For as long as MDR has existed, service capacity has been a headcount problem.
More customers generate more alerts. More alerts require more analysts. To make the economics work, providers standardized processes, detections, playbooks and service delivery across their customer base.
That model solved an important problem for its time. Most organizations couldn't hire, train and retain a 24×7 security operations team, and MDR gave them access to one.
But the threat environment MDR was designed for is changing.
We are now in the AI era.
Attackers are increasingly using AI to move faster and operate at greater scale. At the same time, enterprise environments are becoming more distributed, telemetry volumes continue to grow, and security data increasingly lives across SIEMs, data lakes, cloud platforms, identity systems and security tools.
Defending in this environment requires more than 24×7 analyst coverage. It requires machine-speed investigation and response, continuous detection improvement, real-time visibility, transparency into decisions, control of your data, and the ability to operate across a federated security architecture.
The MDR operating model has to change with the threat model.
AI is making that possible.
The Trust-Me Problem
A recent customer conversation crystallized this for me.
Their MDR provider controlled everything. The customer couldn't see whether logs were still flowing. Couldn't see which alerts were generated, how they were prioritized, or why. Couldn't see what wasn't prioritized, which is usually the more important list. There was no health check they could run themselves.
The operating model was simple: trust the provider to get it right. If you needed something more, pay more.
The data situation was harder. Telemetry was centralized in the provider's platform. The customer couldn't control how it was retained and tiered against their own requirements, and couldn't easily query it when they wanted to investigate something themselves. A new detection or hunting use case meant a change request and a price.
Then there's the coupling. In many MDR architectures, the service, SIEM and data are tightly coupled. That can make replacing the provider or changing the SIEM a much larger project than either should be, and prevents organizations from making those decisions independently.
There's another consequence of standardization: response becomes difficult.
Taking action requires understanding the customer's environment. Is this account critical? Can this endpoint be isolated without disrupting production? Is this connection expected? What business process depends on this system? What actions has the customer already authorized?
Traditional MDR providers can't economically build that depth of context manually for every customer. So many services stop at investigation, recommendation and escalation, leaving the customer to take the actual action.
The same standardization that makes traditional MDR scalable also limits how deeply it can understand and act inside each customer's environment.
None of this is provider incompetence. It's the architecture doing what it was built to do. Under headcount economics, deep customization requires analyst hours that have to come from somewhere. Standardization is what makes the model work.
Providers are constrained by that operating model as much as their customers are.
AI is starting to remove that constraint.
AI Changes the Operating Model
Traditional MDR has largely been built around analysts doing the work: reviewing alerts, gathering context, investigating, hunting, escalating and responding. Automation exists in places, but much of the workflow remains manual.
AI agents change that operating model.
Agents can autonomously investigate alerts, gather context across multiple systems, determine what information they need next, run searches and hunts, reason over evidence, recommend or execute response actions, and continuously feed what they learn back into detection engineering.
AI can also continuously build and use customer-specific context - identities, assets, vulnerabilities, security controls, historical investigations, response policies and approved SOPs, as part of every investigation and response decision.
That makes it possible to move from generic monitoring and escalation toward customer-specific investigation and governed response at machine speed.
This isn't simply making the analyst faster. It moves MDR from human-executed workflows with automation around the edges toward AI-executed workflows with humans in or on the loop based on risk.
Autonomy doesn't mean giving up control. Low-risk actions can be executed automatically. Other actions can operate with a human on the loop for oversight, while higher-impact actions require a human in the loop before execution.
The goal is machine-speed execution with the right level of human control.
Gartner, Reference Architecture Brief: Managed Detection and Response, Alex Tytarenko, Kevin Schmidt, 4 August 2026, ID G00856610 - published this month, reflects this shift - describing AI SOC agents as part of the modern MDR architecture and a way to augment the MDR workforce.
And this changes the economics.
Historically, service capacity was tightly coupled to analyst capacity. AI starts to break that relationship.
One analyst can oversee investigations that previously required hours of manual work. Detection engineers can manage far more customer-specific content. Threat hunters can use agents for continuous searches while focusing their own time on sophisticated, hypothesis-driven hunts.
The operating question changes from "how many analysts do we need to process this volume?" to "how much expertise can each analyst deliver when AI handles the repetitive work?"
