On 25 September 2026 it was reported that the US Office of the National Cyber Director had asked OpenAI and Anthropic to hold back their newest AI models from Britain's AI Security Institute until American authorities had finished testing them. Who decides whether outsiders may test a new AI model before it is released? Not the law. The company that holds the model decides, together with the government that can tell that company to wait.
01Pre-release testing of AI opens and closes by private decision, not by statute
In September the UK AISI did not receive Claude Mythos 5.1, Anthropic's newest model, before it went out. Mythos 5.1 was reported to have launched on 1 September. No rule had been rewritten in the meantime. The US Office of the National Cyber Director asked the two companies to wait, and the companies agreed.
What moved here was not the substance of evaluation but its order. The first look at a new frontier model shifted to an agency of the US Department of Commerce, and the British side was left to reach the model after launch, through the same door as any member of the public.
For anyone who has treated an outside institute's evaluation as grounds for trust, this is not a distant story. When a buyer says a model has been evaluated, whether that evaluation actually happened this time can only be established by opening the provider's report and looking. So long as an organisation cites that evaluation as its grounds, having no step for that look means leaning on grounds it has never checked.
02AISI is not a regulator and holds no legal claim to early access
American officials asked, and the companies agreed. So what remains on the side that was refused?
The mission the UK AISI states for itself in government material is to equip governments with a scientific understanding of the risks posed by advanced AI. Nowhere is it recorded that the institute has been granted statutory power to take an unreleased model from a company. The reporting does not say that either firm broke a duty to supply one. For now, handing a model over is voluntary.
Voluntary also means that refusing sets nothing in motion. No deadline was ever fixed, so nothing ran late. No penalty was ever written, so nothing was breached. What stayed open to the British side was the public door, available after launch.
03The US review came first, and the effect reaches past one British body
Where no duty to supply exists, a single request can reverse the order. This time the Department of Commerce's CAISI tested the model first.
According to the reporting, CAISI has no permanent director and a staff of a few dozen people. The UK AISI has been funded and staffed as a government testing body. One body holds the capacity; the other holds the turn. These are two different resources.
| Point of comparison | US CAISI | UK AISI |
|---|---|---|
| Standing | A Commerce Department body that tests new models first | A body that gives governments scientific understanding; no regulatory power is stated |
| Capacity | Reported to have no permanent director and a few dozen staff | Funded and staffed as a government testing institute |
| What happened in September | American testing was placed first | Did not receive Claude Mythos 5.1 |
The effect does not stop at one British institute. Longpre and colleagues argued in 2025 that in-house evaluation is not enough, and that general-purpose AI needs a route for outside researchers to report flaws along with legal safe harbours that protect the people who report them. That argument presupposes that outside researchers have no settled route to a model before it is released. When the order of first access changes, the waiting time of everyone outside that order lengthens with it.
04Because access rests on goodwill, nothing stands in the way of diplomacy stopping it
The order reversed this easily because the arrangement carries neither deadline nor penalty. So why has it stayed that way?
The practice of handing unreleased models to a government testing body began with the companies themselves. Whoever starts something can stop it. The American explanation was framed around ownership: these are American firms, and for each new frontier model this is American policy. An official at the Office of the National Cyber Director was reported to have called the two firms "American companies" before describing the position as policy.
What is given out of goodwill can therefore be stopped by diplomacy without any procedure at all. Amending a regulation takes debate and time. Changing a budget line brings in the legislature. Changing a stated position needs neither.
There is little room here for blame. The companies broke no promise, and the British institute was not excluded for any failing of its own. The arrangement was built this way from the start.
05Naming access as black-box, grey-box and white-box makes the loss countable
Stopping breached nothing. If so, how much was actually lost in September is a question someone has to count.
The vocabulary for counting already exists. In a May 2026 paper the Royal United Services Institute proposed a shared taxonomy for model access levels — black-box, grey-box and white-box — to standardise how people talk about it. Black-box access shows only outputs; grey-box adds some internal information; white-box reaches the weights. Brundage and colleagues worked along neighbouring lines, dividing confidence in audit findings into four assurance levels, with the higher levels supporting greater confidence.
Apply those words and the September loss narrows to one thing. What the UK AISI lost was not depth but timing. The pre-release moment went; the post-launch door stayed. De Zoete has written that pre-release access continues for some models. Not everything closed.
Losing the timing changes one thing above all. A danger found before launch can stop the launch. A danger found after launch has to be recovered from the hands of people already using the model. The same discovery can prevent harm before launch; after launch it can only undo as much as recovery reaches.
06Anyone relying on outside evaluation needs a step that checks it happened
The pre-release moment dropped out. Who is actually left in difficulty, then? The difficulty splits three ways.
The owner and the requesting government decide who may test
With no deadline and no penalty in the arrangement, who gets to test can change without notice.
