Oct 9 edition/Reporting & analysis
AgentsBusinessSafetyModels

AgentsAutonomy & tool use

Sophos says agents built on OpenAI Daybreak now resolve 52% of its MDR cases

Sophos says AI agents built on OpenAI's Daybreak models close about half of its managed detection and response cases end to end. For those cases, average response time fell from about 38 minutes to 89 seconds, and humans still approve sensitive actions.

THE CORE IDEAS3 TAKEAWAYS
01

Sophos reports that agents resolve 52% of its MDR cases end to end. For the cases the agents handle, average response time dropped from about 38 minutes to 89 seconds, a 96% cut. That figure leaves out cases that still need analysts, so it overstates the gain across all cases. Both numbers come from Sophos and OpenAI and have not been independently checked. [1] [2] [3] [5]

02

Sophos describes a layered design. An investigation agent first gathers customer context, detections, indicators of compromise and threat intelligence. A planning model then runs a plan–execute–review loop and gives analysts a summary with recommended actions. Each customer sets how much the agents may do on their own through Notify, Collaborate or Authorize modes. Potentially destructive actions still need a human to approve them. [2] [3]

03

Daybreak now has two access tiers. Blue gives defenders GPT-5.6 Sol, which still refuses highly dual-use requests. Red adds cyber-tuned models that refuse fewer high-risk security tasks. Sophos's CTO refers only to 'Daybreak models', so it is unclear which version runs the MDR agents. [2] [6] [7] [8]

WHY IT MATTERS

a large MDR provider reports agents closing about half its cases much faster. Implication: buyers should judge agent triage by share of cases closed, wrong closures and human overrides, not average speed.

Read the full assessment

Providers may compete on how they package the same models.

Executive brief

Sophos says AI agents built on OpenAI's Daybreak models now resolve 52% of its managed detection and response (MDR) cases end to end. It also says the average response time for cases handled by those agents fell from about 38 minutes to 89 seconds, a 96% cut (FourWeekMBA). Both figures come from an OpenAI customer story and Sophos's own press release. No independent party has checked them. The 89-second number covers only cases the agents handled, not every case. According to Sophos, people still approve the most sensitive actions (Superpowerdaily).

What changed and event timeline

  1. Sophos joins Daybreak's partner program

    Sophos said it would build OpenAI's frontier models into its Endpoint, MDR and Advisory Services products ().

  2. OpenAI launches Daybreak

    A cybersecurity program that uses OpenAI's models and Codex agents to find and fix vulnerabilities. Cloudflare, Cisco, CrowdStrike, Oracle and Zscaler were named as early users ().

  3. Two access tiers and a new cyber model

    Daybreak Blue gives defenders access to GPT-5.6 Sol. Daybreak Red adds GPT-5.6-Cyber, a model trained for vulnerability research and testing whether exploits work (;).

  4. OpenAI publishes the Sophos case study

    It reports a 96% cut in investigation time and 52% of MDR cases automated, with humans still overseeing the work (;).

Capabilities and access

  • Daybreak Blue: GPT-5.6 Sol for defensive work such as code review, malware analysis and incident response. It still refuses highly dual-use requests (Infosecurity Magazine).
  • Daybreak Red: GPT-5.6-Cyber and GPT-5.5-Cyber, which refuse fewer high-risk security tasks (Engadget).
  • Codex Security is the agent framework Daybreak runs on (Contrast Security). Qualified organizations apply for access (OpenAI Help).
Read the full section
  • Daybreak Blue: GPT-5.6 Sol for defensive work such as code review, malware analysis and incident response. It still refuses highly dual-use requests (Infosecurity Magazine).
  • Daybreak Red: GPT-5.6-Cyber and GPT-5.5-Cyber, which refuse fewer high-risk security tasks (Engadget).
  • Codex Security is the agent framework Daybreak runs on (Contrast Security). Qualified organizations apply for access (OpenAI Help).
  • The reviewed coverage does not say which model version runs Sophos's MDR agents. Sophos's CTO refers only to "Daybreak models" (FourWeekMBA).

