Three labs released their top model twice within the same three-day window in early September. Each split the release into a version anyone can pay for and a version that requires an application. Akira Sumi, writing for Okane Land, frames this as a single pattern rather than three separate launches, and the pattern is worth taking seriously: the price of frontier access held steady while the qualification for the top tier changed entirely.

Anthropic’s public model, Claude Fable 5.1, is open to anyone at $10 for a million tokens in and $50 for a million out. Its sibling, Claude Mythos 5.1, shares its weights but carries different safeguards, as the company describes it, and reaches only “a small, but growing, set of vetted organizations.” Access flows through two trusted programs, one for cyber defense and one for life sciences, both currently restricted to organizations based in the US. Access is granted per organization ID, never per individual account, and the review for the cyber program takes about two business days once a qualifying organization applies.

OpenAI took a similar structure further. GPT-6 Astra ships publicly at the identical $10 and $50 rate, and it is the first model the company has placed at the Critical threshold of its own Preparedness Framework for cybersecurity risk, meaning the underlying weights can locate unknown vulnerabilities and construct exploits without step-by-step human guidance. The public build declines that class of task. The fuller capability rolls out through a program called Daybreak Blue, starting with a small pool of alpha testers before it widens. For an individual seeking access on their own, the requirement is concrete: a government-issued ID plus two hardware security keys enabled through the company’s Advanced Account Security setting, on top of meeting the program’s other eligibility terms.

Google’s version of the split leans on category rather than individual credentials. Gemini 3.8 Flash is public and inexpensive, priced at $0.75 and $3.75 per million tokens through the end of the year. Gemini 3.8 Flash Cyber, a variant tuned to locate security holes and fix them, is restricted to what Google calls trusted defenders and moves through the Fairwind Program. That program lists who it is meant for: security partners and Google Cloud customers, operators of critical infrastructure, core tech platforms, and government bodies including national cyber authorities, and it requires those participants to confine the tool to security staff running multifactor authentication. There is no listed individual path and no published price, because there is no checkout.

Sumi’s read is that these three gates differ in who they let through, even though they rhyme in shape. OpenAI’s route is the one an individual could plausibly clear alone. Anthropic’s route accepts individual applicants but only if they attach to a registered organization. Google’s route admits categories of institution and currently has no lane for a solo applicant at all. That gradient matters for anyone deciding whether to build a product around a security-facing model this year: the door that looks open on paper is not the same door in practice.

There is a second, less obvious consequence for anyone running unattended workloads. According to OpenAI, the safeguards Astra runs with in production can flag “tasks in which an agent is running for an extended period,” and that on the API, a flagged task simply stops rather than pausing for review. A solo operator running an overnight batch job on the public tier is exactly the pattern that monitor is built to catch. Combined with the access gates above, the practical read for smaller teams is that the public model is now both the cheaper option and the more closely supervised one, while the credential is what buys distance from both constraints.

Adapted from analysis by Akira Sumi, published in Okane Land on September 13, 2026.