The product will be sold into a compliance regime, not a free market. That is the structural fact that should shape the company before the first contract, and it is visible in public documents rather than inferred.
What OpenAI already requires
OpenAI runs Daybreak Trusted Access for Cyber in two tiers (overview; expansion post).
Daybreak Blue (GPT-5.6 Sol) covers defensive work — secure code review, vulnerability triage, malware analysis, detection engineering, incident response, patch validation — and is the recommended entry point. Daybreak Red (GPT-5.6 Cyber) covers "advanced authorized workflows like proof-of-concept exploit development, penetration testing, and red teaming," and access "requires additional approval and is subject to stronger verification, monitoring, access controls, and human oversight."
The stated controls, in one list:
| Control | Detail |
|---|---|
| Identity and trust verification | Applicant must be 18+; assessment on "identity and trust verification, risk considerations, the intended use case, and the applicant's ability to strengthen the broader cybersecurity ecosystem" |
| Organisational evidence | Applicants may be asked for organisational information, cybersecurity capabilities and intended defensive workflows |
| Legal attestations | Attestations of approved use |
| Hardware keys | Mandatory hardware security keys for individual accounts from 1 September 2026 |
| Monitoring | Automatic review of elevated-permission agent actions |
| Downstream ban | Flat prohibition on "resale, proxying, embedding, or downstream access for third-party customers or external users" |
Separate reporting on the GPT-5.6-Cyber launch adds that Daybreak Red applicants must demonstrate authorised defensive work plus SOC 2 Type II or ISO 27001, SSO, MFA and monitoring, with the model priced at $12.50/M input and $75/M output (VentureBeat).
Note what is not there: no nationality restriction, no background-check requirement and no geographic limitation appears in the help-centre documentation. The gate is organisational trustworthiness, not citizenship.
What Anthropic already requires
Project Glasswing launched in May 2026 with roughly 50 partners — Cloudflare, Microsoft, Oracle, Palo Alto Networks and several banks among them — using Claude Mythos Preview to scan systemically important code, and expanded by about 150 more organisations in June 2026 across 15+ countries (Anthropic; expansion).
The controls described are: coordinated disclosure on a 90-day timeline, or 45 days post-patch; independent security research firms triaging and verifying findings before disclosure; and staged tooling release, with scanning tools "available to qualifying customers' security teams on request." Anthropic's stated reason for not releasing Mythos-class models publicly is that "at present, no company—including Anthropic—has developed safeguards strong enough to prevent such models from being misused."
There are no published vetting criteria. Membership is by invitation to large, named infrastructure operators, which is itself the finding: the qualification is institutional identity, not certification. A company with no institutional identity has to manufacture one, and the fastest route is the customer list, which is the argument The labs as buyers makes from the demand side.
Mirroring Daybreak is not compliance theatre bolted onto a product. It is (a) the commercial design — gated tiers are how you price and how you stop the corpus leaking into a competitor's training set; (b) the misuse control the buyers will audit; and (c) a legal mitigation, because CPS guidance on CMA s.3A expressly weighs whether distribution was "to a closed and vetted list of IT security professionals or was posted openly" (CPS), and because Article 5 human-rights due diligence under Exploits are free, uploading is an export needs the same buyer file. Build the KYC process once and it discharges three obligations. Ask counsel whether one screening process can serve both KYC and Article 5; it very probably can.
The contractual language to copy is OpenAI's, close to verbatim: a prohibition on "resale, proxying, embedding, or downstream access for third-party customers or external users." It is short, it is already market-standard at the top of this market, and a buyer's counsel will recognise it.
The hole in the record, and how cheap it is to fill
Everything above is what labs require of people who want model access. Nothing in the public record says what a lab requires of a vendor supplying it with offensive-security data. No SOC 2, no ISO 27001, no nationality requirement, no air-gap requirement, no facility standard, no personnel-screening standard could be found for any frontier lab. No lab publishes its supplier security addendum.
This is the largest single evidence gap in the dossier and the cheapest to close: ask two or three labs directly during commercial discovery. It is free, it is fast, it is a normal question for a prospective vendor to ask, and the answer determines whether the company needs a SOC 2 programme in month three or month thirty. Until someone asks, any number in a plan here is invented.
