Zscaler launches Agentic SOC to counter AI-driven cyber threats
- Zscaler launches Agentic SOC on September 9, 2026, to stop AI-driven attacks at machine speed
- Partnerships with Anthropic and OpenAI integrate frontier models with proprietary threat intelligence
- Platform leverages 750 billion daily zero trust transactions for real-time detection and response
- Solution offers closed-loop inline remediation to isolate compromised users and block lateral movement

*this image is generated using AI for illustrative purposes only.
Zscaler Inc (NASDAQ: ZS) launched Zscaler Agentic SOC on September 9, 2026, introducing an AI-first security operations center designed to detect and contain AI-driven attacks at machine speed.
The new platform addresses the growing challenge of AI-powered threats that move faster than traditional manual correlation and analysis can handle. Zscaler stated that simply layering AI capabilities onto existing security stacks is insufficient for current protection needs.
Strategic AI Partnerships
To power the solution, Zscaler partnered with leading frontier AI labs, including Anthropic and OpenAI. By integrating these frontier models with proprietary threat intelligence and zero trust telemetry, the company aims to deliver AI agents that reason with greater depth and accuracy than single models alone.
This collaboration allows security teams to ingest vulnerability findings and operationalize them within SOC workflows. The approach reflects a commitment to building on the best available AI to meet the speed, reliability, and transparency demands of security operations.
Technical Capabilities
Zscaler Agentic SOC combines unique telemetry from the world’s largest decoy mesh network with expert-validated agents. It integrates Zscaler Zero Trust controls alongside customers’ third-party controls to detect threats earlier and automate containment.
The platform sits inline, capturing insights across network, identity, endpoint, cloud, and AI domains. This generates 750 billion daily zero trust transactions that security teams can operationalize for real-time detection and response.
Key Features
- Unified exposure management: Connects proactive attack surface reduction with reactive threat defense in a single platform.
- Specialized AI agents: Trained on more than 10 years of frontline SOC and threat-hunting experience.
- Closed-loop remediation: Automatically contains threats by isolating compromised users and blocking command-and-control communications.
- Data-rich context graph: Correlates real-time telemetry with third-party data to map complex incident chains.
Market Validation
Andrea Liccardi, Sr Cybersecurity Manager at Maire Tecnimont, noted that the previous alert noise forced analysts into triage rather than proactive hunting. He stated that Agentic SOC provides full attack-path context using existing telemetry, enabling faster decisions.
Allie Mellen, principal analyst and author of Code War, emphasized that AI attacks operate at a scale and adaptability different from traditional human-led activity. She argued that effective defense requires doubling down on Zero Trust principles and making AI attacks as expensive as possible.
What the Numbers Show
The scale of Zscaler’s inline telemetry is a critical differentiator in this launch. The platform processes 750 billion daily zero trust transactions, providing the raw data volume necessary to train and validate the specialized AI agents. This high-volume data ingestion supports the claim of machine-speed containment, distinguishing the solution from point-in-time security tools that lack continuous inline visibility.
How might Zscaler's integration with multiple frontier AI labs like Anthropic and OpenAI impact its pricing structure and potential vendor lock-in risks for enterprise customers?
What are the projected implications for traditional SOC staffing models if Agentic SOC achieves widespread adoption of automated containment and closed-loop remediation?
Could the reliance on proprietary telemetry from Zscaler's decoy mesh network create competitive barriers that limit third-party security vendors from integrating effectively with this new platform?

































