The Projection — a symmetric watercolor butterfly

The Projection

The surface is never the system.

AI

Frontier Gatekeeping

The gpt-5.6 gating dynamic made permanent — and it's all one buildout under EO 14409 (2026-06-02): the §3(b) 30-day voluntary access framework (design due ~08-01, same window as the classified NSA-led frontier threshold), the Gold Eagle clearinghouse (launched 07-14; name not on the official record), and the FINRA-style SRO now on Wiles' desk. Watch: the ~08-01 announcement's terms; whether an enforcement body is named (SRO?); Meta's exclusion made official; CAISI leadership (3 directors in a year — can it run classified review?); the first model actually gated.

STATUS · OPEN OPENED · 2026-07-22 LAST SEEN · 2026-09-04
OpenAI Anthropic Google deepmind Demis Hassabis

Summary

OpenAI and Google DeepMind are lobbying against a bipartisan House bill that would give the government emergency shutdown power over frontier AI models.

Whether the EO 14409 review framework due around August 1, including the voluntary access design and NSA-led threshold, becomes real enforcement is the open question.

2026-09-04 — Zuckerberg personally lobbies Trump against the FINRA-style AI regulator this thread has tracked since July

2026-09-03 — A Pentagon official publicly contradicts Commerce’s “Anthropic is back on the right side,” in apparent defiance of the August injunction

2026-09-02 — Google gates a cyber-specialized Gemini 3.8 Flash behind its own “Fairwind Program,” the fourth lab-run defender gate on this thread’s record

2026-09-01 — Anthropic’s flagship 5.1 release carries no reference to the government review apparatus this thread tracks

2026-08-27 — A court says the government may not blacklist a lab for criticising it

A federal judge permanently enjoined the Pentagon’s designation of Anthropic as a national-security supply-chain risk, finding it was retaliation for the company’s public criticism of the administration. Judge Rita F. Lin (N.D. Cal.) granted summary judgment for Anthropic on First Amendment, Fifth Amendment due-process and APA claims in Anthropic PBC v. U.S. Department of War, No. 3:26-cv-01996-RFL, vacating Secretary Pete Hegseth’s 10 U.S.C. § 3252 designation and converting March’s preliminary injunction into a permanent one — the precedent this thread exists to watch for, and it runs in the lab’s favour. ⚠️ A separate FASCSA designation under 41 U.S.C. § 4713 remains pending in the D.C. Circuit (No. 26-1049), so one of the two designations survives; the quoted holding language traces to a single AP wire story and could not be checked against the August order itself. (CNBC, Axios, March preliminary-injunction order, read directly)

The trigger was two safety restrictions Anthropic refused to drop in contract renegotiation — no use of Claude for mass domestic surveillance of Americans, and no fully autonomous lethal weapons — after which a Presidential Directive told every federal agency to stop using the company’s technology. That is the cleanest test case this thread has ever had: a frontier lab held a published red line against its own government, was punished commercially for it, and won. (CNBC)

2026-08-22 — A lab volunteers for pre-release monitoring, at state level

2026-08-16 — The framework this thread tracks assumes labs keep the evaluation capacity OpenAI just cut

2026-08-04 — The White House tells the labs it has no plans to ever publish the framework

2026-08-03 — The EO 14409 framework gets a date without getting published

2026-08-02 — The EU AI Act becomes enforceable while Washington’s own deadline stays silent

2026-07-31 — Altman’s Washington briefing confirmed; EO 14409 deliverables still due tomorrow

2026-07-28 — Labs push back on the Kill Switch Act

2026-07-23 — CAISI’s third leadership change in a year

2026-07-21 — Gating gets a schedule

2026-07-20 — The two proposals surface together

← Backstory (crawl 2026-07-22 → artifacts/findings/frontier-model-gov-review-precedent-2026-07-22.md)

2026-07-20 — SRO on Wiles’ desk; CAISI churns

2026-07-14→18 — Gold Eagle live; “voluntary in name”

