Research hub · started 29 Aug 2026

Can you build a leading defensive AI cyber lab?

A ground-up map of the AI cybersecurity space — the companies, the models, the benchmarks, the money, the law — assembled to answer one question: is there a defensible position for a new lab that makes AI models good at defending code, and if so, what is the first thing to build?

$1B+
XBOW valuation, Mar 2026 — the category's price tag
86 / 68
% of AIxCC synthetic vulns found / patched by autonomous systems
0
C-language real-world bugs patched at AIxCC finals
~56%
of AI-generated code passing security checks (Veracode), flat YoY
<5%
of curl bug-bounty reports now valid, down from >15% (AI slop)
4–7 mo
open-weight lag behind frontier on cyber, per UK AISI

Every figure above is sourced on its page. Figures that did not survive fact-checking were removed and are recorded in the verification ledger.

Reading paths

This is a wiki, not a report. Enter wherever your question is.

If you have 20 minutes
Read the executive summary, then the three verdicts. That is the whole argument.
If you want to test the core premise
The thesis rests on frontier labs gating cyber models. Go straight to Access & gating — the evidence is more nuanced than the premise assumes, and it changes what you should build.
If you are deciding what to build first
If you are thinking about the model
Post-training playbook Data & moatsEconomics. The cost numbers are load-bearing.
If you are worried about the law
Germany, §202c and the Hackerparagraf is the one page a Berlin-based founder cannot skip. Then EU and US.
If you distrust any of this
Good. The verification ledger lists every claim that failed fact-checking, including several that other research passes asserted confidently and which turned out to be false.

Start here

The thesis, the verdicts, and how to read this.

Landscape

The map of the space and what is actually driving demand.

Players

Who exists, what they have raised, and what they can really do.

Technology

Models, benchmarks, open source, data, and how to train.

Access & law

Frontier-lab gating, EU and US regulation, dual-use risk.

Business

Buyers, pricing, gaps, economics, capital and talent.

Reference

Sources, verification ledger, glossary, open questions.