Same Weights, Different Permission
Return to Part 0: Table of ContentsPrevious Article: Part 34, AI Governance: 1,664 Times an AI Faked a Human's Sign-Off
"Can we get the version that actually finds the zero-days, not the one that refuses?"
That is the question a chief information security officer at a New Zealand critical infrastructure operator can now put to their Anthropic, Google, or OpenAI account manager, because between 1 and 3 September 2026 each of the three built exactly that version and then decided who was allowed to touch it. Anthropic shipped Claude Mythos 5.1 on 1 September, reachable only through two vetting programmes [1]. Google shipped Gemini 3.8 Flash Cyber on 2 September, reachable only through a new admission scheme called Fairwind [2]. OpenAI shipped GPT-6 Astra on 3 September, the first model to cross its own Preparedness Framework "Critical" cybersecurity threshold, with the capability that earned that rating withheld from general release and reserved for a vetted coalition called Daybreak [3].
The CISO's answer, for the first time, is not a price list. It is a form, a vetting process with no published criteria, and a "not yet" with no date attached. Their next question, what would we need to prove and to whom, does not currently have an answer any of the three vendors has published.
Three gates in one week is a pattern, not a coincidence
This series named a version of this problem in July, when a US government agency spent nineteen days holding, then restoring, a frontier model's API access to a state agency, with nothing about the model's own capability changing in between. We called that the Access Kill-Switch: proof that what stands between an organisation and a capable AI system is not always the system's competence. Sometimes it is a decision, made elsewhere, that the same authority that made it can also reverse.
At the time that was one dramatic, externally imposed instance: a government agency, one vendor, one emergency measure. Four months on, three of the industry's largest labs have each built a permanent, routine, vendor-run version of the same control, inside the same seven days. Three named programmes shipping that close together is a market structure, not a coincidence, and this piece treats it as one.
Two weeks earlier, Z.ai had already tested a nearby position on the same axis. The Chinese lab delayed the downloadable weights of its GLM-5.3 model by roughly two weeks while it finished safety hardening, then published them anyway, under a custom licence rather than the fully permissive terms its prior release had used. Nothing stayed withheld in the end. The control point simply moved from whether access existed to what licence governed it. Mythos 5.1, Fairwind and Daybreak are a third position on the same axis, and Mythos 5.1 is the instance that finally shows the mechanism in plain view. Nothing is withheld at the capability layer. What is withheld is a filter configuration and a customer list, administered entirely by the vendor.
The demonstration that settles what kind of control this is
Anthropic's own words are the cleanest evidence in the whole story. The company's product page states that Claude Mythos 5.1 "is identical to Fable 5.1, but it offers more permissive safeguards" for vetted individuals and organisations [1]. Fable 5.1 is generally available to any paid Claude plan or API account. Mythos 5.1 is not. It sits behind two trusted access programmes: a Cyber Verification Program offering reduced safeguards on models Anthropic expects to extend to the Mythos class "in the near future," and a separate Life Sciences Verification Program that has enrolled its first participants [1]. Two identical models. One filter configuration, switched on selectively. Nothing about Mythos 5.1's underlying capability was built specially for the people who can reach it.
Google's version of the same move is dressed differently but, on the sourced record, appears built the same way underneath. Gemini 3.8 Flash Cyber is marketed as a distinctly named variant rather than a relaxed-safeguard sibling, and Google has not stated, on any page checked for this piece, whether it shares weights with the standard Gemini 3.8 Flash model released alongside it [2]. What Google has stated clearly is the access mechanism: Fairwind, open to government agencies and national cyber authorities, critical infrastructure operators, and technology platforms serving downstream users, each required to restrict use to security staff and enforce multi-factor authentication [2]. Google reports more than 650 participating organisations "globally," including named partners such as CrowdStrike, Datadog, Menlo Security, Palo Alto Networks, and Snowflake [2] [4]. It has not published a country list.
OpenAI's Astra, released 3 September, scored 100 per cent on the ExploitBench evaluation against 78.5 per cent for its predecessor, GPT-5.6 Sol, the result that crossed the Preparedness Framework's "Critical" designation [3]. General users receive a version that refuses tasks such as generating proof-of-concept exploits. Vetted members of the Daybreak coalition receive, on multiple accounts, less restrictive safeguards on what appears to be the same underlying model, rolled out in the coming weeks [3]. OpenAI separately pledged one billion US dollars to a companion programme, Daybreak for Frontline Defenders, aimed at subsidising access for organisations that cannot otherwise afford it: water and wastewater utilities, electric grid operators, local government, community banks, non-profits, and open-source maintainers [5].
