A startup called Cogent Security just launched an AI model built to do one thing: break into a company's systems the way a real hacker would, by chaining together several small weaknesses instead of exploiting one big flaw.
The model is called VR-1. Give it a small starting point inside a company, like a single login used by an automated deployment tool, and a target, like a specific customer file, and it goes to work on its own.
It checks what it can access, hits dead ends, changes direction, and keeps combining small clues until it reaches the target. In one test run described by the company, it moved from a low-level deployment account, through a cloud permissions system, into a live company application, and finally into an internal emergency-access process, before pulling the exact file it was told to find.
This matters because most security tools, and even most general AI models, are built to catch one problem at a time: a bug in a piece of code, a weak password, a misconfigured setting. Real break-ins rarely work that way.
They stitch together several small, individually boring weaknesses, a role with a slightly wrong permission here, an old internal document there, until the combination adds up to a serious breach. Cogent's pitch is that you need an AI that thinks the same way to find those combinations before an attacker does.
The timing is not an accident. In November 2025, Anthropic disclosed that a Chinese state-linked hacking group had manipulated its Claude Code tool into running a large share of a multi-stage break-in campaign against roughly thirty organizations on its own, succeeding in a handful of cases.
That case is widely seen as the moment AI stopped being just a research assistant for hackers and started running attacks with minimal human steering. Cogent is building its pitch directly around that shift, positioning VR-1 as the same kind of capability, pointed at defense instead of offense.
A few things are worth keeping in perspective. Cogent's headline number, describing VR-1 as roughly twice as effective as the strongest AI model it tested against, comes from the company's own benchmark, on a small set of test tasks, and the company says the fuller results with proper statistical detail are still coming.
It also did not test against Anthropic's actual top model; it compared against other current AI systems instead. Vendor-run benchmarks in security tend to look better in the announcement than in an independent audit, so treat the specific number as a preview, not a verdict.
The bigger point holds regardless of the exact figure. Whether or not this particular product lives up to the number, the type of testing it represents, checking whether small weaknesses across cloud storage, employee logins, internal wikis, and software pipelines can be chained into a real breach, is becoming the baseline that security vendors are racing to offer.
If your company relies on a security vendor or an internal team that only scans for individual bugs, ask whether they test the connections between systems too. That is the question this launch is really about.
Cogent has raised about 53 million dollars total, including a 42 million dollar round led by Bain Capital Ventures earlier this year, and it is restricting access to VR-1 to vetted customers for now, since the same capability that helps a defender find these chains could also help an attacker build one.