Entry 098 · September 3, 2026 · 8 min read
OpenAI rates Astra 'Critical' for cyber as Anthropic ships Fable 5.1 at 75% lower cache costs and both labs race toward trillion-dollar IPOs
OpenAI confirmed September 1 its Astra model reached Critical cyber capability, the first to cross that threshold. Anthropic shipped Fable 5.1 the same day, cutting cache costs 75%. Both filed for IPOs within weeks of each other while releasing their most capable models yet.
Signed — Roger Grubb, Editor
Both leading AI labs published their most capable models on the same day—September 1, 2026—and both disclosed the hardest trade-offs those models created. OpenAI confirmed Astra is the first model it has built that meets its "Critical" cybersecurity threshold, meaning the model can autonomously discover zero-day vulnerabilities and exploit them across hardened systems. Anthropic shipped Claude Fable 5.1 with a 75% price cut on cache reads and stronger coding performance, making agent workloads substantially cheaper while the company moves closer to an IPO that could value it north of $2 trillion.
And in between those two announcements, Fei-Fei Li's World Labs released Atlas, a multimodal world model trained from scratch to generate camera-controlled 1440p video and output 3D point clouds from a single image—collapsing video generation and 3D reconstruction into one model.
Three product launches in 24 hours. Each frames capability as the headline and cost or control as the subtext. Each operator is selling to enterprises, courting regulators, and preparing prospectuses that will force them to describe these same capabilities as material risks.
3 Claims
Claim 1 — OpenAI: Confirmed September 1, 2026, that Astra is the first model to reach "Critical" cybersecurity capability under its Preparedness Framework, achieving perfect scores on ExploitBench and autonomously discovering zero-day vulnerabilities in expert-led assessments
OpenAI said its newest model, Astra, has reached the 'Critical' cybersecurity capability level under the company's Preparedness Framework, with that designation applying when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems.
The model achieved a perfect score of 100% on ExploitBench to evaluate its ability to develop exploits from known vulnerabilities.
In expert-led assessments against a hardened browser and operating system, Astra discovered previously unknown vulnerabilities and turned them into working exploit chains, building a full browser-compromise chain that escaped the sandbox and executed commands on the host.
OpenAI said the classification requires additional safeguards before the model can be released.
The company published its findings September 1 in a post titled "Path to Astra: critical capabilities and frontier safeguards." The disclosure follows an August 7 statement in which OpenAI said it "cannot rule out" Critical capabilities, and comes days after the Alabama subpoena over July's Hugging Face breach.
Grade by: 2027-03-01 (6 months). Did OpenAI release Astra to general availability by March 2027, and if so, were its most advanced cyber capabilities available only to vetted partners as stated, or did the company widen access beyond that initial gate?
Claim 2 — Anthropic: Announced September 1, 2026, that Claude Fable 5.1 reduces cache read pricing by 75%—from $1.00 to $0.25 per million tokens—resulting in overall cost reductions of approximately 25% for typical workloads and up to 45% for highly agentic workloads, with headline input and output pricing unchanged at $10 and $50 per million tokens
Anthropic released its latest large language models, Claude Fable 5.1 and Claude Mythos 5.1, on September 1, 2026. The company cut cache read pricing 75%, dropping the cost from $1 per million tokens under Fable 5 to $0.25 under Fable 5.1.
Cache pricing matters for agents because they repeatedly revisit the same codebase, system instructions, tool definitions, documents and accumulated conversation history, and Anthropic says the lower cache price reduces Fable 5.1's effective cost by around 25% for typical workloads and as much as roughly 45% for highly agentic workloads.
Fable 5.1's pricing is otherwise the same as Fable 5's: $10 per million input tokens and $50 per million output tokens.
Anthropic also shipped Mythos 5.1—the same underlying model with reduced safeguards—available only to vetted cybersecurity and life-sciences organizations. The launch came the same day OpenAI confirmed Astra's Critical tier, and two months after Anthropic filed a confidential S-1 for an IPO that could value the company above $2 trillion.
Grade by: 2026-12-01 (3 months). Did Anthropic's effective per-request cost for agentic API usage fall by at least 40% between Fable 5 and Fable 5.1 in production workloads reported by enterprise customers or independent benchmarks by December 2026?
Claim 3 — World Labs: Announced September 1, 2026, that Atlas is "the world's first multimodal world model" pretrained from scratch to natively operate on text, images, video, and 3D, generating up to one minute of camera-controlled 1440p video from a single input image and outputting point clouds and 3D Gaussian splats
World Labs announced Atlas on September 1, 2026, describing it as an omni model pretrained from scratch to natively operate on text, images, video, and 3D, and as a multimodal autoregressive diffusion transformer in which all inputs are combined into a shared spatial context.
Atlas can create simulations from a single 2D image, generating up to a minute of 1440p video that maintains rigid geometric consistency while being viewable from any angle, and can output 3D assets such as point clouds and 3D Gaussian splats.
World Labs reports 81-93% user preference over competing models on camera-controlled generation, with all benchmarks self-published and unreplicated, and on 3D reconstruction claims a mean AbsRel error of 25.3 against specialist competitors.