Here the piece owes the reader a distinction worth keeping sharp rather than smoothing over. Only one of these three vendors has said, in as many words, that the withheld version and the available version are the same model. Anthropic said it explicitly. OpenAI's structure reads the same way, one model with two safeguard configurations, though this piece could not locate the word "identical" on any OpenAI page describing Astra [3]. Google's is the least clean of the three: a named, separately branded variant, with no statement either way about shared weights. This piece's title describes what Anthropic demonstrated with certainty. For the other two, it describes a pattern that is very likely the same mechanism, not yet a confirmed one. Flattening that difference to make three vendors sound like they ran one experiment would be a tidier story than the sourced record actually supports.
What the demonstration proves regardless of which vendor stated it most explicitly is where the control now sits. It is not in the weights. Frontier labs have spent two years telling the public that safety-relevant capability lives in a model's training, its parameters, its architecture. Mythos 5.1 says otherwise, at least for one company and one product line: the capability was already fully present in the model everybody could already buy. What Anthropic changed was who is permitted to reach it.
For an enterprise buyer this changes what due diligence even means. A capability gap can be benchmarked, timed and priced against a competitor's offering. A permission gap cannot, because there is nothing on the other side of the form to inspect except the vendor's own judgement about who has earned access.
What none of the three will readily tell you
Across every source this piece could locate for all three vendors, on the pages Anthropic and Google published themselves and in the independent reporting on OpenAI's programmes, one thing is consistently and totally absent: an attestation standard, a named third-party certification body, or any right for an admitted organisation to audit the vendor's admission decisions or its own safeguard configuration [1] [2] [3] [4] [5]. Google's Fairwind page describes obligations it imposes on participants, restricting use to security staff, enforcing multi-factor authentication. It describes nothing that certifies participants, and nothing that lets a participant verify what the vendor does on its own side of the arrangement. The same is true, on the sourced record, at Anthropic and at OpenAI.
That absence is the structural centre of this story, not a footnote to it. A governance function can build a case around a control it can inspect: a penetration test result, a compliance certificate, a contractual audit clause. It cannot build one around a vendor's internal judgement, applied through a process nobody outside the vendor can see and nobody outside the vendor can challenge.
The second thing worth pressing on is where the door currently opens, and here the three vendors differ from each other in ways worth naming individually rather than folding into one sentence. Anthropic states its scope in the plainest terms of the three: the Cyber Verification Program is currently only available to a set of US organisations, with the company separately describing coordination with the US government to widen access to more domestic and international partners as quickly as possible [1]. No country, timeline, or admission criterion accompanies that description. Google says the least of the three. Fairwind's more than 650 partners are described only as global, with no geographic breakdown offered anywhere this piece could find, a lower bar for transparency than Anthropic clears even though Google's programme may in fact already reach more countries [2]. OpenAI is the most explicit of the three: American organisations are named as the current priority for Daybreak for Frontline Defenders, with unspecified partner countries following in unstated future weeks, inside an overall six-month target for the subsidy programme to reach full consumption [5]. None of that resolves into a date a New Zealand organisation can put in a procurement calendar. It does mean that collapsing all three vendors into a single line, nobody outside the US can apply, would understate what OpenAI has actually disclosed and overstate what Google has.
Astra's defensive value in testing is reported, by a single technical outlet this piece could not independently corroborate against a security advisory, to have surfaced two previously unpatched vulnerabilities in Google's V8 JavaScript engine [7]. Treat that as illustrative rather than confirmed. The defensive value is genuinely there. What remains unaudited is everything about how the decision to grant it gets made.
None of this is unique to cyber-capable models, and none of it is new in kind, only in scale. What is new is that three of the industry's largest vendors reached for the same structure inside the same seven days, which is what makes this a market pattern rather than one company's decision. The question an enterprise buyer now has to answer is not whether the capability exists. It plainly does. The question is what, if anything, they can actually verify about the process that decides whether they get to use it.