Technical analysis for researchers and developers

  • Pipeline: Sophos turns trillions of daily events into 1,000–2,000 cases, handled across nine security operations centers (FourWeekMBA).
  • Agents: An investigation agent collects customer context, detections, indicators of compromise and threat intelligence. Other agents handle parts of the response (Superpowerdaily).
  • Permissions: Each customer chooses how much the agents may do on its own, using Notify, Collaborate or Authorize modes (FourWeekMBA).
Read the full section
  • Pipeline: Sophos turns trillions of daily events into 1,000–2,000 cases, handled across nine security operations centers (FourWeekMBA).
  • Agents: An investigation agent collects customer context, detections, indicators of compromise and threat intelligence. A planning model then runs a plan–execute–review loop and produces a summary with recommended actions for analysts. Other agents handle parts of the response (Superpowerdaily).
  • Permissions: Each customer chooses how much the agents may do on its own, using Notify, Collaborate or Authorize modes (FourWeekMBA).
  • Reproducibility: The sources give no evaluation protocol, error rates or false-resolution rates.

Claims and evidence

  • Response time fell from about 38 minutes to 89 seconds (96%), for agent-handled cases only. This is a vendor figure (FourWeekMBA).
  • 52% of MDR cases are resolved end to end by AI (Sophos press release).
  • GPT-5.6-Cyber completed 95% of sensitive tasks, compared with 1.5% for GPT-5.6 Sol and 57.3% for GPT-5.5-Cyber. These are OpenAI's own numbers (Infosecurity Magazine).
Read the full section
  • Response time fell from about 38 minutes to 89 seconds (96%), for agent-handled cases only. This is a vendor figure (FourWeekMBA).
  • 52% of MDR cases are resolved end to end by AI (Sophos press release).
  • GPT-5.6-Cyber completed 95% of sensitive tasks, compared with 1.5% for GPT-5.6 Sol and 57.3% for GPT-5.5-Cyber. These are OpenAI's own numbers (Infosecurity Magazine).
  • None of these figures has been independently confirmed.

Context and prior work

  • Sophos reports about 625,000 customer organizations and about 40,000 MDR customers. It is also adding OpenAI's cyber models to a Managed Risk feature called Exploit Path Verification.
  • CIO Dive presents Daybreak as OpenAI's competitive answer to Anthropic's Mythos model (CIO Dive).
Read the full section
  • Sophos reports about 625,000 customer organizations and about 40,000 MDR customers. It is also adding OpenAI's cyber models to a Managed Risk feature called Exploit Path Verification. That feature labels each vulnerability as Confirmed Exploitable, Blocked by a Control, Not Reachable or Insufficient Evidence (Sophos EPV release).
  • CIO Dive presents Daybreak as OpenAI's competitive answer to Anthropic's Mythos model (CIO Dive).

Limitations, safety and contested findings

  • Because the 89-second figure leaves out cases that still need people, it overstates the improvement across all cases (Superpowerdaily).
  • Potentially destructive actions still need a human to approve them (Superpowerdaily).
  • Alex Goller of Illumio argues that model guardrails were never the main defense and that infrastructure controls such as zero trust matter more (Infosecurity Magazine).
Read the full section
  • Because the 89-second figure leaves out cases that still need people, it overstates the improvement across all cases (Superpowerdaily).
  • Potentially destructive actions still need a human to approve them (Superpowerdaily).
  • Alex Goller of Illumio argues that model guardrails were never the main defense and that infrastructure controls such as zero trust matter more (Infosecurity Magazine).
  • Gartner's John Watts expects Daybreak to add to existing security tools rather than replace them. Analysts also note that AI vendors make money from subscriptions and token use, which gives them an interest in promoting these tools (CIO Dive).

Business and practitioner implications

  • Buyers of managed security: Ask what share of cases the agents close, how often they close a case wrongly, and how often humans overrule them.
  • Builders: The design worth copying is the one Sophos describes: agents collect context first, then a plan–execute–review loop runs, with permissions each customer sets.
  • Security leaders: Forrester's Jeff Pollard recommends hands-on testing before committing (CIO Dive).
Read the full section
  • Buyers of managed security: Ask what share of cases the agents close, how often they close a case wrongly, and how often humans overrule them. Average speed alone is not enough.
  • Builders: The design worth copying is the one Sophos describes: agents collect context first, then a plan–execute–review loop runs, with permissions each customer sets.
  • Security leaders: Forrester's Jeff Pollard recommends hands-on testing before committing (CIO Dive).
  • Competition: Sophos says it gives customers these models only through its products, not as direct model access. Managed security providers may differentiate on how they wrap the models rather than on the models themselves (Sophos press release).
FOLLOW THE EVIDENCE

The source trail.

Sources (11)
A LITTLE LESS NOISE. A LOT MORE CONTEXT.

Stay curious.
Follow the evidence.

Independent perspectives, the original sources, and room for the questions that don't have easy answers.

How we build the brief
Connect with us

Find us where you already read.