Artificial intelligence could slash the time needed to train security analysts by half or more, according to a new report from Corelight on AI maturity in Security Operations Centers. The report outlines a three-stage evolution for integrating AI into security operations, moving from basic assistance to full autonomy, and argues that the real constraint on progress isn't technology but trust rooted in reliable data. Organizations can advance through these stages only when they have verifiable, high-quality network data that makes AI outputs traceable and evidence inspectable.
The report divides AI adoption into three distinct levels. At Stage 1, labeled "Assistance," AI helps analysts interpret data faster by analyzing information, explaining alerts, summarizing logs, and translating detection logic—many mature security centers already operate at this level. Stage 2, "Automation," introduces agentic AI that runs investigations, applies context, and proposes actions while analysts retain oversight for accuracy and final decisions. At Stage 3, "Autonomy," AI operates with near independence on routine decisions, running on continuous policy constraints and feedback loops while analysts oversee strategy but aren't involved in individual tasks. The key shift from automation to autonomy is removing case-by-case approval, which inverts the traditional relationship where security teams validate evidence before acting rather than reviewing it after an action executes.
Vijit Nair, SVP of Product at Corelight, states that "if your data itself has bias, the tools skew towards that judgment," emphasizing that AI doesn't fix poor inputs but scales them. Stan Kiefer, Senior Manager for Data Science at Corelight, adds that "AI alone is not trustworthy at this point, and without data to reference back, it may never be." The report finds that moving from assistance to automation is largely a data problem, while moving from automation to autonomy is about trusting the model and the decisions it produces. Analysts should be able to inspect the evidence behind a model's conclusion, which requires data and algorithms to be open to human inspection.
The report explains that AI functions as a "knowledge multiplier" rather than just a force multiplier, helping humans operate above their current expertise. A tier-one analyst can ask a complex question and get an evidence-based answer, gradually building skills to operate at a higher level with more confidence. This approach addresses a chronic problem in security operations: repetitive work that contributes to burnout and turnover, especially for junior analysts. Nair describes this as the difference between "craft"—manually working through data—and "art"—deciding what matters and what to do next, noting that AI "eats the craft" so people can focus on the art. The report argues that by replicating an analyst's workflow, surfacing recurring steps, and explaining complex detections in plain language, AI accelerates the learning curve and lets analysts spend less time on repetitive work and more on tasks requiring knowledge and judgment.
The report recommends that organizations view maturity as a staged process with increasing delegation and trust requirements at each level. It emphasizes that data quality is paramount because incomplete or low-context telemetry inhibits AI effectiveness, and verification enables progression since auditability determines how far AI can safely move into decision-making. The bottom line: trust is evidence-based, and analysts need traceable outputs rather than opaque recommendations to advance through the stages and shift their effort toward the interpretation and validation that require human judgment.

