Anthropic, Google, and OpenAI Launch Paid Tiers for Cybersecurity AI Concurrently

The three companies released AI models for security in restricted access programs in the same week. This marks the monetization of a vertical that was confined to research reports until 2025.
Three Releases in the Same Window
In just over a week, three frontier model manufacturers confirmed paid tiers of AI focused on cybersecurity. Anthropic released Claude Mythos 5.1 on September 1, in a restricted access channel for regulated clients. OpenAI announced GPT-6 Astra, made available on September 3, as the first model to surpass its own internal threshold of Critical for offensive use, and on the same day expanded Daybreak with Blue and Red tracks, each enabling access to versions of GPT-5.6 Cyber. Google joined the queue with Gemini 3.8 Flash Cyber, published in the trusted defenders program with a self-discovery score for vulnerability that, according to the company, outperforms Mythos 5 and GPT-5.6 Sol in internal benchmarks.
The Emerging Market Standard
What concerns the CIO is not the benchmark; it is the sales format. All three releases are behind a gate: restricted access contract, buyer KYC, country restrictions, and in the case of Daybreak Red, mandatory validation of intended use. This is the first generation of frontier models where the list price for the cyber version is not yet public, and where the right to use is stamped in the contract.
Anthropic explained the logic when publishing the design of the Enterprise Frontier Safeguards involving Mythos 5.1: the stated goal is to avoid storing prompts or transcripts on the vendor's servers while retaining the ability to detect misuse between sessions. This design addresses regulated clients who could not activate the standard model without legal review of data leakage.
The Less Obvious Reading
The easy interpretation is to say that AI has finally fit into the security budget. The trajectory of recent years has shown the opposite. Generative AI tools entered the enterprise through Copilot, Slack, Notion, and browser, bypassing the CISO. What changes now is not the arrival of AI in security; it is the opposite. Security has become a product vertical, with its own SKU, access restrictions, and auditing SLAs. This is the first time Anthropic, Google, and OpenAI compete on the same paid shelf, with matched value promises and different contractual guarantees.
The signal also merits a contrary reading. A more capable model in cybersecurity does not inherently change the company's exposure surface. If the purchasing organization does not have an updated inventory of what the agent will see, the paid tier becomes a traffic license rather than a defense platform. Recent incident response reports indicate that the detection bottleneck has little to do with the model's capabilities and much to do with log integration, identity control, and EDR coverage on critical hosts.
The other side also needs to show up. Recent analyses of intrusion traffic indicate that offensive volume with the assistance of automation has consistently grown throughout 2026, although the jump is smaller than the last round of venture investments suggested. There is a gap between automated offensive volume and human defensive capability, and it is not hypothetical.
Where the SKU Lands Outside the U.S.
The impact of the new tier arrives at different paces by region. In the European Union, the framework under the AI Act pushes the product purchase cost to the compliance cost. A financial institution that wishes to use a cyber model with access to customer data will need to submit a reinforced risk assessment and document agent governance to the national supervisor, which tends to favor acquisition consortia rather than individual licenses for mid-sized banks.
In Japan, the regulatory debate over the use of frontier models in fraud detection has gained traction since the beginning of the year, with explicit focus on auditing logs maintained by the vendor. Gemini 3.8 Flash Cyber and Anthropic's Enterprise Frontier Safeguards enter this debate as opposing architectural references: the first writes logs on the vendor's side, while the second attempts to eliminate stored material. Large Japanese banks have already signaled a preference for the zero-retention design in preliminary negotiations.
What Lies Ahead in the Next 90 Days
The CISO's calendar gains three new decisions before the end of the quarter. The first is budgetary: to include or not include the restricted access line in the year-end review, knowing that prices are not public. The second is regulatory: to map if the contracted product falls under the EU AI Act annex and the U.S. national security framework. The third is operational: to define whether the agent will receive read access to the SIEM or operate in an isolated sandbox. None of the three is resolved by the benchmark comparison that the three providers are publishing this week.