Sophos says AI agents bring some cyber responses down to 89 seconds
A new case study describes faster security work within human-set limits. Customers should ask which cases qualify, what the clock measures and who handles mistakes.
- Maturity
- Deployed, stage 4 of 4
- Support
- 2 sources · institution
- Evidence detail
- How we know ↓

An AI security agent that responds in under two minutes sounds useful. A customer also needs to know what it was allowed to do, and who takes over when it is uncertain.
A new OpenAI case study, published October 9, says Sophos’s AI agents have reduced average response time for the cases they handle to about 89 seconds, compared with roughly 38 minutes in its previous process. The average applies to agent-handled cases, rather than every threat Sophos encounters.
Sophos also reports that AI resolves 52% of its managed detection and response cases end-to-end. MDR is an outsourced service that investigates suspicious activity and helps organizations respond. Sophos’s existing partnership article is dated August 10 and currently contains these figures. That date does not establish when the numbers were added. The October 9 publication describes ongoing work, rather than announcing a new rollout.
What the agents actually do
The case study describes agents gathering customer context and threat intelligence, developing and executing an investigation plan, and preparing findings and recommended responses. Other agents can perform parts of the response.
For a small organization, the potential benefit is having more of this work done while its own staff are busy or unavailable. Shortening the gap between an alert and an informed decision could help defenders act sooner and leave people more time for complicated cases.
The permissions remain important. Sophos says customers can choose recommendations only, collaboration before action, or authorized direct response. Agents operate within analyst-calibrated boundaries; potentially destructive actions require human oversight.
Before choosing a service, a customer should be able to understand what can happen automatically and who is accountable if that action interrupts their work.
Three questions behind the headline
Which cases qualify? Ask whether the automated cases resemble the threats your organization faces, and how much work remains for people. The percentage alone cannot describe the difficulty of the remaining cases.
What does the clock measure? Ask when timing starts and stops, how older and newer cases were compared, and how long the slowest serious cases take. An average can hide the cases that matter most.
What happens when it is wrong? Ask for mistaken-action rates, missed threats, escalation times and a recovery process. Speed and decision quality belong in the same conversation.
The published accounts do not supply an evaluation period, sample size, error rates or independent audit for these figures. They do not establish fewer breaches. Bright has not tested the system.
Read our related report on Anthropic’s Cyber Mission and its plans to support defenders of essential services.
Follow useful AI developments with Bright Weekly: five source-checked stories and one useful thing to try, free each week.
How we know2 sources · checked 2026-10-09 · no corrections
Original sources
- Sophos cuts threat investigation time by 96% with OpenAI Daybreak · OpenAI ↗ · institution
- Sophos working with OpenAI · Sophos ↗ · institution
Institutions: Sophos · OpenAI
- Maturity
- Deployed
- Source published
- 2026-10-09
- Captured
- 2026-10-09
- Last source review
- 2026-10-09
- Editorial method
- AI-assisted source review
- Place / relevance
- Organizations using Sophos security services · unspecified
Bright compared this account with the linked original and supporting sources and kept reported, budgeted, projected, and observed claims distinct. Bright did not independently audit the underlying records.
Maturity describes the tested or operational setting. Confidence describes support for the particular claim; one does not determine the other.
Revision & correction history
2026-10-09T17:15:00.106Z · Source-checked explainer of the October 9 Sophos case study, preserving company attribution, denominators, human permission boundaries and evaluation limits.
No corrections recorded.
Keep exploring
Explore the shared question in another setting. These connections do not imply replication.
