Summary
- KDDI has launched a 24/7 managed detection and response service for the US and EMEA using Exaforce’s agentic security operations technology.
- The service combines automated detection, triage, investigation, and response with human oversight and documented escalation processes.
- Its value will depend on investigation quality, false-positive reduction, accountable containment, and whether automation genuinely reduces analyst workload rather than moving it elsewhere.
KDDI is taking agentic AI out of the security-software licence and placing it inside a managed operation, launching a 24-hour detection and response service for organisations that want automated investigation without building an AI-enabled security operations centre themselves.
KDDI’s American and European subsidiaries have launched the managed detection and response service across the United States, Europe, the Middle East, and Africa in partnership with Exaforce. The service combines KDDI’s managed-security operation with software for threat detection, triage, investigation, and accelerated response.
The companies are targeting organisations facing growing security and regulatory requirements without the budget, staffing, or specialist expertise needed to operate the newest generation of security tooling internally. KDDI is effectively packaging the technology as an operating service rather than expecting every customer to buy, integrate, tune, and supervise autonomous security tooling independently.
Exaforce uses AI agents alongside a real-time security knowledge graph to gather evidence and carry out work normally handled by analysts, while KDDI provides round-the-clock managed oversight around that process. KDDI describes the model as keeping people “on the loop”, with human staff retaining accountability over the automated operation rather than treating the agents as an unsupervised replacement for a SOC team.
The service also includes contractual service levels aligned with reporting deadlines and documented response and escalation procedures, linking automation with a more conventional managed-security obligation. That combination is commercially important because customers ultimately buy an outcome — investigated and contained incidents — rather than the number of AI tasks running behind it.
The SOC has an alert economics problem
Security operations centres have spent years accumulating products capable of detecting suspicious activity, yet every additional detection source can create more alerts for employees to investigate. Endpoint tools, identity systems, cloud platforms, email security, network monitoring, and vulnerability products may each identify legitimate concerns, but the combined workload can overwhelm a team before the organisation lacks another source of telemetry.
Automation has consequently moved further into investigation. Conventional security orchestration can execute predetermined steps when an alert meets specific conditions, whereas agentic systems promise to gather context, decide what evidence is relevant, and choose an investigative path without following one fixed playbook for every incident.
That approach could reduce repetitive work if the agent consistently performs the first layers of investigation and leaves analysts with a smaller number of well-supported cases. It could equally create another opaque layer if automated conclusions are incomplete or difficult to challenge, particularly where relevant evidence sits in systems the agent cannot access or unusual business behaviour resembles malicious activity.
A managed service changes the economics because KDDI can build common processes around the technology, supervise its operation across multiple customers, and retain security staff for escalation. Organisations that cannot justify a full internal SOC can therefore consume the capability as a recurring service rather than recruiting specialist analysts and integrating several security platforms themselves.
The commercial test is whether that arrangement removes work rather than redistributing it. Faster automated triage has limited value if customers still repeat the investigation before trusting the outcome, while excessive false positives can move workload between KDDI, Exaforce’s agents, and an internal IT team without reducing it.
Autonomous security needs stricter permissions
The more autonomy a security agent receives, the more consequential its permissions become. Software that reads alerts poses one level of operational risk, while an agent authorised to isolate an endpoint, disable an account, change a firewall rule, or block access can interrupt business activity directly.
Managed detection providers therefore have to establish where automation stops and approval begins. Customers also need evidence showing what the system observed, which action it recommended or executed, and why, particularly when an incident later becomes part of a regulatory investigation, cyber-insurance claim, or internal review.
European customers add a reporting dimension because cyber regimes such as NIS2 have increased formal incident-management obligations across a wider set of organisations. A managed provider can help gather evidence and meet contractual escalation windows, although the organisation itself still has to understand when an event crosses its legal reporting threshold.
KDDI’s inclusion of documented escalation procedures and service levels aligned with reporting requirements is therefore more operationally relevant than the broad claim that AI will make a SOC faster. The service has to connect automated investigation with a process through which somebody remains responsible for the decision and its consequences.
Managed services may be the faster adoption route
The launch also shows how agentic AI is being absorbed into existing enterprise technology categories rather than sold exclusively as a new class of standalone agent. Security vendors are putting autonomous functions inside SOC platforms, identity products, cloud services, and managed operations where organisations already buy software and expertise.
That may give agentic security a more credible route into production because customers can judge it against established measures. Investigation time, false positives, escalation quality, analyst workload, containment speed, unresolved incidents, and missed detections all provide more useful evidence than the number of autonomous actions completed.
KDDI and Exaforce have not published independent comparative performance data for this service, so the launch does not establish that an agentic SOC produces better outcomes than a well-run conventional MDR operation. The technology also inherits the quality of the information available to it: incomplete identity data, missing logs, weak endpoint coverage, or badly configured cloud systems can constrain an agent just as they constrain a human analyst.
That leaves the operating model as the more substantial part of the announcement. KDDI is not asking customers to trust autonomous security software in isolation; it is wrapping the software in human oversight, escalation, contractual obligations, and a managed relationship.
If the agents consistently remove low-value investigation while producing evidence analysts can understand and challenge, that arrangement could extend sophisticated security operations to organisations unable to build them internally. If customers still have to repeat every important investigation before acting, the AI layer will have changed the mechanics of the SOC without changing its economics.












