Why is AI Still Hard to Trust, Measure, and Govern? A SOC Leader’s Guide to the 2026 SANS AI Survey
I recently had the chance to sit on a panel and talk through some of the findings from this year’s SANS AI Survey, specifically as they apply to the security operations center. It’s the question everyone in the room keeps circling back to: why is AI still hard to trust, measure, and govern? I want to talk through all the ways we are getting closer to this trust aspect and how your SOC is exactly where those gaps get closed first.
TL; DR
- The 2026 SANS AI Survey confirms what SOC leaders have felt for a while: AI adoption is far outpacing AI maturity and trust.
- Nearly half of organizations that adopt AI never reach mature, production-level use, and 63% report real shortcomings in AI’s ability to detect or respond to threats, leaving only 37% who actually trust it.
- Swimlane Senior Solutions Engineer Jason Robbins breaks down why: analysts are non-deterministic too, so the fix isn’t demanding perfect AI, it’s pairing AI’s consistency with deterministic guardrails, starting with false positives and low-severity noise, not high-stakes actions.
- The real unlock is context; feeding your knowledge base, runbooks, and escalation criteria into AI, and building trust through explainability rather than speed.
The SOC is Still the Lifeblood
Security is stretching in a lot of directions right now. Identity, vulnerability management, patching, AI governance and compliance; CISOs have a lot on their plate! But underneath all of that, the SOC is still the fundamental piece. Every log, every initial alert, whether it’s handled in-house or through an MSSP, is still processed through that same team. So when I look at where AI adoption is landing, I look at it through that lens first.
The Gap Between Adoption and Maturity
One of the clearest patterns in the SANS AI 2026 survey is the drop-off between where organizations report adopting AI and where they report reaching mature production use of it, something close to a 50% cut. And I think I know why. Too many companies deploy AI first and then turn to the vendor or the internal team and ask, “Okay, now what’s our use case?” That’s backwards. We should be starting with the outcome we’re trying to reach and working back to how AI helps get us there, not deploying AI because the board said to and figuring out the use case afterward.
The places where I see AI adoption happening easily and immediately are log analysis, explaining threats, and report writing. Summarization is something AI does very well; pulling together a variety of data points into something a human can act on quickly, with some control over how that output gets built. Those are the low-hanging fruit. The harder problem is everything past that.
Deterministic vs. Non-Deterministic: Where the Real Work Is
A lot of the hesitation I hear about AI in the SOC comes down to an expectation problem. People want AI to be 100% right before they’ll trust it, while quietly ignoring the fact that our own analysts are non-deterministic too. Put the same ticket in front of five analysts and you might get five different approaches, all shaped by their own experience and expertise. As I put it during the panel:
“We all have a different version of a grilled cheese sandwich that we like to eat. Different cheeses, different toasting methods, everything else. We’re non-deterministic as well.”
Threat intelligence is a good example of this in practice. Every analyst brings their own read to a VirusTotal score: is 2 out of 72 a red flag or noise? What about 57 out of 72? Different analysts land in different places, and that judgment walks out the door when they go off shift. What AI can do is set consistent guardrails around that triage, giving the investigating agent some baked-in weighting and requirements. It’s not fully deterministic, but it gets a lot closer to consistent, and that consistency is what actually moves the needle toward automated response.
Where Automation Actually Earns Trust
When people hear “automated response,” the first thought is usually some version of “I don’t want AI closing out my CEO’s account or resetting sessions on a VIP.” And that instinct is right; that’s not where automation should start. Where I see teams actually succeeding is with the false positives, the low-severity noise, the alerts that are clearly a mistuning or misconfiguration. If AI can validate high confidence that something is benign, let it close that out and keep it away from an analyst entirely. That frees analysts to spend their time on the investigations that actually matter: the phishing click that landed, the early signs of ransomware, instead of sifting through noise. That’s the tandem: non-deterministic judgment paired with deterministic guardrails, each doing what it’s good at.
Trust Requires Context, Not Just Speed
I can’t count how many times I’ve seen a vendor plug in AI and, two minutes later, claim it’s solving problems. I appreciate the speed, but speed isn’t trust. Trust comes from context. An AI model that flags gift card language as a phishing indicator might be exactly right for a pharmaceutical company and exactly wrong for a large retailer, where gift cards are part of daily business. Without your knowledge base, your runbooks, your escalation criteria feeding into how AI makes decisions, you’re going to get false positives and false negatives that erode confidence fast.
That’s the crawl-walk-run mindset I push for. AI needs to show its work, explainability at every step and tell a human reviewer exactly what to verify rather than making them re-triage everything from scratch.
The SANS data backs this up directly with 63% of respondents reporting significant shortcomings in AI’s ability to detect or respond to threats. That means only 37% say they actually trust AI. That gap tracks closely with how low automated action adoption still is: in the 2026 survey, automated incident response sits at 39% adoption. Practitioners are telling us exactly where they’ve decided to extend trust so far, and it isn’t very far. The pieces that build that trust are the same pieces that let you audit and govern the tool… because you can verify it.
Where This Leaves Us
The 2026 SANS AI Survey confirms what a lot of us have felt anecdotally: adoption is outpacing maturity, trust is still the bottleneck, and governance is recognized as important far more often than it’s actually formalized. None of that means AI isn’t working. It means the SOC is still the proving ground where deterministic automation and non-deterministic AI have to learn to work in tandem, with context and explainability doing the heavy lifting on trust.
This blog was just my take on the report regarding SOC and AI. If you want the full data behind these trends, I’d encourage you to go through the report yourself.
Download SANS 2026 AI Survey
If you want the complete findings from the 2026 SANS AI Survey to bring back to your own team or use to benchmark where your SOC stands, download the full report.

