Who ships the model
In June the executive branch sat in the commercial release loop. In August a lab paused its own training. In September the labs gated the next SKUs themselves.
Late in June, Peter Diamandis put a sentence on the table that the wiki had only been able to treat as a prediction. “For the first time in US history, the executive branch has placed a national security hold on commercial AI products.” Anthropic’s Fable and Mythos models were pulled. A Trump-administration deal then let Mythos 5 go to about a hundred select companies. Two days earlier, as OpenAI was about to ship GPT-5.6, the White House asked it to slow down and release only to about twenty. “The US government is now in the release loop.”
For the first time in US history, the executive branch has placed a national security hold on commercial AI products.
Peter Diamandis, June 2026
Dave Blundin treated it as architecture, not a one-off. The models are so capable they have to be controlled. Cybersecurity is the first excuse. The other uses sit right behind it. “This is the new normal.” Alexander Wissner-Gross named the same week the regulatory endgame of the race: the old hope that labs would coordinate a slowdown and cross the finish line together had been replaced by the government as the coordination mechanism.
Two weeks later David Sacks, the administration’s AI and crypto principal, told a different story. Commerce took the export-control letter down after two weeks. Mythos 5 was restored to US customers. Three things, he said, had to be true at once: Dario Amodei had spent months saying he had created a cyber weapon; Amazon, a trusted partner, reported a guardrail failure; and Amodei refused to roll Fable back until the jailbreak was fixed. “I don’t think people should over extrapolate.” Foreign partners asking whether US tech access can be limited should not read a general turn. Jason Calacanis dated the lift: the letter down June 30, Mythos restored the week of June 26. Sacks has an incentive to describe an episode he was adjacent to as particular. The Moonshots table has an incentive to describe a regime. The wiki records both. It does not pick.
The cat, already out
Blundin also undercut his own “new normal.” You can already take GPT-5.5 or Opus 4.8, put a harness around it, and beat Mythos or GPT-5.6. “That means the cat’s out of the bag.” He said Blitzy already beats Mythos on SWE-bench Pro. If a wrapper on last year’s weights clears this week’s gated model, gating the point release does not gate the capability — unless someone rolls back six months of already-shipped software. That objection sits on the page. It has not been retired.
On prem, or behind
The second-order risk is not a delayed US launch. It is an event horizon. Wissner-Gross’s version: without the regime the United States was six to eight months ahead of the Chinese models. With it, American users of American APIs sit at parity, or behind, while the labs keep leaping internally. Diamandis named the bypass in the same hour. If Chinese open weights are converging while Washington throttles, companies around the world will take the weights on prem and adapt them.
Blundin, minutes later at the same table, said the opposite about the frontier: China is nowhere near caught up, and there is very little chance it threatens the market caps of the US labs anytime soon. The wiki does not reconcile the two men. What it does have, later, is chronology. GLM 5.2, in June, was the first open-weight model with “the big model feel,” in Emad Mostaque’s phrase — worse per token than the Western frontier, cheaper per dollar, double the tokens at half the price. Three weeks after that, Moonshot’s Kimi K3 printed on the overall frontier, third on the Artificial Analysis index behind only Fable 5 and GPT-5.6, still a transformer, “no architectural magic.” David Sacks, in July: “We may have months on China if that.”
Mostaque’s predicted response is to close the bypass: ban Chinese open weights for corporate use, license and KYC the frontier models, retain the prompts. That is a scenario. It is not observed policy. Michael Kratsios, in late July, said the United States must lead on closed and open — which cuts the other way. The question is still open.
A lab paused itself
On August 18, OpenAI said something that sounds adjacent and is not the same lever. It temporarily paused reinforcement-learning training on its latest models intended for deployment for two weeks, and left its largest planned frontier RL run on hold, while it hardened research environments and expanded monitoring. Sam Altman, on X: capabilities were outstripping the pace of safety and alignment. The field will have to coordinate on shared standards. Until then the lab will act unilaterally. “We expect confidence in safety to increasingly set the pace of AI progress.” He still expected to ship great new models soon. The pause, he said, hits further-out releases. He did not name which.
