Who Gets Access to Frontier AI?

Governments are beginning to decide who can access frontier AI, under what safeguards, and through which trusted-user systems. The challenge is to address real security risks without turning advanced capability into permanent discretionary privilege.

Share

Governments are beginning to decide which countries, companies, and institutions can use the most capable models—and under what conditions.

The most important frontier AI decision may no longer be whether a model is released.

It may be who is allowed to use it.

That question came into view during the U.S. government’s recent dispute with Anthropic over its Fable 5 and Mythos 5 models. On June 12, the government directed Anthropic to suspend access by foreign nationals, including foreign-national employees inside the United States. Anthropic said it could not comply cleanly without temporarily disabling the models more broadly.

The restriction was then partially loosened. Mythos became available to a group of “trusted” U.S. organizations. Less than three weeks after the original intervention, the government lifted the broader export controls after Anthropic added safeguards and began working with federal agencies and technology partners on common standards for testing and addressing jailbreaks.

Restriction. Trusted access. Added safeguards. Wider restoration.

That sequence may have been an improvised response to a genuine cybersecurity concern. It may also have revealed the outline of something more durable.

Frontier AI access is becoming a governed category.

Advanced models may increasingly be released, delayed, restricted, restored, previewed for approved recipients, or made available only under specified safeguards. Access may depend on nationality, geography, institutional status, beneficial ownership, security practices, government relationships, or participation in an approved technical ecosystem.

We are moving beyond export control applied to a new product. A system for allocating advanced capability is beginning to take shape.

National-security review may be necessary. The difficulty is what happens when the rules remain opaque, discretionary, unevenly applied, or negotiated privately with a handful of frontier labs.

If there is going to be a frontier switch, democracy needs to know who writes the access list, what standards they use, and how those decisions can be examined.

From chips to models to access

The United States has been moving toward this problem in stages.

The first stage focused on hardware.

Beginning in 2022, the Commerce Department used export controls to restrict China’s access to advanced computing chips and semiconductor-manufacturing equipment. The logic was straightforward: if cutting-edge AI depends on scarce compute, control over the inputs can slow an adversary’s progress.

The second stage focused on visibility.

President Biden’s 2023 AI executive order created reporting requirements for companies developing the most powerful dual-use foundation models. The government wanted a clearer view of what frontier labs were building, how those systems were being tested, and whether they were adequately protected.

Then came partnership.

Frontier AI companies became increasingly connected to defense, intelligence, cybersecurity, and critical-infrastructure work. Anthropic’s Claude Gov models for U.S. national-security customers are one example. The federal government was no longer standing outside the industry as regulator alone. It was also becoming a customer, evaluator, collaborator, and operational user.

We now appear to be entering a fourth stage: direct management of access.

The June 2026 White House order on advanced AI innovation and security did not create mandatory licensing or formal preclearance for model releases. It established a voluntary framework under which the government can receive early access to some advanced systems and develop classified benchmarks for national-security capabilities.

That may sound modest. In Washington, “voluntary” can cover a fair amount of institutional territory.

What matters is the direction. The government is moving closer to the release decision itself.

OpenAI’s GPT-5.6 preview made the emerging structure more visible. OpenAI said it planned broad availability, but began with a limited preview for a small group of trusted partners whose participation had been shared with the government. This was not an export-control order. It was another example of frontier access being staged through government consultation and approved recipients.

The emerging pattern is no longer simply “released” or “not released.” It includes:

  • early government access;
  • restricted foreign access;
  • trusted-user access;
  • staged release;
  • access conditioned on safeguards;
  • approved-recipient lists;
  • restoration after review.

Each category may be sensible. Together, they may become the architecture through which frontier capability is distributed.

The security case is real

It would be a mistake to treat every restriction as illegitimate gatekeeping.

Frontier AI can create genuine national-security risks. Models may improve vulnerability discovery, exploit development, cyber defense, biological research, intelligence analysis, weapons design, persuasion, surveillance, and military planning.

Cybersecurity is the clearest immediate example because the same capability can serve defenders and attackers. A system that helps a security team identify a serious vulnerability may help a hostile actor find it first. If a model materially changes the speed or scale of offensive cyber operations, release cannot be treated as an ordinary product decision.

Government also has responsibilities that private firms do not. It must protect military systems, intelligence sources, public infrastructure, and the broader population. A state that cannot independently evaluate frontier capabilities is not exercising democratic capacity. It is simply trusting the companies that built them.

