Saturday, 12 September 2026
ZAR/USDR16.160.06%. Rand weaker against the US dollar
ZAR/EURR18.730.13%. Rand stronger against the euro
ZAR/GBPR21.830.00%. Rand flat against the pound
Tech & Telco

AI’s strongest cyber defence models are US-only, and South African defenders are not on the list

AI’s strongest cyber defence models are US-only, and South African defenders are not on the list

Anthropic’s most capable cybersecurity model is not for sale, and the company is entirely open about why. What is less widely noticed in South Africa is the second half of that sentence: it is not for sale here in particular.

On its own product page for Claude Mythos, Anthropic describes the model as available to “vetted cyberdefenders and life scientists through our trusted access programs”, limited to “a small, but growing, set of vetted organizations”. The page then states the constraint plainly: “we’re only able to make it available to a set of US organizations, though we’re working to expand access.”

That is the company’s own statement of its own policy, which makes it about as reliable as a fact of this kind gets. It also describes a structural arrangement that has quietly become the industry norm over the past six weeks, and that nobody locally has been discussing.

The same model, two sets of brakes

The technical arrangement is worth understanding, because it is not what most people assume when they hear that a lab has a special security model.

Mythos 5.1 and Claude Fable 5.1, the general model this site covered on 10 September, are not two different systems. They are the same underlying engine running two different safety configurations. Fable is that engine with its guardrails in place. Mythos is the same engine with some of those guardrails selectively lifted for defensive work: vulnerability discovery, threat intelligence, red teaming.

The capability, in other words, was never the scarce thing. The permission is. And the permission is being handed out on a list.

Google has built the same shape. Alongside Gemini 3.8 Flash it shipped Gemini 3.8 Flash Cyber, a security-focused variant aimed at vulnerability discovery and automated patching, which is not generally purchasable and is instead gated behind an application-based programme Google calls Fairwind, described as open to trusted government authorities, critical-infrastructure operators and software maintainers. OpenAI’s GPT-6 Astra, which this site covered on 10 September, was the first model the company judged to have crossed the Critical cybersecurity threshold under its own Preparedness Framework.

Three of the largest labs, in roughly a month, all landed on the same answer to the same problem.

The logic of the gate, and where it leaks

The reasoning behind the restriction is sound and the labs state it clearly: a model good enough to find vulnerabilities at scale is equally good at finding them for someone with worse intentions. Gating the unrestricted version to verified defenders is meant to buy defenders time to find and fix flaws before the same capability becomes generally available.

It is a head start, deliberately engineered. The difficulty is that a head start allocated by jurisdiction is not a head start for everyone, and the threat it is defending against was never organised by jurisdiction in the first place.

A South African bank, insurer, hospital group, municipality or internet provider is precisely the sort of critical-infrastructure operator these programmes name. It faces the same automated scanning, the same ransomware crews and the same commodity tooling as its American equivalent. What it does not have, on Anthropic’s published position, is access to the defensive tier. What it does have, like anyone else with a corporate card, is access to the capable general models, which are sold in South Africa without restriction.

What is actually known, and what is not

The honest limits of this are worth stating, because it would be easy to overstate.

Anthropic’s US-only restriction is explicit and quoted above, and the company says it is working to expand access, without publishing a timeline. Google’s Fairwind criteria, as reported, describe the categories of organisation eligible rather than any geographic limit, so it does not follow that a South African operator could not be approved, and this piece does not claim that. Neither company publishes a list of participants. No public record establishes whether any South African organisation has applied to either programme, or been admitted, and that could not be established for this article.

So the accurate statement is narrower than the alarming one: the most capable defensive configuration from at least one major lab is, by that lab’s own account, currently unavailable to South African organisations, and the broader pattern of gated defender tiers is real across at least three labs.

What does reach South Africa

The gate is on raw model access, and that is not the only channel.

Security capability built on these models reaches customers through products rather than through API keys. SecurityWeek has reported that Anthropic’s codebase scanning feature for enterprise customers runs on the Mythos generation, and that the company is working the capability into existing security operations and incident response tooling through partners. A South African business buying a security product from a vendor that has access is getting some of the benefit without being on the list itself.

Anthropic has also committed $35 million in model credits to a fund aimed at open source security work, including patching live vulnerabilities in widely used projects. Open source security is genuinely borderless: a flaw patched in a library used by South African banks is patched for South African banks, regardless of who did the patching or where they were sitting.

What an ordinary business should take from this

For most SMEs, this is context rather than an action item, and it would be a mistake to read it as a reason to worry about something you cannot buy anyway.

The attacks that actually take down small South African businesses are not exotic. They are unpatched software, reused passwords, staff who were never given a way to verify an unusual payment request, and backups nobody has tested a restore from. None of that is affected by which frontier model a defender in another country can access, and all of it is cheaper to fix than it is to survive.

Where this does matter is a level up, in procurement and in policy. If you are buying security services, the access a vendor holds is now a real differentiator and a fair question to ask. And for the people who will eventually write South Africa’s AI rules, currently rather busy rewriting a draft that had to be withdrawn, the question of whether South African defenders can reach the defensive tier of frontier AI is a national capability question, not a commercial one.

The capability exists. The gate is the policy. Somebody should be asking to be let through it.

This is the third frontier AI story this site has covered in a week: alongside GPT-6 Astra’s own cybersecurity threshold and Gemini 3.8 Flash’s pricing changes, it points at the same underlying story: the most capable AI tools are arriving, and being restricted, faster than South Africa’s own AI policy has managed to catch up with any of it. For the practical side of using what is actually available here, see our guide to AI tools for small business.

This report is based on a statement available at www.anthropic.com.