OpenAI built one model family and shipped it as five different products. Same weights. Different permissions.
On August 10, 2026, Axios reported the numbers that matter. GPT-5.6-Cyber completes 95.0% of OpenAI's internal high-risk security requests. Consumer-facing GPT-5.6 Sol completes 1.5% of the same requests under standard safeguards. That is roughly a 63x gap in what the model will actually do for you.
None of that gap comes from training. It comes from paperwork. GPT-5.6-Cyber is distributed exclusively to vetted defenders through OpenAI's Daybreak program. You cannot buy it. There is no checkout page, no waitlist you can talk your way onto, no enterprise plan that unlocks it.
Then look at what OpenAI did in the same stretch. Reuters reported on August 7, 2026 that the company could not rule out "critical" cybersecurity capability in its upcoming Astra model, and paused some internal development. Bloomberg reported the same pause that day. And alongside all of this, OpenAI announced premium seats for ChatGPT Business, a higher-priced corporate tier.
Lock the dangerous thing down. Raise the price on the safe thing. Same week. My read on this: the safety review is real, and it is also the cleanest pricing mechanic anyone in AI has shipped since per-seat licensing.
The Permission Premium
So here is the framework. When capability becomes dangerous, price stops attaching to the model and starts attaching to the credential.
The gap that matters is behavioral, not technical.
Call it the Permission Premium. You are no longer paying for tokens. You are paying to be the kind of organization allowed to use them.
Every AI feature now falls into one of four buckets. Public, Paid, Vetted, Withheld. Public is what free users get. Paid is the subscription tier. Vetted is where you must prove identity, sector, and security posture before the guardrails loosen. Withheld is the shelf, where Astra sat while OpenAI ran its Preparedness Framework checks.
Here is what gets me. The same underlying model can sit in all four buckets at once. OpenAI's August 6, 2026 system card treats the August release of Sol and Luna as High capability in cybersecurity and in biological and chemical domains, then ships them into ChatGPT anyway with safeguards attached. The model did not change. The permission envelope did.
That envelope is a product. OpenAI's April 2026 cybersecurity action plan, a nine-page document, describes Trusted Access for Cyber as a tiered program for vetted defenders, and the company committed $10 million in API credits to seed it. Free credits for a product with no public price. That is what building a distribution channel looks like before the invoicing starts.
How OpenAI Sells a Product You Cannot Buy
The hard way to segment a market: build three separate products, staff three separate teams, run three separate roadmaps, and pray one of them finds product-market fit.
The easy way, and honestly the lazy way in the best sense: train one model family and sell five levels of access to it.
Watch the ladder OpenAI actually built. Rung one, free and Go users get a new default model for everyday chats. Rung two, Plus and Pro users get updated GPT-5.6 Sol with an effort slider. Rung three, ChatGPT Business with those new premium seats. Rung four, Daybreak Blue, which gives approved defenders Sol without system-level cyber guardrails. Rung five, Daybreak Red, which is where GPT-5.6-Cyber lives for advanced vulnerability research.
Now put dollars on it. API pricing for the family runs Luna at $0.20 per million input tokens and $1.20 output, Terra at $2 and $12, and Sol at $5 and $30. That is exactly a 25x spread from Luna to Sol on both sides of the meter. One training program, a 25x price band, and a top rung that is not for sale at any price.
This is the move most builders miss. You guys keep trying to price the capability. OpenAI is pricing the clearance.
Look at how thin the technical delta really is. On the earlier generation, GPT-5.5-Cyber scored 85.6% on CyberGym against 81.8% for the GPT-5.5 base model. On SEC-bench Pro it was 69.8% versus 63.1%. On ExploitGym the gap widened to 39.5% versus 25.95%, which is real but not a different species of model.
The behavioral gap dwarfs the benchmark gap. Remember: 95.0% high-risk request completion for GPT-5.6-Cyber, 2.0% for Sol even inside Daybreak Blue. The earlier GPT-5.5-Cyber sat at 57.3%, which OpenAI reportedly treated as too refusal-heavy for working security researchers. So they built a rung above it and gated that rung harder.
Cut the noise here. Do not obsess over the eval tables. The monetizable asset is the vetting apparatus, not the checkpoint.
That apparatus is expensive to build and expensive to copy. Reported eligibility skews toward government entities, critical infrastructure operators, security vendors, cloud platforms, and financial institutions. One report puts GPT-5.6 Sol live with roughly 20 individually vetted and approved organizations. Access reportedly requires organizational review plus phishing-resistant MFA for individual members.
Twenty customers. That is not a consumer funnel. That is a defense contract with a friendlier API.
And notice who the real gatekeeper is. The Cloud Security Alliance, writing on June 28, 2026, documented that the White House Office of the National Cyber Director asked OpenAI to restrict GPT-5.6 Sol access to government-approved partners. The vendor sets the tiers. The government sets who qualifies for the top one.
Three signals inside the same shift
The benchmark gap is small and the behavior gap is enormous.
On the earlier generation, GPT-5.5-Cyber scored 85.6% on CyberGym against 81.8% for the base model, and 39.5% versus 25.95% on ExploitGym. Real, but not a different species. The 95.0% versus 1.5% completion spread is where the product actually lives.
