Washington Gated the Frontier. Beijing Gave It Away.
This week's loudest AI claim is only half right: that a government can now control frontier AI, the top labs' most capable models. Washington did restrict OpenAI's newest model to roughly twenty vetted organisations on national-security grounds. But the same fortnight, a Chinese lab published a model one point behind the US closed frontier, at a fifth of the cost, free to download. Capability is slipping past the point where any single gate can hold it.
Give the control thesis its strongest form. On 26 June, OpenAI released its newest model family but kept it from the public, opening access only to about twenty organisations approved by the United States government. The company said its flagship had crossed the 'high' cyber-risk line on its own internal safety tests, and the Trump administration asked it to hold the release tight. That followed a June executive order telling US security agencies to build a classified process for designating a 'covered frontier model', a category of AI judged powerful enough that Washington wants a say in who runs it. It is the first time an American lab has shipped a frontier model behind a government-managed access list. If the most capable AI is becoming a controlled export, the people calling this the end of open public frontier AI are describing something real.
Now the fact that ran the other way, in the same stretch of days. On 13 June a Beijing lab, Zhipu, published GLM-5.2 as open weights under a permissive licence, meaning anyone can download the full model, adapt it, and run it on their own servers. It is no toy. On a benchmark that measures whether an AI agent can finish long, real software-engineering jobs, it lands about one point behind Anthropic's Opus 4.8, the model widely rated strongest at that work, and edges ahead of OpenAI's current public flagship. It has not drawn level everywhere; on a second agent benchmark it trails Opus by four points, and the closed frontier still wins the hardest tasks. But it runs at roughly a fifth of the cost per unit of output, and developers moved quickly: traffic through one popular model-routing service climbed faster than it did after DeepSeek's release this spring.
Both facts are true, and holding them together drains the meaning out of the control story for anyone running a business. What Washington gated is a narrow band of capability: frontier-grade cyber-offence, the specific thing OpenAI's model crossed a line on. That is a real national-security question, and rationing it may be sensible. It is also not the reason an operator buys AI. The drafting, analysis, coding, research and customer workflows that fill an actual business run well on a model a point off the frontier, and that model is now open, licensed for commercial use, and sitting on a public download page outside American jurisdiction. We argued in You're on the Other Side of the AI Bubble that operators sit on the far side of the AI build-out, gaining as capability gets cheaper; an open model at the frontier is that same position, now beyond the reach of a government trying to close the tap.
For regulated and non-US operators, the open-weight option is frequently the stronger architecture on its own merits. Europe has already written this preference into law: the European Union's AI Act sets lighter obligations for models released as free and open source, and a model you run inside your own walls answers the data-residency questions a foreign hosted service cannot. One German financial firm reported cutting its compliance-approval time sharply after deploying an open model locally to satisfy the national banking regulator, BaFin. A model that never leaves your servers clears export approval by definition and stays beyond a foreign supplier's power to reprice it or switch it off. Sovereignty, the word European governments keep repeating, turns out to be something an ordinary company can buy for the price of the hardware.
So the adjustment for an operator is concrete: stop treating access to a particular frontier model as an asset. This week showed that access is contingent from both directions. A government can restrict it overnight, and a rival on the other side of the world can hand out something almost as good for nothing. We argued in defensibility in the AI era that models commoditise while judgment, data and process compound; a government gating one model while an open competitor matches it is that argument arriving as a geopolitical event. The operators who should be uncomfortable are the ones whose plan reduces to privileged access: an exclusive deal, an early-access tier, a wager that the best model stays scarce and American. The ones who can hold their ground treat the model as an interchangeable input and spend on the layer a download cannot copy, the proprietary data, the redesigned process, and the judgment about which problems are worth pointing a model at.
The consensus has the event right and the lesson half-drawn. A government did, for the first time, gate a frontier model, and for weapons-grade capability that control is real and probably wise. But for the capability an operator actually uses, the same fortnight pointed the opposite way: near-frontier intelligence is now open, cheap, and beyond any one country's power to ration. So the strategic question this hands you is not which model you can get, since almost everyone can now get almost everything, but what you build on top of it that a competitor holding the identical weights cannot reproduce. If your edge is that you have the best model, this was the week you were served notice that you do not own it, and soon no one will. Build on the part that stays yours after the model becomes something anyone can download.