An absence of evaluation is invisible from outside
Unless it is published, an outsider cannot tell an evaluated model from an unevaluated one.
Users receive only post-launch information
Pre-release test results carry no duty of publication, so the choice narrows to limiting use or testing the model yourself.
The first is who gets to test. That was settled not by law but by the company that owns the model and the government that could tell it to wait. So the presence of an evaluation can change next month, without notice, and no rule obliges anyone to announce that it changed.
The second is visibility. A report can record that testing took place. No report has a field for testing that did not take place. The British case surfaced because journalists wrote about it and because de Zoete sent a letter to a parliamentary committee. Absent that, what an outsider sees is "no evaluation recorded", which is not the same statement as "no evaluation happened". A reader cannot tell those two apart.
The third is the kind of information that arrives. Providers are under no obligation to publish pre-release test results. What reaches a user is the result of their own testing after launch, plus whatever the provider chose to write down. Two roads remain: narrow the use, or test it yourself.
07Unless law requires third-party pre-release access, the same halt can recur elsewhere
Users have to check for themselves. That is a heavy conclusion. Will regulation lighten the load?
Consider the most detailed rule now written. Article 55 of the EU AI Act requires providers of general-purpose AI models with systemic risk to evaluate their models under standardised protocols reflecting the state of the art, including conducting and documenting adversarial testing. What it requires is the provider's own testing, and the provider's own record. It does not require handing the model to a third party before release.
From that, no one can conclude that third-party evaluation is unnecessary. The sayable range ends at: Article 55 does not require it. Whether some future statute will make pre-release third-party access mandatory has not been established.
If the duty never arrives, what a user can do is limited, but it is not nothing.
Look for the record of evaluation
Check whether the provider's report states who tested the model and when.
Decide in advance what absence means
Write down, before the question arises, which uses are permitted and which are not when no outside evaluation is recorded.
Neither step reaches the substance of an evaluation. Both reach its presence or absence. Even so, writing down the date the check was made, along with what was permitted and what was refused that day, leaves a trail that can be followed six months later. When the order of access shifts again, as it shifted in September, the record shows which information a decision was standing on.
- In September the UK AISI did not receive Claude Mythos 5.1 before release. The halt came from a US request and a company's decision, not from any rule.
- No legal basis for AISI to demand pre-release models has been shown. With no deadline and no penalty in the arrangement, withholding a model breaks nothing.
- Article 55 of the EU AI Act requires providers to run and document their own adversarial testing, not to hand models to third parties before release. Whether third-party evaluation becomes mandatory has not been established.
Access for outside testers before release is not set by law. It is set by the company that holds the model and by the government that can tell that company to wait. What happened in Britain in September was those two parties acting.
So for anyone who leans on outside evaluation as grounds for trust, the work does not end at reading the report. It ends at checking whether the evaluation happened, and recording the date of the check along with the line drawn that day between permitted and refused uses. The substance stays out of reach. The presence, and the fact that someone looked for it, do not.
- IT Pro. OpenAI and Anthropic could withhold new AI models from UK's AI Security Institute. 25 September 2026.(US officials asked both firms not to share newly launched models until American testing was complete; Claude Mythos 5.1 did not reach the UK AISI; pre-release access continues for some models)
- BeInCrypto (via Yahoo News). White House Wants Anthropic, OpenAI to Withhold AI Models From Britain. Why the Secrecy? 25 September 2026.(The first testing body is the Commerce Department's CAISI, reported to operate without a permanent director and with a few dozen staff; a letter was sent to a parliamentary committee)
- AI Security Institute (GOV.UK). AI Security Institute — About us. Accessed 25 September 2026.(The institute's mission is to equip governments with a scientific understanding of the risks posed by advanced AI; no regulatory power or right to early access is stated)
- EU Artificial Intelligence Act. Article 55: Obligations of Providers of General-Purpose AI Models with Systemic Risk. 12 July 2024.(Providers must evaluate models under standardised protocols reflecting the state of the art, including conducting and documenting adversarial testing)
- Royal United Services Institute. Developing a Framework for Secure Third-Party Access to Frontier AI. 12 May 2026.(Proposes a shared taxonomy for model access levels — black-box, grey-box, white-box — to standardise communication)
- arXiv (Brundage et al.). Frontier AI Auditing: Toward Rigorous Third-Party Assessment of Safety and Security Practices at Leading AI Companies. 16 January 2026.(Four AI Assurance Levels, the higher of which support greater confidence in audit findings)
- arXiv (Longpre, Klyman, Appel et al.). In-House Evaluation Is Not Enough: Towards Robust Third-Party Flaw Disclosure for General-Purpose AI. 21 March 2025.(Proposes broadly scoped flaw disclosure programmes for general-purpose AI providers, with legal safe harbours protecting researchers)