Notes / The List

The List

Note
Warm sandstone illustration of paths converging on a gated frontier AI system, with a ring of keys in the foreground

On June 12, Claude Fable 5 disappeared for every user. It was not a technical failure. A US government export-control directive required Anthropic to restrict access by foreign nationals. The order took effect immediately, and Anthropic had no reliable way to verify every user's nationality in real time, so it suspended access for everyone. The controls were lifted a little over two weeks later and Fable 5 returned. Its more powerful sibling, Mythos 5, did not return with it. Access was restored first to a set of US organizations working on critical-infrastructure security. (Anthropic)

At almost the same time, OpenAI released GPT-5.6 Sol, Terra, and Luna. They did not arrive in ChatGPT either. The models went first to a small group of “trusted partners,” with the list shared in advance with the US government. OpenAI said in its own announcement that this kind of government access process should not become the long-term default because it keeps the best tools away from users, developers, enterprises, and cyber defenders. It complied anyway. (OpenAI)

Two companies, two explanations. Both point to the same shift: frontier models are turning from products into access credentials.

The risks are real. The standards have not caught up.

It is easy to say that “safety is just an excuse.” But AI governance has always sat at the intersection of politics, economics, and security.

Frontier models do create real risks. In its GPT-5.6 system card, OpenAI classifies Sol, Terra, and Luna as High capability in both cybersecurity and biological and chemical risk. GPT-5.6 Sol scored 96.7% on OpenAI's internal capture-the-flag evaluation, and every model in the family crossed the company's High threshold for cybersecurity. (OpenAI Deployment Safety Hub)

The Fable 5 dispute was also about cybersecurity. It began when Amazon researchers found a way around the model's safeguards, prompting it to identify software vulnerabilities and, in one case, produce code showing how one could be exploited. Anthropic responded with a targeted classifier that blocks this class of request and routes it to an older model. (Anthropic)

The risk exists. But the existence of risk does not mean the standard for restricting access is clear.

Anthropic's counterargument was that Fable 5 offered no unique offensive capability. Similar behavior appeared in Opus 4.8, GPT-5.5, and Kimi K2.7. So the question is not simply, “Does Fable 5 pose a risk?” It is this: if the capability that triggered the restriction was not unique to Fable 5, why was Fable 5 the model taken offline? (Anthropic)

A safety judgment can be reasonable while the standard behind the decision remains opaque. Those two things are not contradictory.

Access is becoming a list

Fable 5 and GPT-5.6 were not merely “restricted.” The more important change is that access itself is being organized as a list.

On Anthropic's side, the government sought to block foreign nationals. The company could not verify nationality in real time, so users everywhere lost access. Once the controls were lifted, Fable 5 returned globally while Mythos 5 returned only to approved US organizations. At that point, the decision was no longer only about model safety. Nationality, institution type, and use case all helped determine who received the key. (Anthropic)

OpenAI's case is even more explicit. GPT-5.6 was not broadly released; it entered a list that outsiders cannot inspect. OpenAI says the arrangement is temporary and that it is working with the government toward a more transparent process. But in this release, access to a frontier model was not an open queue. (OpenAI)

Frontier AI governance does not first arrive as an abstract principle, an industry pledge, or a declaration from a global summit. It arrives as a concrete question: who gets the key?

Safety cannot substitute for rules

Government involvement in frontier-model releases is not surprising. The stronger these models become, the less likely governments are to leave their deployment entirely to private companies. Cybersecurity, biology, chemistry, autonomous execution: when powerful models are misused in these domains, the consequences do not stay inside a content policy. They enter the physical world.

So the question has never been whether there should be a gate. Frontier AI cannot be released without thresholds.

The questions are who guards the gate, what rules they follow, and whether the gatekeepers themselves are constrained.

Today, risk assessment, access lists, and release timing are concentrated in a handful of companies and governments. Companies invoke safety evaluations. Governments invoke national security. Everyone else sees only the outcome: suspended, restored, limited preview, trusted partners, critical-infrastructure organizations.

The mechanism does not have to be malicious to become a black box.

