dArtBook a call
all news
Webpronews · May 30, 2026

Arm Opens Up AI Security Scanner That Finds Bugs Traditional Tools Miss

Webpronews
Arm Opens Up AI Security Scanner That Finds Bugs Traditional Tools Miss
May 30, 2026

Arm has released an open-source AI framework called Metis, designed to hunt down complex software vulnerabilities that conventional static analysis tools routinely overlook. The chipmaker’s product security team built the system to handle the tangled dependencies of modern codebases—where bugs often hide across multiple layers of frameworks, runtimes, and libraries.

Metis already scans over 130 internal Arm software projects, with full company-wide rollout expected by late 2026. The code is now available on GitHub under an Apache 2.0 license. In internal benchmarks, the framework delivered true positive rates up to 10 times higher than leading static analysis tools, while cutting false positives by roughly 50 percent. Those tests used datasets that avoided AI training contamination, meaning the results reflect genuine detection capability.

The system uses retrieval-augmented generation to build a custom knowledge base from source code, build files, and documentation. Large language models then reason over that context to review entire repositories, individual files, or pull requests. Unlike pattern-matching scanners, Metis constructs evidence chains and explains why a finding matters. It can validate its own results and those from external SAST tools. In one setup, it paired with OpenAI’s GPT-5.5-Cyber model to achieve a 98 percent detection rate for known vulnerabilities across 352 firmware and driver cases, compared to just 6 percent for traditional SAST.

Support spans C, C++, Python, Rust, Go, TypeScript, Solidity, Verilog, and more. A plugin system makes adding languages straightforward. Engineers use commands like index, review_code, or review_patch, and output includes clear explanations with suggested fixes. Configuration lives in YAML files, allowing teams to choose LLM providers, adjust prompts, or switch vector stores between ChromaDB and PostgreSQL with pgvector. Docker images simplify deployment, and the CLI works in interactive or non-interactive mode for CI pipelines.

Arm positioned the release as an industry contribution, noting that security problems don’t stop at one company’s walls. Early interest has come from partners eager to test Metis in their workflows. The project recently added Verilog support, with hardware vulnerability checks on the roadmap through ecosystem collaboration.

This launch comes as agentic AI gains traction in security teams. A recent Ivanti survey found 87 percent of security professionals now prioritize agentic AI adoption, and 77 percent are comfortable letting autonomous systems act without constant human review. Governance questions persist, but Metis itself serves defensive purposes—it scans code rather than acting in production environments. Its autonomous reasoning loops, tool use, and iterative validation mirror the systems now raising new risks, but Arm stresses that findings still need human oversight.

The framework won’t solve every security challenge. Complex logic, side channels, and supply-chain risks still demand human creativity. But for the daily grind of code review at scale, Metis hands teams a smarter assistant—one that reasons rather than just matches patterns. Engineers can start today by cloning the repo, setting an API key, indexing a codebase, and running a review. The docs walk through local models via Ollama or vLLM for those avoiding cloud services. Output formats include SARIF for integration with existing tools.

Source: Webpronews

Want a self-updating feed like this on your site?

dArt Studio installs AI for local businesses in Broward & Palm Beach County, FL. We reply within 1 business hour.