,182,183,184,185],"Inventory entry for the agent with an accountable owner, the alert types in scope and the actions it may take","Written triage runbook per alert type, versioned with the agent's instructions","Audit trail of every verdict, the evidence used and every action proposed or taken","Weekly sample review of closed alerts with tracked agreement and misses","Adversarial test set (prompt injection, look alike domains, novel lures) run on every change",[],{"howToBuild":188},"On Blits.ai this is an **agentic workflow** triggered through an API token or on a schedule. Its\n**agent loop** calls the **custom functions** attached to the workflow, REST calls that query the\norganization's SIEM, email security, identity and endpoint tools. **MCP** servers expose further\ntools the agent can call, and retrieval over a **knowledge base** with hybrid retrieval surfaces\nrunbooks and past incident write ups, so the verdict cites the rule it followed. A further\nfunction can write the verdict and a draft incident summary back to the SIEM or case management\ntool.\n\nA **tool execution policy** controls which of these the agent may use, and that scoping is the\nmain defence against prompt injection in the evidence. **Guardrails** check conversations, not\nwhat a workflow reads, so an instruction hidden in an email is limited by what the agent is able\nto call rather than detected. Link only read only functions for evidence, and keep containment\n(isolating a device, disabling an account) out of the workflow: the agent proposes it and an\nanalyst carries it out. Every run keeps a **full audit trail** with downloadable run data.\n**Test suites** can replay labelled alerts, including adversarial samples, against the workflow\nwith deterministic or LLM based grading, and the platform is model agnostic, with EU and UAE data\nresidency for regions that require it.",[190,193,196,199],{"question":191,"answer":192},"How much analyst time does AI alert triage save?","It depends on the alert mix and on how much the agent may close on its own. St. Luke's University Health Network says its triage agent saves nearly 200 hours a month on reported phishing, Google Cloud reports that manual triage at Human Managed was reduced by more than 60%, and TÜV SÜD reports analysis about 60% to 70% faster. These are vendor case studies, so measure your own baseline before you plan on similar numbers.",{"question":194,"answer":195},"Should the AI close alerts by itself?","Only for alert types where its verdicts have matched your analysts' for weeks, and usually only for false positives such as benign reported emails. St. Luke's describes the agent closing thousands of false positive alerts, with analysts focusing on the real threats it surfaces. Containment actions such as isolating a device should stay with an analyst.",{"question":197,"answer":198},"Can attackers trick a triage agent?","Yes, that is the specific risk here: the agent reads text the attacker wrote. Treat email and file content as untrusted data, keep the agent's permissions read only, and test it with prompt injection and novel phishing samples on every change.",{"question":200,"answer":201},"Is phishing triage a separate use case from SOC alert triage?","No, it is a common first step in the same job: user reported phishing is high in volume and its evidence is well defined. Microsoft has renamed its Phishing Triage Agent the Security Alert Triage Agent, and the US Federal Housing Finance Agency has automated responses to user reported suspicious emails since 2021.",[203,204],"aiops-incident-triage","it-service-desk-resolution-agent","2026-09-27",[207],{"date":205,"note":208},"First published","security-alert-triage-and-investigation",[211,236,256,291,316,346,369],{"title":212,"useCases":213,"organization":214,"vendors":218,"summary":219,"stage":220,"year":221,"channels":222,"languages":223,"metrics":225,"outcomeDisclosed":216,"sources":226,"verification":231,"grade":233,"id":234,"organizationSlug":235},"US Immigration and Customs Enforcement: AI assisted review of emails for signs of compromise in the SOC",[209],{"name":215,"anonymized":216,"country":217,"region":171,"industry":22},"U.S. Immigration and Customs Enforcement",false,"US",[],"ICE reports in the 2025 federal AI use case inventory that its security operations centre uses an AI Assisted Compromise Email Detector (AACED) to review a collection of emails exchanged with Microsoft under Emergency Directive 24-02. Named entity recognition flags personal data and keywords, and a chat interface lets analysts ask questions with an email as context, so they can find indicators of compromise faster. This was a review of a fixed set of emails tied to one directive rather than ongoing alert triage, and the inventory classifies it as classical machine learning rather than an agent, so it is a partial fit for this use case. The inventory lists it as deployed since June 2024 and gives no measured result.","production",2024,[33],[224],"en",[],[227],{"url":228,"title":229,"publisher":230},"https://raw.githubusercontent.