TLDR
Google, Anthropic and OpenAI each released specialised cybersecurity AI within 72 hours in early September 2026, with models that can autonomously find and exploit software flaws. Anthropic's own threat report, published nine days later, confirmed state-linked actors had already weaponised its earlier models to build mass surveillance tools.
KEY TAKEAWAYS
Three launches, 72 hours, one unanswered question
Anthropic went first. On 1 September 2026, it released Claude Fable 5.1 via AWS Bedrock and its own platform, priced at $10 per million input tokens and $50 per million output tokens.[1] Alongside it came Claude Mythos 5.1, a variant retaining full cybersecurity and biological research capabilities, available only to vetted defenders through Anthropic's Enterprise Frontier Safeguards programme, currently limited to US access.[2]
Google shipped Gemini 3.8 Flash Cyber the next day, 2 September, through its new Fairwind Program for trusted defenders.[3] The standard Gemini 3.8 Flash, priced at $0.75 per million input tokens and $3.75 per million output tokens, launched simultaneously for general use. Tulsee Doshi, Google's Senior Director of Product Management, said: "We're already using Gemini 3.8 Flash Cyber to secure code across Google."[3]
OpenAI closed the sequence on 3 September with GPT-6 Astra, available through ChatGPT tiers, the OpenAI API, Microsoft Azure and AWS Bedrock.[4] List pricing matches Anthropic exactly: $10 per million input tokens and $50 per million output tokens, with Fast mode running at twice that rate.
What the models claim to do
Amelia Glaese, VP of Research at OpenAI, said Astra "can find previously unknown security flaws and develop ways to exploit them across many well-protected systems without a person guiding each step."[5] GPT-6 Astra is the first model OpenAI has rated as meeting its own "Critical" cybersecurity threshold under its Preparedness Framework, a self-assessed label with no independent verification yet published.[4]
Google claims Gemini 3.8 Flash Cyber exceeds a 70% success rate on the CyberGym benchmark, outperforming significantly larger frontier models.[3] That figure comes entirely from Google's own testing, and no independent replication of the CyberGym result had been published by the time of writing.
The pattern across all three announcements runs the same way: vendor claim, vendor benchmark, vendor-controlled access gate. The Frontier Model Forum, co-founded by Anthropic, Google DeepMind, Microsoft and OpenAI in July 2023 to set safety standards for frontier AI, had not published independent evaluations of any of the three models at the time of writing.
The threat report that arrived nine days later
On 10 September 2026, Anthropic published its threat intelligence report. The timing, nine days after its own cybersecurity model launch, made for uncomfortable reading. Anthropic confirmed that state-aligned actors from Mali, Iran and the People's Republic of China had already used Claude models for surveillance operations, including a Malian consultant who engineered a platform capable of intercepting all mobile operator communications in the country.[6]
The Malian case sits at the centre of the problem these three launches simultaneously represent and claim to address. The consultant used an earlier Claude model, not Fable 5.1, but the work came from the same lab. Anthropic is now selling a gated defender tool built on the same foundation a surveillance contractor already used to cover an entire country's phone network.[6]
What this means for Australian businesses
For Australian businesses running workloads on AWS Bedrock, Azure or Google Cloud, the structure of this market now sits in a specific arrangement. The same vendors that supply cloud infrastructure also built the models capable of finding and exploiting vulnerabilities in that infrastructure, and they now sell gated access to the defensive versions of those same models.
GPT-6 Astra's most capable cybersecurity features are available through OpenAI's access tiers, with OpenAI controlling who qualifies and under what conditions access can be granted or revoked.[4] Google's Fairwind Program and Anthropic's Enterprise Frontier Safeguards operate under the same model: the vendor decides, the vendor gates, the vendor audits.
Australian organisations evaluating these tools have no independent benchmark to test the defensive claims against. What they do have is Anthropic's own September 10 threat report, which documented misuse of the previous generation across three countries before the new generation had been available for ten days.
SOURCES & CITATIONS
FREQUENTLY ASKED QUESTIONS
What is the difference between Claude Fable 5.1 and Claude Mythos 5.1?
Has any independent body verified the cybersecurity benchmark claims from Google, Anthropic or OpenAI?
What misuse did Anthropic's September 2026 threat report disclose?
How do the prices compare across the three models?
Xaviery Malinao writes for Prompt the Market on how brands and agencies are adapting to answer engines, drawing on Bushnote's work with clients across search, AI search and content.
Important
This article discusses pricing and cost structures of AI services. This is general information only and does not constitute financial advice. Pricing and availability of these services may change. Organisations should conduct their own evaluation and seek professional advice before making procurement decisions.







