Frontier AI is no longer behaving like normal software.
That is the uncomfortable thing underneath the recent noise. We are not just watching another product-launch cycle, another safety debate, or another round of companies saying “broad access” while quietly inventing a new pricing page. We are watching the control plane form.
A few days ago, this still sounded like paranoia with a good keyboard. Now it looks more like a pattern.
Anthropic released Claude Fable 5 and Claude Mythos 5 on June 9. On June 12, the U.S. government issued an export-control directive requiring Anthropic to suspend access to those models by foreign nationals. Because Anthropic said it could not verify nationality in real time, it disabled access for all customers. Fable 5 later returned after export controls were lifted, with added safeguards and a changed usage-credit model after an initial grace period. Mythos 5 remained available only to a set of approved U.S. organizations.
OpenAI then previewed GPT-5.6 Sol, Terra, and Luna under limited access. OpenAI said it had previewed the models and capabilities to the U.S. government before launch and, at the government’s request, began with a limited group of trusted partners whose participation had been shared with the government. OpenAI also said this should not become the long-term default because it keeps the best tools away from users, developers, enterprises, cyber defenders, and global partners.
That is the important sentence. Not the benchmark chart. Not the launch branding. Not the “coming soon” language, which has become the tech industry’s preferred form of incense.
The important sentence is that access to the best tools is now explicitly being mediated through government engagement, trusted-partner selection, and release sequencing.
This is not a theory anymore. It is a release pattern.
The product is becoming the permission layer
The old software question was simple enough: What can the product do?
The new AI question is different: Who is allowed to use the version that can do it?
That is a much more dangerous question, because it moves the center of gravity from capability to access. Once access becomes the control surface, the market no longer sorts cleanly by who has the best model. It sorts by who gets early access, who gets account-managed access, who gets API-only access, who gets subscription leftovers, who gets the safety-throttled version, who gets the model after the political window closes, and who gets nothing but a cheerful blog post explaining how this is all for their own good.
Nothing says democratic technology like a velvet rope and a token meter.
To be clear, the national-security concern is not fake. Advanced models are beginning to matter in cyber operations, vulnerability research, agentic coding, biological analysis, and automated misuse. OpenAI itself described GPT-5.6 Sol as its strongest cybersecurity model and said it improved performance in coding, biology, and cybersecurity while adding stronger safeguards. The White House executive order also directs agencies to develop classified benchmarking for “covered frontier models” and design a voluntary framework where developers may provide the government access to such models for up to 30 days before releasing them to trusted partners.
So the question is not whether safety matters. It does.
The question is whether safety becomes a public framework or a private permission economy.
That distinction matters. A public framework has criteria, appeal paths, timelines, oversight, reviewability, and some notion of equal treatment. A permission economy has trusted circles, managed customers, quiet exceptions, selective previews, geopolitical carve-outs, and the familiar smell of institutional favoritism wearing a lab coat.
The executive order says the framework is voluntary and explicitly says it does not authorize mandatory governmental licensing, preclearance, or permitting for the development, publication, release, or distribution of new AI models. That language matters and should be acknowledged honestly.
But practical systems are not governed only by formal wording. They are governed by incentives.
If the government can define “covered frontier model,” run classified benchmarks, receive pre-release access, participate in trusted-partner sequencing, influence release posture, and apply national-security authorities after release, then the practical effect may start to look like preclearance even if the paperwork insists otherwise. Humans have a long and proud tradition of saying “voluntary” while holding the clipboard, the badge, and the budget.
The AI underclass will not look like science fiction
The phrase “AI underclass” sounds dramatic until you remove the movie soundtrack.
It does not mean people get no AI.
It means they get delayed AI, filtered AI, more expensive AI, lower-quota AI, API-only AI, region-limited AI, model-card AI, demo AI, and “we value broad access” AI.
The top tier gets the frontier model while it is still frontier. Government partners, defense users, elite labs, large enterprises, and selected infrastructure operators get the useful version while the market is still learning what it can do.
The second tier gets the commercial version after the trust process settles. Large companies with procurement teams, legal departments, compliance staff, and account representatives can absorb the friction.
The third tier gets API access, assuming they can pay. GPT-5.6 pricing, for example, lists Sol at $5 input and $30 output per million tokens, Terra at $2.50 and $15, and Luna at $1 and $6. That may be rational pricing for expensive infrastructure, but it still means the frontier becomes metered intelligence. For serious builders, those meters are not decoration. They shape what gets built.
The fourth tier gets the consumer subscription version, which may be good enough for casual use but not equal to the frontier release. The user sees the brand. The institution gets the capability.
The fifth tier depends on open weights, local inference, community models, academic work, and whatever remains outside the controlled release machinery.
That fifth tier is the pressure valve. It is also where the next major fight is likely to happen.