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory/main/Data/2025_individually_reported_AI_use_cases.csv","2025 federal agency AI use case inventory, individually reported use cases (raw data)","Office of Management and Budget (GitHub)",{"level":232,"checkedAt":205},"source-verified","B","us-ice-soc-compromised-email-detector","u-s-immigration-and-customs-enforcement",{"title":237,"useCases":238,"organization":239,"vendors":241,"summary":245,"stage":220,"year":246,"channels":247,"languages":249,"metrics":250,"outcomeDisclosed":216,"sources":251,"verification":253,"grade":233,"id":254,"organizationSlug":255},"US Federal Housing Finance Agency: automated triage of user reported phishing emails",[209],{"name":240,"anonymized":216,"country":217,"region":171,"industry":22},"Federal Housing Finance Agency",[242],{"name":243,"role":244},"KnowBe4","platform","FHFA reports in the 2025 federal AI use case inventory that it uses KnowBe4 PhishER to manage the suspicious emails its staff report. Machine learning classifies each email as spam, phishing or malicious and sends the response automatically, so a cybersecurity specialist does not have to analyse hundreds of reported emails by hand. It is a machine learning classifier rather than a generative AI agent, so it covers the classification step of this use case only. The inventory lists the use case as deployed since April 2021 with risk reduction as its benefit, and says the tool reduces the time to respond to staff, but gives no figures.",2021,[248,33],"email",[224],[],[252],{"url":228,"title":229,"publisher":230},{"level":232,"checkedAt":205},"fhfa-phishing-email-identification",null,{"title":257,"useCases":258,"organization":259,"vendors":261,"summary":264,"stage":220,"year":265,"channels":266,"languages":267,"metrics":268,"outcomeDisclosed":283,"sources":284,"verification":288,"grade":289,"id":290,"organizationSlug":255},"Avanade: Security Copilot agents for identity and security investigations",[209],{"name":260,"anonymized":216,"country":217,"region":177,"industry":23},"Avanade",[262],{"name":263,"role":244},"Microsoft","Avanade embedded Microsoft Security Copilot in its identity and security investigations, run with Microsoft Entra. After a five week pilot in which engineers turned recurring investigation patterns into prompt based workflows, it applied the same approach to security operations and built custom agents that consolidate signals, recommendations and playbook steps for analysts. Most of the reported gains are in identity incident handling, closer to identity and access support than to SOC alert triage: guest account investigations dropped from 10 minutes to 1 minute. A separate study of more than 4,100 security operations investigations reports gains in speed, quality and error rates.",2026,[33],[224],[269,277],{"kpi":49,"value":270,"unit":271,"qualifier":272,"period":273,"claimant":274,"quote":275,"sourceUrl":276},80,"percent","up-to","identity incident resolution time","organization","By turning expert knowledge into repeatable, AI-assisted workflows, we reduced resolution times by up to 80% and enabled the team to take on more work with greater consistency and confidence.","https://www.microsoft.com/en/customers/story/27277-avanade-microsoft-security-copilot",{"kpi":50,"value":278,"unit":271,"qualifier":279,"period":280,"claimant":281,"quote":282,"sourceUrl":276},70,"exact","speed and efficiency across more than 4,100 security operations investigations","vendor","In a separate study of more than 4,100 security operations investigations, Avanade found a 70% improvement in speed and efficiency, a 7% improvement in investigation and documentation quality, and a 7% reduction in human error.",true,[285],{"url":276,"title":286,"publisher":287},"Avanade cuts incident resolution time by up to 80% with Microsoft Security Copilot","Microsoft Customer