Newest or sensitive AI capabilities remain behind restricted access

Last updated
OpenBrain 'responsibly' elects not to release it publicly yet (page 10); very few have access to the newest capabilities (page 16).

Restricted access to sensitive frontier capabilities is established. Public awareness and a universal months-long internal lead are not measured.

At a glance

  • Assessment: On Track
  • Confidence in assessment: 90%
  • Outcome: unresolved
  • Timing: pending
  • Evidence: direct
  • Predicted timing: Ongoing through 2027
  • Primary source: ai-2027.com, pages 10 and 16

What AI 2027 Predicted

Access to the newest capabilities becomes restricted, with advanced systems remaining internal or available to few people. Public access and public awareness are different propositions. AI 2027

How We Track This

Track internal deployment, limited access and general availability separately. An announced restricted system can demonstrate unequal access without its existence being secret.

Current Evidence

Anthropic’s September 1 release says Fable 5.1 and Mythos 5.1 share an underlying model, with different safeguards and access to sensitive capabilities. Mythos is restricted to trusted programs. This directly supports capability-access differentiation; it does not demonstrate a secretly larger base model. Anthropic release

Anthropic’s August risk report, covering July 15, describes an unreleased internal Model 2 somewhat stronger overall than Mythos 5. Other internal models were not uniformly stronger. Anthropic risk report, section 1.4

Counterevidence & Limitations

Restrictions sometimes lift quickly. Anthropic announced general Fable access would resume July 1 while Mythos remained restricted. OpenAI’s July 9 general-availability announcement followed its June 26 preview by about 13 days. Fable redeployment · OpenAI general availability

This supports an ongoing access gap, not a uniform, long delay for every frontier system. No cited study measures how much the general public knows about these capabilities. We therefore assess restricted access directly and leave public awareness unresolved.

What Would Change Our Assessment

  • Strengthen: Independent evaluations document substantial capabilities accessible internally or through restricted programs but unavailable generally.
  • Weaken: General releases consistently close those gaps quickly and restricted variants offer no material capability difference.
  • Resolve awareness: Representative evidence measures public knowledge rather than inferring ignorance from access restrictions.

Update History

DateUpdate
2026-09-07Added September restricted-capability access and dated internal-model evidence, balanced against rapid general releases. The assessment concerns access; public awareness remains unmeasured.
2026-09-06Assessment revised from on-track (0.95) to on-track (0.85). Dated disclosures support an internal-access gap; they do not quantify a general months-long lead or public awareness.
2026-08-17Anthropic documented extensive internal deployment of an unreleased model for research and engineering. This adds a direct internal-versus-public access example, while leaving the model’s capability advantage and duration of withholding unknown. Confidence remains at 0.95.
2026-07-14OpenAI released GPT-5.6 generally after roughly two weeks of limited preview. This limits how strongly that preview supports a months-long public capability gap. Sensitive access controls remain in place.
2026-07-05Anthropic said U.S. export controls on Fable 5 and Mythos 5 were lifted after a two-week suspension, with Fable 5 returning broadly and Mythos 5 remaining limited to Project Glasswing partners. This reinforces the restricted-access pattern while showing that specific controls can be temporary.
2026-06-29OpenAI published the GPT-5.6 Preview System Card, saying the initial rollout is limited to trusted partners after U.S. government pre-release engagement and that sensitive cyber and biological capabilities will remain gated for trusted users. This strengthens the restricted-access pattern behind the capability-secrecy prediction. Confidence adjusted 0.90 -> 0.95.
2026-06-15Anthropic launched Fable 5 and restricted Mythos 5 to trusted cyber and planned biology users, then said a US government directive required suspending access for foreign nationals and led it to disable both models for all customers. This adds a concrete example of frontier capability access being restricted after launch. Confidence adjusted 0.85 → 0.90.
2026-06-08A White House executive order directed agencies to create a voluntary framework for up to 30 days of federal access to covered frontier models before release to other trusted partners, paired with classified cyber-capability benchmarking. This supports the restricted-access pattern behind the capability-secrecy prediction.
2026-05-11OpenAI described tiered cyber access for GPT-5.5, GPT-5.5 with Trusted Access for Cyber, and GPT-5.5-Cyber, with more permissive behavior reserved for vetted defenders and specialized authorized workflows. This adds cross-lab evidence that public-facing access can lag or restrict frontier capabilities available to selected users; confidence adjusted 0.80 → 0.85.
2026-04-27Anthropic released Opus 4.7 while stating that the more capable Claude Mythos Preview remains limited and that cyber safeguards are being tested first on less capable models (Anthropic). This adds first-party evidence of a public/internal capability gap; confidence adjusted 0.75 → 0.80.
2026-03-30Anthropic data leak (March 26) revealed “Claude Mythos” (also called “Capybara”) — a model Anthropic describes as a “step change” already in testing with early-access customers, above even Opus tier, with “unprecedented cybersecurity risks.” This provides concrete evidence of multi-month withheld capabilities: the model has been in development and testing while the public knows only Opus 4.6. Fortune/Silicon Angle reporting confirms. Confidence adjusted 0.70 → 0.75.
2026-03Structural forces toward secrecy visible — competitive pressure, safety concerns, and government relationships all incentivize capability withholding. Academic analysis documents growing gap between internal and public-facing capabilities, but no confirmed multi-month withholding yet.