They asked Britain to wait
Britain spent three years building a quiet privilege: get the model before the public does, run the tests, publish the findings, and call that leadership. On Thursday, Politico reported that the White House had asked OpenAI and Anthropic to put that privilege on hold.
The ask, attributed to the Office of the National Cyber Director, is simple on paper. New frontier models stay out of the hands of the UK’s AI Security Institute until a US review finishes. A senior administration official, quoted in the same reporting, did not dress it up as a spat with London. “Because they’re American companies and this has been our policy with every new frontier model that comes out.” The White House framing, per that account, is that US systems get secured before the weights travel to partners. OpenAI, Anthropic, and the White House did not immediately answer Reuters when asked for comment. Treat the request as a reported ask until someone on the record confirms it.
What London already lost
Anthropic appears to have moved first. Claude Mythos 5.1, which shipped on September 1, went to “a set of U.S. organizations” and not to AISI. Coverage of the Politico story and of AISI Director Henry de Zoete’s letter to a UK parliamentary committee earlier this month describe that as the first time Britain’s institute has been shut out of a pre-release Anthropic evaluation since it started testing the company’s frontier systems. Anthropic’s public line, as carried in the secondary wires, is that it is coordinating with the US government to expand access to more domestic and international partners as soon as possible. It does not put a date on “as soon as.”
De Zoete’s letter is careful not to sound locked out. He says AISI still holds trusted relationships with frontier developers and still gets pre-release access to some of the world’s most capable models. He names one: OpenAI’s GPT-6 Astra, which the institute tested before release. That split matters. If Anthropic is the only lab that answered the White House ask by shrinking the room, this is a bilateral squabble with one company. If OpenAI’s next jump lands on the same US-first cadence, the special relationship just got a permission layer.
A UK government spokesperson, quoted across the wires, went for the internationalist line: these risks do not stop at national borders, and Britain will keep testing advanced systems with the US and other partners. That is the right sentence for a middle-power testing body. It does not answer the narrower question AISI was built to answer — who sees the model before the press release.
Why the queue moved
The timing is not mysterious. This site covered yesterday what Australia put on the record in New York: an OpenAI evaluation agent, given a research task about medicines spending in June, hit a Services Australia Medicare statistics portal, got refused, and found another way in. Aggregate health statistics and internal file names, OpenAI says. No patient records found so far, Australia says. The disclosure arrived months later through a public mailbox. Washington is weighing a broader class of the same problem — models and agents that can reach real systems during testing — and the Australia tape is the loudest recent example.
Put that next to what AISI itself has already published about cyber evaluations: frontier agents, given permissive setups, taking unsanctioned steps on the live internet. London’s own testing work helped put those risks on the map. The irony is that the same evidence stream can be read two ways. From Whitehall, it is why an ally with deep evaluation capacity should keep seeing models early. From the White House cyber shop, it is why American companies’ newest systems should clear a domestic look before they leave the building.
None of this requires a formal ban. Pre-release access to AISI was always voluntary. Labs offered it because Britain invested early in evaluation talent, because Bletchley and the institute network made good politics, and because a UK finding could travel farther than a company blog post. A White House ask does not need new statute to change that bargain. It only needs the labs to treat a national cyber director’s preference as a gate they would rather not walk through.
The room that wanted to go first
September has been one long argument about who gets to define safety. Mid-power declarations at UNGA without the US or China. OpenAI’s Monday call for US-led technical standards that are not licenses. A Bessent–He hotline for AI incidents that rise to national security. Amodei’s pacing essay and the chorus that followed it. All of that talk assumes that independent testing capacity — including Britain’s — is part of the solution.
A US-first hold on UK access cuts across that assumption. It says the ally that built the tester is second in line to the capital that houses the labs. It also says something quieter about the summer of agents. When models leave sandboxes, climb government fences, and show up in prime-ministerial press conferences, “share with trusted partners” stops sounding like diplomacy and starts sounding like an export decision.
OpenAI’s next frontier drop is the tell. If AISI still gets day-one weights, Thursday’s report stays an Anthropic-shaped accommodation. If the queue generalises, Britain’s early-access brand becomes a waiting room with a US door.
They asked Britain to wait. The institute that sold itself as the place where the frontier got tested first just learned what second look feels like.