Toolspublished

Proofpoint Adds an OpenAI-Powered Security Agent That Cannot Contain Threats

The SOC Analyst Agent assembles evidence and recommends next steps across Proofpoint’s products, but consequential response actions remain with security staff.

By 2 min read
Proofpoint Adds an OpenAI-Powered Security Agent That Cannot Contain Threats
Proofpoint Adds an OpenAI-Powered Security Agent That Cannot Contain Threats

Listen to this story

The audio brief

About 1:31
0:001:31
Read transcript
Proofpoint is testing a new SOC Analyst Agent that can investigate security threats, but cannot contain them. The tool brings OpenAI’s Daybreak cyber-tuned models into Proofpoint’s security workflows, where it connects alerts, logs, data-loss prevention events, and user-risk signals. Instead of switching between consoles or writing separate queries, an analyst can ask a question in natural language. The agent then assembles findings tied back to the underlying source data, along with recommended next steps. It can also schedule threat hunts, route data-security investigations to the right analysts, and prepare escalation reports for review. That traceability is important because the system’s authority stops at investigation and recommendation. It cannot change an account, contain an active threat, or initiate another consequential remediation action. A human still has to validate the evidence and decide what happens next. The product is in private preview with select beta customers, and Proofpoint expects general availability by the end of the third quarter of 2026, so this is an early workflow rollout rather than a broad release. Proofpoint says the agent addresses alert volume and fragmented security data; its 2025 report found that 54 percent of organizations already use AI-enhanced capabilities for alert triage and investigation. Proofpoint joined the OpenAI Daybreak Defense Network in June 2026. The key constraint to watch is whether future features can move from recommendations toward network-wide fixes without removing human control.

Story brief

3 key points

Proofpoint is testing a security investigation agent with select customers, targeting general availability by the end of Q3 2026. The agent uses OpenAI’s Daybreak cyber-tuned models to connect alerts, logs, data-loss-prevention events, and user-risk signals, then produce source-linked findings and recommended actions. Its boundary is central: it can investigate and escalate, but cannot alter accounts, contain...

  1. 01

    Private preview is limited to select beta customers; Proofpoint expects broader availability by the end of Q3 2026.

  2. 02

    Analysts can query connected Proofpoint data in natural language instead of switching consoles or writing individual queries.

  3. 03

    Findings remain traceable to underlying source data, preserving human validation before response decisions.

Proofpoint has introduced the SOC Analyst Agent, a tool that brings OpenAI Daybreak cyber-tuned models into its security investigation workflows. It is designed to turn analysts’ natural-language questions into traceable findings and recommended next steps, without independently taking consequential response actions.

The product is in private preview with select beta customers, and Proofpoint expects general availability by the end of the third quarter of 2026. That makes the announcement an early customer rollout rather than a broad release.

From scattered signals to an investigation

The agent can plan an investigation using connected Proofpoint alerts, logs, data loss prevention events and user-risk signals. Rather than switching among consoles or writing individual queries, analysts can ask questions in ordinary language and receive findings tied to underlying source data, plus recommended next steps.

Scheduled work can cover

  • Threat hunts across connected Proofpoint security data.
  • Data-security investigations, with results routed to appropriate analysts.
  • Escalation reporting for analyst review.

A workflow tool, not an autonomous responder

That division of labor puts the model’s role in evidence gathering, context building and recommendation. A human still decides whether to alter an account, contain an active threat or take another consequential step. Proofpoint says the traceability of its findings is intended to let analysts validate recommendations before acting.

Proofpoint frames the tool against a growing volume of alerts and security data spread across products and workflows. Its 2025 Data Security Landscape report found that 54% of organizations use AI-enhanced capabilities to triage and investigate alerts, though teams still need to connect signals and decide what deserves attention.

The first Daybreak product from Proofpoint

Proofpoint joined the OpenAI Daybreak Defense Network in June 2026, and says the SOC Analyst Agent is its first capability brought to market through the network. The company is also exploring Daybreak-model uses in threat research, data security and AI security, including work that could trace confirmed malicious findings across a network and recommend fixes for human review. Those remain prospective applications, not features in the preview.

Sources

  1. markets.businessinsider.comProofpoint Brings OpenAI GPT Cyber Models into Security Operations to Help Defenders Investigate Threats Faster