Artemis launches Orion-1, a security model that commits to a decision
The model enters private preview inside Artemis' security platform, where customers set which responses it can take without human approval.
By RuntimeWire Staff · Published
Primary source: PR Newswire
Why it matters
Orion-1 makes Artemis' core bet explicit: security software can move from alert triage to decisions and responses, with customer-set limits on autonomy. Its benchmark results remain company-reported, and the private preview has yet to establish performance at scale.

Artemis Security co-founders Shachar Hirshberg and Dan Shiebler launched Orion-1 on October 8th, a foundation model designed to investigate security alerts across company systems and recommend or take action. It is available in private preview to selected customers through the Artemis platform, with broader availability to follow, according to the PR Newswire announcement.
The model is the founders' attempt to make their central product thesis concrete: security software should connect scattered signals into an account of what happened, then help resolve the incident. Hirshberg led product work at Amazon Web Services and Palo Alto Networks, including work connected to Demisto and AWS GuardDuty, according to Artemis' account of its founding. Shiebler led AI and machine learning at Abnormal AI after machine-learning roles at Twitter, where he says his team's work improved advertising systems. He completed a DPhil in artificial intelligence at Oxford while working full-time.
Orion-1 is designed to follow a signal across identity, cloud, email and other systems, assemble evidence, state its confidence, and recommend or trigger a response. Artemis gives the example of an Okta login, an AWS role assumption and a Google Workspace mailbox rule being interpreted as related activity by one actor.

A model built around the decision
Hirshberg's earlier description of Artemis focused on the gap between security teams' volume of telemetry and their ability to use it quickly. Orion-1 extends that strategy from the platform's environment-specific detections and investigation workflows into a model trained for the same defensive tasks. Artemis' announcement says its training scenarios draw on millions of defensive operations it has run, including investigations, threat hunts and incident response. Artemis says it did not use customer data to train the model.
Customers set autonomy by action type, from recommendations only to fully automated responses; high-impact actions require human approval by default. Artemis says each decision includes its supporting evidence and confidence, and that investigations and actions are logged. A model that can contain a threat could also interrupt legitimate work if it misreads a signal.
Artemis has put a new company-created benchmark, Decision-Grade Readiness, behind its performance claims. The benchmark is intended to test whether a senior security engineer would trust a model's decision enough to act on it. Artemis says it uses thousands of tasks with known outcomes, and gives each model the same trigger, environment context and scoped access to sources and actions.
In its announcement, Artemis says it tested Orion-1 against Claude Opus 5.5, GPT-6 Sol, Grok 4.7 and Kimi K3, and that Orion-1 scored highest on all five measured tasks. Its largest reported margin was in attack reconstruction: Orion-1 scored 80.8, compared with 58.3 for the best of the other models tested. The announcement does not explain the score scale or publish the task inventory, raw results or an independent evaluation. The benchmark reports Artemis' own comparison and offers no outside validation of the model's performance.

Artemis' announcement also cites its own security research, which says suspicious and malicious AI-enhanced activity rose 268% between April and August 2026. Artemis says 92% of confirmed attacks across the environments it defends were caught at the point of entry by detections tuned to those environments. The first figure describes a four-month change in activity observed by Artemis; the second applies to confirmed attacks within Artemis' customer environments. Neither figure establishes an industry-wide rate.
A product bet, not a general model release
Orion-1 is entering the market as part of an existing security operations product, not as a standalone model for developers to use. Its value depends on the platform's ability to connect signals to the customer environment and take actions under customer-defined limits. That makes customer adoption and operational reliability more consequential than a leaderboard result, particularly while access remains limited to a private preview.
On April 15th, 2026, the founders said Artemis was emerging from stealth with $70 million across seed and Series A funding. Felicis led the Series A, while First Round Capital and Brightmind Partners co-led the seed round; Theory VC and Lockstep also participated, according to Artemis' announcement. Orion-1 gives that investment a specific product direction: build a security platform that can move from detection to a confidence-rated decision and, where customers allow it, a response.
Artemis has not announced Orion-1 pricing, how many customers are in the preview or when access will expand. The test for Hirshberg and Shiebler is whether the model can connect evidence across tools, explain its conclusion and act in live security operations without creating a new source of risk.