OpenAI, Google, and Anthropic now sell frontier cyber as a gated product: Daybreak, Fairwind, Mythos. The public model is trained to refuse proof-of-concept exploits, malware analysis, and similar work. The trusted-access program is where those tasks are supposed to live.
What it does
OpenAI Daybreak is the named program for verified public and private defenders to use advanced AI on authorized cyber defense. Path to Astra (1 September) says Astra's most advanced cybersecurity capabilities start with a small tester group, then Daybreak Blue. The 3 September Astra post says the default model will refuse advanced tasks such as creating proof-of-concept exploits, and that Daybreak is how OpenAI plans to expand less-restrictive safeguards for vulnerability and proof-of-concept validation, malware analysis, and detection engineering. The same day's Frontline Defenders post splits the program: Daybreak Blue supports common defensive work with mainline models; Daybreak Red gives approved organizations specialized cyber models for more sensitive work. OpenAI says thousands of defenders across 2,000 approved organizations and workspaces already use Daybreak. Frontline Defenders adds a $1 billion commitment in subsidized Daybreak access, training, and support, targeted to be consumed over six months, plus a Daybreak Defense Network of more than 35 partner products and services, plus an MS-ISAC public-sector and water pilot. Those counts and the dollar figure are OpenAI's.
Google Fairwind, posted 2 September with Gemini 3.8 Flash Cyber, pairs that cyber model with the CodeMender harness for trusted Google Cloud customers, government agencies, and cybersecurity partners. Google says more than 650 participating partners globally. Participating organizations agree to limit access to internal cybersecurity, incident-response, or penetration-testing teams and to deploy multi-factor authentication. CodeMender on publicly available models remains available to any Google Cloud customer without Flash Cyber. Flash Cyber is the gated twin.
Anthropic's Fable 5.1 and Mythos 5.1 product pages (1 September) state they are the same underlying model with different safeguards. Fable is generally available and still routes many biology and cybersecurity queries to less capable Opus models. It can identify software vulnerabilities in source code and still blocks penetration testing, exploit generation, and binary-based vulnerability scanning on the general path. Mythos 5.1 is limited to vetted organizations through trusted access for cybersecurity and life sciences; Claude Security runs on Mythos 5.1. List price on both starts at $10 / $50 per million tokens. FedScoop on 9 September reported Teresa Carlson, Anthropic's global head of public sector, saying Fable 5.1 is on Claude for Government, including for agencies that require FedRAMP High, with Claude for Government Desktop (Claude Code and Cowork) headed toward general availability in coming weeks.
Why it is moving now
The same week OpenAI labeled Astra Critical, Google kept Flash Cyber inside Fairwind, and Anthropic kept Mythos behind Cyber Verification, OpenAI put a $1 billion subsidy on the defender side of the wall. Path to Astra says Astra was not in the Hugging Face incident and that OpenAI incorporated those learnings into Astra safeguards. The Frontline Defenders post frames the dollar commitment as a narrowing defender window, not as a post-mortem for any one breakout. Google's Fairwind post does not name Hugging Face. Three labs, three gates, one operator problem: the public picker is designed to refuse the work you actually need a named program for.
License + activity + maturity (demo | usable | production-shaped)
License: each lab's API and program terms, not an open-weight cyber model. Activity: Fairwind and Flash Cyber on 2 September; Daybreak Frontline Defenders and Astra on 3 September; Fable and Mythos 5.1 on 1 September; Carlson / Claude for Government on 9 September. Maturity: usable if you already have a named relationship (Daybreak workspace, Fairwind partner, Mythos trusted access, or FedRAMP High Claude for Government). Production-shaped only after you know which employees are allowed to call the gated model, how multi-factor authentication and logging work, and what happens when the general-path classifier blocks a legitimate defensive prompt. Demo: marketing that says "frontier cyber" without naming Blue versus Red, Fairwind versus public Flash, or Fable versus Mythos.
When to pick it vs the default alternative
Pick Daybreak when your team is a verified defender who needs Astra-class proof-of-concept and malware workflows OpenAI will not put on the public toggle, or when you are a U.S. essential-service operator who can actually consume subsidized access.
Pick Fairwind when you are already a Google Cloud or government cyber shop and want Flash Cyber plus CodeMender inside that boundary. Pick public CodeMender if you only need patch generation on non-Cyber models.
Pick Mythos 5.1 when Anthropic's Cyber Verification (or life-sciences) gate is the contract you can win. Pick Fable 5.1 when vulnerability identification in source is enough and exploit generation must stay blocked.
Pick Claude for Government when FedRAMP High is the actual requirement Carlson named, not when you only need the commercial Fable string.
Pick none of them when you are a general product team hoping the public ChatGPT, Gemini, or Claude picker grew a pentest mode. It is designed not to.
Failure modes
Applying to the wrong wall. Daybreak, Fairwind, and Mythos do not interoperate. A Fairwind partner is not a Daybreak organization.
Leaving the general model on for incident-response work and reading refusals as quality problems.
Treating OpenAI's $1 billion, 2,000 organizations, 35-plus products, Google's 650 partners, or Anthropic's FedRAMP High quote as your authorization. Those are program claims.
Assuming Fable on Claude for Government includes Mythos cyber. Carlson named Fable 5.1. Mythos remains a separate trusted-access path on the product pages.
Assuming production classifiers make unsafeguarded evaluation incidents impossible. Both labs' summer incidents ran with those classifiers off.
Links
- OpenAI — Daybreak for Frontline Defenders (3 Sep 2026): https://openai.com/index/daybreak-for-frontline-defenders/
- OpenAI — Path to Astra: https://openai.com/index/path-to-astra/
- OpenAI — GPT-6 Astra: https://openai.com/index/gpt-6-astra/
- Google — Fairwind Program: https://blog.google/innovation-and-ai/technology/safety-security/fairwind-program/
- Google — Gemini 3.8 Flash and Flash Cyber: https://blog.google/innovation-and-ai/models-and-research/gemini-models/3-8-flash-and-3-8-flash-cyber/
- Anthropic — Claude Fable: https://www.anthropic.com/claude/fable
- Anthropic — Claude Mythos: https://www.anthropic.com/claude/mythos
- FedScoop — Fable 5.1 on Claude for Government (9 Sep 2026): https://fedscoop.com/anthropic-adds-fable-claude-for-government-carlson/
Eligibility for any of the three programs is not something you can read off a blog post. You have to apply.