AI DevelopmentFramework6 min readPublished September 2, 2026

The model is the same. The gate is the product.

Who Gets the Cyber AI Models: Every Vetting Programme Listed

Every major lab now ships a version of its frontier model with the cyber safeguards loosened, and every one of them gates it differently. Google’s Fairwind Program, launched September 2, is the newest. This table lists each programme in the vendor’s own eligibility wording, with the route in, what you get and what it costs.

DA
Digital Applied Team
Senior strategists · Published Sep 2, 2026
PublishedSep 2, 2026
Read time6 min
As ofSep 3, 2026
Programmes in the table
8
across Google, Anthropic, OpenAI, Microsoft and Z.ai
Fairwind partners at launch
650+
“participating partners globally,” per Google, Sep 2
Glasswing usage credits
$100M
then $25 / $125 per M for participants, per Anthropic
Programmes with a published price
2
Glasswing after credits, and Fable 5.1 at list; the rest do not say

On September 2, 2026 Google launched the Fairwind Program, “a limited access program for governments and trusted partners to use our most advanced cyber defense capabilities,” with Gemini 3.8 Flash Cyber as its first model. It joins Anthropic’s Project Glasswing and Cyber Verification Program, through which Claude Mythos 5.1 is reaching “a set of US organizations” since September 1, and OpenAI’s Daybreak Access for “verified defenders.” Microsoft sells its cyber model inside a product, and Z.ai gates its open-weight model with a two-week delay rather than a form.

We have written about the trend twice, when government-gated releases became the pattern in June and when Google shipped its first gated Flash in July. What neither post has, and what a security lead or a policy reader needs on the day a new programme opens, is the table: every programme, in the vendor’s own words, side by side. That is this page, and it will be refreshed rather than re-written as programmes change.

Key takeaways
  1. 01
    Three kinds of gate: vetted application, product purchase, and time delay.Google, Anthropic and OpenAI vet applicants. Microsoft delivers MAI-Cyber-1-Flash to MDASH customers with enterprise controls and describes no vetting. Z.ai released GLM-5.3’s weights to everyone after a two-week safety hold.
  2. 02
    Fairwind names three eligible groups and claims 650+ partners on day one.Governments and national cyber authorities, critical-infrastructure operators, and core technology platforms. Google says it background-checks applicants and requires access to be limited to internal security teams with MFA.
  3. 03
    Anthropic’s gate is currently US-only for Mythos 5.1.The CVP today covers Opus- and Sonnet-class models with reduced safeguards and will add Mythos-class “in the near future.” Mythos 5.1 access is limited to a set of US organisations while Anthropic coordinates expansion with the US government.
  4. 04
    Only two rows have a published price.Glasswing participants pay $25 and $125 per million tokens after $100M in credits, and Fable 5.1, whose safeguards moved instead of its gate, is $10 and $50 for everyone. Every other programme leaves price to the partner conversation.

01The datasetThe eligibility table.

