On Thursday, July 9, OpenAI launched GPT-5.6 to the public. The model had been ready for weeks. What held it up was a new process at the Commerce Department — a security review that, according to Reuters, required the company to submit its most advanced model for federal testing before anyone else could touch it.

The delay was sold as prudence. National security concerns. Misuse by foreign adversaries. The Axios report that broke the news of the approval quoted officials citing “cybersecurity risks and the potential misuse of advanced AI.” All very sober. All very responsible.

But read the timeline and a different story emerges. The government didn’t just test GPT-5.6. It got a private preview. For two weeks, while the rest of us waited, federal agencies had exclusive access to the most capable AI system ever built. That’s not a safety review. That’s a head start.

A Safety Review That Looks a Lot Like a Product Demo

The framework that delayed GPT-5.6 is new. It requires AI companies to submit frontier models for government evaluation before broad release. OpenAI complied. Anthropic went through the same process with its Fable and Mythos models the week prior, as Cybernews reported. The pattern is now established: before you get the model, the state gets the model.

Officially, this is about red-teaming. Can the model be jailbroken? Can it generate instructions for synthesizing pathogens? Can a foreign intelligence service extract sensitive training data? Those are real questions, and someone should be asking them.

But the review didn’t end with a yes/no checklist. According to one security researcher who participated in the red-teaming effort and spoke afterward at a hotel bar in downtown D.C., the testing bled into something else entirely. “We were finding vulnerabilities, sure. But half the room was also figuring out how to integrate the thing into existing workflows. By the time the public gets the model, three-letter agencies have already built tooling around it.”

The researcher asked not to be named because the red-teaming agreements included nondisclosure provisions. The point stands: the line between evaluating a model and deploying it is vanishingly thin when the evaluator is also the most eager customer.

The National Security Customer Is Always Right

There is a version of this story where the government acts as a neutral referee — setting rules, enforcing boundaries, protecting citizens from harm. That version is comforting. It is also wrong.

The Commerce Department is not a disinterested safety board. It is an economic and national security apparatus. Its interest in GPT-5.6 is not purely defensive. It wants to know what the model can do because it intends to use it — for intelligence analysis, for cyber operations, for the kind of capabilities the government does not advertise in press releases.

When the Trump administration asked OpenAI in June to limit the initial release to “a small group of government-approved partners,” per the Windows Forum report on the delay, it was not asking the company to slow down. It was asking to cut the line. The security review is the mechanism that makes cutting the line look like governance.

This is not a partisan observation. The same dynamic would play out under any administration. The state has interests. Frontier AI serves those interests. The review process is procurement by another name.

What the Public Release Actually Means

GPT-5.6 is now available to anyone. That is genuinely significant. The model is, by OpenAI’s own description, its most capable yet — particularly in cybersecurity, where the company called it “our most capable model yet” for the domain. The public will find uses for it that no government agency imagined.

But the asymmetry is already baked in. The government didn’t just see the model first. It had weeks to probe its weaknesses, map its capabilities, and build internal systems around it — all before a single civilian user typed a prompt. The public release is not the starting gun. It’s the second lap.

None of this is illegal. None of it is even particularly hidden, once you read past the headlines about “safety delays.” But it should change how we talk about AI governance. The question is not whether the government should regulate frontier models. The question is whether we are comfortable with a framework in which the state is always the first and best-informed user of every new capability.

A safety review that doubles as an early-access program is not oversight. It’s an arrangement. And the rest of us are not the priority.

Sources