In short: Attackers use AI to attack faster and at larger scale. In a 2026 warning, Germany's Federal Office for Information Security (BSI) states that AI significantly lowers the effort, time and entry barriers for offensive cyber capabilities. Defenders can use AI in the Security Operations Center (SOC) to triage alerts and classify incidents faster. The decision to intervene stays with people. A pure SOC assistant is generally not a high-risk system under the EU AI Act, but it needs clear rules for data, approvals and traceability.
Why the topic is urgent now
A SOC monitors, assesses and responds to an organisation's security events around the clock. Its bottleneck is almost always human time: every alert must be reviewed, and many are false alarms.
The attacker side is getting faster. In its 2026 cybersecurity warning on the impact of AI developments on organisations' cybersecurity, the BSI writes that AI significantly reduces the effort, time and entry barriers for offensive cyber capabilities. Defenders, by contrast, remain bound by real operational limits such as testing effort, approval processes and patch maintenance windows. ENISA reaches a similar conclusion in its Threat Landscape 2025: AI systems give attackers a new level of scalability.
At the same time, the law demands fast response. The German BSI Act requires measures for handling security incidents (Section 30 BSIG), operators of critical facilities must use attack detection systems (Section 31(2) BSIG), and significant incidents must be reported within 24 hours (Section 32 BSIG). Article 21(2)(b) of the NIS 2 Directive sets the same baseline across the EU.
The terms in plain language
- SIEM (Security Information and Event Management): collects log data from across the IT estate, correlates it and raises alerts on suspicious patterns.
- SOAR (Security Orchestration, Automation and Response): automates steps after an alert, such as enriching data, opening a ticket or locking an account.
- Triage: the first review of an alert. Is it real, how urgent is it, who takes it?
- False positive: a false alarm where harmless activity is reported as an attack.
- MTTD and MTTR (mean time to detect, mean time to respond): average time until detection and until response.
- Playbook: a defined sequence of steps for a specific incident type.
- Human-in-the-loop: a person reviews and approves before an AI recommendation takes effect.
Where AI assistance helps in the SOC
This mainly means language models that support analysts, not autonomous systems that intervene on their own. Typical use cases:
- Preparing triage. The AI summarises an alert with its related events, maps it to a known attack technique and suggests a priority.
- Enriching context. Information on affected systems, users and known indicators of compromise is pulled together from several sources instead of the analyst querying each one.
- Writing queries. Analysts describe in natural language what they are looking for. The AI turns it into a SIEM query, which the analyst checks and runs.
- Documentation and reporting. Drafts for incident reports, shift handovers and the 24-hour initial notification are ready sooner. A person reviews the content and is accountable for it.
- Suggesting playbooks. The AI recommends the matching playbook. It runs after approval or, for clearly defined standard cases, automatically via SOAR.
How much time this saves depends heavily on data quality, processes and the model. To our knowledge, there are no robust, vendor-independent measurements from operations yet. We therefore do not quote percentages. Measure the effect in your own SOC, for example using MTTD, MTTR and time per triage.
Where the limits are
- Hallucination. Language models produce plausible but wrong statements, such as an invented process ID or a false attribution to a threat actor. The BSI names this risk explicitly in its paper on generative AI models and their opportunities and risks for industry and public authorities. Every AI statement must be traceable to raw data.
- Prompt injection. An attacker hides instructions in data the model processes, for example in a log entry, an email subject or a file name. OWASP lists prompt injection as the top risk for LLM applications (LLM01:2025) and distinguishes direct and indirect injection. In a SOC, the indirect form matters most, because much of the input data can be influenced by the attacker.
- Traceability. An escalation or non-escalation must later be justifiable to a regulator, auditor or court. "The AI rated it that way" is not a justification. Inputs, outputs, model version and the human decision need to be logged.
- Data leakage. SOC data contains personal data, credentials and vulnerability details. Which data goes where, who runs the model and where it runs are questions of the GDPR and information security.
- Known patterns. According to a BSI analysis of AI and current cyber threats, AI does not replace classic detection based on indicators of compromise. AI complements rules and signatures, it does not replace them.
Classification under the EU AI Act
The EU AI Act (Regulation (EU) 2024/1689) classifies AI systems by risk. High-risk systems include those under Annex III point 2 that are intended as safety components in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating or electricity. Recital 55 clarifies that components intended to be used solely for cybersecurity purposes should not qualify as safety components.
An AI assistant that supports analysts with triage and reporting is therefore generally not a high-risk system. This is a classification, not an exemption: if the system itself controls facilities, for example by automatically shutting down part of a power supply, the individual case must be reassessed. Following the amendment by Regulation (EU) 2026/1744, obligations for high-risk systems under Annex III apply from 2 December 2027.
Regardless of the risk class, Article 4 applies: providers and deployers take measures to support the AI literacy of their staff. Since the amendment by Regulation (EU) 2026/1744, the duty is worded as a duty to support, but it remains in place. For a SOC this means analysts must understand what the model can do, where it goes wrong and how to check its outputs.
Introduction in five steps
- Define use cases and metrics. Start with a narrowly scoped case, for example summarising phishing reports. Measure before and after: time per triage, MTTD, MTTR, share of false positives.
- Clarify data and operation. Which data may the model see? Does it run in your infrastructure or at a provider, and under which contract? Check the need for a data protection impact assessment and limit the assistant's access rights to the minimum.
- Make human-in-the-loop mandatory. The AI proposes, a person decides. Only standard cases described in an approved playbook run automatically. Interventions in production systems and facilities are always approved by an analyst.
- Harden against attacks on the model. Treat input data as untrusted, check outputs against raw data and keep the assistant's tool permissions narrow. Test the system specifically with prompt injection cases before it goes live.
- Log, train, adjust. Store inputs, outputs, model version and decisions in an audit-proof way. Train analysts in line with Article 4 of the EU AI Act. Review the metrics from step 1 regularly and expand or scale back the use.
How GermanAI Defense supports you
Our 24/7 SOC combines central event analysis (SIEM), fixed playbooks for standard cases (SOAR) and analysts who take over critical situations immediately. With AI Solutions, we build AI assistants and RAG systems with a clear permission architecture. In our GRC consulting, we classify AI use under the EU AI Act and the GDPR. The GAD Academy trains teams on the EU AI Act and AI literacy.
→ More on our Cybersecurity Services: germanaidefense.com/cybersecurity
Sources
- BSI cybersecurity warning 2026 on the impact of AI on organisations' cybersecurity (German)
- BSI: Generative AI models, opportunities and risks for industry and authorities
- BSI: AI and current cyber threats (German)
- ENISA Threat Landscape 2025, section 4.5
- OWASP Top 10 for LLM Applications 2025: LLM01 Prompt Injection
- Regulation (EU) 2024/1689 (EU AI Act), EUR-Lex, Article 4, Annex III, Recital 55
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex
- Directive (EU) 2022/2555 (NIS 2), EUR-Lex, Article 21
- BSI Act (BSIG), gesetze-im-internet.de (German), Sections 30, 31, 32
As of 29 September 2026. This article is a professional overview and does not replace legal advice in individual cases.