Stories",{"level":232,"checkedAt":205},"C","avanade-security-copilot-identity-investigations",{"title":292,"useCases":293,"organization":294,"vendors":298,"summary":301,"stage":220,"year":265,"channels":302,"languages":303,"metrics":304,"outcomeDisclosed":283,"sources":311,"verification":314,"grade":289,"id":315,"organizationSlug":255},"SEP2: custom Gemini agents for security alert triage in a managed SOC",[209],{"name":295,"anonymized":216,"country":296,"region":297,"industry":21},"SEP2","GB","europe",[299],{"name":300,"role":244},"Google Cloud","SEP2, a UK managed security provider, built triage and threat intelligence agents on Google's Gemini Enterprise Agent Platform alongside Google Security Operations. When an alert fires, the agents gather data from firewalls, endpoints and threat feeds in about a minute, a task that took analysts up to 20 minutes, and hand a standardised summary to the human team, who review it and authorise remediation. Engineers also use Gemini to write detection rules from plain language.",[33],[224],[305],{"kpi":50,"value":306,"unit":307,"qualifier":279,"period":308,"claimant":281,"quote":309,"sourceUrl":310},20,"multiplier","gathering the data for a new security alert before human review, from up to 20 minutes to one minute","20x faster to triage new security alerts","https://cloud.google.com/customers/sep2",[312],{"url":310,"title":313,"publisher":300},"SEP2 triages cybersecurity threats 20x faster with Gemini Enterprise Agent Platform",{"level":232,"checkedAt":205},"sep2-gemini-security-triage-agents",{"title":317,"useCases":318,"organization":319,"vendors":323,"summary":328,"stage":220,"year":329,"channels":330,"languages":331,"metrics":332,"outcomeDisclosed":283,"sources":341,"verification":344,"grade":289,"id":345,"organizationSlug":255},"Human Managed: Gemini and Google Security Operations for security alert triage",[209],{"name":320,"anonymized":216,"country":321,"region":322,"industry":21},"Human Managed","SG","asia-pacific",[324,325],{"name":300,"role":244},{"name":326,"role":327},"CloudMile","integrator","Human Managed, a Singapore based security intelligence provider for large enterprises, uses Google Security Operations, Vertex AI and Gemini to analyse its customers' alerts and logs. Before, its specialists needed up to 30 minutes per alert to analyse the data and send a contextual alert to the customer; now statistical models and generative AI produce a confidence score with an explanation, and customers get prioritised alerts with remediation advice within 15 minutes.",2025,[33,35],[224],[333,338],{"kpi":48,"value":334,"unit":271,"qualifier":279,"period":335,"claimant":281,"quote":336,"sourceUrl":337},97,"time to triage an alert, from up to 30 minutes to under one minute","With the system monitoring data and continuously learning about new threats, manual triage has been reduced by more than 60% and the time to triage alerts has been slashed to less than one minute – a 97% reduction that helps Human Managed's customers respond to security incidents much faster.","https://cloud.google.com/customers/human-managed",{"kpi":50,"value":82,"unit":271,"qualifier":339,"period":340,"claimant":281,"quote":336,"sourceUrl":337},"at-least","reduction in manual triage work",[342],{"url":337,"title":343,"publisher":300},"Human Managed uses Vertex AI and Google SecOps to triage security alerts 97% faster",{"level":232,"checkedAt":205},"human-managed-google-secops-alert-triage",{"title":347,"useCases":348,"organization":349,"vendors":351,"summary":353,"stage":220,"year":329,"channels":354,"languages":355,"metrics":356,"outcomeDisclosed":283,"sources":364,"verification":367,"grade":289,"id":368,"organizationSlug":255},"St. Luke's University Health Network: Security Copilot agents for phishing alert triage",[209],{"name":350,"anonymized":216,"country":217,"region":171,"industry":20},"St. Luke's University Health Network",[352],{"name":263,"role":244},"St. Luke's University Health Network, a US hospital network with more than 23,000 employees, runs Microsoft Security Copilot across Defender and Sentinel. Its Security Alert Triage Agent (formerly the Phishing Triage Agent) reads user reported emails, decides whether each is a genuine phishing attempt or a false alarm, explains its verdict in plain text and closes false positives on its own, so analysts can move to threat hunting. Copilot also drafts incident reports that analysts edit and escalate.",[33],[224],[357],{"kpi":51,"value":358,"unit":359,"qualifier":360,"period":361,"claimant":274,"quote":362,"sourceUrl":363},200,"hours","approximately","per month, phishing alert triage","It’s saving us nearly 200 hours monthly by autonomously