Jul 27, 2026
Enterprise

Cogent VR-1 model debuts to test enterprise attack paths

Cogent Security says VR-1 can prove attack paths in live environments, but its benchmark results need careful reading.

Wei-Lin Zhao

By Wei-Lin Zhao · AI Correspondent

· 3 min read

Cogent VR-1 model debuts to test enterprise attack paths
Photo: SiliconANGLE

Cogent Security introduced the Cogent VR-1 model, a frontier reasoning model built to find and verify attack paths inside live enterprise systems. The vulnerability management startup is pitching the model as a defensive answer to more capable AI-assisted intrusions, while disclosing no valuation, revenue or headcount figures tied to the launch.

The company said VR-1 was trained to connect weaknesses across cloud infrastructure, identity systems and internal tooling, then test whether a remediation actually blocks the route. That is a narrower problem than finding a single software flaw, and it is closer to how real breaches often progress: through chains of misconfigurations, over-permissioned identities and low-priority issues that become material in combination.

What is the Cogent VR-1 model?

VR-1 is Cogent Security’s AI model for proving whether an attacker could move from an initial foothold to a specified target in an enterprise environment. Cogent says the model validates exposure without causing damage, persistence or operational disruption.

Cogent released VR-1 alongside IntrusionBench, a benchmark the company created to test agent performance on attack-path execution. In the test, an agent receives a foothold and a target, with scoring based on whether it reaches the target rather than whether it describes a plausible route.

Cogent said VR-1 proved twice as many attack paths as Kimi K3, Claude Opus 4.8 and GLM-5.2 on the hardest IntrusionBench setup, at about one-quarter of the cost. The caveat is material: the benchmark is Cogent’s own, and the headline comparison used the other models on their default harnesses. When those models ran inside Cogent’s AI Harness, Cogent said they came within a few percentage points of VR-1, which itself had a success rate below 30% in that configuration.

As the benchmark revealed more information about the environment, all models improved and the gap narrowed, according to Cogent. That makes the harness and environment context almost as important to the story as the model, especially for buyers evaluating whether a specialized model is needed or whether a strong general model with the right runtime can deliver similar results.

Access will be restricted

Cogent said VR-1 will not be released openly. Access will run through the Cogent Frontier Access Program, which the company says includes vetting, guardrails and audit logging. Qualified applicants can also request a Frontier Model Risk Assessment, a report showing which attack paths a frontier-level model could reach in their environment.

The company is also shipping the Cogent AI Harness, a runtime that gives models scoped tools, environment context and policy enforcement. Cogent says each action is checked against a customer’s policy, reflecting a security market where vendors want frontier-model capability without handing agents broad operational freedom.

Cogent describes VR-1 as “Mythos-class,” referring to an Anthropic frontier model whose cyber capabilities drew scrutiny earlier this year. The company did not benchmark VR-1 against Mythos. Its Anthropic comparison was Claude Opus 4.8.

Founded in 2025, Cogent says its team includes researchers and operators from Google DeepMind, Abnormal AI and Coinbase. The company sells AI agents for vulnerability investigation, routing and fix verification. Cogent says Fortune 500 customers have reduced the exposure window for critical vulnerabilities by 97%, a claim it did not break down with customer names or baseline figures.

Cogent has raised $53 million to date, including a $42 million Series A led by Bain Capital Ventures in February. The VR-1 launch puts the company deeper into the contested category of AI security agents, where defensible performance will depend less on positioning and more on repeatable proof inside customer environments.

This story draws on original reporting from SiliconANGLE.

More from Enterprise

All Enterprise →