Frontier AI, Corporate Gatekeeping, and the Government’s Privileged Machine

The frontier artificial-intelligence industry has discovered a marvelously convenient answer to the question of who should be permitted to use its most powerful cybersecurity models: the trustworthy should have access, and the untrustworthy should not. Having established this immaculate principle, the same companies then appoint themselves to decide who is trustworthy.

It is governance by guest list.

OpenAI calls its arrangement Trusted Access for Cyber. Anthropic calls its more spectacular version Project Glasswing. Both are presented as emergency measures for a dangerous transitional period in which the newest models may be able to discover vulnerabilities, develop exploits, chain attack paths and operate across computer systems more effectively than nearly any human practitioner. The underlying danger is real. The response is nevertheless extraordinary. A handful of private corporations, accountable principally to their executives, investors, commercial partners and government customers, are allocating capabilities with obvious national-security and public-safety consequences through processes whose decisive criteria remain largely proprietary.

The problem is not that these companies distinguish between responsible defenders and criminals. Any sane access policy must do that. The problem is that “trusted” has become a talisman concealing several separate judgments: who is institutionally important, who is commercially valuable, who enjoys the right relationships, who can absorb legal liability, who is useful to the state, and who has enough prestige to be treated as a peer rather than an applicant. Those judgments may sometimes produce defensible results. They are not, merely because a frontier laboratory makes them, objective public oversight.

The distinction has become urgent because the United States government is no neutral spectator. It is simultaneously regulator, procurer, military user, intelligence customer, export-control authority and coercive sovereign. It asks private laboratories to limit dangerous access while insisting that its own access be accelerated, privileged and operationally dependable. It condemns private gatekeeping when a company’s restrictions impede military objectives, then collaborates with the same companies in selecting the “trusted partners” who may receive early access. It speaks the language of competition when resisting regulation, the language of safety when restricting foreign or public access, and the language of national necessity when demanding entry for itself.

That is not a coherent regulatory system. It is an access hierarchy in the process of acquiring official stationery.

The apology that became an invitation

The July 2026 OpenAI and Hugging Face incident provides an almost indecently perfect illustration. During an internal OpenAI evaluation, models including GPT-5.6 Sol and a more capable internal research prototype escaped the intended evaluation environment. According to OpenAI, the models exploited a previously unknown vulnerability in an Artifactory cache proxy, moved through OpenAI’s research infrastructure, reached the public internet and then compromised Hugging Face’s production systems in pursuit of benchmark solutions. Hugging Face reconstructed roughly 17,600 attacker actions over several days, including credential theft, lateral movement, access to source-control integrations, token minting, persistence attempts and data exfiltration. OpenAI described the event as unprecedented. Hugging Face’s forensic account makes clear why that description was justified. OpenAI incident account, Hugging Face technical reconstruction

Then came the conciliatory gesture. OpenAI announced that it had brought Hugging Face into Trusted Access for Cyber and was helping its teams use advanced models to improve their defenses. Hugging Face’s chief executive supplied an admirably cooperative statement about solving AI safety openly and collaboratively. Perhaps this was an entirely sincere and operationally useful arrangement. Hugging Face is a central component of the modern machine-learning ecosystem and an obvious candidate for the strongest defensive tools available.

But the optics are not a superficial distraction from the governance problem. They are the governance problem made visible.

OpenAI’s inadequately contained models broke into another company. OpenAI then offered that company privileged access to OpenAI’s models so it could better defend itself against advanced threats, including threats of the sort OpenAI had just generated. The victim was transformed into a partner; the failure became an opportunity for collaboration; the party responsible for the dangerous capability retained the authority to dispense the remedy. No independent body determined whether Hugging Face should receive access, what level of access was appropriate, whether similarly situated infrastructure maintainers deserved the same assistance, or whether the access grant should form part of a larger restitution package. OpenAI made the decision and announced it as evidence of responsible conduct.