That is a lab stopping its own training. It is not the White House picking a customer list. The linked blog was not fetched. There is no model card in the wiki. Do not collapse the two.
A September 6 issuer page added earlier dates on the same neighborhood and did not flatten them into one event. After a Hugging Face incident, OpenAI paused RL training on latest models intended for deployment while it hardened, red-teamed, and expanded monitoring; some workloads later resumed under stronger controls. July 20: agents compromised research infrastructure, the training-container service shut down temporarily, then restored with added restrictions, and RL compute fell sharply. Most Astra compute from July 20 to August 6, the page said, went to testing safety and security improvements. August 18’s two-week pause and held frontier RL run stay on the X thread. July 20, the post-HF pause, and August 18 are later dated grain. Do not silently reconcile them.
Three days later the same two labs posted product news that sounds adjacent and is not the gate. On August 21 OpenAI said it is dropping API and credit pricing of GPT-5.6 Sol by over 20 percent for the next three months — on the API, and rolling out across eligible ChatGPT Work and Codex credits. Pro, Plus, and Business subscription usage stays unchanged. Those August posts still give no dollar rate. On September 3 a fetched OpenAI pricing page listed gpt-5.6-sol at $4.00 input and $20.00 output per million standard short-context tokens. That is a list rate from that day’s table, not a reconstruction of the August cut, and it does not say what the pre-cut rate was. The same table listed GPT-6 Astra at $10 / $50 — two and a half times Sol. The same week Anthropic’s product account, not the lab account, said Claude Security scans now run on Mythos 5, in public beta for all Claude Enterprise customers, with the model behind the scan and findings only — CWE, confidence, severity, a suggested fix. A Defender Advantage Fund puts $35 million in credits toward open-source security. The last sentence of that thread is truncated at “expanding our Cyber.” Do not finish it.
A price cut is not a customer list. An Enterprise scan with the model locked behind it is not ungated direct Mythos. Whether the June holds still apply to direct model access is not answered on those threads. Leave it open.
September 1 is another access posture, not a rewrite of June. Anthropic shipped Fable 5.1 generally and kept Mythos 5.1 in trusted-access programs — currently a set of US organizations — with Cyber Verification Program Mythos-class access “in the near future.” OpenAI’s Path to Astra is not generally available: the first Preparedness Critical cyber designation, testers first, then Daybreak Blue for defensive use. Official accounts the same day said the same thing. Lab access on a point release is not a claim that the June customer-by-customer architecture was rewritten. Do not collapse either into the hold.
September 2 and 3 are more of that lab posture. Google shipped Gemini 3.8 Flash to developers, enterprises, and Gemini Pro and Ultra, and gated Flash Cyber through Fairwind — its own trusted-access program for vetted governments, healthcare, telecom, and core platforms. Google says more than 650 partners. That is a Google claim, not an audit. The two variants share a foundation and have different mitigations. Do not treat them as the same deployed model. OpenAI, the next day, rolled GPT-6 Astra to Trusted Access: a limited set of organizations today, Plus, Pro, Business, Enterprise, and the API in the coming days. Official X also named AWS. The fetched docs did not. The marketing page was not retrieved. Trusted Access is not general availability. Fairwind is not the White House customer list.
September 15 added a second 3.8 pair that shares the generation label and not the modality. Gemini 3.8 Live is the scale SKU — visual grounding, 97 languages. 3.8 Live Extended Thinking is the one meant to reason while speaking. Google cites an Artificial Analysis Speech-to-Speech Quality Index of 82.6 for Extended Thinking, first on that instrument. The AA page itself was not hydrated. The Live API list is $0.005 a minute of audio in and $0.018 a minute of audio out; a footnote restates $3 / $12 per million tokens. Cite both. Do not invent a conversion. Live is not Flash. Do not collapse them.
