Sophos integrates OpenAI's cyber models into frontline defence with Exploit Path Verification

Sophos is developing Exploit Path Verification (EPV), a new feature within its Managed Risk service, to help defenders identify genuine vulnerabilities by leveraging OpenAI’s advanced cyber models amid the push for AI-driven infrastructure security.

OpenAI’s push to put advanced cyber models into mainstream defensive tooling has moved from partner recruitment to frontline deployment, and Sophos is one of the companies trying to turn that shift into a practical product. As OpenAI rolls out $1 billion of subsidised Daybreak access, training and support for under-resourced defenders, Sophos is building Exploit Path Verification, or EPV, into its Managed Risk service to show which weaknesses can actually be reached in a customer’s environment rather than leaving teams to work from generic severity ratings alone. OpenAI says more than 35 partner products and partner-operated services are now being announced through the Daybreak Defense Network, and Sophos has not yet given dates for early access or general availability of EPV. (openai.com)

Sophos says EPV is being designed to examine factors such as patch status, network reachability, identity privileges, endpoint controls and known exploit availability before assigning one of four results: “Confirmed Exploitable”, “Blocked by a Control”, “Not Reachable” or “Insufficient Evidence”. The company also says the feature is meant to catch chained attack routes in which several lower-priority findings combine into a viable breach path, and to produce remediation text that can be passed into a ticketing workflow. That fits closely with the role OpenAI described for GPT‑5.6‑Cyber in August, when BleepingComputer reported that the model family was intended to help defenders judge exploitability, identify affected systems, develop fixes and support the move of those fixes into production. (globenewswire.com)

The operating model matters nearly as much as the feature list. Help Net Security and BleepingComputer reported in August that Daybreak keeps direct control of the underlying cyber models with approved partners rather than handing them to end customers. In that structure, Daybreak Blue is aimed at broad defensive work, while Daybreak Red is reserved for more specialised and tightly governed tasks such as exploit validation, penetration testing and red teaming. OpenAI’s own description says Blue is built around GPT‑5.6 Sol, while Red provides access to the purpose-trained GPT‑5.6‑Cyber model. In practice, that means Sophos customers are not being given a raw cyber model to operate themselves; they are receiving conclusions, remediation guidance and analyst-reviewed output through an existing managed service. (helpnetsecurity.com)

That arrangement follows the broader expansion of Daybreak earlier this year. In June, OpenAI widened the programme from vulnerability discovery into validation, patching and deployment, and IT Pro reported that partners including Accenture, Check Point, Cisco, CrowdStrike and IBM were part of that earlier phase. The same report said OpenAI had tuned its models to discover and generate patches for critical weaknesses in browsers, network infrastructure, FreeBSD and the Linux kernel. Sophos joined the partner scheme that month, saying it planned to apply those capabilities across products and services used to protect more than 625,000 organisations worldwide. (itpro.com)

By 10 August, OpenAI had expanded the named roster to 16 companies, according to Help Net Security, with nine security and services firms and seven technology partners, including Sophos. Milan Patel, Sophos’s global head of MDR services, told the publication that the model was about delivering “frontier-grade defense at scale to organizations unable to deploy these models on their own”. Help Net Security also reported that engagement controls could include identity verification, defined testing scopes, logging, monitoring and human oversight. OpenAI subsequently tightened its own controls further, saying Daybreak accounts would be required to use hardware security keys from 1 September 2026. (helpnetsecurity.com)

The timing of the Sophos announcement is therefore important. On 3 September, OpenAI broadened Daybreak again with Daybreak for Frontline Defenders, described by OpenAI and TechRadar as a pool of subsidised token credits plus training and technical assistance, targeted first at the United States and intended to be used over the next six months. The priority list includes water and wastewater operators, electricity providers, state and local government, community and regional banks, non-profits and open-source maintainers, with expansion to partner countries promised in the coming weeks. SecurityWeek noted, however, that OpenAI has not explained whether the subsidy is fixed per organisation, percentage-based or limited to particular services. (openai.com)

OpenAI’s public argument is that defenders have only a short period to use capable models before attackers industrialise them. Greg Brockman, OpenAI’s president, warned in remarks reported by The Register that the world could be heading towards a future where “critical infrastructure outages are just a way of life”. OpenAI said it has already convened utility participants from 40 states and the District of Columbia that collectively serve more than half of the US population, and it is launching a pilot with the Multi-State Information Sharing and Analysis Center to train state, local, tribal and territorial defenders, beginning with public-sector and water-system teams. OpenAI also says Daybreak is already being used by thousands of defenders across 2,000 approved organisations and workspaces. (theregister.com)

There is still a clear note of caution around the funding drive. Tatyana Bolton, cybersecurity lead at Monument Advocacy, told The Register that “AI in (operational technology) OT is inevitable”, but added that “software credits alone will not solve the underlying challenges” in environments defined by ageing equipment, scarce engineering resources and resistance to rapid operational change. That is where Sophos’s EPV pitch becomes more credible than a simple model-access story. If it works as described, the feature could help customers decide which exposures are genuinely usable by an attacker and which are already blocked by controls, while leaving human analysts inside the review loop. What it does not yet offer is a shipping date. (theregister.com)

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.