Cisco releases Antares-350M and Antares-1B, open-weight AI models for finding known vulnerabilities within a codebase, and is training an Antares-3B model next
- Cisco says the models performed similarly to much larger models, including OpenAI's GPT-5.5 and Z.ai's GLM-5.2 …
Context & Ripple Effects
Cisco’s Antares release brings an open-weight option to a cybersecurity-model market where OpenAI has limited access to its defensive variants, including a GPT-5.5-Cyber preview for vetted security teams.
The stated focus is finding known vulnerabilities in a codebase, not general-purpose autonomous security work. That narrower task framing makes Cisco’s claim of performance comparable with much larger models commercially relevant while keeping the comparison bounded.
First-order effects
- Security teams and developers can evaluate Cisco’s 350M and 1B open-weight models for known-vulnerability detection without relying solely on restricted cybersecurity-model programs.
- Cisco gains a foothold in AI-assisted code security and a path to extend the product line with the planned 3B model.
Second-order effects
- Providers of gated security models face a clearer trade-off between tightly controlled access and the adoption advantages of deployable open weights; OpenAI’s earlier defensive GPT-5.4-Cyber access program illustrates the controlled-access approach.
- If small specialized models prove useful on this task, buyers may put more weight on task-specific performance and deployment flexibility than on the parameter scale of general models.
Third-order effects
- Cybersecurity AI may split into open, narrowly scoped defensive tooling for repeatable tasks and restricted access for higher-capability systems, rather than converging on one model-access model.
- The release is another data point in AI industrialization: model value can increasingly come from domain tuning, evaluation, and workflow integration rather than scale alone.
The trend: Specialized, smaller open-weight models are emerging as a counterweight to restricted frontier-model access in enterprise security workflows.