April 2026: The Model Anthropic Wouldn't Ship

Claude Mythos found and exploited a 17-year-old FreeBSD vulnerability on its own, and Anthropic kept it from the public. Meta rebuilt its AI stack, and OpenAI shipped GPT-5.5 six weeks after GPT-5.4.

For two years the question in AI was how fast labs could ship. In April, the most important launch was a model that didn't ship.

Claude Mythos Preview and Project Glasswing

Anthropic announced Claude Mythos Preview on April 7. It is strong across the board, but its security capability drove the release decision. In Anthropic's testing, it autonomously found and exploited a 17-year-old remote code execution vulnerability in FreeBSD.

Anthropic did not release it publicly. Through Project Glasswing, a group of companies got access to scan critical software for vulnerabilities before attackers could use the same capability.

That is a new kind of launch plan. Model access used to be sequenced for commercial reasons. Here it was sequenced by who needs to patch before everyone else can attack. Once one lab gates a model on cyber capability, it becomes hard for the others to argue they shouldn't.

If a model can find decades-old bugs on its own, the vulnerability backlog in every large codebase becomes finite and discoverable. The question becomes who finds them first.

Meta starts over with Muse Spark

On April 8, Meta Superintelligence Labs released Muse Spark, its first model under Alexandr Wang. Meta described it as a ground-up rebuild of its AI stack. It is small and fast by design, handles a million tokens of context, and is proprietary.

The strategy shift matters more than the benchmarks. Meta spent years arguing that open weights would commoditize the frontier. Its first model after spending billions on talent is closed.

GPT-5.5, six weeks later

OpenAI released GPT-5.5 on April 23, six weeks after GPT-5.4, and it reached the API the next day. OpenAI pitched it as better at carrying a task to completion: writing and debugging code, research, documents and spreadsheets, and operating software across tools. It is another step toward a single app that combines ChatGPT, Codex, and the browser.

The cadence is the story. Frontier models now update like SaaS releases. For enterprise buyers, evaluation can't be a one-time procurement exercise anymore. If the model under your product changes every six weeks, you need regression tests on your own tasks that run every time it does.

Google Cloud Next and Gemma 4

Google Cloud Next focused on agents in production, with the Gemini Enterprise Agent Platform and eighth-generation TPUs. Google also released Gemma 4, its open model family, in the same month Meta stepped away from open weights.

The Sora app shut down on April 26, as scheduled.

What April tells us

  • Release decisions are now security decisions. Mythos set the precedent.
  • Open weights lost a major backer. Google kept shipping open models while Meta went proprietary.
  • Evals have to run continuously. Six-week model cycles break annual vendor reviews.