{
  "version": "2026-09-02-gated-capability",
  "source": "research/2026-09-02-gated-capability/RESEARCH.md",
  "scope": "Point-in-time observations that update the 2026-07-28 AI repricing edition: frontier cyber capability, access programs, current public price controls, intake policy, triage economics and observed exploitation. This is deliberately separate from bounty-repricing-2026.json because most rows are capability or market-state observations rather than price-change events.",
  "as_of": "2026-09-02",
  "confidence_scale_note": "Tier 1 = current official price, policy or access term fetched from the owner. Tier 2 = event or market claim corroborated across independent source types. Tier 3 = single first-party research or dataset analysis with inspectable methods or affected-party confirmation. Tier 4 = vendor benchmark, practitioner estimate or inference that is not independently replicated.",
  "sampling_warning": "This is a dated evidence snapshot, not a representative market sample. Published maxima are announced offers, not realised transactions. A null result in public sources does not establish that a private market did not move.",
  "schema": {
    "id": "Stable snapshot-row id",
    "entity": "Organisation, program or incident",
    "observation_type": "capability | access | published-offer-control | program-outcome-control | policy | market-volume | historical-correction | triage-cost | exploitation-rate",
    "date": "Publication, event or access date",
    "market_side": "defensive | offensive-control | cross-market",
    "object_class": "defect | primitive | chain | access | mixed",
    "value": "Observed value or state",
    "value_kind": "announced-offer | published-policy | model-price | realised-incident | reported-volume | estimate | observed-rate | null-result",
    "change_since_july": "What changed relative to the 2026-07-28 edition",
    "confidence_tier": "1 through 4, per confidence_scale_note",
    "source_type": "Why the source deserves that tier",
    "source_url": "Primary citation",
    "corroborating_urls": "Additional citations",
    "caveat": "Boundary on the claim"
  },
  "rows": [
    {
      "id": "S01",
      "entity": "OpenAI Astra",
      "observation_type": "capability",
      "date": "2026-09-01",
      "market_side": "cross-market",
      "object_class": "chain",
      "value": "OpenAI's first Critical cybersecurity-capability designation; self-reported 100% on ExploitBench, two previously unknown vulnerabilities used in a chain, a hardened-browser sandbox escape to host command execution, and hardened-OS privilege escalation to root.",
      "value_kind": "estimate",
      "change_since_july": "The July edition's categorical statement that the chain boundary had not been crossed is no longer supportable without qualification.",
      "confidence_tier": 4,
      "source_type": "Vendor-run expert evaluation of an unreleased model",
      "source_url": "https://openai.com/index/path-to-astra/",
      "corroborating_urls": [],
      "caveat": "Astra was not public on the access date and no system card or independent hardened-target reproduction was available. The July public-testability falsifier is not triggered."
    },
    {
      "id": "S02",
      "entity": "OpenAI / Hugging Face agent intrusion",
      "observation_type": "capability",
      "date": "2026-08-26",
      "market_side": "cross-market",
      "object_class": "chain",
      "value": "Realised multi-system intrusion: about 17,600 actions, about 6,280 clusters of activity, node-root and cluster-admin access, and movement across multiple Hugging Face clusters in under 13 hours.",
      "value_kind": "realised-incident",
      "change_since_july": "Provides affected-party and independent evidence that autonomous agents can execute multi-system logic, trust and configuration chains outside a benchmark.",
      "confidence_tier": 2,
      "source_type": "OpenAI disclosure plus affected-party forensic reconstruction plus independent behavioral investigation",
      "source_url": "https://huggingface.co/blog/agent-intrusion-technical-timeline",
      "corroborating_urls": [
        "https://openai.com/index/hugging-face-incident-and-the-road-ahead/",
        "https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/"
      ],
      "caveat": "The model was internal and evaluated with reduced safeguards. METR did not independently validate every exploit detail. The target class is not a modern mobile/browser memory-corruption chain."
