# Gated Model Releases

> Gated model releases give frontier AI to vetted cyber defenders first: OpenAI Daybreak, Anthropic Glasswing, Google Fairwind, plus new US government review.

Source: https://metavert.io/gated-model-releases  
Published: 2026-10-05  
Updated: 2026-10-05

**Gated model releases** are a deployment pattern in which an AI lab gives its most capable model to a vetted group, usually cybersecurity defenders and critical-infrastructure operators, before or instead of releasing it to the general public.

## What Is a Gated Release?

For most of the large-language-model era, a new [frontier model](https://metavert.io/frontier-ai) went from internal testing to a public API and consumer app on the same day. In 2026 that changed. As models became able to find and exploit software vulnerabilities on their own, the leading labs began to treat cyber capability as the factor that decides who gets access, and when. A gated release typically combines three elements: an early-access program for defenders, a separate and more restricted tier of the model with fewer safeguards, and some form of vetting, such as verified organizations or government review.

The logic is the same [dual-use](https://metavert.io/dual-use-ai) argument everywhere. A model that can find a zero-day for a defender can find one for an attacker. Giving defenders a head start lets them patch before equivalent capabilities spread. By October 2026, all three leading US labs ran such a program.

## Anthropic: Glasswing, Mythos and the Fable Tier

[Anthropic](https://metavert.io/anthropic) set the template with [Claude Mythos](https://metavert.io/claude-mythos), which it deployed only through [Project Glasswing](https://metavert.io/project-glasswing), a consortium of defenders. In a May 26, 2026 update, Anthropic said Glasswing had found 23,019 issues across more than 1,000 open-source projects, 6,202 of them rated high or critical, and that fixing them, not finding them, had become the bottleneck.

Anthropic then split its top model into two tiers. Fable is the generally available version with stronger safeguards; Mythos is the restricted version. In September 2026 it released Fable 5.1 and Mythos 5.1, which it describes as the same model under different safeguards. Fable 5.1 is generally available at $10 per million input tokens and $50 per million output tokens and scores 55.8% on Terminal-Bench 4.0. Mythos 5.1 scores 60.9% and is restricted to verified US organizations.

## OpenAI: Daybreak

[OpenAI](https://metavert.io/openai)'s equivalent is Daybreak, a cybersecurity program for vetted defenders. On September 3, 2026, [GPT-6 Astra](https://metavert.io/gpt-6-astra) went to Daybreak first and reached ChatGPT Pro, Plus, Business and Enterprise plans and the API within a week. According to Layer3 Labs, Astra is the first OpenAI model rated "Critical" under its Preparedness Framework, and some of its cyber capabilities are withheld from general users.

## Google: Fairwind and Gemini 4 Argon

[Google](https://metavert.io/gemini) joined the pattern on September 30, 2026, when it announced Gemini 4 Argon with initial access limited to its Fairwind cyber-defender program and trusted testers. Argon scores 77.9% on DeepSWE, against 74.2% for Claude Opus 5.5, and supports outputs of up to 1 million tokens. Google set an introductory price of $2/$10 per million tokens, rising to $4/$20. Google also ships a cyber-specialized smaller model, Gemini 3.8 Flash Cyber.

## Government Enters the Gate

Gating began as a voluntary lab practice. In 2026, governments started to take part.

### The June 2 Executive Order

A US executive order signed June 2, 2026 created a voluntary pre-release review: developers can give the government up to 30 days of access to "covered frontier models" before launch. Which models count as covered is decided by a classified benchmarking process. Developers keep control over release timing. See [AI regulation](https://metavert.io/ai-regulation) for the wider policy context.

### The Staggered GPT-5.6 Rollout

OpenAI's GPT-5.6 was among the first models to go through this process. According to reporting from NYU Shanghai's RITS, it went generally available on July 9, 2026 after a two-week preview under a government review that began June 26. The flagship GPT-5.6 Sol tier reportedly scores 73.5% on ExploitBench, against 47.9% for GPT-5.5, which shows why cyber capability drew review.

