Evidence at a glance
Behind the Speedup Is a Case-Filtering System
On October 9, 2026, OpenAI published a case study describing how Sophos uses Daybreak models in Sophos Fusion, its cyber defense system for managed detection and response (MDR). The workflow addresses a practical load: Sophos says Fusion combines data from its own products and more than 500 third-party integrations, collecting trillions of sensor events a day and filtering them into roughly 1,000 to 2,000 cases for investigation across nine security operations centers. This is not a model made available for customers to query on their own. It is embedded in a defense workflow managed by Sophos.
Sophos says the average response time for cases using agents fell from about 38 minutes to 89 seconds, and that AI resolves 52% of MDR cases end to end. The point is not to treat these figures as a general promise that AI makes security work faster. It is to understand where they sit in the pipeline: Fusion does not hand every raw event directly to a model. It first reduces events to cases, then agents perform some of the investigation and response work. Automation is being applied not just to an analyst’s recommendation, but to selected casework within defined limits.
Agents Take On a Workflow With Checkpoints
In OpenAI’s description, an investigation agent first gathers customer context, detection results, indicators of compromise (IoCs), and relevant threat intelligence. A planning model then runs a plan-execute-review process: it creates an investigation plan, completes the steps, and prepares a summary with recommended response actions for an analyst to review. Other agents can carry out parts of the response. The division of work separates evidence gathering, investigation, and proposed action rather than asking one agent to pursue a vague goal from start to finish.
The practical value may be that Sophos can apply its accumulated expertise and response procedures repeatedly across more cases. Sophos says it protects more than 625,000 organizations and has four decades of cybersecurity experience. At that scale, service capacity need not grow only by adding scarce security analysts; compute and standardized procedures can also be scaled. But the published material does not explain how each task is judged complete, how agents handle disagreements, or where analysts intervene case by case. A workflow description is not, by itself, proof of reliability.
Permission Modes Carry Customer Control Into Automation
Sophos MDR offers three modes of customer involvement. In Notify, Sophos investigates and recommends a response, but the customer acts. In Collaborate, Sophos and the customer coordinate before taking action. In Authorise, Sophos can respond on the customer’s behalf after receiving permission. The case study says these boundaries apply to both people and agents: actions that could cause damage require appropriate human oversight, and work an agent should not handle is passed to a person for judgment.
This shifts the central automation question from “Can the model perform this action?” to “Under what authorization may it perform it?” Notification, collaboration, and delegated response carry different levels of risk. Once an agent can change a customer’s environment, permissions and handoff conditions need to be part of the system design, not left to prompts or retrospective review. When Sophos announced in June 2026 that it was joining the Daybreak partner program, it also said the models would be introduced to defense workflows in stages, with analysts and controls involved rather than direct customer access.
One public description remains unclear: 52% of cases are said to be resolved end to end by AI, while the case study also emphasizes analyst-defined boundaries and service-level oversight. Sophos’s service description characterizes those cases as requiring no human intervention. These statements may refer respectively to whether a person handles an individual case and to governance at the service level, but the available material does not define the distinction. In de
The 96% Figure Has a Specific Scope
“A 96% reduction in investigation time” is the headline claim, but the direct comparison in the case study is an average of about 38 minutes in the previous process versus about 89 seconds in response time for cases using agents. Calculating from those rounded figures gives a reduction of roughly 96.1%. Yet the headline refers to investigation time while the body describes response time, and the published material does not say whether the start and end points are identical. More importantly, 89 seconds applies to cases using agents, not to all MDR cases.
The case study does not publish the measurement period, sample size, distribution of case types, control group, or an independent audit. The figures therefore show that Sophos reports a substantial process speedup and give technical leaders a basis for asking about automation coverage. They do not establish that accuracy, missed detections, or the risk of mistaken actions improved as well. Sophos also says its previous process performed better than 96% of professional security operations centers. That provides context for the old baseline, but remains a company statement in the case study, not a substitute for a like-for-like evaluation of the new workflow.
Define Action Boundaries Before Chasing Coverage
For security leaders building a similar system, a safer starting point is not to maximize the number of cases handed to a model. It is to break mature, repetitive investigations into tasks with defined inputs, expected outputs, and review points, then specify which response actions may run automatically. Permission levels like Notify, Collaborate, and Authorise offer a framework for discussion, but each action still needs a named authority, conditions for human takeover, and clear responsibility when something goes wrong. The case supports this approach to boundary-setting; it does not publish a universal set of rules.
Evaluation should then separate speed from quality. Track which cases enter the agent workflow, when the clock starts, what counts as a completed response, and how often people take over. The Sophos case provides coverage and speed figures, but not accuracy, error rates, or independent validation. Those omissions matter when deciding whether automation can safely expand. Daybreak’s reported change is not that analysts have left the process. Their expertise is being extended through constrained workflows, and further expansion will depend on which judgments a team is willing and able to delegate.