Analyst(s): Fernando Montenegro
Publication Date: September 18, 2026
Zscaler has entered the agentic SOC market with four specialized AI agents, inline containment, and frontier models from Anthropic and OpenAI. The agents themselves are now table stakes; what stands out is the telemetry they run on, and the open question is how far autonomous containment should go when the SOC’s hardest calls are the ones agents can least reliably verify.
What Is Covered in This Article:
- What Zscaler announced: A generally available Agentic SOC offering built on inline telemetry, a decoy mesh, and Red Canary detection, with four agents spanning triage, investigation, verdict, and response.
- Why the telemetry matters more than the agents: Autonomous depth is bounded by verifier quality, and Zscaler’s inline position and deception assets are a strong source of the ground truth agents need to act.
- The claim worth pressing is that closed-loop containment without step-by-step approval is credible for routine tasks and riskier for ambiguous ones, so the human gate is the thing to locate.
- Adjudication needs context the wire does not carry: Assets like Avalor and Symmetry Systems help, but resolving hard cases will depend on how deeply Zscaler integrates identity, CMDB, and business context it does not own.
- A crowded market: CrowdStrike, Palo Alto Networks, Microsoft, and others are selling a version of the same story, and Zscaler’s differentiation is inline enforcement reach rather than agents alone.
The News: Zscaler (NASDAQ: ZS) announced Zscaler Agentic SOC on September 9, 2026, a security operations offering built around specialized AI agents and now generally available worldwide. The platform pairs Zscaler’s inline telemetry, drawn from what the company reports as 750 billion daily zero-trust transactions, with a data-rich context graph that correlates that signal with identity, device, cloud, and third-party data to map and prioritize incidents.
Four specialized agents divide the work across triage, investigation, verdict, and response, and the platform can contain threats inline through native controls that isolate users, block command-and-control traffic, and cut off lateral movement. Zscaler is combining the agents with its decoy mesh network and detection expertise from Red Canary, the MDR provider it acquired in 2025. To power the agents’ reasoning, Zscaler has partnered with frontier AI labs, including Anthropic and OpenAI.
Zscaler Launches Agentic SOC, Betting on Telemetry Over Model Horsepower
Analyst Take: The agentic SOC went from pitch to table stakes in a single year. CrowdStrike shipped its next evolution a week before this announcement. Palo Alto Networks rebuilt Cortex around agents in February, and Microsoft, SentinelOne, Cisco through Splunk, Google, and a crowd of AI-SOC startups have all planted flags in the same ground. Whether a platform has agents is no longer the question worth asking. What those agents can trust when they act is, because that, far more than model choice, is what separates a demo from production.
Our standing view is that autonomous depth in the SOC is bounded by verifier availability, not by model capability. An agent goes as far as it has a cheap, reliable way to check its own work, and then it stops. Triage, enrichment, and detection translation come with usable oracles, so agents get good at them fast. The hard calls are a different animal. Adjudicating an ambiguous true positive, or containing a threat when the attacker and a legitimate user look identical at the indicator level, is where the oracle turns expensive, and autonomy should stall.
The Edge Is the Oracle, Not the Agents
Seen this way, Zscaler’s real advantage is not the four agents. It is the material they run on. Inline position across a very large volume of zero trust transactions, a decoy mesh that produces a high-confidence signal by design, and the validated detections and analyst judgment that arrived with Red Canary last year add up to an unusually good set of verifiers.
Deception is the cleanest case. An interaction with a decoy is close to unambiguous, and that is the ground truth an agent needs to move without a human reading over its shoulder. A pure-play startup with strong models and thin telemetry is working the same problem from the wrong end. This is the part of the announcement we think Zscaler has earned.
It also does not launch from weakness. Zscaler carried a Net Score of 32 on 303 respondents in ETR’s latest TSIS survey, down about three points survey over survey and closer to four and a half years over year, even as its deployment breadth widened slightly. Spending intent is not a measure of product quality and says nothing about this offering in particular. It does tell us the base underneath the launch is still expanding.
Reading the Wire Is Not the Same as Understanding the Case
There is a real question embedded in the closed-loop pitch: Is enforcement-path visibility sufficient to adjudicate the case? Zscaler sees an enormous amount on the wire, but ambiguous incidents are resolved with context that the inline view lacks. Who owns the asset, how critical it is, whether this identity is behaving oddly for this person in this role this week, and whether a change ticket already explains the anomaly.
