Cloud Security Podcast by Google

EP261 No More Aspiration: Scaling a Modern SOC with Real AI Agents

20 snips
Feb 2, 2026
Dennis Chow, Director of Detection Engineering at UKG, builds and runs detection and response systems and leads agentic AI work for SOC workflows. He discusses AI-powered attacks being real and detection-as-code responses. He defines hybrid AI agent pipelines, explains a seven-stage master control flow, and shares production uses like triage, containment, and payload analysis.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

AI Attacks Are Here, But Not Dominant

  • AI-powered attacks are already present but not yet at large-scale zero-day exploitation via agents.
  • Detection pipelines and automated testing that simulate attacks give defenders an early advantage.
ADVICE

Guard The Agent With Deterministic Shells

  • Build a deterministic master control flow around agentic components to control cost and runaway behavior.
  • Use semi-deterministic checks, sampling, and final-disposition agents to limit investigations to 5–15 minutes.
ANECDOTE

From Full ADK To Hybrid After Costs Spiked

  • UKG moved from full ADK-driven agents to a hybrid model after costs and context windows spiraled.
  • The hybrid approach restored control and cut runaway investigation time significantly.
Get the Snipd Podcast app to discover more snips from this episode
Get the app