Taught at Yale for a decade before a specific problem pulled Amin Karbasi into industry. The tools built to protect a company's code often require sending that code somewhere else first. I spoke with Karbasi at Black Hat this month. He is Vice President and Chief AI Scientist at Cisco Foundation AI, an adjunct professor at Stanford, and a member of the scientific board at the Simons Institute for the Theory of Computing. He joined Cisco through its 2024 acquisition of Robust Intelligence, where he was chief scientist, and he now leads the team behind Antares, the vulnerability-scanning models this site covered in July.
Small Models Solve a Custody Problem
Karbasi traced Antares to a bet the team made a year ago, before coding agents became routine. More generated code means more inherited mistakes, since the models writing that code learned from human code in the first place. The team scaled the model down instead of up: small enough to run on a single GPU, inside a customer's own environment, trained to search a codebase the way an investigator works a lead rather than the way a chatbot answers a question.
That size difference is why the scan runs in minutes instead of hours, and why a 500-task sweep across 290 repositories costs $0.82 instead of $141 (Vijay et al., Cisco Foundation AI, 2026). The number that matters more than either figure never shows up on an invoice.
No source code leaves the building to get that answer.
Access Stays Gated on Purpose
Antares-3B, the strongest model in the family, is not open. Karbasi called the decision deliberate, shaped by risk rather than marketing caution. A tool built to find vulnerabilities can also help someone exploit them, so the team tested its smaller models against compiled production code and confirmed they could not reconstruct an exploit without source-level access, access only a codebase's owner already has. Cisco is building a product around the 3B model instead of releasing its weights. Karbasi said it will land inside Cisco Cloud Control for customer security teams, available even to organizations whose developers never touch Antares directly.
Owning Intelligence Versus Renting It
Karbasi framed the broader bet behind Antares as a question every enterprise will face. Renting intelligence from a vendor exposes a company to decisions it does not control: pricing, and a vendor's ability to cut off access without warning.
Meta launched Muse Code five days earlier, a coding agent with a contributor tier priced at twenty cents per million output tokens in exchange for training rights (Bellamkonda, shashi.co, Aug. 2026). That is the trade Karbasi describes as renting intelligence at a steep discount. Antares is Cisco's bet that some intelligence, the kind that touches a company's own source code, has to be owned instead.
What CIOs Should Ask Next
Karbasi's question for CIOs is which slice of intelligence they can afford to rent, and which one they have to own.
Karbasi, Amin. Profile. Stanford University, stanford.edu.
Cisco. "Introducing Antares: Highly Efficient Open Weight AI Models for Vulnerability Localization." Cisco Blogs, 21 July 2026, cisco.com.
Vijay, Priyanshu, et al. "Antares: Foundation Models for Agentic Vulnerability Localization." Cisco Foundation AI, 2026, cisco.com.
Bellamkonda, Shashi. "Cisco's Antares Finds Vulnerabilities Cheaply." shashi.co, 22 July 2026, shashi.co.
Bellamkonda, Shashi. "Meta Prices Its Coding Agent Below Cost to Chase the Usage Numbers Investors Want." shashi.co, 9 Aug. 2026, shashi.co.
