12 SEP 2026 — Alerts triggered by AI tools in corporate security operations centres grew 685 per cent between February and June. They are 0.43 per cent of all alerts, and 94.1 per cent of them are noise.
All three numbers come from the same analysis, and reporting any one without the other two produces a different story. The first is the one that will travel, so the other two are set out here beside it.
What a 685 per cent rise is measuring
Any growth rate depends entirely on what it grew from. Work backwards from 0.43 per cent and the starting point was somewhere around 0.05 per cent — a change from almost none to very few.
The word "around" is necessary because "grew 685 per cent" is ambiguous between growing by 685 per cent, which puts February near 0.055 per cent, and growing to 685 per cent of the original, which puts it near 0.063 per cent. Those are not far apart here, and in a figure quoted to three significant digits it is worth noticing that the headline number cannot be resolved to two.
That is not a reason to dismiss the finding. A category growing this fast from a small base is exactly what an early trend looks like, and a SOC manager planning capacity for next year should care more about the slope than the level. But the sentence "AI alerts grew 685 per cent" invites a reader to picture security teams overwhelmed by AI, and the same data says AI accounts for about one alert in every 233.
What the figure captures is a category showing up, not a category that has grown large. That is still worth reporting the first time anyone can count it.
The noise rate is the operational number
Of the AI-related alerts, 94.1 per cent are classified as noise and 5.8 per cent as genuine security risk.
A 94 per cent false-positive rate is poor on its own terms, and it is worse than it sounds because of where the cost falls. Every one of those alerts consumes an analyst's attention before being dismissed, and the dismissals train the analyst. A category that is wrong nineteen times out of twenty becomes a category people learn to close quickly, which is precisely how the twentieth is missed.
This is the well-documented failure mode of any new detection class, and it is not an argument against detecting AI usage. It is an argument that current detections are untrustworthy, and that a SOC should plan to tune them extensively, not just deploy them.
Where the alerts are coming from
Not from attacks, mostly. The analysis describes a new class of alert produced by ordinary use: developers running coding agents, and non-technical staff signing consumer AI tools into corporate accounts.
That changes what the number is about. The 685 per cent tracks the adoption of AI inside the company, seen through security telemetry: employees doing their jobs with new tools, arriving at a monitoring system that has no category for them and therefore treats them as anomalies.
Seen this way, the detector is working and the definition is missing. An alert that fires because somebody authenticated a coding assistant is correctly observing something and incorrectly calling it a risk, and the fix is policy — a decision about which tools are sanctioned — rather than a better rule.
Three numbers, three different decisions
Each figure supports a different action, and conflating them is how this kind of research gets misused.
At 0.43 per cent there is no case for restructuring a SOC around this yet. The growth rate argues for planning anyway, since a category climbing at that pace will not stay marginal for many quarters. And with 94.1 per cent noise, whatever gets deployed now will mostly be wrong, so it needs tuning against the local environment before it reaches a queue that humans read.
Each figure alone misleads in its own direction: underinvestment from the first, panic from the second, and from the third a decision that the detections are useless and should be switched off. That last one does the most damage.
What to measure in your own environment
The published percentages are somebody else's denominator. The version that matters is local and is cheap to obtain.
Count what fraction of your alert volume comes from AI tool usage, and what fraction of those you closed without action last quarter. If your noise rate is near 94 per cent you have the same problem as everybody else and the fix is tuning. If it is much lower, your detections are narrower than the ones in this study and the comparison does not transfer.
Second, count how many distinct AI tools appear in that telemetry. That number is a shadow-IT inventory obtained for free, and it is usually larger than the list anyone in the organisation would have given you.
What to watch
Whether the noise rate falls. Ninety-four per cent noise in a category's first year is ordinary. The same figure a year later would say nobody tuned it, and that nobody is going to.
And whether the share keeps compounding. The threshold to watch for is the moment AI-related alerts begin competing with established categories for analyst time, which is a question about queue position, not about percentages. At 0.43 per cent that is some way off, and at 685 per cent a year it is not as far off as it looks.