Splunk and AWS are making AI autonomy a security setting

Splunk and AWS are turning AI autonomy into a configurable security dial. Through an expanded partnership, the two tech giants are shifting AI agents from simply offering advice to actively taking containment and remediation actions. While security automation is hardly new because firewalls, EDR platforms, and identity managers have executed predefined rules for years, agentic AI fundamentally shifts the operational paradigm. Rather than following rigid scripts, an agent investigates, evaluates context, formulates a strategy, and acts. Splunk and AWS now want enterprises to decide precisely how much operational authority they are comfortable surrendering to that machine logic.

The initiative centres on Splunk’s Agentic SOC, framed as an architectural co-development rather than a superficial platform integration. At its core is adjustable autonomy, a framework that allows security operations teams to dial an AI’s role from purely advisory up to autonomous execution while preserving policy controls and human oversight. Splunk and AWS are making authority itself a setting, and enterprise security is an unforgiving proving ground for the experiment.

The modern SOC is already saturated with alerts, dashboards, and automated triage scripts. Splunk has built detection, investigation, and response workflows using Automated Threat Analysis alongside entity analytics to feed agents the context they need. The company describes this trajectory as an evolution from human-driven, AI-assisted security to an agentic-led, human-governed operational model. The crucial pivot point arrives when software shifts from inquiry to direct execution.

Recommending an account suspension after spotting an identity compromise is straightforward, but actually executing that suspension carries serious systemic risk. If that account manages production infrastructure, a mathematically sound security response could trigger a business outage. Security data rarely arrives pre-packaged with organisational context, meaning a sudden off-hours login could be an active breach or an executive boarding an international flight. Similarly, an unmapped API call might indicate lateral movement or simply an unannounced DevOps deployment. Humans misjudge these scenarios too, but an autonomous agent executes at a speed and volume that fundamentally alters the blast radius of a mistake.

Splunk’s adjustable autonomy model addresses this risk by eliminating the all-or-nothing approach. Security teams can establish granular, risk-based parameters governing where and when an agent can act. In this architecture, governance stops being a compliance afterthought and becomes core engineering. Securing autonomous operations requires teams to determine which assets permit automated intervention, build rollback mechanisms for faulty actions, and maintain detailed audit trails tracking the evidence and policy rules that triggered each intervention. Building agentic security is less about raw reasoning capacity and far more about managing, auditing, and reversing what happens immediately after that reasoning concludes.

The operational feasibility of this approach depends heavily on AWS Security Hub Extended. AWS introduced the Extended plan to aggregate signals across first-party services and third-party vendors under unified billing and consumption models. As a primary partner, Splunk pulls findings from Security Hub Extended into Splunk Enterprise Security to correlate them against enterprise-wide telemetry. This plumbing directly dictates what an agent can deduce, since an isolated alert means little without identity posture, host history, data classifications, and network topology. AWS simplifies the collection of telemetry across identity, endpoint, cloud, and supply chains, while Splunk provides the analytical engine. In production security environments, access to deep operational context and the permissions to act on it matter far more than the underlying foundation model.

The standard enterprise defence for deploying AI is that a human always remains in control. While that safeguard works when reviewing five alerts a day, it falters when the primary reason for adopting AI is that humans can no longer keep pace with modern attack velocity. If an analyst must manually approve every minor step, the performance gains evaporate. Conversely, if the AI is given free rein over routine tasks, the human role shifts upstream towards defining operational boundaries, tuning policies, and managing edge cases.

That transition demands seasoned judgment, which directly clashes with a well-documented talent pipeline bottleneck. Cybersecurity has an experience problem, and AI may make it harder to solve because the repetitive baseline work automated away by agents is the exact training ground where junior practitioners build institutional intuition. This issue is particularly stark in South Africa, where Cisco’s 2025 Cybersecurity Readiness Index revealed that 78% of surveyed organisations faced severe talent shortages, with over half reporting more than ten critical vacancies. While agentic systems offer smaller teams immediate leverage, those teams must still know enough to recognise when a model hallucinates or overreaches. Without deliberate junior development, enterprises risk building sophisticated automated defences supervised by analysts who lack the depth to challenge them.

Engineering roadmaps frequently treat full autonomy as the inevitable goal under the assumption that AI must assist, then recommend, and finally operate completely independently. Security demands a more deliberate posture, as some operations like terminating an unsanctioned token should run on autopilot, while others like severing a core database connection remain far too tied to business risk to leave unattended. Adjustable autonomy recognises that the optimal level of automation is rarely the maximum level available. As Splunk and AWS advance their platform, success will depend on how safely organisations can widen an agent’s authority over time, proving that knowing where to limit automated execution requires far more intelligence than the code needed to enable it.

