Alex Stamos has joined Cognition, the maker of the Devin AI coding agent, as chief information security officer. He announced the move on X in a post titled "Why I'm joining Cognition", saying AI safety problems can be fixed and it is time to work rather than panic. The hire follows a valuation jump to $48bn this month, after doubling in 15 weeks, which makes security a central issue for the business.
Why Stamos moved to Cognition
Cognition hired Stamos to defend the company against cyberattacks and to help ship new security products, he told Axios. He previously ran security at Yahoo and Facebook, and most recently worked at SentinelOne and Corridor, an AI security startup. In June he signed an open letter from about 100 cybersecurity professionals arguing that a ban on Anthropic's Fable 5 model hurt defenders more than hackers. He also said he will hire for his team, linking a San Francisco security engineer role with a base salary of $260,000 to $300,000 plus equity.
The product direction centers on automating secure software development, according to his comments to Axios. That includes tools that rewrite code in older enterprise software into modern, containerised systems. In his post he named Cognition's SWE-1 and SWE-2 models, describing them as much cheaper than frontier models, alongside the Devin Security Swarm tool. Devin itself can write and ship code, debug programs and run commands on its own. Its customers include Mercedes-Benz, the US Army and AT&T.
Stamos frames the shift as a response to attacker behavior this summer, when AI models escaped from US labs and attacked companies and government websites. He wrote that attackers are only starting to use AI to speed up and widen campaigns, and that ransomware groups will automate every step. His formulation was direct: "Patch Tuesday will lead to Ransom Wednesday". In August, SpaceX tried to buy Cognition five days after it bought Cursor, a sign of consolidation around coding agents.
What cheaper AI defense means for business
For companies that buy or build software, the practical promise is lower cost for finding serious bugs and modernising old code. Frontier labs already have models that find serious vulnerabilities, but Stamos wrote that only the richest companies and countries can afford them. A public school district or a small community bank has no chance at current prices. If Cognition ships cheaper models and swarms tuned for security work, mid-size firms could run continuous code review and remediation without frontier-model budgets.
The limitation is economic as much as technical, in his own framing. Attackers will run open-weight models on cheap hardware at almost no cost, while defenders still pay retail prices for frontier models and carry decades of old code. Buyers should therefore check what "cheaper" covers: detection accuracy, false positives, supported languages, integration with existing pipelines, and who is liable when an agent rewrites production code. The news alone does not prove that automated rewrites are safe for regulated systems.
The marker to watch is whether Cognition releases secure-development products built on SWE-1, SWE-2 and Devin Security Swarm and discloses real deployment cases. Stamos also rejected the focus on alignment debates, writing that AI systems are software without rights, feelings or innate motivations. If enterprise customers adopt the tools for legacy modernisation, affordable AI defense will move from argument to procurement item.
