In early September 2026 the Financial Times reported that Anthropic did not give Britain’s AI Security Institute pre-release access to Claude Mythos 5.1. US organisations still got the model. The EU’s ENISA received the older Mythos 5, not 5.1. AISI had tested OpenAI’s GPT-6 Astra the week before.
Cipher Projects is an Australian engineering studio. We are not a law firm and not an assessor. This page is for Australian and Singapore buyers who treated “the UK tested it” as a line in the risk file. That referee just missed a release. Your residency story has to stand on its own.
Quick answer
An Australian or Singapore company cannot rely on UK or EU pre-release testing of a US frontier model. Frontier weights are treated more like a national-security asset: the United States will sell sovereign inference (a data centre running a US model on your soil) while training and the most restricted weights stay domestic. Keep customer data and fine-tunes in your account: Bedrock, a VPC, a region you can name. Model choice is a vendor plus residency decision. A foreign eval is a nice-to-have, not a control.
Best for: operators who assumed an ally’s safety institute was sitting in the loop, and teams that need a data-residency story that survives a withheld model. Honest limit: Cipher does not certify you, lobby Washington, or obtain restricted weights. We put prompts, logs, and fine-tunes in an account you own and leave an evidence trail. A Power Day will not make you compliant.
Last updated: 12 September 2026. Terms that show up as atmosphere belong on the cluster glossary. If you cannot explain “sovereign inference” to the person who owns the budget, do not put it in the proposal.
Can an Australian or Singapore company rely on UK or EU safety testing of US frontier models?
No. A foreign pre-release eval is not a control you can put in your risk file. It is a lab-to-government arrangement that can stop without notice.
The FT story, as reported by TNW and IT Pro, is the first time AISI was left out of an Anthropic frontier pre-release. Mythos 5.1 launched on 1 September 2026 for approved Project Glasswing partners. IT Pro says AISI did get Claude Mythos 5 in April. A Cabinet Office spokesperson told IT Pro that AISI still works with industry, “including Anthropic,” and that it tested GPT-6 Astra before that model’s public release.
Two readings sit on the same facts. One: labs hide the most dangerous systems from governments as the systems get more dangerous. Two: US labs go protectionist even toward allies, including the lab that markets itself as the safety lab. You do not have to pick a reading to run a company. You have to stop treating AISI or ENISA as your tester.
Cipher’s through-line does not change. The scarce thing is a specified problem, clean data inside a boundary you control, and an evidence trail. A withheld weight file is a reminder that the boundary is yours.
Are frontier model weights a national-security asset now?
In practice, yes: the file that can generate the next model is treated as something you do not hand to a rival jurisdiction, even an allied one.
A weight file is not a chatbot subscription. It is the trained parameters. If you have the weights, you can run the model, fine-tune it, and (if the architecture allows) distill a cheaper follower. That is why the second copy is the sensitive object. Selling inference (API calls, a rack in Sydney or Singapore running a hosted US model) is a different product from handing over the file that makes the next version cheap.
The US State Department’s Pax Silica initiative is the chip and supply-chain layer: minerals, energy, fabs, trusted partners. Australia and Singapore are in that conversation. Model geography may not match silicon geography. A country can host inference and still never see the frontier weights. Do not assume “we are in the silicon club, therefore we get the model file.”
Schmidt, Hendrycks, and Wang’s Superintelligence Strategy paper uses MAIM (mutual assured AI malfunction) as a deterrence frame between states. Cite it if you are writing policy. It does not tell an SME which region Bedrock should run in. Your file is simpler: who can copy the weights, where prompts land, and whether a fine-tune leaves your account.
What should we do about data residency if the UK is no longer the referee?
Keep customer data and fine-tunes in an account and region you can name. Treat model choice as vendor plus residency, not as a vibe about which lab is “the safety one.”
| Choice | Best for | Honest limit |
|---|---|---|
| Frontier API in a vendor’s default multi-tenant cloud | Spiky chat, no residency need, no fine-tune of customer data | You do not control where logs and embeddings sit. A foreign eval does not fix that. |
| Bedrock or equivalent in your AWS account, named region | AU/SG teams that need isolation language, IAM, and no vendor training on prompts | You still do not own the frontier weights. You own the data path. |
| Open weights in your VPC | When you must run a named checkpoint on metal you control | You take GPU, memory, and patch burden. See HBM and KV cache. |
| Restricted partner programme (Glasswing-class) | Organisations that the lab will actually admit | Most mid-size firms will not be on that list. Do not write the proposal as if you were. |
Cipher’s first-hand pattern is the middle row for regulated and legal-adjacent work: private AI on Bedrock, plus the Australian and Singapore legal notes (AU, SG). Singapore’s named buyer is often the Data Protection Officer. The evidence layer is the same one we already sell: inventory, owners, data flows, halt on writes. Are you using AI? Can you prove it?