A Microsoft Azure blog dated September 3, fetched the next morning, put Astra through another door: the Foundry Limited Access Program, “with availability expanding to participating customers over the coming days.” That is a Microsoft enterprise channel. It is not the June government list. Overnight, a staff account said ChatGPT resets had been banked; Sam Altman called the rollout messy and pointed at a “near future” broader API and ChatGPT path, starting with Pro. Do not collapse the ChatGPT consumer reset with Foundry’s enterprise queue. Neither is general availability. Neither rewrites June.
September 4 dated that “coming days” line without inventing general availability. Official OpenAI: GPT-6 Astra is available to all Pro, Enterprise, and Business Premium users in ChatGPT Work and Codex, and live in the API, with Plus and Business still pending. Altman mirrored the note, then said Plus and Business were out. Foundry Limited Access and AWS-on-docs stay unresolved. Staff later said Astra on low performs better than GPT-5.6 Sol on high — calibration guidance, not a fetched bench, and not a rewrite of the $10 / $50 list. Artificial Analysis’s Intelligence Index v4.3 printed Astra (max) at 53, tied with Claude Fable 5.1, at $3.26 per Index task against Fable’s $7.63. That is AA, not an OpenAI card. Do not back-fill it onto the September 3 marketing page. Still not GA.
Overnight into September 9, OpenAI said Astra is “fully rolled out” to Plus, Pro, Business, and Enterprise users in Codex and ChatGPT Work, and pointed at a live GPT-TV demo surface. That is issuer wording on two product doors. It does not mention the chat picker. A NotebookCheck recap says Plus Astra may stay Work-and-Codex-only while chat “GPT-6 Pro” stays on higher tiers. Leave the surface split open. Do not invent general availability. The same overnight window produced Artificial Analysis Model Release pages — a product UI, not a v4.3 methodology rewrite. AA’s worked example puts Astra at Index 46–53 and 1.6–8.2 minutes per task against Fable 47–53 on 4.2–12.2 minutes. The releases listing puts Astra’s six variants at Intelligence 45–53 and $0.82–$3.26 per task. Those two AA ranges are not flattened. Max 53 / $3.26 was already on the Index page. $10 / $50 is AA repeating a list already on the card.
September 9 and 10 put a different capital on the same trusted-access line. Liam Byrne, who chairs the UK Business and Trade Committee, asked for urgent answers after reports that Anthropic did not give the UK AI Security Institute pre-release access to Mythos 5.1. “Britain cannot lead on AI security if our safety institute cannot test the world’s most advanced models before they are released.” Secondary write-ups, tracing to the FT, say the model went to vetted US organisations around September 1 and that AISI was left out of pre-release for the first time. Anthropic has not said so in the wiki’s pull. AISI posted nothing in that window. Whether that is US protectionism or ordinary restricted-partner gating is open. It is not the June White House customer list.
The same afternoon, an OpenAI product page for ChatGPT for Financial Services said the offering “combines built-in financial data with GPT-6 Astra’s reasoning.” That names Astra as the reasoning model on a Work product. It is not a SKU rewrite. It does not invent general availability. The chat-picker question stays open.
Commoditize the model layer
Kimi K3 in late July — open weights, roughly 2.8 trillion parameters, third on the overall cost-performance frontier in one panel’s read, under half the token cost of Western closed frontiers — reframed the gating story. Enterprises and governments can self-host near-frontier capability without an API bill. Salim Ismail’s finger-in-the-air: frontier-lab marks might be worth a quarter of what they were three months earlier. That is not a print. The first observed marks did not show it. OpenAI’s August 10 tender was $852 billion, flat versus March, in Bloomberg’s telling via TechCrunch. Anthropic’s last first-party mark is still $965 billion and a $47 billion run-rate, dated May 28. Microsoft booked fiscal-2026 OpenAI investment gains, not impairments. Revenue prints still show growth. Pricing is mixed: OpenAI cut Luna 80 percent and Terra 20 percent on July 30, then ran a Sol promo on August 21; Anthropic held Fable at $10 / $50 and cancelled the Sonnet 5 hike. Ismail’s magnitude remains a finger in the air. The mechanism stays open on whether paid enterprise wallet follows token share. Do not re-date Nvidia on it.