Some secrecy is unavoidable. The government should not publish a detailed explanation of how a dangerous model can be exploited, nor should every security finding become a convenient roadmap for malicious use.

But secrecy about technical vulnerabilities is different from secrecy about the structure of decision-making.

The public may not need to know every classified finding. It does need to know the broad rules: when access can be restricted, who makes the decision, how comparable models are treated, how long restrictions last, and what oversight exists.

Necessary secrecy should protect the vulnerability.

It should not hide the system of authority.

From oversight to allocation

Why does the Anthropic episode matter beyond one company and two model names?

Because it shows how quickly safety review can become access allocation.

The original order restricted a category of users. The next step created a trusted group. Wider access returned only after safeguards were accepted.

Any one of those moves may have been reasonable. Together they establish something new: the government is helping decide who receives advanced capability and under what conditions.

The same pattern is appearing beyond individual model releases.

In July, the Commerce Department approved the United Arab Emirates government and selected companies to receive advanced computing items, including AI chips and servers, without individual licenses. The decision was tied to a broader U.S.–UAE artificial-intelligence cooperation framework and to UAE commitments to invest in U.S. AI infrastructure.

There may be sound strategic reasons for this arrangement. The United States has always differentiated among allies, partners, competitors, and adversaries.

Still, the case makes the shift visible. Advanced AI access is becoming an affirmative instrument of state policy.

Governments are deciding not only who must be denied capability, but who will be helped to obtain it.

That distinction matters. A strategic-access system can include chips, models, cloud services, training, technical assistance, data, and implementation support. Access can reward alliances, strengthen supply chains, encourage investment, define trusted ecosystems, and build geopolitical dependence.

Frontier AI is beginning to resemble other forms of strategic infrastructure: nuclear technology, advanced weapons systems, intelligence sharing, satellite access, and secure communications.

It is not simply sold into a global market. Increasingly, it is distributed through relationships.

China is moving toward its own strategic-access system

This is not only an American development.

China has spent years objecting to U.S. restrictions on advanced chips and technology transfer. It has promoted open models and lower-cost access as an alternative to a U.S.-dominated frontier ecosystem.

Now China is also beginning to treat its leading AI capability as a strategic asset.

Reuters reported in early July that Chinese authorities were considering restrictions on overseas access to the country’s most advanced models. More recent reporting suggests that the discussion may extend beyond finished services to model weights, training data, semiconductor designs, and overseas transactions that could transfer advanced technology. The proposals were still under consideration when this essay was written, and their eventual scope remains uncertain.

Even so, the underlying tension is becoming easier to see.

As Chinese models become more capable, Beijing faces much the same tradeoff as Washington. Openness can expand influence and accelerate adoption. It can also transfer strategic capability to competitors.

The U.S.–China AI contest may therefore resist the neat story in which one side is closed and the other open. Both countries may combine openness and restriction. Both may make some capabilities broadly available while reserving others for trusted users, domestic institutions, allies, or approved partners.

Both may decide that the frontier should travel—but not entirely on its own.

The more revealing difference may be the institutional form through which access is provided.

Access can be offered as well as withheld

China’s creation of the World Artificial Intelligence Cooperation Organization with 28 other countries adds another dimension.

The organization is presented as a mechanism for international governance, training, public applications, and technical cooperation. President Xi Jinping also announced thousands of training opportunities for developing countries, regional cooperation centers, and the extension of Chinese AI-enabled meteorological services to additional countries.

This may expand meaningful capacity in places that have been largely excluded from frontier AI development. Many countries do not possess the compute, technical staff, regulatory expertise, or bargaining power needed to participate on equal terms in the AI economy. Training, applications, and technical assistance could help narrow that gap.

Yet access offered through an international institution is never entirely neutral. It comes with standards, technical dependencies, governance assumptions, preferred platforms, and relationships to the state that provides it.

The United States increasingly organizes advanced capability around trusted partners, export rules, commercial providers, investment arrangements, and secure supply chains.

China is offering a competing model built around development assistance, state-to-state cooperation, public applications, and institutions aimed at the Global South.

This raises an important question: who gets to define the terms on which other countries gain AI capacity?

A country may receive valuable new capability while becoming dependent on the models, infrastructure, standards, security rules, and political relationships of the provider.

Access can disperse capability. It can also organize a sphere of influence.

A new public-private control layer

The usual AI concentration story focuses on private firms.

