
Orion-1 is a frontier foundation model for cyber defense, and the top-performing model on Decision-Grade Readiness, the new benchmark we built to measure whether a model’s security decisions can be trusted to act on.
Today we are introducing Orion-1, a frontier foundation model trained for cyber defense. Attackers now move at machine speed, while defenders still move at human speed, and that gap is where breaches happen. Closing it means defense that runs at machine speed with a model that does the manual work of security operations, enabling teams to focus on judgement. Orion-1 finds threats in security data, reading logs across identity, cloud, endpoint, SaaS, network, and AI systems, working out whether they describe an attack, and backing that conclusion with evidence.
We are releasing results on the first five tasks we measured: threat detection, investigation, attack reconstruction, threat hunting, and correlating activity. Orion-1 scored higher than every frontier model we tested with no frontier model scoring higher across the benchmark.

Why cyber defense needs its own model
General-purpose models reason well, but they were not trained to find attacks. Given billions of events, they lose the thread, flag benign activity that looks strange, or describe an attack correctly and still miss it in the data.
A real attack rarely shows up as one alarming event. It shows up as one actor leaving small traces across many systems, none of them alarming on its own. Finding the attack means reading them together and knowing what is normal for a particular environment.
The bar keeps rising as attackers use AI to run their attacks. Across the environments Artemis defends, suspicious and malicious AI-enhanced activity rose 268% between April and August 2026. These attacks run faster than any team can follow, cost little to scale, and adapt while they are happening. General-purpose models were never trained to separate these attacks from the noise around them, so keeping pace requires a model built for defense from the start.
Orion-1: Trained on the full-lifecycle of cyber defense

We post-trained Orion-1 on the defensive work Artemis runs every day: threat detection, threat hunting, generating detections, investigation, and incident response. Artemis has run millions of defensive operations across enterprise environments, helping to define the scenarios Orion-1 was trained to master, without using customer data.
Post-training targeted four behaviors. Orion-1 starts working from the first signal and builds the picture across the stack as it goes. It composes evidence across domains, so a login from Okta, a role assumption in AWS, and a mailbox rule in Google Workspace read as one story about one actor. When a thread runs out, it changes approach instead of narrating the dead end. And it commits to a decision with a stated confidence, then carries that decision through to a recommended or triggered response within the autonomy the customer has set.
How we measured Orion-1: Decision-Grade Readiness
Existing models are mostly evaluated on proxy tasks: multiple-choice questions about MITRE, capture-the-flag puzzles, and spotting vulnerabilities in code. None of them tell a security team whether a decision the model made can be trusted.
So we built Decision-Grade Readiness (DGR), a new benchmark that measures whether a security decision made by a model can be trusted enough to act on. DGR asks one question of every defensive decision: would a senior security engineer trust this enough to act on it? Each of DGR’s thousands of tasks is drawn from a scenario with a known ground-truth outcome.

Every model is evaluated with the same trigger, the same environment context, and the same sources and actions a defender would have. We further challenge the models with test cases that contain no attack at all, or with benign data that appears malicious at first glance.
Each decision is scored on whether the model reached the correct conclusion and whether the evidence it presented supports that conclusion. The results below cover threat detection, investigation, and attack reconstruction, and Orion-1 scored higher than both GPT-6 Sol and Claude Opus 5.5 on the tasks we measured.

Where Orion-1 runs in Artemis
Every environment is different, and the attacks that get through are the ones that look like normal activity in that particular environment. Artemis maps each customer’s users, AI agents, devices, SaaS applications, network activity, and cloud infrastructure, and keeps that map current as the environment changes. That map is what tells Orion-1 what is expected in an environment it has never seen. From there it finds threats in the customer’s data, writes the adaptive detectors that catch them, investigates every finding, and runs threat hunts that search for a specific attack across every connected source.

Orion-1 runs inside Artemis, so customers keep the controls they already use: every decision ships with its evidence and a stated confidence, autonomy is set per action type, and high-impact actions require human approval by default.
Put Orion-1 to work in your environment
Orion-1 is available first in private preview to Artemis customers, with broader availability to follow. We are selecting a small number of customers to start.
Artemis works directly with each customer to set autonomy thresholds that match their risk tolerance, and to share a readout of the threats Orion-1 found, the coverage it built, and the gaps it exposed.
Want to see what Orion-1 finds in your environment? Get in touch at artemissecurity.com.