OpenAI said Astra has crossed its “Critical” cybersecurity threshold, while Google and Anthropic separately unveiled new cyber-focused models and tighter access programs for trusted defenders. Google’s Gemini 3.8 Flash Cyber is now in the Fairwind Program, and Anthropic is limiting some of its strongest models to trusted access channels.
The practical change is that these systems are no longer just helping people reason about bugs; they can independently find weaknesses and, in OpenAI’s testing, turn them into working exploits or chain flaws against hardened targets. That is why the vendors are pairing capability gains with release gating, early-access programs, and stricter safeguards instead of treating access as a generic product launch.
For organizations that use frontier models for code review, vulnerability research, or security automation, the control question now matters as much as the model’s raw skill. If a model can do part of the exploit chain on its own, who is allowed to use it, and under what guardrails, becomes part of the defense picture.