Proofpoint Adds an OpenAI-Powered Security Agent That Cannot Contain Threats
The SOC Analyst Agent assembles evidence and recommends next steps across Proofpoint’s products, but consequential response actions remain with security staff.
Listen to this story
The audio brief
Story brief
3 key pointsProofpoint is testing a security investigation agent with select customers, targeting general availability by the end of Q3 2026. The agent uses OpenAI’s Daybreak cyber-tuned models to connect alerts, logs, data-loss-prevention events, and user-risk signals, then produce source-linked findings and recommended actions. Its boundary is central: it can investigate and escalate, but cannot alter accounts, contain...
- 01
Private preview is limited to select beta customers; Proofpoint expects broader availability by the end of Q3 2026.
- 02
Analysts can query connected Proofpoint data in natural language instead of switching consoles or writing individual queries.
- 03
Findings remain traceable to underlying source data, preserving human validation before response decisions.
Proofpoint has introduced the SOC Analyst Agent, a tool that brings OpenAI Daybreak cyber-tuned models into its security investigation workflows. It is designed to turn analysts’ natural-language questions into traceable findings and recommended next steps, without independently taking consequential response actions.
The product is in private preview with select beta customers, and Proofpoint expects general availability by the end of the third quarter of 2026. That makes the announcement an early customer rollout rather than a broad release.
From scattered signals to an investigation
The agent can plan an investigation using connected Proofpoint alerts, logs, data loss prevention events and user-risk signals. Rather than switching among consoles or writing individual queries, analysts can ask questions in ordinary language and receive findings tied to underlying source data, plus recommended next steps.
Scheduled work can cover
- Threat hunts across connected Proofpoint security data.
- Data-security investigations, with results routed to appropriate analysts.
- Escalation reporting for analyst review.
A workflow tool, not an autonomous responder
That division of labor puts the model’s role in evidence gathering, context building and recommendation. A human still decides whether to alter an account, contain an active threat or take another consequential step. Proofpoint says the traceability of its findings is intended to let analysts validate recommendations before acting.
Proofpoint frames the tool against a growing volume of alerts and security data spread across products and workflows. Its 2025 Data Security Landscape report found that 54% of organizations use AI-enhanced capabilities to triage and investigate alerts, though teams still need to connect signals and decide what deserves attention.
The first Daybreak product from Proofpoint
Proofpoint joined the OpenAI Daybreak Defense Network in June 2026, and says the SOC Analyst Agent is its first capability brought to market through the network. The company is also exploring Daybreak-model uses in threat research, data security and AI security, including work that could trace confirmed malicious findings across a network and recommend fixes for human review. Those remain prospective applications, not features in the preview.
Sources
- markets.businessinsider.comProofpoint Brings OpenAI GPT Cyber Models into Security Operations to Help Defenders Investigate Threats Faster