AI Cut a 38-Minute Security Investigation to 89 Seconds—What Did Humans Give Up?
Sophos says OpenAI-powered agents now resolve 52% of MDR cases within analyst-defined boundaries. The speed is striking, but the approval boundary matters more.
Sophos says AI agents reduced the average response time for cases using those agents from about 38 minutes to 89 seconds. It also says 52% of managed detection and response cases can now be resolved end to end by AI within boundaries calibrated by its analysts.
Those numbers are dramatic. They are also a vendor-and-customer case study, not an independent audit. The most useful lesson is not that every security team can become 96% faster. It is how Sophos decided what an agent may investigate, what it may recommend, and when a human must take over.
What the agents actually do
Sophos Fusion combines the company’s own products with more than 500 third-party integrations. According to the case study, those sensors generate trillions of events per day, which are reduced to roughly 1,000–2,000 cases for nine security operations centers.
An investigation agent gathers customer context, detections, indicators of compromise, and threat intelligence. A planning model then runs a plan-execute-review loop, completing investigative steps and producing a summary with recommended response actions. Other agents can perform parts of the response.
This is not a chatbot answering a security analyst. It is a constrained operational pipeline that has access to defined data and actions.
The number needs a denominator
The 38-minute-to-89-second comparison applies to cases using the agents. The public case study does not publish a full independent error analysis, the severity mix, the percentage of cases excluded before automation, or the cost of model inference and integration.
Sophos and OpenAI have strong incentives to showcase successful deployment. That does not make the result false, but it changes how the claim should be used. Buyers should ask:
- Which case categories were eligible for automation?
- What percentage required human correction or reopening?
- How were false positives and missed indicators measured?
- Does the 89 seconds include queues, approvals, and downstream action?
- What is the cost per resolved case after compute and oversight?
Without those answers, the result is evidence of feasibility, not a portable benchmark.
The approval boundary is the real product
Sophos describes three customer operating modes. Notify means Sophos investigates and recommends while the customer acts. Collaborate means the parties work together before action. Authorise allows Sophos to respond on the customer’s behalf.
The company says the same boundaries apply whether the work is performed by a person or an agent, and potentially destructive actions retain human oversight when the team is not comfortable delegating them.
That is the architectural lesson. Faster reasoning does not create authority. An agent may be able to isolate a device, revoke access, block traffic, or alter configurations, but whether it should do so depends on reversibility, customer policy, confidence, and business impact.
An effective security agent therefore needs more than a model:
- explicit scopes for data and tools;
- customer-specific response policies;
- evidence attached to each conclusion;
- human escalation rules;
- idempotent and reversible actions where possible;
- audit logs for every step;
- continuous measurement of misses and corrections.
Why this use case fits agents
Security operations contain many repeatable investigations with structured inputs, known playbooks, and measurable outcomes. Analysts already gather context from multiple systems, compare indicators, check threat intelligence, and decide whether a case fits a familiar pattern.
That makes the work more automatable than vague knowledge tasks. The system can use deterministic checks around model judgment, and the highest-risk exceptions can be escalated.
The benefit is not merely headcount reduction. If routine cases are handled consistently, scarce analysts can spend more time on novel threats, ambiguous evidence, and decisions where business context matters.
The risk is automation complacency. Attackers adapt. A pipeline optimized around yesterday’s case patterns can process the wrong conclusion very quickly. Teams need shadow testing, sampled human review, adversarial exercises, and rollback procedures even after the system appears reliable.
Verdict
Sophos’s 89-second result is a compelling deployment signal, not proof that autonomous security is solved. The headline speed came from combining frontier models with private telemetry, established playbooks, tool boundaries, and human escalation.
The competitive advantage is not an agent that acts fastest. It is an agent that knows when it is allowed to act, preserves the evidence behind its decision, and hands uncertainty to a human before speed becomes damage.
Sources
> Want more like this?
Get the best AI insights delivered weekly.
By subscribing, you agree to our Privacy Policy. You can unsubscribe at any time.
> Related Articles
Can Google Detect an AI Image in 10 Seconds? The Catch Is Bigger Than It Looks
Google's SynthID Detector is now open to everyone, but it reads supported watermarks—not every possible sign of AI generation.
GPT-6 Answers With Apps Now—Is Traditional SaaS in Trouble?
OpenAI's Intelligent UI can generate interactive charts, forms, calculators, and mini-tools inside ChatGPT. The shift is real, but it does not erase software businesses overnight.
AI Decision Models Are Becoming a Control Plane, Not a Chat Feature
OpenAI's typed Decisions API and Strands' local Decider 2B point to a layered architecture where models estimate, application policy decides, and uncertain cases escalate.
Tags
> Stay in the loop
Weekly AI tools & insights.