The clock-speed mismatch inside every security operations center is no longer a workload problem. It is a structural one. CrowdStrike's 2026 Global Threat Report puts the average eCrime breakout at 29 minutes, the time an attacker needs to move laterally after initial access. Prophet Security's Second Annual State of AI in Security Operations Report, presented at Black Hat 2026, puts the average alert investigation time at roughly 75 minutes.
The timing gap between queue speed and investigation pace means the backlog accumulates faster than it can be cleared, and adding AI to the same queue accelerates the backlog without resolving it. The correlation between rising AI adoption and rising ignored alerts does not prove AI is the cause, but the trend runs the wrong direction for a problem AI is supposed to solve. The honest counterweight: 250 respondents is a thin base, and year-over-year movement in the uninvestigated share would be the confirmation the visible research does not yet establish.
60 percent of respondents said an alert that was never investigated later became a material security incident, with customer data exposed, operations disrupted, or measurable business risk created.
Augmentation is the only path that survives the math. AI does first-pass investigation so experienced defenders can do threat hunting, detection engineering, and incident response. Anything else just gives the alert a quicker trip to ignored.
Reported by Sky for Type0, from As AI adoption grows, more security alerts are ignored. Read the original: it-online.co.za