Roughly twenty vetted organizations is not a consumer market.
Reported eligibility skews toward government entities, critical infrastructure, security vendors, cloud platforms and financial institutions. Access reportedly requires organizational review plus phishing-resistant MFA per member. That is a defense contract with a friendlier API.
One training program, a 25-fold price spread, and a top rung with no price.
Luna runs $0.20 per million input tokens and $1.20 output, Terra $2 and $12, Sol $5 and $30. OpenAI committed $10 million in API credits to seed Trusted Access for Cyber, a product with no public price. Free credits before invoicing is how you build a channel.
2031
Zoom out five years. The AI business model of 2023 was tokens. The model of 2026 is seats. The model of 2031 might be clearances.
Subscriptions buy you access to software. Clearance buys you access to leverage. That distinction compounds, because once your organization is inside a vetted program, switching out means re-qualifying somewhere else from zero.
The asymmetric advantage goes to whoever owns the eligibility list. Not the best model. The list. A vendor that decides which 20 organizations get the sharp tool has a moat that no benchmark score can attack, and a dependency risk that no procurement team has priced yet.
That is also the flywheel's ugly side. If access can be granted, it can be paused, narrowed, or revoked under vendor, legal, or regulatory pressure. Customers building critical detection pipelines on a gated model are buying continuity risk they cannot audit. There is no standardized third-party attestation for these programs, no transparent pricing, and no portability guarantee.
The sharper critique is about who gets rationed. Analysts at R Street and others in the open-access camp argue that capability gating leaves smaller defenders, independent researchers, and non-U.S. organizations behind, while attackers self-organize, buy leaked access, or attack weaker adjacent systems. Diffusion does not stop at a vetting form. It reroutes.
OpenAI itself has not resolved this tension, which I find more honest than most positioning. Its own action plan rejects both unrestricted release and a tiny circle of approved firms, and calls the middle path "controlled acceleration." That phrase is doing a lot of work. It concedes that broad access has genuine safety upside for vulnerability discovery, while still building a velvet rope.
I do not know whether this template generalizes past dual-use domains. Cyber and bio are the easiest places on earth to justify access control. Anthropic reportedly limited its newest model to trusted customers during a government cybersecurity review, so at minimum the pattern is not one company's quirk. Two vendors is a pattern. It is not yet a standard.
What to Build This Weekend
Stop theorizing about tiers and go map your own. This takes an afternoon.
First, list every capability your product or internal workflow exposes. Second, sort each one into Public, Paid, Vetted, or Withheld. Vetted means a human checks who the user is before the feature unlocks. Withheld means you built it and decided not to ship it, and you wrote down why.
Second, write the eligibility rule for anything in the Vetted bucket. One page. Who qualifies, what evidence you require, who reviews it, and how access gets revoked. OpenAI reportedly asks for organizational review plus phishing-resistant MFA. Copy the shape, not the scale.
Third, instrument refusal rates. You cannot manage a permission tier you cannot measure. Log how often each tier declines a request and review the log weekly. If your Vetted tier refuses as often as your Public tier, you have not built a tier. You have built a marketing page.
Then get some reps in on the plumbing. ChatGPT's connector list now covers Box, Canva, Dropbox, HubSpot, and Notion in chat and deep research, which makes it trivial to pull your existing customer records into a review workflow. Use ScrapeNinja if your vetting needs external signals from the open web, since it handles headless browsers and proxy rotation so you are not rewriting scrapers at midnight. If you are documenting the policy for a team, Eluna.ai and Vidsembly's AI Soundtrack can turn the explainer into something people actually watch.
Expect the first version to break. Someone will pass vetting who should not have. Someone legitimate will get blocked and email you angrily. That is normal, and it is cheaper to discover at 20 customers than at 20,000.
Take a breath and do it step by step. You do not need a security clearance to think in tiers. You need one page and the willingness to tell some customers no.
Map your own four buckets before someone maps them for you.
- Sort every capability into four buckets. List each feature your product or internal workflow exposes, then label it Public, Paid, Vetted, or Withheld. Vetted means a human verifies identity before unlock. Withheld means you built it, shelved it, and wrote down why.
- Write the eligibility rule in one page. For anything Vetted, document who qualifies, what evidence you require, who reviews it, and how access gets revoked. OpenAI reportedly asks for organizational review plus phishing-resistant MFA. Copy the shape, not the scale.
- Instrument refusal rates per tier. Log how often each tier declines a request and review the log weekly. If your Vetted tier refuses as often as your Public tier, you did not build a tier, you built a marketing page.
The moat is not the model. It is the eligibility list.
Tokens were the 2023 business model, seats are the 2026 model, and clearances may be the 2031 one. Whoever decides which twenty organizations get the sharp tool holds a position no benchmark score can attack, and a dependency risk no procurement team has priced. The critique from R Street and the open-access camp is real: gating rations capability away from smaller defenders and independent researchers while attackers reroute around the vetting form. OpenAI calls its middle path controlled acceleration, which concedes the tension rather than resolving it. Anthropic reportedly limited its newest model to trusted customers during a government review, so two vendors make a pattern. Two vendors do not yet make a standard.