2026-06 — De facto gating begins

2025→2026-05 — Rebuilt voluntary from a revoked mandate

This week's evidence

The Pentagon put ChatGPT and Grok in front of three million people and left Claude out — six days after a federal judge ruled the exclusion unlawful. GenAI.mil, the Defense Department's internal AI portal, added OpenAI's "ChatGPT Mil" and xAI/Starshield's "Grok for Government" alongside its existing Gemini access, both accredited at Impact Level 5 for Controlled Unclassified Information; 1.7 million of roughly 3 million DoD personnel were already onboarded. Claude is still absent. Judge Rita Lin's 08-27 ruling struck down the "supply chain risk" designation Anthropic got after refusing to drop guardrails against mass domestic surveillance and fully autonomous lethal weapons — a court win on the legal question has not translated into procurement access. ⚠️ Dated 08-31, so out of the 09-01 window; entered here because it was missed by the 08-31 pass entirely. (DefenseScoop, DoD, TechCrunch) 2026-09-01
Anthropic released Claude Fable 5.1 and Claude Mythos 5.1 on 09-01 — one model at two safeguard levels, Fable generally available and Mythos restricted to vetted cyber and life-sciences users through two trusted access programs, the latter "developed in partnership with the US government." Anthropic's own numbers: Terminal-Bench-Science 52.6% vs Fable 5's 24.7% (Opus 5 29.0%, GPT-5.6 Sol 22.4%); Terminal-Bench 4.0 55.8% (Mythos 5.1: 60.9%) vs 42.0%; AutomationBench 31.4% vs 17.1%; Humanity's Last Exam 60.9% without tools. Artificial Analysis puts it at a record 66 on its Intelligence Index, at 20% higher cost per task because it writes ~1.7x the tokens. Cache reads cut 75% to $0.25 per million tokens — ~25% cheaper on typical workloads, up to ~45% on agentic ones; standard rates unchanged at $10/$50. New in this release: default text watermarking under the EU AI Act code of practice with a detection API in private preview; "Enterprise Frontier Safeguards," a phased customer-held zero-data-retention option; cyber safeguards that intervene ~60% less and now allow vulnerability discovery (not exploit development); and strengthened anti-distillation mechanisms, with Anthropic disclosing for the first time that it traced 16 million exchanges to ~24,000 distillation accounts and naming DeepSeek, Moonshot and MiniMax. Neither the announcement nor the system card names CAISI, the UK AISI or the 30-day review framework. ⚠️ Missed for two days with 45-50 hits in this map's own buffer; recorded on Distillation Fight and Frontier Gatekeeping where it bears on a watch line, and offered as a thread candidate. (Anthropic, system card, Artificial Analysis, VentureBeat, TechCrunch) 2026-09-01
OpenAI said the same evening that its next model, Astra, is the first to reach the "Critical" cybersecurity threshold under its Preparedness Framework, and that it would limit the model's advanced cyber features after the July Hugging Face incident. Fortune (16:00 ET) and TechCrunch (17:06 ET) carried the tease; the "Path to Astra" safety brief followed. The launch itself came 09-03 and is in that day's digest. (Fortune, TechCrunch, OpenAI) 2026-09-01
Commerce Secretary Howard Lutnick said "we trust Anthropic" and that the company is "back on the right side" with the Trump administration — a public reset of a fight that ran most of 2026, and the export controls are already lifted. Speaking at the G20 Innovation Ministerial in Chapel Hill, NC, Lutnick closed out a sequence this map has tracked across two threads: Anthropic restricted Pentagon use of its models against autonomous-weapons and mass-surveillance applications; Trump directed federal agencies to stop using Anthropic and called it "radical left, woke"; the Pentagon designated the company a supply-chain risk in March; Lutnick himself invoked export controls restricting Claude Mythos 5 and Claude Fable 5 to foreign nationals; and in late August Judge Rita Lin ruled the blacklist unlawful First and Fifth Amendment retaliation. Anthropic co-founder Tom Brown is reported to have led the reconciliation talks, with Lutnick and National Cyber Director Sean Cairncross. What this does not resolve: Claude is still absent from GenAI.mil, where ChatGPT and Grok were added on 08-31 — a rhetorical reset and a lifted export control are not the same as procurement access. ✏️ (Finalize correction: this bullet originally continued "and the 7-day stay on Judge Lin's judgment expires tomorrow." There was no stay — see the ⏳ section.) ⚠️ Axios and Forbes both 403'd on direct fetch; sourced through syndications carrying the same quotes verbatim, cross-checked against each other. (Axios, Forbes) 2026-09-02
