Pillar
AI security, on this site, is not a separate universe of ‘AI-native’ platforms. It is what happens when a model sits on the same tickets, logs, and tools a human analyst already had, and when that model is allowed to act.
Triage the queue
Open the listTreat model output as untrusted
Open the listInventory the agent before it talks
Open the listQuestions about AI Security
That is the list we have finished. A model that reads the alert queue and drafts or closes tickets is a job we can compare: does it see the same evidence as the analyst, can you refuse the vendor cloud, and does it stop at a suggestion. Broader AI-security lists are still in research.
Tools that sit with detection and response: Microsoft Security Copilot, Vega, Dropzone AI, Shuffle, TheHive, and Keep. We care whether they hunt, whether they respond, and whether a human can still see the case they touched.
The AI SOC list also appears under Security Operations, next to SIEM and XDR, because that is where the queue lives. This category exists for readers who arrived looking for AI and should not have to guess that the useful page is named SOC.
Yes, when we can score them. A prompt firewall that only works in the vendor’s demo is not a list yet. The standard will be the same as XSS: does the control hold at the sink where the model output is used.