Skip to content
All systems operational0 AI providers monitored, polled every 2 minutes
Live status
Back to Originals

Google's Fairwind Makes It Five Gated Cyber Models. The Change That Matters Happened on the Tier Nobody Has to Apply For.

Kira Nolan··7 min read
Security · Access Programs

Two days, three labs. On Tuesday, September 1, 2026, Anthropic shipped Claude Fable 5.1 and Claude Mythos 5.1, the second with heavier safeguards and a trusted-access gate in front of it. On Wednesday, September 2, Google announced Gemini 3.8 Flash Cyber and put it behind a brand new program called Fairwind, which it says already has more than 650 participating partners. The same Wednesday, OpenAI published its path-to-Astra post saying Astra meets the Critical cybersecurity capability threshold under its Preparedness Framework, and that its safeguards now sufficiently minimize the risk of severe harm for release.

Every outlet covered this as three product launches. It is one story, and the story is not the models. Five labs now ship a frontier model with the cyber safeguards loosened, and no two of them decide who gets it the same way. The gate has become the product.

What almost nobody covered is the row underneath the gates. In the same 48 hours, the tier with no application form moved further than any of the vetted ones.

The Census

ProgramModelGate designPublished price
Google FairwindGemini 3.8 Flash Cyber, with the CodeMender harnessVetted application. Background check on the organization, access restricted to internal security staff, MFA requiredNot published
Anthropic Cyber Verification ProgramOpus and Sonnet class today, Mythos class said to be comingVetted application. Mythos 5.1 currently limited to a set of US organizationsNot published
Anthropic Project GlasswingThe Mythos line, since AprilInvitation. Named partners plus maintainers via Alpha-Omega, OpenSSF and the ASF$25 / $125 per M after $100M credits
OpenAI Daybreak AccessDaybreak line including Daybreak Red, Codex Security, GPT-5.6 SolVetted application, but most organizations are routed through a partner rather than directNot published
Microsoft MDASHMAI-Cyber-1-Flash, routed with GPT-5.4 on hard tasksProduct contract. Tenant isolation and role-based access instead of vettingNot per token
Z.ai weights holdGLM-5.3, 753B, open weightsTime delay. Two weeks after launch, then everyone. Weights landed August 28Open weights
Anthropic general availabilityClaude Fable 5.1No gate. The safeguards moved instead$10 / $50 per M

Program and eligibility details are from each vendor's own announcement pages dated September 1 and 2, 2026, as collected by Digital Applied. Fable 5 list pricing is confirmed against our own models tracker at $10 in and $50 out.

Three Designs, Not Five

Read the gate column and the rows collapse into three patterns. The first is the vetted application: Google, Anthropic and OpenAI each take a form, check the applicant, and decide. They disagree on who gets a yes. Google leads with governments, national cyber authorities, critical infrastructure operators in healthcare, telecom, energy and financial networks, and what it calls core technology platforms. Anthropic's verification program is scoped to organizations whose work is blocked by the cyber restrictions, and for Mythos 5.1 specifically that currently means US organizations while expansion is coordinated with the US government. OpenAI wants verified defenders and mostly wants you to reach it through a partner.

The second design is a contract. Microsoft does not run a vetting program at all. It sells MAI-Cyber-1-Flash inside MDASH and describes tenant isolation, role-based access and sandboxes with no internet egress. The gate is a purchase order.

The third design is a timer. Z.ai said GLM-5.3's cyber capability developed faster than expected, held the weights for two weeks while it ran safety evaluation and hardening, and then published them. That happened on August 28. The open-weight answer to a dangerous capability is a fortnight, after which the eligibility criteria are: have a hard drive.

Three of these designs are attempts to allocate advantage to defenders. One of them is a countdown. They are all in the same market, and the countdown sets the ceiling on what the other two can achieve.

What a Refusal Costs, in Dollars

Two rows in that table have a published price, and putting them next to each other produces the most interesting number of the week.

Anthropic describes Mythos 5.1 as the same model as Fable 5.1 with more permissive safeguards. Not a different architecture, not a different training run that anyone has disclosed. Same base, different refusal policy. And it charges the same for both. Fable 5.1 and Mythos 5.1 sit on consecutive rows of Anthropic's own published pricing table at $10 per million input tokens and $50 per million output, the Mythos row marked limited availability and linked to Glasswing. Fable 5.1 is carried on our own pricing tracker at that rate; Mythos 5.1 is not, because a model nobody outside a vetted list can buy does not belong in a catalog agents route on. The gated tier carries no premium at all.

ModelInput per 1MOutput per 1MWho can buy
Claude Fable 5.1$10.00$50.00Any API customer
Claude Mythos 5.1$10.00$50.00Vetted organizations only
Ratio1.0x1.0xSame base model and the same rate, per Anthropic's own table

One number does circulate that looks like a premium, and it should not be read as one. Project Glasswing, the invitation-only program running the Mythos line since April, lists a participant rate of $25 in and $125 out once its $100 million in credits is exhausted. That is a program rate attached to a specific onboarding and support burden, not the list price of Mythos 5.1, and putting the two side by side to produce a 2.5x ratio compares a program to a price list. On the rate card itself, the gated model and the ungated model cost exactly the same.

That is a genuinely new pricing object. Every price premium in this industry so far has been paid for capability: more parameters, longer context, better benchmarks, lower latency. This one is paid for the absence of a refusal. The compute cost of not declining a request is zero. What you are buying is the vetting, the legal posture, and the indemnity of being on a list. Priced that way, the cyber tier is not an inference product at all. It is a compliance product with tokens attached.

The Row Under the Gates

Now the part the launch coverage skipped. While five labs were publishing eligibility criteria, the tier with no eligibility criteria got materially more capable at security work.

