Zscaler Agentic SOC: the agent now pulls the trigger
Zscaler's Agentic SOC uses Anthropic and OpenAI models to triage, investigate, and contain threats automatically. The line that moved is autonomous remediation.
Zscaler launched Agentic SOC globally on September 9, and the notable part is not that AI agents do triage. Half the security market shipped that in 2026. The notable part is closed-loop inline remediation: the agents isolate users, kill command-and-control traffic, and cut off lateral movement without waiting for a human to click approve.
What actually happened
Per Zscaler's announcement, Agentic SOC is available globally now. It combines a context graph, specialized AI agents, threat-intelligence-informed detections, continuous threat hunting, and closed-loop remediation.
The agents handle triage, root-cause investigation, verdict assignment, and response workflow triggering. Zscaler says it partnered with Anthropic and OpenAI, running frontier models alongside its own threat intelligence rather than betting on one lab. The grounding claim is 750 billion daily zero trust transactions plus more than a decade of managed detection experience.
Deepen Desai, Zscaler's EVP of Cybersecurity, framed the reason plainly: AI-driven attacks move faster than traditional SOC models were designed to handle. A customer quote from Maire Tecnimont says the quiet part — top analysts stuck doing triage instead of hunting.
Note what is a claim and what is a fact. The 750 billion transactions and the lab partnerships are stated by Zscaler. Detection and containment accuracy in your environment is not in the press release, and nobody should assume it.
Why autonomous containment matters for your business
You probably do not run a SOC. You will still meet this pattern, because the same design is arriving in every tool you own — the agent that used to recommend an action now takes it.
The question to ask any vendor shipping this is not "how good is the model." It is what does a false positive cost me. An agent that isolates a compromised laptop is a good trade. An agent that isolates your warehouse manager's laptop at 4pm on a shipping day is an outage you did not schedule, and the vendor's SLA does not cover your carrier cutoff.
So before you turn on autonomous action anywhere: know which actions are reversible and which are not, and gate the irreversible ones behind a person. Know how you turn it off in thirty seconds at 2am. Confirm the action log names what the agent did, to which asset, on what evidence — because when it gets one wrong, that log is your only path back.
Autonomous containment is the right direction. Attack speed genuinely broke the human-in-the-loop model. Just buy it with the blast radius mapped, not the demo memorized.
Key takeaways
- Zscaler Agentic SOC shipped globally September 9, 2026 with closed-loop inline remediation, not just AI triage
- Agents isolate users, block C2 traffic, and limit lateral movement autonomously
- Zscaler partnered with both Anthropic and OpenAI rather than standardizing on one frontier lab
- Stated grounding: 750 billion daily zero trust transactions and 10+ years of managed detection experience
- Accuracy in your environment is not in the release — treat vendor detection claims as unverified until you pilot
- Before enabling any autonomous action: map irreversible actions, gate them on a human, and confirm the kill switch
Autonomous agents are worth it when the blast radius is bounded. We build automation with explicit approval gates on irreversible actions, an audit trail you can read, and an off switch that works — so the agent handles the volume and you keep the veto. See how we build governed automation, or tell us which workflow you want to automate first.
Sources: Zscaler via GlobeNewswire, CIO Influence.
- #ai-agents
- #security
- #soc
- #zscaler
- #automation
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Suno v6 retrained on licensed music. Check your lineage
Suno rebuilt v6 from scratch on licensed Warner, BMG and Believe catalogs and retired its old models the same day. Training-data provenance is now a product feature.
Read itOpenAI tests outcome-based pricing after an 80% price cut
OpenAI's CFO says an 80% cut to Luna drove 10x usage, and the company is testing outcome-based pricing. Re-run your AI cost math before the meter changes.
Read it