The US Department of Commerce announced on Tuesday that Google DeepMind, Microsoft, and xAI have agreed to let the government look at their frontier AI models before anyone else does. The agreements were signed with the Center for AI Standards and Innovation at NIST, which has had similar arrangements with OpenAI and Anthropic since August 2024, and they are voluntary, carry no statutory force, and confer on CAISI no power to block a release. Taken together, the five agreements are nevertheless something close to the architecture of a frontier-AI pre-market regime, drawn quietly and increasingly difficult to ignore.
CAISI has run more than forty evaluations on frontier models so far, some of them unreleased, some with safeguards stripped out at the developer’s request, some inside classified environments. The taxonomy that has emerged is narrow and specific: cybersecurity capabilities, biosecurity risks, chemical-weapons potential. Microsoft signed a parallel agreement with the United Kingdom’s AI Security Institute on the same day. Two governments, one cooperative methodology, the same set of labs.
What Mythos Did
What has CAISI doing all of this so visibly, after twenty months of doing it quietly, is a model called Mythos. Anthropic introduced it in April, described it as unusually good at finding software vulnerabilities, and decided not to release it publicly. The National Security Agency reportedly began using Mythos almost immediately to scan US government software for exactly those vulnerabilities. Anthropic restricted broader access to a small set of vetted financial and technology firms while federal agencies tested it, an arrangement the White House tried to block from expanding at the end of April. Banks and utilities, which had been politely asking for two years whether agentic AI was about to obsolete their threat models, took Mythos as their answer.
The administration, after sixteen months of telling the labs to build faster, began briefing executives at Anthropic, Google, and OpenAI on a possible pre-release review process. Mythos changed things, in the words of one observer.
What those briefings were building toward is the subject of reporting from Politico, the New York Times, the Wall Street Journal, The Information, and Axios, which collectively describe a draft executive order that would set up a working group of tech executives and government officials to design a review process modeled on the UK’s AISI. Some officials are pushing for “first access” without veto power. The White House has called all of this “speculation,” which it may be and may also not be.
One line in the Politico version is worth pausing on. According to four of the outlet’s seven anonymous sources, the draft order may prohibit AI companies from “interfering” with government uses of their models. The language is generic in form and quite specific in aim. Anthropic spent early 2026 in failed contract negotiations with the Pentagon over guardrails it refused to lift, including ones designed to prevent mass surveillance and weapons-system automation. The Pentagon then signed a classified AI deal with eight other vendors, conspicuously without Anthropic.
One Lab, Three Signals
This makes for an interesting moment at Anthropic. The lab is the company that triggered the new regime by introducing Mythos, the company that has been CAISI’s most cooperative partner since 2024 and on whose original agreement the new ones are modeled, and simultaneously the company frozen out of the Pentagon’s frontier procurement and the implicit target of the draft order’s “interfering” language. Three Washington signals, pointing different directions, all addressed to the same building in San Francisco.
Anthropic’s position, which is that frontier capabilities should be reviewed before release and that not every government use of them should be allowed, is internally coherent. Washington’s position, which is that the same review is now important and that companies should not be permitted to constrain government use, is harder to hold together without picking a public fight with the lab whose model is currently the best argument for the review existing at all.
The Open-Weights Question
There is a structural question underneath all of this that the week’s coverage has mostly stepped past. AI commentator Andrew Curran articulated it cleanly on X: a pre-release review regime that only covers closed-weight labs may not be a stable equilibrium.
Open-weight frontier models currently trail the closed labs by roughly nine months, and the gap has been narrowing. If pre-release review slows the closed labs by a few months, the gap narrows faster. Eventually an open-weight model becomes capability-competitive with a reviewed closed one, except without the review, and the regime becomes porous. The administration’s options at that point are to bring open-weight inside the gate, to ban capable open-weight imports from China, or both. The first runs against the administration’s own July 2025 AI Action Plan, which treats open-weight investment as a pillar of American AI leadership. The second only works if Beijing agrees to a parallel regime for its own open-weight releases, and Beijing will have its own price, with NVIDIA export controls the obvious thing on the table.
How much of this is in the actual draft order is unclear, and the US-China track is Curran’s extrapolation rather than anything that has been reported. But the structural problem is real, and it is the part of this story the public reporting has not yet engaged with.
Drawn Voluntarily
So the frontier-AI pre-market regime is being drawn now, in real time, without a statute behind it, by five labs and one Commerce Department office and a working group that may or may not produce an executive order. The UK is running its own track in parallel. The lab whose Mythos kicked the whole sequence into motion is at once the regime’s closest collaborator and its likely antagonist. Voluntary regimes hardening into de facto rules without legislation is a familiar pattern in AI policy by now, visible most recently in the multi-body race to define agent identity standards.
How any of this lands depends on questions the administration has not publicly answered. What gets tested. What capabilities trip a recommendation. Whether open-weight is in scope. What happens when a Chinese open-weight release matches the closed frontier. What happens the first time a developer politely declines. The CAISI agreements and the draft executive order are the visible structure. The unanswered questions are the load-bearing parts.
–
By the Control Plane Editorial Team