In seven days in late June 2026, the US government became the party that decides which frontier models ship, and to whom. On 26 June it blocked the public release of OpenAI’s GPT-5.6 Sol and restricted the model to roughly 20 vetted partners. The same day, it re-authorised Anthropic’s Mythos 5 for about 100 federal-approved organisations. Within 72 hours, OpenAI floated a 5% stake to Washington worth an estimated $42.6 billion.
The instrument is Executive Order 14409, signed 2 June 2026. On paper it is voluntary. Both labs treated it as binding. The framework’s first stress tests were the 5% stake and Anthropic’s 19-day suspension under an export-control directive.
The thesis: a voluntary framework backed by procurement leverage behaves like regulation, and the consequence is that model access is now a supply-chain risk. That is the full story behind the government gatekeeper model.
In This Series
- How the US Government Gatekeeper Model for AI Releases Works: the mechanics of Executive Order 14409 and why a “voluntary” order binds.
- How OpenAI and Anthropic Responded When Washington Restricted Their Models: the GPT-5.6 and Mythos 5 cases that first tested the gate.
- Assessing AI Vendor Regulatory Risk When a Model Can Vanish Overnight: a decision framework for weighing provider exposure and continuity.
- The Securitisation of Frontier AI and How Governments Control Access: how national-security framing is reshaping who gets access globally.
What is the government gatekeeper model for AI releases, and how does it actually work?
The government gatekeeper model is the arrangement where Washington, not the vendor or the market, decides when a frontier model ships, to whom, and under what conditions. Executive Order 14409 invites developers to hand over up to 30 days of pre-release access and ship only to vetted “trusted partners”. A developer that says no risks exclusion from federal procurement or an export-control switch-off.
Think of the gate as a stack: the Covered Frontier Model threshold, the Pre-Release Access Window (the “30-Day Rule”), the NSA’s designation authority and classified benchmarking, and the Trusted Partners list. The paradox is that the order is explicit about what it does not require. Section 3(c) disclaims mandatory licensing, pre-clearance and permitting, yet procurement leverage turns that disclaimer into a de facto obligation. As Lawfare puts it, “voluntary” looks different when your customer is the federal government. The procurement rules and certification patterns that transmit this leverage are covered in the gatekeeper mechanics explainer.
If you ship or buy frontier models, this gate decides what you can ship or buy. Read this if you want to know what Washington can do before a model ships: how Washington gates a frontier model before it ships.
How did OpenAI and Anthropic respond when Washington restricted their models?
OpenAI and Anthropic took opposite paths through the same gate. OpenAI cooperated: it held GPT-5.6 Sol to roughly 20 vetted partners, reached general availability in thirteen days, and offered Washington a 5% stake worth about $42.6 billion. Anthropic was served an export-control directive and watched Fable 5 and Mythos 5 go dark for 19 days. The two cases differ by mechanism: OpenAI negotiated; Anthropic was prohibited.
These were the gate’s first tests, the “same day, two gates” of 26 June 2026, when the Mythos 5 re-authorisation and the GPT-5.6 Sol preview landed together. Washington asked OpenAI to restrict GPT-5.6 Sol at launch, and Anthropic’s suspension ran under the Lutnick letter because the company could not verify users’ nationality in real time.
The comparison pits OpenAI’s financial concession against the supply-chain risk designation, a prohibition. Sam Altman sits on one side, the export-control machinery on the other. A lab can buy its way through the gate or be pushed through it, which changes how you should plan; the full analysis of both responses lives in the lab-case comparison.
Read this if you want to know how the two labs reacted when their models were gated: the two lab cases that tested the pre-release gate.
How should you assess an AI vendor’s regulatory exposure when a model can vanish overnight?
The risk to weigh is availability as much as capability: someone else can switch a gated model off. Treat a provider’s regulatory exposure as a standing variable alongside price, latency and data residency. Ask which instrument could pull the model, and whether you hold a second source or an open-weight alternative. The operative question is “can it be taken away”.
Treat this as a Vendor Regulatory-Exposure Assessment. A provider can lose access to its own product overnight, so procurement exposure, the gated-versus-open-weight bet and AI sovereignty become architecture inputs for your business.
The trade-offs: the instrument of exposure changes how a model fails, open-weight models are the structural hedge, and AI sovereignty explains why exposure varies by jurisdiction. Published weights have no central switch to flip, which is what makes open-weight models hard to recall. The United States Studies Centre describes Australia’s position as “managed dependence”, one national pattern of many. The Sol versus Mythos capability comparison is covered in the vendor-risk guide.
Read this if you are choosing a provider and need to price in that risk: what the gate mechanism means for what you build on.
What is the securitisation of frontier AI, and why does it matter for who gets access?
Securitisation treats model access as a national-security question rather than a commercial-release question. Once a frontier model is treated as a security asset, access becomes a permission granted to trusted parties instead of a product sold to customers. That logic now drives Washington’s classified benchmarking, the EU AI Act‘s evaluation powers and allied access tiering — which is why who can use a frontier model is increasingly decided by governments, not vendors.
Zoom out: frontier AI has moved from a commercial-release question to a national-security one. Washington’s classified approach (the NSA’s designation authority and classified benchmarking) sits against the EU AI Act’s statutory evaluation powers in Articles 91 and 92, and against civilian evaluation under CAISI, the Commerce Department’s AI standards centre, and NIST, the National Institute of Standards and Technology. The two regimes share the same intent but use different instruments.
