How frontier labs are winning the cybersecurity market

TL;DR: OpenAI embeds in existing security workflows, Anthropic sells to security vendors, Google and Cisco ride distribution they already own. Whichever lands in the enterprise budget, a new $250k to $2M token line sits on top of the existing spend, and the labor budget is a target for cuts.

In the last few weeks I've been asked for my view on the frontier labs' cybersecurity GTM strategies and their impact on the broader cybersecurity market and on enterprises.

So I blew the dust off the MBA diploma, looked up the labs' most recent announcements and job postings, and asked Claude to be my thinking partner. Claude's guardrails deemed the topic dangerous though, so no Fable 5.

I took a look at the strategies of the labs, plus Cisco, which I added to my analysis to understand the SOC play. What core security products they push to the market, what specialized cyber models they have, what GTM strategies they deploy, and what their top bets look like.

Core product, cyber model, GTM, and the bet for OpenAI, Anthropic, Google, and Cisco.
Core product, cyber model, GTM, and the bet for OpenAI, Anthropic, Google, and Cisco.

OpenAI

OpenAI open-sourced Codex Security in July 2026 and released GPT-5.6-Cyber on August 10 for vetted defenders.

Field teams in San Francisco, Dublin, Tokyo, and Singapore embed with customers to wire the models into existing security workflows, from AppSec to SOC and GRC, converting analyst hours into metered consumption. Alongside that, the Daybreak Cyber Partner Program carries the models into partner products, and OpenAI for Government puts them, vetted through NSA and CISA evaluations, into federal defenders' hands.

OpenAI is betting on an AI reasoning and workflow layer on top of existing SOC tools, while being explicit that it's not building another SIEM or SOC.

Anthropic

The Claude Security plugin for Claude Code is in beta, and Mythos 5, the cyber model, is available to approved partners only.

Anthropic is putting $100M in credits behind 200 cybersecurity companies to use Claude in their detection, response, and security operations products. It also runs partner programs across SIEM/SOAR, EDR, identity, cloud, and GRC vendors.

The bet is to become Intel inside for cyber, with Claude as the best model for security vendors to build their products around.

Google

Google announced CodeMender, which finds and patches vulnerabilities, in public preview on July 21, and released Gemini 3.5 Flash Cyber the same day for governments and trusted partners.

Google's GTM investment goes into strengthening its existing sales workforce rather than building new teams. Security is sold through the Google Cloud sales force worldwide and through Mandiant consulting, which handles incident response, red teaming, and offensive security. In addition, a heavy federal push runs out of Reston, Virginia, and Washington, DC via Google Public Sector, which is building the Booz Allen of cyberspace.

Google's bet is to own and expand distribution. The model-agnostic CodeMender and Gemini 3.5 Flash Cyber optimized for volume signal that Google treats the model as a commodity rather than frontier intelligence. However, I don't support the ongoing theme that Google has left the frontier model race. I think it's just resolving an internal channel conflict between Google Cloud and DeepMind.

Cisco

Cisco shows an example of a good strategy for the security vendors that own an anchor product deployed in enterprises but don't have a frontier model.

Cisco has no standalone AI security tool, and its AI monetization goes through Splunk Enterprise Security, the SOC platform. It released Foundation-Sec-8B-Reasoning in January 2026 to protect a slot in the stack from being taken by the frontier labs' small models.

Like Google, Cisco relies on its distribution and its flagship Splunk to ride the AI wave.

Who else trained open-weight cyber models

  1. Trend Micro: Llama-Primus (August 2025), 8B and Nemotron-70B, the only one to also release open pretraining datasets.
  2. Kindo: Deep Hat (August 2025), an uncensored offensive and defensive 7B.
  3. Clouditera: SecGPT V2.0 (April 2025) in 1.5B, 7B, and 14B sizes, focused on Chinese-language security work.
  4. Trendyol: Cybersecurity-LLM (2025), Qwen3-32B and Llama-3.3-70B fine-tunes, GGUF only.

My take:

  1. The labs establish a strong presence in high-ticket accounts through forward deployed engineers (FDEs) at the fully loaded cost of $350k-$550k each. The goal seems twofold: convert security workflows into metered inference and de-risk AI agent deployment across the enterprise to unlock further token consumption.
  2. The total enterprise security cost will go up. The incumbent AppSec budget lines will remain for now and a new $250k-$2M token line lands on top of them, plus Accenture/PwC/Wipro/Cognizant fees to support what the FDEs built. The cost-avoidance song never works and reductions must happen somewhere. Most likely they land on the in-house or outsourced analyst budget lines.
  3. The AppSec vendors will have a double challenge: keep their presence in the refactored pipelines of their top accounts and keep the engineers in their consoles. The strong ones will remain the orchestration layer and resell tokens with governance on top. Many vendors will lose as contraction starts at their top accounts and renewal prices get challenged, because of the reduced perceived value. See my point above that reductions must happen somewhere.
  4. The SOC game will be different. The data-plane owners will most likely keep their power. The labs will convert analyst labor, in-house or outsourced to an MSSP, into metered inference. The trick for the MDR and MSSP providers, whose value used to be managing analyst pools and taking the 3 a.m. calls, would be to keep per-endpoint pricing while improving the economics with AI agents.

Sources:

  1. Daybreak (OpenAI) (Last accessed 08-14-2026)
  2. Expanding Daybreak as the cyber defense window narrows (OpenAI) (Last accessed 08-14-2026)
  3. Codex Security repository (GitHub) (Last accessed 08-13-2026)
  4. Project Glasswing (Anthropic) (Last accessed 08-12-2026)
  5. Claude Fable 5 and Claude Mythos 5 (Anthropic) (Last accessed 08-12-2026)
  6. Claude Security plugin (Claude Code docs) (Last accessed 08-14-2026)
  7. CodeMender public preview (Google Cloud) (Last accessed 08-12-2026)
  8. Introducing Gemini 3.5 Flash Cyber (Google DeepMind) (Last accessed 08-12-2026)
  9. Foundation-Sec-8B-Reasoning (Cisco) (Last accessed 08-12-2026)
  10. Cisco Foundation AI models (Hugging Face) (Last accessed 08-12-2026)
  11. Cisco elevates the SOC with agentic AI (Cisco) (Last accessed 08-12-2026)
  12. Trend Micro AI Lab models (Hugging Face) (Last accessed 08-12-2026)
  13. DeepHat-V1-7B (Hugging Face) (Last accessed 08-12-2026)
  14. Clouditera SecGPT models (Hugging Face) (Last accessed 08-12-2026)
  15. Trendyol Cybersecurity LLM v2 70B (Hugging Face) (Last accessed 08-12-2026)