OpenAI has delayed the broad release of its new GPT-5.6 model family following a request from the United States government. Instead of making the models generally available, the company has opened a limited preview for a small group of vetted partners whose identities were shared with US authorities.

The decision represents more than another cautious technology rollout. It suggests that access to frontier artificial intelligence is becoming a matter of national security, geopolitical alignment and government approval.

According to Reuters, the initial arrangement involves government participation in approving access “customer by customer” during the preview period. The request reportedly followed discussions involving the Office of the National Cyber Director and the White House Office of Science and Technology Policy.

What OpenAI is releasing

OpenAI CEO Sam Altman publicly acknowledged the tension created by the arrangement. He said extensive safety testing was reasonable but objected to the government effectively selecting which customers could receive the technology.

The GPT-5.6 family consists of three capability tiers:

  • Sol, OpenAI’s flagship and most capable model;
  • Terra, a lower-cost model intended for balanced everyday use;
  • Luna, the fastest and least expensive version.

During the preview, the models are available only through selected API and Codex deployments. OpenAI says broader availability through ChatGPT, Codex and the API is planned, although the timing depends partly on how the controlled preview develops.

OpenAI describes GPT-5.6 Sol as its strongest model to date, with significant improvements in coding, biology and cybersecurity. However, the company says Sol did not cross the “Cyber Critical” threshold under its internal Preparedness Framework.

In testing involving Chromium and Firefox, the model identified software defects and components that could contribute to an exploit, but it did not autonomously produce a working end-to-end exploit under the tested conditions. OpenAI nevertheless warned that benchmarks cannot represent every possible combination of an AI model, external tools and multi-stage workflows.

The company has therefore introduced a layered control system involving model-level restrictions, real-time monitoring, account-level risk signals, differentiated access, human review and continued red-team testing. OpenAI says it used more than 700,000 A100-equivalent GPU hours for automated testing designed to identify broadly effective jailbreak techniques.

The new US policy framework

The restricted rollout follows Executive Order 14409, signed on 2 June 2026 under the title “Promoting Advanced Artificial Intelligence Innovation and Security.”

The order directs US agencies to develop a classified benchmarking process for measuring the advanced cyber capabilities of AI systems. Models exceeding a yet-to-be-defined threshold may be designated as “covered frontier models.” The determination would involve the National Security Agency, the Office of the National Cyber Director, CISA and other national-security bodies.

The order also calls for a voluntary framework under which AI developers may:

  • consult the federal government on whether a model qualifies as a covered frontier model;
  • provide the government with access to the model for up to 30 days before releasing it to other trusted partners;
  • cooperate with federal authorities in selecting organisations that should receive early access.

The order explicitly states that it does not establish a mandatory government licensing, preclearance or permitting regime for new AI models.
That distinction is important. Formally, the framework is voluntary. In practice, however, OpenAI agreed to restrict its launch after a government request and shared the identities of preview partners with the authorities. The episode demonstrates how government influence can extend beyond formal licensing powers.

The broader US strategy is not intended only to restrict access. It also seeks to make frontier models available to federal agencies, local authorities and operators of critical infrastructure, including hospitals, banks and utilities. The executive order requires the creation of an AI cybersecurity clearinghouse to coordinate vulnerability discovery, validation, remediation and software patching.

A separate national-security memorandum directs US agencies to build close partnerships with the private sector and make advanced frontier models rapidly available to national-security professionals. It also requires contractual and technical safeguards preventing vendors or external actors from disabling, degrading or materially altering AI systems used for national-security missions without government approval.

The policy therefore has two complementary objectives: prevent uncontrolled distribution of high-risk capabilities while ensuring that the US government and selected domestic partners retain reliable access to them.

Anthropic faced a more direct restriction

The OpenAI arrangement follows an even more consequential intervention involving Anthropic.

On 12 June, Anthropic said the US government had issued an export-control directive suspending access to its Fable 5 and Mythos 5 models for every foreign national, including foreign nationals located inside the United States and Anthropic’s own non-US employees.

Anthropic said it disabled the models for all customers because it could not otherwise guarantee compliance with the directive. The company stated that the government had cited national-security authorities but had not initially provided detailed information about the underlying concern.

The restrictions were reportedly connected to concerns that model safeguards could be bypassed and that the models possessed powerful cybersecurity capabilities. Anthropic argued that the demonstrated bypass identified only a small number of previously known, relatively minor vulnerabilities that other publicly available models could also discover.

