You probably think about a frontier AI model the way you think about any enterprise product: price, capability, licence terms, then buy. That assumption is quietly coming apart.
Two live access regimes are at work: US Executive Order 14409 and the EU AI Act‘s evaluation powers. Together with a widening divide between classified and civilian evaluation, they mean who may use a frontier model is being settled by governments on unseen terms. The US government has effectively appointed itself gatekeeper over frontier AI access.
So what’s actually going on? This piece defines the “securitisation of frontier AI” framing, then compares the two access regimes and the two evaluation models side by side. For the wider arc this belongs to — how a nominally voluntary US order hardened into a binding release gate — see where securitisation fits the government gatekeeper model. By the end you’ll have a map of who controls access, what instrument they use, and which gate actually holds, plus what that means for your business.
What is the “securitisation of frontier AI”, and why does it matter for who gets access?
Securitisation is a term borrowed from security studies: an issue recast as an existential threat, urgent enough to justify exceptional measures and a smaller circle of decision-makers sitting outside ordinary politics. RUSI’s Dr Louise Marie Hurel describes the shift as moving who may access these models “into the narrower register of national security.”
Applied to frontier AI, securitisation means reclassifying a model as a dual-use security asset. Access then stops being a product you buy and becomes a permission a government grants or withholds. The question you have to answer is “am I permitted to use this?”
That reframe produces three consequences: fragmentation, where each jurisdiction builds its own gate; exclusion, where outsiders get cut off; and capture, where security actors set the terms.
In one early case, weeks before the export-control directive, the Pentagon hit Anthropic with a supply-chain risk designation, a label once reserved for foreign adversaries. EO 14409 adds a “preview of the preview”, a pre-release government look at covered models.
The logic is scaling beyond Washington. The European Technological Sovereignty Package, the UK Sovereign Model Coalition and the Five Eyes cyber warning all show allies adopting the same security-first lens, replicating the government gatekeeper model for AI releases jurisdiction by jurisdiction. Two forces contest it: AI sovereignty and open-weight models.
The framing becomes concrete in two instruments, which is where the comparison starts.
Executive Order 14409 vs the EU AI Act’s evaluation powers: how do the two access regimes differ?
Both regimes want the same thing: government access to frontier models before, or independent of, public release. The difference is the instrument. Executive Order 14409 relies on voluntary, classified judgement, while the EU AI Act’s Articles 91 and 92 write evaluation powers into statute.
Executive Order 14409 leans on executive authority and classified judgement. Access is voluntary, triggered only when a model crosses a classified “covered frontier model” threshold set by the NSA, and the order explicitly disclaims any mandatory licensing, preclearance or permitting scheme.
The EU AI Act works differently. Articles 91 and 92 give the EU AI Office statutory powers to request information, conduct evaluations of general-purpose AI models, and require access so the office or independent experts can run them. Non-compliance is backed by fines of up to €15 million or 3% of turnover.
In short, one side is executive, classified and discretionary, the other statutory, published and evaluative.
The reason each side insists on its own answer is AI sovereignty. Europe’s 90 per cent dependence on US cloud and AI infrastructure leaves it exposed to extraterritorial reach, so a statutory regime is Brussels’ answer. Its “appropriate access” remains under-defined, though: the GPAI Code of Practice asks for it without specifying.
Inside the US, the same tension plays out between two institutions, which is the next comparison.
CAISI’s civilian evaluation model vs the NSA’s classified designation: which institutional design is better?
The choice between civilian and classified evaluation trades accountability against control. On one side, CAISI’s civilian, standards-based model buys legitimacy and reviewability. On the other, the NSA’s classified designation buys speed and control. Neither wins on every criterion, so which is better depends on which value you care about most. It is also the fault line running through the wider government gatekeeper model, where the same decision resurfaces as a question of institutional design.
On the civilian side sits CAISI, the Center for AI Standards and Innovation, a NIST office that has run the government’s frontier-model evaluation to date. It works under public agreements with OpenAI and Anthropic, and has expanded testing to Google DeepMind, Microsoft and xAI. Because its standards are published, you can see them and challenge them, and third-party evaluators and red teams can contest the results.
On the classified side sits the NSA. Under EO 14409, its Director runs a classified benchmarking process deciding which models count as covered frontier models, placing the designation with the national security establishment rather than the civilian standards office. Its advantage is speed, but nobody outside can audit where the line sits. Lawfare calls moving that designation behind a classified benchmark the wrong institutional design, and argues Congress should anchor the standards function at CAISI instead.
Third-party evaluation is the unresolved middle. Everyone agrees it’s needed, yet there is still no shared definition of what “adequate access” means, even as venues like the AI Evaluator Forum and the Frontier Model Forum try to standardise it.
Then there’s the pressure valve shadowing both designs: open-weight models. A model whose weights are public can be downloaded and run locally, so a government gate on hosted access does not control it. Any access regime is only as strong as the closed/open boundary, which neither Washington nor Brussels controls.
