Three labs shipped a security-gated model in three days. Anthropic published a full rate card for one its own cyber programme cannot sell you yet, Google published no number at all, and OpenAI published a pointer.
Claude Mythos 5.1 landed September 1, Gemini 3.8 Flash Cyber September 2, and OpenAI's $1 billion Daybreak commitment September 3. All three are models you have to be approved to touch, and all three answer the question "what does it cost" differently. One answers in seven exact figures. One does not answer. One answers by pointing at a model you already have a price for, and says the pointer will move.

Three labs, three days, three different answers
| Lab | Model | Shipped | What it says about price |
|---|---|---|---|
| Anthropic | Claude Mythos 5.1 | September 1 | Full seven-line rate card, published. Invite-only under Project Glasswing, and the cyber programme does not carry it yet. |
| Gemini 3.8 Flash Cyber | September 2 | No price on any surface. No model ID. Fairwind Program by application, and resale is contractually forbidden. | |
| OpenAI | Daybreak Blue and Red | September 3 | No card of their own. Both are aliases onto GPT-5.6 models, and OpenAI says the pointer will move. |
A published price normally means you can go and pay it. None of these three do. That is worth working through properly, because the gap between a rate card and a purchase is where most of the interesting arithmetic in this week's releases actually sits.
Anthropic printed seven numbers, and they are somebody else's numbers
Mythos 5.1 sits in the main pricing table as its own row, and the model page removes any ambiguity about how it was priced: it shares Claude Fable 5.1's specifications and pricing. Not approximately, and not on the headline lines only. Read the two columns and there is no cell where they part company.
| Line, per million tokens | Mythos 5.1, gated | Fable 5.1, open |
|---|---|---|
| Input | $10.00 | $10.00 |
| Output | $50.00 | $50.00 |
| Cache write, 5-minute | $12.50 | $12.50 |
| Cache write, 1-hour | $20.00 | $20.00 |
| Cache read | $0.25 | $0.25 |
| Batch input | $5.00 | $5.00 |
| Batch output | $25.00 | $25.00 |
| Context window | 1,000,000 | 1,000,000 |
| Max output | 128,000 | 128,000 |
That $0.25 cache read is the interesting one, and we wrote about it on Tuesday when it was a Fable 5.1 story. Anthropic had priced a cache hit at exactly a tenth of base input on every model it has ever sold. Fable 5.1 and Mythos 5.1 are the first two exceptions at 0.025x, and the footnote naming them names both. So the cut did not go to the model people can buy and stop there. It went to the generation, and the gated twin came along.
Now the part that makes this a strange rate card. Anthropic says Mythos 5.1 is available to vetted cyberdefenders and life scientists, through the Cyber Verification Program and the Life Sciences Verification Program. Read the CVP page and it says something narrower: the programme currently provides access to certain Opus- and Sonnet-class models, and will also include Mythos-class models in the near future. The cyber door, today, is a form that registers interest. Only the life sciences programme is described as having enrolled anybody, and that was done in partnership with the US government.
So Anthropic has published a complete, unambiguous, seven-line price for a model that its own cyber programme cannot presently sell to a cyberdefender. The price is real. The transaction is not, yet.
Google shipped a model and did not publish a number anywhere
We went looking for a Gemini 3.8 Flash Cyber rate on every surface Google prices models on. The Vertex AI pricing page does not have one; pulling the raw page and searching it, the string "cyber" appears four times and every one is site navigation for Cybershield and Mandiant, nowhere near a pricing table. The Gemini API pricing page has no row. The DeepMind model page carries no cost information. The Fairwind Program page carries no cost information. The launch post does not mention a price. Google has not even published an API model identifier for it.
Fairwind is an application programme, and the eligibility list is institutional rather than commercial: governments and national cyber authorities, critical infrastructure operators across healthcare, telecommunications, energy and financial networks, and core technology platforms. Applicants have to show a proven track record of ethical operations and research, and implement user-level authentication and phishing-resistant MFA.
One clause in the Fairwind terms explains the missing price better than the missing price does. Access cannot be shared, redistributed or sold. A rate card exists so that a thing can change hands at a known number, and Google has written down that this thing does not change hands at all. Publishing a price would be describing a transaction the programme forbids.
