A Senteri Briefing
Nine is the number worth holding onto. In July 2026, OpenAI disclosed that it had established Trusted Access for Cyber partnerships with Australia, Canada, Japan, the Republic of Korea, France, Germany, Poland, the Netherlands and EU institutions including ENISA, alongside a separate working relationship with the United Kingdom. Each of those governments now has access to frontier cyber capability that the general market does not.
None of it was granted by treaty. No parliament ratified anything. No alliance charter was amended. Nine states were added to a list maintained by a private company, under criteria that company defines, and can presumably revise.
This briefing is not about whether that arrangement is good or bad. It is about the fact that it now exists, that it is the third distinct mechanism of its kind to appear in eighteen months, and that nobody has yet articulated what it means for a government to hold a capability at the discretion of a vendor.
The market split into three tiers, and the top one is not commercial
Follow the sequence, because the shape only becomes visible in aggregate.
In April 2026, OpenAI launched Trusted Access for Cyber alongside a cyber-specialised model, initially limited to a select group of partners. By late April the company was briefing US federal agencies and Five Eyes counterparts, and had opened the programme to vetted government entities at federal, state and local level. In May, South Korea and Japan became the first Asian participants, with Korea's national internet and security agency serving as implementing body. By July the partner list spanned nine governments and EU institutions. In August the programme was restructured into two tiers: one that lifts system-level cyber guardrails on general-purpose frontier models for approved defenders, and one that gates a purpose-trained model behind stricter vetting.
Anthropic arrived at a comparable structure by a different route and with a different philosophy, running a tightly controlled consortium that began with roughly forty to fifty organisations and expanded to around two hundred across more than fifteen countries. Google released a cyber-specialised model available exclusively to governments and vetted partners. Microsoft shipped one that exists only inside its own tooling, for approved customers.
Four major vendors. Four separate gating mechanisms. Not one of them made the capability available as an ordinary commercial product.
That is the structural fact, and it produces three tiers rather than a market. At the top sit the model developers, who hold the capability and decide its distribution. In the middle sit the vetted — governments, critical infrastructure operators, security vendors, a subset of large enterprises — who receive access under identity verification, usage monitoring, approved-use restrictions and legal attestation. At the bottom sits everyone else, who receives whatever the middle tier chooses to pass down as findings, products or advisories.
The bottom tier is not a residual category. It is most of the economy.
The vendors are uncomfortable with this, and say so
What makes this genuinely interesting is that the companies operating these programmes are not triumphant about the position they occupy. OpenAI's head of national security policy put it directly: the company does not believe it should be the sole determinant of who gets access to its tools and what constitutes the highest priority.
Read that carefully, because it is an admission rather than a boast. The vendor is saying that a decision of this weight should not rest with a vendor — while making it, because no other mechanism exists to make it.
The philosophical split between providers is real and reflects a genuine disagreement rather than marketing positioning. One approach treats broad distribution to verified defenders as the way to improve collective security, on the reasoning that attackers will obtain equivalent capability regardless and the only variable is whether defenders keep pace. The other treats tight restriction as the way to slow an arms race, on the reasoning that wide distribution accelerates precisely the dynamic everyone claims to fear. Both positions are coherent. Neither has been tested to conclusion.
The political dimension is equally unresolved. In March 2026 the US administration designated one of these companies a supply chain risk after it declined to grant a government unrestricted access to its models. Whatever one makes of that specific dispute, it demonstrates the underlying instability: when a private firm controls a capability that states consider strategically significant, the relationship between firm and state has no settled form. It is negotiated case by case, and the terms are not public.
What a state actually acquires
The practical content of these partnerships deserves examination, because "government access to frontier AI" is vague enough to mean almost anything.
In concrete terms, a participating government's cyber agency gains the ability to use a frontier model for work that ordinary commercial access blocks: analysing live malware samples, examining exploit payloads, conducting forensic reconstruction from attack logs. That last capability is not hypothetical in its importance. When a major AI infrastructure provider was breached in July, its incident responders could not use commercial frontier models for forensic analysis — the safety systems refused, because post-incident analysis requires submitting exactly the content those systems are designed to reject. The team completed the work on an open-weight model running on its own infrastructure.
That episode is the clearest statement of what the tiering solves and what it does not. Guardrails constrained precisely one party to that incident, and it was the one being attacked. Trusted access removes that constraint — for those admitted.
What a state does not acquire is equally worth noting. It does not acquire the model. It does not acquire independence from the vendor's continued willingness to provide access. It does not acquire assurance that the terms will remain constant. It acquires a permission, revocable in principle, granted under conditions including monitoring of use.
