# White House tells OpenAI and Anthropic to hold new models back from Britain's AI Security Institute

> The White House asked OpenAI and Anthropic to hold new models back from the UK's AI safety testers.

*For three years, US and UK testers assessed the same frontier models in parallel. Washington's request that it sees them first ends that arrangement, and leaves the labs holding the risk in between.*

By Behzad Hosseini · WireRead
Canonical: https://wireread.com/news/white-house-openai-anthropic-uk-ai-security-institute-analysis

For three years, the case for the UK's AI Security Institute rested on a simple claim: that Britain, allied with Washington but formally outside its chain of command, could examine the same frontier models the American government examined, at the same time, and catch what a single tester working alone might miss. On 24 September 2026, Politico's Sophia Cai and Joseph Bambridge reported that the White House has quietly ended that arrangement. A British official confirmed the report to Bloomberg the following day.

## What Washington actually asked for

The request is narrower than 'the UK is banned from AI safety testing', and the precision matters. It does not touch models already released, and it is not a statute or an executive order — it is a policy position, relayed to two companies by an office few people outside Washington could name. The Office of the National Cyber Director sits inside the White House and ordinarily coordinates cyber policy; using it, rather than the Commerce Department's own testing body, to deliver the message tells its own story about how the administration is framing this — as a security instruction, not a science-sharing decision.

> Because they're American companies and this has been our policy with every new frontier model that comes out,
> — [Politico](https://www.politico.com/news/2026/09/24/white-house-asks-openai-and-anthropic-to-hold-new-models-from-uk-testers-until-u-s-review-01091769), 2026-09-24

That is the entire stated rationale, attributed to a senior administration official. It is a jurisdictional argument, not a technical one: American companies' most capable systems get reviewed by the American government first, and only then do allies see them. Politico's sourcing — one senior official and one person familiar, both granted anonymity — means there is, as of this week, no public directive or memo to cite. The instruction exists because two companies are following it, not because a published rule compels them to.

## Anthropic appears to have gone along already

The clearest evidence the request has teeth arrived before Politico's report did. Anthropic launched Claude Mythos 5.1 on 1 September 2026 and restricted it, as it had restricted the base Mythos model in June, to a set of US organisations. The company was explicit about the gap on its own product page, in language Politico later quoted directly in its report:

> only available to a set of US organizations, though we're coordinating with the US government to expand access to a broader set of domestic and international partners as quickly as possible.
> — [Anthropic](https://www.anthropic.com/claude-fable-and-mythos-5-1), 2026-09-01

Read against Politico's reporting, that line stops being a routine access-tier disclosure and becomes the first documented instance of the White House's policy actually working. Anthropic did not contest it, did not negotiate a carve-out for AISI, and declined to comment when Politico and Bloomberg both asked. Given the company's history with this administration — a February order pulling federal agencies off its products, a June export-control letter that briefly locked all foreign nationals out of Mythos and Fable entirely — quietly going along is the least surprising part of this story.

## AISI's case that nothing has changed

The institute's public position is that its access is intact. AISI director Henry de Zoete made that case in a letter to the House of Commons Business and Trade Committee on 15 September 2026, responding to the committee's questions about the Mythos 5.1 gap:

> We maintain strong relationships with all frontier AI developers and continue to have prerelease access to some of the world's most capable models,
> — [Politico](https://www.politico.com/news/2026/09/24/white-house-asks-openai-and-anthropic-to-hold-new-models-from-uk-testers-until-u-s-review-01091769), 2026-09-15

He pointed to AISI's evaluation of OpenAI's GPT-6 Astra ahead of its public release as evidence the channel still works. Both things can be true at once: AISI still gets some models early, and it did not get one of the two most consequential releases of the autumn. A UK government spokesperson made the reassurance case in stronger terms to Politico, adding that 'these risks do not stop at national borders and no country can tackle them alone' — a fair description of the risk, but not, on its own, a rebuttal to the narrower claim that the US now sees new frontier models before the UK does.

## The asymmetry underneath the reassurance

What makes the sequencing sting is that AISI is not the junior partner on paper. Politico's reporting noted, almost in passing, that the US testing body Washington is now asking to go first — the Commerce Department's Center for AI Standards and Innovation (CAISI) — has no permanent director and only a few dozen technical staff, and is increasingly stretched as it is asked to evaluate an expanding stream of frontier models. AISI, by its own account, is considerably better resourced.

| | AISI (UK) | CAISI (US) |
| --- | --- | --- |
| Permanent director | Yes — Henry de Zoete | No, per Politico |
| Annual funding | £66m | Not disclosed |
| Technical staff | 100+ | 'A few dozen', per Politico |
| Compute access | Priority access to £1.5bn+ | Not disclosed |

> **Key:** This is not, on the evidence, a story about which government is more capable of testing a frontier model safely. It is a story about which government gets to decide who tests it first — and Washington has just settled that question by fiat, through an office with no public mandate to arbitrate it, rather than through the comparative competence of the two testing bodies.

## What this ends, and what to watch

Since the Bletchley Park summit in November 2023, the working theory behind national AI safety institutes was that allied governments testing the same systems independently would catch more between them than either would alone — the same logic that underpins financial-market supervision and aviation safety. A US-first queue does not abolish that theory, but it does convert AISI from a parallel tester into a downstream one, seeing what Washington has already looked at, on Washington's schedule.