A small number of companies control much of the frontier-model market, advanced compute, cloud infrastructure, developer distribution, and user access. That concentration remains important.

Frontier access creates another path: growing interdependence between the national-security state and a small group of AI labs and infrastructure firms.

Government needs the companies because they possess the models, engineers, compute, and operational knowledge.

The companies need government because it controls export authority, security classifications, procurement, defense relationships, alliance policy, and access to sensitive markets.

The result may be a powerful public-private control layer.

This is not quite government takeover and not quite private monopoly. It is a system in which a small number of agencies and firms become regulators, customers, suppliers, evaluators, and strategic partners—sometimes all at once.

The roles begin to blur.

A lab may help define the benchmark against which its own model is evaluated. A government agency may restrict access while depending on the same company for national-security applications. A cloud provider may enforce a state access rule through proprietary account systems. A trusted-user designation may reflect security concerns, company safeguards, and commercial relationships at the same time.

Some cooperation is inevitable. Frontier systems are too technically complex, too expensive, and too strategically important for government and industry to operate in separate rooms.

The democratic concern begins when cooperation becomes unreviewable fusion.

That is why frontier access belongs primarily in Lane 2 — National Security and Frontier Control, while also reaching into Lane 5 — Platforms, Distribution, and Separations.

The switch is not held by government alone or industry alone.

It sits in the relationship between them.

Legitimate control versus discretionary gatekeeping

The goal cannot be to eliminate government oversight or require immediate public access to every powerful model.

The harder task is distinguishing legitimate security control from discretionary gatekeeping.

Legitimate control begins with a clearly defined risk. It uses rules that apply to comparable capabilities, not merely to one disfavored company or user. It limits secrecy to what must remain secret. It includes independent technical capacity, institutional oversight, and a route for reconsideration. Restrictions last only as long as the risk justifies them.

Discretionary gatekeeping has a different feel.

The trigger is unclear. The standard changes from one company or recipient to another. “Trusted” status is undefined. Access depends on private negotiation or political favor. Restrictions lack a clear duration. Affected parties cannot understand the decision or seek review. Temporary emergency measures quietly settle in and begin receiving mail.

The line will not always be obvious. Several tests can help make it visible.

Are the triggers clear?

The public should know the broad capability thresholds or risk categories that can produce review, staged release, or restriction.

Technical details may remain classified. The existence and scope of the authority should not.

Are similar cases treated similarly?

A rule aimed at dangerous capability should follow the capability across companies, countries, and delivery systems.

If one model is restricted while a comparable system is ignored, the process begins to look less like safety governance and more like selective control.

Is there independent capacity?

Government cannot rely entirely on company claims, and one agency should not be the sole source of judgment.

Independent evaluators, inspectors general, congressional committees, courts where appropriate, and technically capable public institutions provide checks on both industry and executive discretion.

Can decisions be revisited?

Emergency action may need to be fast. Long-term control should not be indefinite by default.

Access decisions need review dates, procedures for presenting new safeguards, and a clear path from restricted to staged to general access when conditions change.

Is access separable from political and commercial favoritism?

Trusted access should not quietly become preferred access for favored companies, allies, investors, or government partners without generally applicable criteria.

National-security policy will always distinguish among countries. The basis for those distinctions should still be visible enough to evaluate.

These requirements do not make the decisions easy.

They make the system more contestable.

The frontier switch is becoming a system

The Anthropic dispute may eventually look like an awkward early episode.

The government acted quickly. The company responded broadly. Trusted access was created. Safeguards were added. Restrictions were lifted.

That could be evidence of a system learning.

But the larger pattern already extends beyond one model.

The United States is developing early-access arrangements, trusted-recipient rules, export controls, alliance-based compute access, and public-private security partnerships.

China is considering its own restrictions while building international institutions through which technical capacity, training, and applications can be distributed.

Frontier AI access is becoming a form of statecraft.

That does not make every restriction wrong or every cooperation program suspect. It means access itself has become a site of power.

The old question was who could build the frontier.

The emerging question is who can cross it.

If the rules remain improvised, secret, and concentrated among a few firms and agencies, the frontier may become a closed public-private control layer.

If the rules are capability-based, reviewable, consistent, and institutionally accountable, governments may be able to address real security risks without turning access into permanent discretionary privilege.

More than one hand now rests on the frontier switch.

Democracy needs to know how the system works.

References and Further Reading

Historical foundation

United States frontier review and access

Strategic compute and recipient access

China and international access