AI

Three AI labs released hacking-capable models in 72 hours

Anthropic went first on 1 September, then Google, then OpenAI. Each is selling the defence to the risk it has just made cheaper. What the models can do, and what they cost.

6 min read
A green circuit board unravels as copper traces detach and curl menacingly.
Illustration: Prompt the Market
By Xaviery Malinao · 2026-09-17

TLDR

Google, Anthropic and OpenAI each released specialised cybersecurity AI within 72 hours in early September 2026, with models that can autonomously find and exploit software flaws. Anthropic's own threat report, published nine days later, confirmed state-linked actors had already weaponised its earlier models to build mass surveillance tools.

KEY TAKEAWAYS

01GPT-6 Astra is the first OpenAI model self-rated as 'Critical' for cybersecurity under its Preparedness Framework.
02A Malian consultant used Claude to build a platform intercepting all mobile communications across Mali, Anthropic confirmed.
03Claude Fable 5.1 and GPT-6 Astra carry identical list pricing: $10 per million input tokens and $50 per million output tokens.
04Google claims Gemini 3.8 Flash Cyber exceeds 70% on CyberGym benchmarks, with no independent replication published.
05All three vendors gate their most capable cybersecurity models behind proprietary programmes they control exclusively.

Three launches, 72 hours, one unanswered question

Anthropic went first. On 1 September 2026, it released Claude Fable 5.1 via AWS Bedrock and its own platform, priced at $10 per million input tokens and $50 per million output tokens.[1] Alongside it came Claude Mythos 5.1, a variant retaining full cybersecurity and biological research capabilities, available only to vetted defenders through Anthropic's Enterprise Frontier Safeguards programme, currently limited to US access.[2]

Google shipped Gemini 3.8 Flash Cyber the next day, 2 September, through its new Fairwind Program for trusted defenders.[3] The standard Gemini 3.8 Flash, priced at $0.75 per million input tokens and $3.75 per million output tokens, launched simultaneously for general use. Tulsee Doshi, Google's Senior Director of Product Management, said: "We're already using Gemini 3.8 Flash Cyber to secure code across Google."[3]

OpenAI closed the sequence on 3 September with GPT-6 Astra, available through ChatGPT tiers, the OpenAI API, Microsoft Azure and AWS Bedrock.[4] List pricing matches Anthropic exactly: $10 per million input tokens and $50 per million output tokens, with Fast mode running at twice that rate.

Introducing GPT-6 Astra: the most intelligent and aligned model in the world.

What the models claim to do

Amelia Glaese, VP of Research at OpenAI, said Astra "can find previously unknown security flaws and develop ways to exploit them across many well-protected systems without a person guiding each step."[5] GPT-6 Astra is the first model OpenAI has rated as meeting its own "Critical" cybersecurity threshold under its Preparedness Framework, a self-assessed label with no independent verification yet published.[4]

Google claims Gemini 3.8 Flash Cyber exceeds a 70% success rate on the CyberGym benchmark, outperforming significantly larger frontier models.[3] That figure comes entirely from Google's own testing, and no independent replication of the CyberGym result had been published by the time of writing.

The pattern across all three announcements runs the same way: vendor claim, vendor benchmark, vendor-controlled access gate. The Frontier Model Forum, co-founded by Anthropic, Google DeepMind, Microsoft and OpenAI in July 2023 to set safety standards for frontier AI, had not published independent evaluations of any of the three models at the time of writing.

The threat report that arrived nine days later

On 10 September 2026, Anthropic published its threat intelligence report. The timing, nine days after its own cybersecurity model launch, made for uncomfortable reading. Anthropic confirmed that state-aligned actors from Mali, Iran and the People's Republic of China had already used Claude models for surveillance operations, including a Malian consultant who engineered a platform capable of intercepting all mobile operator communications in the country.[6]

The Malian case sits at the centre of the problem these three launches simultaneously represent and claim to address. The consultant used an earlier Claude model, not Fable 5.1, but the work came from the same lab. Anthropic is now selling a gated defender tool built on the same foundation a surveillance contractor already used to cover an entire country's phone network.[6]

Introducing GPT-6 Astra for developers

What this means for Australian businesses

For Australian businesses running workloads on AWS Bedrock, Azure or Google Cloud, the structure of this market now sits in a specific arrangement. The same vendors that supply cloud infrastructure also built the models capable of finding and exploiting vulnerabilities in that infrastructure, and they now sell gated access to the defensive versions of those same models.

GPT-6 Astra's most capable cybersecurity features are available through OpenAI's access tiers, with OpenAI controlling who qualifies and under what conditions access can be granted or revoked.[4] Google's Fairwind Program and Anthropic's Enterprise Frontier Safeguards operate under the same model: the vendor decides, the vendor gates, the vendor audits.

Australian organisations evaluating these tools have no independent benchmark to test the defensive claims against. What they do have is Anthropic's own September 10 threat report, which documented misuse of the previous generation across three countries before the new generation had been available for ten days.

This article contains analysis and commentary on market conditions. It does not constitute financial, investment, or professional advice. Past performance is not indicative of future results. Always consult a qualified adviser before making financial decisions.

FREQUENTLY ASKED QUESTIONS

What is the difference between Claude Fable 5.1 and Claude Mythos 5.1?
Claude Fable 5.1 is generally available via AWS Bedrock and Anthropic's platform. Claude Mythos 5.1 retains full cybersecurity and biological research capabilities and is restricted to vetted defenders through Anthropic's Enterprise Frontier Safeguards programme, currently with limited US access only.
Has any independent body verified the cybersecurity benchmark claims from Google, Anthropic or OpenAI?
No. Google's claim that Gemini 3.8 Flash Cyber exceeds 70% on CyberGym comes from the company's own testing. OpenAI's 'Critical' rating under its Preparedness Framework is self-assessed. No independent replication of any of the three models' cybersecurity benchmarks had been published at the time of writing.
What misuse did Anthropic's September 2026 threat report disclose?
Anthropic confirmed that state-aligned actors from Mali, Iran and China used earlier Claude models for surveillance operations. A Malian consultant used Claude to build a platform capable of intercepting all mobile operator communications across Mali.
How do the prices compare across the three models?
Claude Fable 5.1 and GPT-6 Astra carry identical pricing at $10 per million input tokens and $50 per million output tokens. Gemini 3.8 Flash is significantly cheaper at $0.75 per million input tokens and $3.75 per million output tokens, though the gated Gemini 3.8 Flash Cyber is not publicly priced.

Xaviery Malinao

Xaviery Malinao writes for Prompt the Market on how brands and agencies are adapting to answer engines, drawing on Bushnote's work with clients across search, AI search and content.

Important

This article discusses pricing and cost structures of AI services. This is general information only and does not constitute financial advice. Pricing and availability of these services may change. Organisations should conduct their own evaluation and seek professional advice before making procurement decisions.

The prompt
Every weekday morning: the five stories moving marketing, media and money, with the number that matters in each.
Sending your link…
Check your inbox to confirm.
That didn't go through. Try again.
Related topics

Make us a preferred source on Google

Tap once and our reporting shows at the top of your Google search results and AI answers. You can change this at any time.

Add as a preferred source on Google
Subscribe, it's free