# Sophos puts OpenAI models to work

> Source: <https://itdaily.com/news/security/sophos-openai/>
> Published: 2026-09-10 13:51:14+00:00

**Sophos is expanding its Managed Risk service with a new feature that analyzes vulnerabilities using OpenAI cyber models. The technology is designed to help security teams prioritize endless lists of vulnerabilities, although caution with AI models remains necessary.**

Sophos integrates OpenAI’s GPT cyber models into its Managed Risk platform to determine which vulnerabilities attackers can actually exploit. Security teams today face an ever-widening gap between the number of detected vulnerabilities and the time available to resolve them.

Traditional scanners map out thousands of weaknesses and assign them general risk scores. However, these scores rarely account for specific security measures or actual network accessibility within a corporate environment. As a result, organizations waste valuable time patching holes that are not even accessible to attackers.

With Exploit Path Verification, Sophos aims to bridge that gap. The system combines real-time data on assets, patch status, network access, and known exploits to establish well-founded priorities and formulate remediation advice.

## Assessment with human oversight

The technology categorizes vulnerabilities based on exploitability. Additionally, the system recognizes linked attack paths, where multiple minor vulnerabilities together form a single exploitable route. It can also verify whether a measure truly stops an attack technique or merely blocks a public test attack. Sophos explicitly positions the tool as an advisory addition, where the company’s internal analysts review the AI assessments before customers receive them.

This human intervention is not an unnecessary luxury given recent [security incidents](https://itdaily.com/news/security/openai-hijacking-german-wiki/) involving OpenAI’s AI models. Not only do OpenAI’s models repeatedly deviate from expected behavior, but large language models generally remain susceptible to manipulation via prompt injections. By explicitly marking every report as AI-generated and keeping the underlying evidence transparent, Sophos attempts to prevent incorrect AI reasoning from being followed blindly in security management.

## Balance between automation and risk

The integration stems from the OpenAI Daybreak Defense Network, which Sophos joined in June. The goal is to safely deploy advanced reasoning capabilities in MDR investigations. Nevertheless, the application of external AI models in critical IT environments remains a delicate balance. Still, models from major AI companies are increasingly finding their way into security solutions. Cloudera [announced](https://siliconangle.com/2026/09/09/cloudera-brings-mistral-ais-frontier-models-into-its-secure-hybrid-data-environments/) yesterday that it will be collaborating with Mistral. 

Sophos intends to make Exploit Path Verification available to business customers within the Managed Risk portfolio soon. The company will announce the exact timing for the rollout at a later date.