For scale, the model you can buy is cheap. Gemini 3.8 Flash lists at $0.75 input and $3.75 output on introductory pricing that runs through December 31, 2026 and then doubles to $1.50 and $7.50. We covered that expiry on Wednesday. Whether Cyber inherits any of it is unknowable, which is the honest answer and the only one available.
OpenAI's cyber models have no price because they are not models
Both Daybreak model pages are live. Neither carries a rate card. They list rate limits by tier, from 500 RPM and 500K TPM at Tier 1 up to 15,000 RPM and 40M TPM at Tier 5, and then link out to the central pricing page. Search that pricing page for "daybreak" and there is no row.
The reason is stated plainly in OpenAI's own documentation: gpt-daybreak-blue-latest and gpt-daybreak-red-latest are aliases that currently point to gpt-5.6-sol and gpt-5.6-cyber. Daybreak Red does not share a price with GPT-5.6 Cyber by coincidence. It is GPT-5.6 Cyber.
| Alias | Resolves to | Input | Cached | Output |
|---|---|---|---|---|
| Daybreak Blue | gpt-5.6-sol | $4.00 | $0.40 | $20.00 |
| Daybreak Red | gpt-5.6-cyber | $12.50 | $1.25 | $75.00 |
OpenAI then adds the sentence that makes budgeting against these names hard. As new models are released through the Daybreak programme, the aliases will be updated to point to the latest models, with pricing adjusted to match each underlying model. Your model string is stable and your rate is not. Anybody forecasting a Daybreak spend is forecasting against a redirect, and the two targets it currently has differ by 3.52x on a blended basis.
What a billion dollars of subsidised access actually buys
One wording correction first, because it matters for a pricing post. A lot of the coverage called this $1 billion in credits. OpenAI did not. The announcement says subsidised access, and the only credits OpenAI names anywhere on that page are a separate, much smaller offer of up to $1 million in no-cost API credits to states and utilities after attacks on US water systems. The $1 billion covers access, training, technical support and partnerships, starting with the United States, and OpenAI is targeting it to be consumed over the next six months.
A subsidy denominated against a published rate card is still a token quantity, though, and the aliases tell us which card. Here is what the money converts to at a 3:1 input-to-output blend. These are our figures on OpenAI's published rates, not OpenAI's, and they assume every dollar goes to inference, which it explicitly does not.
| Routing | Blended per 1M | Tokens for $1B | Per day, 180 days |
|---|---|---|---|
| Daybreak Blue, no caching | $8.0000 | 125.00 trillion | 694 billion |
| Daybreak Blue, 85% cache hits | $5.7050 | 175.29 trillion | 974 billion |
| Daybreak Red, no caching | $28.1250 | 35.56 trillion | 198 billion |
| Daybreak Red, 85% cache hits | $20.9531 | 47.73 trillion | 265 billion |
Read the first and third rows together. The same billion dollars is 125 trillion tokens or 35.6 trillion tokens depending on nothing except which of the two aliases a defender is approved for. Not on how well they cache, not on how efficiently they prompt, and not on anything they can negotiate. Blue is the mainline model for common defensive work and Red is the specialised one for sensitive vulnerability research, so the split is a policy decision made during approval, and it moves the value of the grant by a factor of three and a half. OpenAI says thousands of defenders across 2,000 approved organisations already use Daybreak, which puts the average at $500,000 an organisation if the money were spread evenly, and nothing suggests it will be.
