The Sophos AI Security 2026 report, released last month, just showed us the current state of AI-enhanced cyberattacks: Timelines are accelerating from weeks into days. Defending against that speed requires more than access to advanced models. Organizations also need a system to operationalize those models into working defenses, and the reach to deliver that capability at scale.
Today, Sophos and OpenAI are announcing a partnership with OpenAI to bring OpenAI frontier models to the channel and service providers through Sophos Fusion, the industry's most complete AI-native cybersecurity defense system. By combining OpenAI’s model capabilities with deep knowledge across our customers’ environments, we intend to give partners a new way to deliver frontier AI security as one connected defense system, and to build recurring services on top of it.
Sophos has also been invited to join a new program that extends OpenAI’s Daybreak Cyber Partner Program for managed security services.
The three ways AI meets cybersecurity
Futurum Group’s Fernando Montenegro frames the relationship between AI and cybersecurity in three parts, and Sophos will have a focus on each of them with OpenAI:
- Security from AI: AI is accelerating the development of malicious tradecraft, vulnerability exploitation, and enabling threat actors to launch more attacks against more targets. Stopping these AI-enabled attacks is a core pillar of the Sophos defense system. For example:
- Sophos Endpoint blocks the techniques used to exploit vulnerabilities, so a novel, AI-discovered weakness meets the same wall as a known one.
- Our agentic SOC compresses detection, investigation, and response to match the speed AI hands attackers, with 52% of incidents resolved end-to-end by AI in an average of 89 seconds.
- Our researchers track adversarial AI use continuously, and what they find feeds directly back into both.
- AI for security: Fight fire with fire. We’ve been using AI in our solutions since 2017 and AI capabilities are embedded right across the Sophos portfolio. Plus, every threat the system encounters informs and improves the system as a whole. The OpenAI partnership has a goal of adding frontier model capability on top of a foundation that is already AI-native rather than bolting AI onto it.
- Security for AI: Organizations are standing up AI across their lines of business and need security guardrails along with it. This is where Sophos AI Defense fits, giving organizations visibility into AI and shadow AI use, enforcing policy, and helping govern how sensitive data is used across AI models and tools.
One connected defense system for the channel
Sophos Fusion is built on a single, open architecture where every control point operates as one, whether native to Sophos or a third-party integration. The partnership will extend that openness by bringing OpenAI frontier models into our defense system, which already connects endpoint, network, email, cloud, identity, and security operations while continuously compounding intelligence from every threat it encounters.
Many managed service providers (MSPs) and managed security service providers (MSSPs) are uniquely positioned to turn frontier cyber capabilities into practical security outcomes because they understand their customers’ environments and already operate the workflows organizations rely on. Sophos Fusion supports that work by connecting endpoint, network, email, cloud, identity, and security operations in one coordinated defense system. By pairing that foundation with OpenAI’s frontier capabilities, Sophos plans to help approved partners enhance detection, investigation, and response, while also helping MSPs develop and scale new AI security services for their customers. Sophos intends to expand this protection with OpenAI, securing the AI workloads, data, and usage as part of one connected defense system.
Reach that spans SMB to enterprise
Sophos defends more than 625,000 organizations worldwide, from small businesses to global enterprises, delivered through a channel of over 25,000 partners, including more than 7,000 MSPs. That breadth is how frontier AI can reach the organizations that need it most, including those unable to deploy these models on their own.
Building on Daybreak: frontier AI across our managed services
Sophos is also extending its partnership within OpenAI’s Daybreak Cyber Partner Program. In June, Sophos gained access to OpenAI's cyber models to strengthen our products and threat intelligence.
Now we're extending that work into Sophos MDR, Digital Forensics and Incident Response (DFIR), and advisory services as a launch partner in OpenAI's new Daybreak Cyber Partner Program for Managed Security Services.
This program brings frontier cyber models to organizations delivering managed security. As a launch partner, Sophos applies the latest cyber-capable models across three pillars of our managed services, with expert operators in control and no direct customer access to the models:
- MDR: The models help analysts correlate signals across endpoint, network, identity, email, and cloud, separating real threats from noise in seconds. Analysts validate each finding and direct the response.
- DFIR: The models help responders rebuild the attack timeline and assess what an intruder accessed, moved, or took. This will support containment, disclosure obligations, and recovery.
- Advisory services, including offensive security and penetration testing: The models help consultants map likely attack paths and validate exploitable weaknesses, giving customers a prioritized, evidence-backed view of their exposure.
The benefit for customers is frontier-grade defense that would be extremely difficult to build in-house. Most organizations can't hire the rare talent needed or take on the capacity or financial obligations associated with running frontier AI in their own security operations, and they shouldn't have to. Customers can rely on Sophos experts to operate the latest models, govern them, and stay accountable for the outcome.
Sophos is uniquely positioned to deliver these capabilities, operating the world's largest agentic security operations center and defending more than 40,000 MDR customers worldwide, with human analysts maintaining oversight throughout and keeping hands-on-keyboard in every engagement.
Sophos will continue to develop the safety, abuse-prevention, and monitoring standards for responsible use of these capabilities.
Learn more
We look forward to sharing further updates as our solution delivery progresses. In the meantime, to learn more about Sophos Fusion, visit sophos.com/fusion. To hear Fernando Montenegro in recent conversation with Joe Levy, Sophos CEO, watch our Sophos Fusion launch event.
Forward-looking statements
This announcement contains forward-looking statements regarding anticipated products, services, collaborations, and future capabilities. Any unreleased services or features referenced are subject to change and may not become generally available. Customers should make purchasing decisions based solely on currently available products and services.

