On September 2, 2026 Google launched the Fairwind Program, “a limited access program for governments and trusted partners to use our most advanced cyber defense capabilities,” with Gemini 3.8 Flash Cyber as its first model. It joins Anthropic’s Project Glasswing and Cyber Verification Program, through which Claude Mythos 5.1 is reaching “a set of US organizations” since September 1, and OpenAI’s Daybreak Access for “verified defenders.” Microsoft sells its cyber model inside a product, and Z.ai gates its open-weight model with a two-week delay rather than a form.
We have written about the trend twice, when government-gated releases became the pattern in June and when Google shipped its first gated Flash in July. What neither post has, and what a security lead or a policy reader needs on the day a new programme opens, is the table: every programme, in the vendor’s own words, side by side. That is this page, and it will be refreshed rather than re-written as programmes change.
- 01Three kinds of gate: vetted application, product purchase, and time delay.Google, Anthropic and OpenAI vet applicants. Microsoft delivers MAI-Cyber-1-Flash to MDASH customers with enterprise controls and describes no vetting. Z.ai released GLM-5.3’s weights to everyone after a two-week safety hold.
- 02Fairwind names three eligible groups and claims 650+ partners on day one.Governments and national cyber authorities, critical-infrastructure operators, and core technology platforms. Google says it background-checks applicants and requires access to be limited to internal security teams with MFA.
- 03Anthropic’s gate is currently US-only for Mythos 5.1.The CVP today covers Opus- and Sonnet-class models with reduced safeguards and will add Mythos-class “in the near future.” Mythos 5.1 access is limited to a set of US organisations while Anthropic coordinates expansion with the US government.
- 04Only two rows have a published price.Glasswing participants pay $25 and $125 per million tokens after $100M in credits, and Fable 5.1, whose safeguards moved instead of its gate, is $10 and $50 for everyone. Every other programme leaves price to the partner conversation.
01 — The datasetThe eligibility table.
| Programme | Model | Who is eligible (vendor wording) | Route in | What you get | Price | Source |
|---|---|---|---|---|---|---|
| Google · Fairwind Program | Gemini 3.8 Flash Cyber, with the CodeMender harness | “Governments and national cyber authorities,” “critical infrastructure operators” (healthcare, telecommunications, energy, financial networks) and “core technology platforms.” Google says it has more than 650 participating partners globally | Interest form; Google says it conducts background checks on applying organisations and reviews “eligible partners who meet our criteria.” Participants must limit access to internal security, incident-response or penetration-testing teams and use MFA | Early access to the Cyber model inside the partner’s secure cloud environment; non-members can use CodeMender with public models | Not published | blog.google and deepmind.google, Sep 2, 2026 |
| Anthropic · Cyber Verification Program (CVP) | Opus- and Sonnet-class models with reduced cyber safeguards today; Mythos-class models “in the near future” | “Vetted individuals and organizations whose work is affected by the cybersecurity … restrictions.” Mythos 5.1 access is “currently … only available to a set of US organizations,” with expansion coordinated with the US government | Application at Anthropic’s CVP portal | Reduced cyber safeguards for defensive security work; Mythos 5.1 is the same model as Fable 5.1 with more permissive safeguards | Standard model pricing; Mythos 5.1 pricing not separately published | anthropic.com Fable and Mythos 5.1 announcement, Sep 1, 2026 |
| Anthropic · Project Glasswing | Claude Mythos Preview (April); the Mythos line since | Named launch partners plus “over 40 additional organizations that build or maintain” critical software; open-source maintainers via Alpha-Omega, OpenSSF and the Apache Software Foundation | Invitation and partner onboarding; maintainers through the Linux Foundation and ASF grants | Mythos Preview for finding and fixing vulnerabilities in foundational systems, with $100M in usage credits across participants | $25 / $125 per million tokens for participants after the credits | anthropic.com/glasswing (April 2026) |