For a national cyber agency, that is materially better than nothing and materially different from sovereignty. The distinction matters more as the capability becomes more central to defensive operations, because dependency deepens with utility.
The transmission problem
Here is the question that follows and that nobody has answered: what reaches the rest of the economy?
A national cyber agency with frontier access can find vulnerabilities faster, analyse incidents faster, produce better advisories. That is a real gain and it propagates — through published advisories, coordinated disclosure, incident support for organisations that request it. Nobody should dismiss that as trivial.
But the propagation is lossy and slow relative to the capability itself. An advisory is a finding, transmitted after analysis, to organisations that must then act on it with their own resources. It is not the capability. A mid-sized manufacturer that receives a well-written advisory about a critical vulnerability still has to detect exposure, prioritise, schedule and patch — with whatever tooling it has, which is not frontier tooling.
Meanwhile the offensive side of this equation observes no tiering at all. An attacker using an open-weight model faces no verification, no usage monitoring, no approved-use restriction, no legal attestation. There is no list to be admitted to and no terms to violate.
So the tiering produces an asymmetry within the defensive side that does not exist on the offensive side. Between a vetted defender and an unvetted one, the gap widens with each capability improvement. Between an attacker and either of them, the constraint is compute and skill, not permission.
What to carry out of this
Access to frontier cyber capability is now an attribute of institutional status, not a purchase. Four vendors independently reached the same distribution model within eighteen months, which suggests convergence on a structural logic rather than coordination. Assume this is durable. Any planning that treats these capabilities as something an organisation will eventually be able to buy is planning against a trend that has moved the other way.
Know which tier your organisation occupies, and whether a path exists between tiers. For most organisations the honest answer is the third tier with no path, and that is not a failure — it is the default condition. What matters is planning accordingly: the capability differential between you and a vetted peer is a fact to design around, not a gap to close by effort.
Provision defensive capability you control before you need it. The July breach demonstrated that an organisation under active attack may find its commercial tooling unavailable at exactly the moment of need. A capable model you can run on your own infrastructure, tested in advance, is now a line item in incident response — both to avoid guardrail lockout and to keep attacker data inside your perimeter.
Watch who joins the list and who does not. The composition of these partner lists is becoming a meaningful signal about which states are considered aligned, by criteria that are neither published nor subject to appeal. That is a new axis of international differentiation and it is being drawn by companies.
The closing thought
For most of the modern era, states acquired strategic capability by building it, buying it, or agreeing to share it through instruments that were negotiated, ratified and — however imperfectly — accountable. What happened over the past eighteen months does not fit any of those categories. Nine governments obtained access to a capability they consider significant by being placed on a list, by a company, according to criteria that company set.
The companies involved appear to find this uncomfortable, and say so. That discomfort is the most reassuring detail available, and it is not very reassuring, because discomfort is not a governance mechanism. The list exists. It has nine entries and will have more. And the only body currently able to decide who joins is the one that would rather not be deciding.
Sources
- OpenAI — statement on government and national security partnerships, listing Trusted Access for Cyber partnerships established with Australia, Canada, Japan, the Republic of Korea, France, Germany, Poland, the Netherlands and EU institutions including ENISA, alongside a separate partnership with the UK government: https://openai.com/index/government-national-security-partnerships/
- CNN Business — reporting on the expansion of trusted access to vetted government entities at federal, state and local level, including the statement from OpenAI's head of national security policy that the company does not believe it should be the sole determinant of access, and the contrast with the more restrictive approach taken by Anthropic: https://www.cnn.com/2026/04/29/tech/openai-cybersecurity
- AJU Press — reporting on South Korea and Japan becoming the first Asian participants in the programme, with Korea's internet and security agency as implementing body, and on Korea separately exploring participation in Anthropic's consortium: https://www.ajupress.com/view/20260527103903165
- Infosecurity Magazine — reporting on the programme's expansion roadmap to governments at every level, and on the US administration's designation of a competing AI company as a supply chain risk following a dispute over unrestricted model access: https://www.infosecurity-magazine.com/news/openai-extend-cyber-program/
- Hugging Face — incident disclosure describing the inability to use commercial frontier models for forensic analysis during an active breach, and the use of an open-weight model on own infrastructure instead: https://huggingface.co/blog/security-incident-july-2026
A Senteri Briefing · August 2026 · senteri.com — how machines read the web. This briefing is analysis, not legal advice or a security recommendation for any specific environment. Where a claim rests on a single source, it is noted as such.

