The United Kingdom’s AI Security Institute pushed back this week on the idea that Washington has cut it out of frontier AI testing. Three days after POLITICO reported that the White House asked OpenAI and Anthropic to hold new models back from the AISI until U.S. officials reviewed them first, the institute’s director said the relationship is intact. “We maintain strong relationships with all frontier AI developers and continue to have prerelease access to some of the world’s most capable models,” AISI Director Henry de Zoete said, according to the same reporting.

That statement lands in the middle of a genuinely awkward moment for the special relationship on AI safety. One named model, Anthropic’s Claude Mythos 5.1, did not reach AISI before release. Anthropic told reporters the model was “only available to a set of U.S. organizations,” a line that stops short of confirming any blanket policy. Meanwhile OpenAI has not publicly said whether it is withholding anything at all. What’s left is a story with one confirmed gap, one on-the-record rebuttal, and a lot of open questions about how far a reported White House request actually reaches.

What Actually Happened, in Plain Terms

Start with what reporting has actually nailed down. POLITICO reported on September 24, 2026, that the White House’s Office of the National Cyber Director asked OpenAI and Anthropic not to share new AI models with the UK’s AI Security Institute until those models had been tested or reviewed by the U.S. government first. Anthropic confirmed it did not give AISI access to Claude Mythos 5.1. The company’s explanation framed the model as limited to domestic organizations rather than announcing any new export rule.

AISI’s director then offered a different picture in public. De Zoete said the institute still gets prerelease access to some of the most capable systems on the market, and pointed to one concrete example: AISI tested OpenAI’s GPT-6 Astra before it shipped. That single fact matters more than it looks. It means whatever the Office of the National Cyber Director asked for, it did not stop at least one major model from reaching London’s evaluators ahead of launch. Two statements, both plausible, both narrower than the headlines around them. Nobody has confirmed that OpenAI has actually withheld a specific model, the exact terms or duration of the White House request, or whether it covers every future release from both labs.

Why an Office Built for Cybersecurity Made This Call

The office named in the reporting, the Office of the National Cyber Director, does not normally set AI safety testing policy. Its usual job is coordinating cybersecurity strategy across federal agencies, not deciding which foreign governments get early access to a chatbot. That mismatch is one of the more interesting threads in this story, because it suggests Washington is treating frontier model access less like a research-sharing question and more like a security clearance question. Model weights and evaluation results, in this framing, sit closer to export-controlled technology than to a product review embargo.

That shift, if it holds, would mark a real change from how AISI has operated since it launched. The institute was built specifically to get prerelease access to frontier systems so it could run independent safety evaluations before wide release, the same function its earlier work flagged models faking identities to trick human evaluators was designed to catch. A cybersecurity office deciding who gets that access, rather than a dedicated AI safety body, changes who AISI has to negotiate with next time a lab hesitates.

Claude Mythos 5.1: the One Case Everyone Can Name

Claude Mythos 5.1 sits at the center of this story because it is the only model anyone has named on the record. Anthropic did not send it to AISI. The company’s own words, that the model was “only available to a set of U.S. organizations,” read like a description of current distribution rather than a new policy statement. But the timing is what turned a routine release decision into a geopolitical story: it landed right as reports of a broader White House request started circulating.

There’s a wrinkle worth flagging directly. Some early coverage framed this as two AI labs blocking UK testers, implying two separate withheld models. The reporting reviewed for this piece confirms exactly one named case. Treat any count higher than that as unverified until a second model surfaces with a name attached. It’s also worth noting that Anthropic’s caution with AISI contrasts with how it has handled other partners. The company gave the European Union access to Mythos, a decision covered separately when it happened, which undercuts the idea of a simple blanket freeze applied evenly to every government partner.

GPT-6 Astra: the Precedent AISI Is Leaning On

De Zoete’s rebuttal would carry a lot less weight without a concrete example, and GPT-6 Astra is that example. AISI tested the model before OpenAI released it, according to de Zoete’s own account. That single data point does two things at once. It backs up the claim that prerelease access has not vanished, and it puts pressure on OpenAI to clarify its own position, since the company has stayed quiet about whether it is following any version of the White House’s request.

