Announced 9 Oct 2026 · Sources checked
What did OpenAI publish on 9 October?
OpenAI’s customer story is the dated primary object for this article. It frames Sophos—protecting “more than 625,000 organisations” on the page we opened—as using Daybreak to combine frontier models with Sophos’s own threat intelligence, response playbooks, and security expertise. The aim, in OpenAI’s wording, is to scale Sophos expertise across customers rather than to hand analysts “another tool.”
The page centres Sophos Fusion, described as Sophos’s AI-native cyber defense system that includes Managed Detection and Response. Sensors from “more than 500 third-party integrations” plus Sophos products are said to generate “trillions of events every day,” distilled into “roughly 1,000 to 2,000 cases” for nine security operations centres. Those volume lines are OpenAI’s restatement of Sophos’s operating picture.
This is a defensive-operations automation story, not a malware-attribution report. For a same-week reminder that agent actions on real networks can go wrong, see our coverage of Anthropic’s Philadelphia false-tip disclosure—a different vendor, different failure mode, useful as governance contrast rather than a rebuttal of Sophos’s metrics.
How do the Daybreak agents work, on the vendors’ account?
OpenAI describes an investigation agent that gathers customer context, detections, indicators of compromise, and relevant threat intelligence. A planning model then runs a plan–execute–review loop: build an investigation plan, complete steps, and produce a summary with recommended response actions for analysts. Other agents “can carry out parts of the response.”
Sophos’s MDR blog (Elvis Hovor) describes two production-grade agents designed in-house and refined with MDR analysts. The Triage Agent activates on new detections, correlates signals, flags benign penetration-testing activity, deduplicates, and assigns severity; Sophos says that automated triage “reduces alert noise by more than 60%.” The Case Investigation Agent builds timelines, enriches IoCs, de-obfuscates command lines, iterates plans, and emits an explainable verdict with recommended actions; Sophos says it “reduces mean time to investigate by up to 50%."
Those Sophos blog percentages are not the same measurement as OpenAI’s 89-second / 52% lines. Keep them in separate columns: noise reduction and MTTInvestigate on Sophos’s blog; agent-handled response time and end-to-end AI resolution on OpenAI’s case study.

What do the 89-second and 52% figures actually measure?
OpenAI’s results block states an average response time of 89 seconds “for cases using AI agents,” a 96% reduction “in investigation time using OpenAI models,” and “52% of MDR cases resolved end-to-end by AI.” Peterson’s quoted baseline is a pre-Daybreak process averaging around 38 minutes, which he says was already “better than 96% of professional security operations centres.”
The important qualifier is in the noun phrase: “cases using AI agents.” The 89-second average is not defined on the page as the mean across every MDR case. Cases routed entirely to human judgement can sit outside that average. The 52% end-to-end figure is likewise Sophos’s classification of which cases agents may close “within boundaries calibrated by Sophos analysts.”
OpenAI’s page does not publish sample size, date range, case-mix, or the stopwatch definition of “response time” (first enrich? containment? ticket close?). Without those, outside parties cannot recompute the 96% reduction. Treat the arithmetic as Sophos’s internal KPI storytelling distributed through OpenAI.
Where do humans and customers still sit in the loop?
OpenAI lists three MDR operating modes that apply whether a person or an agent works the case: Notify (Sophos investigates and recommends; customer acts), Collaborate (joint work before action), and Authorise (Sophos may respond on the customer’s behalf). Peterson is quoted that anything Sophos is uncomfortable letting an agent handle “gets passed off for human judgement,” and that potentially destructive actions still need the right oversight.
That mode matrix is the buyer-control surface. A customer in Notify mode should not read “52% end-to-end by AI” as permission for unsupervised containment on their estate. Authorise mode customers still need an action-specific matrix for which response steps agents may take without an analyst—OpenAI’s page does not print that matrix.
If you are designing internal agent autonomy, pair vendor mode names with technical enforcement—sandboxing, approval gates, and runtime policy—not prompts alone. Our AI agent sandboxing explainer and GitHub Copilot local sandboxing GA note cover isolation layers that MDR vendors and platform teams still have to wire explicitly.

What should security leaders take—and leave?
Useful takeaways that do not depend on accepting the 96% headline: (1) investigation agents need customer context, IoCs, and threat intel in one plan–execute–review loop; (2) response agents should inherit the same customer-mode boundaries as humans; (3) measuring agent-handled subsets separately from human-only cases avoids mixing populations.
What to leave behind: assuming your SOC will match 89 seconds without Sophos’s playbooks, sensor fabric, and case routing; treating Daybreak as a publicly purchasable SKU without reading OpenAI’s programme terms; and equating “end-to-end by AI” with “no human ever looks.”
Peterson’s closing advice on the OpenAI page returns to fundamentals—patching, layered controls, MFA, segmentation—rather than to model brands. That sentence is the least glamorous and the most portable.
- Ask Sophos which case types enter the 89-second average and which are excluded.
- Map Notify / Collaborate / Authorise to your incident authority matrix.
- Demand action-level allowlists for any agent-driven containment.
- Track human-only MTTR beside agent-handled MTTR so the KPI cannot hide queueing.
What did we not verify?
We did not access Sophos MDR consoles, case management systems, or raw telemetry. We did not reproduce triage noise-reduction percentages, MTTInvestigate lifts, or end-to-end closure rates. We did not interview Peterson or OpenAI’s Daybreak team. Quotes and figures are from the OpenAI page and Sophos blog HTML we opened and hashed on 10 October 2026. No identifiable person’s photograph is used in this article’s imagery.
Common questions
Is the 89-second figure for every Sophos MDR case?
No. OpenAI’s page states average response time for cases using AI agents. Human-only cases can sit outside that average.
Did AiLookout reproduce the 96% reduction?
No. The 96% line compares Sophos’s ~38-minute baseline to the ~89-second agent-handled average as the vendors present them. We did not recompute it.
Does Daybreak remove human oversight?
Not on the pages we opened. OpenAI says destructive actions still need appropriate human oversight, and Sophos’s blog keeps analysts confirming findings.
What to remember
File the 9 October OpenAI–Sophos Daybreak story as a measured vendor case study: strong workflow detail, headline KPIs that apply to agent-handled subsets, and customer modes that still bound autonomy.
Sources & further reading
How this story was made
Written by Kristian Kostov with AI assistance and checked against the linked sources. Company performance claims are attributed to the company. Analysis reflects AiLookout’s interpretation; we have not independently tested the products discussed. Cover photography is illustrative and does not depict the specific announcement or product.
Our editorial standards





