White House Tells OpenAI and Anthropic: Hold the Models, Britain Can Wait
The White House's Office of the National Cyber Director has asked OpenAI and Anthropic to withhold new AI models from the UK's AI Security Institute until Washington reviews them first. It quietly reverses an 18-month-old testing partnership and raises a bigger question about who gets to verify frontier AI.
The White House just told two of America's biggest AI labs to keep their newest models away from one of its closest intelligence allies. Not China. Not Russia. Britain.
That's an awkward position for an administration that spent the past year selling American AI as an export, and it's worth understanding now, because this is the first real test of whether Washington intends to treat frontier models like weapons or like software.
What Actually Happened
The request came from the Office of the National Cyber Director, the White House's top cybersecurity policy shop. According to a person familiar with the matter and a senior administration official, the ONCD asked OpenAI and Anthropic to withhold new models from the UK's AI Security Institute until US agencies get a look first. No written directive, at least not yet. Just an ask, which is how a lot of policy starts.
Here's the awkward part. In April 2024, the US and UK signed a memorandum of understanding that made their respective AI safety institutes the first pair of national bodies of their kind to formally cooperate on model testing. Britain's outfit, renamed the AI Security Institute in February 2025, had been getting pre-deployment access to frontier models as a matter of routine.
Now it isn't. Not because the models changed. Because the politics did.
That leaves the two labs in a genuinely uncomfortable spot. Give AISI early access, or keep the White House happy. There's no version where they do both without someone noticing.
The Real Calculus
Granted, there's a defensible security thesis here. Frontier models increasingly encode capabilities that look like offense, and letting a foreign government's testers probe the weights before your own agencies do is a sequencing problem, not a philosophical one. The ONCD's entire job is this kind of border control. Proponents would argue the US is simply asserting the primacy of its own review process over an ally's convenience, and to be fair, that's a coherent position.
I'm not entirely convinced it's the whole story.
AISI's track record is thin but real. It has run pre-deployment evaluations on models from Anthropic, OpenAI, and Google DeepMind, and it publishes its methodology. Shutting it out doesn't make models safer. It just means fewer people can say anything credible about them. And it hands a quiet win to every testing lab outside the US-UK circle, which is to say, everyone.
The market read is messier still. If closed frontier models get gated behind a Washington review queue, the relative appeal of open-weight alternatives goes up. So does the appeal of decentralized compute networks that no cyber director can slow down. Several of those networks trade on-chain, and their pitch has always been the same: no single jurisdiction gets to decide who runs inference. If this ask hardens into formal policy, that's a marketing gift to the entire sector, and I don't think the White House has priced it in.
The question worth asking: if the US won't share models with the UK, why would Japan, Korea, or the EU keep trusting American labs as their testing partners?
What to Watch
Three things. First, whether this stays a phone call or becomes a written rule, because informal asks are easy to walk back and formal ones aren't. Second, whether AISI responds by building out its own pre-training evaluation capacity, which would take years and serious money. Third, whether the labs comply quietly or push back in public, since both have spent the past two years arguing that independent evaluation is a safety feature rather than a liability.
History suggests allies don't stay locked out forever. They build their own version. The one to watch is whether Britain builds a test lab in London or quietly leans on tokenized compute markets in Singapore and Zug. Admittedly, I know which one moves faster.
Related Articles
Explore More
Key Terms Explained
Not controlled by any single entity, authority, or server.
A network of distributed GPU and CPU providers that offer computing power for AI training, inference, and rendering without relying on centralized cloud providers like AWS or Google Cloud.
Transactions and data recorded directly on the blockchain.