Skip to content
All news
ChatGPT|Playbook··Abhishek Kapoor

Daybreak, Mythos, and Fairwind: how gated cyber access changes a ChatGPT, Claude, and Gemini shortlist

From 1 September through 3 September 2026, OpenAI, Anthropic, and Google each shipped a flagship and put the riskiest cyber work (and, for Anthropic, life-sciences work) behind a trusted-access program. Treat every vendor as two SKUs: the generally available model, and the defender-only variant.

Three locked access panels on a dark field, each marked for a different vendor cyber program, with a checklist beside an unlocked general-availability lane
Summarize this page with AI

A shortlist that still says “we will use ChatGPT, Claude, or Gemini for security work” is now incomplete. From 1 September through 3 September 2026, OpenAI, Anthropic, and Google each shipped a flagship. Each lab also put the riskiest cyber capabilities, and in Anthropic’s case the riskiest life-sciences capabilities, behind a named trusted-access program: Daybreak, Mythos verification, and Fairwind.

The procurement fact is simpler than the model names. You are no longer buying one assistant. You are buying a generally available SKU that will refuse or redirect dual-use work, and a defender-only SKU that requires identity checks, an authorized scope, and (often) a separate application that a contract does not guarantee. Some roundups also named Meta. We could not verify a primary Meta or Llama post in that window for a Muse Spark 1.3 cyber gate, so this piece does not invent one.

What the three labs shipped in that window

Read the dates as a cluster, not as three unrelated launches. The public model and the access program arrived together, which is why a feature matrix that only lists “coding quality” will mis-rank the stack.

Daybreak itself predates this cluster. OpenAI’s help article still defines the live tiers on GPT-5.6 Sol (Blue) and GPT-5.6 Cyber (Red). Astra is the new flagship. Daybreak is the gate. Do not collapse those into one line item. The Astra capability write-up covers the Critical designation. This post covers what a buyer should put on the order form.

The shared pattern: a public model and a defender-only variant

Each lab split one generation into two products. The public SKU keeps dual-use refusals, classifiers, or redirects. The gated SKU relaxes a subset of those controls for people the vendor has verified, on systems those people are authorized to test. Usage policies still apply. Approval is not a jailbreak license.

  • OpenAI Daybreak: Trusted Access for Cyber. Daybreak Blue uses GPT-5.6 Sol with more precise defensive safeguards. Daybreak Red uses GPT-5.6 Cyber for authorized pentest, red team, exploit validation, and controlled vulnerability research. Existing GPT-5.5-Cyber approval does not include Red.
  • Anthropic Mythos verification: Fable 5.1 and Mythos 5.1 share weights. Fable is generally available. Mythos relaxes cyber and life-sciences safeguards for vetted users through the Cyber Verification Program and the Life Sciences Verification Program. Anthropic says Mythos is currently limited to a set of US organizations.
  • Google Fairwind: Gemini 3.8 Flash is the workhorse. Gemini 3.8 Flash Cyber ships with more permissive cyber mitigations and is prioritized for governments, critical-infrastructure operators, and maintainers of widely used software.

OpenAI: Astra is Critical, and Daybreak is still a different SKU

OpenAI’s Path to Astra note and system card say GPT-6 Astra is the first model the company has designated Critical for cybersecurity under its Preparedness Framework. In OpenAI’s words, with the right tools and access the model can find previously unknown flaws and develop ways to exploit them across many well-protected systems without a person guiding each step.

That is why the launch post draws a hard product line. The version rolling out can do secure code review and patching. It will refuse more advanced cyber tasks such as creating proof-of-concept exploits. OpenAI says it plans to expand less restrictive safeguards through Daybreak in the coming weeks. Until that expansion is live on your tenant, Astra on ChatGPT is not your exploit-validation tool.

What Blue and Red actually provision today

OpenAI’s Daybreak overview is the SKU sheet. Blue is the recommended start for most security teams. Red needs extra approval, stronger verification, monitoring, and human oversight. Trusted Access does not remove all refusals, does not grant zero data retention by default, and does not allow resale, proxying, or customer-facing traffic on the same organization.

  • Blue (API alias `gpt-daybreak-blue-latest`, model `gpt-5.6-sol`): vulnerability triage, secure code review, malware analysis, detection engineering, incident response, and patch validation, on systems you own or are explicitly authorized to test.
  • Red (API alias `gpt-daybreak-red-latest`, model `gpt-5.6-cyber`): authorized pentest, red teaming, proof-of-concept exploit development, and exploit-chain validation. Separate approval. Not automatic if you already have Trusted Access or GPT-5.5-Cyber.
  • Astra caveat, from the same help article: reduced refusals are not available on Astra for most Daybreak customers. You can keep Astra with standard safeguards or switch to a model that supports Blue. In Codex signed in with ChatGPT, OpenAI documents a Daybreak toggle. An API key has no toggle.

