Swimlane has launched an intelligent routing system for its AI-powered security operations center platform that directs alerts to automation, AI-assisted analysis, or fully autonomous investigation, with one healthcare customer reporting 90% cost savings. The company announced the expanded AI SOC capability is designed to help security teams manage rising alert volumes without defaulting every task to expensive AI models. The new routing layer evaluates incoming alerts and matches them to the appropriate level of artificial intelligence or traditional automation.

The routing system sends each alert down one of three paths: deterministic automation for well-understood threats, AI-assisted investigation where analysts stay in control while AI handles research, or fully agentic investigation where AI manages the entire process. Swimlane highlighted a healthcare organization that investigates roughly 180 threats daily and achieved 90% cost savings by reserving autonomous AI for the most complex 10% of its investigation workload. The platform also supports model selection to optimize AI expenses and allows customers to bring their own model. Over time, the system can convert repeated AI-driven investigations into validated automation paths.

"When you're processing hundreds of thousands of investigations, spending five or ten dollars in tokens for each investigation doesn't scale," said Cody Cornell, co-founder and CEO at Swimlane. According to Cornell, the platform "pairs the speed and predictability of automation with AI where reasoning and judgment create real value, so customers can expand what their SOC can handle without replacing an analyst-capacity problem with an AI-spend problem." The company says the capability addresses the sharp increase in alerts facing security teams, particularly as more investigation tasks are pushed to AI models by default in a shift that can become expensive at scale. Swimlane's chief operating officer Srikant Vissamsetti stated that the routing ensures customers use AI with purpose while removing technical barriers across the platform.

The routing system works by evaluating the level of judgment required and the organization's confidence in the outcome for each alert. Well-understood alert types go straight to automation for maximum speed, scale, and predictability at a fraction of AI token costs, while unknown alert types are handled through AI-assisted or fully autonomous investigations. The platform includes self-learning optimizations that let teams convert knowledge gained from unknown alerts into repeatable playbooks, creating what Swimlane describes as a continuous optimization cycle where investigations evolve from AI-driven to fully automated. The company also unveiled additional Hero AI capabilities designed to increase development capacity, including an intelligent visualization agent that generates reports from plain-language descriptions, a data ingestion agent that connects Turbine to new sources, and an enhanced playbook generator that asks clarifying questions while creating workflows. All capabilities are generally available now as part of the current Turbine release. For security operations leaders balancing headcount constraints against cloud budgets, the intelligent routing model reframes AI adoption as a tiering decision rather than a binary choice. Organizations that treat automation and agentic AI as complementary tools instead of competing philosophies may find more sustainable paths to scaling investigation capacity without triggering runaway token expenses.