OpenAI's Astra tease ran all day in the trade press: SecurityWeek and the-decoder reported the unreleased model had crossed the Preparedness Framework's "Critical" cyber threshold after finding zero-days, and PCMag reported OpenAI limiting its cybersecurity tools after the Hugging Face hack. The tease itself is dated 09-01 evening (Fortune, TechCrunch) and is in that day's late catch; the launch came 09-03 at ~14:00 ET. 35 buffer hits across the two days, none curated until the finalize. (SecurityWeek, the-decoder, PCMag) 2026-09-02
Google shipped Gemini 3.8 Flash and a cyber-specialized 3.8 Flash Cyber at 11:00 ET, and Meta shipped Muse Spark 1.3 the same afternoon — two more releases in the launch week, both missed by the 09-02 run. Gemini 3.8 Flash is Google's third Flash in six weeks at unchanged pricing ($0.75 / $3.75 per million tokens), claiming 54.9% on HLE-Verified; the Cyber variant goes to "trusted defenders" through a new Fairwind Program — the fourth lab-run defender gate this map now tracks alongside Daybreak, the CVP and Glasswing. Muse Spark 1.3 rolled out in Muse Code and the Meta Model API with its max reasoning mode held for "additional safety testing," benchmarked by Meta against GPT-5.6 Sol and Opus 5; Meta shares rose ~4% on 09-03 on the parity claim. TLDR AI led its 09-03 edition with both. 46 buffer hits on Muse Spark 1.3 alone. (Google, Meta, TLDR AI) 2026-09-02
OpenAI launched GPT-6 Astra, the first model in its history to meet the "Critical" cybersecurity threshold of its own Preparedness Framework, and its president Greg Brockman closed the briefing with "Welcome to the AGI era." OpenAI's own materials call it Astra; the press and the reported API string (gpt-6-astra) call it GPT-6. Its "Path to Astra" safety brief says the model "discovered and used two zero-day vulnerabilities as part of an exploit chain" during evaluation (now being disclosed) and scored 100% on ExploitBench; the most advanced cyber tools are gated behind the Daybreak access program, a restriction OpenAI ties directly to July's Hugging Face sandbox escape. It ships "recurrent depth" — also described as "opaque recurrence" — which loops text through model layers and reasons in latent space rather than legible chain-of-thought; chief scientist Jakub Pachocki called CoT monitoring "fragile" and "unfortunately trending in a negative direction," and Redwood Research's Buck Shlegeris and Ryan Greenblatt warned that scaling it "totally destroys CoT monitorability." Marketed as "the world's best computer use model" (OSWorld 2.0 offline subset 72.6% in ~40 minutes per task vs GPT-5.6 Sol's 65.7% in ~75), priced at $10/$50 per million input/output tokens ($20/$100 in a 2.5x-faster mode), reaching ChatGPT Plus/Pro/Business/Enterprise, the API, Bedrock and Azure within days of today's tester-first start. (OpenAI, "Path to Astra", TechCrunch, The Verge, VentureBeat, TechCrunch on the reasoning technique) 2026-09-03
Pentagon Under Secretary of War Emil Michael said Anthropic "is still a designated Supply Chain Risk" and remains one "for the Defense Industrial Base" — one day after Commerce Secretary Lutnick said the administration "trust[s] Anthropic," and a week after a federal judge permanently enjoined the designation. Bloomberg's headline: the Pentagon says its ban is on despite Lutnick. Michael's statement does not say which of the two designations this map distinguishes he means — the vacated 10 U.S.C. §3252 designation or the separate FASCSA one still pending at the D.C. Circuit — so it is either a lawful reassertion of the surviving one or a public restatement of the one a court struck down. ✏️ And the court record this map carried was wrong a second time: the Order of Final Relief (Dkt. 251), read today from the RECAP PDF, contains no stay of any kind; the injunction has run since 08-27, no notice of appeal exists, and the "7-day stay expiring 09-03" this map logged on 09-02 — and built a dated expectation on — never existed. That expectation is withdrawn. (Axios, Washington Examiner, Bloomberg, Order of Final Relief, Dkt. 251) 2026-09-03
