Everyone told you to deploy AI agents. No one told you what happens to your SOC when you do

Key summary
Adversary breakout speeds have shrunk: fastest recorded 27 seconds; average now 29 minutes, down from 48 minutes in 2024.
CrowdStrike detects more than 1,800 distinct AI applications on endpoints and nearly 160 million unique application instances; each instance generates detection, identity, and data-access logs that flow into SIEM systems.
AI agent adoption is widespread but not production-ready: 85% of surveyed enterprises are running agent pilots while only 5% have moved agents into production; an 80-point gap exists because security teams cannot answer basic questions about agents.
In most default logging setups, agent-initiated activity looks the same as human-initiated activity; distinguishing them requires walking the process tree — e.g., a Chrome process launched from Louis’s cloud Cowork or ChatGPT is agent-controlled, unlike a desktop-launched Chrome.
Supply-chain risks are emerging: ClawHavoc, described as the first major supply-chain attack on the AI agent ecosystem, targeted ClawHub; OpenClaw is a public skills registry; audits found malicious skills and compromised packages (Koi: 341 malicious of 2,857; Antiy CERT: 1,184 compromised packages).