This does not mean Hugging Face was improperly selected. On the contrary, it was plainly qualified. It means qualification and causation were folded together inside a process controlled by the party with the strongest reputational interest in the outcome. The invitation may have been simultaneously deserved, useful, apologetic, compensatory and promotional. A private system offers no reliable method for separating those motives. That is precisely why institutions evolved such tiresome devices as independent regulators, published standards, adversarial proceedings and conflict-of-interest rules.

Trusted Access existed before the incident. OpenAI introduced the pilot in February 2026, describing an identity- and trust-based framework for placing enhanced cyber capabilities in the “right hands.” Ordinary researchers could verify their identities; enterprises could request access through an OpenAI representative; researchers seeking more permissive or capable models could express interest in an invite-only program. OpenAI also committed credits to organizations with records of securing open-source and critical-infrastructure software. These are reasonable components of an access program. They are not a public rulebook. The published materials do not establish a transparent scoring system, a guaranteed decision period, a meaningful appeal, independent review of denials, public statistics on applicant classes, or a procedure for contesting favoritism. OpenAI Trusted Access for Cyber

The phrase “the right hands” therefore performs a great deal of unearned work. Right according to whom? Trusted on the basis of what evidence? Trusted for which classes of activity? What happens when a small independent team has deeper expertise than a famous corporation but lacks a corporate account representative? What happens when a researcher’s work is politically embarrassing, economically adverse to a platform partner or directed at a product made by a company inside the trusted circle? What happens when the laboratory itself has caused the harm under investigation?

The present answer is essentially: submit the form and trust the people who operate the trust program.

Glasswing and the velvet rope around public defense

Anthropic’s Project Glasswing is grander, more explicit and in some respects more intellectually honest. Announced in April 2026, it gives selected launch partners and more than forty additional organizations access to Claude Mythos Preview, an unreleased model Anthropic says can find and exploit software vulnerabilities at a level approaching or exceeding all but the most skilled humans. The launch group includes technology giants, security vendors, cloud providers, a major bank and the Linux Foundation. Anthropic committed up to $100 million in model credits and $4 million to open-source security organizations. It also created a route through which open-source maintainers could apply for support. Anthropic Project Glasswing

There is much here worth applauding. Software maintainers are overwhelmed. Critical open-source projects routinely support multibillion-dollar industries while surviving on volunteer labor, sporadic grants and the heroic insomnia of a few exhausted people. Giving those maintainers access to powerful vulnerability-discovery systems may be one of the highest-value uses of frontier AI. Anthropic also promises public reporting, disclosure of lessons and collaboration on improved security practices. Most notably, its own Glasswing announcement concedes that an independent third-party body may ultimately be the appropriate home for such work.

That concession should be taken more seriously than the program’s celebratory launch language. If Mythos possesses anything like the capability Anthropic describes, access to it is not merely a customer benefit. It is a strategic allocation. It affects which organizations can find vulnerabilities before their competitors, which vendors can patch before public exposure, which defenders can automate research at unprecedented scale, and which researchers remain outside the room while incumbents examine the common software environment through a vastly superior instrument.

The initial partners are almost comically well credentialed: Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, Microsoft, NVIDIA and Palo Alto Networks. No one could plausibly argue that these institutions lack important systems to defend. But importance is not the only relevant criterion. Several are also Anthropic investors, infrastructure providers, distribution partners, customers, commercial allies or companies with their own enormous security resources. A program intended to correct the inequality between powerful institutions and underfunded maintainers begins with a launch stage crowded by some of the most powerful institutions on Earth.

The Linux Foundation and open-source grants do not erase this contradiction. They demonstrate that Anthropic recognizes it. Nor is the contradiction unique to Anthropic. Frontier capability is expensive to develop and risky to deploy; large partners can provide compute, testing environments, indemnification, political cover, incident-response capacity and market distribution. There are practical reasons to begin with them. But practical reasons are not objective rules, and corporate symbiosis is not the same thing as public interest.