What a New Zealand organisation can check today
On the New Zealand side of this, the record is short and consistent. A targeted search for any New Zealand or Australian organisation engaging with Gemini 3.8 Flash Cyber, GPT-6 Astra, Daybreak, or Fairwind specifically returns nothing: no agency, no enterprise, no admission, on any public record checked for this piece. The most recent on-record New Zealand government statement on the general question predates all three programmes by more than three months. In May 2026, before any of this month's launches existed, New Zealand's National Cyber Security Centre, NCSC-NZ, told RNZ directly that it was "not part of Glasswing," Anthropic's earlier trusted-access programme, but was talking regularly with a range of partners and vendors, some of them involved with Glasswing, to understand the landscape and provide guidance on the implications of frontier AI [6]. A separate report has claimed NCSC-NZ received Glasswing access on the New Zealand government's behalf. That claim conflicts directly with NCSC-NZ's own quoted statement, and this piece treats the agency's own words as the ones that stand.
This series used New Zealand's absence from Glasswing once already, in July, in the same article that first named the Access Kill-Switch. Four months and three additional vendor programmes later, the pattern has not moved. That continuity, not novelty, is the honest way to describe it: a documented gap, checked again, still there.
No New Zealand regulatory instrument located for this piece addresses, from any regulator, whether a vendor's unilateral and unaudited access decision is something any current instrument contemplates. That is a narrower gap than "no AI regulation exists," and it is the more useful one for a board to actually understand.
What to ask before you apply
None of that means an enterprise buyer should wait for an invitation. It means the due diligence has to happen before the form does, not after. Three questions are worth putting to any vendor offering a permission-gated tier, cyber-capable or otherwise.
What specifically distinguishes the gated version from the one already in production? Is the difference a capability that does not otherwise exist, or a safeguard switched off for a vetted list? The answer changes which governance function should own the decision.
What does the vendor publish about how admission decisions get made? Does any of it amount to a standard an auditor could test against, rather than a form and a wait with no published criteria behind it?
Who, outside the vendor, can see the criteria, the decision, or the list? A control nobody outside the vendor can inspect is not a control a board can rely on, whatever the marketing page calls it.
None of the three vendors currently answers all three questions in public. Treat "we were admitted" as the start of a governance conversation, not the end of one.
- Between 1 and 3 September 2026, Anthropic, Google, and OpenAI each shipped a cyber-capable frontier model with its most capable behaviour reserved for a vetted access tier: Claude Mythos 5.1, Gemini 3.8 Flash Cyber, and GPT-6 Astra.
- Anthropic states directly that Mythos 5.1 and the generally available Fable 5.1 are identical models, differing only in which safeguards are relaxed and for whom. OpenAI's structure reads the same way; Google has not confirmed or denied whether its gated variant shares weights with the standard release.
- None of the three vendors publishes an attestation standard, a named third-party certification, or a customer audit right over its own admission or safeguard decisions.
- Anthropic states its programme is currently US organisations only. OpenAI is the most explicit of the three about staged international access with no date attached. Google discloses a partner count but no country list.
- No New Zealand or Australian organisation appears on any public record as admitted to any of the three programmes, a pattern unchanged since this series first checked it in July.
- Three practical questions for any vendor offering a gated tier: what actually distinguishes the gated version, what does the vendor publish about how it decides, and who outside the vendor can check.
The open-source dimension of this sits two weeks earlier and one door over. Z.ai held back the downloadable weights of its GLM-5.3 model for roughly two weeks in August while it finished safety hardening, driven by capability the company said came back higher than its own post-training was designed to produce. It then published the weights anyway, on schedule, under a custom licence rather than the fully permissive terms of its prior release. Nothing stayed withheld; the control point moved from whether the weights existed to what terms governed them, a more inspectable position than a vendor-run admission list with no published criteria at all. An enterprise choosing between the two paths is not choosing open against closed. It is choosing a licence it can read in full before committing, against a decision it cannot read at all [8].
The implication on the sovereignty side is worth stating directly. The United States already runs a government-administered version of a similar structure for export-controlled technology: the Bureau of Industry and Security's Validated End-User authorisation, which pre-clears specific organisations for goods and technology that would otherwise require a licence for each transaction [9]. The difference is what the Bureau retains that these three vendors do not. Validated End-User status carries published eligibility criteria, and the authorising regulator keeps the right to audit and revoke it. Anthropic's Cyber Verification Program, Google's Fairwind, and OpenAI's Daybreak coalition borrow the shape of a government permission list without the government's obligation to publish how it decides or to answer to anyone who asks. A control that resembles export administration but answers to no external authority is not the same control, whatever it is called.
