GPT-5.6 was released to the public on July 9, after weeks in which access stayed limited to organisations approved by the US government. It is described as the first frontier model to clear a customer-by-customer government review before public release.
The procedure is the novelty, not the model. Pre-release review of software by a public authority is common in sectors like healthcare and aviation, and practically absent from general-purpose technology. Applying it to a language model sets a precedent whose reach isn't yet defined.
The stated criterion involves cybersecurity capability. Models able to find flaws in software serve both defence and attack, and that dual use is what motivates the control.
The commercial effect is immediate and uneven. A company needing approval to ship works on a different timeline from one that doesn't, and compliance cost favours those with legal infrastructure in place. A competitor publishing open weights doesn't pass through that funnel.
For anyone building on someone else's model, the practical takeaway is about planning: availability of a frontier model stopped being purely technical or commercial and now depends on a regulatory calendar too.