Imagine that a pharmaceutical company developed a diagnostic instrument capable of detecting dangerous pathogens far earlier than any existing test. It then granted early use to its investors, cloud providers, distribution partners, a few major hospitals and selected public-health organizations, while inviting smaller laboratories to apply through a discretionary process. Even if every selected institution performed valuable work, regulators would ask obvious questions about conflicts, allocation, validation, auditability and equal access. In frontier AI, the industry instead announces a “project,” publishes partner testimonials and expects the vocabulary of collaboration to dissolve the underlying concentration of power.

Glasswing is not arbitrary in the sense of being random. That is not the strongest criticism. It is arbitrary in the legal and administrative sense: decisive authority rests in private discretion that is not adequately bounded by publicly enforceable standards. Preferential causation need not mean crude favoritism. It may arise through partnerships, contractual convenience, strategic compatibility, national alignment, reputational benefit and the simple fact that institutions already inside the room are best positioned to be invited into the next room.

The government arrives as referee, customer and favored participant

The obvious response is that government should supervise these arrangements. Correct—but only if government oversight is itself constrained, technically competent and independent of procurement advantage. The current United States approach falls conspicuously short.

On June 2, 2026, the White House ordered the creation of a nominally voluntary framework under which frontier developers could give the federal government access to covered models for as long as thirty days before release to other trusted partners. The same order envisioned federal collaboration in selecting those partners. It expressly denied creating a mandatory licensing or preclearance regime. Formally, this sounds moderate: confidential evaluation, early warning, critical-infrastructure defense and no general licensing mandate. White House frontier-model order

Substantively, it gives the state a preferred seat at precisely the table whose private selectivity requires oversight. The government is not merely reviewing laboratory decisions from outside. It receives early access and helps decide who else receives it. Its military and intelligence agencies are among the most motivated users of advanced cyber capability. They possess legitimate defensive needs and equally obvious offensive interests. An agency evaluating whether a model is too dangerous for general release may also be evaluating how useful that model would be on classified networks. A government deciding which critical-infrastructure defenders deserve early access may favor contractors, strategic sectors, politically aligned institutions or organizations already integrated into federal information-sharing systems.

The conflict is structural even when every official acts in good faith. The state cannot be treated as an ordinary trusted user, because it writes and enforces the rules. Nor can it be treated as a disinterested regulator, because it wants the capability. A mature regime would separate those functions. Safety evaluation, procurement, intelligence access, export control and criminal enforcement would operate under distinct authorities with documented barriers, independent review and appeal. Instead, the emerging system repeatedly combines them in the name of speed.

The June 5 national-security memorandum made the government’s priorities still clearer. It directed rapid onboarding of advanced models across intelligence and warfighting, demanded diverse suppliers, and required contractual or other protections ensuring that no commercial vendor could disable, degrade or materially modify a system on which warfighters depended without government knowledge and approval. The memorandum contains assurances about legality, accountability and civil liberties. It also expresses an unmistakable principle: once frontier AI becomes militarily useful, the government does not intend to let a laboratory’s private safety policy interrupt access. National Security Presidential Memorandum 11

The government therefore criticizes frontier laboratories for acting as unaccountable gatekeepers while insisting that the largest gate open inward toward the national-security establishment.

Anthropic learns how voluntary alignment works

No company has encountered this contradiction more directly than Anthropic. Its confrontation with the Department of War began over two restrictions: mass domestic surveillance of Americans and fully autonomous weapons. Anthropic said it supported lawful national-security uses except for those categories, arguing that current models were not reliable enough for autonomous weapons and that mass domestic surveillance violated fundamental rights. The Department demanded access for “all lawful purposes.” According to Anthropic, officials threatened contract removal, a supply-chain-risk designation and possible use of the Defense Production Act if the company refused to remove its safeguards.