Access programmes for AI models with reduced cyber safeguards, as of September 3, 2026. Eligibility and route text is quoted or closely paraphrased from each vendor’s page; capability claims in the “what you get” column are the vendor’s own.
ProgrammeModelWho is eligible (vendor wording)Route inWhat you getPriceSource
Google · Fairwind ProgramGemini 3.8 Flash Cyber, with the CodeMender harness“Governments and national cyber authorities,” “critical infrastructure operators” (healthcare, telecommunications, energy, financial networks) and “core technology platforms.” Google says it has more than 650 participating partners globallyInterest form; Google says it conducts background checks on applying organisations and reviews “eligible partners who meet our criteria.” Participants must limit access to internal security, incident-response or penetration-testing teams and use MFAEarly access to the Cyber model inside the partner’s secure cloud environment; non-members can use CodeMender with public modelsNot publishedblog.google and deepmind.google, Sep 2, 2026
Anthropic · Cyber Verification Program (CVP)Opus- and Sonnet-class models with reduced cyber safeguards today; Mythos-class models “in the near future”“Vetted individuals and organizations whose work is affected by the cybersecurity … restrictions.” Mythos 5.1 access is “currently … only available to a set of US organizations,” with expansion coordinated with the US governmentApplication at Anthropic’s CVP portalReduced cyber safeguards for defensive security work; Mythos 5.1 is the same model as Fable 5.1 with more permissive safeguardsStandard model pricing; Mythos 5.1 pricing not separately publishedanthropic.com Fable and Mythos 5.1 announcement, Sep 1, 2026
Anthropic · Project GlasswingClaude Mythos Preview (April); the Mythos line sinceNamed launch partners plus “over 40 additional organizations that build or maintain” critical software; open-source maintainers via Alpha-Omega, OpenSSF and the Apache Software FoundationInvitation and partner onboarding; maintainers through the Linux Foundation and ASF grantsMythos Preview for finding and fixing vulnerabilities in foundational systems, with $100M in usage credits across participants$25 / $125 per million tokens for participants after the creditsanthropic.com/glasswing (April 2026)
Anthropic · general availabilityClaude Fable 5.1Any API customerNone; the safeguards moved instead of the gateVulnerability discovery now permitted; exploit development, penetration testing and binary scanning still redirected. Anthropic expects about 60% fewer cyber-safeguard interventions per Claude Code session$10 / $50 per million tokensanthropic.com, Sep 1, 2026
OpenAI · Daybreak and Daybreak AccessDaybreak models including Daybreak Red; Codex Security; GPT-5.6 Sol for defensive workflows“Verified defenders,” through partners for most organisations. Daybreak Red is “specialized for advanced, authorized vulnerability research, exploit validation, penetration testing, and red teaming”Daybreak Access form (“enterprise trusted access for cyber”), “pairing more capable and permissive defensive tools with stronger verification”; or working with a Daybreak partnerFrontier cyber capability in partner tools and workflows; Patch the Planet with Trail of Bits for open source ($17M credits, 41 codebases, 858 issues per OpenAI)Not published for gated tiersopenai.com/daybreak, read Sep 3, 2026
OpenAI · Astra (unreleased)Astra, an upcoming model OpenAI says it “cannot rule out” reaching Critical cyber capabilityNobody outside OpenAI; internal activities not meeting strengthened controls are pausedNone; OpenAI has applied its Preparedness Framework controls and universal monitoring internallyNot availableNot applicableopenai.com, “Responding to the next frontier of critical cyber capabilities”
Microsoft · MAI-Cyber-1-Flash inside MDASHMAI-Cyber-1-Flash, routed with GPT-5.4 for the hardest tasks; Perception agent systemsMDASH customers. Microsoft’s post describes enterprise controls (role-based access, tenant isolation, sandboxed execution with no internet) rather than an application or vetting processCommercial product access through MDASHVulnerability identification and remediation harness; Microsoft claims 96% on CyberGym for the combined system (vendor-run) at 50% of the cost of its previous offeringNot published as per-token pricingmicrosoft.ai, updated Aug 13, 2026
Z.ai · GLM-5.3 weights holdGLM-5.3 (753B), open weightsEveryone, after a delay: Z.ai released the weights “two weeks after launch, once safety evaluation and hardening are complete”None; time-gated rather than vetted. Weights landed Aug 28, 2026Open weights of a model Z.ai says is state of the art on CyberGym, with cyber capability that “developed faster than we expected”Open weights under Z.ai’s own licence; hosted pricing variesz.ai/blog/glm-5.3

02New rowFairwind, the new row.

Google’s programme is the most explicit about who it wants. The launch post, by Google’s Vice President for Security and Privacy, names three groups in priority order: governments and national cyber authorities, critical infrastructure operators across “healthcare, telecommunications, energy, and financial networks,” and core technology platforms whose software reaches “millions of downstream users at once.” The programme page adds that Google conducts background checks on applying organisations “to verify security history and analyze their record of ethical operations,” and that participants agree to limit access to internal cybersecurity, incident-response or penetration-testing staff and to deploy multi-factor authentication.