The frame ties back to AI sovereignty and the open-weight pressure valve. Allied momentum, the European technological sovereignty package, the UK Sovereign Model Coalition and the Five Eyes warning all show the logic spreading beyond Washington.
Read this if national-security framing is the lens you need: how governments control access to frontier AI.
Conclusion
Treat model access as a supply-chain dependency from here on, and watch how far the gate extends next. Start with how the gatekeeper model fits together or, if you are arriving from the news cycle, how two frontier labs navigated the first gated releases.
Build decisions start at how to price provider continuity before you commit; the series closes with the securitisation analysis.
Frequently Asked Questions
What exactly is a “covered frontier model”, and who decides?
A covered frontier model is an AI model whose advanced cyber capabilities cross a classified threshold, making it subject to the pre-release gate. The National Security Agency Director makes the designation, in consultation with the national cyber director and other security officials. Executive Order 14409 does not define the term. The benchmark is settled through a classified process, so no vendor or buyer can self-assess whether a model qualifies.
What is the 30-day rule, and does it delay every new model release?
The 30-day rule is the Pre-Release Access Window: developers may give the federal government access to a covered frontier model for up to 30 days before releasing it to other trusted partners. It applies only once a model is designated covered, and participation is framed as voluntary, so it delays only a subset of releases. In practice, advance planning is required, because the window compresses your release schedule.
How does a company become a trusted partner?
There is no published application process, and that is the point. Trusted partners are selected through a classified vetting arrangement, with criteria Executive Order 14409 leaves undefined. For GPT-5.6 Sol the list was roughly 20 organisations, each individually vetted and shared with the government; for Mythos 5 it was about 100. Without published criteria, you cannot self-assess eligibility or appeal a decision.
What happens to a model I’m already using if Washington restricts it?
A gated model can be disabled for every user, foreign and domestic, with little warning, as Anthropic’s Fable 5 and Mythos 5 showed during their 19-day suspension. If your workloads depend on a closed model, an export-control letter or a procurement condition can take it offline overnight. The practical hedge is a tested second source or an open-weight fallback you can switch to without a rebuild.
Does the government gain access to my data when a model is gated?
Gate status can change your data terms as well as your access. Anthropic imposed a minimum 30-day retention requirement on Fable 5 and Mythos 5 traffic during the restriction, overriding prior zero-retention enterprise agreements. So gating can affect what is logged and for how long. Read the retention clauses in any managed-access arrangement, because safety and defence framing can reset the terms you negotiated.
Are open-weight models completely immune to government restrictions?
They are structurally harder to switch off. Once weights are published and downloaded, there is no central switch for a Commerce Department letter to flip, so an existing checkpoint keeps working. The trade-offs: open-weight models generally trail the closed frontier on the hardest knowledge and retrieval workloads, and you still depend on hosting and distribution. Treat them as a continuity hedge.
Did OpenAI have to give the US government a 5% stake?
No. OpenAI proposed handing Washington 5% worth roughly $42.6 billion as a voluntary offer, framed as a way to share AI’s upside under political pressure. Executive Order 14409 contains no such requirement; the concession was designed to shape the relationship. Anthropic made no comparable offer, which shows the response was strategic.
What is the difference between an export-control directive and a supply-chain risk designation?
They are different instruments that fail a model in different ways. An export-control directive, like the Lutnick letter, is a legal prohibition on transferring a model to restricted parties, and it forced Anthropic to disable access worldwide. A supply-chain risk designation is an administrative label that steers procurement and trust. One removes the product; the other removes the customer. Both convert access into a permission.
What is Project Glasswing, and how does it relate to the gate?
Project Glasswing is Anthropic’s managed-access arrangement for its cyber-capable Mythos model, the vetting pipeline that granted early access to partners such as Cisco and JPMorgan Chase. It is the concrete channel through which a gated release actually reaches organisations. Glasswing shows how a vendor-side process can align with the government’s trusted-partner model to produce a controlled rollout.
Is the US the only country that can switch off a frontier model?
No. Washington set the precedent, but the logic is spreading. The EU AI Act carries statutory evaluation powers under Articles 91 and 92, and allied access is being tiered by jurisdiction. The European sovereignty package, the UK Sovereign Model Coalition and a Five Eyes warning all point the same way. Different governments are using different instruments, but the direction of travel is national-security control over who gets frontier access.
What is Sam Altman’s IAEA-style international AI forum, and would it extend the gate?
Sam Altman has proposed a US-led international AI body modelled on the IAEA, the nuclear watchdog that inspects and verifies member states. If realised, it would extend the gatekeeper architecture globally, adding an international access layer above national controls. The proposal is notable because it comes from a lab and would formalise access tiering across allied and non-allied states.
What does the government gatekeeper model mean for Australian companies?
Australian organisations sit inside the “managed dependence” the United States Studies Centre describes, securing favourable access on terms they negotiate. A US export-control directive can reach you even though you are outside America, because it governs nationality, which follows you across borders. That makes jurisdictional exposure a procurement variable: diversify providers, keep an open-weight fallback, and treat access terms as a contract risk to be tested.