I've written before that email is still the front door for most attacks, and that the modern phishing message is AI-written — clean grammar, correct local idiom, your company's tone, none of the old tells. That's one half of the story. The other half arrived this year: the defenders got the same class of tool. Microsoft's Security Copilot now runs a Phishing Triage Agent that helps analysts find the genuinely malicious mail dramatically faster — the figure Microsoft quotes is up to 550% faster triage. So we've arrived at a strange new normal where an AI writes the attack and an AI helps sort the response. It's worth being precise about what that does and doesn't change, because the marketing on both sides is loud.
1. Both sides got an AI, and the symmetry is the point
The uncomfortable truth of 2026 security is that generative AI lowered the cost of a convincing attack far faster than it raised the cost of defending. One competent attacker can now produce thousands of tailored, well-written phishing messages that would once have taken a team. That flood is the problem Security Copilot is really answering: not that human analysts can't spot a bad email, but that they can't spot ten thousand of them before the one that matters lands. AI on defence isn't about being cleverer than the attacker. It's about matching their new throughput so your people can still get to the decision that counts.
2. What Security Copilot actually does
Stripped of the branding, the useful reality is triage at machine speed. The Phishing Triage Agent works through the flood of reported and suspected messages, does the tedious correlation a junior analyst would do — pulling the signals together, checking the indicators, ranking what's likely malicious — and hands the analyst a prioritised, explained shortlist instead of an undifferentiated queue. It's the same move as the rest of the Copilot family: take the high-volume, low-judgement grind off the human and give them back the time for the part that needs a brain. For a small security team drowning in alerts, that's not a gimmick. That's the difference between investigating the real incident today versus next week.
3. It's an analyst multiplier, not a replacement
Here's where I part company with the more breathless takes. A triage agent makes a good analyst faster; it does not make you an analyst. It's excellent at "which of these ten thousand emails deserve a human's attention" and genuinely bad at the judgement calls that define real security work — is this anomaly an attack or a badly-behaved integration, is this insider activity malicious or just unusual, is the confident-sounding conclusion actually right. Hand those to the agent and you've automated the production of plausible-looking mistakes. The teams that win with this tooling use it to clear the grind and reinvest the reclaimed hours in the hard analysis. The teams that lose treat it as a reason to think less.
AI on the SOC floor raises your floor, not your ceiling. It stops good analysts drowning in volume. It does not turn thin coverage into deep expertise — and pretending it does is how you get quietly owned.
4. The governance trap nobody's talking about
Now the auditor in me has to speak up, because there's a trap here that the excitement obscures. A security AI agent, by definition, has privileged reach — into your mail, your alerts, your security telemetry, sometimes your response actions. That makes it one of the most sensitive identities in the whole estate, and therefore one of the most attractive targets. An attacker who can influence, poison or hijack your defensive AI is attacking the thing you trust most. So the same discipline I argued for with Copilot generally applies double here: the agent needs a named owner, least-privilege scope, its own monitoring, and a place in the control plane. Microsoft has moved agent security under a centralised control plane for exactly this reason. Defensive AI that isn't itself governed is a single point of failure wearing a superhero cape.
5. The human you can't patch
For all the AI-vs-AI framing, the target in the middle is still a person. Business email compromise still costs organisations billions a year, and the reason isn't weak filters — it's that a well-crafted message convinces a human to move money or change a payment detail. No triage agent changes that last mile. What holds it is the boring, human-plus-process control I keep coming back to: out-of-band verification for anything financial, so that a convincing email or even a convincing voice call isn't sufficient on its own. AI can help you find the malicious message faster. It cannot substitute for a culture where "the email looked completely legitimate" is never the whole story before money moves.
6. Where it fits in a real SOC
So where does this land for a practitioner deciding whether to adopt it? My honest read: Security Copilot and its agents are a genuine step forward for the specific, painful problem of alert and phishing volume, and if you run a lean team the time they hand back is real. Adopt it — but adopt it as an analyst multiplier sitting on top of a functioning security program, not as a substitute for one. Keep the human judgement, keep the out-of-band verification for money, and govern the defensive agents as carefully as you'd govern any privileged account. Do that, and the AI-vs-AI front line tilts your way. Skip it, and you've just given yourself a faster way to be confidently wrong. If you're weighing where AI fits in your security operations, I'm happy to compare notes.