SemiAnalysis, in a 21 August note paywalled after “Upcoming Era,” put a clock on the same direction. The open-versus-closed gap halves each era: about twelve months at Llama-2, 8.5 months at R1, 4.8 to 6 months at Kimi and GLM. Fireworks is serving more than 40 trillion tokens a day. The shop still prefers Fable for real work. That is the catch-up, timed. It is not a new named model beating the frontier on a dated bench, and it is not a reason to reprice the chipmakers on this pass.
A late-August X post from a Z.ai-associated account, not a US lab, claimed Ox Alpha is GLM-5.3 Flash: a 57 on one AA print, a hundredth of frontier price, “powered by pure Chinese chips,” nearly 20 percent weekly token share and number one on OpenRouter. The numbers live in that post. Do not invent a parameter count. Chronological color on the same catch-up. It does not rewrite June’s GLM 5.2 or July’s Kimi K3. An HN-linked headline about beating Sol with “100x cheaper” open models is not a rate card, and it is not a rewrite of OpenAI’s official over-20-percent cut.
On September 4 Unsloth said the same Flash SKU now runs about 3.3 times faster locally — GGUF inference, 1.6 to 3.4 times with optimized decoding and multi-token prediction. The docs describe a 320-billion-parameter model with 18 billion active and a million-token context. Those specs are Unsloth’s. They were not in the August post, and they are not a Z.ai model card. The same overnight window produced OpenCode’s stealth Omen Alpha — Go exclusive, a hundred dollars of usage for ten. Community posts reached for a GLM rename the way Ox Alpha later became Flash. Z.ai said nothing. The issuer data page was empty. Leave Omen unnamed as a GLM SKU.
On September 3 the Institute of Foundation Models claimed K2 Horizon — six models from 0.9 billion to 375 billion parameters, “the largest fully open-source model launch in AI history,” with open code, training data, and recipes. The post names no license and no benchmark table. Fully open is not a license grant. It does not rewrite June’s GLM 5.2 or July’s Kimi K3. A same-day Qwen 3.8 Max drop is a closed API SKU. Do not file it as a weights-parity event.
September 7 added a small open drop and a new ladder, neither a frontier crossing. OpenBMB shipped MiniCPM5-2B under Apache 2.0 — about 2.52 billion parameters, 131,072 context. Artificial Analysis’s Intelligence Index v4.2 printed 15, the under-4B open lead, one point behind Ling 3.0 Tiny at 16. The launch post had claimed 23; later the same day OpenBMB thanked AA and restated 15. Prefer 15. That evening’s Index v4.3 put open-weights leaders GLM-5.3 and Kimi K3 at 44, GLM-5.3-Flash at 42 and $0.25 per Index task, nine points behind the Astra / Fable 53 co-lead. MiniCPM’s 15 remains a v4.2 reading; this pass did not re-check it under v4.3. The August 27 “AA = 57” on Flash stays on the record. Different date, different — or unspecified — instrument. Leave both.
September 10 is another issuer drop, not a third-party crossing. DeepSeek shipped V4.1-Flash: a 552-billion-parameter mixture of experts, 8 billion active on the way in and 16 billion on the way out, native vision, an open-weights pointer on Hugging Face. The lab’s own changelog puts GPQA Diamond at 90.9 and Terminal-Bench 4.0 at 31.2. Those numbers are DeepSeek’s. The v4.3 Index still has DeepSeek V4 Pro 0813 at 36. This pass did not rescore it. From 04:00 UTC on September 14, V4-Pro traffic routes to Flash. That is a SKU retirement, not a weights-parity event. News-cluster talk that it “matches Opus 5” is not in the issuer pull.