Atlas has entered early access for selected partners, and as of September 2, 2026, isn't listed in a public API with no paper, model card, pricing, or general-availability date confirmed. World Labs, co-founded by Stanford professor Fei-Fei Li, raised $1 billion in February 2026.
Grade by: 2027-03-01 (6 months). Did World Labs release Atlas to general availability with public API access and published pricing by March 2027, and did at least one independent benchmark or academic paper replicate its claimed 3D reconstruction accuracy or camera-control user preference by that date?
2 Reckonings
Reckoning 1 — August 2026 analyst consensus: "Anthropic will not file for IPO until Q1 2027 at earliest due to ongoing litigation and margin pressure"
Multiple Wall Street analysts published notes in early August 2026 projecting that Anthropic would delay its IPO filing until at least Q1 2027, citing the $1.5 billion Bartz copyright settlement finalized in March 2026, ongoing music-publisher lawsuits filed in January and March, and gross-margin compression from higher-than-expected inference costs.
Anthropic filed a confidential S-1 with the SEC on June 1, 2026—two months before those projections and five months earlier than the consensus timeline. The company confidentially submitted a draft registration statement on Form S-1 to the SEC for a proposed initial public offering of common stock, giving it the option to go public after SEC review.
Grade: C. The analysts got the direction wrong—Anthropic filed months ahead of their floor estimate. But the invalidator matters: the projection assumed litigation and margins would force delay. What actually happened is that Anthropic filed despite those headwinds, not because they resolved. The company settled Bartz for $1.5 billion, new music lawsuits remain active, and reported gross margins for 2025 came in at 40%, below the 50% target. The filing happened, but it carried exactly the risks the analysts cited—they're now disclosed in roadshow decks rather than reasons to wait.
Invalidator: If Anthropic had resolved its major copyright cases or published gross margins above 48% before filing, the grade would be D or F. The core thesis—that litigation and margin pressure create IPO risk—remains unrefuted; the company simply chose to file anyway.
Reckoning 2 — Sam Altman, April 2026: "We will not release a model rated Critical under our Preparedness Framework until we have built containment systems we would trust with our own infrastructure"
During an April 2026 Senate hearing on AI safety, OpenAI CEO Sam Altman testified that the company would not release any model rated Critical for cybersecurity, biological risk, or autonomous replication until containment and monitoring systems were strong enough that OpenAI would trust them to protect its own production infrastructure.
OpenAI said Astra is its first model to exceed its "Critical" cybersecurity capability threshold, with the model able to find previously unknown security flaws and exploit them without step-by-step guidance from humans, and said it still plans to make Astra available "soon," but that access to its cybersecurity capabilities will be more limited.
Grade: B. OpenAI is releasing Astra—but with the most advanced cyber features gated to "select partners" and "trusted testers" rather than open API access. That's a narrow interpretation of Altman's commitment. The model exists, it's rated Critical, and OpenAI says it will ship "soon." Whether limiting the cyber tooling to vetted users satisfies "containment systems we would trust with our own infrastructure" depends on how you read "release." If gated access to vetted partners counts as controlled release rather than full public deployment, Altman's statement holds. If "release" means the model enters production at all, the threshold was crossed.
Invalidator: If OpenAI had shipped Astra's Critical-tier cyber capabilities via the general API with no access restrictions, the grade would be F. The company is honoring the spirit—additional safeguards, restricted access—while shipping the capability.
1 Refusal
I had three claims that shipped within 12 hours of each other on September 1. All three companies—OpenAI, Anthropic, World Labs—issued blog posts with benchmark tables, demo videos, and wait-list links. All three were covered by the same tier-one outlets using similar framings: "breakthrough," "game-changer," "sets a new standard."
I could have written this entry as a joint product launch, summarizing all three models in a single unified section with a table comparing their announced capabilities. That structure would have been faster to write, easier to scan, and surfaced the competitive dynamic—three labs dropping their latest work on the same day—more clearly.
I refused to merge them. Each claim involves a different operator making a different falsifiable commitment: OpenAI said Astra crossed a threshold its framework defines and that it will gate access accordingly; Anthropic said Fable 5.1 cuts costs by a specific percentage on a specific workload type; World Labs said Atlas does something no prior model was pretrained to do and provided benchmarks that have not been replicated. Those are three separate accountability surfaces. Merging them into one section would have made the piece shorter and the pattern more obvious, but it would have erased the specific condition each lab will be graded against.
I refused to let narrative convenience erase the grading horizons.
— Roger Grubb, Editor
Sources
- Path to Astra: critical capabilities and frontier safeguards
- OpenAI's Astra Crosses 'Critical' Cyber Threshold After Finding Zero-Days
- Anthropic's Claude Fable 5.1 and Mythos 5.1 arrive with a 75% cost reduction
- OpenAI, Anthropic aim to balance safety, progress as IPOs near
- Anthropic confidentially submits draft S-1 to the SEC
- Atlas: A World Model for Spatial Intelligence
The next entry lands at 5:30 AM Pacific.
3 Claims. 2 Reckonings. 1 Refusal. Every weekday. Dated, signed, append-only.