The US subsequently allowed Anthropic to make Mythos available to selected trusted US organisations and was reportedly considering restoring broader Fable 5 access. The rapid restriction, partial reversal and renegotiation illustrate how access to frontier AI may be changed at short notice as governments reassess security risks.

Europe is paying attention

The dispute has already triggered a European political response.

Austria has urged the European Union to explore hosting Anthropic operations within the EU so that European users are not excluded from major technological developments by decisions made in the United States.

Austria’s State Secretary for Digitalisation, Alexander Pröll, asked whether Europe intended to shape its own technological future or remain dependent on decisions taken elsewhere. His proposal referred to offering legal certainty, market access, capital and a European values framework, although no detailed implementation mechanism has yet been presented.

The Austrian initiative reflects a broader concern: Europe may regulate artificial intelligence extensively while remaining dependent on non-European companies and governments for access to the most capable underlying models.

Why this matters for business leaders

For companies, frontier-model access can no longer be considered an ordinary cloud-service dependency.

An organisation may comply with its contract, maintain strong security controls and operate in a legally supported market, yet still lose access because of government decisions involving national security, export controls, employee nationality or the intended use of the technology.

This creates several strategic risks.

1. AI continuity risk. Business processes built around one frontier model may be disrupted by regulatory restrictions, delayed releases or changes to regional availability. Organisations should avoid assuming that every model currently available will remain available in every jurisdiction.

2. Geographic and nationality restrictions. The Anthropic directive shows that restrictions can apply not only to where a company is incorporated or where its servers are located, but also to the nationality of employees who access the system. Multinational companies may therefore need stronger controls over model entitlements, development environments, support access and cross-border collaboration.

3. Unequal access to defensive capabilities. The most capable models may help security teams identify vulnerabilities, analyse malware, validate patches and review software at a speed unavailable to organisations using older models. OpenAI already operates an identity- and trust-based access programme under which verified cyber defenders receive more permissive access for legitimate defensive activities, while requests involving credential theft, persistence, malicious deployment or attacks against third-party systems remain restricted. If the strongest models are distributed only to government-approved or specially vetted organisations, cybersecurity capability may become increasingly uneven.

4. Government involvement in supplier selection. The US framework allows authorities and AI developers to collaborate in selecting early-access partners. This could create significant advantages for approved critical-infrastructure operators, defence contractors, research institutions and strategically important companies. It could also raise concerns about transparency, competition and whether governments should influence which private companies receive early access to commercially valuable technology.

5. Digital sovereignty. The European reaction demonstrates that AI sovereignty is no longer only about data residency, cloud hosting or semiconductor manufacturing. It also concerns whether European companies can rely on continued access to advanced models whose release is governed elsewhere.

What executives should do now

Boards and executive teams should treat frontier AI as a strategic technology dependency and take several immediate steps:

  • Map model dependencies. Identify business processes, products and cybersecurity operations that depend on particular providers or model versions.
  • Prepare viable alternatives. Maintain tested fallback options involving another commercial provider, a less restricted model or a locally deployable model where appropriate.
  • Review geographic exposure. Determine how restrictions based on location, citizenship, export controls or data access could affect multinational teams.
  • Strengthen AI procurement clauses. Contracts should address service suspension, regulatory restrictions, model substitution, data portability, advance notification and transition assistance.
  • Separate critical workflows from a single model. High-impact processes should not become technically or operationally dependent on an AI capability that may be withdrawn without a normal product deprecation period.
  • Monitor government classification frameworks. Definitions such as “covered frontier model” may eventually influence availability, procurement, security testing, reporting obligations and cross-border access.

A new stage in AI governance

The most significant development is not the release of another more capable model. It is the emergence of a system in which access to advanced AI is negotiated among technology companies, cybersecurity authorities, intelligence organisations and political decision-makers.

The current US framework stops short of mandatory licensing. Nevertheless, the OpenAI and Anthropic cases show that governments already possess multiple ways to influence availability: voluntary cooperation, procurement power, national-security authorities, export controls and the selection of trusted partners.

Frontier AI is beginning to resemble other strategically sensitive technologies. Access may increasingly depend not only on price and technical requirements, but also on jurisdiction, nationality, government trust and geopolitical alignment.

For business leaders, the conclusion is clear: AI strategy must now include resilience, sovereignty and continuity planning, not merely adoption.