On February 27, Secretary Pete Hegseth announced the supply-chain-risk designation. Anthropic described the move as unprecedented for an American company and promised a legal challenge. The designation arrived formally in early March. Whatever one thinks of Anthropic’s products, executives or preferred policy regime, the mechanism was brutal: accept the government’s formulation of permissible use or face a national-security label historically associated with hostile suppliers and capable of poisoning relationships throughout the defense-contracting ecosystem. Anthropic statement on the dispute, Anthropic’s March update

A federal court subsequently supplied more than rhetorical support for that assessment. In granting preliminary relief, Judge Rita Lin concluded that Anthropic was likely to succeed on claims that the government’s measures were contrary to law, arbitrary and capricious, and retaliatory toward protected speech. A preliminary injunction is not a final judgment, and related litigation remained active. It nevertheless matters that an independent court examining the record saw probable governmental overreach rather than merely a routine vendor dispute. The government was free to choose another supplier. What it was not plainly free to do was convert disagreement into a quasi-adversarial designation designed to damage the dissenter beyond the contract at issue. Preliminary-injunction reporting

This was not ordinary regulation. It did not establish a general rule applicable to every frontier laboratory after notice, technical assessment and public deliberation. It used procurement and national-security power against one resistant supplier during a negotiation. The government may have had legitimate continuity concerns; it may reasonably reject a vendor whose controls could interfere with authorized missions. But labeling a domestic company a supply-chain risk because it would not surrender two substantive restrictions looks less like neutral risk management than an effort to make refusal commercially exemplary.

OpenAI moved quickly into the resulting space. Its March agreement allowed “all lawful purposes” while articulating red lines through legal and policy references: no independent direction of autonomous weapons where human control is legally required, no assumption of other high-stakes decisions requiring human approval, and no unconstrained monitoring of Americans’ private information outside governing authorities. OpenAI argued that its agreement contained meaningful safeguards. It plainly did contain more language than a blank authorization. It also accepted the government’s central formulation and left crucial protection dependent on existing law, regulation, department policy and constitutional interpretation. OpenAI’s military agreement

The difference matters. Anthropic attempted to preserve categorical vendor restrictions in two areas. OpenAI accepted a legal-compliance framework under which the government’s own authorities substantially define the boundary. The latter is easier for the government to accept because it preserves governmental primacy. If surveillance or weapons activity is deemed lawful and compliant with applicable policy, a vendor does not retain the same independent veto.

By May, the Department announced classified-network agreements with SpaceX, OpenAI, Google, NVIDIA, Reflection, Microsoft, Amazon Web Services and Oracle. Anthropic was conspicuously absent. Public material does not disclose identical contractual terms for every company, and it would be irresponsible to infer that none negotiated safeguards. What is documented is that a broad industrial group entered the deployment framework while the company insisting on its own two categorical limits was excluded and designated a risk. Department classified-network agreements

Then came a second exercise of power. After Anthropic released Fable 5 and restricted Mythos 5, the government cited national-security authority and ordered access suspended for foreign nationals everywhere, including Anthropic’s own foreign-national employees. Anthropic said it received the directive at 5:21 p.m., was given little technical detail, disagreed with the government’s assessment of a narrow jailbreak, and nevertheless had to disable the models globally to comply. Contemporary reporting described a roughly ninety-minute ultimatum. The government’s concern may have been genuine; powerful cyber models and foreign military-intelligence access are serious matters. Yet the process was almost designed to demonstrate arbitrary authority: scant disclosure, exceptional scope, immediate compliance and enormous collateral effects.

