Swimlane Cuts Investigation Costs Up to 90% with Intelligent Routing for Agentic AI
New routing layer in Swimlane AI SOC applies AI reasoning where it adds value and provides agents with access to
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.

![]()
Swimlane, the leader in agentic AI automation for every security function, today expanded Swimlane AI SOC with intelligent automation routing to support end-to-end agentic investigations. The new capability evaluates each incoming alert and directs it to one of three execution paths: deterministic automation, AI-assisted investigation or fully agentic investigation. By matching the level of AI involvement to the work required, Swimlane helps security teams increase investigation capacity without defaulting every task to a costly AI model.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260819876631/en/

AI Where It Matters, Automation Everywhere Else
Security teams are being asked to investigate more alerts with the same headcount, at the exact moment token costs across the industry are climbing. Many AI SOC platforms respond by pushing every task through a model, regardless of whether the task needs one. Swimlane takes a different approach: intelligent routing decides, alert by alert, whether the job needs automation, AI assistance, or a fully agentic investigation, and sends it down that path automatically. Additionally, Swimlane’s AI SOC capability supports model selection to optimize AI costs and allows customers to bring their own model (BYOM)
“As AI consumption continues to rise, the next generation of the SOC will not be able to run every task through AI by default. It will know which work actually needs AI,” said Cody Cornell, Co-Founder and CEO of Swimlane. “When you’re processing hundreds of thousands of investigations, spending five or ten dollars in tokens for each investigation doesn’t scale. Swimlane pairs the speed and predictability of automation with AI where reasoning and judgment create real value, so customers can expand what their SOC can handle without replacing an analyst-capacity problem with an AI-spend problem.”
A More Sustainable Path to the Agentic SOC
With Swimlane AI SOC, security teams stop paying AI prices for work automation already does well, sending well-understood alert types straight to automation for maximum speed, scale and predictability at a fraction of the cost of AI tokens. Unknown alert types are handled either by fully agentic investigations where Hero reaches a verdict with zero human configuration or touch, or through AI-assisted investigations where analysts remain in control but AI handles the investigation work, provides context and recommends the next action.
This balance of automation and AI translates into immediate financial impact. For example, a Swimlane healthcare customer who was investigating about 180 threats a day achieved 90% of cost savings by using intelligent routing to reserve agentic AI for only the most complex 10% of threats across their entire investigation workload.
Over time, repeated investigations get validated and codified into known automation paths. The system becomes more scalable and more efficient as it learns from the work it has already done.
New capabilities include:
- Intelligent Automation Routing: A new routing layer within the Investigation & Response Agent evaluates each alert and directs it to deterministic automation, AI-assisted investigation or fully agentic investigation based on the level of judgment required and the organization’s confidence in the outcome.
- Fully Agentic Investigations: For alerts an organization trusts, the Investigation & Response Agent handles the entire investigation with zero configuration. Trigger it from a webhook or an API call, and the agent takes it from there, no playbook required.
- Self-Learning Optimizations: Swimlane AI SOC learns as it investigates, letting teams codify knowledge gained from unknown alerts into repeatable playbooks. This creates a continuous optimization cycle in which investigations evolve from AI-driven to fully automated, keeping AI budget focused on complex work while maximizing the scale of standard automation.
Built to Avoid the Tradeoffs of AI-First and Automation-Only Platforms
Traditional SOAR platforms are effective for deterministic processes but can require significant expertise to build and maintain. AI-first SOC products can reduce manual investigation work, but often depend on model-driven processing even when a known automation path would be more efficient. Swimlane combines both approaches in one governed platform and dynamically selects the right one for each alert.
The same architecture gives enterprises the control required to operate AI safely at scale, including analyst oversight, transparent case management and the ability to govern how investigations are executed across security functions.
Additional Hero AI Innovations
The Swimlane Turbine release also expands how security practitioners build and manage automation through Hero AI, helping teams increase development capacity without requiring specialized platform expertise.
- Intelligent Visualization Agent: Users describe the report or visualization they need in plain language, and Hero AI instantly generates the visualization, displays it in a live preview and applies the result directly to a dashboard or case.
- Data Ingestion Agent: A deep agent connects Turbine to new ingestion sources, reducing the manual work required to build and maintain integrations.
- Enhanced Playbook Generator Agent: Hero AI now asks clarifying questions and provides real-time progress updates while creating or modifying playbooks, improving first-pass accuracy and reducing rework.
- Hero AI Model Selection: Customers can select a specific AWS Bedrock model for each Hero AI agent, allowing teams to align model cost, performance and availability with the requirements of the task.
“Turbine is evolving from a platform security teams build on to a platform they can simply ask,” said Srikant Vissamsetti, Chief Operating Officer at Swimlane. “Hero AI removes technical barriers across the platform, while intelligent routing ensures customers use AI with purpose. Together, these capabilities help security teams build faster, investigate more and maintain control over how AI is applied.”
Availability
These capabilities are generally available now as part of the current Turbine release. Hero AI must be enabled in a customer’s tenant to access the widget-building and model-selection features.
Key Resources
- Learn more about Swimlane AI SOC: swimlane.com/product/ai-soc
- Learn more about Swimlane Turbine: swimlane.com/swimlane-turbine
- Register for our upcoming webinar “Intelligent Routing for Agentic Investigations” on September 23 at 11:00 AM ET.
- Request a demo: swimlane.com/demo
About Swimlane
At Swimlane, we believe the convergence of agentic AI and automation can solve the most challenging security, compliance and IT/OT operations problems. With Swimlane, enterprises and MSSPs benefit from the world’s first and only AI automation platform for every security function. Only Swimlane gives you the scale and flexibility to unify security teams, tools and telemetry, ensuring today’s SecOps are always a step ahead of tomorrow’s threats.
Learn more: swimlane.com
View source version on businesswire.com: https://www.businesswire.com/news/home/20260819876631/en/
Media gallery


