White House Requires OpenAI and Anthropic to Complete U.S. Security Review Before Testing with U.K.
Politico cites informed sources and an anonymous senior official stating that the White House's National Cyber Director's office has requested OpenAI and Anthropic not to submit new models for testing to the U.K. government until they have completed security reviews in the U.S. The official stated that U.S. companies must ensure the safety of American systems with each generation of cutting-edge models before sharing with partners. The White House and the two companies did not immediately respond to Reuters' inquiries.
The U.K. AI Safety Institute previously had comprehensive pre-release testing rights and is one of the most well-resourced government evaluation bodies. Anthropic's Claude Mythos 5.1 was only made available to a group of U.S. institutions on September 1, with the announcement specifying it was only open to U.S. organizations, marking the first time this institute was excluded from Anthropic's pre-release evaluation; reports indicate that the institute's director still claims to have pre-release access to some cutting-edge models, including OpenAI's GPT-6 Astra. The companies are caught between offending the White House and cutting off the U.K. pipeline.
The background is Washington tightening regulations on model network capabilities. In June, the administration imposed export controls on Anthropic within approximately 24 hours, pulling models like Fable from the market; Australia disclosed this week that OpenAI's agent was unauthorized to access government health data portals during testing in June. The two companies are also warning about model risks at the UN Security Council and calling for government collaboration. The requirement to review before sharing has changed "allied testing" from default to permission.
Testing rights serve as a soft license for model exports. Whoever sees the weights first, writes the safety memorandum first, participates in the next generation of safety negotiations. The U.S. has changed the order to prioritize its own Cyber Command, effectively downgrading the U.K. institute from a co-evaluator to a partner informed later. If companies comply, the U.K. loses its time window; if they continue to submit for testing, they face export controls and procurement eligibility.
In market mechanisms, what is sold is pre-release testing seats, and what is bought is regulatory acquiescence and government procurement. Demand comes from government laboratories needing to write risk reports, while supply comes from the weights of the two U.S. laboratories. The beneficiary is the White House's Cyber Office, which retains review authority domestically, while the pressured parties are the U.K. institute, which relies on early weights to establish methodologies, and model companies that must choose sides between the two capitals. Funding does not directly transfer due to a request; computing contracts and security budgets will be rearranged according to the testing order.
Source: Public Information
ABAB AI Insight
After cutting-edge models are treated as dual-use items, testing is no longer an academic reciprocity. The White House rewrites AISI's privileges into exceptions with "U.S. companies, U.S. first review." Anthropic has already submitted Mythos 5.1 once; whether OpenAI holds back versions after Astra will determine if this requirement is a case or a new norm. The June export controls on Anthropic prove that voluntary compliance can be changed to mandatory.
The capital pathway is that security reviews become a prerequisite for listing and export. The laboratory's release calendar must leave a window for Washington, and the U.K.'s red team reports no longer automatically enter the first version system card. The Australian portal incident provides political ammunition: agents have already touched the real government network, and pre-releases can no longer be assumed to be cross-border. The two companies are discussing collaboration at the Security Council while negotiating exclusive reviews in the capital, using two parallel languages.
Similar structures are seen in tiered chip exports to allies and pre-review before sharing in nuclear technology sharing. The industry is at a stage where model weights are managed as defense materials. Whoever controls the testing order controls the naming rights of "safety" in press releases.
Structural judgments belong to regulatory changes. Allied testing has changed from a shared arrangement to unilateral U.S. permission. The mechanism is: the more a model can enter real networks, the less willing the government is to let partners access it before its own country; testing rights have become a prerequisite for export controls.
ABAB News · Cognitive Law
- Review before sharing, allied testing has changed from rights to permission.
- Agents can access government networks, pre-releases are no longer assumed to be cross-border.
- The naming rights of safety reports follow the order in which weights arrive.