Agentic AI Quietly Rewrites the NDR Pitch, But Procurement Rules Have Not Caught Up
Network detection vendors say autonomous triage is thinning the alert queue. Buyers are now asking what regulators will let those agents actually do.

Network Detection and Response (NDR) has long carried a reputation for drowning analysts in alerts. That reputation is being challenged by a wave of products bolting agentic artificial intelligence onto the detection layer, with vendors arguing that autonomous triage is now closing tickets rather than opening them. The shift, underway across 2024 and into 2025, is forcing a parallel conversation inside compliance teams about what an AI agent is permitted to decide on its own.
The technical claim is straightforward. Where legacy NDR scored flows and handed everything to a human, agentic systems chain detection, enrichment, and containment into a single loop. Vendors including Vectra AI, Darktrace, and ExtraHop have all shipped agent-style features in the past year. Operators running them report fewer false positives and faster mean time to triage.
The regulatory question is less settled.
Under Article 22 of the General Data Protection Regulation (GDPR), data subjects have a right not to be subject to a decision based solely on automated processing where it produces legal or similarly significant effects. Quarantining an employee endpoint, revoking a session, or blocking a contractor's traffic can plausibly meet that threshold. The European Data Protection Board has not yet issued specific guidance on autonomous security agents, and national supervisory authorities are reading the provision differently.
In the United States, the picture is more fragmented. The Cybersecurity and Infrastructure Security Agency (CISA) has encouraged automation in its Zero Trust Maturity Model, placing "automated" and "manual" decisioning on a defined progression. CISA has not, however, set boundaries on when a security agent should escalate to a human. The Securities and Exchange Commission (SEC) cybersecurity disclosure rule, codified at 17 CFR §229.106, requires registrants to describe their processes for assessing and managing material cybersecurity risks, which several outside counsel read to include the role of autonomous tooling in incident determination.
"Firms need to document where the agent acts and where the analyst acts, and they need to be able to reproduce that decision after the fact," said Luke Dembosky, co-chair of the data strategy and security group at Debevoise & Plimpton, in a client note circulated in October.
That documentation burden is the friction point. A security operations centre lead at a mid-sized European bank, speaking on background because the procurement is ongoing, said internal audit had asked for written sign-off on every action class an NDR agent could take before deployment. The list ran to forty-one items.
And the buyers are not waiting for clarity. Gartner's most recent Market Guide for NDR, published in June, identified agentic capabilities as a near-term differentiator rather than a future one.
The CISA Zero Trust Maturity Model v2.0 remains the closest thing to an American reference point. A revision is expected in the first half of 2026. Comments on the SEC's broader rulemaking around AI use by registrants close in February. Until then, the agent decides, and the lawyers reconcile.