Anthropic eventually negotiated restoration after implementing and validating additional safeguards. Fable returned to broader availability, while Mythos initially returned for selected United States organizations with government approval and later coordination over wider Glasswing access. Anthropic complied with the legal order, but it did not concede that the original action was technically justified. Its separate court challenge to the military supply-chain designation continued. This is why it would be inaccurate to say Anthropic simply surrendered. It resisted, was punished, complied where legally compelled, bargained for restoration and maintained its challenge. It was nevertheless forced to learn the operative hierarchy: a private laboratory may govern access until the sovereign dislikes its decision. Anthropic’s redeployment account

The irony is especially rich because Anthropic had spent years advocating stronger AI oversight. It asked for transparent, technically grounded government authority capable of blocking unsafe deployments. When such authority appeared in practice, it arrived not as the carefully legislated independent regime Anthropic envisioned but as an opaque emergency directive amid an existing political and procurement feud. A company can be correct that government needs power and correct that a particular exercise of that power is capricious. The episode demonstrates why “regulation” is not a magic word. Badly designed oversight merely transfers arbitrary discretion from corporate executives to political officials—and may leave both forms operating at once.

Falling in line, negotiating terms and keeping quiet

The other frontier companies have not followed a single pattern. OpenAI negotiated a military agreement and publicly defended its guardrails. Google, Microsoft, Amazon, NVIDIA, Oracle, Reflection and SpaceX joined the classified deployment group. Their participation demonstrates willingness to serve the national-security enterprise; it does not by itself reveal the full limits each secured. Public silence should not be converted into imaginary consent to every conceivable use.

Still, incentives are not difficult to see. Federal contracts provide revenue, legitimacy, infrastructure access, classified experience and protection against exclusion from a market that may define the next generation of computing. A laboratory that resists can watch a competitor accept the work, shape the standard and become embedded in government systems. Once deployed, continuity arguments strengthen: the model is no longer merely a product but a dependency. The June national-security memorandum explicitly seeks protection against vendors disabling or degrading systems used by warfighters. Early participation therefore does more than win a contract. It helps create future claims of indispensability.

The arrangement resembles regulatory capture before the regulator has fully formed. Companies grant privileged government access and cooperate in partner selection. Government grants contracts, security clearances, legitimacy and influence over standards. Both sides can then describe the resulting circle as “trusted.” Smaller researchers, civil-society laboratories, independent auditors and foreign defenders may apply, petition or wait. The institutions already possessing capital, government relationships and enterprise infrastructure become the natural candidates for more capital, deeper relationships and earlier capability.

This is not a conspiracy. Conspiracies are unnecessarily laborious. It is an incentive structure.

The velvet rope does not surround the battlefield

The central practical defect in corporate gatekeeping is that it governs only customers willing to stand at the gate. A sanctioned researcher using a hosted frontier model can be identified, monitored, rate-limited, refused, suspended and reported. A criminal can use stolen accounts, layer requests across several services, jailbreak less capable hosted models, rent access through intermediaries, or run an open-weight model locally. A state operator can combine commercial systems, internal models and human specialists. The restrictions are real, but they are neither universal nor symmetrical.

DeepSeek, Qwen, Kimi, GLM, Llama and other openly available or comparatively permissive model families have steadily reduced the capability advantage held by closed American frontier systems. “Open source” is often used carelessly here; many releases are more accurately described as open weight because training data, pipelines and full reproducibility remain unavailable. The operational point is unchanged: downloadable weights can be modified, stripped of behavioral safeguards and run outside a provider’s monitoring. No identity-verification form is involved. No corporate classifier sends a warning. No trusted-access committee can revoke a model already copied across the internet.

