In the new benchmark “Decision - Grade Readiness” for measuring whether the security decisions of AI are credible enough to take action based on, Orion-1 scored the highest in all five tasks measured, with no leading model performing better than it throughout the entire benchmark test.
New York, October 8, 2026 / PRNewswire / -- Artemis Security Today, Orion-1 is released. The company states that this is a cutting-edge foundational model trained to defend against the next generation of machine speed attacks. Orion-1 handles threats in a manner similar to seasoned defense personnel: it begins with the first signal and conducts investigations across each system it touches to determine what has occurred with a certain level of confidence, and then proposes response recommendations or triggers responses within the autonomous authority set by the customer. Orion-1 is now available as part of the Artemis platform, offering a private preview to select customers.
Artemis indicates that as AI changes the economics of attacks, Orion-1 has emerged as a result. New data from Artemis Security Research shows that between April and August 2026, suspicious and malicious AI activities increased by 268%. These attacks operate faster than any team's ability to respond, can scale almost without cost, and continuously adapt during the course of occurrence. The study also reveals what truly constitutes a strong defense: in the environments protected by Artemis, 92% of confirmed attacks were detected at the entry point, thanks to detection methods optimized for each environment. The company claims that defenses can succeed when they operate within the context of the environments they protect. Orion-1 is precisely designed to sustain such defenses and fight at the attacker's pace.
Built for the next generation of attacks
Artemis indicates that it has executed millions of defense operations in a corporate environment, including investigations, detection engineering, threat hunting, remediation, attack surface reduction, and incident response. These operational records define the scenarios for which Orion-1 is trained, and no customer data is used in this process.
The company stated that the later training phase focuses on four types of behaviors. Orion-1 starts working from the first signal and builds a comprehensive picture across the entire technology stack as it progresses. It is capable of integrating evidence across domains; therefore, a single login from Okta, a role switch within AWS, and an email rule from Google Workspace are all interpreted as part of the same individual's actions. When a lead reaches a dead end, it changes its approach instead of continuing to pursue that path. It also makes decisions with a clear level of confidence and implements these decisions as recommended responses or triggers within the autonomous authority set by the customer.
Artemis Security CTO Dan Shiebler stated: "Over the past 15 years, I have been at the forefront of AI and cybersecurity. Generalized models have strong reasoning capabilities, but they have never been trained for this task. In real attacks, the same actor will leave tiny traces in many systems, and these traces alone are not sufficient to trigger an alarm. Orion-1 After end-to-end training, it is capable of integrating these traces into a complete picture, making clear decisions, and advancing towards problem resolution."
Decision - Grade Readiness: Measuring whether defense is trustworthy
Artemis indicates that the current security AI is mostly assessed through proxy tasks: multiple-choice questions regarding MITRE, flag-raising competition puzzles, code vulnerability identification, etc. However, none of these can tell the Chief Information Security Officer whether a certain decision made by the model is trustworthy.
Decision - Grade Readiness The benchmark (DGR) poses the same question to every defense decision: Will senior security engineers trust it enough to take action based on that? The thousands of tasks in DGR come from scenarios with known real results. Each model is evaluated under exactly the same conditions: the same triggering factors, the same environmental context available at the time, and the same range of sources and operational access permissions as the defense personnel. Some test cases do not contain any attacks at all, or they contain data that appears malicious at first glance but is actually harmless. The scoring for each decision is based on two points: whether the model reached the correct conclusion, and whether the evidence it provided supports that conclusion.
Artemis indicates that it tested Orion-1 with four cutting-edge models: Claude Opus 5.5, GPT-6, Sol, Grok 4.7, and Kimi K3. Orion-1 was at the forefront in each task. The project where it had the greatest lead was attack reconstruction, which involves restoring the attacker's steps in the order in which the attacks occurred; in this project, Orion-1 scored 80.8, while the best cutting-edge model tested scored 58.3.
Artemis Security The CEO stated: "The industry has been asking AI to do what analysts do, but that is the wrong goal. Attackers act at machine speed, while defenders act at human speed, and it is in this gap that vulnerabilities arise. You cannot bridge this gap by making analysts work faster. What you need to do is build defenses that operate at the attacker's pace. Orion-1 This is such a model. It is trained for the defensive tasks that are executed on our platform every day, and it is judged according to the same standards that customers have long used to measure us: am I confident enough in it to take action based on its findings?"
Autonomy controlled by the customer
Artemis indicates that Orion-1 operates within the safeguard mechanism of the Artemis platform. Each decision comes with its evidence and a clear level of confidence. Customers can set their level of autonomy based on the type of operation, ranging from merely providing suggestions to full automation, while high-impact responses require manual approval by default. Every investigation and action is recorded and can be audited end-to-end. During the private preview period, Artemis will work directly with each customer to set an autonomous threshold that suits their risk tolerance.
Availability
Artemis indicates that Orion-1 is currently providing a private preview to some Artemis customers, and the scope of availability will be expanded in the future. Relevant institutions can apply for access through artemissecurity.com.
Attackers act at machine speed. Now, defenders can too.
About Artemis Security
Artemis Security indicates that it is an agent-based security operations platform, trusted by Cursor and Fortune 500 companies. It is used to detect, investigate, and contain attacks at machine speed. Artemis can connect endpoints, identities, code, cloud, and evidence from SaaS to form a single, highly confident case for each incident; it generates detections optimized for each customer's environment; and it responds in the instant an attack begins, without the need to deploy new agents or migrate data. Artemis is built on AWS and runs in a customer-specific environment. For more information, please visit artemissecurity.com.
Media contact:
Danielle Ostrovsky
[ email protected ]











