Software.
UK AISI publishes GPT-5.5 cyber evaluation (71.4% Expert pass rate, highest tested; beats Mythos Preview at 68.6% and Opus 4.7 at 48.6%); OpenAI launches GPT-5.5-Cyber as restricted-access, adopting the same vetted-customer gating Sam Altman previously criticized when Anthropic used it for Mythos
aisi.gov.uk, deploymentsafety.openai.com/gpt-5-5/cybersecurity, simonwillison.net
Anthropic ships Claude Security in public beta — an Opus 4.7-powered codebase vulnerability scanner with auto-patching, scheduled scans, and audit integrations; embedded with CrowdStrike, Microsoft Security, Palo Alto Networks, SentinelOne, Wiz, plus Accenture, BCG, Deloitte, Infosys, PwC
claude.com/blog/claude-security-public-beta, securityweek.com
Mistral releases Medium 3.5 (open-weight modified MIT, 128B dense, 256K ctx) at 77.6% SWE-Bench Verified and $1.50/$7.50 per Mtok; replaces Devstral 2, Magistral, and Medium 3.1 in one consolidated release with Vibe remote cloud coding agents and Le Chat Work mode on the same runtime
mistral.ai/news, the-decoder.com, awesomeagents.ai, decrypt.co
US Department of War inks classified-network AI deals with eight vendors (OpenAI, Google, Microsoft, AWS, NVIDIA, SpaceX, Reflection AI, Oracle); Anthropic explicitly excluded on supply-chain-risk grounds with Mythos cited by Pentagon CTO Emil Michael as a separate national security moment
war.gov press release, oracle.com/news/announcement/2026-05-01, AP News, The Verge, CNBC, Breaking Defense, Washington Post, SCMP
GPT-5.5 + Codex + Bedrock Managed Agents land natively on AWS Bedrock in limited preview; OpenAI inference now billable against AWS commitments under IAM, PrivateLink, and CloudTrail — the same week Microsoft / OpenAI exclusivity formally ends and OpenAI's revenue-share is capped through 2030
openai.com/index/openai-on-aws, aws.amazon.com What's New, blogs.microsoft.com
What this means
Three arcs converged in one week. Software-internal capability gating: AISI's GPT-5.5 cyber numbers plus the simultaneous launch of OpenAI's gated GPT-5.5-Cyber and Anthropic's Opus-4.7-powered Claude Security make frontier-grade cyber an explicit, separately-priced product line — CISOs and security architects must update agentic threat models this quarter and pick a defender stack now. Software-distribution: GPT-5.5 going Bedrock-native plus the end of Microsoft exclusivity decouples closed-frontier intelligence from cloud residency for the first time, so boards previously locked in by Azure-only constraints should reopen OpenAI procurement on AWS or GCP within the limited-preview window before pricing hardens at GA. Federal-distribution: the Friday May 1 Pentagon eight-vendor classified-network slate puts frontier-grade AI on IL6/IL7 deployment paths and explicitly excludes Anthropic citing Mythos — vendor-risk frameworks now need a federal-disqualification dimension, not just an availability SLA. See the Model Pulse for the full architecture read on the six new tree rows that landed this week.