Google, Microsoft, and xAI Agree to CAISI Pre-Release AI Testing — Government Gets Guardrail-Off Access Before Launch
Three more US frontier labs have agreed to pre-release government access for their AI models. Google DeepMind, Microsoft, and xAI signed agreements with the Commerce Department’s Center for AI Safety and Infrastructure (CAISI) that give government testers access to models before public launch — including versions with reduced or removed safety guardrails.
OpenAI and Anthropic made equivalent agreements in 2024. The new signings bring five of the six leading US frontier labs under the program. Meta has not signed.
What CAISI Actually Gets
The access is specifically designed to measure raw model capability rather than the polished public behavior companies ship to consumers. A model tested with reduced guardrails will attempt tasks that production versions refuse: identifying and chaining software vulnerabilities, assisting with malware construction, mapping attack paths against critical infrastructure. CAISI’s job is to quantify what a frontier model is capable of doing to a sufficiently motivated adversary, not what it does for an average user.
CAISI has completed more than 40 such evaluations to date, including tests on models that have not been publicly released.
The Mythos Trigger
The immediate driver was Anthropic’s Claude Mythos Preview. Anthropic described the model as unusually capable at finding and chaining software security vulnerabilities — capable enough that the company concluded public release was not appropriate. That disclosure, combined with AISI’s published findings on Mythos’s 32-step cyberattack range, reached the White House and accelerated Commerce Department action.
The result is a policy reversal. The same Trump administration had rolled back Biden-era reporting requirements for powerful AI systems on the grounds that heavy regulation risked slowing US progress relative to China. Mythos’s demonstrated cyber capability appears to have changed the calculation.
What the Agreement Does Not Do
The program does not give the government a release veto. Labs can still ship models after testing. The practical constraint is political: a negative CAISI evaluation finding that a model can substantially assist nation-state-grade cyberattacks would be difficult to ignore in a public release decision.
The agreement also has no mandatory timeline. Labs submit models when they are ready to test, not on a schedule driven by CAISI capacity or government priorities.
Why This Matters Beyond Cybersecurity
The CAISI framework is the first systematic mechanism through which the US government can evaluate frontier AI models before they reach adversaries, researchers, or the public. If it works — if evaluations are rigorous, findings are actionable, and labs comply with spirit rather than letter — it becomes the de facto pre-clearance regime for frontier AI in the US. If labs submit late, submit stripped versions, or treat the testing as a box to check, it becomes security theater with extra steps.
The absence of Meta, which operates open-weights models with no comparable pre-release gating mechanism, remains the largest gap in the framework.