AI Tools Are Flooding SOCs With Alerts, But Most Are False Alarms
Security researchers analysing enterprise security operations centres (SOCs) have found a fast-growing category of alerts triggered simply by staff using AI tools at work, not by attacks on AI systems. While AI-related alerts still make up a small fraction of all SOC alerts (0.43%), that share grew 685% between February and June 2026, making it the fastest-growing alert type tracked.
The research breaks these alerts into three groups: noise (94.1%), genuine risk (5.8%), and real attacks (just 0.02%). In other words, almost all AI-related alerts look alarming but turn out to be harmless, while a small number of real exposures can get buried underneath them. Two distinct employee behaviours are driving this: developers using AI coding agents that perform actions (like spawning shells or accessing credentials) that look identical to early-stage intrusions, and non-technical staff granting AI apps access to company data through OAuth consent or by pasting sensitive documents into generative AI tools.
Both behaviours land in the same SOC alert stream and look similarly concerning at first glance, even though one is loud but usually harmless, and the other is quiet but where actual data loss tends to occur. The core challenge for defenders is learning to tell these apart quickly, so real risks are not missed amid the noise.