Anthropic and OpenAI now decide who can use their most capable models, and offensive security researchers say the vetting is keeping the wrong people out.
Mark Dowd has spent two decades finding the software flaws that Western governments pay a premium for. In late June, the AI that would help him find the next one got a lot harder to reach, and not because of anything he did.
Dowd can name a zero-day, a previously unknown software flaw, and sell the details to a Western intelligence agency the same week. On the Three Buddy Problem podcast this month, he put the new arrangement plainly: "It's not really comfortable to me that these random large companies are making arbitrary decisions about what is safe in security and what's not." He is exactly the user the labs say they want behind the gate. The gate, in this case, is Anthropic's real-time cyber safeguards program and the related Cyber Verification Program (CVP), a vetting track that gives approved researchers a less restricted version of the company's most capable models. OpenAI runs a parallel program called Trusted Access for Cyber, internally branded as Daybreak, with its own application form and troubleshooting flow.
Offensive security, in plain terms, is the work of breaking software on purpose so it can be fixed. The researchers who do it are the same people governments and Fortune 500 companies hire to test systems before adversaries do. Their deliverables are bug reports and proof-of-concept exploits; their customers are the defenders.
In June, the U.S. government imposed export controls on two Anthropic models, codenamed Mythos and Fable, at least partly in response to a TechCrunch report claiming their cyber guardrails could be bypassed. Fable 5 returned to general access on July 1. Mythos 5 came back too, but only to vetted U.S. organizations under government review. For everyone else, including most of the offensive-security community, the model is effectively off-limits. That June-July sequence is the clearest public data point yet on what a frontier access regime looks like in practice, and it raises a question the lab PR pages do not answer: who, exactly, is on the right side of the gate.
Chris Anley told TechCrunch that the new vetting process adds days of waiting and re-submission to work that used to be a prompt. Anley studies the kind of low-level memory corruption bugs that have driven some of the most damaging exploits of the last decade. He does not object to the existence of a gate; he objects to not knowing what is on the other side of it.
The pattern repeats across both major vendors. OpenAI's Trusted Access for Cyber overview describes an application flow that asks for institutional affiliation, a research statement, and a sample of prior work. Anthropic's CVP, by the same account, asks for similar artifacts. Neither vendor publishes a rubric. Neither publishes an appeals process. Neither publishes a list of who has been turned down.
The same model that can help Anley find a buffer overflow can help someone else build a ransomware payload. The vendors learned that lesson the hard way; the export controls on Mythos and Fable are the regulatory receipt. Some friction is the price of shipping the model at all.
The researchers' case is equally straightforward, and it is the part the wire coverage tends to flatten. When a gate is conservative by default, the cost of a wrong answer is invisible: a bug that does not get found, a research lead that goes cold, a young researcher who decides the application is not worth the paperwork. The labs do not measure those costs because they do not have a way to.
The next test is whether the July 1 split is the new normal. If Mythos 5 stays gated, every successor model will be gated too, and "vetted access" stops being a special track and becomes the only track. The application form, in that world, is not a side door. It is the door.
The labs have not said which it will be. Dowd, for his part, is not asking for the gate to come down. He is asking who decided it was up.