Does hiring a UK official mean the UK gets the weights?
No. People cross the Atlantic. The files do not have to follow them.
On 2 September 2026 Matt Clifford, who drafted the UK AI Opportunities Action Plan and advised Downing Street, joined Anthropic as managing director of international affairs, based in London, covering governments outside North America. The Guardian and The Register covered the hire. He first said he would stay as chair of ARIA; after conflict-of-interest criticism he said he would step down as ARIA chair, remaining until 6 November 2026 while a successor is appointed. The UK still did not get Mythos 5.1 for pre-release testing.
That is the usable signal for a buyer. A revolving door is a staffing fact. It is not a substitute for a test report. If your risk paper says “the former UK AI adviser is at the lab, so we are fine,” rewrite the paper. The test you can run is: where do our prompts go, who can fine-tune, and which human can halt a write.
What belongs in the risk file this quarter?
Vendor and SKU, the data path, the eval you actually have, and a halt.
- Vendor and SKU. Named model, not “Claude.” Restricted versus generally available. Who is allowed to call it.
- Data path. Prompts, logs, embeddings, fine-tunes: account, region, retention, whether the vendor trains on them.
- Eval you actually have. Your evals on your tasks. A foreign institute’s pre-release note is optional colour, not a control.
- Halt. Which actions a human must approve. Unmonitored agents against production stay off. The p(doom) page is the company checklist without the metaphysics: what p(doom) means.
Compare regimes if you sell into more than one: EU AI Act vs Australia vs Singapore. One evidence layer. Different trigger dates. Waiting for the next AISI report is not a residency strategy.
FAQ
Can we send frontier model weights to the UK? You probably cannot send them anywhere. You are buying inference. The lab decides who sees the file. An Australian or Singapore company should assume it will not hold frontier weights and should design as if that is true.
Can we rely on UK or EU safety testing? Not as a control. AISI missed Mythos 5.1. ENISA got Mythos 5. GPT-6 Astra did go through AISI. That mix is the point: the loop is optional from the lab’s side.
What should we do about data residency? Named account, named region, no vendor training on customer prompts, fine-tunes that never leave the account. Bedrock in your VPC is the common AU/SG path. Open weights only if you will operate the GPU and the patch cycle.
Is this ITAR? Not yet as a statute we can cite for every model. Treat the operational pattern as ITAR-like: the file does not travel even when the people do.
Does Pax Silica mean Australia gets the models? Pax Silica is a US-led supply-chain and silicon partnership. Hosting inference is not the same as receiving restricted weights.
Will a Power Day get us the weights? No. It produces an inventory and a data-flow record. We build the evidence layer. We do not certify you, and we do not obtain Glasswing access.
Sources
- TNW, 9 September 2026: FT report that Anthropic withheld Mythos 5.1 from AISI; US orgs got access; ENISA got Mythos 5, not 5.1.
- IT Pro, 9 September 2026: first AISI miss on an Anthropic frontier pre-release; Mythos 5 was tested in April; Cabinet Office statement; GPT-6 Astra tested.
- UK AI Security Institute: mandate: capabilities, impacts, mitigations; works with developers and governments.
- US Department of State, Pax Silica: official silicon / AI supply-chain initiative.
- The Guardian, 2 September 2026: Matt Clifford joins Anthropic as MD, international affairs.
- The Register, 7 September 2026: Clifford stepping down as ARIA chair after the hire.
- Schmidt, Hendrycks, Wang, Superintelligence Strategy: MAIM frame; policy, not an SME control.
Related: Buzzword soup glossary · What p(doom) means · Can you prove it? · Power Day · Private AI on Bedrock · Private AI, Australia · Singapore DPO · EU vs AU vs SG
