Monday, September 21, 2026

Zscaler’s 46-agent “Virtual SOC Workforce” draws paying customers ahead of general availability

At the core of Zscaler’s new approach is its agentic SOC solution, currently made up of 46 AI agents.

Zscaler is accelerating its push into “agentic AI” for security operations, with a fleet of specialised AI agents already in use by paying customers and more on the way as threats and infrastructure become increasingly AI-driven.

The company’s Zscaler ThreatLabz –  a global research arm of more than 150 experts across seven countries –  has long focused on phishing, malware, zero‑day exploits, and threat actor infrastructure. But that traditional research function is now being augmented by a growing line up of AI agents designed to take on defined roles in the security operations centre (SOC).

“We are now recruiting agents as well as part of that research team,” Zscaler’s Chief Security Officer and EVP R&D, Deepen Desai said – referring not to new hires, but to AI agents that can perform analysis, tracking, and conduct reverse engineering so senior analysts can focus on higher‑value work.

A modular AI workforce for the SOC

At the core of Zscaler’s new approach is its agentic SOC solution, currently made up of 46 AI agents. Each is tuned for a specific function – triage, detection, response, context, or correlation –  and built on top of multiple frontier models that Zscaler further trains with its own data and reinforcement learning.

Deepen explained, “And it’s not just one (AI model) vendor we are leveraging. We are evaluating multiple frontier models, and then we will do our own tuning on top of that model by using our own training dataset and reinforcement learning… that’s how we are able to then make (agent) an expert at a certain domain of the SOC field.”

“So, the triage, detection, response, context, correlation agents… so all of these are trained by our Zscaler Cyber AI team.”

The executive explained that one can subscribe to agents they want as part of their SOC team, to work on telemetry and deliver outcomes. Customers don’t have to use all 46 agents; they can pick what fits their environment and budget.

Rather than offering a single, monolithic AI layer, Zscaler positions these as a virtual SOC workforce that customers can selectively deploy.

Not every agent is producing the same level of efficacy.

Deepen Desai

The product is currently in limited availability, with six paying customers who have “moved everything over” to the agentic model as part of their SOC, and around a dozen design partners, including some very large enterprises, testing it in limited, controlled scenarios.

At the time of the interview, Deepen mentioned that general availability of these agents are slated to be launched in a quarter or so.

Customer pushback: Efficacy and token costs

Early adopters are already shaping the roadmap. One Fortune 500 CxO challenged the economics of running dozens of agents at once, asking bluntly who would shoulder token costs and whether all 46 are truly necessary “if I am already doing some of this myself?”

That kind of feedback could be seen as pushing Zscaler toward a more modular, subscription-like model for agents, rather than a one-size-fits-all bundle. Deepen had said the goal is to expand the number of agents to cover as much security expertise and knowledge as possible.

Operationally, Zscaler acknowledges that some agents are more mature than others: “Not every agent is producing the same level of efficacy,” Deepen said, noting that certain agents have required far more tuning based on real-world customer use.

What’s emerging as a non‑negotiable is data quality. The “garbage in, garbage out” problem is “10x more applicable to agentic workflows,” he said. 

If an organisation’s telemetry and data fabric are weak, AI agents will inherit those flaws.

Preparing for AI-native threats

Zscaler is also building agents specifically for AI infrastructure defense, arguing that AI detection and response is “a whole different game” from traditional IT security. 

The agent count is expected to grow over time, not shrink, as the company sees more opportunities for finely tuned agents across new threat surfaces like AI infrastructure

As Zscaler targets general availability in the coming quarter, its early customers are effectively test‑driving what a hybrid SOC – built from human analysts plus a configurable roster of AI agents —-could look like at scale.

Powered byspot_img

Read more

News

Powered byspot_img