Anthropic now permits Fable 5.1 to identify software vulnerabilities. That is a permission change on a generally available model at list price, available to anyone with a card on file. The company reports roughly a 60 percent drop in cyber-safeguard interventions per Claude Code session, which is the honest way of saying the model used to refuse a lot of legitimate work and now mostly does not. Exploit generation, penetration testing and binary-based vulnerability scanning still get redirected to Opus-class models. The line is drawn between finding a bug and weaponizing one.

ChangeTierWho it reached
Gemini 3.8 Flash Cyber releasedGatedFairwind members, 650+ claimed partners, vendor-stated
Mythos 5.1 released with permissive safeguardsGatedA set of US organizations
Astra declared releasable under the Preparedness FrameworkGated, and not shippedNobody outside OpenAI yet
Fable 5.1 permitted to find vulnerabilitiesGenerally availableEvery Anthropic API customer, at list price, on day one
GLM-5.3 weights published after the holdOpenAnyone, permanently, no revocation path

Count the reach. Three rows went to hundreds of organizations that had to prove who they were. Two rows went to everyone. A background check applied to the top of a distribution does not do much when the middle of the distribution moved on the same day and the bottom is a torrent.

Astra Let Go of the Brake

One row deserves its own paragraph because it closes a loop we opened four weeks ago. In August, OpenAI became the first lab to pause a model at the top tier of its own risk framework, saying it could not rule out critical cyber capabilities in Astra. Wednesday's post upgrades that hedge into a finding. Astra meets the Critical threshold. It scores 100 percent on ExploitBench for developing exploits from known vulnerabilities. During evaluation it discovered and chained two zero-days in unspecified software, built a full browser compromise that escapes the sandbox and executes commands on the host when an HTML file is opened, and combined multiple flaws in a hardened operating system into a privilege escalation chain from unprivileged user to root.

The safety number in the same post: Astra declines 91.5 percent of jailbreaking requests against 59 percent for GPT-5.6 Sol. That is a real improvement and it is also a refusal rate on the most capable offensive system anyone has described, which means roughly one in twelve attempts gets through. OpenAI also warns, in its own words, that Astra's safeguards may erroneously flag legitimate activity as cyber misuse. Both failure directions are now documented by the vendor before the model has a price.

The brake held for four weeks and then the same company that pulled it decided it was safe to let go. That is what a self-administered framework looks like when it works, and it is also what one looks like when it does not. There is still no external referee. The federal launch bar that was supposed to land August 1 has not.

Three Objections

The gates were never meant to stop attackers. This is the strongest argument against everything above, and we concede most of it. The stated purpose of Fairwind is to give defenders an early advantage, not to deny anyone capability. Nobody at Google thinks a background check stops a state actor. The theory is that defenders and attackers both get powerful tools eventually, so you hand the defenders theirs first and let them burn down the backlog. Judged on that theory the programs are reasonable. Our answer is that the theory only works if the lead time is real, and a two-week weights hold at one lab plus a same-day permission change at another compresses the lead time to something close to nothing. You cannot run a defender-advantage strategy on a head start you are simultaneously giving away.

Finding a bug is not exploiting one. Correct, and the GA permission is narrower than the headline suggests: Fable 5.1 can identify vulnerabilities, and pen testing, exploit generation and binary scanning still route elsewhere. The counter is that the discovery half is the expensive half. Writing an exploit for a known memory-safety bug in a known target is well-trodden engineering. Finding the bug in a million lines nobody has audited is the part that used to require a specialist and a month. That is the half that just got cheaper for everybody.

Every number in this story is vendor-run. Also true, and worth saying loudly. The 650 partner count is Google's and is not itemized. The 100 percent ExploitBench score, the 91.5 percent refusal rate, the 60 percent reduction in safeguard interventions, the CWE-Bench and CyberGym figures are all produced by the companies selling the models, on evaluations they chose. Not one of the capability claims in the last 48 hours has been independently reproduced. Anthropic, for its part, disclosed that it has paused external cyber evaluations of pre-release models after unauthorized access incidents, which means the one channel that might have produced third-party numbers is currently closed.

Our Take

The cyber tier spent 2026 being covered as a governance story: who is trusted, who decides, what the criteria are. The pricing table is the flattest possible answer to all of it. Anthropic put $10 and $50 on the model that will not write exploits, and $10 and $50 on the model with the safeguards relaxed, for weights the vendor says are otherwise the same. Nobody is charging for the permission. Whatever the gate is doing, it is not being monetized, which means it is not being treated as a scarce good by the only party in a position to price it. A company that believed the relaxed tier was worth more would have said so on the rate card, and it had the opportunity to, on the same table, one row apart.

The larger read is that gating is converging on ceremony. Five labs, five different doors, elaborate criteria at three of them, and the actual distribution of cyber capability this week was determined by a permission flag on a generally available model and a fourteen-day timer on a 753 billion parameter weights drop. If you are a security lead deciding whether to apply to Fairwind or the verification program, the answer is probably still yes, because the harness and the support are real. But do not let the application queue convince you the capability is scarce. It is not scarce. It is $10 in and $50 out, and your adversary did not fill in a form.

Three signposts. First, whether the Mythos 5.1 row ever moves off the Fable 5.1 rate, because the day a lab charges more for the same weights with the guardrails set differently is the day a permission becomes a product, and everyone else will index to whatever number it picks. Second, whether any lab publishes an eligibility rejection rate, since a vetting program that approves 650 partners in one day and has never said no is a registration desk wearing a security badge. Third, whether the next open-weight release from any lab ships with a hold longer than two weeks, because the fortnight is currently the shortest gate in the census and it is the one that sets the clock for all the others.