Never lose a customer to a missed message
An AI agent trained on your own business, replying in seconds, in any language, on every channel your customers already use.
Google, Anthropic and OpenAI have each rolled out specialized cyber AI models within weeks of one another, racing to put advanced vulnerability-hunting systems into the hands of defenders before attackers get equivalent tools. The near-simultaneous launches — Google’s Gemini 3.8 Flash Cyber, Anthropic’s Claude Fable 5.1 and Claude Mythos 5.1, and OpenAI’s Astra — mark the clearest signal yet that frontier AI labs now see cybersecurity as a distinct, high-stakes product category rather than a side feature.
Google’s Fairwind Program
Google launched its Fairwind Program on September 2, 2026, giving vetted organizations access to Gemini 3.8 Flash Cyber paired with CodeMender, a system built for vulnerability research and remediation, according to The Hacker News’ reporting. Access is currently limited to government agencies, Google Cloud customers and cybersecurity partners, with priority given to critical infrastructure operators, and more than 650 organizations — including CrowdStrike and Palo Alto Networks — are already participating, per Security Boulevard’s coverage. Google reports the model scores 86.2% on CyberGym vulnerability benchmarks, up from 77.5% for its predecessor, and participants must adopt controls like multifactor authentication and restrict access to security-focused staff.
Anthropic’s tiered safeguards
Anthropic released two models in the same window: Claude Fable 5.1, with expanded vulnerability-identification capabilities but offensive techniques like penetration testing and exploit generation restricted to its more capable Opus-tier models, and Claude Mythos 5.1, which remains locked to trusted-access programs focused specifically on cybersecurity and life-sciences work. Alongside the models, Anthropic introduced Enterprise Frontier Safeguards, combining zero data retention with what it describes as state-of-the-art misuse detection, and said it has increased monitoring for model misalignment and paused some external evaluations following unauthorized access incidents.
OpenAI’s threshold claim
OpenAI took a different tack, declaring that its Astra model meets the “critical cybersecurity capability threshold” under its own Preparedness Framework — effectively OpenAI’s internal classification for models capable enough to warrant the tightest controls. Astra is being distributed through a program called Daybreak Blue to selected testers only. OpenAI says the model declines 91.5% of jailbreak attempts and scored 100% on ExploitBench, a benchmark for vulnerability exploit development, while adding stronger safeguards against unauthorized model actions.
Why the labs are converging on the same moment
The timing is not entirely coincidental. All three labs frame these releases around the same tension: AI systems capable enough to find and patch vulnerabilities are, by construction, also capable of finding and exploiting them. Restricting access to vetted defenders first is each company’s attempt to get ahead of that dual-use problem, rather than release the capability broadly and hope attackers lag behind. The strategy also mirrors how each company has handled other high-risk capabilities, granting broader access only after a period of monitored use with trusted partners.
What this means for organizations without access yet
The vast majority of businesses and public bodies are not inside Fairwind, Daybreak Blue or Mythos 5.1’s trusted programs, and none of the three companies has committed to a firm timeline for when access will broaden. In the meantime, smaller organizations remain reliant on the general-purpose versions of these models and on existing vendor security tooling, which lack the specialized vulnerability-hunting depth their restricted counterparts offer — a gap that critics of the staged-rollout approach argue leaves under-resourced defenders exposed for longer, even as it slows the risk of the same capability reaching attackers.
What happens next
Expect access programs to widen gradually rather than open up all at once — Google’s Fairwind Program and OpenAI’s Daybreak Blue are both explicitly framed as trusted-tester stages, not general releases. The real test will be whether defenders’ adoption of these tools measurably reduces exploitation timelines industry-wide, or whether attackers gain access to comparable capability through leaked access, jailbreaks, or their own frontier models before that advantage compounds.
The benchmark numbers, in context
CyberGym and ExploitBench are both designed to simulate realistic vulnerability-hunting and exploit-development tasks rather than abstract test questions, which is why labs cite scores on them as evidence of real-world capability rather than marketing claims alone. Still, benchmark performance in a controlled test environment does not guarantee identical results against live, unpatched systems in the field, and independent security researchers have historically pushed back on vendor-reported benchmark figures until third parties can replicate them.
More tech coverage
Related reading: OpenAI’s rogue-agent incident on government websites, the chip-export loophole reaching Nvidia hardware into China, and Microsoft’s quiet reboot of Copilot.
AI cyber model questions answered
What is Google’s Fairwind Program?
A program launched September 2, 2026 giving vetted organizations — governments, Google Cloud customers and cybersecurity partners — access to Gemini 3.8 Flash Cyber, a model built to find and patch software vulnerabilities.
What’s the difference between Claude Fable 5.1 and Mythos 5.1?
Fable 5.1 has expanded vulnerability-identification abilities but restricts offensive techniques to Opus-tier models. Mythos 5.1 is more capable still and remains limited to trusted-access programs in cybersecurity and life sciences.
What did OpenAI claim about Astra?
That it meets the “critical cybersecurity capability threshold” under OpenAI’s Preparedness Framework, with a 91.5% jailbreak-decline rate and a perfect score on the ExploitBench vulnerability benchmark.
Who can access these models right now?
Access is restricted to vetted participants: Fairwind covers government agencies, Google Cloud customers and cybersecurity partners; Astra is limited to OpenAI’s Daybreak Blue testers; Mythos 5.1 is restricted to trusted cybersecurity and life-sciences programs.
Why are three labs launching similar products at once?
Each is responding to the same dual-use problem: models capable of finding and fixing vulnerabilities can also be used to find and exploit them, so all three are prioritizing vetted defenders before wider release.
Sources
- The Hacker News — Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs. https://thehackernews.com/2026/09/google-anthropic-and-openai-unveil.html
- Security Boulevard — Google Launches Fairwind Program for Gemini 3.8 Flash Cyber Access. https://securityboulevard.com/2026/09/google-launches-fairwind-program/
Verification your users actually receive.
Send one-time passcodes over WhatsApp with a single API call. Replio can generate, hash and verify the code for you.

