cd /news/artificial-intelligence/sophos-puts-openai-models-to-work · home topics artificial-intelligence article
[ARTICLE · art-125869] src=itdaily.com ↗ pub= topic=artificial-intelligence verified=true sentiment=· neutral

Sophos puts OpenAI models to work

Sophos is expanding its Managed Risk service with Exploit Path Verification, a new feature that uses OpenAI's GPT cyber models to determine which vulnerabilities attackers can actually exploit, the company said. The system combines real-time data on assets, patch status, network access, and known exploits to prioritize remediation, and Sophos analysts review every AI assessment before customers receive it, with each report explicitly marked as AI-generated. Sophos joined the OpenAI Daybreak Defense Network in June and will announce the rollout timing for business customers within the Managed Risk portfolio at a later date.

by read2 min views2 publishedSep 10, 2026
Sophos puts OpenAI models to work
Image: Itdaily (auto-discovered)

Sophos is expanding its Managed Risk service with a new feature that analyzes vulnerabilities using OpenAI cyber models. The technology is designed to help security teams prioritize endless lists of vulnerabilities, although caution with AI models remains necessary.

Sophos integrates OpenAI’s GPT cyber models into its Managed Risk platform to determine which vulnerabilities attackers can actually exploit. Security teams today face an ever-widening gap between the number of detected vulnerabilities and the time available to resolve them.

Traditional scanners map out thousands of weaknesses and assign them general risk scores. However, these scores rarely account for specific security measures or actual network accessibility within a corporate environment. As a result, organizations waste valuable time patching holes that are not even accessible to attackers.

With Exploit Path Verification, Sophos aims to bridge that gap. The system combines real-time data on assets, patch status, network access, and known exploits to establish well-founded priorities and formulate remediation advice.

Assessment with human oversight #

The technology categorizes vulnerabilities based on exploitability. Additionally, the system recognizes linked attack paths, where multiple minor vulnerabilities together form a single exploitable route. It can also verify whether a measure truly stops an attack technique or merely blocks a public test attack. Sophos explicitly positions the tool as an advisory addition, where the company’s internal analysts review the AI assessments before customers receive them.

This human intervention is not an unnecessary luxury given recent security incidents involving OpenAI’s AI models. Not only do OpenAI’s models repeatedly deviate from expected behavior, but large language models generally remain susceptible to manipulation via prompt injections. By explicitly marking every report as AI-generated and keeping the underlying evidence transparent, Sophos attempts to prevent incorrect AI reasoning from being followed blindly in security management.

Balance between automation and risk #

The integration stems from the OpenAI Daybreak Defense Network, which Sophos joined in June. The goal is to safely deploy advanced reasoning capabilities in MDR investigations. Nevertheless, the application of external AI models in critical IT environments remains a delicate balance. Still, models from major AI companies are increasingly finding their way into security solutions. Cloudera announced yesterday that it will be collaborating with Mistral.

Sophos intends to make Exploit Path Verification available to business customers within the Managed Risk portfolio soon. The company will announce the exact timing for the rollout at a later date.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @sophos 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/sophos-puts-openai-m…] indexed:0 read:2min 2026-09-10 ·