Decoding the world of cybersecurity

KDDI launches agentic MDR across EMEA

KDDI has launched a managed detection and response service for the US and EMEA using Exaforce technology to automate parts of security triage, investigation, and response.

KDDI launches agentic MDR across EMEA
Summary
  • KDDI America and KDDI Europe have launched a 24/7 MDR service spanning the US, Europe, the Middle East, and Africa.
  • Exaforce technology will provide AI-assisted detection, triage, investigation, and response within the service.
  • The model reflects a wider shift in managed security towards automating SOC analysis while retaining human oversight and contractual accountability.

KDDI has launched a managed detection and response service across Europe, the Middle East, Africa, and the US using agentic-AI technology from Exaforce to automate parts of security operations.

The 24/7 service combines KDDI’s managed-security operation with Exaforce’s AI-native SOC platform, which uses a security knowledge graph and software agents to support threat detection, alert triage, investigation, and response.

KDDI says human analysts retain oversight of the service rather than being removed from decision-making. That distinction will be central to how organisations assess AI-heavy managed security services, particularly where provider actions can affect production systems.

The service is being launched by KDDI America and KDDI Europe and is intended for customers across the US and EMEA. KDDI also says contractual service levels can be aligned with regulatory reporting deadlines and supported by documented escalation and response procedures.

That creates a more substantive proposition than simply adding a conversational AI assistant to a SOC. Incident-handling obligations increasingly have strict timelines, while managed providers may possess much of the telemetry and expertise needed to determine whether an event reaches a regulatory reporting threshold.

Under regimes such as NIS2 and DORA, responsibility remains with the regulated organisation even when parts of detection and response are outsourced. A provider can support evidence collection, triage, escalation, and containment, but it cannot remove the customer’s accountability for governance and regulatory decisions.

Automation can nevertheless address a persistent operational problem: security teams receive far more alerts and telemetry than human analysts can inspect manually. AI agents can potentially assemble context, correlate events, and perform repetitive investigative steps before presenting higher-confidence findings to specialists.

The risk is that speed without reliable controls can amplify mistakes. Automated systems need clear authority boundaries around containment, credential revocation, endpoint isolation, or other actions capable of interrupting legitimate operations.

Providers also need evidence trails showing how an AI-assisted conclusion was reached, particularly when a customer must later explain an incident to regulators, insurers, auditors, or its own board.

KDDI says Exaforce uses a neuro-symbolic AI approach designed to process enterprise-scale security data efficiently. Those efficacy and cost claims are supplied by the companies and will depend on real-world deployments.

The wider direction is easier to establish. MDR providers are increasingly competing not only on staffing and threat expertise but on how much investigation can be automated, how rapidly evidence can be assembled, and how tightly response services integrate with compliance obligations.

That creates a procurement question extending beyond detection rates. Organisations using AI-intensive managed security will need to understand where automation acts independently, where approval remains human, what telemetry leaves their environment, how model or platform failures are handled, and what contractual responsibility applies when automated analysis is wrong.

KDDI’s new service therefore sits at the intersection of two trends: the continuing outsourcing of security operations and the movement of AI from analyst assistance towards more autonomous investigative workflows. The value of that combination will ultimately be measured in operational outcomes and accountability rather than the presence of an AI agent in the SOC.

×