| Anthropic · general availability | Claude Fable 5.1 | Any API customer | None; the safeguards moved instead of the gate | Vulnerability discovery now permitted; exploit development, penetration testing and binary scanning still redirected. Anthropic expects about 60% fewer cyber-safeguard interventions per Claude Code session | $10 / $50 per million tokens | anthropic.com, Sep 1, 2026 |
| OpenAI · Daybreak and Daybreak Access | Daybreak models including Daybreak Red; Codex Security; GPT-5.6 Sol for defensive workflows | “Verified defenders,” through partners for most organisations. Daybreak Red is “specialized for advanced, authorized vulnerability research, exploit validation, penetration testing, and red teaming” | Daybreak Access form (“enterprise trusted access for cyber”), “pairing more capable and permissive defensive tools with stronger verification”; or working with a Daybreak partner | Frontier cyber capability in partner tools and workflows; Patch the Planet with Trail of Bits for open source ($17M credits, 41 codebases, 858 issues per OpenAI) | Not published for gated tiers | openai.com/daybreak, read Sep 3, 2026 |
| OpenAI · Astra (unreleased) | Astra, an upcoming model OpenAI says it “cannot rule out” reaching Critical cyber capability | Nobody outside OpenAI; internal activities not meeting strengthened controls are paused | None; OpenAI has applied its Preparedness Framework controls and universal monitoring internally | Not available | Not applicable | openai.com, “Responding to the next frontier of critical cyber capabilities” |
| Microsoft · MAI-Cyber-1-Flash inside MDASH | MAI-Cyber-1-Flash, routed with GPT-5.4 for the hardest tasks; Perception agent systems | MDASH customers. Microsoft’s post describes enterprise controls (role-based access, tenant isolation, sandboxed execution with no internet) rather than an application or vetting process | Commercial product access through MDASH | Vulnerability identification and remediation harness; Microsoft claims 96% on CyberGym for the combined system (vendor-run) at 50% of the cost of its previous offering | Not published as per-token pricing | microsoft.ai, updated Aug 13, 2026 |
| Z.ai · GLM-5.3 weights hold | GLM-5.3 (753B), open weights | Everyone, after a delay: Z.ai released the weights “two weeks after launch, once safety evaluation and hardening are complete” | None; time-gated rather than vetted. Weights landed Aug 28, 2026 | Open weights of a model Z.ai says is state of the art on CyberGym, with cyber capability that “developed faster than we expected” | Open weights under Z.ai’s own licence; hosted pricing varies | z.ai/blog/glm-5.3 |
02 — New rowFairwind, the new row.
Google’s programme is the most explicit about who it wants. The launch post, by Google’s Vice President for Security and Privacy, names three groups in priority order: governments and national cyber authorities, critical infrastructure operators across “healthcare, telecommunications, energy, and financial networks,” and core technology platforms whose software reaches “millions of downstream users at once.” The programme page adds that Google conducts background checks on applying organisations “to verify security history and analyze their record of ethical operations,” and that participants agree to limit access to internal cybersecurity, incident-response or penetration-testing staff and to deploy multi-factor authentication.
What members get is Gemini 3.8 Flash Cyber paired with CodeMender, Google’s find-verify-fix harness, inside the member’s own cloud environment. Google’s claims for the model, from the same day’s 3.8 Flash launch, are vendor-run: a success rate above 70% on an internal vulnerability-discovery benchmark across 20 languages, CWE-Bench pass@1 of 47.2% against 47.8% for “a leading frontier model,” 2.6 times more correct Chrome patches than “the best commercial models,” and Wiz’s report of 7.5 to 9.7 points more recall at 2.3 to 5.2 times lower cost. Non-members are pointed at CodeMender with public models. The claim of “more than 650 participating partners globally” on launch day is Google’s and is not itemised.
The general 3.8 Flash and the Cyber variant share one base model; what differs is the safeguard set and the gate. A reader choosing a Flash model needs the price and the benchmark. A reader deciding whether their organisation can get the Cyber variant needs this table. Keeping them apart is why each post says less than the launch post does.
