Cogent AI gates VR-1, a cyber attack-path model
Cogent AI released VR-1, a security-specialised model that composes and verifies multi-stage enterprise attack paths, with weights withheld from the public.
Post-trained for intrusion, not vulnerability lists
Cogent AI released VR-1 on Monday, a model post-trained specifically for cybersecurity work. Its stated target is not finding individual vulnerabilities but assembling and verifying whole attack paths: investigating an environment under incomplete information, forming and testing hypotheses, chaining steps across system boundaries, recovering after a failed route, and confirming an objective by executing it rather than describing it. Runs are bounded at roughly two hours or 250 agent turns.
The model shipped with two accompanying pieces: IntrusionBench, an execution-based evaluation suite, and the Cogent AI Harness, a governed runtime for security agents.
Numbers, and their caveats
Cogent reports that in black-box testing VR-1 achieved roughly double the attack-path success rate of Kimi K3, Claude Opus 4.8 and GLM-5.2 at about a quarter of the cost. It also states plainly that VR-1's own black-box success rate remains under 30% and calls the results preliminary — a rate that says as much about how hard end-to-end intrusion chaining still is as it does about the model.
Weights are not public. Access runs through a Cogent Frontier Access Program limited to vetted organisations, with guardrails and audit logging attached. The stated customer base is Fortune 2000-scale enterprises and government bodies in finance, healthcare, SaaS, retail, telecom and critical infrastructure.
Why it matters
Offensive security capability is where the open-weights debate gets uncomfortable, and VR-1 is a clear statement of one answer: build the capability, keep the weights, admit customers individually, log everything. That structure is closer to arms-export control than to a model launch, and it will be cited by both camps in the current argument over release policy.
The honest read on capability is more measured. Sub-30% success on full black-box chains, published by the vendor itself, undercuts the idea that autonomous intrusion is solved — and echoes VulnCheck's recent finding that only 1.3% of AI-discovered vulnerabilities in the first half of 2026 were confirmed exploited. The gap between generating plausible attack paths and landing them remains the industry's main margin of safety.