Fugu-Cyber: Sakana AI's New Cybersecurity AI Model Outperforms GPT and Claude on Key Benchmarks

The Japan-based AI lab's security-focused orchestration model scores 86.9% on CyberGym and 72.1% on CTI-REALM, but access comes with strict conditions

Fugu-Cyber: Sakana AI's New Cybersecurity AI Model Outperforms GPT and Claude on Key Benchmarks

A New Cybersecurity AI Model Enters the Arena — With Gated Access and Serious Benchmark Numbers

Sakana AI, the Tokyo-based artificial intelligence research lab known for its nature-inspired approach to machine learning, has released Fugu-Cyber — a security-tuned endpoint built on its Fugu orchestration model. The new cybersecurity AI model reports 86.9% on CyberGym and 72.1% on CTI-REALM, two of the most recognized benchmarks in the AI security evaluation space. Critically, those scores place it ahead of competing offerings from OpenAI and Anthropic, specifically GPT-5.5-Cyber and Claude Mythos Preview, marking a notable milestone for a lab that operates largely outside the Silicon Valley mainstream.

For developers, IT security teams, and policy professionals tracking the fast-moving intersection of AI and cybersecurity, Fugu-Cyber represents more than a benchmark headline. Its architecture, access controls, and intended use case raise important questions about how AI companies are approaching the responsible deployment of security-capable AI systems — a topic that regulators in Europe and elsewhere are watching with increasing attention. Access to the model is not open: it requires manual approval from Sakana AI, agreement to a defensive-use policy, and enrollment in the company's Token Plan.

Cybersecurity professional analyzing AI security model output on screen
Fugu-Cyber is designed for defensive cybersecurity applications, with access gated behind a manual approval process

What Is Fugu-Cyber and How Does the Orchestration Model Work?

Fugu-Cyber is built on top of Sakana AI's Fugu orchestration framework — a system designed to coordinate multiple specialized AI components rather than relying on a single monolithic model. Orchestration-based AI systems have gained significant traction in enterprise security environments because they can route queries to the most appropriate sub-model, aggregate outputs, and apply reasoning layers on top of raw results. This architecture lends itself particularly well to cybersecurity tasks, where context-switching between different domains — such as malware analysis, threat intelligence parsing, and vulnerability assessment — is routine.

Sakana AI was founded by former Google DeepMind researchers and has built its reputation on evolutionary and bio-inspired AI techniques, as covered by outlets including TechCrunch and Wired. The Fugu family of models reflects a broader strategy of developing specialized, efficient AI systems rather than competing directly with the largest general-purpose language models from OpenAI or Google. With Fugu-Cyber, the company is making its most explicit move yet into the security sector.

The security endpoint is designed with defensive applications in mind — a distinction that the company enforces through its access policy. Users must agree that they will not use the model for offensive purposes, which includes activities like developing cyberweapons, conducting unauthorized penetration testing, or automating attacks. This kind of policy-level guardrail is increasingly standard in the field, but the combination of manual approval plus a usage policy plus a paid plan makes Fugu-Cyber one of the more tightly gated AI security tools currently available.

"The challenge with security-capable AI is not just building it — it's ensuring that the people who access it are doing so for legitimate, protective purposes. Gated access is one of the few mechanisms we have right now to make that distinction operationally meaningful."

— AI security researcher commenting on responsible deployment of cybersecurity AI models

Breaking Down the CyberGym and CTI-REALM Benchmark Scores

Benchmark scores are only as meaningful as the benchmarks themselves, and in the AI security world, CyberGym and CTI-REALM have emerged as two of the more rigorous evaluation frameworks available. Understanding what these numbers actually measure is essential for anyone trying to assess whether Fugu-Cyber is relevant to their organization's security posture.

CyberGym is a benchmark designed to evaluate an AI model's ability to handle realistic cybersecurity tasks — including capture-the-flag (CTF) challenges, vulnerability identification, and security reasoning problems. A score of 86.9% places Fugu-Cyber in elite company. For context, passing human cybersecurity professionals typically score in similar ranges on structured CTF events, making this a genuinely impressive result rather than a narrowly constructed benchmark win. Research published through platforms like arXiv has increasingly highlighted CyberGym as a meaningful proxy for real-world security task performance.