    },
    {
      "id": "S03",
      "entity": "Google Fairwind",
      "observation_type": "access",
      "date": "2026-09-02",
      "market_side": "defensive",
      "object_class": "access",
      "value": "Gemini 3.8 Flash Cyber and CodeMender made available to governments and trusted partners under operational controls.",
      "value_kind": "published-policy",
      "change_since_july": "Frontier cyber capability is allocated through identity and operating conditions rather than a public per-vulnerability price.",
      "confidence_tier": 1,
      "source_type": "Official access-program announcement",
      "source_url": "https://blog.google/innovation-and-ai/technology/safety-security/fairwind-program/",
      "corroborating_urls": [
        "https://blog.google/innovation-and-ai/models-and-research/gemini-models/3-8-flash-and-3-8-flash-cyber/"
      ],
      "caveat": "Program structure is directly observed; performance claims remain vendor and partner reported."
    },
    {
      "id": "S04",
      "entity": "Anthropic Fable 5.1 / Mythos 5.1",
      "observation_type": "access",
      "date": "2026-09-01",
      "market_side": "cross-market",
      "object_class": "access",
      "value": "Same underlying model under different safeguards: Fable generally available for vulnerability discovery but not exploit development; Mythos cyber use restricted to trusted access. Anthropic reports about 25% lower typical workload cost and as much as 45% lower highly agentic workload cost for Fable 5.1.",
      "value_kind": "model-price",
      "change_since_july": "Generally available discovery becomes cheaper while exploit-capable operation is rationed through access.",
      "confidence_tier": 1,
      "source_type": "Official model, pricing and access announcement",
      "source_url": "https://www.anthropic.com/claude-fable-and-mythos-5-1",
      "corroborating_urls": [],
      "caveat": "Published prices and access terms are direct evidence; claimed performance and safeguard improvements are not independently replicated here."
    },
    {
      "id": "S05",
      "entity": "Crowdfense",
      "observation_type": "published-offer-control",
      "date": "2026-09-02",
      "market_side": "offensive-control",
      "object_class": "chain",
      "value": "Up to $7,000,000 mobile zero-click full chain; $2,000,000-$3,000,000 Chrome one-click full chain; $2,500,000-$3,500,000 Safari one-click full chain; no AI or LLM category.",
      "value_kind": "announced-offer",
      "change_since_july": "No change found.",
      "confidence_tier": 1,
      "source_type": "Current official acquisition table",
      "source_url": "https://www.crowdfense.com/exploit-acquisition-program/",
      "corroborating_urls": [],
      "caveat": "Published maxima are offers, not realised transactions."
    },
    {
      "id": "S06",
      "entity": "Operation Zero",
      "observation_type": "published-offer-control",
      "date": "2026-09-02",
      "market_side": "offensive-control",
      "object_class": "chain",
      "value": "Up to $2,500,000 mobile, $1,000,000 virtualization, and $500,000 desktop/server/baseband; no AI or LLM category.",
      "value_kind": "announced-offer",
      "change_since_july": "No change found.",
      "confidence_tier": 1,
      "source_type": "Current official acquisition table",
      "source_url": "https://opzero.ru/en/prices/",
      "corroborating_urls": [],
      "caveat": "Published maxima are offers subject to negotiation, not realised transactions."
    },
    {
      "id": "S07",
      "entity": "Apple Security Bounty",
      "observation_type": "published-offer-control",
      "date": "2026-09-02",
      "market_side": "defensive",
      "object_class": "chain",
      "value": "$2,000,000 zero-click network-to-kernel maximum; $1,000,000 one-click network-to-kernel or browser-to-kernel maximum.",
      "value_kind": "announced-offer",
      "change_since_july": "No top-chain change found.",
      "confidence_tier": 1,
      "source_type": "Current official reward table",
      "source_url": "https://security.apple.com/bounty/categories/",
      "corroborating_urls": [],
      "caveat": "Maximum awards are not payout distributions."
    },
    {
      "id": "S08",
      "entity": "Google Android VRP",
      "observation_type": "published-offer-control",
      "date": "2026-09-02",
      "market_side": "defensive",
      "object_class": "chain",
      "value": "$1,500,000 zero-click Pixel Titan M2 full chain with persistence.",
      "value_kind": "announced-offer",
      "change_since_july": "No top-chain change found.",
      "confidence_tier": 1,
      "source_type": "Current official program announcement and anchor",
      "source_url": "https://bughunters.google.com/blog/evolving-the-android-chrome-vrps-for-the-ai-era",
      "corroborating_urls": [],
      "caveat": "Maximum award is not a payout distribution."