Open weights are the problem governments cannot fully solve
Closed models are easy to control compared with open-weight models. A company can throttle usage, change classifiers, alter terms, disable accounts, restrict countries, modify API behavior, and coordinate with government. That is not always wrong. It is simply where control lives.
Open weights are different. Once weights are released and mirrored globally, they are hard to recall. The control surface shifts from possession to distribution, hosting, financing, cloud access, enterprise adoption, app-store availability, payment rails, and legal exposure.
That does not make open weights magically safe. It makes them structurally different.
Governments can pressure platforms. They can restrict U.S.-hosted repositories. They can make cloud providers nervous. They can tell API companies not to serve a model. They can turn compliance departments into a thousand tiny border guards. They can create enough legal ambiguity that responsible organizations self-censor before anyone issues a formal order.
But they cannot easily unpublish a model that has already become part of the global substrate.
That is why open weights make governments uncomfortable. It is not only because open models can be misused. It is because open models reduce the leverage of the gatekeeper.
And this is where the policy line gets dangerous. If every frontier open-weight model becomes presumptively suspect, then open research and independent capability collapse into a liability category. The winners become whoever can afford legal interpretation, government relations, controlled infrastructure, and enough lobbyists to make the whole thing smell respectable.
This is how you create a capability aristocracy without ever admitting you are doing it.
The compute ownership line
There is a deeper layer below accounts, APIs, and release tiers: compute ownership.
If you can own enough GPUs, run capable weights locally, and keep inference inside your own infrastructure, the permission layer loses some of its power. If you cannot, then intelligence remains something you rent through someone else’s policy surface.
That is why chip controls are not adjacent to AI governance. They are AI governance. A model provider can gate the interface. A platform can gate the account. A cloud provider can gate capacity. A government can gate export of advanced accelerators. Capital markets can quietly gate who can build a cluster at all.
The crude version is that GPUs are the new ammunition. The less theatrical version is still serious: advanced accelerators are becoming strategic assets because they determine who can train, serve, adapt, and independently operate high-capability models.
None of this proves private GPU ownership will be banned. That would be a reckless overclaim, and reckless overclaims are how serious points get escorted out of the room by security.
But the control chain is visible: first the interface, then the model, then the weights, then the hardware. At each layer, fewer actors can meaningfully participate. At each layer, the exit option gets more expensive.
This is why open weights matter. This is why local inference matters. This is why independent compute matters. They preserve an exit from rented intelligence, even if that exit is imperfect, expensive, and operationally annoying enough to make every normal person consider gardening instead.
The AI underclass becomes durable when the lower tiers cannot leave the rented layer. It is one thing to get a weaker model by subscription. It is another thing to be priced, regulated, or classified out of owning the machines that could run an alternative.
The most important access control may not be the login screen. It may be the line where independent people, small firms, researchers, schools, and public-interest institutions lose the practical ability to own capable compute.
China is reading the same playbook
The access-control pattern is not staying inside the United States.
Reuters reported on July 7 that Chinese authorities have held meetings with major technology firms, including Alibaba, ByteDance, and Z.ai, about potentially restricting overseas access to China’s most advanced AI models, including models not yet released. The discussions reportedly included possible limits on both closed and open-weight models, penalties for leaks or theft under national-security law, and restrictions on foreign funding of domestic AI startups. Reuters said the scope remains under discussion and may apply only to future models.
That matters because it confirms the strategic logic. The United States starts treating frontier models as national assets. China considers doing the same. Each side points to the other side as justification. Then everyone acts shocked when the open market becomes an intelligence border regime.
This is not complicated. It is geopolitical recursion with better GPUs.
If China restricts overseas access to its best models, global firms lose low-cost alternatives. If the United States restricts access to its best models, foreign developers and smaller firms have stronger incentives to adopt Chinese or open-weight alternatives. If both sides restrict frontier access, the world gets fragmented model spheres: U.S.-approved intelligence, China-approved intelligence, regional substitutes, gray-market inference, and open models living under constant legal weather.
That is not an innovation market. That is a controlled supply chain for cognition.
The infrastructure story cuts both ways
There is another contradiction forming under the surface.
The industry is building enormous AI infrastructure while the model stack itself is becoming more vertically integrated and more selective. OpenAI and Broadcom announced Jalapeño, a custom LLM inference chip intended to make advanced AI faster, more reliable, and more accessible through a full-stack infrastructure strategy. Reuters also reported that DeepSeek is developing an inference chip to reduce reliance on Nvidia and Huawei, joining a broader trend of AI developers seeking tighter control over their hardware stack.
That does not mean Nvidia is suddenly irrelevant. That would be lazy analysis, and lazy analysis already has enough venture funding.
It means the center of value may shift. The early AI boom rewarded whoever could get scarce GPUs. The next phase may reward whoever can integrate model architecture, inference hardware, serving systems, customer routing, safety controls, and access policy into one vertically managed stack.