If a system can decide who gets access and who does not, but cannot explain its triggers, scope, review schedule, or appeals process, then it is no longer dealing with safety alone. It is also exercising power.

Safety can be a real problem. It cannot become a universal pass.

Gatekeeping can reinforce winner-takes-all markets

AI governance has an uncomfortable side effect: rather than weakening winner-takes-all dynamics, it may entrench them.

The more safety matters, the more companies need red teams, compliance staff, lawyers, government relationships, and infrastructure. The more cautious deployment becomes, the more likely we are to see trusted-partner programs, institutional certification, government review, and staged access. None of this is fatal to the largest companies. OpenAI, Anthropic, Google, and Meta have the safety teams, legal resources, and government relationships required to enter early evaluations and sit at closed-door tables.

The people most likely to remain outside are smaller companies, open-source communities, independent developers, ordinary researchers, and users in countries beyond the core markets.

Regulation raises the cost of entry in the name of reducing risk. In the name of public safety, it may also lock in the capability advantage of a few incumbents.

This is not an argument against regulation. Frontier AI must be governed. But regulation is not inherently the same as public interest. Powerful actors can absorb it and turn it into a new market barrier. Without external constraints, the language of safety can slide easily into governance by a capability club.

The OpenAI irony

The most revealing part is that OpenAI already understands the problem.

When Sam Altman announced GPT-5.6, he called the limited preview the “bad news”: OpenAI had planned for wider access, but the US government asked for a restricted preview. He also said that staged deployment had legitimate benefits and matched OpenAI's iterative approach, but that this was not the company's preferred process. (Sam Altman)

OpenAI's official announcement was more direct: it does not believe this kind of government access process should become the long-term default. Its reason is clear. The process keeps the best tools away from the people who need them — developers, enterprises, cyber defenders, and global partners. (OpenAI)

That statement is worth sitting with.

OpenAI is not rejecting safety governance. It is objecting to a system led by government, organized around a list, and operating before its standards have been made clear. Yet it still had to release GPT-5.6 through that system.

The irony is not that OpenAI contradicted itself. It is that frontier-model companies have entered a new position: they may dislike the logic of the gate, but they can no longer easily route around it.

That is also why companies cannot solve the problem alone. They will naturally argue for rules that favor their own position, balancing safety, market incentives, and government demands. It is unrealistic to place the entire public interest in corporate self-regulation.

Do not wait for a world government

Some people will point to “global AI governance” as the answer. It sounds correct. Its practical force is limited.

Frontier AI moves too quickly, its capabilities are too concentrated, its commercial stakes are too high, and its connection to national security is too deep. The actors that control the models, compute, and release schedules are unlikely to hand decisive authority to an external multilateral body. International institutions can provide forums, principles, and soft constraints. They are unlikely to become the real judge.

That is not pessimism. It is recognition.

But rejecting the fantasy of a world government does not mean accepting an invisible list.

A more realistic goal is to constrain the gatekeeping mechanism itself. What is the basis for a restriction? Which capability triggers it? Does it apply by country, nationality, institution type, or specific use case? How long does it last? When is it reviewed? Is there an independent evaluation? Where is the appeals process? Will public-interest research retain a path to access?

These questions are not grand. They are usable.

They do not require a world government. They require the people handing out the keys to explain where those keys came from, who received them, and why.

Frontier models will no longer be available to everyone by default. That is close to an established fact.

The stronger the capability, the more necessary the boundary. The greater the risk, the less plausible indiscriminate access becomes. The real question is not how to abolish the threshold. It is how to keep the threshold from becoming a black box.

Access itself is a competitive advantage. Whoever receives a powerful model first can build applications earlier, train teams sooner, accumulate data faster, and establish market position before everyone else. When frontier AI becomes an access credential, the list is no longer just a safety measure. It becomes part of the economic order.

Fable 5's return does not resolve the issue. GPT-5.6's limited preview is not an ordinary product rollout. Together, these events show that frontier AI has entered the age of handing out keys.

The safety is real.

So is the list.

Mature AI governance does not mean refusing to hand out keys. It means that the people who hand them out must explain the rules, disclose who has access, and submit their decisions to scrutiny.