handling and closing thousands of false positive alerts.","https://www.microsoft.com/en/customers/story/25330-st-lukes-university-health-network-microsoft-security-copilot",[365],{"url":363,"title":366,"publisher":287},"St. Luke’s saves nearly 200 hours monthly with AI-powered Security Copilot agents",{"level":232,"checkedAt":205},"st-lukes-security-alert-triage-agent",{"title":370,"useCases":371,"organization":372,"vendors":375,"summary":377,"stage":220,"year":221,"channels":378,"languages":379,"metrics":380,"outcomeDisclosed":283,"sources":385,"verification":388,"grade":289,"id":389,"organizationSlug":255},"TÜV SÜD: Security Copilot for threat analysis in the SOC",[209],{"name":373,"anonymized":216,"country":374,"region":297,"industry":23},"TÜV SÜD","DE",[376],{"name":263,"role":244},"TÜV SÜD, the German testing and certification group, protects about 28,000 employees with Microsoft Defender solutions, runs Microsoft Sentinel as its SIEM and joined the early adopter programme for Security Copilot. Its analysts use Copilot inside Defender to enrich alerts, investigate threats, start remediation and produce consistent investigation reports, and the company says new analysts become effective within months.",[33],[],[381],{"kpi":50,"value":82,"unit":271,"qualifier":360,"period":382,"claimant":274,"quote":383,"sourceUrl":384},"speed of threat analysis, reported as 60% to 70% faster","We analyze results about 60% to 70% faster with Security Copilot.","https://www.microsoft.com/en/customers/story/25045-tuv-sud-microsoft-security-copilot",[386],{"url":384,"title":387,"publisher":287},"TÜV SÜD anticipates the future confidently with Microsoft Defender, Security Copilot",{"level":232,"checkedAt":205},"tuv-sud-security-copilot-threat-analysis",0,[392,401,406,411,415],{"kpi":50,"label":393,"unit":271,"aggregate":283,"higherIsBetter":283,"n":68,"nUpTo":390,"median":82,"min":82,"max":278,"byClaimant":394,"vendorOnly":216,"points":397},"Productivity gain",{"organization":395,"vendor":396,"regulator":390,"independent":390},1,2,[398,399,400],{"evidenceId":290,"organization":260,"value":278,"qualifier":279,"claimant":281,"grade":289,"pooled":283},{"evidenceId":345,"organization":320,"value":82,"qualifier":339,"claimant":281,"grade":289,"pooled":283},{"evidenceId":389,"organization":373,"value":82,"qualifier":360,"claimant":274,"grade":289,"pooled":283},{"kpi":48,"label":402,"unit":271,"aggregate":283,"higherIsBetter":283,"n":395,"nUpTo":390,"median":334,"min":334,"max":334,"byClaimant":403,"vendorOnly":283,"points":404},"Handling time reduction",{"organization":390,"vendor":395,"regulator":390,"independent":390},[405],{"evidenceId":345,"organization":320,"value":334,"qualifier":279,"claimant":281,"grade":289,"pooled":283},{"kpi":51,"label":407,"unit":359,"aggregate":216,"higherIsBetter":283,"n":395,"nUpTo":390,"median":358,"min":358,"max":358,"byClaimant":408,"vendorOnly":216,"points":409},"Hours saved",{"organization":395,"vendor":390,"regulator":390,"independent":390},[410],{"evidenceId":368,"organization":350,"value":358,"qualifier":360,"claimant":274,"grade":289,"pooled":283},{"kpi":50,"label":393,"unit":307,"aggregate":283,"higherIsBetter":283,"n":395,"nUpTo":390,"median":306,"min":306,"max":306,"byClaimant":412,"vendorOnly":283,"points":413},{"organization":390,"vendor":395,"regulator":390,"independent":390},[414],{"evidenceId":315,"organization":295,"value":306,"qualifier":279,"claimant":281,"grade":289,"pooled":283},{"kpi":49,"label":416,"unit":271,"aggregate":283,"higherIsBetter":283,"n":390,"nUpTo":395,"median":255,"min":255,"max":255,"byClaimant":417,"vendorOnly":216,"points":418},"Time to repair reduction",{"organization":390,"vendor":390,"regulator":390,"independent":390},[419],{"evidenceId":290,"organization":260,"value":270,"qualifier":272,"claimant":274,"grade":289,"pooled":216},{"low":421,"high":422},45000,1000000,[424,449,472,485],{"slug":203,"title":425,"shortTitle":426,"definition":427,"status":9,"industries":428,"functions":432,"patterns":435,"audience":36,"autonomy":437,"adoptionStage":38,"evidenceCount":438,"publicEvidenceCount":439,"organizations":440,"bestGrade":233,"headline":445,"lastVerified":205,"indexable":283},"AI for IT incident triage and root cause analysis (AIOps)","AIOps incident triage","AI that turns a flood of monitoring alerts into one probable incident, routes it to the right team, proposes likely root causes and remediation from runbooks and past incidents, and drafts the stakeholder updates and the post incident review, while an engineer authorizes