On the day Russia invaded Ukraine in 2022, operatives disabled thousands of satellite modems across Ukraine and other European countries. The malware is known as AcidRain, and it hit Viasat's network.

It remains one of the clearest examples of a cyber operation timed to a military one, and of civilian infrastructure being the thing that breaks.

Four years on, Viasat says it has spent the past year working with a company called Atalanta on a product named Argo, to validate that its network is now more resilient.

What is being claimed

Argo is described as an AI-assisted tool that combines mathematics with machine learning to analyse software and internet-connected systems for weaknesses more comprehensively than earlier approaches. Atalanta's chief executive, Anjana Rajan, frames the underlying capability as software understanding, and argues the tools and techniques of yesterday do not scale for today.

Viasat's Nick Saunders describes the outcome as a capability to develop an understanding of how their systems are more resilient against attacks, with mathematical backing behind the claim.

The Pentagon's chief technology officer, Emil Michael, has said he wants the underlying mathematics to become the Department of Defense's gold standard for cybersecurity.

What is actually behind the words

"Mathematical backing" is not marketing filler, and it is worth explaining because it is the substantive part.

Conventional security testing is empirical. You scan, you fuzz, you attack, and what you learn is that you did not find anything — which is different from there being nothing. Formal and mathematical methods aim at the other kind of statement: proving that a property holds for all inputs rather than the ones you tried.

That is a genuinely stronger claim when you can get it, and it is why defence agencies care. It is also expensive, historically limited to small critical components, and dependent on the model of the system being faithful to the system. The interest in AI here is about scale — using models to do the work of building and checking those representations across code bases too large to handle by hand.

What has not been published

Everything that would let anyone else evaluate it.

No vulnerability count. No description of what Argo examined or what it found. No statement of what property was proved, over what part of the system, under what assumptions. No independent review. The announcement contains an endorsement from a customer, an endorsement from a government official, and an ambition.

That is not an accusation. It is a description of the evidence available, and it is the same standard we applied to OpenAI publishing its own safety overhaul and to Anthropic's account of its evaluation incidents — a company's account of its own security work is worth reading and is not verification.

The contrast worth holding is the UK AI Security Institute publishing its own numbers on a model's cyber capability, methodology included, six days after the vendor's announcement. That is what an outside check looks like when somebody does one.

Why it still matters

Because the alternative framing — that satellite operators learned nothing from 2022 — is not true either, and the direction is right.

AcidRain worked because modems could be reached and wiped at scale. Any serious work on proving resilience properties of that estate is better than another year of penetration tests finding nothing in particular. If the mathematics is real, it is the correct approach.

The reasonable position is to want the result published.

What is not established

  • What Argo found. Nothing has been disclosed.
  • What was proved, and about what. No property, scope or assumption set has been stated.
  • Whether AI is central or incidental to the method.
  • Whether anyone outside Viasat and Atalanta has assessed it. No independent evaluation has been reported.