Skip to content

openai

Sophos lets Daybreak agents close 52% of MDR cases

Promtime

At Sophos, an average security event now gets a response in 89 seconds instead of roughly 38 minutes, according to reports on the case, and AI agents resolve more than half of its managed detection and response cases end to end. The core claim comes from OpenAI's customer story on Sophos, which credits OpenAI's Daybreak cyber program with a 96% cut in investigation time.

At a glance

  • Human analysts at Sophos keep control over consequential actions, so the Daybreak agents work cases end to end while the decisions that carry weight still go to a person.
  • OpenAI puts the reduction in investigation time at 96%, and reports translate that into average security event response time falling from approximately 38 minutes to 89 seconds.
  • Both percentages are OpenAI's own figures from a customer story, the minute counts appear only in secondary reports, and the published summary does not explain how cases were counted or over what period.

If you have not been following, Daybreak is OpenAI's program for cyber defenders. According to Unite.AI, OpenAI launched it earlier in 2026 so that verified public- and private-sector defenders could use advanced AI for authorized cyber defense. AIToolly, citing TechCrunch, reports that in August 2026 OpenAI added a model trained specifically for cybersecurity, framed as a response to the multiplication of AI-led attacks. The same program was recently opened to Ukraine's civilian defense.

Daybreak agents resolve 52% of Sophos's MDR cases end to end

MDR stands for managed detection and response: a security vendor watches a customer's systems, triages the alerts and acts on the ones that turn out to be real. Every alert that looks serious becomes a case, and traditionally an analyst works through each one by hand.

According to OpenAI, agents built on Daybreak now resolve 52% of Sophos's MDR cases end to end. In plain terms, the agent carries such a case from the opening alert through to its resolution, instead of passing a half-finished summary to a person.

The arrangement has a fixed boundary. Human analysts retain control over consequential actions, so a person still signs off on the steps that carry real weight. OpenAI presents the result as automation with human oversight preserved, not as analysts being taken out of the loop.

Average response time fell from about 38 minutes to 89 seconds

OpenAI's headline number is a 96% reduction in the time it takes to investigate a cyber threat. Reports covering the case put concrete figures on it: Sophos's average security event response time fell from approximately 38 minutes to 89 seconds. Those minute counts appear in secondary reports rather than in OpenAI's own summary.

The two sets of numbers agree with each other. Eighty-nine seconds is a little under 4% of 38 minutes, which matches a 96% cut. They are named differently, though: OpenAI speaks of investigation time, while the reports describe response time to a security event, and the summary does not say whether the two are the same measure.

Who else is getting access to Daybreak?

Sophos is one customer among many. According to OpenAI, as cited by Unite.AI, thousands of defenders across 2,000 approved organizations and workspaces already use Daybreak, including cybersecurity companies, defense organizations and law enforcement organizations.

Unite.AI also reports that on September 3, 2026 OpenAI introduced Daybreak for Frontline Defenders, committing $1 billion in subsidized access to Daybreak models, training, technical support and partnerships, alongside a pilot with MS-ISAC.

According to the same outlet, Daybreak for America prioritizes operators of essential services such as water and wastewater and the electric grid, along with state and local governments, community and regional banks, nonprofits, open-source maintainers and other organizations with limited security resources.

What sits underneath the agents Sophos runs?

According to Unite.AI, OpenAI's program page describes Daybreak as a governed cyber defense stack: frontier models paired with a coding harness, security tooling, trusted workflows and ecosystem partners. Access comes in two tiers. Daybreak Blue covers common defensive work with OpenAI's mainline models, while Daybreak Red gives approved organizations specialized cyber models for more sensitive and technically demanding work.

Unite.AI describes the agents' job as a loop: take inventory, discover problems, validate them dynamically, assign an owner, then carry out verified remediation. People review consequential changes and independently verify deployed fixes. AIToolly, citing TechCrunch, describes the cyber-trained model as fine-tuned for the nuances of security tasks and serving as the backbone for threat detection and defensive operations.

Think of a hospital emergency room. A triage team sees every incoming patient, runs the standard checks and sends the routine cases home, while anything that needs surgery goes to a doctor who makes the call. Sophos's figures describe agents doing the triage and a good share of the treatment, with the surgical decisions left to analysts.

All the headline figures come from OpenAI's customer story about a company using OpenAI's own product. The summary does not say what period they cover, which Daybreak tier Sophos runs, or what kinds of cases make up the automated 52%. In our view, that share is a more useful number than the 96%, because it measures how much of the workload agents actually finish, not just how fast they move.

Six months of subsidized Daybreak

According to Unite.AI, the subsidized access under Daybreak for Frontline Defenders is meant to be used up over the next six months, and OpenAI said it intends to extend the model to partner countries in the coming weeks. Whether organizations with much smaller security teams than Sophos get anywhere near 89 seconds remains an open question. No follow-up figures for Sophos have been given.

Related stories

  1. Codex Security Cloud reviews commits with the laptop closed
  2. OpenAI opens Daybreak to Ukraine's civilian cyber defense
  3. Defense Factory sets out OpenAI's defender playbook
  4. OpenAI's Daybreak Red and Blue land in Amazon Bedrock
  5. OpenAI says fired safety trio broke sensitive-info rules
  6. Guardian: AI helped write OpenAI's hack email to Australia

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.