Sophos is set to introduce Exploit Path Verification (EPV), a new capability powered by OpenAI's GPT cyber models, to help security teams prioritise vulnerabilities based on actual exploitability rather than generic severity scores.
The feature, which will be integrated into Sophos Managed Risk, aims to transform lengthy exposure lists into evidence-backed priorities by identifying which vulnerabilities attackers can actually reach in a specific environment.finance.
Security teams currently face a widening gap between the vulnerabilities they can detect and those they can remediate. While scanners surface thousands of exposures ranked by severity, these scores cannot indicate whether a critical flaw sits behind effective controls or whether multiple low-severity findings chain together into an exploitable path.
EPV is designed to close this gap by reasoning over asset and patch state, endpoint protection policy, network reachability, identity and privilege facts, and known exploit availability.
The capability will return one of four evidence-backed exploitability verdicts: Confirmed Exploitable, Blocked by a Control, Not Reachable, or Insufficient Evidence.
EPV will also identify chained attack paths where multiple lower-severity findings combine into one exploitable route, assess whether a control blocks a technique class or only a common public proof of concept, and draft remediation text ready for a ticket.
Every verdict will be labelled as AI-generated with supporting evidence visible, and Sophos analysts will review results before delivery to customers.
"One of the most common challenges we hear from security teams today is the volume of findings they need to sift through, and the lack of clarity of which findings matter most, or in other words, put them at greatest risk," said John Peterson, chief technology officer at Sophos.
John Peterson
"Exploit Path Verification is being built to make it clear what in their environment is reachable by an attacker, with the evidence to prove it, so they fix what counts first." John Peterson
EPV extends Sophos' existing work with OpenAI through the Daybreak Defense Network (formerly the Daybreak Cyber Partner Program), which the company joined in June 2026.
Through this partnership, Sophos has integrated frontier cyber models into managed detection and response (MDR) investigation, advisory assessments, and workflows that help customers discover, validate, and remediate exposures. OpenAI's GPT cyber models provide frontier reasoning to assess exploitability, while Sophos supplies environment-specific evidence and product controls.
"Our goal through the OpenAI Daybreak Defense Network is to give defenders the advantage of frontier AI, safely," said McCall McIntyre, head of Global Cyber Partnerships at OpenAI. "Sophos has been a thoughtful partner since joining the program, and Exploit Path Verification is a clear example of frontier reasoning applied to a real defensive problem, with the guardrails that responsible deployment demands."
EPV is currently in development for enterprise and mid-market customers of Sophos Managed Risk. Sophos will announce availability, including early access and general availability timing, at a later date.