Cybersecurity
Cybersecurity is a problem of finding a few events that matter inside millions that do not.
A world model learns the normal dynamics of a system rather than matching each event against a static rule. It can ask:
- What is genuinely unusual here?
- Which apparently separate events belong to the same developing incident?
- What is likely to happen next?
- Where should an analyst or agent spend attention first?
- How does the forecast change under a possible response?
Current work
In one current evaluation, a model read 1.1 million events and surfaced the 250 most unusual at 94% accuracy. A frontier model cannot make a consistent comparison across an event history of that size in one context. The world model does the search; the frontier model can investigate the short list.
That is the shape of the system we want: the world model keeps track of the whole changing environment, while people and frontier models spend their time on the events that deserve judgment.
The detailed cybersecurity report is not public yet.
Where this goes
From unusual-event discovery, the model can grow into a living account of incidents, assets, identities and responses. Each new event updates the state. Each later outcome grades what the model expected. Over time, the system learns not only what looks strange, but what tends to matter.