That stack will not just decide how cheap intelligence becomes. It will decide who gets it.
There is also a capacity-risk question. It is plausible that some AI infrastructure becomes mismatched to actual demand, especially if inference efficiency improves, custom chips absorb workloads, governments restrict access, and enterprises become more careful about cost. Academic work on large GPU clusters has already shown that execution-idle states can consume meaningful energy even when visible activity is low, which is a reminder that installed GPU capacity is not the same thing as useful work.
So the issue is not “dark GPUs” as a settled fact. It is capacity mismatch as a strategic risk.
We may end up with a strange split: too much capital poured into undifferentiated compute, while the truly useful frontier access remains rationed by trust, price, national policy, and platform control. That would be very on-brand for humanity: build the power plant, then sell candles to everyone outside the approved district.
Public ownership is not automatically wrong. It is automatically dangerous without rules.
The reported OpenAI government-stake proposal adds another layer.
Reuters reported, citing the Financial Times, that OpenAI discussed giving the U.S. government a 5% stake and suggested similar stakes from other U.S. AI firms. Reuters said it could not independently verify the FT report. The proposed structure would reportedly resemble the Alaska Permanent Fund, with AI companies allotting equity to a vehicle that could distribute returns to citizens.
The charitable version is easy to understand. If AI creates massive wealth from public knowledge, public infrastructure, public research, and labor displacement risk, then maybe the public should share in the upside.
That is not crazy. In fact, the instinct is morally serious.
But structure is everything.
A public wealth fund can be defensible if it is independent, transparent, nonpartisan, diversified, insulated from model-release decisions, and governed under clear fiduciary rules. The public should not be asked to accept “trust us” from companies whose entire business model is turning trust into a product feature.
The corrupt version is also easy to see.
If the government owns part of a frontier AI company while also influencing release timing, access categories, export controls, procurement, national-security classification, and market approvals, then the conflict is obvious. It becomes difficult to tell whether the government is protecting the public, protecting national security, protecting its investment, protecting a favored firm, or protecting the political story that all of this is for the little guy.
A government stake may spread upside.
It may also convert regulatory risk into a shareholder relationship.
That is where the alarms should go off. Not because public upside is bad, but because political co-ownership and capability control need a firewall thick enough to survive actual incentives, not press-release morality.
The correct answer is not “release everything”
The childish version of this debate says one side wants safety and the other side wants chaos.
That framing is useless.
There are real dual-use risks. Some frontier capabilities should probably have staged releases, red-team gates, abuse monitoring, and qualified-access programs. Defensive cybersecurity teams, critical infrastructure operators, medical researchers, and trusted public-interest institutions may need earlier access under controlled terms. Serious model providers should not be forced to pretend that every user, every geography, every capability, and every deployment context carries the same risk.
But the opposite error is just as dangerous.
If every hard problem becomes an excuse for opaque access control, then safety becomes the language of rationing. The public gets reassured. The powerful get the model. The startup gets a waitlist. The researcher gets a policy page. The independent builder gets a bill. Everyone else gets told the future is coming soon.
This is not enough.
A serious framework needs public release criteria, time limits, independent technical review, appeal paths, safe harbors for legitimate defensive research, publication rules for open-weight models, and clear separation between national-security review and commercial favoritism.
If a model is too dangerous for broad release, say why at the right level of abstraction. If only certain users can access it, define the categories. If access is delayed, publish the timeline. If the standard is classified, publish the governance wrapper around the classification process. If open weights are treated differently from APIs, explain the difference. If government equity is involved, firewall ownership from access decisions.
This is not anti-safety.
It is anti-fog.
The real divide is coming
The next AI divide may not be between people who use AI and people who do not.
It may be between those who receive frontier intelligence as infrastructure and those who receive it as a metered, delayed, filtered service.
That distinction will shape who builds companies, who secures systems, who researches cures, who automates work, who learns faster, who competes globally, and who gets permanently stuck using last quarter’s intelligence because the current version is reserved for trusted parties.
That is the future worth watching.
Not because every restriction is illegitimate. Some will be justified.
Not because every company is sinister. Some are trying to survive impossible tradeoffs.
Not because open models are pure. They are not.
The issue is simpler and harder: access to intelligence is becoming a political, economic, and strategic control point. Once that happens, the governance of access matters as much as the governance of the models themselves.
If frontier AI is becoming critical infrastructure, then the public cannot be treated as a downstream user class while governments and platform owners quietly build the permission architecture upstream.
Safety needs rules.
National security needs limits.
Public wealth needs firewalls.
Open weights need a serious framework, not panic buttons.
And broad access needs to mean more than “maybe after the trusted people are done with it.”
Otherwise, the AI underclass will not arrive through some dramatic dystopian decree. It will arrive through release notes, usage credits, trusted previews, export language, account tiers, pricing tables, and safety classifiers.
No villain speech required.
Just paperwork.