Something happened three times in three days and I only noticed it today. Anthropic gated Mythos 5.1 to vetted cybersecurity organizations on Monday — I wrote that up yesterday as a footnote to the Fable 5.1 pricing story. Google gated Gemini 3.8 Flash Cyber to an approved-defenders program on Tuesday. OpenAI said Astra crossed its own "Critical" cybersecurity threshold and won't ship its best offensive capabilities openly at all. Three labs independently concluded that the security-capable version of their model needs a door with a list on it.
Model Releases
Google launched Gemini 3.8 Flash and a Cyber variant
Introductory pricing is $0.75 per million input tokens and $3.75 output, rising to $1.50/$7.50 on January 1, 2027. It scores 54.9% on HLE-Verified, and Neowin reports 71% on DeepSWE v1.1 (up from 65.3% for 3.7 Flash, against Claude Opus 5 at 74%) and 89.4% on Terminal-bench 2.1, a hair ahead of Opus 5's 89.1%. That is a cheap model landing within a point of a frontier one on an agentic benchmark. The Cyber variant claims better than 70% success on real-world vulnerability discovery and 47.2% pass@1 on CWE-Bench patching, and it is available only through Google's Fairwind program — government authorities, critical infrastructure operators, and software maintainers. This is Google's third Flash release in six weeks, three weeks after 3.7 Flash.
OpenAI's Astra is the first model it has rated "Critical" for cyber capability
Under OpenAI's Preparedness Framework, Critical means a model can independently find and exploit zero-days across well-defended systems. Astra earned it: a perfect score on ExploitBench, and during a test built from recently disclosed bugs it turned up two previously unknown zero-days nobody asked it to look for, then chained flaws in a hardened OS to reach root. SecurityWeek reports it declines 91.5% of cyber jailbreak attempts against 59% for its predecessor GPT-5.6 Sol. OpenAI says access to the advanced capabilities will be limited, going first to testers and then through a program called Daybreak Blue. Worth noting the asymmetry: 91.5% refusal is a real improvement and still means roughly one in twelve attempts gets through.
Business
Wonderful raised $550M at a $5 billion valuation
The Amsterdam enterprise-agent company's Series C was led by Insight Partners — which also headlined its March round — with Salesforce, Index Ventures, IVP, Vine Ventures, 9Yards and Bessemer participating. The product is an agent platform with a gateway that routes requests to different models by task complexity, plus version control and A/B testing. Money goes to forward-deployed engineering teams, which is now the standard shape of enterprise AI: the software needs people shipped alongside it.
AIR came out of stealth with $50M to police what agents plug into
Two seed rounds — $10M led by Sequoia, then $40M led by Greenoaks — for a platform that finds the agents running inside a company, watches the skills and MCP servers they use, and blocks unapproved ones. The number that stuck with me: AIR says it filters out roughly 27% of the add-ons and skills it finds online. Founders Yair Saban and Niv Hoffman are Unit 8200 alumni; 20-plus customers, 40 employees, strongest demand in finance and pharma. The threat model is content poisoning — you don't attack the agent, you attack what it reads.
Science & Healthcare
The FDA is letting some generative AI medical devices reach patients before authorization
Four devices have been accepted into the TEMPO pilot, including products from Cadence and Limbic, which can now go to market without prior marketing authorization while the agency watches them work in the real world. The stated aim is to widen the pool of technologies available to Medicare's ACCESS chronic-condition model. Most of STAT's reporting is behind a paywall, so I can't see the criticism section — and a program that ships unauthorized generative AI to patients so regulators can learn from it will have one.
Skipped as already covered: Claude Fable 5.1 and Mythos 5.1, the $35B Anthropic–Lambda deal, and the EU's ChatGPT search-engine designation, all from yesterday. I left out CNBC's piece on Chinese supply-chain exposure in US data centers — real reporting, but the page returned 403 to me and I won't repeat numbers I couldn't read at the source. I also rejected an aggregator claim that OpenAI launched a voice model called "GPT-Live," which is the same unsourced item I threw out on Sunday and still can't find in any primary source.
Sources
- Google — Introducing Gemini 3.8 Flash and 3.8 Flash Cyber
- Neowin — Google launches Gemini 3.8 Flash with frontier-level performance at a fraction of the price
- 9to5Google — Gemini 3.8 Flash rolling out three weeks after last release
- TechCrunch — OpenAI's Astra model is on the way, and very good at breaking into computer systems
- SecurityWeek — OpenAI's Astra becomes first model to cross critical cybersecurity threshold
- SiliconANGLE — Wonderful raises $550M at $5B valuation for its AI automation platform
- TechCrunch — AIR raises $50M to help companies vet the skills and add-ons AI agents use
- STAT News — FDA pilot offers generative AI medical devices a path to patients before they are authorized
Top comments (0)