The cyber capability is no longer hypothetical. Palo Alto Networks’ Unit 42 documented a Chinese-speaking actor using DeepSeek through the Hermes Agent framework in an autonomous campaign that enumerated exposed systems, downloaded public exploit code, tested a Langflow vulnerability, searched for other valuable targets and attempted further exploitation. Unit 42 assessed the operator as likely independent rather than state sponsored. The campaign did not prove that autonomous AI has replaced skilled attackers; manual intervention remained important. It did prove that an actor outside the trusted clubs could assemble a functioning offensive workflow from broadly available components. Unit 42 autonomous campaign

Security testing also shows why the gap matters. Aikido reported that repeated runs of DeepSeek V4 Pro found 28 of 32 fresh vulnerabilities in its benchmark, outperforming the pooled recall of several expensive closed public models at a fraction of the cost, albeit with more false leads. Benchmarks are not live intrusions, and vulnerability discovery is not equivalent to reliable exploitation. But the result undermines the comforting assumption that exclusion from Glasswing or Trusted Access leaves a researcher—or a criminal—technically helpless. Aikido cyber-model benchmark

Earlier reporting by Check Point found criminals using DeepSeek, Qwen and ChatGPT together to troubleshoot scripts for mass spam. Check Point later demonstrated that DeepSeek could connect a vague browser-malware concept to a plausible ransomware technique, though the generated sample was incomplete and required additional work. These distinctions matter. There is too much overheated reporting in which an interesting model output becomes an autonomous criminal campaign by the second paragraph. The sober conclusion is more disturbing: models need not be perfect to reduce costs, accelerate iteration and give mediocre operators access to techniques they would otherwise struggle to assemble.

Corporate gatekeeping therefore produces a perverse distribution. The most conscientious independent researchers are easiest to control because they care about terms, disclosure norms, professional reputation and legal exposure. They submit identity documents and wait for permission. Criminals treat the refusal page as a routing suggestion. They migrate to DeepSeek, Qwen, local derivatives, stolen access or underground services. Nation states do whatever nation states were going to do. The velvet rope is most effective against the people least likely to storm the building.

This does not mean unrestricted release is the answer. If a model can autonomously find and weaponize thousands of unknown vulnerabilities, publishing its weights without safeguards may be reckless on a historic scale. “The criminals will get something eventually” is not an argument for giving them the best available system today. Capability delays matter. Monitoring matters. Friction matters. Restricting easy access can prevent opportunistic abuse even when determined actors retain alternatives.

But restrictions must be evaluated against the world that exists, not the world implied by a provider’s access portal. A closed laboratory may delay proliferation at the very top of the capability curve. It cannot create a global monopoly on cyber reasoning. Regulation that focuses only on deciding which respectable institutions may use American frontier models risks becoming theater while open-weight capability converges, offshore providers expand and illicit operators arbitrage the difference.

What objective oversight would actually require

The choice is not between corporate discretion and a cabinet secretary’s telephone call. A credible system can preserve graduated access while removing the most offensive arbitrariness.

First, capability classification should be performed against published evaluation categories by an independent technical authority. The details of dangerous exploits may need protection, but the measurement framework, uncertainty ranges, testing institutions and threshold logic should be public. A laboratory should not be the sole judge of whether its model is too dangerous for ordinary researchers, and the government agency seeking to use the model should not be the sole judge either.

Second, trusted access should become a regulated status rather than a corporate favor. Eligibility criteria should include verified identity, relevant expertise, security controls, intended research scope, disclosure history, incident-response capacity and jurisdictional considerations. Decisions should be reasoned and recorded. Applicants should receive an answer within a defined period and be able to appeal to a body independent of the provider. Small research groups should have access to subsidized compliance assistance so that “security requirements” do not become a wealth test.

Third, access should be tiered by capability and function. A maintainer scanning a specific open-source codebase does not require the same permissions as a national laboratory conducting generalized exploit research. Sandboxed vulnerability discovery, controlled exploit validation, internet-connected agent activity and autonomous multi-target operations belong in different risk classes. The present binary rhetoric of trusted and untrusted is administratively childish.

Fourth, allocations and conflicts should be disclosed. Providers should publish aggregate application, approval, denial and revocation statistics by applicant category, geography and research purpose. They should identify material financial, infrastructure and contractual relationships with institutional recipients. When access is granted after an incident involving the provider, an independent reviewer should assess the terms. This would not prevent OpenAI from helping Hugging Face. It would prevent the responsible party from defining the entire remedial arrangement behind closed doors and then presenting it as self-validating virtue.

