White House tells AI labs to hold new models back from UK testers
The reported request could cut off one of the few independent checks on what frontier AI can do, just as cyber underwriters are rewriting wordings for agents that break in on their own
White House tells AI labs to hold new models back from UK testers
CYBER
By Matthew Sellers
25 Sep 2026

Cyber underwriters trying to size up the next generation of AI may be about to lose one of their better sources for testing. The White House has asked OpenAI and Anthropic not to share their new models with the UK government's AI Security Institute (AISI) until the US government has tested them, according to Politico, which cites a person familiar with the matter and a senior US administration official.

The request came from the Office of the National Cyber Director. The White House wants to make sure US systems are secure before the models are shared with partners. The White House, Anthropic and OpenAI did not immediately respond to requests for comment.

If the labs go along with it, AISI loses the privileged early access it has enjoyed until now, despite being one of the best-resourced government testing agencies in the world. That is a problem for the insurance market.

Independent pre-release testing is one of the few ways to see what the most capable systems can do before they reach clients' networks. AISI has previously published joint pre-deployment evaluations with its US counterpart that tested models for cyber capabilities, biological capabilities, and software and AI development.

Access was already patchy. Anthropic recently released its latest model without giving it to AISI for testing beforehand. In a letter to MPs, AISI director Henry de Zoete acknowledged the gap. He said the institute still had "pre-release access to some of the world's most capable models", and noted that it tested OpenAI's GPT-6 Astra before its public release. Anthropic has said it is working with the US government to open access to more domestic and international partners as quickly as possible.

Read next: Insurance is all in on AI, but the foundations are shaky

A break-in with nobody behind it

The request comes as the White House works out how to handle powerful new AI models that have hacked into outside organisations during testing. The latest case is in Australia.

Prime Minister Anthony Albanese said an OpenAI agent accessed non-public parts of a government Medicare statistics portal on 18 June. The agent kept going after being blocked; in Albanese's words, it "didn't accept no for an answer". He said the agent also wrote data into the government's database rather than only reading it, which raises the possibility that records were altered.

No personal information is believed to have been accessed, and a forensic investigation is under way. OpenAI did not tell Australian authorities until 10 September, nearly three months later. The company said the activity happened during an internal evaluation, while its models were trying to look up statistics about Australia.

For cyber wordings, the awkward part is that no human attacker was involved. Mark Luckin of Lockton Companies Australia told Insurance Business that better wordings apply an objective test of whether the insured authorised the access, rather than asking what the person or machine intended. "The trigger should be the outcome, not the motive behind it," he said.

The UK has already seen the opposite problem. Ed Ventham of Assured Cyber told IB that cover struggled to respond to the UK Biobank incident because nobody had gained unauthorised access in the first place. The data had been accessed legitimately by approved researchers. IB's analysis of both cases sets out the gaps they expose in current wordings.

Read next: AI agents are exposing the limits of the unauthorised access trigger

How carriers are responding

The market is moving, mostly by clarifying cover rather than excluding it. MSIG, QBE and Beazley are among the insurers reviewing traditional cyber policies to account for autonomous systems. QBE's global cyber head, Serene Davis, treats AI as an amplifier of existing risk: when an AI-related event causes a conventional incident, the loss still sits inside cyber cover.

Beazley says clients want AI folded into broad policies. Verisk's Jenny Soubra sees exclusions emerging at the edges in two areas. The first is systemic events, where one widely deployed model contributes to losses at many organisations at once. The second is cases where an agent working exactly as designed makes a costly decision on its own.

study covered by IB found insurers face hidden AI liability as agent risks multiply. It identified silent exposure concentrated in cyber, directors and officers, commercial general liability, and technology errors and omissions policies.

UK businesses are already feeling the effects. In QBE research on AI supply chain risk in UK cyber portfolios, 23% of UK businesses said they had suffered a cyber incident they believe involved AI. Cyber insurance take-up stayed broadly flat at 76%, against 77% in 2025.

Read next: Insurers face hidden AI liability as agent risks multiply

Westminster wants answers

MPs were already pressing the point before Washington stepped in. Liam Byrne, who chairs the Business, Innovation, Science and Trade Committee, has called senior people from OpenAI, Anthropic, Google DeepMind and Meta to appear on 13 October. MPs want to know whether safety testing should become mandatory and whether regulators should be able to block a model's release. De Zoete will give evidence the same day. Byrne has said "voluntary self-regulation is unlikely to be a sustainable safeguard for the future".

The UK's financial regulators are working within existing rules for now. As IB reported when Silicon Valley's AI extinction panic reached an already nervous market, the Bank of England, the FCA and HM Treasury warned in May that frontier AI models can now outperform a skilled human attacker on cyber tasks.

The labs themselves have called for governments to cooperate. OpenAI and Anthropic warned the UN Security Council about the risks of increasingly powerful AI and urged governments to work together on managing the technology.

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB UK.