Zscaler has been moving toward that context. Avalor gave it a security data fabric, and Symmetry Systems added data security posture, so the raw material is better than it was a year ago. The open part is the plumbing into the rest of the enterprise: identity providers, the CMDB, asset ownership, and the business context that lives in systems Zscaler does not run. How well the agents adjudicate will track how deep those integrations go, not how much traffic the platform inspects.
The Claim to Press: Containment Without Approval
The boldest line in the announcement is closed-loop containment at machine speed, with native controls that isolate users, cut command-and-control, and stop lateral movement. On cheap-oracle tasks, let it run. Regarding consequential containment, we want to see where the human gate sits and how the system determines that an incident is unambiguous enough to act on alone. Isolating a compromised service account is recoverable. Isolating the wrong executive in the middle of a live deal is not. That distance is precisely the judgment the oracle is weakest at. Take the capability seriously, and still ask to see the guardrails.
A Crowded Floor
None of this plays out in a vacuum. CrowdStrike, Palo Alto Networks, Microsoft, SentinelOne, Google, and Cisco are all selling a version of the same story, and several of them own the endpoint or the SIEM that Zscaler does not. Zscaler’s counter is enforcement reach. It already sits inline, so containment is a native action rather than an API call handed to someone else’s control point. That is a genuine distinction, and also a boundary, because the SOC still has to cover endpoints, cloud control planes, and identity systems that Zscaler does not mediate. The open-platform posture and third-party integrations carry as much weight as the inline story.
Two Frontier Labs and the Bill That Follows
Partnering with both Anthropic and OpenAI, rather than committing to one, buys model diversity, a better shot at explainability, and a hedge against any single provider’s roadmap. It also sends security investigation context, some of the most sensitive data an enterprise holds, through more than one external frontier lab, and plenty of security teams have not finished that AI-governance conversation with themselves. Investigation is context-hungry by nature, so the token bill scales with the very thing that makes the offering good. We would want the unit economics at enterprise volume on the table before assuming they improve on their own.
What to Watch:
- Where does autonomous containment stop and the human gate begin? Zscaler says its agents contain threats without approval at each step. The line between recoverable and irreversible actions is where buyers should push hardest in a proof of concept.
- Do the enterprise integrations run deep enough to adjudicate? Inline traffic does not carry asset ownership, identity behavior, or business context. Adjudication quality will track how far the agents reach into systems Zscaler does not run, not traffic volume.
- What do the token economics look like at scale? Investigation depth is the product, so cost tracks context. Enterprises should model per-incident cost against analyst headcount before assuming the agentic approach is cheaper.
- Quis custodiet ipsos custodes (who watches the watchers… err, agents)? As enterprises fill with their own autonomous agents, can a SOC keyed to identity and channel telemetry monitor a population that acts through authorized paths and reroutes when a channel is closed?
For more information, read the full announcement from Zscaler.
Disclosure: Futurum is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.
Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum as a whole.
Other Insights From Futurum:
Netskope Bets Agentic AI Can Solve the SOC Capacity Crisis
CrowdStrike Deepens Agentic SOC Strategy Across Partners, Services, and Devices
Zscaler Bets on Agentic AI Security at Zenith Live 2026
Can Zscaler Own the AI Agent Control Plane?
Author Information
Fernando Montenegro serves as the Vice President & Practice Lead for Cybersecurity & Resilience at The Futurum Group. In this role, he leads the development and execution of the Cybersecurity research agenda, working closely with the team to drive the practice's growth. His research focuses on addressing critical topics in modern cybersecurity. These include the multifaceted role of AI in cybersecurity, strategies for managing an ever-expanding attack surface, and the evolution of cybersecurity architectures toward more platform-oriented solutions.
Before joining The Futurum Group, Fernando held senior industry analyst roles at Omdia, S&P Global, and 451 Research. His career also includes diverse roles in customer support, security, IT operations, professional services, and sales engineering. He has worked with pioneering Internet Service Providers, established security vendors, and startups across North and South America.
Fernando holds a Bachelor’s degree in Computer Science from Universidade Federal do Rio Grande do Sul in Brazil and various industry certifications. Although he is originally from Brazil, he has been based in Toronto, Canada, for many years.