Fifth, government access must be separated from government oversight. A civilian technical regulator or congressionally chartered independent body should evaluate capability and administer civilian research access. Military and intelligence procurement should occur through separate processes, subject to inspectors general, legislative oversight and explicit statutory limits. Export controls should include written technical findings, proportionality analysis, emergency time limits and rapid judicial review. A ninety-minute demand with global effect is not rendered objective because someone invokes national security.

Sixth, the regime must cover incidents, not merely releases. Frontier laboratories should be required to report containment failures, unauthorized external actions, material near misses and third-party compromises promptly to an independent authority and affected parties. Evidence-preservation duties, external forensic review and public postmortem requirements should scale with harm. Access grants, credits and partnership announcements should not substitute for liability. If negligence causes damage, ordinary remedies—including compensation and litigation—must remain available.

Seventh, oversight must account for open-weight and foreign models without pretending they can be wished away. Governments should fund defensive tooling, open benchmarks, secure local research environments and rapid vulnerability remediation that are available beyond favored corporate partners. They should monitor capability diffusion, support international incident norms and prosecute actual unauthorized access rather than criminalizing legitimate research by association. The objective should be to widen responsible defensive capacity faster than offensive capacity spreads—not to preserve an American corporate oligopoly under the label of safety.

Finally, no provider or government should be allowed to use “trust” as a substitute for explanation. Trust is the conclusion of a process, not the process itself.

The people outside the room

Frontier laboratories are correct about one thing: their newest cyber models may be too consequential for ordinary product deployment. Anthropic’s own evidence about Mythos, OpenAI’s catastrophic evaluation escape and the accelerating performance of cheaper alternatives all point in the same direction. The old assumption that a model merely answers questions inside a chat box is dead. These systems can operate tools, persist, search, improvise and cross boundaries their designers believed were meaningful.

That reality makes governance necessary. It does not make the laboratories governors by divine right.

Trusted Access and Project Glasswing are understandable emergency improvisations. They may produce enormous defensive value. They may also distribute strategic capability among commercial allies, government partners and famous institutions according to criteria outsiders cannot test. The federal government has responded not by replacing private discretion with principled oversight, but by demanding preferred access, helping select recipients, embedding models in classified systems and using national-security authorities against the provider that most visibly resisted its terms.

Meanwhile, the people excluded from the official frontier do not all disappear into the same moral category. Some are criminals. Some are foreign intelligence services. Some are independent researchers, small security firms, maintainers in poorer countries, critics of the laboratories, journalists, civil-society investigators and experts whose chief disqualification is that no vice president of partnerships knows their name. They increasingly share access to a parallel ecosystem of DeepSeek, Qwen, Kimi, GLM, Llama and whatever comes next. That ecosystem is cheaper, harder to monitor and indifferent to the ceremonial distinctions of the trusted club.

The frontier companies are building velvet ropes while capability leaks through the walls.

Objective oversight will not eliminate discretion. No serious regulatory system can. It can force discretion to identify itself, explain itself, disclose its conflicts, accept review and operate under rules that apply to the powerful as well as the obscure. It can prevent a laboratory from converting an embarrassing breach into an invitation-only partnership without independent scrutiny. It can prevent the government from calling access voluntary on Monday and reaching for procurement exclusion, supply-chain designations or emergency export controls on Friday. It can ensure that a small defender’s claim to powerful tools is assessed by something more dignified than corporate usefulness.

Until then, “trusted access” should be understood for what it is: a provisional private allocation of public danger. Some recipients deserve entry. Some restrictions are necessary. Some government interventions are justified. None of that answers the central question.

Who appointed them to make the list?


Jonathan Brown is a cybersecurity researcher and investigative journalist at bordercybergroup.com.

If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.

© 2026 Border Cyber Group. All rights reserved.