Red is the only one of the three that loses its discounts too
Gating a model and gating its discount tiers are separate decisions, and the two vendors with published prices made them differently. Mythos 5.1 keeps everything Fable 5.1 has, batch included, at $5.00 and $25.00. GPT-5.6 Cyber supports only the Responses API; Chat Completions, Realtime, Assistants and Batch are all unavailable, and OpenAI publishes no batch, flex or fast rate for it. There is one price and one way to call it.
| Comparison at a 3:1 blend | Daybreak Red | Mythos 5.1 | Ratio |
|---|---|---|---|
| Standard rate | $28.1250 | $20.0000 | 1.41x |
| Best rate each model publishes | $28.1250 | $10.0000 | 2.81x |
On rate card alone Red costs about 41% more than Mythos 5.1. Once each model is allowed to use the cheapest tier it actually publishes, Red costs nearly three times as much, because Mythos can halve and Red cannot. The missing tier is worth more than the headline gap. For a lot of defensive work that stings more than it looks like it should: corpus sweeps, retrospective log analysis and bulk triage of an issue backlog are exactly the latency-tolerant jobs batch exists for, and they are a large share of what a resource-constrained security team wants a model for in the first place.
One vulnerability triage run, priced on every card that exists
Assume an agent working through a repository: 1,000 turns, 60,000 input tokens a turn because it keeps the codebase in context, 3,000 output tokens a turn, and an 85% cache hit rate because most of that prompt is the same repository every time. The token counts are assumptions chosen to be legible; the rates are published.
| Model | Standard | Batch | Note |
|---|---|---|---|
| Daybreak Blue | $116.40 | $58.20 | gpt-5.6-sol, batch available |
| Daybreak Red | $401.25 | no batch tier | Responses API only |
| Mythos 5.1 | $252.75 | $126.38 | full 50% batch discount |
| Gemini 3.8 Flash Cyber | no published rate | no published rate | priced row below is the ungated model |
| Gemini 3.8 Flash, ungated | $21.82 | $10.91 | introductory, doubles January 1 |
Blue and Red are the same programme, the same approval, the same $1 billion, and $284.85 apart on one run. Red against Mythos 5.1 is a smaller spread, about 59% more, and it inverts if the work can batch. The Gemini row is there to show the order of magnitude the gated model is being withheld from rather than to compare like with like, and the honest reading of it is that a cheap Flash-class model doing this job for around twenty dollars is the reason the Cyber variant's missing price is interesting at all.
One caveat on the Gemini row. It uses the same 85% hit rate as the others, applied to Google's $0.075 cached input, which is the introductory rate and halves again on Batch. Google bills implicit and explicit caching differently and charges $0.50 per million tokens per hour to hold an explicit cache, none of which is in that $21.82. Treat it as indicative of the order of magnitude rather than as a quote.
The resale layer knows exactly which of these you can buy
We pulled OpenRouter's full catalogue and searched it rather than trusting a summary, because the interesting result here is an absence and absences are easy to get wrong. The file is 714,005 bytes and carries 431 models. Searching both the id and name fields, case-insensitively: zero rows matching mythos, zero matching daybreak, zero matching cyber, zero matching glasswing.
Their ungated twins are all present. Claude Fable 5.1 is there with a batch variant, Claude Fable 5 is there with a batch variant, and Gemini 3.8 Flash is there with a batch variant. Five Fable rows and two Gemini 3.8 rows, and not one row for any of the three models this post is about.
That is the cleanest available test of whether a price is a price. An aggregator lists what it can resell. Google's Fairwind terms forbid resale in as many words, OpenAI's Daybreak models require separate approval and provisioning, and Anthropic's Mythos 5.1 is invite-only. Three different mechanisms, one identical result in the one catalogue that only cares about whether a transaction is possible.
"Same model" is doing different work in each of these sentences
All three vendors tie their gated model to an ungated one, and it is tempting to read those claims as equivalent. They are not, and the differences run in the direction that should make you most cautious about the cheapest comparison.
| Lab | What they actually wrote | How strong that is |
|---|---|---|
| Anthropic | "the same model, but with different levels of safeguards" | Flat identity. Safeguards fork only. |
| "powered by the same foundational intelligence" | Shared base, plus specialised training and looser mitigations. | |
| OpenAI | "aliases that currently point to gpt-5.6-sol and gpt-5.6-cyber" | Not an identity claim at all. A redirect, with a stated intent to move it. |
Anthropic's is the strongest and the easiest to price: identical model, identical card, one fork in safeguards. Google's shares a base and then adds specialised training on top, so borrowing Gemini 3.8 Flash's $0.75 as a proxy for Cyber is a guess about a different artifact, not an inference about the same one. And OpenAI's is not an identity claim in the first place. It is a redirect with a documented intent to be repointed later.
