
Sakana AI's Fugu-Cyber orchestration model leads on key benchmarks but faces access limits and no independent verification. Security professionals should weigh the promise against the restrictions.
Sakana AI launched Fugu-Cyber on July 21, 2026, an orchestration endpoint that reports 86.9% on CyberGym and 72.1% on CTI-REALM, edging past GPT-5.5-Cyber (85.6%) and Claude Mythos Preview (83.1%). However, these results are self‑reported and unreplicated, and access is tightly gated. The model is only available as a hosted API with no released weights, requires manual approval for a defensive‑use acceptable use policy, and is unavailable in the EU and EEA. Pricing follows a Token Plan: $6 per million input tokens and $36 per million output tokens, a 1.2x premium over Fugu‑Ultra. This article breaks down the benchmarks, architecture, restrictions, and what they mean for cybersecurity professionals.
Fugu-Cyber is not a new frontier language model. Instead, it is an orchestration model that sits on top of existing LLMs, deploying what Sakana AI calls “learned agentic scaffolding.” The system routes tasks across three defined roles:
These roles interact over multiple recursive model calls, mimicking a team of specialized agents. This architecture allows Fugu‑Cyber to break down complex cybersecurity operations into manageable, verifiable steps—an approach that is increasingly central to AI performance in security contexts.
The CyberGym benchmark, developed at UC Berkeley, includes 1,507 real‑world vulnerabilities across 188 OSS‑Fuzz projects. To score a success, the AI must produce a crashing proof‑of‑concept that verifies the vulnerability—a rigorous test that goes beyond simple identification.
Fugu‑Cyber achieved 86.9%, narrowly beating GPT‑5.5‑Cyber (85.6%) and Claude Mythos Preview (83.1%). To contextualize the pace of improvement: the best agent‑model pair in the 2025 CyberGym academic paper managed only 20%. The jump to nearly 87% in one year underscores dramatic progress in AI‑driven vulnerability discovery, though the gap between top models is narrowing to just 1.3 points at the top.
The CTI‑REALM benchmark, created by Microsoft, pushes models to generate detection rules from cyber threat intelligence reports across 37 scenarios covering Azure cloud, Linux endpoints, and Azure Kubernetes Service. The metric is a trajectory reward that measures the quality of generated rules; Sakana AI reports this as a 72.1% success rate.
Fugu‑Cyber surpasses the best Claude configuration in Microsoft’s evaluation (68.5%) and the third‑place Claude config (62.4%). For perspective, mean scores across all evaluated models were 28.2% on Azure cloud (APT‑style), 58.5% on Linux endpoints, and 51.7% on Azure Kubernetes Service. Fugu‑Cyber’s performance nearly triples the cloud mean, indicating the orchestration approach is particularly effective in complex, multi‑step detection tasks.
Fugu‑Cyber’s performance stems from its learned agentic scaffolding. When given a task, the Thinker decomposes the problem—e.g., “scan the binary for known vulnerable functions, then craft an input that triggers a crash.” The Worker then interacts with tools, from debuggers to vulnerability databases. The Verifier inspects results and, if the goal is not met, refreshes the plan.
This iterative loop applies to both exploitation (CyberGym) and detection rule creation (CTI‑REALM). By narrowing each step, the underlying LLM can specialize, improving accuracy. Recursive calls allow error correction without human manual back‑and‑forth, an advantage over simpler single‑turn approaches.
Sakana AI has imposed significant access barriers:
Pricing is premium but predictable inside the Token Plan:
Fugu‑Cyber sits at the intersection of three key trends:
For security professionals, Fugu‑Cyber demonstrates that orchestrated AI can achieve strong benchmark results. Yet independence and openness remain open questions.
Sakana AI’s Fugu‑Cyber shows that orchestration architecture can push cybersecurity AI benchmarks above existing frontier models, but the improvements are modest and the access model is restrictive. For technology professionals, the core takeaways are clear: consider Fugu‑Cyber as part of a toolkit, not a silver bullet; demand independent validation; and prepare for an era where compliance and cost may outweigh raw performance in procurement decisions. The race to secure systems with AI is accelerating, but it is increasingly a race with multiple tracks—model capability, system design, and policy constraints—that must all be evaluated together.
Fugu-Cyber is an orchestration model, not a new language model. It uses 'learned agentic scaffolding' to coordinate three specialized roles—Thinker, Worker, and Verifier—that decompose complex cybersecurity tasks into manageable steps. This agent-driven approach allows it to outperform standard LLMs on benchmarks like CyberGym and CTI-REALM.
The architecture assigns three roles: the Thinker analyzes the problem and outlines a strategy, the Worker executes specific actions such as writing code or querying tools, and the Verifier checks outputs for correctness. These roles collaborate through multiple recursive model calls, replicating a team of specialists to ensure reliable results.
Fugu-Cyber scored 86.9% on CyberGym (a real-world vulnerability benchmark) and 72.1% on CTI-REALM, narrowly beating GPT-5.5-Cyber (85.6%) and Claude Mythos Preview (83.1%). This marks dramatic improvement from earlier results—top models reached only 20% in 2025—but the gap between leaders is now very small.
Fugu-Cyber is only available as a hosted API with no released model weights, requires manual approval for a defensive-use acceptable use policy, and is not accessible in the EU and EEA. Pricing is $6 per million input tokens and $36 per million output tokens—a 1.2x premium over Sakana's Fugu-Ultra.
The results highlight rapid progress in AI-driven vulnerability discovery and detection engineering, but the self-reported, unreplicated benchmarks and tightly gated access warrant caution. Professionals should view the architecture as a promising step toward automating complex security workflows, while awaiting independent verification.