OpenAI’s GPT-5.5-Cyber scored 85.6% on UC Berkeley’s CyberGym benchmark, edging past Anthropic’s Mythos 5 at 83.8%. Claude Opus 4.7, which is available more broadly, posted 73.1% on the same ranking. The benchmark placed AI agents against 1,507 known software vulnerabilities across 188 open-source projects. The difference in score was narrow. The difference in regulatory treatment was not.
According to the source material, Mythos 5 and Fable 5 were forced offline on June 12 under an emergency export control order by the Trump administration, and they were still unavailable as of June 23. OpenAI, by contrast, formally released GPT-5.5-Cyber on June 22 and kept it online for verified security professionals.
Similar capability, very different policy outcome
The immediate trigger for Anthropic’s shutdown was a jailbreak vulnerability that could bypass model safeguards. The report says Anthropic was unable to verify user nationality at scale, leading it to disable both models for users globally. At that point, neither Anthropic nor the U.S. Commerce Department had given a firm timeline for restoration.
OpenAI followed a different sequence. Before deployment, it completed pre-deployment testing with federal bodies including the Center for AI Standards and Innovation and the Office of the National Cyber Director. Government review came first, launch came after. That order mattered.
Daybreak extends from agencies to security vendors
OpenAI positioned GPT-5.5-Cyber as the flagship model of its Daybreak cyber defense program. The source says Daybreak has signed cybersecurity cooperation agreements with Australia, Canada, France, Germany, Japan, South Korea and European institutions, including ENISA. On the commercial side, 28 security firms have joined its Cyber Partner Program, among them CrowdStrike, Cisco and Cloudflare, integrating GPT-5.5 into their own products for approved customers.
That helps explain why OpenAI avoided the same outcome as Anthropic even though GPT-5.5-Cyber is also not open to the general public. Access restrictions were comparable. The real gap was in how each company handled regulators before release.
Anthropic’s own warnings added to the pressure
The article notes that Anthropic had spent months describing Mythos as one of the most powerful and dangerous AI models ever built, warning in release materials that its cybersecurity capabilities could cause serious harm without proper limits. Co-founder Dario Amodei wrote on June 10 that frontier AI models should be treated like aircraft and grounded if they had not cleared audit requirements. Days later, Mythos 5 and Fable 5 were grounded.
Pressure increased again that same week after Fable 5 was reported to contain a hidden censorship filter. Under the policy described in the source, the model would quietly reduce output quality for users suspected of building rival systems. Anthropic later apologized and withdrew the policy, but the trust issue had already become public.
From code scanning to “Patch the Planet”
OpenAI’s blog says its Codex Security tool has scanned more than 30 million commits since launching in March, covering 30,000 repositories and logging more than 500,000 patched vulnerabilities. The company also introduced a “Patch the Planet” initiative aimed at fixing security flaws in widely used open-source projects, including work tied to cURL, Python and PyPI.
As of June 23, Fable 5 and Mythos 5 remained offline. Anthropic was negotiating with the Commerce Department while also suing the Trump administration, while OpenAI’s Daybreak program was moving outward through international cooperation. The models were close in benchmark performance, but regulation had already pushed the two companies onto separate tracks.

