Palo Alto rents out the cyber models Anthropic and OpenAI keep locked

Unit 42's Continuous Frontier AI Defense sells Claude Mythos 5 and GPT-5.6-Cyber behind an annual subscription priced by model mix. The gate built as a safety control is now the moat, and the risk of the models spreading sits with everyone outside it.

Vincent JiangVincent Jiang · 3 min read
Share
Nikesh Arora, chairman and chief executive of Palo Alto Networks, in a portrait photograph
1 / 6Slide 1 of 6
Nikesh Arora, chairman and chief executive of Palo Alto Networks.

The only way to buy a model the labs keep locked

Palo Alto Networks opened subscriptions on 22 September to Unit 42 Continuous Frontier AI Defense, an always-on offensive security service that runs Anthropic's Claude Mythos 5 and OpenAI's GPT-5.6-Cyber against customers' web apps, APIs, cloud and code 1. After a full-estate scan it keeps testing as systems change, proposing code fixes or temporary "virtual" patches 4.

Neither model is sold to the public. OpenAI confines GPT-5.6-Cyber to Daybreak Red, its tier for offensive cyber work 2. Anthropic has kept Mythos out of general release because it finds flaws and chains them into working attacks too well to hand out freely 3. The price varies with the mix of Anthropic, OpenAI and open-weight models a customer chooses 4.

From export freeze to invoice line

The gate has a short, loud history. In June, Washington blocked Anthropic from offering Mythos 5 to foreign nationals and businesses; by late June, Commerce had cleared it for release to "certain trusted partners" 5, and access returned on 1 July 4. In June, Mythos was a national-security risk. By September, it is a line on an enterprise invoice: Unit 42's Sam Rubin markets "exclusive access to gated capability models" 1.

Anthropic built the resale template itself, launching Glasswing on 7 April with $100M of API credits for roughly 50 partners, Microsoft and Apple among them 3. Rubrik holds the same gated-resale position, earlier in its cycle: Code Guardian runs Mythos 5 against an air-gapped copy of customers' code, in private preview 6.

A franchise re-accelerating under the moat

The pitch lands on a franchise that just sped up. Fiscal 2026 revenue reached $11.48B, up 24.5%, and next-generation security ARR stood at $8.13B, up 60% 7. Quarterly growth jumped from the mid-teens a year ago to 34.5% in the July quarter 8. Bernstein's 17 September downgrade to Market Perform, target $351, prices the other side: a $282M GAAP net loss and a stock that already assumes delivery 7.

Growth reaccelerated from the mid-teens to 34% in the second half of fiscal 2026

$1.5B$2B$2.5B$3B$3.5BQ2 FY24Q4 FY24Q2 FY25Q4 FY25Q2 FY26Q4 FY26$3.41BAnthropic launches Glasswing 7April
Data
Revenue
Q1 FY24$1.88B
Q2 FY24$1.98B
Q3 FY24$1.99B
Q4 FY24$2.19B
Q1 FY25$2.14B
Q2 FY25$2.26B
Q3 FY25$2.29B
Q4 FY25$2.54B
Q1 FY26$2.47B
Q2 FY26$2.59B
Q3 FY26$3B
Q4 FY26$3.41B
Quarterly revenue, US$ billions, as reported in SEC filings; fiscal year ends 31 July. Source: Sharadar quarterly fundamentals.8,7

Receipts, and 21,119 findings nobody checked

Palo Alto's numbers are company-claimed: six months and $17M across more than 100 engagements, exposures at every customer tested, 37% of them high or critical, and a year's worth of exposures on its own systems found in three weeks 4. The company also claims, without independent verification, that AI attackers compress breach cycles by almost 97%, from weeks to hours 4.

Independent audit cuts both ways. External reviewers confirmed 90.8% of the 1,900 checked Mythos findings, and one Linux kernel root exploit cost under $2,000 of compute 9. But 21,119 of 23,019 candidate bugs have never been reviewed outside Anthropic, and independent scorers called 13 of 27 CVE-rated findings overstated 9.

The labs say the channel is the safeguard

OpenAI's McCall McIntyre says Daybreak pairs the cyber models with "strong governance, and human judgment" 1. Capability is the draw: OpenAI's own tests have GPT-5.6-Cyber completing 95% of a set of sensitive offensive requests, against 1.5% for the public model 2.

The buyer's fear is blunter. "The Chinese will have Mythos next month. What do I do?" said Yevgeny Dibrov, ServiceNow's SVP and GM of cybersecurity and risk, calling it the top board-level concern 10. That risk lands on everyone outside the gate: subscribers get their own attack paths checked, but the flaws sit in open-source software everyone runs, and most findings have never been checked outside Anthropic 9.

Palo Alto's November report will show whether the subscription adds ARR 7. What nobody will see is the split: the share of each subscription flowing back to Anthropic and OpenAI is not public.

How this brief was made

01Gathered & sourced409 channels · 1,462 articles▾

Agents swept 409 channels and ingested 1,462 articles, then de-duplicated and ranked them for signal.

02Verified & cross-validated10 claims · 28 data feeds▾
03Reviewed & edited1 human editor▾

One editor read the draft against the evidence, tuned the framing, and signed off before it shipped.

Become a contributor

Reporting on the business of AI and want it read? We take pitches from outside contributors who bring primary sources and a number worth arguing about.

Share

Deepdive

AI-generated from this story and its cited sources. Not investment advice.

Reader comments

0 comments

    Sign up

    Get your curated digest

    After email confirmation, you will receive a daily digest of the most relevant news that matter to your portfolio