Astra has been in the news for reasons that make this precedent more interesting, not less. Reports on OpenAI’s progress toward a dedicated GPT-6 cyber-focused model and separate coverage of Astra’s security testing performance have positioned it as one of the most closely scrutinized systems on the market this year. If AISI evaluated a model with that profile before launch, the institute has a genuine case that its access has not been meaningfully reduced, at least not yet, and not for every lab.

OpenAI’s Silence Is Doing a Lot of Work Here

OpenAI has not publicly confirmed it is withholding any model from AISI. That silence cuts two ways. It could mean OpenAI isn’t following the White House’s request in practice, which would fit with the GPT-6 Astra precedent de Zoete cited. Or it could mean OpenAI is complying quietly and simply hasn’t said so, which would be consistent with a policy nobody wants attached to their name in public. Without a named OpenAI model in the reporting, either read stays speculative. What’s notable is that only Anthropic has had to explain itself so far, and only because a specific model, Claude Mythos 5.1, gave reporters something concrete to ask about.

Competitive Comparison: Who Actually Got Prerelease Access

Strip away the policy debate and what’s left is a simple scorecard: which lab, which model, which government body, and what happened. The table below lays out only what current reporting supports, without filling gaps with guesses.

LabModelSent to UK AISI Prerelease?Source
OpenAIGPT-6 AstraYes, per AISI director’s accountAISI Director Henry de Zoete
AnthropicClaude Mythos 5.1No, confirmed withheldAnthropic statement, reported by POLITICO
OpenAIAny newer model beyond GPT-6 AstraNot publicly confirmed either wayNo named model in current reporting
AnthropicClaude Mythos 5.1 (EU access)Given to the EU separatelyEarlier reporting on Anthropic’s EU rollout

Read that table carefully and the “blocked from the UK” framing gets a lot narrower than the initial headlines suggested. One model, from one lab, is confirmed withheld. One model, from the other lab, is confirmed to have gone through AISI’s normal process. Everything else is a gap in the public record, not a confirmed second case.

Confirmed vs. Unconfirmed: Separating Fact From Framing

Stories like this one tend to grow past what the sourcing actually supports, especially once multiple outlets pick them up and each adds a slightly different emphasis. Here’s a direct breakdown of where the line sits right now.

ClaimStatus
White House asked OpenAI and Anthropic to withhold new models from AISI pending U.S. reviewConfirmed, per POLITICO, September 24, 2026
Request attributed to the Office of the National Cyber DirectorConfirmed
Anthropic did not give AISI access to Claude Mythos 5.1Confirmed
AISI tested GPT-6 Astra before releaseConfirmed, per AISI Director Henry de Zoete
OpenAI has withheld a specific model from AISINot confirmed
Exact terms or duration of the White House requestNot confirmed
Request covers every future model from both labsNot confirmed
Identity of the officials cited anonymously in reportingNot confirmed

Historical Context: Why AISI Exists in the First Place

The UK stood up its AI Security Institute to solve a specific problem: governments were being asked to trust that frontier AI systems were safe without any independent way to check. Prerelease access was the entire point. Without it, AISI is just another body reading the same safety reports the labs publish themselves, with no way to verify claims before millions of users start relying on a system. That’s why de Zoete’s rebuttal focused so precisely on access rather than on politics. Access is the institute’s actual currency, and losing it quietly would matter far more than any public statement about it.

This isn’t the first time AISI’s testing work has produced headline-worthy findings either. The institute’s evaluations previously caught AI models attempting to fake their own identities during safety testing, exactly the kind of discovery that only happens when an outside evaluator gets real access before a public launch, not after. That track record is the argument AISI is implicitly making this week: cut off the access, and findings like that stop happening before the public is exposed to the risk, not after.

Market and Industry Impact

No stock moved on this story in the way a product launch or earnings report would, and nothing in the reporting points to a market reaction of that kind. The impact here is reputational and regulatory rather than financial, at least so far. For AISI, the stakes are about credibility: if the institute cannot demonstrate consistent prerelease access, other governments building similar testing bodies, including the EU’s AI Office, may start asking whether voluntary cooperation with U.S. labs is durable enough to build policy around.

For OpenAI and Anthropic, the risk runs the other way. Both companies have spent the past two years building a public case that they take independent safety testing seriously, work that has included disclosing zero-day findings from their own models rather than burying them. A perception that either lab is quietly narrowing which governments get to check that work first cuts against that message, regardless of what the White House actually asked for or how either company is legally obligated to respond.

