Zscaler Launches Agentic SOC to Contain AI-Driven Cyber Threats at Machine Speed
Zscaler has launched Agentic SOC, an AI-first security operations approach designed to detect, investigate and contain AI-driven threats using specialised AI agents, zero trust telemetry and automated response.
Xcademia Team
Xcademia Research Team

Zscaler Moves Security Operations Toward Agentic AI
AI is changing not only how organisations defend their environments, but also how quickly cyber threats can operate. In response, Zscaler has announced Zscaler Agentic SOC, an AI-first approach to security operations designed to detect, investigate and contain threats at machine speed.
The announcement, made on September 9, 2026, positions Agentic SOC as more than an additional AI capability layered onto an existing security stack. Zscaler says the approach combines exposure management, security operations workflows, specialised AI agents, zero trust controls and third-party security data.
The company says the goal is to proactively reduce exposure, extend the capabilities of human security teams and automate containment when threats are detected.
Why Zscaler Says Traditional SOC Workflows Are Under Pressure
According to Zscaler, AI-driven attacks are increasing the speed and adaptability of malicious activity. Its ThreatLabz research team has also observed evasive techniques involving trusted websites, legitimate remote management tools and browser-based attacks.
For conventional security operations centres, the challenge is not simply detecting another alert. Analysts may need to correlate signals across identities, endpoints, networks, cloud environments and applications before deciding whether an incident requires action.
Zscaler's approach is designed to bring those signals together so that AI agents can assist with investigation and response rather than leaving every stage of the process to manual analysis.

What Powers Zscaler Agentic SOC?
Zscaler says Agentic SOC combines several components rather than relying on a single AI model.
These include Zscaler telemetry, a decoy mesh network, specialised AI agents, zero trust controls and integrations with customers' existing third-party security controls.
The company also says it is working with frontier AI providers including Anthropic and OpenAI. Their models are integrated with Zscaler's threat intelligence and zero trust telemetry to support the company's AI agents.
Zscaler describes this as an open-platform approach. Security teams can also bring vulnerability findings and third-party security information into SOC workflows.
The significance is that the AI layer is intended to operate with security-specific context rather than analysing isolated alerts without broader environmental information.
From Detection to Investigation and Response
One of the more important elements of the announcement is the move from AI-assisted detection toward automated security operations.
Zscaler says its specialised agents can perform different roles across the investigation process, including:
Alert triage
Root-cause investigation
Assigning verdicts
Triggering response workflows
Continuous threat hunting
The platform's data-rich context graph is designed to correlate real-time zero trust telemetry with third-party information. This is intended to help security teams map and investigate complex incident chains.

Closed-Loop Remediation
Zscaler also highlights what it calls closed-loop inline remediation.
According to the company, its native inline controls can isolate compromised users, block command-and-control communications and restrict lateral movement. The platform can also integrate with third-party security tools to support additional response actions.
This creates a workflow in which security telemetry can feed investigation, investigation can lead to a verdict, and the resulting decision can trigger a containment action.
The broader concept is important for modern SOC design: detection alone does not stop an attack. The operational value comes from shortening the distance between identifying malicious activity and taking an appropriate defensive action.
A Security Context Layer for AI Agents
Another notable component is Zscaler's use of a data-rich context graph.
Rather than treating individual security alerts as isolated events, the system is designed to connect telemetry with additional security information to establish relationships between events and prioritise complex incident chains.
Zscaler says its telemetry spans network, identity, endpoint, cloud and AI activity. The company states that its platform processes 750 billion daily zero trust transactions, which it says can be operationalised for real-time detection and response.
Zscaler also says its AI agents have been trained and continuously tuned using more than 10 years of frontline SOC, managed detection and response and threat-hunting experience, with threat intelligence informed by thousands of customer environments globally.
These figures and claims are from Zscaler and should be understood as company-provided information.

Human Expertise Still Has a Role
Despite its focus on autonomous agents, Zscaler does not describe Agentic SOC as a replacement for human security expertise.
The company says its approach combines AI speed with human judgement from Zscaler and Red Canary security experts.
This distinction matters because automated security response introduces its own operational risks. A system that acts quickly still needs reliable context and appropriate controls to ensure that defensive actions match the threat.
Zscaler's announcement therefore frames agentic security as a way to extend human expertise, reduce repetitive analyst workload and allow security teams to concentrate on higher-value investigation and threat hunting.
The Broader Shift Toward Agentic SecOps
Zscaler's announcement highlights a broader industry shift toward agentic security operations.
Traditional security automation generally follows predefined rules. Agentic approaches aim to introduce systems that can interpret context, perform specialised tasks, make decisions within defined workflows and initiate actions.
For enterprises, this could mean a gradual shift from SOC platforms that primarily collect and present security alerts toward systems designed to actively participate in investigation and response.
However, the effectiveness of such approaches will depend on the quality of telemetry, the reliability of AI reasoning, response controls and the governance surrounding automated actions.
The announcement does not provide independent performance testing or comparative results demonstrating how Agentic SOC performs against competing SOC technologies.
Availability
Zscaler says Agentic SOC is globally available today. The company directs organisations to its Agentic SecOps solution and global launch webinar for additional information.
Additional details were not disclosed in the announcement regarding independent performance benchmarks, detailed pricing or comparative effectiveness against other SOC platforms.
What This Means for Security Teams
The launch reflects growing demand for security operations that can keep pace with increasingly automated and adaptive threats.
The most important change is not simply the addition of AI to a SOC. It is the attempt to connect AI reasoning with security context and direct response controls.
For security leaders, the development reinforces several practical priorities:
Consolidate security context across major environments.
Reduce the time between detection and investigation.
Automate repetitive SOC workflows where appropriate.
Maintain human oversight for important security decisions.
Integrate existing third-party security controls.
Treat zero trust and access controls as important components of AI-era defence.
Zscaler's Agentic SOC represents one company's approach to this transition. Its success in real-world environments will ultimately depend on how effectively AI agents, security telemetry, automation and human oversight work together.
Source: Zscaler
About the Author