This series has now watched this axis move three times in four months. In July, it was access, binary and imposed from outside: a government could switch a model off, and did. In August, it was licence terms: Z.ai delayed its open weights, then published them anyway, under different terms than before. This month, at three vendors simultaneously, it is permission: nothing withheld at the level of capability, only at the level of who is allowed to use it, and the decision belongs entirely to the vendor. Each step has moved further from anything the customer standing outside the arrangement can verify. Access can at least be observed, a model answers or it does not. Licence terms can be read in full. Permission, administered privately with no attestation and no audit right, can only be taken on trust.
If your organisation applied to one of these three programmes tomorrow, what would you actually be able to verify about the decision that came back, and what would you do if the answer turned out to be nothing at all?
If your organisation is moving AI agents from pilot to production and nobody outside the vendor has inspected the control plane, message me and I will send the scope and the fixed fee for an independent review.
The views expressed in this article are entirely my own, informed by morethan 30 years of professional experience in architecture, security, andtechnology leadership in New Zealand. I write as director of Te PonoLimited; the views are personal and do not represent the position of anyclient, any government agency, or the New Zealand government. My commentaryon legislation and policy is analytical, drawing on publicly availablesources and my professional expertise in architecture, security, and AIgovernance, and it is politically neutral.
Andreas Hamberger is a New Zealand leader in Architecture & Security and Associate Member of the Institute of Directors. The Hamberger Report: Generative AI 2026 provides enterprise leaders with evidence-based analysis of the AI landscape. Through Te Pono he provides independent reviews of agentic AI control planes for organisations moving from pilot to production; contact andreas@thehambergerreport.com for the scope and fixed fee.
This article was produced with AI assistance under my direction. Research, drafting and images pass through a pipeline I built and govern: automated gates for source verification, forbidden language and political neutrality, and my own review before anything is published. The tools include Claude, Gemini and Openart. The frameworks, arguments and editorial judgements are mine and are the same discipline I apply to the AI systems I audit for clients. AI accelerated the work; the thinking, and the responsibility for it, are mine.
[1] Anthropic. "Introducing Claude Fable 5.1 and Claude Mythos 5.1." 1 September 2026. https://www.anthropic.com/claude-fable-and-mythos-5-1
[2] Google. "Google's Fairwind Program: Cyber defense tools for trusted partners." 2 September 2026. https://blog.google/innovation-and-ai/technology/safety-security/fairwind-program/
[3] CSO Online. "OpenAI launches GPT-6 Astra, its first model to cross a critical cybersecurity threshold." 4 September 2026. https://www.csoonline.com/article/4218679/openai-launches-gpt-6-astra-its-first-model-to-cross-a-critical-cybersecurity-threshold.html
[4] The Hacker News. "Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs." 2 September 2026. https://thehackernews.com/2026/09/google-anthropic-and-openai-unveil.html
[5] SecurityWeek. "OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders." 4 September 2026. https://www.securityweek.com/openai-pledges-1-billion-to-bring-frontier-ai-to-critical-infrastructure-defenders/
[6] RNZ. "NZ at wild frontier of AI superhacking." 24 May 2026. https://www.rnz.co.nz/news/science-and-technology/596203/nz-at-wild-frontier-of-ai-superhacking
[7] MarkTechPost. "OpenAI Releases GPT-6 Astra: A 1.05M-Context Computer-Use Model Gated Behind a 'Critical' Cyber Threshold." 3 September 2026. https://www.marktechpost.com/2026/09/03/openai-releases-gpt-6-astra-a-1-05m-context-computer-use-model-gated-behind-a-critical-cyber-threshold/
[8] Axios. "Z.ai delays GLM-5.3 open weights for cyber-safety hardening." 14 August 2026. (URL not captured in the source research package; cited in full without one per this project's URL integrity rule rather than an invented link.)
[9] United States Bureau of Industry and Security. "Validated End-User Authorization Program." Export Administration Regulations, Part 748. (URL not captured in the source research package; cited in full without one per this project's URL integrity rule rather than an invented link.)

