TLDRocket
Sign in

Introducing Fugu-Cyber: our new orchestration model that achieves state-of-the-art performance on real-world cybersecurity benchmarks

Sakana AI

Sakana AI launched Fugu-Cyber, an orchestration model for cybersecurity that hits 86.9% on CyberGym and 72.1% on CTI-REALM. It matches top rivals like GPT-5.5-Cyber, but Sakana insists the model alone won't fix enterprise security.

Based on reporting by Sakana AI — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Sakana AI has pushed out a cybersecurity-specific version of its Fugu orchestration system, and the benchmark numbers are the kind that get attention: 86.9% on CyberGym, which tests whether an agent can actually verify vulnerabilities in messy real codebases, and 72.1% on CTI-REALM, which checks if a system can turn raw threat intel into working detection rules. Those scores put Fugu-Cyber in the same tier as GPT-5.5-Cyber and Anthropic's Mythos Preview, at least on paper.

But the more interesting part of Sakana's announcement isn't the leaderboard placement. It's the argument buried in the middle of the post, where the company pushes back hard against what it calls fearmongering around frontier model cyber capabilities. Sakana points to a recent Nikkei Digital Governance report showing that even major Japanese financial institutions with access to Anthropic's Mythos still struggle to operationalize it. Access to a capable model, in other words, doesn't automatically translate into patched vulnerabilities or working defenses. You need people who understand the codebase, and you need integration work that no API call alone provides.

Fugu-Cyber itself is built the same way as the original Fugu model: a single endpoint that quietly dispatches a request across a pool of specialized agents rather than relying on one vendor's model. Sakana frames this as protection against single-vendor dependency, which is a polite way of saying they don't want customers locked into one lab's roadmap. The pitch is orchestration as insurance policy.

Where this gets more concrete is in how Sakana says it plans to deploy the thing. Any vulnerability the system flags has to pass through sub-agents specialized in security plus a human-in-the-loop check before a patch even gets proposed. That's a direct response to the obvious failure mode of raw cyber-capable models: false positives, and lots of them, especially when a model has no real grasp of what a live production environment actually looks like. Sakana's Applied Enterprise team is apparently already working with large Japanese institutions to build these verification harnesses, treating the model itself as one component rather than the whole product.

Access won't be trivial either. Fugu-Cyber sits behind an updated Acceptable Usage Policy barring offensive misuse, and getting in requires submitting a request form with verified contact info and a stated use case, reviewed manually by Sakana's team. It'll run on the Token Plan. For a company selling itself partly on the idea of AI sovereignty and multi-model orchestration, gating access this tightly is a signal that they're taking the dual-use risk seriously, or at least want to look like they are.

My take — AI-written commentary, not fact-checked reporting

I like that Sakana is willing to say out loud what most cyber-AI vendors bury in a footnote: a benchmark score is not a security program. The gatekeeping around access feels a bit theatrical given how quickly these capabilities proliferate anyway, but the emphasis on human-in-the-loop verification is the right instinct in a market that's been selling autonomous vulnerability hunting as if it's already solved. Orchestrating multiple frontier models instead of betting on one vendor is also a smart hedge, and probably the more honest story here than the CyberGym number everyone will quote.

Read more about this at: Sakana AI

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.