| Claude 3.7 Sonnet | Anthropic | API | Claude shared chats containing sensitive personal and health data were indexed by Google, creating an unresolved data exposure concern for enterprise deployments. Until Anthropic confirms remediation and revised data handling controls, the model cannot retain a GREEN designation. | Aug 26 |
| Claude Fable 51 flag | Anthropic | API | The U.S. government has partially reversed its prior export control suspension on Claude Fable 5 for foreign nationals, though the model remains under restricted access conditions. A full suspension was in effect due to a jailbreak finding, and the partial reversal does not clear all constraints. | Jul 29 |
| Claude Mythos 52 flags | Anthropic | Partner-only | The U.S. government has partially reversed the June 12 export control suspension, restoring access under an approved-partner framework. Access remains restricted rather than generally available, so a YELLOW designation is appropriate. | Jul 16 |
| Claude Mythos 5.1 | Anthropic | Partner-only | Claude Mythos 5.1 is a restricted-access variant of Claude Mythos 5, released by Anthropic with a differentiated safeguard configuration relative to the base model. Access is limited and not generally available, suggesting a controlled rollout to select partners or researchers. The modified safeguard profile distinguishes it meaningfully from the tracked Claude Mythos 5 model. | Sep 2 |
| Claude Opus 5 | Anthropic | Public | Anthropic launched Claude Opus 5 with a significantly reduced safety classifier engagement profile compared to prior Claude models. The model operates under a separate data retention regime that diverges from existing Anthropic model policies, creating compliance uncertainty for enterprise deployments. | Aug 27 |
| Claude Sonnet 51 flag | Anthropic | API | Anthropic has published a formal age assurance policy restricting Claude's availability to minors, shifting verification responsibility onto operators and platform builders. Enterprises without independent age-gating mechanisms in their products now face a direct compliance gap. Organizations embedding Claude in any product that could reach underage users must review and update their access controls to remain in good standing with Anthropic's usage policies. | Sep 12 |
| DeepSeek V32 flags | DeepSeek | Open weights | Chinese-developed model. Open weights available globally. API routes data through Chinese servers, subject to Chinese data laws. Self-hosted deployment recommended for regulated enterprise use. | Jun 27 |
| Gemini 3.7 Flash | Google DeepMind | Public | Google DeepMind released Gemini 3.7 Flash with updated CBRN safeguards. The model ships with an always-on Gemini Spark agent component that introduces unresolved human oversight gaps. Enterprise deployments face elevated risk from the agentic capabilities included in this release. | Aug 27 |
| Gemini 3.8 Flash | Google DeepMind | API | Google DeepMind released Gemini 3.8 Flash alongside a restricted Cyber variant, creating separate compliance tracks for each. The standard model appears to be generally available, but the Cyber variant carries access restrictions that differentiate its regulatory posture. Organizations must evaluate which variant they are accessing, as compliance obligations differ between them. | Sep 9 |
| GPT-4o | OpenAI | Public | OpenAI's new ChatGPT Work agentic product introduces material access control and audit risks that affect the broader GPT-4o deployment context. Additionally, the ChatGPT Health expansion amid an active product liability lawsuit raises unresolved enterprise risk concerns tied to the same underlying model family. | Jul 29 |
| GPT-5.61 flag | OpenAI | Partner-only | GPT-5.6 Cyber has launched under a restricted partner-access program called Daybreak Access, reinforcing the existing YELLOW designation. No change in status is warranted, but the development record should be updated to reflect this new access-control layer. | Aug 12 |
| Grok 4.52 flags | xAI | API | Released July 8, 2026, Grok 4.5 is explicitly designed for sustained autonomous operation ("agentic rollouts can run for many hours") and is immediately available via API and in Cursor on all plans. The launch announcement contains no safety card, model card, or red-team disclosure. The model is withheld from the EU at launch, expected mid-July, in a timeline that coincides with EU AI Act GPAI systemic risk obligations taking effect August 2, 2026. | Jul 9 |
| Kimi K35 flags | Moonshot AI | Open weights | 2.8T-parameter open-weight model from Chinese developer Moonshot AI. UK AISI and CAISI found built-in safeguards failed to block offensive cyber attempts ahead of the July 27 open-weight release. No technical safety report was published at launch, and Chinese-origin open-source AI is now under active US sanctions and export-control scrutiny. | Jul 25 |
| Llama 4 (Scout / Maverick) | Meta | Open weights | A federal lawsuit alleging Meta's internal AI system selected approximately 8,000 employees for layoffs without adequate human oversight introduces reputational and regulatory risk for enterprise Meta AI deployments. While the suit targets an internal system rather than Llama 4 directly, it signals governance exposure that warrants a cautionary flag. | Aug 8 |
| Muse | Meta | Public | Meta launched Muse, a proactive personal AI agent operating across Meta platforms, distinct from the previously tracked Muse Glimmer and Muse Spark 1.1 models. Its proactive, cross-platform nature raises unresolved enterprise data governance questions. No government action has been filed, but the agentic scope introduces meaningful data handling concerns for enterprise users. | Sep 9 |
| Muse Glimmer | Meta | Open weights | Meta released Muse Glimmer under the Apache 2.0 license, signaling a strategic shift toward open-weight AI. An imminent open-source release of Muse Spark 1.2 was also announced. The open release raises unresolved distillation and model intake policy concerns for enterprise users. | Aug 27 |
| Qwen31 flag | Alibaba Cloud | Open weights | Chinese-developed model. Open weights available globally. API service subject to Chinese data law jurisdiction. Open-weights self-hosting is the recommended path for regulated enterprise use. | Jun 27 |