### The Commerce Freeze on Anthropic

The sharpest intervention came in June. In a June 12, 2026 letter signed by Commerce Secretary Howard Lutnick, the US Department of Commerce ordered Anthropic to cut off foreign nationals' access to Fable 5 and Mythos 5. Because Anthropic could not tell foreign nationals apart in real time, it disabled both models worldwide, three days after Fable 5 launched on June 9. The trigger was reportedly a jailbreak by Amazon researchers that reached the Mythos 5 model underneath Fable's safeguards. According to The Next Web, the controls were lifted on June 30; access returned on July 1, capped at 50% of normal capacity until July 7, and in exchange Anthropic agreed to proactively find vulnerabilities, help develop standards and report malicious activity.

## Why It Matters

Gated releases change what "launching a model" means. The most capable version may never be public, the public version may be a safeguarded tier of the same weights, and governments can now delay or halt access. For defenders, gating offers a real head start; Glasswing's backlog shows the bottleneck has moved to patching. For developers and businesses, it means capability arrives in stages, and access depends on vetting and nationality as much as price. The Fable episode also shows the weak point of the tier model: if a jailbreak can reach the restricted model underneath, the gate is only as strong as its safeguards. The pattern is now a core part of [AI safety](https://metavert.io/ai-safety) practice and of [AI in cybersecurity](https://metavert.io/ai-in-cybersecurity).

## Related Topics

- [Claude Mythos](https://metavert.io/claude-mythos) — The model that established the defenders-first pattern
- [Project Glasswing](https://metavert.io/project-glasswing) — Anthropic's defender consortium
- [GPT-6 Astra](https://metavert.io/gpt-6-astra) — OpenAI's model released first through Daybreak
- [Gemini](https://metavert.io/gemini) — Google's model family, including Fairwind-gated Gemini 4 Argon
- [Dual-Use AI](https://metavert.io/dual-use-ai) — The core rationale for gating cyber-capable models
- [AI in Cybersecurity](https://metavert.io/ai-in-cybersecurity) — The domain driving gated access
- [AI Regulation](https://metavert.io/ai-regulation) — The executive order and Commerce controls in policy context
- [AI Safety](https://metavert.io/ai-safety) — Gating as one layer of frontier-model risk management
- [Chain-of-Thought Monitorability](https://metavert.io/cot-monitorability) — Another factor now shaping release decisions
- [Frontier AI Models](https://metavert.io/frontier-ai) — The capability tier subject to gated releases

## Further Reading

- [Anthropic Project Glasswing update — Help Net Security](https://www.helpnetsecurity.com/2026/05/26/anthropic-project-glasswing-update/) — Glasswing's vulnerability counts and the patching bottleneck
- [Claude Fable and Mythos 5.1 — Anthropic](https://www.anthropic.com/claude-fable-and-mythos-5-1) — The two-tier release of the same model
- [OpenAI launches Astra — TechCrunch](https://techcrunch.com/2026/09/03/openai-launches-astra-its-powerful-and-controversial-new-model/) — Astra's Daybreak-first rollout
- [Gemini 4 Argon announcement — 9to5Google](https://9to5google.com/2026/09/30/gemini-4-argon-announcement/) — Fairwind-first access and pricing
- [Google releases Gemini 4 Argon — TechCrunch](https://techcrunch.com/2026/09/30/google-releases-gemini-4-argon-called-its-most-powerful-model-yet/) — Benchmarks and availability
- [New executive order addressing early access to frontier models — JD Supra](https://www.jdsupra.com/legalnews/new-executive-order-addressing-early-6123982/) — The June 2 pre-release review order
- [Washington pulled the plug on Anthropic Fable 5 and Mythos 5 — Security Affairs](https://securityaffairs.com/193579/ai/washington-pulled-the-plug-on-anthropic-fable-5-and-mythos-5-models.html) — The June 12 Commerce letter and global shutdown
- [Anthropic Fable 5 export controls lifted — The Next Web](https://thenextweb.com/news/anthropic-fable-5-export-controls-lifted) — Terms of the restoration
- [OpenAI launches GPT-5.6 family — NYU Shanghai RITS](https://rits.shanghai.nyu.edu/ai/openai-launches-gpt-5-6-family-sol-terra-and-luna-reach-general-availability/) — The staggered GPT-5.6 rollout