03 — PatternThree kinds of gate.
Read down the “route in” column and the eight rows sort into three designs. The first is the vetted application: Google, Anthropic and OpenAI all take a form, check the organisation, and decide. They differ in who they say yes to. Google leads with governments and infrastructure. Anthropic’s CVP is for “vetted individuals and organizations whose work is affected by the cybersecurity restrictions,” and for Mythos 5.1 specifically that currently means US organisations, while Glasswing was built around named partners and open-source maintainers with $100M in credits. OpenAI’s Daybreak Access is for “verified defenders” and pushes most organisations toward a partner rather than direct access, with Patch the Planet as the open-source route.
The second design is the product. Microsoft’s MAI-Cyber-1-Flash is delivered inside MDASH, and the post describes tenant isolation, role-based access and sandboxes with no internet rather than an application; the gate is a contract. The third is the delay. Z.ai’s GLM-5.3 post said the weights would follow “two weeks after launch, once safety evaluation and hardening are complete,” because cyber capability “developed faster than we expected,” and they did. The open-weight answer to a dangerous capability is a fortnight, after which everyone is eligible. One row belongs to none of the three: OpenAI’s Astra is gated from everyone, including much of OpenAI, until its controls catch up.
04 — DecisionIf you are deciding whether to apply.
Most organisations reading this will not qualify for the vetted rows and should not assume they need to. The day these programmes opened, the generally available models moved too: Anthropic now permits vulnerability discovery on Fable 5.1 for any customer, and the curl result we covered the same day shows a specialised system on ordinary models out-finding a gated frontier scan on production code. The router below is how we would place an organisation against the table.
For the last group, which is most of our clients, the practical change this week is not a gate but a permission: the general Fable 5.1 will now look for vulnerabilities in your code. That is work our web development practice already runs with a human acceptance step, and the table above is what we check before telling a client that a gated model is, or is not, something they can get.
05 — MethodMethodology.
A collected census of access programmes, built from each vendor’s own programme page or announcement. Eligibility is quoted; capability claims are attributed to the vendor.
- What was collected
- For each programme through which a lab offers a model with reduced cyber safeguards: the model, the vendor’s eligibility wording, the route in, what a participant receives, published pricing, and the source with its date.
- Sources
- Google’s Fairwind Program blog post and programme page (Sep 2, 2026) and the Gemini 3.8 launch post; Anthropic’s Fable and Mythos 5.1 announcement (Sep 1, 2026) and Project Glasswing page; OpenAI’s Daybreak page and its Astra statement; Microsoft AI’s MAI-Cyber-1-Flash post (updated Aug 13, 2026); Z.ai’s GLM-5.3 post.
- As-of date
- Collected September 3, 2026. The page is dated September 2 for the Fairwind launch; this row is the only statement of the collection date.
- Exclusions
- Programmes for biology and life sciences, including Anthropic’s Life Sciences Verification Program, which are gated on different grounds. Export-control regimes, which gate by country rather than by programme. Vendor security products that do not involve a model with loosened safeguards.
- Known limitations
- Partner counts and capability figures are vendor-stated and not independently verified. Programmes change terms without notice; each row names its source for re-checking. Pricing for gated tiers is mostly unpublished and is recorded as such.
06 — ConclusionSame model, different door.
Five labs, three kinds of gate, two published prices. The capability is converging; the eligibility rules are not.
Fairwind makes it five labs with a named route to a cyber-capable model, and the routes could hardly differ more: a background check and three priority groups at Google, a US-only verification programme at Anthropic, a partner network at OpenAI, a product contract at Microsoft, and a two-week wait at Z.ai.
For the organisations these programmes name, the table is the application checklist. For everyone else, the news of the week is that the generally available models moved as well, and that one of the most audited codebases on the internet was just improved by a system nobody had to be vetted to use.