Washington wrote three rules in 24 days in June 2026 governing the delivery of the most capable AI models — who can receive a finished advanced AI system, what evidence must precede deployment, and whether the trained model parameters cross borders.
The bottleneck for advanced AI is no longer the model itself. It is the release gate: who receives a finished frontier model, what evidence must precede distribution, and whether the weights cross borders.
Washington wrote the first U.S. version of those rules in 24 days in June 2026, a sequence compliance, procurement, and security teams can now read as a single operating frame. China has governed the same surface since August 15, 2023. The two regimes are not mirror images, but they are converging on the same question: what happens to a model in the days before it is deployed.
The U.S. sequence crystallized around three mechanisms, each documented in compliance and regulatory coverage of the June 2026 actions.
On June 2, 2026, a Trump executive order directed Treasury, the NSA, and CISA to design a voluntary framework for frontier AI: up to 30 days of pre-release access for federal agencies, paired with a classified cyber-capability benchmark that the model would have to clear before distribution. The mechanism is voluntary, but its scope is forward-looking. It covers future frontier releases, not just the models already in the market.
On June 12, the Commerce Department took non-voluntary action, barring foreign national access to Anthropic's Mythos 5 and Claude Fable 5. That restriction held for 18 days. It is the first time the U.S. export-control apparatus, originally built around chips, has reached into a deployed software model.
On June 26, OpenAI began a voluntary limited preview of GPT-5.6, with broad release on July 9. The preview sits in the same window as the Commerce action, and it tells procurement teams that the operating surface is wider than any single restricted model.
The strongest counterargument is that this is a routine export-control moment that only affects named models. The June 2 EO undercuts that read. It is voluntary, applies to future frontier releases, and pairs a 30-day pre-release window with a classified cyber-capability benchmark. The operating surface extends past any single restricted model.
China's framework is older and different in kind.
The Interim Measures for the Management of Generative AI Services, issued by the Cyberspace Administration of China and effective August 15, 2023, already cover security assessments, content controls, and pre-deployment obligations for any generative AI service offered to the Chinese public. An English translation by China Law Translate lays out the regime in detail. A Mythos-class release would not require a new regime; it would require add-ons to the existing one. That is the structural difference. The U.S. is writing a release gate for the first time; China has been operating one for nearly three years.
The gap between the two regimes is closing in the open-weight lane.
Moonshot's Kimi K3, released in July 2026, is an open-weight model that benchmarks near the top on coding and agentic tasks according to the Kimi K3 model card and third-party benchmark trackers. No Chinese lab has shipped a model in the same class as Anthropic's Mythos 5 or OpenAI's GPT-5.6. The U.S. frontier is still ahead, but the open-weight frontier is the lane where the two countries' release-gate regimes will be tested first, because open weights cross borders by construction.
For compliance, procurement, and security teams, the operating frame is now legible.
Three questions define it: which customers can be lawfully served, what evidence must be held before deployment, and how fast a model's access state can flip. The Mythos 5 case is the clearest answer to the third. Eighteen days passed between the Commerce Department's restriction and its release. A model that is in production on Monday can be restricted to a narrow customer set by Friday, and back to broad access two weeks later.
The procurement corollary is that vendor due diligence now has to track a model's regulatory state, not just its license terms. The audit corollary is that pre-deployment evidence requirements, the 30-day federal window on the U.S. side, the security assessment on the Chinese side, are now first-class artifacts in any rollout. The incident-response corollary is that access restrictions can arrive without a software patch, and that the response playbook is a regulatory one, not a technical one.
The next test will be whether a Chinese lab ships a Mythos-class model under the 2023 framework, and how the U.S. readjusts its own release gate in response. The mechanism is in place. The question is how it operates at the new scale.