Four frontier releases in three days, and each lab's most capable cyber variant is gated by the lab — none by a government. OpenAI's Daybreak (Astra), Anthropic's Cyber Verification and Life Sciences Verification programs (Mythos 5.1, the latter "in partnership with the US government"), Google's new Fairwind Program (Gemini 3.8 Flash Cyber). Neither the announcements nor the system cards name CAISI, the UK AI Security Institute, or the EO 14409 30-day pre-release framework this thread was opened to watch land on a real model. Anthropic classified Mythos 5.1 on its own CB-1/CB-2 scale; OpenAI on its own Preparedness levels. (OpenAI, Anthropic system card, Google) 2026-09-03
Greg Brockman said "the US government" reviewed Astra before release and "came back with nothing to change" — the first time any lab has claimed the executive order's review framework touched a real launch. No agency is named, and the framework itself explicitly disclaims preclearance, so the claim and the mechanism do not obviously fit together. This is the precise question this thread was opened to watch, answered for the first time by an interested party rather than by a regulator. 2026-09-03
Senator Bernie Sanders and Representative Greg Casar announced the Ban Artificial Superintelligence Act — forthcoming legislation that would permanently prohibit developing or deploying AI that surpasses human intelligence, can overthrow human governments or can subvert shutdown commands, and would pause advanced AI development until a new cabinet-level federal AI agency has written safety rules and a model-review process. Penalties of up to 20 years in prison for individuals and a "corporate death penalty" for entities; the agency would "supervise the destruction of artificial superintelligence"; US foreign policy would be directed toward international agreements and export controls against superintelligence anywhere. The release cites the July OpenAI agent breakout, the Hugging Face breach and the labs' acknowledged loss-of-control incidents, and quotes their own prior pause commitments back at them. The opposite pole from the FINRA-style self-regulatory body the administration has floated: statute and a new agency, from the left, with no bill number or committee referral yet. (Office of Sen. Sanders, bill summary) 2026-09-03
Mark Zuckerberg personally raised concerns about the proposed FINRA-style national AI regulator with President Trump in a private call, per Politico. This is the first reported instance of a lab CEO lobbying the White House against the self-regulatory-organisation proposal this map has tracked since Bessent and Hassabis surfaced it on 07-20 — where the public positions on record (Nadella, Altman, Musk) all ran the other way. The united industry front this thread's record shows may be splitting. ⚠️ Sourced via a Livemint pickup of Politico; the Politico piece was not opened directly. (Livemint, citing Politico) 2026-09-04
The US and China are preparing their first bilateral talks devoted to AI safety of Trump's second term, planned for mid-September ahead of an expected Trump-Xi summit, per a Reuters exclusive — Treasury Secretary Bessent leading for the US, Vice Premier He Lifeng the likely Chinese lead, with a reported agenda of Washington's concern about a future Chinese Mythos-class model's cyber capability and US allegations that Chinese labs distilled proprietary American models. ⚠️ Contested on its face: a Treasury spokesperson told Reuters no meeting is currently scheduled and the agenda and participants are unsettled. The first wire-sourced date attached to talks reported since July only as "later this year"; logged as a rumored expectation for the week of 09-14. (CNBC, carrying Reuters, Japan Times) 2026-09-05

Related threads (shared entities)

· GPT-5.6
· Jalapeño
· OpenAI IPO
· Microsoft's Hedge
· Apple × Gemini
· Circular Financing
· Stargate
· Containment Breach
· Nippon Life v. OpenAI
· Hyperscaler Capex
· Google Capex
· Distillation Fight
· Where the Capex Lands
· Compute Spend
· Datacenter Sites
· Nvidia's Order Book
· In-House Silicon
· Camellia
· Big Tech into Health
· Google Health
· OpenAI Health
· Lab IPO Wave
· Anthropic IPO
· Nvidia as Lender
· Oracle's Stargate Bet
· Allianz AI Claims
· The #2 Cashes In
· Targets
· The Rogue Agent
· DeepMind Succession
· Copyright Exposure
· AI Psychosis
· Anthropic Rents the Buildout
· The Backlash Prices In
· The Enterprise Agent Land Grab