Sophos says OpenAI’s Daybreak cut its threat investigation time by 96%
In a customer story published by OpenAI, cybersecurity firm Sophos reports using OpenAI’s Daybreak to cut cyber-threat investigation time by 96% and to automate 52% of cases in its managed detection and response (MDR) service, while keeping human analysts in the loop.
OpenAIOriginally published 1 min
Why it matters
Security operations centres are a natural fit for AI agents: high alert volumes, repetitive triage and a shortage of analysts. The figures come from a vendor case study rather than an independent evaluation, but they show how far security providers are pushing automation into frontline investigation work.
For business & IT
When evaluating AI-assisted security services, ask providers which case types are fully automated, how escalation to humans works, and how automated decisions are audited.
A study reported by Ars Technica finds that the productivity gains from AI coding agents are largely “absorbed” downstream: developers generate more code, but human code review becomes the bottleneck, so the amount of software actually shipped does not grow accordingly.
An opinion piece in CIO argues that enterprise AI pilots impress in the sandbox but break down once they touch real, regulated business processes. It cites Gartner’s projection that more than 40% of agentic AI initiatives will be cancelled by the end of 2027, and makes the case that governed context — controlled, trustworthy business data and rules supplied to agents — is what allows them to scale.
A new category of small, specialized decision models is emerging to handle the bounded choices an agent makes between reasoning and acting. InfoWorld points to TypeSafe’s Jev, Cloudflare’s Clef, AWS’s Strands Decider and OpenAI’s Decisions API as recent examples, all pitched as a way to cut latency and inference costs.