The reasonable working assumption, pending that answer, is that a lab will push its own regime downward. Daybreak Red already demands SOC 2 Type II or ISO 27001 of an organisation that merely wants to use a model; it is hard to imagine looser terms for an organisation that supplies the training data for one. Budget for ISO 27001 as a cost of entry and treat SOC 2 as the US-facing equivalent.
The other side of the gate: what the workers may lawfully sell
Access control points outward at buyers and inward at contributors, and the inward problem is the one that generates litigation.
Most security firms use a Proprietary Information and Invention Assignment Agreement assigning inventions conceived during employment, usually with a "relates to the employer's business" or "using employer resources" hook. Attack reasoning derived from professional practice sits squarely inside that hook. The strongest employee-side protection in the record is California Labor Code § 2870, which voids assignment of inventions developed entirely on the employee's own time without employer equipment or trade secret information — except where the invention relates to the employer's business or actual R&D, or results from work performed for the employer (overview). That exception swallows most of the protection for a pentester moonlighting on pentest data.
The honest answer to "can an employed pentester sell reasoning traces derived from their professional skill?" is: the skill is theirs; the specific artefacts usually are not. General expertise is not assignable and is not a trade secret. A trajectory that reproduces a client engagement, a client environment, a proprietary internal tool or an undisclosed finding is very likely the employer's or the client's confidential information regardless of who typed it.
The market already has an answer, and it is one line from a Mercor cyber posting worth copying verbatim into the contributor agreement (Mercor):
"Your work at Mercor will not involve access to confidential or proprietary information from any employer, client, or institution."
A parallel warranty and indemnity from every contractor, plus a per-artefact provenance attestation, is the minimum viable control — and it is also the recruiting position argued in The corpus is the target and priced in Paying the crowd. Bug bounty platform terms are a separate layer on top: HackerOne's Finder Terms explicitly state that "HackerOne does not claim any ownership rights in any Finder Submissions," but individual programme policies routinely impose non-disclosure until the customer authorises publication, and those are the operative constraint [UNVERIFIED at the programme level — check per programme]. See The bounty platforms.
The analogues to § 2870 — Germany's Arbeitnehmererfindungsgesetz, the UK Patents Act 1977 ss.39–43, and national employment-contract law across the EU — were not researched here, and for a Europe-based company recruiting European contractors that is the relevant body of law rather than a Californian statute. Treat this as an open question for employment counsel, not as covered ground.
Two claims that should not go in a deck
The Mercor Five-Eyes restriction could not be confirmed. The premise that Mercor's cyber postings restrict to US/CA/UK/AU/NZ and require background checks does not survive contact with the live postings. The Cybersecurity Research Expert – Offensive Security & Vulnerability Research role pays $200–$250/hr, is an independent contractor engagement paid weekly via Stripe or Wise, and says "fully remote globally," with the only stated restriction being an inability to support H-1B or STEM OPT candidates. No background check is mentioned. The Cyber Security Experts role at $85–$95/hr and the Cybersecurity Expert role at $80–$90/hr say the same. A Cybersecurity Labeling Expert posting at $100–$150/hr is listed as "Worldwide Remote". One aggregator titles that same role "Remote: Canada, USA, UK, Australia, New Zealand," but its page could not be retrieved. [WEAK — the restriction is plausible for some roles and unverifiable on any Mercor-controlled page. Do not state it as fact.]
What the same postings do establish is the cost floor: $80–$250/hr, with offensive and vulnerability-research work at the top of the band and scenario design at the bottom. Offensive supply works out who is actually available at those rates, and Offensive security why this niche is worth entering at all.
US clearance holders are probably not available to an EU company. US clearance holders report foreign contacts, foreign travel and outside activities under SEAD 3, and Adjudicative Guideline L (Outside Activities) covers employment or services for a foreign national, foreign government or foreign-owned entity (SEAD 3 summary; Guideline L). Contracting to an EU company is reportable outside activity with a foreign entity. Not prohibited — but reportable, adjudicatively relevant, and many cleared professionals will decline rather than file. Expect the cleared US talent pool to be largely closed to an EU-domiciled contracting entity, which is the strongest argument in this dossier for a US subsidiary if that pool matters. The equivalent UK (SC/DV) and German (SÜG) rules could not be established.
Next: The corpus is the target, where the corpus itself becomes the thing that gets attacked.