Surfaces matter as much as model IDs. Astra is rolling out to a limited set of organizations first, then to ChatGPT Plus, Pro, Business, and Enterprise, plus the API and AWS. OpenAI says Enterprise administrators enable Astra and that access is off by default at launch. Extra safety checks can pause legitimate work. In ChatGPT or Codex the user may have to review an action. On the API, OpenAI says the task stops. OpenAI’s earlier Daybreak expansion note required individual Daybreak accounts to adopt hardware security keys beginning 1 September 2026.

Daybreak for Frontline Defenders is a separate offer on top of that gate: subsidized access, training, and support, starting with US operators of water, power, local government, community banks, nonprofits, and open-source projects. An interest form is not an approval. If your team is a well-funded product-security org, do not plan the budget as if you were a water utility.

Anthropic: same weights, two safeguard stacks, and customer-held monitoring data

Anthropic’s Fable and Mythos page is unusually plain: the two names are the same model with different safeguards. Fable 5.1 is generally available on Anthropic’s API and on AWS, Google Cloud, and Microsoft Azure as `claude-fable-5-1`. Mythos 5.1 is the permissive configuration for people whose work hits the cyber or life-sciences wall. The Fable and Mythos system card repeats that split.

Fable still covers a real defensive slice. Anthropic says Fable 5.1 may be used to identify software vulnerabilities, and that updated cyber safeguards produce about 60% fewer interventions per Claude Code session than the previous Fable 5 safeguards (company-reported). The same page says several dual-use tasks still redirect to Opus models: penetration testing, exploit generation, and binary-based vulnerability scanning. If your statement of work includes those three, Fable on the general Claude seat is the wrong line item.

  • Cyber Verification Program: Anthropic says CVP currently gives reduced cyber safeguards on certain Opus- and Sonnet-class models for defensive work, and that Mythos-class access is planned “in the near future.” Apply, then ask which model ID you will actually receive this quarter.
  • Life Sciences Verification Program: this is the extra gate the other two labs did not ship in this cluster. Anthropic says it enrolled first participants with the US government and will keep other safeguards in place. Biology research-and-development queries on Fable still go to Opus.
  • Claude Security: Anthropic says this Enterprise product, which scans codebases and suggests patches for human review, is now powered by Mythos 5.1. That is a constrained workflow, not a Mythos chat seat for your red team.

Enterprise Frontier Safeguards is the regulated-buyer counterpart to the model split. Anthropic will store monitoring data in cloud infrastructure the customer controls, send flags to the customer, and (by default) skip Anthropic human review. It says EFS will cover Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google’s Agent Platform, and Microsoft Foundry, rolling out in phases later this fall. Eligible customers get zero data retention on Fable 5 and 5.1 until EFS is ready. Anthropic does not charge for EFS. The cloud provider bills storage. Details and caveats sit in the Fable, Mythos, and EFS briefing.

Google: Flash for builders, Flash Cyber for Fairwind

Google’s 3.8 Flash announcement states that both variants share the same foundational intelligence. Gemini 3.8 Flash is the generally available workhorse: Google AI Studio and the Gemini API, Gemini Enterprise, Google AI Pro and Ultra, and Antigravity for agent-first coding. Introductory API pricing is $0.75 per million input tokens and $3.75 per million output tokens through 31 December 2026, then $1.50 and $7.50 (vendor-stated).

Gemini 3.8 Flash Cyber is the other SKU. Google says it ships with a more permissive set of cyber mitigations, so it is available only to trusted defenders through Fairwind. The company frames the model around autonomous vulnerability discovery and automated patching, and it says it prioritized fixing over offensive exploitation. Company-reported examples include Chrome Security producing 2.6 times more correct Chrome patches than larger commercial models it compared, and an internal multi-language discovery benchmark above 70% success. Treat those as vendor figures, then run your own repos. The Flash and Fairwind product note is the place for the scoreboard.

  • Fairwind initial staging, per Google: national cyber authorities, critical-infrastructure operators (healthcare, telecom, energy, finance), and core technology platforms whose software has many downstream users.
  • Operating rules participants accept: limit use to internal cybersecurity, incident-response, or penetration-testing staff, and deploy protections such as multi-factor authentication. Google reports more than 650 participating partners globally.
  • CodeMender split: Fairwind pairs Flash Cyber with the CodeMender harness for find, verify, and fix inside the customer’s cloud. Google also says any Google Cloud customer can run CodeMender with publicly available models on the Gemini Enterprise Agent Platform. That second path is the GA security option for teams that will not clear Fairwind.

Do not assume Antigravity inherits Flash Cyber because it sits on Gemini. Google’s get-started list sends developers to Antigravity for 3.8 Flash, and it sends cyber applicants to Fairwind. Score those as two boxes on the Gemini row.

How this changes the ChatGPT, Claude, Gemini, and agent shortlist

Keep one shortlist for knowledge work and coding. Keep a second for dual-use security and (if you are in life sciences) research biology. The first list can stay on general availability. The second list is a program application plus a workspace that must not serve customer-facing traffic.