What members get is Gemini 3.8 Flash Cyber paired with CodeMender, Google’s find-verify-fix harness, inside the member’s own cloud environment. Google’s claims for the model, from the same day’s 3.8 Flash launch, are vendor-run: a success rate above 70% on an internal vulnerability-discovery benchmark across 20 languages, CWE-Bench pass@1 of 47.2% against 47.8% for “a leading frontier model,” 2.6 times more correct Chrome patches than “the best commercial models,” and Wiz’s report of 7.5 to 9.7 points more recall at 2.3 to 5.2 times lower cost. Non-members are pointed at CodeMender with public models. The claim of “more than 650 participating partners globally” on launch day is Google’s and is not itemised.

Why 3.8 Flash Cyber is here and not in the 3.8 Flash post

The general 3.8 Flash and the Cyber variant share one base model; what differs is the safeguard set and the gate. A reader choosing a Flash model needs the price and the benchmark. A reader deciding whether their organisation can get the Cyber variant needs this table. Keeping them apart is why each post says less than the launch post does.

03PatternThree kinds of gate.

Read down the “route in” column and the eight rows sort into three designs. The first is the vetted application: Google, Anthropic and OpenAI all take a form, check the organisation, and decide. They differ in who they say yes to. Google leads with governments and infrastructure. Anthropic’s CVP is for “vetted individuals and organizations whose work is affected by the cybersecurity restrictions,” and for Mythos 5.1 specifically that currently means US organisations, while Glasswing was built around named partners and open-source maintainers with $100M in credits. OpenAI’s Daybreak Access is for “verified defenders” and pushes most organisations toward a partner rather than direct access, with Patch the Planet as the open-source route.

The second design is the product. Microsoft’s MAI-Cyber-1-Flash is delivered inside MDASH, and the post describes tenant isolation, role-based access and sandboxes with no internet rather than an application; the gate is a contract. The third is the delay. Z.ai’s GLM-5.3 post said the weights would follow “two weeks after launch, once safety evaluation and hardening are complete,” because cyber capability “developed faster than we expected,” and they did. The open-weight answer to a dangerous capability is a fortnight, after which everyone is eligible. One row belongs to none of the three: OpenAI’s Astra is gated from everyone, including much of OpenAI, until its controls catch up.

04DecisionIf you are deciding whether to apply.

Most organisations reading this will not qualify for the vetted rows and should not assume they need to. The day these programmes opened, the generally available models moved too: Anthropic now permits vulnerability discovery on Fable 5.1 for any customer, and the curl result we covered the same day shows a specialised system on ordinary models out-finding a gated frontier scan on production code. The router below is how we would place an organisation against the table.

A government body, national cyber authority or critical-infrastructure operator
Apply to Fairwind and Anthropic’s CVP; you are the named audience for both. Expect background checks, an internal-team-only access rule and MFA at Google, and US-only Mythos access at Anthropic for now.
Fairwind + CVP
A widely used software platform or an open-source maintainer
Google’s third Fairwind group is “core technology platforms.” Anthropic routes maintainers through Alpha-Omega, OpenSSF and the ASF; OpenAI through Patch the Planet with Trail of Bits. Apply to the one whose model you already run.
Platform routes
A security vendor or consultancy
Daybreak is built around partners, and Google says its partner list includes cybersecurity firms. Being the partner is the access. Microsoft’s route is being an MDASH customer.
Partner programmes
Everyone else with code to secure
Use the generally available tier: Fable 5.1 with vulnerability discovery now permitted, CodeMender with public Gemini models, Codex Security, or a specialised analyzer. Judge them by findings your reviewers accept, and revisit this table when a programme widens.
GA models + review

For the last group, which is most of our clients, the practical change this week is not a gate but a permission: the general Fable 5.1 will now look for vulnerabilities in your code. That is work our web development practice already runs with a human acceptance step, and the table above is what we check before telling a client that a gated model is, or is not, something they can get.

05MethodMethodology.

Methodology

A collected census of access programmes, built from each vendor’s own programme page or announcement. Eligibility is quoted; capability claims are attributed to the vendor.