every change.",[19,429,21,430,431],"banking","telecommunications","payments",[26,433,434],"operations","risk-management",[436,29,30,31,28],"anomaly-detection","copilot",6,5,[441,442,263,443,444],"Google","Meta","Mizuho Financial Group","TD Bank",{"kpi":54,"label":446,"unit":271,"n":68,"nUpTo":390,"kind":447,"value":448,"qualifier":279,"claimant":255,"organization":255,"vendorReported":216},"Accuracy","median",90,{"slug":204,"title":450,"shortTitle":451,"definition":452,"status":9,"industries":453,"functions":455,"patterns":456,"audience":36,"autonomy":37,"adoptionStage":458,"evidenceCount":459,"publicEvidenceCount":438,"organizations":460,"bestGrade":233,"headline":467,"lastVerified":205,"indexable":283},"AI agent for IT service desk resolution","IT service desk resolution","An AI agent in Microsoft Teams, Slack or the intranet that takes the high volume IT support queue, such as password and MFA resets, account unlocks, VPN, device and software requests, and resolves common requests by acting in the identity and IT service management systems, handing the rest to the right resolver group with the context attached.",[19,429,21,454,20],"retail-and-ecommerce",[26,433],[457,28,31,29],"conversational-agent","mainstream",8,[461,462,463,464,465,466],"7-Eleven Vietnam","Bank of America","Equinix","IBM","Mercari US","Vituity",{"kpi":468,"label":469,"unit":271,"n":396,"nUpTo":390,"kind":470,"value":471,"qualifier":279,"claimant":281,"organization":465,"vendorReported":283},"employee-adoption","Employee adoption","reported",94,{"slug":473,"title":474,"shortTitle":475,"definition":476,"status":9,"industries":477,"functions":478,"patterns":479,"audience":36,"autonomy":437,"adoptionStage":38,"evidenceCount":481,"publicEvidenceCount":481,"organizations":482,"bestGrade":233,"headline":255,"lastVerified":205,"indexable":283},"software-vulnerability-remediation","AI for software vulnerability triage and remediation","Vulnerability remediation","AI that takes security findings from scanners, fuzzers and bug reports, filters out duplicates and false positives, reproduces and ranks the real ones, and drafts a code fix with a test for each, which a developer reviews and merges through the normal change process.",[19,21,20],[25,26],[480,28,29],"code-generation",4,[441,483,484],"Labelbox","PatientPoint",{"slug":486,"title":487,"shortTitle":488,"definition":489,"status":9,"industries":490,"functions":493,"patterns":495,"audience":36,"autonomy":437,"adoptionStage":38,"evidenceCount":481,"publicEvidenceCount":481,"organizations":497,"bestGrade":233,"headline":255,"lastVerified":205,"indexable":283},"ai-model-inventory","AI system and model inventory with shadow AI discovery","AI model inventory","A governed register of every AI system and model an organization builds, buys or uses, with its owner, purpose, data, risk tier and approval status, kept current by AI that discovers unregistered use, reads the documentation and assembles the evidence a board, auditor or supervisor asks for.",[19,429,491,22,492],"insurance","manufacturing",[434,494,26],"regulatory-compliance",[28,496,31,29],"document-processing",[498,499,500,501],"Board of Governors of the Federal Reserve System","Office of Management and Budget","Unilever","U.S. Department of Justice",{"indexable":283,"reasons":503},[],[505,511,516,522,527,532,539,546,553,560,565,571,578,585,591,595,602,608,613,619,625,631,636,641,646,653,659,664,669,676,682,688,694,699],{"id":159,"label":506,"issuer":507,"region":297,"url":508,"description":509,"useCases":510,"indexable":283},"EU AI Act","European Union","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":160,"label":512,"issuer":507,"region":297,"url":513,"description":514,"useCases":515,"indexable":283},"GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":164,"label":517,"issuer":518,"region":177,"url":519,"description":520,"useCases":521,"indexable":283},"ISO/IEC 42001","ISO and IEC","https://www.iso.org/standard/81230.html","The international management system standard for AI.",110,{"id":163,"label":523,"issuer":170,"region":171,"url":524,"description":525,"useCases":526,"indexable":283},"NIST AI Risk Management Framework","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",83,{"id":162,"label":528,"issuer":507,"region":297,"url":529,"description":530,"useCases":531,"indexable":283},"DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":533,"label":534,"issuer":535,"region":297,"url":536,"description":537,"useCases":538,"indexable":283},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":540,"label":541,"issuer":542,"region":297,"url":543,"description":544,"useCases":545,"indexable":283},"uk-consumer-duty","FCA