AI gives defenders a way to keep up with attackers. Its success creates a new infrastructure challenge: supplying the evidence for every investigation.
AI is giving attackers the ability to do more, faster. A major cybersecurity provider’s 2026 threat report recorded an 89% increase in attacks by AI-enabled adversaries in 2025 compared with 2024. That measures activity observed by one provider—not an 89% increase in all cyberattacks or SOC alerts—but it signals the pressure facing defenders.
An overloaded security operations center cannot close the gap simply by asking analysts to work harder. Every investigation still needs context. While the team works through one set of questions, new alerts keep arriving.
Defenders need to investigate more activity without increasing manual effort at the same rate. AI offers a way to do that. But reducing the work required from an analyst does not necessarily reduce the work required from the data infrastructure.
The investigation still needs its evidence.
AI gives the SOC a way to catch up
In one published production deployment, a 30-minute manual investigation became an automated workflow completed in under three minutes. The pipeline combined deterministic checks, specialized AI agents, and a final review agent.
Consider a suspicious login. An agent can check the identity’s recent activity, look for endpoint evidence, examine related network events, and assemble the findings. Instead of starting with a blank investigation, the analyst starts with context.
The promise is not simply speed. It is the ability to investigate more alerts, pursue relevant leads, and reserve human attention for decisions that require judgment.
For a team struggling to keep pace, this looks like the breakthrough it needs. But the analysts are not the only ones who have to keep up.
Why now: agents are adding demand on both sides of the data layer
AI agents are not just investigators. They are also part of the environment being investigated.
In a major log-management provider’s 2026 survey of 450 senior enterprise leaders, respondents attributed an average 93% increase in logs and telemetry over the preceding year to AI. In the same survey, 85% reported difficulty ingesting logs at the scale driven by AI workloads.
These findings cover AI workloads broadly, not agents alone. But they expose the first source of pressure: more evidence to collect, retain, and make usable.
Agents add another dimension. They can both generate telemetry and consume it—retrieving information, evaluating results, taking actions, and inspecting what happened next.
That makes the agent a new kind of data user in an operational sense, not a separate population outside machine identities.
The infrastructure must support both sides: more data produced by AI workloads and more data access required by automated investigations.
That is why this matters now. The SOC can become more capable at the same time that supplying its evidence becomes harder.
The agent does not just ask the same questions faster
It can pursue more of them.
- What else did this identity access?
- Which endpoint was involved?
- Has the same pattern appeared elsewhere?
- How far back does it go?
Each answer can lead to another query.
Even the initial deterministic IP-based triage in the published production workflow can execute up to 16 queries before later investigation stages. That is not a human-versus-AI benchmark. It illustrates how much data access can sit behind a single alert.
A simple model makes the potential multiplier visible:
Assume 1,000 investigated alerts per day. At four queries per alert, the backend serves 4,000 queries per day. At 40 queries per alert, it serves 40,000.
The same alert volume produces 10 times the queries under those assumptions.
Actual demand depends on investigation depth, context reuse, query consolidation, and query budgets. More queries are not automatically better investigations.
But expanding coverage and pursuing more relevant leads can increase backend work even as manual effort falls. Running those investigations in parallel can also concentrate demand into shorter periods.
AI can relieve the analyst bottleneck while exposing the infrastructure bottleneck.
The query multiplier can hit two different walls
The Query Multiplier Crisis is the risk that successful automation outgrows either the capacity or the economics of the systems supplying its evidence.
Those are different problems.
A concurrency wall
Published documentation for an enterprise search platform describes finite concurrent-search slots. When those slots are occupied, additional searches can be queued or rejected, depending on configuration.
An agent may know exactly which question to ask next and still have to wait for the backend to accept it.
Adding more automated investigators does not solve that constraint. Faster reasoning cannot compensate for unavailable search capacity.
A billing wall
In scan-priced systems, the cost depends on how much data each query processes. One published cloud-query pricing example uses $5 per terabyte scanned.
Apply that rate to the earlier workload model, assuming 0.01 TB scanned per query and a 30-day month.
At 4,000 daily queries, the modeled monthly scan charge is $6,000. At 40,000 daily queries, it is $60,000.
The outcome is not inevitable. Compression, columnar formats, and selective queries can reduce the bytes scanned. Not every data platform uses scan-based pricing.
But where that pricing applies, repeated evidence retrieval becomes an operating-cost variable that the automation plan must account for.
Keeping data affordably and investigating it affordably are not the same problem.
Enterprises are already rationing access to evidence
This is not only a hypothetical capacity-planning exercise.
In the same 2026 enterprise survey, respondents estimated average annual spending of $2.47 million on logging solutions, including ingestion, management, storage, indexing, rehydration, and querying. 75% reported higher log-management costs over the preceding year.
The more important finding is how organizations respond.
38% limit the number of queries and/or the amount of data queried. Another reported measure, used by 34%, is limiting investigations to avoid the cost of restoring logs from cold storage.
These measures can overlap, and they cover enterprise log management—not exclusively security operations. But their implication for an AI SOC is clear: a more capable investigator delivers less value when it cannot access the evidence it needs.
The friction also reaches AI deployment. 80% said the effort required to turn telemetry into actionable insights was hurting customer experience and delaying the transition of AI projects from pilot to production.
That does not establish that AI has overwhelmed every data platform. It establishes that data cost and usability are already constraining what some enterprises investigate and deploy.
The tempting response is to make the agent ask fewer questions. Sometimes tighter query discipline is appropriate. But restricting useful investigation merely to fit the infrastructure can sacrifice the depth that made automation attractive.
The answer should not be to make a better investigator stop following relevant evidence.
Rover is built for the questions an AI SOC asks
Rover approaches the problem through how evidence is indexed and how query compute is provisioned.
Indexed search in your own object storage
Rover stores inverted indexes alongside security records in customer-owned object storage. The query engine can use those indexes to locate relevant evidence rather than depend on repeated broad scans.
Compute allocated per query
Rover’s serverless query engine uses ephemeral, per-query compute. Query execution is separated from a permanently provisioned search cluster, so storage growth and investigative demand do not have to drive the same infrastructure decisions.
History without a restore step
Retained security history remains searchable without first rehydrating it from a cold archive. An investigation can follow a lead into older evidence rather than treating the recent hot tier as its boundary.
These are architectural design choices, not a claim of unlimited capacity or zero query cost. They address the two questions at the center of the problem: how evidence is found, and how the work of retrieving it is provisioned.
Let the SOC keep the advantage
The purpose of an AI SOC is not to generate more queries. It is to reach better-supported conclusions across more of the activity that deserves investigation.
That requires a data-infrastructure plan alongside the automation plan. The question is no longer only, “How much investigative work can we automate?” It is also, “Can we supply the evidence that work requires, at a sustainable cost and acceptable latency?”
AI gives the SOC the ability to ask more questions. The data infrastructure should help it get answers—not force it to stop asking.