xAI, Google and Microsoft have all agreed to submit frontier AI models to the US government for pre-release safety reviews.
On May 5, the three companies confirmed that they would participate in a review process run by CAISI, the Center for AI Standards and Innovation under the US Department of Commerce. In practice, model developers hand over versions before public release so government scientists can test them for national-security risks.
What CAISI does
CAISI is housed inside the Commerce Department. Its current mandate grew out of the Trump administration's July 2025 commitment to work with technology companies on AI vetting.
The core job is straightforward: evaluate frontier AI models before public deployment and identify national-security risks. CAISI says it has already completed more than 40 frontier-model evaluations, with tests focused on cyberattacks, military misuse and other dangerous capabilities.
CAISI director Chris Fall framed the work as a measurement problem, saying independent and rigorous measurement science is the basis for understanding frontier AI and its national-security implications.
The mechanism is concrete. Developers are not only sharing the product version with safety guardrails intact. They are expected to provide internal versions with guardrails removed, so CAISI can test the real upper bound of model capability.
How the list expanded
The timeline now looks like this:
- 2024: OpenAI and Anthropic signed voluntary agreements first.
- July 2025: The Trump administration committed to cooperate with tech companies on AI vetting.
- May 5, 2026: Microsoft, Google and xAI joined the process.
Microsoft said it would work with government scientists to test models for unexpected behavior. That phrase matters because it points to abilities not caught during training but revealed after deployment.
xAI's move is more striking. Elon Musk has long argued that AI needs regulation while also disclosing xAI compliance risk in SpaceX materials. Joining CAISI is a rare moment of accommodation from the company.
Mythos raised the pressure
The timing is not accidental. Anthropic recently released Mythos, a cybersecurity model that reportedly found a vulnerability in OpenBSD that had gone unnoticed for 27 years. Anthropic later organized a 12-company alliance, briefed central-bank leaders and prompted urgent meetings among Jerome Powell, Scott Bessent and Wall Street executives.
Inside CAISI, the concern is that systems like Mythos may already be strong enough to augment hackers. If that is the capability threshold, no leading AI company should be able to release without a national-level review.
That is the real reason the roster has moved from two companies to five. CAISI cannot focus only on OpenAI and Anthropic when Google's Gemini, xAI's Grok and Microsoft's Phi models have crossed similar capability thresholds.
The Pentagon is running a separate track
There is a second line of policy moving in parallel. CAISI is the Commerce Department's safety-review channel; the Pentagon is building procurement and deployment partnerships.
Earlier this week, the Pentagon signed classified network-deployment agreements with eight AI companies. Anthropic was not on the list, reportedly because its strict guardrails on military use left some use cases unresolved.
The current map is therefore uneven:
- CAISI review list: OpenAI, Anthropic, Microsoft, Google and xAI.
- Pentagon partnership list: eight AI companies, excluding Anthropic.
- A federal court also rejected Anthropic's emergency request over a Defense Department ban last week.
Anthropic is cooperating with CAISI but remains hard for the Defense Department to use. OpenAI and Google are active on both tracks.
A regulatory framework is taking shape
The United States still has no comprehensive federal AI law, but agencies and policy tools are being activated one by one: the FTC, SEC, DOJ, CAISI, the Pentagon and White House executive orders. At the state level, New York's RAISE Act is finalized, while California and Texas are moving in similar directions.
The significance of CAISI's expanded list is that model pre-review has moved from a voluntary gesture by two companies to a de facto standard for top AI labs. If the White House later writes the process into a mandatory executive order, it would become a gate for market access.
Will this slow new model launches? Probably. A model such as GPT-5.5 may no longer move from internal testing to release in only a few weeks if CAISI needs a review window. For the AI industry, that may matter more than it first appears: when capabilities move this quickly, having no one review them is the bigger risk.
Sources: Microsoft, CocoLoop, xAI and Google will share AI models with US govt for security reviews (combined wire reports, 2026-05-05); Pentagon strikes deals with 8 Big Tech companies after shunning Anthropic (CNN Business, 2026-05-01)