AI alerts in the SOC: up 685%, and 94% of them are noise
Intezer's telemetry shows AI-related security alerts grew 685% from February to June 2026. They are still under half a percent of volume. Plan for the slope.
Your team adopted AI tools faster than your security tooling learned what they are. Intezer, which runs automated triage across live enterprise alert queues, published numbers this week putting a shape on it: AI-related security alerts rose 685% between February and June 2026. The interesting part is the other number next to it.
What actually happened
Across roughly 16.9 million SOC alerts in Intezer's telemetry, about 73,000 — 0.43% — were AI-related. That is a rounding error on today's volume attached to a slope that steep.
The classification breakdown is the part worth sitting with. Of those AI-related alerts, 94.1% were noise, 5.8% were genuine security risk, and 0.02% were real attacks. Intezer's automated triage returned benign verdicts on 79.8%, suppressed 81.7% outright, and escalated 5.4% to a human. The research was written up by Intezer senior researcher Nicole Fishbein at The Hacker News. These are one vendor's numbers from its own customer fleet, not an industry census — read them as a trend line, not a benchmark.
The alerts are not exotic. They come from ordinary use: developers running coding agents, non-technical staff signing consumer AI tools into corporate accounts, browser extensions, unfamiliar API destinations. Normal work that your detection stack has never seen before and does not have a rule for.
Why this matters for your business
A 94% false-positive rate on a new alert category is the recognizable early shape of a detection gap. Your tooling sees an unknown binary calling an unknown endpoint and fires, because that is genuinely what it should do with no context. The fix is context, not a louder alarm — and nobody is going to supply that context for you.
Here is the part most small companies get backwards. The 0.43% makes this look like a problem for later. It is not, because the noise arrives before the threat does. If you wait until AI alerts are 5% of volume to start classifying them, you will be building the ruleset during the incident. Right now the volume is low enough to sort by hand, which is exactly why now is when it is cheap.
Three moves that cost you an afternoon. Write down which AI tools are sanctioned — the actual list, with the accounts they sign into and the data they can reach. Anything not on that list generating traffic is a finding, and you cannot have findings without a list. Tune before you scale, meaning suppress the known-good agent traffic deliberately instead of letting analysts learn to ignore a whole alert class. Alert fatigue is not a personality trait; it is what happens when a category is 94% noise and nobody prunes it. Watch the OAuth grants, because the highest-risk version of shadow AI is not a chatbot — it is an employee granting a random AI product read access to your Google Workspace or Microsoft 365 tenant in two clicks.
The trend is not going to reverse. Decide now whether your team learns to triage this category or learns to ignore it.
Key takeaways
- Intezer's telemetry shows AI-related security alerts up 685% from February to June 2026
- They were about 73,000 of roughly 16.9 million alerts — 0.43% of volume
- 94.1% were noise, 5.8% genuine risk, 0.02% real attacks; automated triage suppressed 81.7% and escalated 5.4%
- These are a single vendor's customer numbers, so treat the slope as the signal rather than the absolute rate
- The alerts come from ordinary use: coding agents, consumer AI tools on corporate accounts, browser extensions
- Build the sanctioned-tool list and tune suppressions now, while the volume is still small enough to sort by hand
Do you know which AI tools your team signed into your company accounts? Most owners do not, and the OAuth grants are where it gets expensive. We inventory the AI surface in a small business, document what each tool can reach, and set the guardrails before the alert volume forces the issue. Ask for an AI surface review or see what we build.
Sources: The Hacker News / Intezer research.
- #shadow-ai
- #security-operations
- #ai-governance
- #alert-fatigue
- #small-business-it
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Nvidia weighs $10B anchor stake in Anthropic's IPO
Reuters reports Nvidia is in talks to anchor Anthropic's IPO with up to $10 billion at a ~$2 trillion valuation. What a supplier-turned-shareholder means for your AI contracts.
Read it77% claim an AI agent inventory. 44% have the tooling
A Harness survey of 700 enterprises finds AI agent confidence running far ahead of controls: no discovery, no kill switch, no release gate. Here's the fix list.
Read it