The politics of the same week make the gap harder to paper over. Prime Minister Andy Burnham used the UN General Assembly to describe AISI as working 'hand in glove with the U.S. and the leading labs on AI safety' and to call for a 'single set of global principles and standards'. President Trump, addressing the same UN gathering, dismissed any coordinated global framework as a 'globalist scheme'. Those are not compatible starting positions, and the model-access story is the first concrete evidence of which one is actually governing company behaviour.

Two dates now matter more than the headline. On 13 October, OpenAI, Anthropic, Google DeepMind and Meta are due before the Commons Business and Trade Committee — which had already been pressing the voluntary-access question before Washington's request became public — with de Zoete giving evidence the same day. And the next frontier release from either lab is the real test: if AISI receives it on a materially later schedule than CAISI, the 'nothing has changed' line will be difficult to repeat with a straight face.

## Key takeaways

- Politico reported on 24 September 2026 that the White House's Office of the National Cyber Director asked OpenAI and Anthropic to hold new models back from the UK's AI Security Institute until the US tests them first.
- A British official confirmed the report to Bloomberg on 25 September; OpenAI, Anthropic and the White House declined to comment or did not respond.
- Anthropic had already restricted Claude Mythos 5.1, released 1 September, to a set of US organisations — the first documented instance of the policy in effect.
- AISI director Henry de Zoete told a parliamentary committee on 15 September the institute still has prerelease access to other models, including GPT-6 Astra, and a UK spokesperson said nothing has fundamentally changed.
- The request ends the model of independent, parallel US-UK testing built since the 2023 Bletchley Park summit and replaces it with a US-first queue — even though AISI is the better-resourced of the two testing bodies.

## FAQ

### What did the White House actually ask OpenAI and Anthropic to do?
Not to share new frontier AI models with the UK's AI Security Institute until the US government has reviewed them first — a request from the Office of the National Cyber Director, reported by Politico on 24 September 2026, not a public rule or executive order.

### Has this already affected a real model?
Yes. Anthropic's Claude Mythos 5.1, released 1 September 2026, was restricted to a set of US organisations; Anthropic said it was coordinating with the US government to expand access. AISI did not receive it for testing.

### Does the UK still get to test any new US models?
AISI director Henry de Zoete says the institute retains prerelease access to other models and tested OpenAI's GPT-6 Astra before its release — but not, on the evidence so far, on the same schedule as the US.

### Is the UK's AI Security Institute less capable than its US counterpart?
No — the opposite, on the public record. AISI reports £66m in annual funding, priority access to over £1.5bn of compute and 100-plus technical staff; Politico reported the US Center for AI Standards and Innovation has no permanent director and only a few dozen technical staff.

### What happens next?
OpenAI, Anthropic, Google DeepMind and Meta are due before the Commons Business and Trade Committee on 13 October, with de Zoete giving evidence the same day. Whether AISI's access to the next major release lags CAISI's will be the practical test of the policy.

## Sources

- [White House asks OpenAI and Anthropic to hold new models from UK testers until US review](https://www.politico.com/news/2026/09/24/white-house-asks-openai-and-anthropic-to-hold-new-models-from-uk-testers-until-u-s-review-01091769) — Politico, 2026-09-24
- [Trump Tells OpenAI, Anthropic to Withhold Models From UK Agency](https://www.bloomberg.com/news/articles/2026-09-25/trump-tells-openai-anthropic-to-withhold-models-from-uk-agency) — Bloomberg, 2026-09-25
- [Donald Trump tells OpenAI, Anthropic to withhold models from UK agency](https://www.business-standard.com/world-news/donald-trump-tells-openai-anthropic-to-withhold-models-from-uk-agency-126092501029_1.html) — Business Standard (Bloomberg), 2026-09-25
- [Introducing Claude Fable 5.1 and Claude Mythos 5.1](https://www.anthropic.com/claude-fable-and-mythos-5-1) — Anthropic, 2026-09-01
- [About the AI Security Institute](https://www.aisi.gov.uk/about) — AI Security Institute, 2026-09-26
- [OpenAI and Anthropic summoned to parliament on fears UK AI rules 'not fit for future'](https://www.cityam.com/openai-and-anthropic-summoned-to-parliament-on-fears-uk-ai-rules-not-fit-for-future/) — City AM, 2026-09-22
- [OpenAI and Anthropic could withhold new AI models from UK's AI Security Institute](https://www.itpro.com/security/openai-and-anthropic-snub-uks-ai-security-institute-on-new-model-testing) — IT Pro, 2026-09-25
- [Trump orders federal agencies to stop using Anthropic as dispute escalates](https://www.aljazeera.com/news/2026/2/27/trump-orders-federal-agencies-to-stop-using-anthropic-as-dispute-escalates) — Al Jazeera, 2026-02-27
- [Judge temporarily blocks Trump administration's Anthropic ban](https://www.npr.org/2026/03/26/nx-s1-5762971/judge-temporarily-blocks-anthropic-ban) — NPR, 2026-03-26
- [Anthropic disables Fable and Mythos AI models after U.S. government bars it from giving foreigners access](https://fortune.com/2026/06/13/anthropic-disables-fable-mythos-export-controls-national-security-threat/) — Fortune, 2026-06-13
- [Federal appeals court rules Pentagon's blacklist of Anthropic was legal](https://www.cnn.com/2026/09/25/tech/anthropic-pentagon-blacklist-dc-ruling) — CNN, 2026-09-25
