In this briefing
- 01Capability layer: the same underlying model no longer means the same access
- 02Risk layer: capability thresholds begin to change interruption semantics
- 03Data layer: monitoring enters the customer cloud while review remains customer-owned
- 04Execution layer: one task can divide work between cloud and local compute
- →What to watch next
- ↗Sources and verification
- Anthropic's Claude Fable 5.1 and Mythos 5.1 use the same underlying model, but the former is generally available through the API and the three major cloud platforms, while the latter is currently open only to vetted US institutions; Fable 5.1's cache-read price fell to the rate-card level “token 0.25 dollars per million”.
- OpenAI classifies Astra as its first model to reach the Critical cybersecurity-capability threshold but still describes it as forthcoming; advanced cybersecurity capabilities will initially be limited to testers, and added monitoring may slow, pause or stop legitimate tasks.
- Perplexity Hybrid Compute is open to Pro, Max and Enterprise subscriptions, using the cloud for complex reasoning, search and planning while handling sensitive files and device actions locally on an Apple silicon Mac; Anthropic's customer-cloud monitoring design, EFS, is due to be phased in this autumn.
Capability layer: the same underlying model no longer means the same access
On 1 September, Anthropic released Claude Fable 5.1 and Claude Mythos 5.1, stating explicitly that they use the same underlying model but apply safeguards of different strength and different access conditions. Fable 5.1 is available through Claude Pro, Max, Team, Enterprise, the Claude API, and Amazon Web Services, Google Cloud and Microsoft Azure; Mythos 5.1 is available through a trusted-access programme to vetted cyber-defence and life-sciences institutions, currently limited to a group of US institutions.
Fable 5.1's rate card keeps the input level “token 10 dollars per million” and output at 50 dollars per million, while the cache-read level “token 0.25 dollars per million” is 75% lower than Fable 5. Based on actual usage across four weeks in 2026-08, Anthropic estimates that typical workloads cost about 25% less and that high-context, tool-intensive Agent workloads cost up to about 45% less; these percentages are vendor estimates under its default effort and billing conditions, not general results for different enterprise workloads.
For enterprise deployment, the model name, underlying weights, safeguard configuration and access eligibility need to enter procurement and validation checklists separately. The same underlying model may expose different capabilities in a generally available version and a controlled-access version, and public benchmarks may use different safeguard conditions; price reductions deliver corresponding gains only for workloads with a high share of cache hits. Production evaluations are comparable only when the model version, access programme, fallback path, data retention and billing method match.
Risk layer: capability thresholds begin to change interruption semantics
Astra has not yet been released but, after public and private benchmarks and expert evaluations, was judged to have reached the Preparedness Framework's Critical cybersecurity-capability threshold. OpenAI announced this on the same day. The threshold covers finding unknown vulnerabilities and forming workable exploit chains with appropriate tools and access, or carrying out novel end-to-end attack strategies against hardened targets with less step-by-step human guidance. The displayed capability results use Daybreak Blue access conditions, not the default production configuration. OpenAI notes this distinction, and the full system card will be provided only when the model is released.
Astra is still described as forthcoming, and its advanced cybersecurity workflows will first be opened to a small group of alpha testers before defensive uses expand through Daybreak Blue. OpenAI says classifiers will inspect model reasoning and actions in production and automatically stop potentially unauthorised activity, while acknowledging that the added checks may misclassify legitimate tasks. In ChatGPT or Codex, a paused task may require human review; in other interfaces such as the API, the task stops immediately.
For enterprise deployment, the delivery boundary for frontier capabilities enters availability design directly. Restricted access, automatic stopping and human review can reduce the probability that high-risk capabilities are misused, but they also change the latency, retries, idempotency and service levels of long-running tasks. Astra has not been formally released. The current materials cannot be extrapolated to its price, regions, API form or general business performance. Even after release, results under controlled evaluation cannot replace validation of task-completion and false-interruption rates under the default production configuration.
Data layer: monitoring enters the customer cloud while review remains customer-owned
On the day it released Fable 5.1, Anthropic announced Enterprise Frontier Safeguards (EFS). The design keeps activity data used for monitoring in the customer's own cloud account, where customer-managed encryption keys, access policies and audit logs can continue to apply. Automated systems check rolling windows for severe abuse, leaked credentials and signals associated with offensive cyber or biological capabilities; flags go directly to the customer, whose personnel decide what happens next, and by default no manual review by Anthropic staff is required.
Customer-owned storage, customer-managed keys and fully automated review are all optional EFS capabilities. They are scheduled for phased rollout from this autumn, with broad availability targeted for later in the autumn, so EFS cannot currently be described as fully available. Anthropic says it co-designed the system with more than 100 enterprises as well as AWS, Google Cloud and Microsoft Azure. EFS carries no separate fee, but cloud providers still charge for storage, reads and writes, and data egress in the customer's cloud. Eligible customers can use zero data retention for Fable 5 and Fable 5.1 during the transition period.
For enterprise deployment, automated detection by the model provider, customer-held logs and keys, and final review by customer personnel form a more concrete division of responsibility than a single zero-retention promise. This also turns log integrity, retention periods, cross-account correlation, false alerts, response permissions and cloud-egress charges into separate operational items. Because EFS is not yet beyond staged rollout, applicable products, regions, log fields and data handling during failures still need to be governed by the actual contract and deployment documentation.
Execution layer: one task can divide work between cloud and local compute
On 1 September, Perplexity launched Hybrid Compute for Mac and opened it to Pro, Max and Enterprise subscriptions. Within one task, Perplexity Computer assigns frontier reasoning, web search and long-range planning to cloud models, while local models on the Mac handle private files, sensitive information and device actions. The Privacy Gate on the Mac detects information such as names, addresses, account details and keys before data leaves the device, and can keep it local, redact it, refuse to send it or request consent. Enterprise administrators can configure organisation-wide policies and audit when information leaves a device.
The feature requires Apple silicon, macOS 15 or later and at least 24GB of unified memory; the initial local models include Gemma 4 E4B, Qwen3.6 35B-A3B and Perplexity's own model. It is hybrid compute, not a fully offline arrangement, because the cloud still participates in reasoning, search and orchestration. VentureBeat also notes that the Privacy Gate is itself a classifier, and a missed detection can send sensitive information to the cloud. Public materials provide no uniform independent tests of local time to first token, throughput or power use across different Mac configurations.
For enterprise deployment, the data boundary can be refined from an application-level choice to specific steps within one task, with a local small model and a frontier cloud model working continuously through the same orchestrator. Availability remains constrained by hardware memory, the operating system, classifier accuracy, local-model quality, connectivity and cloud contracts, so sensitive steps being able to remain local cannot be presented as the entire workflow staying on the device. A single Mac product is also insufficient to prove that enterprise deployment has generally become smaller, but it provides verifiable device specifications and an already-open status that can serve as a new sample for tracking this hypothesis.
What to watch next
- The system card, default production configuration, regions and pricing after Astra is formally released, and the effect of automatic stopping on long-task completion and false-interruption rates.
- The actual availability scope of EFS, its log and alert fields, retention and deletion mechanisms, cross-account correlation, and the costs of reads, writes and egress in the customer cloud.
- Independent evaluation of the Hybrid Compute privacy classifier, local-model quality, latency, throughput and power use across Mac configurations, and progress towards support for Windows, Linux or other edge devices.
Sources and verification
Golden Data has edited this briefing from the public materials listed above. The original sources govern facts and figures. The enterprise relevance sections are Golden Data editorial analysis and do not constitute an endorsement of any third-party product.
← Back to AI Daily Briefing