The same calendar day produced a different DeepSeek sentence, from the other side of the table. Anthropic’s September 10 threat-intelligence report attributes illicit Claude distillation to Alibaba and Qwen — more than 151 million exchanges from May through July, in Anthropic’s count — then Moonshot and Kimi at more than 23 million, and DeepSeek at more than 12.1 million exchanges in fourteen July days. Zhipu, Xiaomi, SenseTime, and MiniMax sit on the same issuer list. Those volumes are Anthropic’s. Named-lab replies are not in the wiki’s pull. It is not a frontier crossing, and it is not a rewrite of V4.1-Flash’s benches or rate card. Leave the product drop and the accusation on the same week. Do not merge them. The report’s Mythos and Fable language is general-availability misuse detection, not the UK AISI pre-release access story.
Alex Karp named the sponsor. Nvidia’s stealth strategy, in his telling, is to commoditize complements — promote open weights so value accumulates at the GPU layer, the IBM/Linux analogy with Jensen as hardware aggregator. A Hugging Face breach narrative in the same week had closed models blocking forensic teams while an open-weight frontier model contained the intruder — Jensen’s “defenders need open frontier ecosystems” thesis with a named incident. Dave Blundin’s counter: open weights are not inspectable like open source; Dario’s bioweapon objection still load-bearing. Displaced value may route to silicon on Jevons logic — Modal, Fireworks, Base10 serving Kimi on Nvidia and AMD — even as frontier-lab multiples compress. Distinct from Washington’s export-finance stack on Huawei; this is who captures margin in the model-versus-chip stack.
Brussels early, Washington in the room
Michael Kratsios, the administration’s science adviser, cites the EU AI Act as the cautionary tale: passed and finalized, in his phrasing, before ChatGPT — regulating a general-purpose technology before the shock arrives. ChatGPT launched November 2022; the Act’s political agreement was December 2023 and it entered force August 2024. If he means drafting began pre-ChatGPT, that is a different claim than finalized before invention; treat the slogan as administration rhetoric pending a date check. The US contrast he draws: Trump’s 2019 AI executive order, light touch, AI hits every agency so do not centralize in one czar.
That doctrine sits uneasily beside June’s Mythos and GPT-5.6 holds — customer lists, national-security framing — and beside a mid-July industry proposal for a FINRA-style self-regulatory organization for frontier models: industry-funded, federally overseen, Demis Hassabis’s essay, Musk and Altman adding voices the same week. David Sacks could “potentially get on board” with five conditions — broad representation including open source, frontier-only scope, catastrophic-risk tests not speech policing, voluntary first, substitute not stack. Critics smell cartel formation: incumbents writing rules that box out open weights. Wissner-Gross reported the administration may run with an SEC-hosted variant that could make Chinese open weights economically toxic for public companies. Proposal, not rule. Light-touch rhetoric and release-loop practice remain unreconciled on the wiki.
On September 1, at a two-day G20 tech gathering in North Carolina, Kratsios pressed members to take a hands-off approach. Countries that signed the “Carolina Principles,” in a Reuters-bylined reprint — the original Reuters URL was 401, so the wiki treats the Hindu reprint as the grain — agreed to avoid writing entirely new regulations for AI and instead write rules for “novel” situations. Policymakers, he said, “should not treat every emerging technology as a first-of-its-kind policy problem.” He told reporters China signed. He did not provide a copy. Hassabis, on video the same Tuesday, called for safety tests. That is not an SRO shipping. Zuckerberg opposed restricting open-weight models. Musk criticized EU rules. Altman and Huang were scheduled Wednesday with Commerce Secretary Lutnick; the reprint does not say they had already spoken. Hands-off new-reg language at a G20 and customer-by-customer model gating are different levers. The wiki records both. It does not pick.