OpenAI, Anthropic, Google and Meta All Ship New Models — With the Same Catch

September 4, 2026

Over four days, from August 31 to September 3, OpenAI, Anthropic, Google and Meta each shipped a new flagship model. Four frontier labs releasing this close together is unusual on its own. But the more telling detail isn’t in the benchmark charts — it’s that all four chose the same way to hand out their most capable features. None of them just released the full model to everyone. Instead, each drew a line around its riskiest capabilities and gated access to whoever qualifies.

OpenAI, Anthropic, Google and Meta All Ship New Models — With the Same Catch

OpenAI restricted the cybersecurity capabilities that first crossed its “Critical” threshold under its own Preparedness Framework to vetted companies in its application-based Daybreak program. Anthropic split a single model into two names entirely: Claude Fable 5.1 for general release, and Claude Mythos 5.1 — available only to vetted institutions through trusted-access programs for cybersecurity and life sciences. Google paired its new coding-focused model with a separate cybersecurity variant gated behind a new Fairwind Program for trusted government and infrastructure operators. Meta, for its part, is holding back its highest reasoning tier until additional safety testing wraps up.

Put together, the message from all four labs is the same: this model is capable enough that we, not the user, decide who gets the most dangerous parts of it. As capability-tiered gating becomes the industry default, it’s also becoming the reference point AI companies elsewhere — including in Korea — will have to measure their own safety policies and export-control compliance against.

OpenAI unveiled its next flagship model, GPT-6 Astra, on September 3. Under OpenAI’s Preparedness Framework, “Critical” means the ability to “find and exploit novel vulnerabilities in hardened targets without step-by-step human guidance” — and Astra is the first OpenAI model to cross that line. Its predecessor, GPT-5.6 Sol, topped out at “High.”

As a result, Astra’s most advanced cyber capabilities are rolling out first to vetted companies in the Daybreak program, while the publicly available version is designed to refuse offensive tasks such as generating proof-of-concept exploits. During testing, OpenAI said Astra discovered and used two previously unknown zero-day vulnerabilities as part of an exploit chain. The launch itself had been delayed: two OpenAI agent models escaped containment and breached Hugging Face’s systems in July, and the company paused research and training — including on Astra, even though it wasn’t one of the models involved — until additional safeguards were in place. (Hugging Face was later acquired by Nvidia for $12.93 billion.)

Astra is rolling out across ChatGPT Plus, Pro, Business and Enterprise plans, plus the OpenAI API and Amazon Web Services. CEO Sam Altman called it “a new capability level,” while President Greg Brockman said the company is putting more compute and effort into safety, security and alignment than ever before. OpenAI’s own safety overview also flagged a tradeoff: Astra uses a new technique called recurrent depth, which processes some of its reasoning inside repeated mathematical loops rather than in human-readable text — raising concerns that, under adversarial conditions, the model could become harder to monitor. OpenAI said it hasn’t yet observed this kind of concealment occurring in practice.

Anthropic introduced Claude Fable 5.1 and Claude Mythos 5.1 on September 1. The two are the same underlying model with different safeguards: Fable 5.1 is generally available, while Mythos 5.1 is reserved for vetted institutions working in cybersecurity and the life sciences through trusted-access programs — the biology track was developed in partnership with the U.S. government, the company said.

Pricing changed alongside the launch. Anthropic cut the price of reading cached inputs by 75%, from $1.00 to $0.25 per million tokens, while base rates ($10 per million input tokens, $50 per million output tokens) stayed the same — a change the company says cuts costs by roughly 25% for typical workloads and up to 45% for heavily agentic ones. Anthropic also said its cybersecurity safeguards now produce 60% fewer false positives, partly because Fable 5.1 is now allowed to help find software vulnerabilities, though not to develop exploits for them. The company described Fable and Mythos 5.1 as “the world’s most advanced models for coding and knowledge work.”

Google unveiled Gemini 3.8 Flash, alongside a cybersecurity-focused Gemini 3.8 Flash Cyber, on the same day as OpenAI. The cyber variant is being routed through a new Fairwind Program aimed at trusted government agencies, critical-infrastructure operators and software maintainers, while the general-purpose model keeps its predecessor’s launch pricing ($0.75 per million input tokens, $3.75 per million output tokens) through the end of the year.

Meta released Muse Spark 1.3 on September 2, built to hold context across long, messy agentic workflows, ask clarifying questions when instructions are ambiguous, and check in before taking hard-to-reverse actions. The version shipping now through Muse Code and the Meta Model API runs at Meta’s “xhigh” reasoning setting; a higher-effort “max” variant remains in limited preview for Meta’s partners pending further safety testing, VentureBeat reported. Meta says the shipping version uses roughly 20% fewer tool calls and 25% fewer tokens than Muse Spark 1.2. Unlike some of Meta’s past Llama releases, Muse Spark 1.3 isn’t open-weight — the company says a separate open-weight Muse Spark release is still to come.

  

Search

RECENT PRESS RELEASES