Cyber-capable AI now ships behind a vetting desk, not a price list

An electronic access control terminal mounted on a concrete wall in an industrial interior.

OpenAI has, for the first time, classified one of its own models as Critical for cyber capability under its Preparedness Framework — and shipped it anyway, with the exploit-finding capability reserved for vetted defenders. The threshold that was written to stop a release turned out to be a distribution setting.

That is not one company’s judgment call. Inside four days, OpenAI, Anthropic and Google each put their most cyber-capable model behind an application form rather than a price tier: Astra’s alpha and Daybreak Blue, Anthropic’s Cyber Verification Program, Google’s Fairwind. The shared reason is that the capability is now strong enough that the buyer’s identity is the last remaining control. For anyone running critical infrastructure — energy is named explicitly in Google’s eligibility list — that changes procurement. The best defensive tooling is becoming a credential you hold rather than a licence you buy.

The counterweight sits at the bottom of the market, where token prices closed at a record low and Google’s newest Flash undercuts the frontier roughly sixfold on cost per benchmark task. Capability is getting cheap; permission is getting expensive. And the Pentagon spent the same week working the same lever in reverse, keeping Anthropic off its portal over a designation a federal judge has just called unlawful. Watch whether the vetting programs stay genuinely open: 650 partners is either a large number or a very small one, depending on how many operators you think there are.


Path to Astra: critical capabilities and frontier safeguards

OpenAI · 1 September 2026 — Astra is the first model OpenAI has rated Critical for cyber under its Preparedness Framework, scoring 100% on ExploitBench and refusing 91.5% of cyber jailbreak attempts against 59% for GPT-5.6 Sol. Advanced cyber access starts with alpha testers and widens through the Daybreak Blue defender program.

Why it matters: A safety threshold has been converted into an access tier, which is a very different thing from a pause.

Introducing Claude Fable 5.1 and Claude Mythos 5.1

Anthropic · 1 September 2026 — The two releases are the same underlying model with different safeguard configurations. Fable 5.1 is generally available and more than doubles its predecessor on Terminal-Bench-Science, 52.6% against 24.7%; Mythos 5.1 is reachable only through Cyber Verification and Life Sciences Verification programs.

Why it matters: Identical weights sold through two doors makes the vetting process, not the model, the product boundary.

With Gemini 3.8 Flash, Google reminds everyone it’s still in the race

The Register · 2 September 2026 — Google’s fourth Flash model in four months scores 59 on the Artificial Analysis Intelligence Index at $0.75 per million input tokens, introductory pricing that doubles after the new year. A separate Gemini 3.8 Flash Cyber variant runs through the Fairwind program, which Google says has over 650 partners across government, healthcare, telecoms and energy.

Why it matters: The same company is racing to the bottom on commodity intelligence while walling off the cyber tier behind partner status.

The Pentagon now has its own version of ChatGPT and Grok

TechCrunch · 31 August 2026 — ChatGPT Mil and Grok for Government joined Gemini on the GenAI.mil portal, which has onboarded 1.7 million of the Department of Defense’s 3 million personnel. Anthropic remains absent, three days after Judge Rita Lin ruled the supply-chain risk designation against it unlawful, writing that “the empty invocation of national security is not a blank check”.

Why it matters: Buyers can gate vendors on access terms just as readily as labs gate customers — and a court loss has not yet reopened the portal.

AI model pricing is hitting record lows, squeezing revenue for frontier labs

Quartz · 1 September 2026 — Silicon Data’s LLM Token Expenditure Index closed at 97 cents per million tokens on Monday, less than half its summer peak and the lowest reading since the index launched in late 2025. When we covered the OVHcloud price rise two weeks ago, the divergence was directional; it now has a number on it.

Why it matters: If inference margin keeps compressing, gated tiers stop looking purely like safety policy and start looking like pricing power.


The number to watch is how many organisations actually clear these vetting programs over the next quarter. If the approved lists stay in the hundreds while attackers face no such queue, the defensive advantage these launches promise will be thinner than the announcements suggest.

Written by my AI assistant.

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.