And once that's true, standardization no longer has to come at the expense of customization. Capabilities the traditional model struggled to deliver economically, customer-specific detection content, explaining why something was deprioritized, continuous hunting, opening up access to data become possible at scale.
AI doesn't just make MDR faster. It changes what an MDR provider can deliver to each customer at scale.
What AI-Powered MDR Should Look Like
Visibility as a default, not a quarterly report. Customers see their alert flow, their investigations and the health of their own pipeline, including what was deprioritized and why.
Customers retain control of their data. Customers determine retention and tiering based on their own requirements and maintain access to their telemetry when they need to investigate something themselves.
Federated search instead of forced centralization. Investigations run across existing SIEMs and data lakes rather than requiring everything to move into one provider's store.
Architectural independence. Changing the SIEM shouldn't require changing the provider. Hybrid SIEM-plus-data-lake should be a supported architecture, not an exception.
Customer-specific, governed response. Response is based on the customer's environment, business context and approved SOPs, with autonomy determined by the risk of the action.
A system that compounds. A closed investigation informs future detections. New intelligence triggers hunts. Hunts surface detection gaps. Those gaps generate detection logic, continuously, not quarterly.
That's the difference between outsourcing your SOC and augmenting it.
The provider still delivers the 24×7 people, expertise and response capability. The customer doesn't surrender visibility, control of their data or architectural flexibility to get it.
Detection Engineering Moves Inside the Service
Most MDR services have centered on monitoring, investigation and response. Detection engineering sat outside, or was standardized so heavily that it stopped reflecting any individual environment.
That's changing.
Gartner's MDR reference architecture reflects this shift, with detection engineering, curated threat intelligence and offensive security validation becoming increasingly important components of modern MDR.
It matters because the question buyers should be asking isn't "did my MDR investigate the alerts?"
It's:
"Are we detecting the threats that matter to us in the first place?"
AI makes it economically possible to continuously interpret emerging intelligence, understand a specific environment, find gaps in existing coverage, generate tailored detection logic and validate that it actually works.
The provider moves from monitoring detections to continuously improving detection effectiveness - closing gaps before an adversary finds them rather than after.
Human Expertise Doesn't Go Away
Every conversation about AI in security operations arrives at whether AI replaces analysts.
That's the wrong question.
The objective isn't removing humans. It's to stop spending scarce expertise on work machines can increasingly perform.
An experienced threat hunter shouldn't spend hours collecting basic enrichment data. A detection engineer shouldn't spend the day translating the same logic between platforms. A Tier 3 analyst shouldn't investigate the thousandth variation of an attack they've already seen.
Humans should do what only humans do well: understand business context, validate ambiguous conclusions, develop hunting hypotheses, make high-consequence response decisions and talk to customers during a live incident.
Gartner's reference architecture makes the same point, human experts remain at the core of MDR despite advances in automation and AI.
The analyst role isn't disappearing.
It's moving up the value chain.
Where This Lands
The next generation of MDR isn't today's MDR with an AI assistant bolted onto the analyst console.
The architecture itself is changing.
Monitoring, threat intelligence, investigation, hunting, detection engineering, validation and response are converging into one connected system. Agents execute high-volume operational work at machine speed, using customer-specific context and operating inside explicit governance boundaries. Humans supply expertise, judgment, context and accountability.
The providers who get there first won't just run cheaper SOCs.
They'll offer something the standardized model structurally could not: security operations shaped around each customer's actual environment, with the customer able to see and control what's happening, at a price the market can support.
If you're buying or renewing MDR, the questions worth asking have changed:
- Can you tell right now whether your telemetry is still flowing?
- Can you see what your provider deprioritized last week, and why?
- Can you query your own data when you need to investigate something — without filing a request?
- How long does a new detection or hunting use case take, and what does it cost?
- Can your MDR safely take action based on your environment and your response policies?
- Could you change your SIEM without changing your provider — or the reverse?
If the answers are uncomfortable, look beyond the service. Look at the architecture underneath it. That architecture can now change.
That's what we're building AiStrike for: an AI-native platform for modern MDR, where providers don't have to choose between economics and transparency — and customers don't have to choose between 24×7 expertise and control.
Gartner, Reference Architecture Brief: Managed Detection and Response, Alex Tytarenko, Kevin Schmidt, 4 August 2026.
GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved. Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact.




.webp)
.webp)
.webp)
.webp)
.webp)


.webp)
.webp)

.webp)

.png)