All posts

Cisco's Antares SLMs detect code flaws on-prem, no cloud needed

Manaal KhanAugust 10, 2026 at 7:01 PM4 min read
Cisco's Antares SLMs detect code flaws on-prem, no cloud needed

Cisco has released Antares, a set of small language models built to find security vulnerabilities in code without sending that code to the cloud. Two of the models, Antares-350M and Antares-1B, are now available as open-weight releases for developers and security teams.

Cisco's Antares SLMs detect code flaws on-prem, no cloud needed
Source: TahawulTech.com

The pitch is straightforward: general-purpose AI scanners typically require uploading proprietary source code to external servers. That's a non-starter for government agencies, universities, and any organization bound by data-sovereignty rules. Antares runs locally, on the organization's own hardware.

Advertisements

What makes Antares different from cloud-based scanners?

CLIP: Cisco Launches Antares AI to Spot Code Flaws | #TFDRundown

Most AI-powered vulnerability detection relies on large language models hosted by the vendor. That means the code leaves your network. Cisco designed Antares to be compact enough to run on-premises, eliminating the compliance headache for sectors that cannot risk data exfiltration.

The models also work differently than rule-based static analysis. According to Cisco, Antares reads a vulnerability description, searches for relevant code, abandons dead-end paths, and narrows down the file paths most likely to contain a threat. The company describes this as "human-like investigation."

With Antares, we are giving security teams the power of AI locally so they can pinpoint vulnerabilities faster while keeping sensitive source code firmly within their own secure environment.

— Fady Younes, Managing Director for Cybersecurity, Cisco METAC

Why open-weight, and who benefits?

Cisco is releasing the 350M and 1B parameter models openly. The stated goal is to "democratize AI security" for smaller teams that lack the budget or infrastructure for proprietary large language models.

Open weights let security researchers audit the model's behavior, fine-tune it for specific codebases, or integrate it into existing CI/CD pipelines without licensing friction. For startups or open-source projects, this removes a real barrier.

350M & 1B
Parameter counts for the two Antares models Cisco is releasing openly
Advertisements

Performance claims and what's missing

Cisco says benchmark testing shows Antares outperforms "many larger, more expensive AI models" on critical security tasks at a fraction of the cost. The company has not published the benchmarks, the competing models tested, or the hardware requirements for running Antares locally. That makes it hard to verify the claim independently.

The announcement also doesn't specify which languages or frameworks Antares supports, or whether the models require fine-tuning for a given codebase to reach their advertised accuracy. Security teams evaluating adoption will need those details before committing.

ℹ️

Logicity's Take

For AI builders integrating security scanning into pipelines, Antares offers a genuinely useful constraint: no external data transfer. The open-weight release signals Cisco is betting on ecosystem adoption over licensing revenue, similar to Meta's approach with Llama. The gap right now is transparency. Until Cisco publishes benchmark methodology and hardware specs, teams should treat this as a promising tool to test, not a proven replacement for existing scanners like Snyk or Semgrep.

Where this fits in Cisco's AI strategy

Cisco frames Antares as part of a broader effort to create "the ecosystem and standards needed for practical, trustworthy enterprise AI adoption." Translation: the company is positioning itself not just as a model provider but as a standard-setter for on-prem AI security tooling.

That's a reasonable bet. Enterprises will need local AI capabilities that comply with regional data laws, and whoever defines the integration patterns early gains influence. Whether Antares becomes the default depends on whether the community builds on it or waits for something better documented.

Also Read
CyrusOne eyes $5B IPO in 2027 as AI data center deals surge

Enterprise AI infrastructure is driving data center demand, relevant to teams planning on-prem AI deployments

ℹ️

Need Help Implementing This?

Logicity covers AI tooling for engineering and security teams. If your organization is evaluating on-prem AI scanning or building automated vulnerability workflows, reach out to discuss what's working in practice.

Source: TahawulTech.com / Daniel Shepherd

M

Manaal Khan

Tech & Innovation Writer

Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.