The Same Model Shipped Twice and Only the Eligibility Changed

The Same Model Shipped Twice and Only the Eligibility Changed

In three days at the start of September, Anthropic and OpenAI both shipped their top model in two versions that differ by who is allowed to use it rather than what you pay. The argument is that the frontier has stopped being a single public artifact, and that capability gating buys time rather than safety.

In the first three days of September, two AI labs shipped their best model twice. Same weights, two doors, and the difference between the doors is not what you pay. It is who you are.

Keys demonstrating access to LLMs, with one key being locked in a box

In the first three days of September, two AI labs shipped their best model twice. Same weights, two doors, and the difference between the doors is not what you pay. It is who you are.

On 1 September 2026 Anthropic released Claude Fable 5.1 for general use and Claude Mythos 5.1 for a vetted set of organisations. Anthropic was unusually plain about the mechanics: Fable and Mythos are the same underlying model with different levels of safeguards. Mythos sits behind trusted access programmes covering cyber defence and life sciences, and at launch it was available to vetted professionals at selected US organisations, with Anthropic saying it was working with the US government on widening that out.

Two days later, on 3 September, OpenAI began rolling out GPT-6 Astra. Astra is the first model OpenAI has designated as reaching the Critical cybersecurity threshold under its Preparedness Framework, meaning that with the right tools and access it can find unknown vulnerabilities and build exploit chains against well defended systems without a human steering it the whole way. The sharpest version of that capability is not going out with the general release. It goes to trusted defenders through a gated programme, with priority given to organisations that protect critical digital infrastructure.

Most of the coverage of that week argued about two things. Whether Astra counts as AGI, and whether any of this is safe. Both are fair arguments and I have nothing new to add to either. The thing I have not seen anyone say is much duller and, I think, more consequential.

The frontier has stopped being one public object

For about four years, the top of the market worked in a way everybody understood without having to think about it. The best model was a thing you could buy. It cost more than the second best model. If you had a credit card and an internet connection you had the same ceiling as a Fortune 500. That was not a policy anyone designed. It was just what happened when capability was sold rather than allocated.

That ceiling is now conditional. As of this month, the honest answer to "what is the most capable model I can use" is no longer a number on a pricing page. It is an eligibility question, and the eligibility criteria are not published, the assessor is a private company, and there is no stated appeals route if the answer is no.

I want to be careful here, because this is the point where the argument usually goes silly. Nobody has taken anything away. The general tier of both releases is extremely good, better than what was available a quarter ago, and for the overwhelming majority of commercial work the gated tier would make no difference whatsoever. If you are automating quotes or triaging inbound, this changes nothing about your week.

But the shape of the market changed, and shape is the kind of thing that only looks obvious later.

Price is a bad gate that has one great property

Price sorts people by money, which is unfair in an obvious and well understood way. Its one virtue is that it is legible. You can read it, plan against it, budget for it, and complain about it in public. If a model costs eight times what you can afford, you know exactly what you are excluded from and exactly what would change that.

Vetting sorts people by institutional standing. It is probably fairer in intent. It is far less legible. A security consultancy in Bangkok and a US critical infrastructure operator can be equally competent, equally ethical, and equally in need of the tool, and only one of them is currently in the room. Right now geography is doing a lot of the sorting, because that is where the programmes started and where the regulatory relationships already exist. That is not a conspiracy. It is just how any vetting scheme boots up. But the effect is a capability gap that runs along institutional and national lines rather than along skill lines, and unlike a price gap, you cannot see the size of it from outside.

The threat model the gate does not cover

Here is the part that bothers me most, and I hold it loosely because I am not a security researcher.

Gating works well against the casual bad actor. It works less well against the serious one, because the serious one does not apply. A well resourced adversary has three routes that the gate does not touch. Compromise an organisation that was approved. Recruit somebody inside one. Or wait, because open weight models keep closing the distance on last year's frontier and waiting is free.

So the gate reliably excludes the mid tier legitimate defender, the small national CERT, the regional consultancy, the in house security team at a mid sized firm, and only probabilistically excludes the attacker. That is not an argument against gating. It is an argument that what gating actually buys is time, not safety, and those are different purchases. Time is genuinely valuable. A year of defenders having something attackers mostly do not is a real advantage. But it should be described as what it is, a temporary asymmetry with a decay curve, rather than as a control.

The state is already inside the loop

None of this is happening in a vacuum. Executive Order 14409, signed on 2 June 2026, set up a voluntary process where developers give the federal government access to covered frontier models for thirty days before release, and gives the Director of the NSA the authority to determine what counts as a covered frontier model in the first place. The order goes out of its way to say it does not create a mandatory licensing or preclearance regime.

I believe that disclaimer is sincere. I also think it is beside the point. A voluntary scheme that every serious lab participates in, whose criteria are classified, and which sits upstream of who gets access to what, does most of the work a licensing regime would do. It just does it without the administrative law that normally comes attached to licensing, the published criteria, the reasons, the right of reply, the route to challenge a decision.

That is not a complaint about anyone acting in bad faith. It is a complaint about a governance structure that has grown up faster than the procedures that would normally surround it.

What I cannot verify from out here

The honest limits of my own argument.

I do not know how big the gap is. Anthropic says Fable and Mythos are the same model with different safeguards, and I have no way to measure what the safeguards actually withhold. It could be a large gap or a narrow one. I am reasoning about a shape I cannot see the size of, and so is everyone else outside the programmes. In fairness, that opacity is partly the point of the exercise.

I also think the counterargument is strong. If a model genuinely can build exploit chains against hardened systems without supervision, shipping that to anyone with a payment method is worse than what they did. And running the same base model with different safeguard tiers is a real improvement on the older alternative, which was to sit on the model entirely or ship it lobotomised for everybody. Both labs chose a harder engineering path than the easy options available to them, and that deserves saying.

So I am not arguing they got the call wrong. I am arguing that a structural change happened in three days, in public, and it got read as a story about model capability when it is really a story about distribution.

The question nobody has answered

Who is a defender, and what happens when the answer is wrong.

Every gated programme so far has been described in terms of who gets in. None of them has said much about the other half. What are the criteria. Who applies them. What does an organisation that is refused get told. Is there a review. What happens to a customer whose access is withdrawn mid contract because a rule changed upstream, or because their country moved into a different category. These are not exotic hypotheticals. They are the first questions any regulated industry had to answer, usually after getting them wrong publicly.

I would rather that conversation happened now, while the programmes are small and the people running them are still open to being argued with, than in two years after somebody competent and legitimate gets shut out of the tool their job depends on and there is no process to appeal to.

I might have this backwards. The case against me is that vetting at this stage is necessarily informal because the risk is moving faster than any procedure could, and that demanding published criteria now would either freeze the criteria too early or hand adversaries a map of exactly what to fake. That is a serious objection and I do not have a clean answer to it.

So the open question I would actually like an argument about. Is there a version of capability gating that stays fast enough to be useful and still gives a refused applicant a reason and a route back. Or is the honest position that we have accepted a discretionary system, and the work is making sure the discretion sits somewhere we can at least watch.

I drafted parts of this with AI assistance, which feels like the minimum disclosure given the subject.