For almost three years, the American and British AI institutes tested frontier models side by side. That arrangement now has a gate in front of it. The White House Office of the National Cyber Director (ONCD) has asked OpenAI and Anthropic not to share new frontier models with the UK AI Security Institute (AISI) until the US government has reviewed them, Politico reported on September 24, 2026, and a British official confirmed the request to Bloomberg the next day (The Next Web; Bloomberg). Anthropic, OpenAI and the White House all declined to comment, according to The Next Web.
What the White House asked for, and what Anthropic did
A senior administration official told Politico that the US wants to review new models first, explaining: "Because they're American companies and this has been our policy with every new frontier model that comes out" (The Next Web). No written directive has been published, so the exact scope and duration of the request remain unconfirmed.
At least one model was already affected. Anthropic released Claude Mythos 5.1 on September 1, 2026, and limited it to a set of US organizations, saying it would "coordinate with the U.S. government to expand access" over time (The Next Web; ITPro). Reports describe it as the first Anthropic model the UK institute was not allowed to test before launch (Tech Times).
Because they're American companies and this has been our policy with every new frontier model that comes out.
Senior administration official, as reported by Politico
The de Zoete letter to Parliament
The gap first surfaced in Westminster. On September 9, Liam Byrne, chair of the House of Commons Business and Trade Committee, wrote to AISI director Henry de Zoete about reports that Anthropic had not given the institute pre-release access to Mythos 5.1 (Computing). In his reply, de Zoete wrote that "Anthropic made clear at the time of the release of Mythos 5.1 that no organisations outside of the US had access to the model" (ITPro).
He also pointed to continuing access elsewhere: AISI maintains "strong relationships with all frontier AI developers" and continues "to have prerelease access to some of the world's most capable models," including OpenAI's GPT-6 Astra, which it tested before release (The Next Web). An AISI spokesperson added that "these risks do not stop at national borders and no country can tackle them alone" (ITPro). Whether AISI received early access to the models released on September 22, Claude Opus 5.5 and GPT-6 Sol and Luna, has not been publicly confirmed.
How US-UK AI safety cooperation was built
The partnership was designed for exactly the kind of shared testing now in question. The US announced its AI Safety Institute on November 1, 2023, saying it would work with the UK's (US Commerce Department). The UK launched its institute a day later at the Bletchley Park summit, where 28 countries and the EU signed the Bletchley Declaration (GOV.UK).

On April 1, 2024, Commerce Secretary Gina Raimondo and UK Technology Secretary Michelle Donelan signed a memorandum of understanding committing the institutes to share capabilities and run at least one joint testing exercise (US Commerce Department). Both institutes were later renamed. The UK body became the AI Security Institute on February 14, 2025 (AISI), and on June 3, 2025, Commerce Secretary Howard Lutnick reformed the US institute into the Center for AI Standards and Innovation (CAISI), focused on demonstrable risks such as cybersecurity and biosecurity (US Commerce Department).
From shared testing to a US-first review: a verified timeline
Green marks the cooperation era built around joint evaluation. Gray marks the 2026 events that opened the access gap.
Sources: US Commerce Department, GOV.UK, NIST, UK AISI, CNBC, ITPro, Computing, Politico via The Next Web, Bloomberg.
What pre-deployment testing actually does
The first joint exercise shows the mechanics. In November 2024, the two institutes evaluated Anthropic's upgraded Claude 3.5 Sonnet before release, running separate but complementary tests on biological capabilities, cyber capabilities, software and AI development, and safeguard efficacy. The model completed 90% of non-expert cyber tasks, and the findings were shared with Anthropic before public release (NIST).
That is the value at stake: a government gets an independent read on dangerous capabilities while the developer can still adjust safeguards. Post-release testing can still happen, but it cannot change what shipped.
A US review body without a permanent director
The request routes review through US agencies at a moment when CAISI itself is thinly led. Director Chris Fall resigned on July 20, 2026, after about three months, and Arvind Raman was named acting director (CNBC). The Decoder reports that CAISI has "no permanent director and only a few dozen staffers" (The Decoder). How long a US review takes before models reach allies is not public.
Sovereignty versus shared evaluation
Two readings are possible. From Washington's side, models built by American companies with strong cyber capabilities are a national security asset, and reviewing them first is consistent with the voluntary pre-release review approach covered in our posts on the frontier AI model review framework and the finalized AI safety framework. From London's side, an evaluator that sees models only after a delay offers less assurance to its own government. Byrne has said that "voluntary self-regulation is unlikely to be a sustainable safeguard for the future," and the committee has scheduled an October 13 session with major labs, according to Insurance Business.
For other allies with their own institutes, the question is whether access to US frontier models now depends on bilateral sequencing rather than parallel testing. For labs, it adds one more government relationship to manage per release. For teams building on these models, availability can differ by country and change quickly, which is one practical reason model-agnostic tools such as Metir let users switch between providers.
What to watch
- Whether the White House publishes the terms of the request, including how long US review lasts.
- Whether AISI gains access to Mythos 5.1 or the September 22 releases.
- Whether CAISI gets a permanent director, and what the October 13 committee session produces.
Sources:
- The Next Web: White House asks OpenAI and Anthropic to hold AI models from UK testers
- Bloomberg: Trump tells OpenAI, Anthropic to withhold models from UK agency
- The Decoder: White House tells OpenAI and Anthropic to let U.S. review new models first
- Digital Watch Observatory: US asked OpenAI and Anthropic to hold AI models for US review
- Tech Times: White House bars UK AI Safety Institute from frontier AI testing
- ITPro: OpenAI and Anthropic could withhold new AI models from UK's AI Security Institute
- Computing: UK AI Security Institute may be blocked from testing latest models
- Insurance Business: White House tells AI labs to hold new models back from UK testers
- CNBC: Head of AI safety agency CAISI resigns after months on job
- US Commerce Department: Establishing the U.S. AI Safety Institute (November 2023)
- GOV.UK: The Bletchley Declaration
- US Commerce Department: U.S. and UK announce partnership on science of AI safety
- AISI: Our first year
- US Commerce Department: Statement on transforming the AI Safety Institute into CAISI
- NIST: Pre-deployment evaluation of Anthropic's upgraded Claude 3.5 Sonnet
Image credits
- Hero: Round table hosted by Deputy Prime Minister Oliver Dowden on day two of the AI Safety Summit at Bletchley Park, 2 November 2023. Photo by Marcel Grabowski / UK Government. Source: Wikimedia Commons, licensed CC BY 2.0.
- In-body: Delegates arriving on day one of the AI Safety Summit at Bletchley Park, 1 November 2023. Photo by Marcel Grabowski / UK Government. Source: Wikimedia Commons, licensed CC BY 2.0.

Anthropic