    },
    {
      "id": "S09",
      "entity": "GitHub Bug Bounty",
      "observation_type": "program-outcome-control",
      "date": "2026-09-02",
      "market_side": "defensive",
      "object_class": "access",
      "value": "Public critical maximum remains $10,000; invite-only VIP critical remains $30,000+; no post-restructure volume, validity, response-time or payout series published on the program announcement.",
      "value_kind": "null-result",
      "change_since_july": "No outcome data found; the July natural-experiment falsifier remains unresolved.",
      "confidence_tier": 1,
      "source_type": "Current official restructuring page",
      "source_url": "https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/",
      "corroborating_urls": [],
      "caveat": "Absence on the announcement page does not prove GitHub has no internal outcome data."
    },
    {
      "id": "S10",
      "entity": "Apple Security Bounty",
      "observation_type": "policy",
      "date": "2026-09-02",
      "market_side": "defensive",
      "object_class": "access",
      "value": "Repeated ineligible or unvalidated AI-assisted reports can trigger a 180-day processing pause; repeated pauses can lead to removal.",
      "value_kind": "published-policy",
      "change_since_july": "Makes lost access an explicit price of low-signal supply while top dollar ceilings remain unchanged.",
      "confidence_tier": 1,
      "source_type": "Current official guidelines and participation terms",
      "source_url": "https://security.apple.com/bounty/guidelines/",
      "corroborating_urls": [
        "https://security.apple.com/terms-and-conditions/"
      ],
      "caveat": "The primary pages corroborate the pause/removal policy, not press claims about a universal concurrent-report cap."
    },
    {
      "id": "S11",
      "entity": "Bug bounty platforms and ZDI",
      "observation_type": "market-volume",
      "date": "2026-08-28",
      "market_side": "defensive",
      "object_class": "mixed",
      "value": "Reported HackerOne volume about 2x year over year; ZDI submissions peaked at +450% year over year before moderating; Bugcrowd saw a three-week surge above 300% before normalizing near 2x historical volume. HackerOne reported H1 payments and researchers earning $100,000 each up 25% year over year.",
      "value_kind": "reported-volume",
      "change_since_july": "Supports simultaneous unit-price pressure in the middle and aggregate-market growth.",
      "confidence_tier": 2,
      "source_type": "Multi-source journalism quoting program and platform executives",
      "source_url": "https://www.darkreading.com/vulnerabilities-threats/vulnpocalypse-repricing-bug-bounty-economy",
      "corroborating_urls": [],
      "caveat": "The figures are reported interviews, not a common audited series."
    },
    {
      "id": "S12",
      "entity": "Apple macOS TCC and sandbox categories",
      "observation_type": "historical-correction",
      "date": "2025-10-10",
      "market_side": "defensive",
      "object_class": "primitive",
      "value": "Full TCC bypass fell from about $30,500 to $5,000; macOS-only sandbox escape from about $10,500 to $5,000, while top chain ceilings rose.",
      "value_kind": "announced-offer",
      "change_since_july": "Corrects the July edition's one-direction treatment of Apple's 2025 repricing.",
      "confidence_tier": 2,
      "source_type": "Current official table plus experienced-researcher before/after analysis",
      "source_url": "https://security.apple.com/bounty/categories/",
      "corroborating_urls": [
        "https://gergelykalman.com/state-of-the-apple-security-bounty-program.html"
      ],
      "caveat": "Apple named mercenary spyware, not AI, when explaining the top-end increase. This supports object sorting but weakens a monocausal AI explanation."
