Last week, all four frontier labs shipped inside 72 hours. Anthropic opened with Claude Fable 5.1. Google and Meta launched the next day. OpenAI closed the week with GPT-6 Astra and a declaration... "Welcome to the AGI era."
Three of the four labs shipped two versions of the same model. One you can buy. One you have to be approved for.
Anthropic's Mythos 5.1 is Fable 5.1 with safeguards lifted in some areas, available only through two named programmes... one for vetted cybersecurity work, one for life sciences, built with the US government. Google paired Gemini 3.8 Flash, cheap and generally available, with Gemini 3.8 Flash Cyber, restricted to its Fairwind Program of government authorities, critical-infrastructure operators and other vetted defenders. OpenAI rated Astra the first model to hit its own critical cybersecurity threshold and kept those capabilities with a small circle of trusted testers.
And the restricted versions are seriously capable. Google says Flash Cyber found a critical vulnerability for its own security team in under two hours... work that normally takes months. Astra formatted contracts and drafted a tax return from a W-2 in its demos, and OpenAI admitted the model got harder to monitor in oversight testing. So the top tier does professional-grade work that its own maker struggles to watch. Hence the vetting.
The other unbuyable tier
And it's not just the labs deciding what stays off the market. The most sophisticated buyers are doing it too.
Kirkland & Ellis is spending 500 million dollars on an AI platform it refuses to license... its chairman's argument being that tools everyone can buy raise the floor for everyone, so they cannot make you better than the firm across the street. Goodwin built Regina, its own operating system. Thomson Reuters trained a model on decades of Westlaw and Practical Law content... a training set it has gone to court to defend. And Harvey's big move this year was productising exactly this... post-train an open-weight model, own the result, keep your intelligence instead of renting it.
So AI now comes in three layers. A commodity layer anyone can buy, getting cheaper and better by the month. A restricted layer the labs ration by approval. And a private layer firms build and refuse to sell.
Almost every vendor pitch your firm receives lives in the commodity layer. So does your competitor.
The commodity layer is convulsing
Google shipped its third Flash model in six weeks at 75 cents per million input tokens... and announced the price doubles in January. Anthropic cut cache pricing by 75%, which it says lowers effective costs by 25 to 45% depending on workload.
And yet the bills keep going the other way. The Information reported that ServiceNow started monitoring employee usage after burning through its annual Anthropic budget, and Anthropic's own run-rate revenue has tripled since December, past 30 billion dollars. Unit prices fall, spend explodes, because usage grows faster than prices drop. Firms are starting to manage AI the way manufacturers manage electricity.
What this means if you run a firm
The floor is rising and the ceiling is gated. Everything you can buy, your competitor can buy the same afternoon, cheaper by the quarter. Whatever advantage AI gives a professional firm now lives in the two layers that are not for sale... the one you qualify for, and the one you build.
A firm negotiating an enterprise AI contract this quarter should be running four vendors against each other on January's price rises, not accepting list rates. And when input costs drop 25 to 45% in a week, how you charge decides who keeps the saving... a firm priced on outcomes banks the difference, a firm billing by the hour hands it to the client, because the conduct rules require billing the time actually spent. The faster the floor drops, the more expensive the billable hour becomes.
As for building... Kirkland's bet looked extravagant when it was announced. After a week in which the buyable tier was repriced twice and the unbuyable tiers multiplied, it looks like a position. And the entry price has collapsed. Harvey post-trained an open-weight base in two months. Thomson Reuters spent 40 million dollars over two years on its model, of which the final training run was about 450,000. Owning a model is no longer a Kirkland-sized decision.
What I think happens next
The verification programmes spread beyond cyber and biology. The first time a model can find exploitable gaps in contracts or regulation the way Flash Cyber finds them in code, there will be a Fairwind for professional services... and a bar association or financial regulator will demand a seat as a trusted tester, because supervising a profession whose core input it cannot inspect won't hold for long.
The labs spent the week arguing about whether this is AGI. I think that's the least interesting question they raised. The interesting one is that the best AI in any domain is steadily leaving the open market... and your firm's position now depends on what you can qualify for or build, because what you can buy, everyone has.
One question I keep turning over... does the top tier stay gated, or does competition eventually force it open? I have a view, but I'd rather hear yours. Hit reply... I read everything, and the sharpest replies shape the next edition.
Subscribe and every one lands in your inbox.
See you next time.
