{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/usf-soc-agentic-ai-companion-deployment-2026/",
 "asOf": "2026-09-26",
 "id": "usf-soc-agentic-ai-companion-deployment-2026",
 "date": "2026-09-05",
 "datePrecision": "day",
 "title": "Year-long SOC fieldwork finds analysts reused an agentic AI companion's output in over 90% of tickets",
 "lane": "defense",
 "kind": "paper",
 "summary": "University of South Florida researchers embedded in a working SOC for over a year built and deployed an LLM-based agentic companion to handle high-volume, low-priority tickets, with analysts using it in the final four months. They report that companion outputs were reused in analysts' closing reports in more than 90% of cases, and that analysts who shaped the companion's behaviour came to trust it more.",
 "whyItMatters": "It is field evidence from a real SOC, not a benchmark, on how analysts adopt and trust an AI triage agent.",
 "actors": [
  "university-of-south-florida"
 ],
 "topics": [
  "soc-automation"
 ],
 "atlas": [
  "human-approver"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://arxiv.org/abs/2609.06250",
   "publisher": "arXiv",
   "title": "It is Not Yet Another Tool: Creating and Deploying an Agentic AI Companion in a Security Operations Center",
   "date": "2026-09-05",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "Fieldwork ran over one year; analysts were invited to use the companion during the last four months.",
   "locator": "Abstract"
  },
  {
   "fact": "In more than 90% of cases the companion's outputs were reused in the ticket's closing report; of 108 coded tickets, 35 used the draft verbatim, 63 partially and 10 were written from scratch.",
   "locator": "Abstract; Results, Table 2"
  },
  {
   "fact": "The coded corpus is 108 tickets from six analysts (29 April to 31 July 2026); the companion was offered only to more experienced analysts. Median draft reuse was 96.7% and the mean 85.5%.",
   "locator": "Corpus and coding; Results"
  }
 ],
 "significance": 2,
 "fideQuestions": [
  "FID-076"
 ],
 "methods": [],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}