The pitch was fewer false positives. The reality in many SOCs is a new flavour of noise: AI detectors that confidently flag anomalies nobody has time to chase.

Analysts describe dashboards that look busy and feel empty. Each alert demands context — asset ownership, change tickets, whether the “unusual” login was just a founder on holiday Wi‑Fi. Models don’t know the politics of your org chart.

Teams fighting back tune ruthlessly, measure mean-time-to-triage, and refuse tools that can’t explain themselves. Vendors that ship transparency and better defaults keep seats; those that dump raw model scores lose renewals.

AI belongs in detection. It does not get to outsource accountability. Someone still has to decide what “urgent” means at 2 a.m.

AI alert noise is still an ownership problem dressed up as a model problem.

Alert class Keep? Tune by
Known change windows Suppress Change tickets
Rare admin paths Keep hot Asset criticality
Vague “anomaly” Demote Explainability score

SOCs that refuse unexplained scores get quieter nights. The others drown politely.

None of this arrives as a clean discontinuity. It shows up as slightly different meetings, slightly different checklists, and a few people who quietly stop doing the old workaround because the new path finally hurts less.

Seen up close, the pattern is less about breakthrough theatre and more about quieter competence: fewer surprises, clearer owners, and tools that survive contact with Tuesday afternoon.