What was collected
For each programme through which a lab offers a model with reduced cyber safeguards: the model, the vendor’s eligibility wording, the route in, what a participant receives, published pricing, and the source with its date.
Sources
Google’s Fairwind Program blog post and programme page (Sep 2, 2026) and the Gemini 3.8 launch post; Anthropic’s Fable and Mythos 5.1 announcement (Sep 1, 2026) and Project Glasswing page; OpenAI’s Daybreak page and its Astra statement; Microsoft AI’s MAI-Cyber-1-Flash post (updated Aug 13, 2026); Z.ai’s GLM-5.3 post.
As-of date
Collected September 3, 2026. The page is dated September 2 for the Fairwind launch; this row is the only statement of the collection date.
Exclusions
Programmes for biology and life sciences, including Anthropic’s Life Sciences Verification Program, which are gated on different grounds. Export-control regimes, which gate by country rather than by programme. Vendor security products that do not involve a model with loosened safeguards.
Known limitations
Partner counts and capability figures are vendor-stated and not independently verified. Programmes change terms without notice; each row names its source for re-checking. Pricing for gated tiers is mostly unpublished and is recorded as such.

06ConclusionSame model, different door.

Vetting census

Five labs, three kinds of gate, two published prices. The capability is converging; the eligibility rules are not.

Fairwind makes it five labs with a named route to a cyber-capable model, and the routes could hardly differ more: a background check and three priority groups at Google, a US-only verification programme at Anthropic, a partner network at OpenAI, a product contract at Microsoft, and a two-week wait at Z.ai.

For the organisations these programmes name, the table is the application checklist. For everyone else, the news of the week is that the generally available models moved as well, and that one of the most audited codebases on the internet was just improved by a system nobody had to be vetted to use.

Access, or the alternative

Know which door is yours.

We check this table before advising a client on gated-model access, and we run the generally available models with a human acceptance gate for everyone the programmes do not name.

Free consultationExpert guidanceTailored solutions
What we work on

AI security engagements

  • Eligibility review against every lab’s programme
  • AI vulnerability discovery with reviewer acceptance
  • Tool trials scored on accepted findings
  • Safeguard-aware model selection for security work
  • Disclosure and patch workflows for client code
FAQ · Cyber model access

The questions we get about gated cyber models.

Google prioritises governments and national cyber authorities, critical infrastructure operators in healthcare, telecommunications, energy and financial networks, and core technology platforms. Applicants complete an interest form, Google conducts background checks on the organisation, and participants must restrict access to internal security teams and use multi-factor authentication. Google says more than 650 partners participate.
Related dispatches

Continue exploring AI security and access.

AI Development

AI Model Releases: September 2026 Tracker and Dated Ledger

A dated ledger of AI model releases in September 2026, each row verified against the vendor’s announcement, with price, context and what it replaces.

September 2, 2026 · 5 minRead
AI Development

Why an AI’s Reasoning Can’t Follow You to Another Model

Anthropic, OpenAI and Google now bind a model’s reasoning to the model that produced it. What each locks, what breaks on a switch, and how a router copes.

September 2, 2026 · 7 minRead
AI Development

A Startup’s AI Found Six curl Bugs Where Mythos Found None

curl’s maintainer posted that Mythos and Codex Security had nothing left to find. Days later AISLE filed 29 reports; six became Low CVEs in curl 8.22.0.

September 2, 2026 · 8 minRead
AI Development

Agent Frameworks That Rewrite History Now Break on Fable 5.1

Claude Fable 5.1 rejects a thinking block if anything before it changed. A census of ten agent frameworks: which trim, summarise or rebuild history, plus fixes.

September 2, 2026 · 8 minRead
AI Development

AI Finds Decades-Old Bugs: GLM-5.3 Disclosure Ledger

A vendor-published disclosure ledger reports thousands of findings across hundreds of open-source projects. What maintainers and security teams should check.

August 15, 2026 · 13 minRead
AI Development

Preview, Beta, GA: What Vendors Said vs What Coverage Said

Thirty-six AI vendor announcements from 17-22 August 2026, each scored on the vendor's own status word against the word its coverage used, where located.

August 22, 2026 · 27 minRead