The number about to get misquoted is Google's 70%
Three figures are circulating for Gemini 3.8 Flash Cyber and they come from three different places. The one being repeated most is the weakest sourced.
| Benchmark | Score | Provenance |
|---|---|---|
| Internal, 20 programming languages | above 70% | Google's own, unnamed benchmark |
| CyberGym, pass@1 | 86.2% | named by DeepMind as the industry standard |
| CWE-Bench, pass@1 | 47.2% | external |
"Above 70% real-world vulnerability discovery" is a phrase you will see this week. Google wrote something narrower: a success rate exceeding 70% on an internal benchmark spanning 20 programming languages. It is unnamed, unreleased and Google's own. The named benchmark on CyberGym, which DeepMind itself calls the industry standard for finding vulnerabilities, is 86.2% pass@1, and the external CWE-Bench figure is 47.2%. If you are going to quote one number for this model, the 86.2% is better attributed and the 47.2% is more sobering. The 70% is the only one of the three nobody outside Google can check.
Mythos 5.1 is US-only twice over, and the two do not cancel
Anthropic says Mythos 5.1 is currently available only to a set of US organisations, and that it is coordinating with the US government to widen that to domestic and international partners. That is a restriction on who may hold an account. Separately, Anthropic charges a 1.1x multiplier on every token category for Claude 4.6 and later models when you pin inference_geo to "us", which is a restriction on where the request runs and it costs money.
Being a US-only organisation does not get you US-only routing for free. A US cyberdefender who needs the data residency guarantee pays $11.00 input, $0.275 cache read, $13.75 and $22.00 on cache writes, $55.00 output, and $5.50 and $27.50 on batch. Anthropic does not name Mythos 5.1 individually in that rule, so this rests on the generational scope statement covering 4.6 and later rather than on a Mythos-specific sentence.
OpenAI's equivalent is geographic in a different way: the $1 billion starts with the United States, with an intent to expand to partner countries in the coming weeks. Google's Fairwind eligibility is written around institution type rather than country. Three gates, three shapes, and only one of them shows up as a line item.
Which of these numbers you should actually put in a budget
If you are approved for Daybreak, the number that matters is not the rate, it is which alias you were approved for, and you should find that out before modelling anything. Blue and Red differ by 3.52x blended and Red cannot batch, so a workload plan built on Blue economics falls apart if the approval comes back Red. Ask, and put the answer in the model, because OpenAI has told you the alias will be repointed later and given no notice period for it.
If you are waiting on Mythos 5.1 for cyberdefence, the price is genuinely settled and the availability is not. Budget at Fable 5.1's card, because that is what Anthropic has committed to in writing, and treat the CVP timeline as unknown rather than imminent. The one thing the published card does buy you today is the ability to prototype against Fable 5.1 at identical rates and have the arithmetic survive the switch.
And if you are looking at Gemini 3.8 Flash Cyber, there is nothing to budget. No rate, no model ID, no resale, no aggregator row. Anyone quoting you a per-token figure for it this week is extrapolating from the ungated model, and Google's own wording about specialised training on top of a shared base is the reason that extrapolation is not safe. The absence is not an oversight to be filled in with a plausible guess. It is currently the most accurate thing anybody can tell you about what that model costs.
