Sophos Taps OpenAI’s Cyber Models To Tell Defenders Which Vulnerabilities Actually Matter

Sophos is adding OpenAI-powered exploit verification to help security teams prioritize which vulnerabilities attackers can actually reach.


Sophos has unveiled a new tool called Exploit Path Verification (EPV), designed to solve one of cybersecurity’s most persistent headaches: too many vulnerabilities and not enough clarity on which ones actually put a company at risk. The capability will be added to Sophos Managed Risk and will run on OpenAI’s GPT cyber models through the Daybreak Defence Network. No launch date has been set yet.

The Problem With Severity Scores

Vulnerability scanners are good at finding flaws thousands of them but a generic severity score doesn’t say whether a hacker can actually reach that flaw inside a specific company’s systems. A “critical” bug might sit behind a firewall that blocks it entirely, while two “low-risk” issues could chain together into a real breach path. Security teams end up patching by score rather than by actual exposure, wasting time on threats that were never reachable.

What EPV Actually Does

EPV analyses a company’s patch status, security controls, network setup, user privileges, and known exploit activity, then sorts each vulnerability into one of four categories: Confirmed Exploitable, Blocked by a Control, Not Reachable, or Insufficient Evidence. It also flags when multiple minor issues combine into a serious attack route, checks whether a defence actually stops an attack technique or just a known demo exploit, and drafts remediation notes teams can drop straight into a ticket.

Humans Still Check The Work

Sophos says every AI-generated verdict comes with visible evidence and is reviewed by its own analysts before reaching customers; the system is designed to assist, not replace, human judgment. “Exploit Path Verification is being built to make it clear what in their environment is reachable by an attacker, with the evidence to prove it, so they fix what counts first,” said John Peterson, Sophos’s chief technology officer.

Part Of A Bigger OpenAI Partnership

The move builds on Sophos’s membership in OpenAI’s Daybreak Defence Network, joined in June 2026, which already feeds frontier AI models into its threat investigations. Sophos protects more than 625,000 organisations and 40,000 managed detection and response customers, and says the goal is to make verified exploit analysis available beyond just the largest, best-funded security teams.

Author