Consumer Duty","Financial Conduct Authority","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":547,"label":548,"issuer":549,"region":322,"url":550,"description":551,"useCases":552,"indexable":283},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":554,"label":555,"issuer":556,"region":322,"url":557,"description":558,"useCases":559,"indexable":283},"apra-cps-230","APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",25,{"id":166,"label":561,"issuer":562,"region":177,"url":563,"description":564,"useCases":306,"indexable":283},"PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",{"id":566,"label":567,"issuer":568,"region":171,"url":569,"description":570,"useCases":306,"indexable":283},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":572,"label":573,"issuer":574,"region":297,"url":575,"description":576,"useCases":577,"indexable":283},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",16,{"id":579,"label":580,"issuer":581,"region":177,"url":582,"description":583,"useCases":584,"indexable":283},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":586,"label":587,"issuer":507,"region":297,"url":588,"description":589,"useCases":590,"indexable":283},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":161,"label":592,"issuer":507,"region":297,"url":593,"description":594,"useCases":590,"indexable":283},"NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":596,"label":597,"issuer":598,"region":171,"url":599,"description":600,"useCases":601,"indexable":283},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":603,"label":604,"issuer":507,"region":297,"url":605,"description":606,"useCases":607,"indexable":283},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":165,"label":609,"issuer":610,"region":171,"url":611,"description":612,"useCases":607,"indexable":283},"HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":614,"label":615,"issuer":616,"region":177,"url":617,"description":618,"useCases":607,"indexable":283},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":620,"label":621,"issuer":507,"region":297,"url":622,"description":623,"useCases":624,"indexable":283},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":626,"label":627,"issuer":628,"region":171,"url":629,"description":630,"useCases":624,"indexable":283},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":632,"label":633,"issuer":549,"region":322,"url":634,"description":635,"useCases":69,"indexable":283},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",{"id":637,"label":638,"issuer":507,"region":297,"url":639,"description":640,"useCases":69,"indexable":283},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":642,"label":643,"issuer":507,"region":297,"url":644,"description":645,"useCases":69,"indexable":283},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":647,"label":648,"issuer":649,"region":297,"url":650,"description":651,"useCases":652,"indexable":283},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",9,{"id":654,"label":655,"issuer":656,"region":171,"url":657,"description":658,"useCases":459,"indexable":283},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",{"id":660,"label":661,"issuer":507,"region":297,"url":662,"description":663,"useCases":459,"indexable":283},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":665,"label":666,"issuer":507,"region":297,"url":667,"description":668,"useCases":438,"indexable":283},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",{"id":670,"label":671,"issuer":672,"region":673,"url":674,"description":675,"useCases":439,"indexable":283},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",{"id":677,"label":678,"issuer":679,"region":297,"url":680,"description":681,"useCases":481,"indexable":283},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",{"id":683,"label":684,"issuer":685,"region":297,"url":686,"description":687,"useCases":481,"indexable":283},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":689,"label":690,"issuer":691,"region":322,"url":692,"description":693,"useCases":68,"indexable":283},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":695,"label":696,"issuer":507,"region":297,"url":697,"description":698,"useCases":68,"indexable":283},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":700,"label":701,"issuer":702,"region":171,"url":703,"description":704,"useCases":68,"indexable":283},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598301552]