Last updated: 22 September 2026
Would you give an external AI provider access to your company's private source code — including vulnerabilities that haven't been fixed yet?
For banks, governments, hospitals and other organisations handling sensitive systems, that can be a difficult trade-off.
Cybersecurity company Aikido Security is taking a different approach with Altar, a new open-weight AI model designed to run inside the infrastructure it is protecting.
Instead of sending code to a cloud AI service, an organisation can run the model on its own hardware — even inside an air-gapped network with no connection to the internet.
BUILT FOR CYBERSECURITY
Altar powers Aikido Machine, the company's autonomous penetration-testing system.
The system can examine applications for vulnerabilities and attempt to validate whether discovered weaknesses can actually be exploited.
That distinction matters.
Security scanners can produce large numbers of warnings. An AI system capable of investigating those findings further could help security teams identify which vulnerabilities represent genuine risks.
Aikido says Altar will support work including vulnerability research, code analysis and remediation.
HOW DID THEY MAKE IT SMALLER?
Altar is based on GLM-5.3, which Aikido says originally occupies about 1.51 TB.
Quantisation reduced that to 488 GB.
Aikido then used a technique called expert pruning to reduce it further to approximately 328 GB.
GLM-5.3 uses a mixture-of-experts architecture. Instead of using every part of the model for every task, different groups of specialised neural networks handle different inputs.
Aikido analysed which experts were most useful for cybersecurity workloads and removed less useful ones while trying to preserve the capabilities needed for security analysis.
The result is still enormous. Aikido recommends four NVIDIA H200 GPUs to run Altar comfortably, so this isn't "local AI" intended for an ordinary gaming PC.
Here, local means the AI runs inside the organisation's own infrastructure.
WHY THIS MATTERS
Cybersecurity may become one of the strongest use cases for privately hosted AI.
Source code, network architecture and unpatched vulnerabilities can reveal exactly how an organisation could be attacked.
Keeping that information inside the organisation removes one of the concerns associated with using external AI services for sensitive security work.
There is an important limitation, however: most performance claims currently come from Aikido itself. Independent testing will be important for determining how Altar compares with leading cloud AI models in real security assessments.
But the larger idea is worth watching. As AI models become more specialised, the future may not be only about sending everything to enormous cloud systems. Some of the most sensitive AI workloads may move in the opposite direction — back inside the organisations that own the data.
MicLinks Radar — Discover. Understand. Build.