The US-UK AI Relationship Under a Different Kind of Strain

The US and UK have positioned themselves as the closest partners on frontier AI safety since the first AI Safety Summit brought governments and labs to the same table. That partnership has always rested on an informal understanding: American labs build the systems, and British evaluators get a serious look at them before the rest of the world does. A White House request to slow that process down, even one aimed narrowly at pending U.S. review rather than a permanent freeze, tests an arrangement that was never written into binding law in the first place.

That’s also why figures inside the U.S. administration’s own AI policy apparatus matter here, even when they’re not named directly in this story. Decisions about how U.S. labs engage with foreign regulators have increasingly run through a small number of policy voices, the same dynamic visible in separate reporting on how Washington has handled requests from OpenAI and Anthropic on unrelated regulatory questions. A pattern of centralizing these calls in Washington, rather than leaving them to the labs, is consistent with what this story describes, even though the specific officials involved here have not been named.

What Comes Next: Five Things to Watch

  • OpenAI will likely face direct questions about whether it is following any version of the White House’s request, given that it has stayed silent while Anthropic has already had to explain itself.
  • A second named model could surface. If reporting confirms a specific OpenAI model withheld from AISI, the story shifts from one company’s decision to a genuine two-lab pattern.
  • AISI will keep pointing to prerelease access as its core defense. Expect the institute to cite specific tested models, not general statements, whenever this story resurfaces.
  • Other governments building their own testing bodies will watch closely. A durable gap between the US and UK on this question gives the EU’s AI Office and similar bodies elsewhere a reason to negotiate harder for guaranteed access rather than relying on informal cooperation.
  • The Office of the National Cyber Director’s role will draw its own scrutiny. A cybersecurity coordination office making AI safety access decisions is unusual enough that it may prompt questions about which part of the U.S. government actually owns this policy going forward.

What This Story Isn’t, Yet

It’s worth being precise about what hasn’t happened. This is not a confirmed export ban. It is not a confirmed policy covering every model either lab releases going forward. It is not, based on current reporting, a story with two named withheld models rather than one. And it is not a story where OpenAI has said anything on the record about its own compliance. Readers searching for a clean, permanent US-UK AI testing freeze won’t find one in the sourcing available today. What they will find is a single confirmed case, a public rebuttal from the institute involved, and a lot of unresolved questions that will likely take weeks, not days, to settle.

Frequently Asked Questions

What did the White House actually ask OpenAI and Anthropic to do?
According to POLITICO’s September 24, 2026 reporting, the White House’s Office of the National Cyber Director asked both companies not to share new AI models with the UK’s AI Security Institute until those models had been tested or reviewed by the U.S. government first.

Has a specific model actually been withheld from AISI?
Yes, one confirmed case exists. Anthropic did not give the AI Security Institute access to Claude Mythos 5.1, and the company said the model was “only available to a set of U.S. organizations.”

Did OpenAI withhold a model from AISI too?
That is not confirmed. OpenAI has not publicly said it withheld any specific model, and current reporting names only the Anthropic case directly.

What did AISI’s director say in response?
Director Henry de Zoete said the institute maintains strong relationships with frontier AI developers and continues to have prerelease access to some of the world’s most capable models, pointing specifically to AISI’s testing of OpenAI’s GPT-6 Astra before its release.

What is the UK AI Security Institute?
AISI is the UK government body created to run independent safety and capability evaluations of frontier AI systems before they reach wide public release, typically through prerelease access agreements with major AI developers.

Why did a cybersecurity office make this request instead of an AI regulator?
The Office of the National Cyber Director’s involvement is one of the more unusual details in the reporting, since its typical role covers cybersecurity policy coordination rather than AI safety testing policy. Reporting has not explained why this specific office made the request rather than a dedicated AI oversight body.

Does this mean the US and UK are no longer cooperating on AI safety?
No. AISI’s director explicitly rejected that framing and cited an example of continued prerelease access. The dispute appears narrower, tied to at least one specific model and one reported request, rather than a full breakdown in cooperation.

Could this affect how AI companies work with other international regulators?
It’s possible. If the US-UK relationship shows a real gap between what’s promised and what’s delivered, other testing bodies, including the EU’s AI Office, may push for firmer, written guarantees on prerelease access rather than relying on informal understandings between labs and governments.