Brief IA

Campus Security: Over 5 Million Alerts Handled by AI Agents

🛠️ AI Tools·Tom Levy·

Campus Security: Over 5 Million Alerts Handled by AI Agents

Campus Security: Over 5 Million Alerts Handled by AI Agents
Key Takeaways
1An AI agent powered by Gemini processed over 5 million alerts in one year at Google, reducing analysis time from 30 minutes to 60 seconds
294% of IT teams in higher education are understaffed in the face of rising threats
3AI agents are subject to strict safeguards and enhanced auditability, with limited autonomous actions
476% of cybersecurity professionals reported experiencing burnout in 2025
💡Why it mattersAI agents help relieve overwhelmed security teams, but their use requires rigorous oversight to ensure the safety and traceability of decisions.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

Faced with understaffed security operations centers, AI agents are already being deployed to sort alerts and accelerate investigations. According to Google, an agent powered by Gemini processed over 5 million alerts in one year, reducing a typical 30-minute analysis to just 60 seconds. These applications come with precise safeguards, featuring limited autonomous actions and enhanced auditability.

Agents can isolate a workstation at 2 AM, but cannot modify a firewall

Ramya Chitrakar illustrates the operational limits: an autonomous agent can consult threat intelligence and quarantine a standard workstation at 2 AM, but modifying a critical firewall rule still requires human authorization based on risk policies. She emphasizes the need for strict safeguards and a clear definition of interfaces to frame what an agent is allowed to observe and execute. The visibility of the SOC is presented as inseparable from extreme explainability and centralized logging, ensuring that the morning team has a transparent audit trail and understands the decisions made by an agent. Recommendations include governing agents with the same rigor as human analysts and prohibiting any uncontrolled access to SIEMs, SOAR tools, and downstream application points. Integrating these limits and identity governance directly into the operations platform should, according to Chitrakar, enable the evolution of autonomous defense without losing control or oversight.

Google claims to have processed over 5 million alerts with an agent

According to Ramya Chitrakar, Google's security operations rely on a triage and investigation agent that has handled over 5 million alerts in a year. Thanks to Gemini, this system reportedly reduced a typical manual analysis from 30 minutes to just 60 seconds. Chitrakar also cites malware analysis and vulnerability discovery among the use cases, mentioning VirusTotal Code Insight, powered by Gemini, to analyze binary behaviors and identify emerging threats. When platforms integrate agentic capabilities, the creation of agents can, according to the proposed principle, occur in plain language rather than through specialized queries.

Understaffing and burnout weigh on campus teams

According to Nile, 94% of IT teams in higher education are understaffed in the face of rising threats. According to Sophos, 76% of cybersecurity professionals reported experiencing burnout in the past year. Ramya Chitrakar attributes this situation, among other factors, to an ongoing alert overload and the prevalence of manual tasks that exhaust teams. She believes that SOCs find themselves trapped in a reactive loop, at the expense of a more proactive and optimized posture.

Sorting, interception, and limited human role to major cases

According to Ramya Chitrakar, significant benefits are observed for defenders: artificial intelligence facilitates alert sorting and can help identify malicious behaviors, while humans focus on the most critical situations. For small teams, she indicates that automation helps reduce alert fatigue, automates sorting, and ensures continuous monitoring, 24/7. Agentic AI is described as a means to allow analysts to concentrate on priority tasks while optimizing security strategies and freeing up resources.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.