Cisco released two open-source AI models designed to detect software vulnerabilities at a fraction of the cost of large language models like GPT-5.5. The company claims its smaller models find approximately 150 times more vulnerabilities per dollar spent compared to larger AI agents, based on internal testing.
The models represent a strategic shift in how enterprises approach vulnerability detection. Rather than relying on expensive, general-purpose AI systems, Cisco built specialized security tools optimized specifically for identifying code flaws and security gaps. This approach trades the versatility of large models for focused performance in a single critical domain.
Cost efficiency drives the value proposition. Enterprise security teams face mounting pressure to identify vulnerabilities faster as attack surfaces expand. Large language models require significant computational resources and per-token pricing models that scale with usage. Cisco's smaller, purpose-built models run on standard infrastructure with lower operational costs, making continuous vulnerability scanning economically feasible for organizations of all sizes.
The open-source release matters strategically. By making these models publicly available, Cisco enables community contributions and broader adoption. Security researchers can audit the models, integrate them into existing toolchains, and improve detection algorithms collaboratively. This contrasts with proprietary approaches that lock vendors into closed ecosystems.
However, the "150 times more vulnerabilities per dollar" metric requires scrutiny. This likely measures detection volume against cost, but doesn't directly address detection accuracy or false positive rates. A model finding more vulnerabilities means nothing if it generates excessive noise or misses critical security issues. Cisco's internal testing doesn't constitute independent validation.
The timing reflects broader industry recognition that frontier AI models often perform poorly on specialized tasks. A general-purpose model trained on internet-scale data lacks the depth of security-specific knowledge that purpose-built systems develop. Cisco's bet assumes that security teams value focused accuracy and cost efficiency over the flexibility of general AI.
This approach