# Sophos says AI agents bring some cyber responses down to 89 seconds

Agent contract: 1.2.0

A new case study describes faster security work within human-set limits. Customers should ask which cases qualify, what the clock measures and who handles mistakes.

Canonical: https://brightaifuture.com/discoveries/sophos-ai-cyber-response-89-seconds
Format: discovery
Source publication: 2026-10-09
Bright publication: 2026-10-09
Substantive update: None recorded
Evidence and review: Deployed; confidence: unassessed; approved; ai-assisted. Primary company sources and archival image rights checked. Published as a case-study explainer; company-reported metrics and missing independent security outcomes are explicitly labeled. No claim of a new rollout or last-hour release.

## Editorial image

A row of black server cabinets with computer equipment and yellow cables in a data center.: https://brightaifuture.com/media/content/43b44ed9e6e73291f8425ed2f49ddba30e8ff2faf3a6b994752041b285a274cf.jpg

Credit: Server racks in an archival photograph. Contextual image; it does not show a Sophos installation, customer or cyber incident. Photo: Wil Weterings / Wikimedia Commons (public domain).. License: Public domain dedication by copyright holder.

Source: https://commons.wikimedia.org/wiki/File:Datacenter.jpg

contextual; not a Sophos installation, customer or cyber incident.

## The story

An AI security agent that responds in under two minutes sounds useful. A customer also needs to know what it was allowed to do, and who takes over when it is uncertain.

A new [OpenAI case study, published October 9](https://openai.com/index/sophos/), says Sophos’s AI agents have reduced average response time for the cases they handle to about 89 seconds, compared with roughly 38 minutes in its previous process. The average applies to agent-handled cases, rather than every threat Sophos encounters.

Sophos also reports that AI resolves 52% of its managed detection and response cases end-to-end. MDR is an outsourced service that investigates suspicious activity and helps organizations respond. [Sophos’s existing partnership article](https://www.sophos.com/en-us/blog/sophos-working-with-openai) is dated August 10 and currently contains these figures. That date does not establish when the numbers were added. The October 9 publication describes ongoing work, rather than announcing a new rollout.

## What the agents actually do

The case study describes agents gathering customer context and threat intelligence, developing and executing an investigation plan, and preparing findings and recommended responses. Other agents can perform parts of the response.

For a small organization, the potential benefit is having more of this work done while its own staff are busy or unavailable. Shortening the gap between an alert and an informed decision could help defenders act sooner and leave people more time for complicated cases.

The permissions remain important. Sophos says customers can choose recommendations only, collaboration before action, or authorized direct response. Agents operate within analyst-calibrated boundaries; potentially destructive actions require human oversight.

Before choosing a service, a customer should be able to understand what can happen automatically and who is accountable if that action interrupts their work.

## Three questions behind the headline

Which cases qualify? Ask whether the automated cases resemble the threats your organization faces, and how much work remains for people. The percentage alone cannot describe the difficulty of the remaining cases.

What does the clock measure? Ask when timing starts and stops, how older and newer cases were compared, and how long the slowest serious cases take. An average can hide the cases that matter most.

What happens when it is wrong? Ask for mistaken-action rates, missed threats, escalation times and a recovery process. Speed and decision quality belong in the same conversation.

The published accounts do not supply an evaluation period, sample size, error rates or independent audit for these figures. They do not establish fewer breaches. Bright has not tested the system.

Read our related [report on Anthropic’s Cyber Mission](https://brightaifuture.com/discoveries/anthropic-cyber-mission-power-water) and its plans to support defenders of essential services.

Follow useful AI developments with [Bright Weekly](https://brightaifuture.com/newsletter): five source-checked stories and one useful thing to try, free each week.

## Provenance and history

{
  "dates": {
    "captureDate": "2026-10-09",
    "eventDate": null,
    "lastReviewedDate": "2026-10-09",
    "publicationDate": "2026-10-09"
  },
  "provenance": {
    "origin": "editorial",
    "externalId": "https://openai.com/index/sophos/"
  },
  "revisions": [
    {
      "id": "revision:sophos-first-publication",
      "recordedAt": "2026-10-09",
      "sourceIds": [
        "source:openai-sophos-case-study",
        "source:sophos-working-with-openai"
      ],
      "summary": "Source-checked explainer of the October 9 Sophos case study, preserving company attribution, denominators, human permission boundaries and evaluation limits."
    }
  ],
  "corrections": []
}

## Original sources

- [Sophos cuts threat investigation time by 96% with OpenAI Daybreak · OpenAI](https://openai.com/index/sophos/)
- [Sophos working with OpenAI · Sophos](https://www.sophos.com/en-us/blog/sophos-working-with-openai)

## Continue exploring

- [Anthropic brings AI and engineers to the teams protecting power and water](https://brightaifuture.com/discoveries/anthropic-cyber-mission-power-water)