The initiative centers on Splunk’s Agentic SOC

, framed as an architectural co-development rather than a superficial platform integration. At its core is adjustable autonomy, a framework that allows security operations teams to dial an AI’s role from purely advisory up to autonomous execution while preserving policy controls and human oversight. Splunk and AWS are making authority itself a setting, and enterprise security is an unforgiving proving ground for the experiment.

The modern SOC is already saturated with alerts, dashboards, and automated triage scripts. Splunk has built detection, investigation, and response workflows using Automated Threat Analysis alongside entity analytics to feed agents the context they need. The company describes this trajectory as an evolution from human-driven, AI-assisted security to an agentic-led, human-governed operational model. The crucial pivot point arrives when software shifts from inquiry to direct execution.

Recommending an account suspension after spotting identity compromise is straightforward, but actually executing that suspension carries serious systemic risk. If that account manages production infrastructure, a mathematically sound security response could trigger a business outage. Security data rarely arrives pre-packaged with organizational context, meaning a sudden off-hours login could be an active breach or an executive boarding an international flight. Similarly, an unmapped API call might indicate lateral movement or simply an unannounced DevOps deployment. Humans misjudge these scenarios too, but an autonomous agent executes at a speed and volume that fundamentally alters the blast radius of a mistake.

Splunk’s adjustable autonomy model addresses this risk by eliminating the all-or-nothing approach. Security teams can establish granular, risk-based parameters governing where and when an agent can act. In this architecture, governance stops being a compliance afterthought and becomes core engineering. Securing autonomous operations requires teams to determine which assets permit automated intervention, build rollback mechanisms for faulty actions, and maintain detailed audit trails tracking the evidence and policy rules that triggered each intervention. Building agentic security is less about raw reasoning capacity and far more about managing, auditing, and reversing what happens immediately after that reasoning concludes.

The operational feasibility of this approach depends heavily on AWS Security Hub Extended

. AWS introduced the Extended plan to aggregate signals across first-party services and third-party vendors under unified billing and consumption models. As a primary partner, Splunk pulls findings from Security Hub Extended into Splunk Enterprise Security to correlate them against enterprise-wide telemetry. This plumbing directly dictates what an agent can deduce, since an isolated alert means little without identity posture, host history, data classifications, and network topology. AWS simplifies the collection of telemetry across identity, endpoint, cloud, and supply chains, while Splunk provides the analytical engine. In production security environments, access to deep operational context and the permissions to act on it matter far more than the underlying foundation model.

The standard enterprise defense for deploying AI is that a human always remains in control. While that safeguard works when reviewing five alerts a day, it falters when the primary reason for adopting AI is that humans cannot keep pace with modern attack velocity. If an analyst must manually approve every minor step, the performance gains evaporate. Conversely, if the AI is given free rein over routine tasks, the human role shifts upstream toward defining operational boundaries, tuning policies, and managing edge cases.

That transition demands seasoned judgment, which directly clashes with a well-documented talent pipeline bottleneck. Cybersecurity has an experience problem, and AI may make it harder to solve

 because the repetitive baseline work automated away by agents is the exact training ground where junior practitioners build institutional intuition. This issue is stark in regions facing acute talent shortfalls, such as South Africa, where Cisco’s 2025 Cybersecurity Readiness Index revealed that 78% of surveyed organizations faced severe talent shortages, with over half reporting more than ten critical vacancies. While agentic systems offer smaller teams immediate leverage, those teams must still know enough to recognize when a model hallucinates or overreaches. Without deliberate junior development, enterprises risk building sophisticated automated defenses supervised by analysts who lack the depth to challenge them.

Engineering roadmaps frequently treat full autonomy as the inevitable goal under the assumption that AI must assist, then recommend, and finally operate completely independently. Security demands a more deliberate posture, as some operations like terminating an unsanctioned token should run on autopilot, while others like severing a core database connection remain far too tied to business risk to leave unattended. Adjustable autonomy recognizes that the optimal level of automation is rarely the maximum level available. As Splunk and AWS advance their platform, success will depend on how safely organizations can widen an agent’s authority over time, proving that knowing where to limit automated execution requires far more intelligence than the code needed to enable it.

Zeen Social Icons