Accessing a frontier model is not enough to secure an enterprise

Sakana AI launches Fugu-Cyber to analyze vulnerabilities. Why access to this frontier model is not enough to protect an infrastructure.

Sakana AI is releasing a cybersecurity version of its Fugu orchestrator. Fugu-Cyber arrives as a new API endpoint, based on the same principle already established by the original model: a multi-agent system that behaves like a single model, where a request arrives at an endpoint before the system dynamically mobilizes a pool of specialized agents. The company claims 86.9% on CyberGym and 72.1% on CTI-REALM. The former evaluates an agent's ability to analyze complex codebases to confirm real vulnerabilities, while the latter assesses its aptitude for converting raw threat intelligence reports into operational detection rules.

The post then devotes an unusual portion of its content to tempering the significance of these results. Sakana believes that the current discourse surrounding the cyber capabilities of frontier models is partly driven by fear-mongering, and above all, that access to such a model does not solve an organization's security on its own. Drawing on a report from Nikkei Digital Governance, it observes that large organizations, including financial institutions, struggle to put these tools into production. Without specialized in-house expertise or deep integration with proprietary source code, even a highly capable model cannot easily identify or patch real vulnerabilities.

Deployed on its own, a model produces false positives and poorly understands the specificities of a production environment without the proper harness, the company continues. Its position relies on a validation chain: a vulnerability flagged by an AI system goes through specialized sub-agents and then a human review, which confirms that it would actually trigger, before a patch is proposed. Its Applied Enterprise team is working in this direction with major Japanese institutions.

Access remains restricted. A revised usage policy prohibits offensive uses, the model falls under the Token Plan, and each request goes through a form detailing the use case with verified contact information, which is manually reviewed before approval.