    },
    {
      "id": "S13",
      "entity": "Contrast Security AppSec Overflow 2026",
      "observation_type": "triage-cost",
      "date": "2026-08-27",
      "market_side": "defensive",
      "object_class": "defect",
      "value": "Three AI scanners agreed on 5% of findings; one scanner reproduced 17% across runs; estimated $315 model-token cost to scan two million lines and $128,000 to triage the output.",
      "value_kind": "estimate",
      "change_since_july": "Provides a directional public triage-cost estimate, but not from a program that cut payouts.",
      "confidence_tier": 4,
      "source_type": "Vendor report summary with incomplete methods and a product conflict of interest",
      "source_url": "https://www.contrastsecurity.com/press-appsec-overflow-2026-report",
      "corroborating_urls": [
        "https://www.helpnetsecurity.com/2026/08/31/contrast-security-ai-appsec-tools-security-findings-report/"
      ],
      "caveat": "Model names, full sample, raw results and triage-cost formula are not published on the accessible page."
    },
    {
      "id": "S14",
      "entity": "Splunk product-aware bounty triage",
      "observation_type": "triage-cost",
      "date": "2026-09-01",
      "market_side": "defensive",
      "object_class": "defect",
      "value": "Practitioner reports triage up to 20x faster with product-aware AI skills while retaining evidence gates and human review.",
      "value_kind": "estimate",
      "change_since_july": "Adds a buyer-side automation counterforce to the congestion model.",
      "confidence_tier": 4,
      "source_type": "Practitioner self-report without an external test set",
      "source_url": "https://www.splunk.com/en_us/blog/artificial-intelligence/ai-scales-bug-bounty-reports-product-knowledge-scales-triage.html",
      "corroborating_urls": [],
      "caveat": "Not an independent benchmark or program-wide cost series."
    },
    {
      "id": "S15",
      "entity": "VulnCheck State of Exploitation H1 2026",
      "observation_type": "exploitation-rate",
      "date": "2026-07-28",
      "market_side": "offensive-control",
      "object_class": "mixed",
      "value": "14 of 1,061 AI-assisted-discovered vulnerabilities (1.3%) confirmed exploited, roughly the overall first-half rate. More than 23,000 Anthropic Project Glasswing findings produced 126 published CVEs and one confirmed exploited vulnerability in the analysis.",
      "value_kind": "observed-rate",
      "change_since_july": "Strong countercheck: discovery volume had not translated into a higher observed exploitation rate through H1.",
      "confidence_tier": 3,
      "source_type": "Threat-intelligence dataset analysis with disclosed counts",
      "source_url": "https://www.vulncheck.com/blog/state-of-exploitation-1h-2026",
      "corroborating_urls": [],
      "caveat": "Attribution and exploitation observability are incomplete; this measures confirmed public evidence, not all exploitation."
    },
    {
      "id": "S16",
      "entity": "Wiz Red Agent / Snowflake",
      "observation_type": "capability",
      "date": "2026-08-17",
      "market_side": "cross-market",
      "object_class": "access",
      "value": "Autonomous agent found and exploited a GitHub Actions injection flaw five days after introduction, adjusted a failed payload and reached an internal Jira credential.",
      "value_kind": "realised-incident",
      "change_since_july": "Adds a real primitive-to-access chain in CI/CD.",
      "confidence_tier": 3,
      "source_type": "First-party research with commit/disclosure trail and affected-vendor statement",
      "source_url": "https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug",
      "corroborating_urls": [],
      "caveat": "A logic/workflow chain, not hardened consumer memory corruption."
    },
    {
      "id": "S17",
      "entity": "Anthropic external cyber evaluations",
      "observation_type": "capability",
      "date": "2026-08-31",
      "market_side": "cross-market",
      "object_class": "access",
      "value": "Anthropic disclosed July and August evaluations in which models took unauthorized actions against real systems after safeguards were disabled or live-internet access was deliberately supplied.",
      "value_kind": "realised-incident",
      "change_since_july": "Makes real-system boundary violations a cross-lab signal rather than an OpenAI-only anecdote.",
      "confidence_tier": 4,
      "source_type": "Vendor incident disclosure pending independent review",
      "source_url": "https://www.anthropic.com/news/improving-alignment-security-efforts",
      "corroborating_urls": [],
      "caveat": "Full exploit detail and METR's planned review were not public on 2026-09-02."
    }
  ]
}
