The AI You're Not Allowed to Use

The gates are closing and the keys are on the table.


This week, three of the most powerful AI companies in the world closed the door at the same time.

On Monday, Anthropic confirmed that its most powerful model ever built, Claude Mythos, will not be released to the public. It has been locked behind a programme called Project Glasswing, where 40 handpicked organisations including Amazon, Apple, Microsoft, and CrowdStrike will use the model to scan critical software for vulnerabilities. Anthropic committed $100 million in usage credits for these partners. Everyone else was told to wait.

The same day, OpenAI published a 13-page paper called "Industrial Policy for the Intelligence Age," a blueprint for how governments should restructure taxes, shorten the workweek, and build public wealth funds to prepare for superintelligence. A former US Senate staffer who worked on AI policy in 2023 responded publicly, saying she already had all of it in her handwritten notes from three years ago. The ideas were familiar and the authorship was the point..,.OpenAI wants to write the rules for the technology it profits from.

And on Wednesday, Meta released Muse Spark, the first model out of its newly formed Superintelligence Labs. It is closed source. Meta abandoned its open-weight Llama strategy after the Llama 4 launch disappointed and Chinese lab DeepSeek cloned its architecture. The company says it hopes to open-source a version eventually, though it will keep its most sensitive capabilities proprietary.

"Eventually" is doing a lot of work in that sentence.

Three companies. Three justifications. Safety. Policy. Competition.

The same week it locked Mythos behind a firewall, Anthropic announced that its annualised revenue had surpassed $30 billion, overtaking OpenAI for the first time. That figure was $9 billion at the end of 2025 which means it tripled in four months.

The growth is almost entirely enterprise with over 1,000 customers now spend more than $1 million annually on Claude, a number that doubled from 500 in under two months.

Eight of the Fortune 10 are Claude customers and Claude Code alone generates $2.5 billion in run-rate revenue. These are organisations replacing line items in their operating budgets with AI infrastructure that renews, expands across teams, and compounds. OpenAI, by contrast, still draws heavily from consumer subscriptions and its 900 million weekly ChatGPT users. It projects $14 billion in losses for 2026 and does not expect to break even until 2030.

With this, Anthropic projects positive free cash flow by 2027.

The company generating more revenue than any other AI lab is also the one that will not release its most powerful model. And the company writing policy papers about how society should prepare is the one falling behind.

TechCrunch has pointed out that Mythos's controlled release also conveniently protects against model distillation, the process by which competitors copy frontier capabilities into smaller, cheaper models.

Moreover, Anthropic, Google, and OpenAI have reportedly been working together to identify and block distillers.

The safety conversation and the business argument it would seem like, are wearing the same clothes.

On April 2, while the restriction conversation dominated the headlines, Google released Gemma 4 under the Apache 2.0 licence. That is the most permissive open-source licence available.

The model family includes variants that run on a laptop, a Raspberry Pi, or a phone. The 31-billion-parameter dense model outperforms Meta's Llama 4 on maths, coding, and reasoning benchmarks despite being a fraction of the size. It supports 140 languages, processes text, images, video, and audio natively, and has been downloaded over 400 million times across the Gemma series. Google built it from the same research that powers its proprietary Gemini 3 line and gave it away.

Chinese lab Z.ai released GLM-5.1 under the MIT licence. A 744-billion-parameter model with open weights on Hugging Face. On the SWE-Bench Pro software engineering benchmark it scored 58.4, edging out both GPT-5.4 and Claude Opus 4.6.

This means that this is the first open-source model to top all major closed-source models on a real-world coding benchmark.

It was built entirely on Huawei Ascend chips. Z.ai has been on the US Entity List since January 2025 without an NVIDIA hardware and no American silicon. The export controls designed to prevent frontier AI capability from reaching China did not prevent this.

Perplexity is making a different argument altogether. Perplexity Computer, launched in February and expanded in March, orchestrates multiple frontier models from a single interface. Claude handles reasoning and code. Gemini handles research. Grok handles fast queries. The system picks the best model for each subtask, runs them in parallel, and delivers the finished result. This costs $200 a month.

The Personal Computer product runs locally on a Mac mini with full access to your files, apps, and workflows. The premise is that models are interchangeable components. Perplexity does not care who built the smartest one. It routes to whichever is best for the job and that challenges the idea that controlling the frontier model is what matters most.

I have been building across models for a while now. Claude, Gemini, ChatGPT and open-weight models, and increasingly orchestration layers that let me switch between them depending on the task. I do this because my work demands it, and because locking into a single provider has always felt like a vulnerability for the kinds of businesses I serve, where the budget is not seven figures and the margin for error is thin.

If you are only looking at the closed labs, the gap between what exists and what you are allowed to touch has never been wider. But if you look sideways, the doors are wide open. Gemma 4 runs on a laptop. GLM-5.1 is free on Hugging Face.

The AI Intelligence Index, the composite benchmark that tracks frontier model capability, has been stuck at 57 since February.

The models are not meaningfully smarter than they were two months ago. What changed is who gets to use them and on what terms.

While Mythos's cybersecurity capabilities are genuinely significant and the idea of giving defenders time to patch vulnerabilities before attackers exploit them is reasonable. But the framing assumes that restriction works, that containing capability at the top keeps everyone safer.

This week proved, concretely, that it does not. The capability is already loose.

I think about the business owner reading about a model "too dangerous to release" while a free alternative that outperforms it sits on an open repository. The operator who was told this technology would level the playing field, watching it split into a tier they can afford and a tier they cannot.

All the Zest 🍋

Cien

Sources and further reading

From the LaunchLemonade blog

Previous
Previous

The SaaSpocalypse Is Half Right

Next
Next

AI Can Write The Perfect Poem But It Will Never Need To