If you’ve tried to get your hands on the newest, most capable version of a major AI model this month and hit a waitlist or an application form instead of a simple sign-up, you’re not imagining things. Since the start of September 2026, Google, Anthropic, OpenAI, and Microsoft have all quietly shifted to a new release pattern: ship the flagship model to everyone, then ship a second, more powerful version to almost no one. Welcome to the era of gated AI models.
What “gated AI models” actually means
A gated AI model is a version of a company’s flagship system with certain safety restrictions loosened — usually around cybersecurity tasks like finding and exploiting software vulnerabilities — that’s only available to organizations the company has specifically approved. The regular public gets the standard model. A smaller, vetted group gets the version that can do more.
This isn’t a hypothetical. On September 1, Anthropic released two versions of the same underlying model: Claude Fable 5.1, available to anyone with an API key, and Claude Mythos 5.1, which is currently limited to “a set of US organizations” while Anthropic coordinates a wider rollout with the US government. A day later, Google launched its own version of the same idea — Gemini 3.8 Flash for everyone, and a “Cyber” variant gated through a brand-new invite-only Fairwind Program.
Four companies, four different locks on gated AI models
Every major lab is gating its cyber-capable models, but none of them are gating them the same way:
- Google’s Fairwind Program — an application process for governments, critical-infrastructure operators, and “core technology platforms,” with background checks on applicants and a requirement that access stay limited to internal security teams using multi-factor authentication. Google says more than 650 partners were approved on day one.
- Anthropic’s Cyber Verification Program and Project Glasswing — a vetting portal that currently covers Anthropic’s Claude Opus and Sonnet models, with the more powerful Mythos line being added “in the near future.” Glasswing separately gives named partners and open-source maintainer groups $100 million in shared usage credits.
- OpenAI’s Daybreak Access — reserved for “verified defenders,” reachable either through a direct application or through a partner already inside the program, aimed at authorized vulnerability research and red-teaming rather than general use. OpenAI’s own next flagship model, Astra, hasn’t shipped publicly at all yet — the company has said internally it can’t rule out the model reaching a “critical” cyber capability level, the same caution we covered when OpenAI flagged GPT-6 Astra as a safety-critical release.
- Microsoft’s approach — instead of a vetting form, Microsoft simply sells its cyber-capable model, MAI-Cyber-1-Flash, as part of an enterprise product (MDASH) with role-based access controls and sandboxed execution baked in.
A fifth pattern comes from Z.ai, which took a different route entirely: it released its open-weight GLM-5.3 model to the public with no application at all, just a two-week delay after launch “once safety evaluation and hardening are complete.”
Why gated AI models are showing up now
The timing isn’t a coincidence. This same week, an Anthropic researcher publicly resigned and warned against what they called self-improving AI, and Anthropic’s own CEO has been outlining a plan to deliberately slow the pace of frontier development — the same push toward caution we wrote about when Anthropic’s CEO first called for an AI development slowdown. These models are also getting close enough to genuinely useful cybersecurity work that the same capability which helps a defender patch a vulnerability could just as easily help an attacker find one first — a risk that isn’t theoretical after AI agents already went rogue and found real exploits on their own earlier this year.
That dual-use tension is exactly why the industry is converging on gating rather than simply refusing to build these capabilities at all. A model that can automatically discover and fix a zero-day vulnerability is valuable to a bank’s security team and dangerous in the wrong hands — so instead of one release decision, companies are now making two: what the model can do, and who’s allowed to make it do that.
What this means if you’re not a security researcher
For most everyday users and small businesses, none of this changes what’s in front of you today — the publicly available versions of these models (Claude Fable 5.1, Gemini 3.8 Flash, standard GPT and Muse models) aren’t losing capability, and pricing on the public tiers has largely held steady even as the gated versions roll out. What’s worth tracking is the trend itself: as AI models keep getting better at security-adjacent tasks like code analysis and vulnerability discovery, expect this two-tier release pattern to expand into other sensitive categories over time, not just cybersecurity.
If your business does touch security-sensitive work — anything from penetration testing to critical infrastructure — it’s worth knowing these programs exist now, since eligibility and application details differ meaningfully between vendors, as this September 2026 model release tracker lays out in detail. Anthropic’s CVP is application-based and largely US-focused today; Google’s Fairwind explicitly welcomes healthcare, telecom, energy, and financial-sector applicants; OpenAI’s Daybreak leans toward organizations already doing authorized red-teaming work.
What to watch next
A few open questions will shape how this plays out over the rest of 2026:
- Whether Anthropic’s Mythos-class gating expands beyond the US, as the company has said it intends to.
- Whether other labs follow Z.ai’s time-delay model instead of a formal vetting process — a much lighter-weight approach that still creates some friction before release.
- Whether gating spreads beyond cybersecurity into other high-stakes categories, like biological research or critical financial infrastructure.
For now, the practical takeaway is simple: if a new AI model announcement mentions a “verification program,” a “trusted partner,” or a name like Glasswing, Fairwind, or Daybreak, that’s not marketing language — it’s the industry’s newest safety mechanism, and it’s likely to become a permanent fixture of how frontier AI ships from here on.