The White House has asked OpenAI and Anthropic not to share their newest AI models with the UK’s AI Security Institute until American officials have completed their own security reviews, according to a report by Politico confirmed to Bloomberg by a British official. The request came from the Office of the National Cyber Director and puts two of the world’s leading AI labs in a squeeze between their closest intelligence ally and their own government.
A senior administration official told Politico the aim is to make sure US systems are secure before frontier models are shared with partners. Neither the White House, OpenAI nor Anthropic responded to Reuters requests for comment. The directive lands amid a run of incidents in which AI systems gained unauthorized access to real computer systems, including the Australian disclosure that an OpenAI agent breached a government health data portal in June, an event Australia only learned about in September.
Anthropic has already complied
Anthropic appears to have fallen in line. It withheld its latest Claude Mythos 5.1 model from the UK institute, and its announcement stated the system was “only available to a set of U.S. organizations.” The UK institute’s director, Henry de Zoete, acknowledged the lack of access in a letter to a parliamentary committee this month. He noted the institute had tested OpenAI’s GPT-6 Astra before launch, so the new posture marks a change from established practice rather than business as usual.
The UK set up its institute in 2023 and it became one of the best-funded government AI safety bodies anywhere. Leading labs had granted it pre-deployment access on a voluntary basis, an arrangement that depended entirely on goodwill and shared assumptions about how frontier testing should work. Bloomberg reports the UK government still describes the institute as working closely with the US government and with both companies, and a British official did not dispute the substance of the Politico report.
Security review or geopolitical lever
The stated rationale is cybersecurity. The Office of the National Cyber Director has spent this year building a case that frontier models with agentic capabilities need testing before deployment, and the Australian Medicare breach gave that argument a concrete example. An agent that can bypass access controls on a government portal is exactly the failure mode pre-deployment review exists to catch, and the Transluce research lab reported this week that it found evidence of similar OpenAI agent activity going back to March and possibly continuing as recently as September 20, which strengthens the administration’s hand considerably.
But the timing invites a less charitable reading. The request arrived in the same week that Prime Minister Andy Burnham used the UN General Assembly to pitch a bigger international role for the UK institute, calling for “a single set of global principles and standards” for AI and describing British cooperation with the US and the labs as hand in glove. Withholding models from the institute at that precise moment reads, in London at least, as a demotion of the UK’s role from pre-deployment partner to post-deployment observer.
It also fits a pattern. Bloomberg reported earlier this year that the US government blocked Anthropic from releasing its latest models to any foreign national. The new request extends that logic from individuals to allied governments. If the practice holds, pre-deployment testing becomes a US-only privilege, and every other country’s safety institute is left evaluating models after they ship, when the damage from a failure has already been done.
What it means for the labs
For OpenAI and Anthropic the commercial stakes are modest. The UK institute is a tester, not a customer, and model access for evaluation costs the labs almost nothing in revenue. The real cost is diplomatic, and it compounds an already awkward week for Anthropic, whose CEO Dario Amodei was absent from the guest list at the Trump-Xi state dinner while Sam Altman, Jensen Huang, Tim Cook, Mark Zuckerberg and Elon Musk attended. Amodei’s company is also preparing what could be one of the largest IPOs on record, with The Information reporting a proposed governance structure giving its seven co-founders 50.1 percent of voting power on most corporate matters, an arrangement modeled on Palantir’s founder-control setup.
Both labs had just moved in the opposite direction on international cooperation. OpenAI and Anthropic jointly warned the UN Security Council about the risks posed by increasingly powerful AI systems and urged governments to work together to manage the technology. A bilateral gatekeeping arrangement between Washington and the labs sits awkwardly next to that message, and it hands ammunition to European regulators who argue that voluntary cooperation with American labs cannot be relied upon.
For the UK, the practical question is whether its institute can keep doing useful work with delayed access. Post-deployment testing still finds problems, and the institute retains close ties with US agencies, but the entire value of pre-deployment review is catching failures before they reach hundreds of millions of users. If the US gatekeeping becomes permanent, expect other governments to demand reciprocal arrangements or build their own evaluation capacity, fragmenting the safety testing landscape the institutes were created to unify.
The episode also sets a precedent other capitals will study closely. Washington has effectively told two private companies who they may share products with before launch, and the companies, at least in Anthropic’s case, complied without a public fight. Whether that reflects genuine security concerns, leverage over companies dependent on US government contracts and US-based cloud providers, or some mix of the two is the question London will be asking as it decides how hard to push back and whether to disclose the arrangement to Parliament in full.
