Building the Reference Architecture for AI-Enabled Security Operations

As AI drives cyberattacks to machine speed, traditional Security Operations Centers can no longer rely on human response alone.

In this episode of Built for Trust, Nick Lippis and Peter Campbell, Security Researcher & Agentic AI Working Groups Lead at ONUG, unpack ONUG’s AI-Enabled SOC Working Group, one of the highest-voted initiatives from the ONUG board. Together, they explore how organizations can safely adopt autonomous AI while maintaining governance, trust, and human oversight.

Nick and Peter walk through the group’s reference architecture, covering AI agent personas, levels of autonomy, and the decisions that should remain in human hands. They also discuss distributed versus orchestrated agent architectures and why preserving forensic evidence is just as important as responding at machine speed.

Whether you’re modernizing your SOC or preparing for agentic security operations, this episode offers a practical framework for building AI-enabled security without sacrificing trust, compliance, or control.

Want to help shape this framework? ONUG is looking for practitioners and vendors to help refine the reference architecture ahead of the AI Networking Summit in New York City on October 28–29. Learn more and get involved.

New episodes of the Built for Trust Podcast come out every Thursday. Subscribe to get notified.