The US government issued the most unusual product announcements in tech history on Friday: not specs, not pricing, just a list of who gets in.
OpenAI released GPT-5.6 — the first of a three-tier family that also includes Terra (balanced) and Luna (fast) — but only to roughly 20 companies whose access was approved by the Trump administration. The company said it expected to expand to more next week and planned a broad rollout in the coming weeks. OpenAI called the restrictions “not the norm we want to establish” while complying anyway, a posture that will look familiar to anyone watching frontier labs navigate an export-control environment they didn’t design and can’t fully control. Sol is priced at $5 per million input tokens and $30 output — the most capable model OpenAI has shipped, built with stronger coding, biology, and cybersecurity capabilities, and the first release explicitly framed around a redesigned reward audit pipeline after GPT-5.5’s documented alignment failures.
Hours later, the Commerce Department sent a letter clearing Mythos 5 — the model dark since the June 12 export-control directive — for limited deployment to roughly 100 government agencies and vetted private companies for defensive cybersecurity use. Commerce Secretary Howard Lutnick wrote that “appropriate safeguards are in place,” a phrase that neatly sidesteps explaining what those safeguards are. Claude Fable 5, the general-purpose frontier model, remains offline; Anthropic said it was in talks but gave no timeline.
Taken together, Friday marked the first time any government has functioned as a frontier AI model registry — approving specific customers for specific models, not just imposing country-level export lists or blanket capability thresholds. The precedent is real regardless of whether it becomes permanent policy. Washington has demonstrated it can manage model access at the individual-organization level, with an undisclosed list and an undefined approval process.
The same week, Anthropic disclosed to the Senate Banking Committee what it called “the largest known distillation attack on Anthropic to date”: 28.8 million Claude interactions run through 25,000 fraudulent accounts linked to Alibaba’s Qwen lab between April 22 and June 5. The purpose was adversarial distillation — using outputs from a more capable model to train a weaker one without paying for the capability or the license. The scale was nearly double the previous record, set by three Chinese labs combined. The attack ran while Anthropic was negotiating with the same government that now manages its access list. It demonstrates the structural problem that approved-organization lists cannot solve: anyone with patience and an API key can approximate what official channels are designed to restrict, and there are 25,000 fake accounts’ worth of evidence for how that works in practice.
Meanwhile, OpenAI and Broadcom unveiled Jalapeño, the first custom inference silicon OpenAI has produced. Developed in a nine-month cycle — itself accelerated using OpenAI’s own models for parts of the design — Jalapeño is a reticle-sized ASIC targeting LLM inference, with first deployments expected by year-end. It won’t end OpenAI’s Nvidia dependency quickly. But it marks the first step toward a compute stack OpenAI controls end-to-end, which is the kind of move a company makes when it has watched a government switch off a competitor’s model with ninety minutes’ notice and decided not to be fully exposed to the same risk.
Two things are simultaneously true this week. The government is taking a more active role in who accesses powerful AI than it ever has. And the people who want that access are more resourceful than any access list can account for. Friday’s announcements moved the first variable measurably. Alibaba’s 28.8 million exchanges are a controlled experiment in what the second variable looks like when it has six weeks and 25,000 accounts to run unchecked.