  • ChatGPT: plan for Astra as the default flagship once your admin turns it on. Plan Daybreak as a separate internal-security workspace if you need reduced cyber refusals. Do not write “Astra plus our Enterprise contract” and assume Blue or Red.
  • Claude: Fable 5.1 is the GA seat, including vulnerability identification. Mythos is the verification seat, currently US-scoped, and CVP may hand you Opus or Sonnet reduced-safeguard access before Mythos-class IDs. Life-sciences teams should ask about LSVP by name.
  • Gemini: 3.8 Flash is the GA seat. Flash Cyber is Fairwind. If you are not a government, operator of essential services, or widely used platform maintainer, budget the public CodeMender path, not the Cyber model.
  • Claude Code: this is where Fable’s “identify, do not exploit” line will show up as fewer interrupts and as sudden Opus redirects. EFS, when it reaches you, is a Claude Code control as much as a chat control. Mythos inside Claude Code is not implied by a Team plan.
  • Google Antigravity: treat it as the Gemini agent IDE on Flash, useful for long-horizon coding. Fairwind does not automatically follow the repo into Antigravity.
  • OpenAI Codex: this is the surface with a documented Daybreak toggle for supported models when you are signed in with ChatGPT. Require auto-review (or an equivalent human gate) on any Daybreak-enabled project. Do not put Daybreak on the same organization that serves product API traffic.

Pair this split with the questions in our OWASP agentic vendor rubric. Gated access changes who is allowed to ask the model for an exploit chain. It does not change whether the agent that runs that chain has its own identity, a kill switch, or an exportable tool-call log. For scoring a proof rather than a slide, use the 2026 agent evaluation framework.

Run this checklist before you keep a vendor on the security row

Do this in order. The first unanswered item is the one that should block a “yes” on dual-use work.

  1. Write two columns for each vendor: generally available model ID, and gated model ID (or “none”). For OpenAI that is Astra versus `gpt-5.6-sol` / `gpt-5.6-cyber`. For Anthropic, `claude-fable-5-1` versus `claude-mythos-5-1` (or the Opus/Sonnet CVP IDs you are actually granted). For Google, Gemini 3.8 Flash versus Gemini 3.8 Flash Cyber.
  2. List the workflows you need in production language: secure review, vuln discovery, patch generation, malware analysis, pentest, proof-of-concept, exploit-chain validation, binary analysis, or (Anthropic only in this window) professional life-sciences R&D.
  3. Mark each workflow as allowed on the GA SKU, allowed only after approval, redirected to another model, or refused. Use the vendor’s current help page, not a launch keynote.
  4. Confirm eligibility: geography, sector, age (OpenAI individuals must be 18+), and whether the workspace can be reserved for internal security only. If you sell a product that embeds the model, assume Daybreak and Fairwind will say no.
  5. Name the product surface that will run the work: ChatGPT, Claude.ai, Gemini, Claude Code, Codex, Antigravity, API, Bedrock, Vertex, or Foundry. Ask whether the gated SKU exists on that surface this month.
  6. Get the data story in writing: Daybreak is not zero data retention. EFS stores monitoring data in your cloud and is not generally available yet. Fairwind work is meant to stay in your secure cloud environment. Record who sees flags: the vendor, your SOC, or both.
  7. Ask for a timed proof on a repo you own, with the exact model ID, effort level, and tool set you would buy. Score findings and patches with your staff, not with the vendor’s ExploitBench, CyberGym, or Terminal-Bench slide.
  8. Record identity and device controls: hardware security keys, multi-factor authentication, per-project Daybreak toggles, and whether contractors can sit on the approved workspace.
  9. Write the fallback if approval takes a quarter or never arrives: stay on Fable identification, Astra review and patching, or CodeMender with public Flash, and keep a human pentest retainer for the rest.
  10. Assign two owners: the person who files the access application, and the person who reviews agent actions when a monitor pauses a run. If both names are “the vendor,” you do not have a program.

Questions that separate a program from a brochure

Send these in writing. A specific answer names a model ID, a surface, and a date. A deflection talks about “frontier safety” and “trusted partners” without saying what your tenant can call on Monday.

  • Which exact model IDs and aliases will this workspace receive if our application is approved, and which IDs stay on standard refusals?
  • After approval, which dual-use tasks still refuse or redirect (OpenAI still applies leftover safeguards; Anthropic still redirects some work to Opus; Google still ships CBRN and cyber-offense safeguards on Flash)?
  • Is approval per organization, per project, per seat, or per individual? Does a Bedrock, Vertex, or Foundry listing match the first-party toggle?
  • What is the current median time from complete application to a yes or no, and what evidence do you want (authorization letter, scope, SOC contacts)?
  • Can we export tool-call traces and pause events to our SIEM, and who is paged when misalignment or abuse monitoring stops a job?
  • If you change the safeguard set on the gated SKU, how do you notify us, and do you version the behavior we tested?
  • Are we allowed to put this access in a managed-security offering for our customers? (OpenAI’s published answer is no, except through a separate partner path.)

When the written answers are in, open the ChatGPT, Claude, and Gemini profiles, add Claude Code, Antigravity, and Codex if those are the runtimes, and save two shortlists: GA coding, and gated defense. Re-open both when a lab moves a model across the gate.