Three labs, the same week, the same decision

On September 2, Google introduced Gemini 3.8 Flash Cyber, its most capable model yet at finding and patching software vulnerabilities. On the CyberGym benchmark for autonomous vulnerability discovery, it beats Google's own prior cyber model and larger general-purpose frontier models alike, and in Google's internal testing it found real flaws across 20 programming languages more than 70 percent of the time.

Nobody outside a screened list can use it. Access runs through a new Fairwind Program, limited to government agencies, critical infrastructure operators, software maintainers, and Google Cloud customers who pass an eligibility check and agree to controls including mandatory multi-factor authentication. More than 650 organizations are already inside it, among them CrowdStrike, Datadog, Menlo Security, Palo Alto Networks, Snowflake and Wiz.

Anthropic and OpenAI made the identical call

Google was not alone. In the same window, Anthropic shipped Claude Fable 5.1 and Claude Mythos 5.1, and drew the same line: Fable 5.1 can now identify software vulnerabilities for anyone using it, but penetration testing, exploit generation and binary-level vulnerability scanning are pushed to Mythos 5.1, which Anthropic restricts to its own trusted access program for cybersecurity and life-sciences work. Anthropic paired the release with Enterprise Frontier Safeguards, combining zero data retention with new misuse-detection tooling, and said it had paused external cyber evaluations of pre-release models following unauthorized access incidents.

OpenAI has not yet shipped its Astra model publicly, but disclosed that it already clears a Critical cybersecurity capability threshold, able to find and exploit zero-day flaws in well-defended systems on its own; in evaluation it scored 100 percent on the ExploitBench benchmark and surfaced a previously unknown full browser-escape chain. Access, for now, runs through a restricted tester group called Daybreak Blue.

How the three gates compare

LabModelAccess modelReported capability
GoogleGemini 3.8 Flash CyberFairwind Program, 650+ vetted partners70%+ real-vulnerability find rate across 20 languages
AnthropicClaude Mythos 5.1Separate trusted access programHandles pen-testing and exploit generation Fable 5.1 declines
OpenAIAstra (unreleased)Daybreak Blue testers100% on ExploitBench; found a full browser-escape chain

The gate is the story, not the benchmark

AI capability normally spreads down-market fast: a frontier model ships, gets cheaper, and within a year a mid-sized company can use roughly what only a lab could a year earlier. These three releases break that pattern on purpose. Each company built the eligibility screen into the launch itself, before any public demand forced their hand, because an AI that finds zero-days as reliably as these three claim is also a tool that hands an attacker the same find. The safe move was never going to be a broad release; it was always going to be a list.

That inverts who benefits first. The 650 Fairwind partners already run mature security operations; a mid-market company without an existing CrowdStrike or Palo Alto Networks relationship has no fast path in. The defenders who most need an automated vulnerability hunter, teams too small to have found this flaw themselves, are exactly the ones least likely to already sit inside one of these three programs.

What an owner should actually do with this

Do not assume your organization gets this generation of AI security tooling just because a competitor announced it. Check eligibility directly: Fairwind through your Google Cloud account team, Anthropic's trusted access program through its enterprise sales contact, OpenAI's Daybreak Blue by request. None of these publish an open self-serve signup, and all three can change eligibility criteria without much notice.

Until access widens, the practical defense is unchanged: patch cadence, dependency hygiene and incident response quality still matter more than which lab's model you cannot yet use. An AI vulnerability hunter you are not eligible for protects nobody. The organizations getting real value from these three releases right now are the ones that already had strong security practice before the invitation arrived.

Servola Journal

We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.

Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.

If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.