Sources, and what we could not pin down
- Anthropic: Claude pricing - Read September 5, 2026. Mythos 5.1 and Fable 5.1 as separate rows at $10.00, $50.00, $12.50 and $20.00 cache writes, $0.25 cache read, $5.00 and $25.00 on Batch; the footnote stating that cache hits and refreshes on Fable 5.1 and Mythos 5.1 are priced at 0.025x base input while all other models use the standard 0.1x; the "limited availability" label linking to Project Glasswing; the 1.1x inference_geo multiplier on all token categories for Claude 4.6 and later; and the Managed Agents exclusion table
- Anthropic: Claude Fable 5.1 and Mythos 5.1 - September 1, 2026. The sentences that Fable 5.1 and Mythos 5.1 are the same model with different levels of safeguards, that Fable 5.1 is generally available while Mythos 5.1 is available only through trusted access programmes, that Mythos 5.1 is available to vetted cyberdefenders and life scientists, and that it is currently available only to a set of US organisations. Also the Cyber Verification Program wording placing Mythos-class access in the near future rather than today, against the Life Sciences Verification Program having enrolled its first participants
- OpenAI: gpt-daybreak-red-latest and gpt-daybreak-blue-latest - Both pages live and carrying no rate card, only per-tier rate limits and a link to central pricing; the statement that the two names are aliases currently pointing to gpt-5.6-sol and gpt-5.6-cyber; the note that aliases will be updated to the latest models with pricing adjusted to match; the separate approval and provisioning requirement; and the Responses-API-only restriction on the Red target that removes Batch. Note the un-prefixed URLs without "gpt-" return 404
- OpenAI: API pricing - The gpt-5.6-sol row at $4.00 / $0.40 / $5.00 cache write / $20.00 with batch at $2.00 and $10.00, and the gpt-5.6-cyber row at $12.50 / $1.25 / $15.625 cache write / $75.00 with no batch, flex or fast tier published. Searching the page for "daybreak" returns no row
- OpenAI: Daybreak for Frontline Defenders - September 3, 2026. The $1 billion in subsidised Daybreak access, training, technical support and partnerships, starting with the United States and targeted to be consumed over the next six months; the separate up-to-$1 million no-cost API credit offer to states and utilities after the water system attacks; the eligibility list; the figure of thousands of defenders across 2,000 approved organisations already using Daybreak; and the split of Blue for common defensive work on mainline models against Red for specialised cyber models
- Google DeepMind: Fairwind Program and the 3.8 Flash and 3.8 Flash Cyber launch post - September 2, 2026. Eligibility across governments and national cyber authorities, critical infrastructure operators and core technology platforms; the proven-track-record and MFA requirements; the clause that access cannot be shared, redistributed or sold; the "same foundational intelligence" wording plus specialised training and more permissive mitigations; the internal 20-language benchmark above 70%; CyberGym 86.2% pass@1 and CWE-Bench 47.2% pass@1
- Google Cloud: Vertex AI generative AI pricing - Gemini 3.8 Flash at $0.75 and $3.75 introductory through December 31, 2026, stepping to $1.50 and $7.50 on January 1, 2027, with cached input $0.075 and batch $0.375 and $1.875. The page carries no Gemini 3.8 Flash Cyber row and no occurrence of "fairwind"
- OpenRouter: full model catalogue - Pulled September 5, 2026. 714,005 bytes, 431 models. Zero rows matching mythos, daybreak, cyber or glasswing across the id and name fields; five Fable rows including batch variants and two Gemini 3.8 Flash rows
- TokenCost: the Fable 5.1 cache read cut and the Gemini 3.8 Flash introductory price - Our September 2 and September 3 posts establishing the two ungated cards this one leans on
- What we could not establish. Google publishes no price, no model ID and no cost statement for Gemini 3.8 Flash Cyber on any surface we could find, so every Gemini figure here belongs to the ungated model and is labelled that way; the row in the triage table is an order-of-magnitude marker, not a forecast. Whether Daybreak Red is billed to participants at all, or fully subsidised, or subsidised in part, is not stated anywhere in OpenAI's announcement, so the $1 billion conversion is arithmetic on published rates and should not be read as a claim about what defenders will be invoiced. The same conversion assumes the whole commitment goes to inference, which OpenAI explicitly contradicts by listing training, technical support and partnerships alongside access. The 3:1 input-to-output blend, the 60,000-token prompts and the 85% cache hit rate in the workload table are our assumptions, picked to be legible rather than typical. Anthropic does not name Mythos 5.1 individually in the inference_geo rule, so the 1.1x figures rest on the scope statement covering Claude 4.6 and later. Anthropic's Project Glasswing page describes Claude Mythos Preview at $25.00 and $125.00, which is an earlier and different model from Mythos 5.1 and is not the card used anywhere above. And no vendor has said whether a gated model's price is meant to be paid or is simply inherited from the twin it forked from, which is the question underneath this entire post