Sophos, a cybersecurity firm protecting more than 625,000 organisations, has cut threat investigation time by 96% by building AI agents with OpenAI's Daybreak programme. According to the company, cases handled by these agents now average 89 seconds to investigate and respond, compared with roughly 38 minutes for its previous human-led process. About 52% of its Managed Detection and Response (MDR) cases are now resolved end-to-end by AI, within boundaries that Sophos analysts calibrate.
The agents sit inside Sophos Fusion, the company's AI-native defense system. An investigation agent gathers customer context, detections, indicators of compromise, and threat intelligence for each case. A planning model then creates a plan–execute–review loop, producing a summary with recommended response actions for analysts to review. Other agents can carry out parts of the response. Sophos says this lets it scale compute instead of adding equivalent headcount, and returns analysts to the threats, exceptions, and decisions where their expertise matters most.
Sophos has kept human judgement central by giving customers three operating modes: Notify, where Sophos recommends but the customer acts; Collaborate, where both sides work together; and Authorise, where Sophos can respond directly on the customer's behalf. The same boundaries apply whether a person or an agent does the work. As CTO John Peterson puts it, anything the company is not comfortable with an agent handling is passed off for human judgement.
Because this is a single vendor-authored case study from OpenAI, there are no independent sources to compare against. The story also notes that frontier AI is a double-edged sword: the same capabilities are spreading to open-weight models, giving attackers new ways to discover vulnerabilities. Peterson advises security leaders to return to fundamentals—patching, endpoint protection, MFA, network segmentation, and strong security operations—as vulnerabilities are being exploited at an unprecedented scale.