CTI-REALM (Cyber Threat Intelligence - Realistic Evaluation and Assessment of Language Models) focuses specifically on threat intelligence tasks: parsing threat actor reports, extracting indicators of compromise, attributing attacks, and synthesizing intelligence from unstructured data. A 72.1% score on CTI-REALM is significant because this benchmark is widely considered harder than general cybersecurity reasoning tasks — the ambiguity and domain specificity of threat intelligence make it notoriously difficult for AI systems to navigate reliably.

Model CyberGym Score CTI-REALM Score Access Model
Fugu-Cyber (Sakana AI) 86.9% 72.1% Manual approval + Token Plan
GPT-5.5-Cyber (OpenAI) Below 86.9% Below 72.1% API access via OpenAI platform
Claude Mythos Preview (Anthropic) Below 86.9% Below 72.1% API access via Anthropic platform

It is worth noting that benchmark comparisons in AI are always somewhat contested. The specific versions of competitor models tested, the evaluation methodology, and whether the benchmarks were run independently or by Sakana AI itself all matter. Nonetheless, the margin over GPT-5.5-Cyber and Claude Mythos Preview — both purpose-built security variants from the two largest AI labs in the world — is meaningful if it holds under independent scrutiny.

Why the Gated Access Model Matters for Security and Compliance Teams

The decision to require manual approval, a defensive-use agreement, and a paid plan before granting access to Fugu-Cyber reflects a broader debate happening across the AI industry about dual-use risk. Cybersecurity AI is one of the clearest examples of a dual-use technology: the same capabilities that help a security analyst identify vulnerabilities in their organization's systems can, in the wrong hands, be used to exploit those same vulnerabilities in someone else's.

For European organizations and policy professionals, this access model sits at an interesting intersection with emerging AI regulation. The EU AI Act, which has been making its way through implementation since its passage, classifies certain AI systems as high-risk based on their potential for harm. Security-capable AI models that could be used offensively represent exactly the kind of technology that regulators are trying to bring under structured oversight. As reported by Reuters, the EU AI Act's provisions around high-risk AI are expected to place significant compliance obligations on developers and deployers alike.

86.9% CyberGym Score
72.1% CTI-REALM Score
3-step Access requirements
#1 Ranked vs GPT & Claude security variants

For IT decision makers and small business owners evaluating AI-powered security tools, the gating mechanism also has practical implications. Unlike API-first tools that can be integrated immediately after signing up, Fugu-Cyber requires a human review step. This slows down procurement and integration timelines but may also signal a higher level of accountability — both from Sakana AI's side and from the user's side, since agreeing to a defensive-use policy creates a documented record of intended use. For organizations operating under GDPR or sector-specific data protection rules, this paper trail could be relevant to demonstrating due diligence in AI tool selection.

How Fugu-Cyber Fits Into the Growing Market for AI-Powered Cybersecurity

The release of Fugu-Cyber comes at a moment when the cybersecurity industry is undergoing a fundamental shift driven by AI. According to research published by Gartner, AI-augmented security operations are becoming a strategic priority for enterprise security teams, with autonomous threat detection and response moving from experimental to production deployment across sectors. The analyst firm has highlighted that the volume and sophistication of cyberattacks is outpacing the capacity of human-only security teams, making AI assistance not a luxury but an operational necessity.

Threat intelligence, in particular, is a domain where AI-powered tools have shown dramatic productivity gains. Security analysts traditionally spend significant time manually correlating threat data from multiple feeds, attributing attacks to known threat actor groups, and synthesizing intelligence into actionable briefs. A model that scores 72.1% on CTI-REALM is doing a credible job of automating exactly these tasks — which matters enormously for organizations that lack the budget or headcount to staff a full threat intelligence function.

Data center infrastructure supporting AI-powered cybersecurity operations
AI-powered security models like Fugu-Cyber are increasingly central to enterprise threat intelligence operations

The competitive landscape is also evolving rapidly. OpenAI's GPT-5.5-Cyber and Anthropic's Claude Mythos Preview represent major investments by the two dominant AI labs in security-specific capabilities. The fact that a smaller, specialized lab like Sakana AI is reporting benchmark superiority — even if only on these two specific evaluations — suggests that the security AI market is not yet consolidated around a small number of incumbents. This is consistent with broader trends in enterprise AI, where vertical specialists are often outperforming general-purpose models on domain-specific tasks, as noted in analysis from McKinsey's technology research.

For European organizations specifically, there

Originally reported by MarkTechPost. Summarised and curated by European Purpose.