Here’s the changed question: for any frontier model, ask whether you are permitted to use it, and who decided. What decides which gate, if any, holds is the stand-off between AI sovereignty, which keeps pushing jurisdictions to build their own gates, and open-weight models, which keep making those gates optional. You are left holding both forces at once. The comparative picture that closes the cluster traces how that stand-off plays out across Washington, Brussels and their allies.
Frequently Asked Questions
Is Executive Order 14409 actually a law, and could a future president reverse it?
No. EO 14409 is an executive order, not a statute passed by Congress, so it rests on presidential authority rather than legislation. That makes it durable only while the administration that issued it holds office: a future president can amend, suspend or revoke it, and the voluntary review it creates would lapse with it. A statutory regime like the EU AI Act cannot be undone so easily, which is precisely the accountability trade-off at stake.
What is a “covered frontier model”, and who decides the threshold?
A covered frontier model is one that crosses the capability bar EO 14409 uses to trigger government review. That bar is a classified designation set by the NSA, not a published compute figure, so the same model may be treated as covered or not without the developer being able to verify why. The secrecy is the point: it lets the threshold move as capabilities advance, but it also means no outsider can audit where the line sits.
What is a supply chain risk designation, and what does it do to a company?
A supply chain risk designation flags a vendor as a security risk inside a trusted technology stack, and the article notes one applied to a US lab. The practical effect is exclusion rather than prosecution: the firm can be shut out of government procurement, dropped from trusted-partner arrangements and avoided by allies wary of the label. It is securitisation operating through market access rather than a court.
What does “preview of the preview” mean?
“Preview of the preview” describes the informal pre-release access governments now get to frontier models before any public launch. Rather than waiting for a formal review, officials are shown early builds and capability demonstrations ahead of the announced release, effectively a preview before the preview. The practice matters because it turns security scrutiny into a routine step that happens off the record, before regulators, competitors or the public know a model exists.
Can I run an open-weight model locally without government permission?
In most cases, yes, and that is exactly what makes open-weight models the pressure valve on every access regime. Once the weights are downloadable, the model can be copied and run on local hardware, so a government gate on hosted access does not control it. The caveat is that open weights only route around the gate if the model is strong enough to matter and the download itself is not restricted.
What happens if a company refuses a government evaluation request?
It depends entirely on which regime applies. Under EO 14409’s voluntary framework, refusal does not trigger a statutory penalty, but it can cost a firm its place in the trusted-partner circle and its goodwill with the agencies that gate procurement. Under the EU AI Act, Articles 91 and 92 are backed by fines, so refusing to provide documentation or access carries enforceable financial consequences.
What is AI sovereignty, and why is Europe pursuing it so aggressively?
AI sovereignty is the drive to build and control a domestic AI stack, from compute and data to models and evaluation, rather than depending on another country’s. Europe pursues it aggressively because its dependence on US cloud and AI infrastructure leaves it rule-taking rather than rule-making: if Washington can restrict access, Brussels’ own statutory powers mean little. Sovereignty is the motive that pushes each jurisdiction to erect its own gate.
How are US allies outside Europe responding to the securitisation of frontier AI?
They are adopting the same security-first lens rather than resisting it. The UK’s Sovereign Model Coalition and the Five Eyes cyber warning both treat frontier model access as a shared security problem, aligning allied evaluation and intelligence efforts. The pattern is convergence around the framing even where the instruments differ: allies are building national capacity while coordinating on the security question, rather than leaving access to the open market.
What is CAISI, and how does it relate to NIST?
CAISI, the Centre for AI Standards and Innovation, is the civilian evaluation body housed within NIST that assesses frontier models through transparent, standards-based methods. It sits on the accountability side of the design trade: it publishes its approaches, engages third-party evaluators and red teams, and keeps assessment contestable. The NSA’s classified designation process is its counterpart, setting the covered-frontier-model threshold in secret and assessing advanced cyber capability on non-public terms.
Who counts as a “trusted partner”, and how does a company join that circle?
The trusted-partner circle is the set of firms and institutions governments allow early or privileged access to frontier models, and membership is granted on security terms rather than bought. Entry typically follows government vetting, contractual security conditions and a track record of cooperation with evaluators, so it rewards incumbents with existing agency relationships. Because the criteria are rarely published, the circle tends to look closed from the outside.
Do export controls and access controls achieve the same thing?
No, they operate at different points in the chain. Export controls restrict the movement of hardware and model weights across borders, targeting where the technology physically goes. Access controls restrict who may use or assess a model, even inside the country, by conditioning access on government permission. The securitisation frame uses both: export controls stop the capability leaving, access controls decide who is admitted once it stays.
Will the securitisation of frontier AI lead to an outright ban on advanced models?
Unlikely, and that is the more subtle risk. Securitisation works through permission rather than prohibition: models are not banned but gated, with access granted to a trusted circle on security terms. The practical effect can resemble a ban for those outside that circle, without the legal clarity a ban would bring. The danger is quiet exclusion, not a headline prohibition, which is harder to challenge or even notice.