The next major AI release may not really be one release.
It may be a ladder.
At the bottom, millions of people get the standard version. Higher up, paying customers may get more. Verified professionals can receive fewer restrictions. Researchers may get specialized access. Government evaluators and selected partners can see capabilities before most of the public ever touches them.
That isn't a hypothetical model for some distant AI future. Pieces of it are already appearing.
OpenAI's new GPT-6 Astra is the clearest example yet.
The same AI, different access
OpenAI released Astra in September as what it calls the most capable model it has broadly deployed. It is also the first OpenAI model to reach the company's “Critical” threshold for cybersecurity capability.
According to OpenAI, Astra can, with the right tools and access, discover previously unknown vulnerabilities and develop ways to exploit hardened computer systems. The company responded by strengthening its safeguards and limiting some of Astra's most advanced cybersecurity capabilities. Advanced cyber work was initially reserved for a small group of testers, with expanded access planned through OpenAI's Daybreak program for verified defensive users.
That creates an important distinction.
A model can be publicly available without every user receiving exactly the same capability.
OpenAI says higher-risk accounts can face stricter cybersecurity boundaries. A verified security professional may receive greater flexibility for legitimate defensive work. Other users may encounter refusals or additional monitoring for similar requests.
Anthropic has described a similar philosophy. Its published safeguards envision normal users receiving standard protections while certain vetted partners can receive modified access after additional due diligence. The company says it considers both the trustworthiness of the partner and whether the intended use is beneficial.
The question is starting to change from “Will this AI be released?” to “Which version of its capabilities will be released to whom?”
Government is moving toward the front of the line
AI companies are not the only institutions shaping that answer.
In June, the White House issued an executive order creating a voluntary process for developers of certain powerful AI systems to provide the federal government with pre-release access.
Under the order, covered frontier models could be provided to federal evaluators for as long as 30 days before the developer plans to release them to other trusted partners. The framework also calls for government agencies and AI developers to collaborate in choosing trusted partners that can receive early access for cybersecurity and critical-infrastructure work.
The order specifically says this should not be interpreted as mandatory government licensing or preapproval for releasing AI models.
Still, the direction matters.
For some of the most consequential models, government may know what a system can do before businesses, developers, researchers, or ordinary users do.
That may make sense when national-security risks are involved. It also gives government a privileged position in an emerging access hierarchy.
Researchers can get special access too, but someone still chooses
There are more positive versions of selective access.
OpenAI recently announced a program intended to eventually give 100,000 scientists, mathematicians, and engineers free access to frontier AI tools.
Demand immediately exceeded the first round. OpenAI said applications represented as many as 65,000 potential researcher seats, while the initial cohort would contain only 10,000 researchers. Eligible applicants for that cohort are being selected through a lottery.
Google DeepMind is experimenting with another solution: letting outside organizations evaluate proprietary AI systems inside protected computing environments. The external evaluator does not receive Google's model weights, while Google does not receive the evaluator's secret test questions.
These approaches can widen participation without simply releasing everything to everyone.
But they also reveal the same underlying problem.
Someone still designs the gate.
Someone decides which institutions qualify, which professionals are trusted, which research receives support, which countries participate, and which capabilities deserve tighter restrictions.
Open models are the pressure valve
There is another philosophy: instead of asking a company for permission, let people download the model.
Open-weight AI allows developers and researchers to run models on their own infrastructure, modify them, fine-tune them, and build without depending entirely on the original provider.
Even companies known for tightly controlled frontier models acknowledge the benefit.
OpenAI releases downloadable gpt-oss models. Anthropic CEO Dario Amodei has argued that open-weight models without dangerous capabilities are a public good because they provide low-cost value to researchers, developers, and businesses.
Openness can reduce dependence on a few large AI companies. It can give startups more room to compete, allow researchers to examine systems more deeply, and let organizations keep sensitive data on infrastructure they control.
But openness changes the safety equation too.
Once a model's weights can be downloaded and copied, the original developer cannot easily revoke every copy, update every safeguard, or stop someone from modifying the model. OpenAI has acknowledged that problem in its own open-weight safety documentation, and a 2026 NIST assessment noted that safeguards on self-hosted open-weight models can be circumvented.
So neither extreme solves the entire problem.
Put every powerful capability behind corporate gates and society risks concentrating extraordinary power among a small group of companies, governments, and approved institutions.
Release every powerful capability without meaningful controls and some safeguards may become impossible to enforce once the technology spreads.
The real fight is over who gets to define “trusted”
That may be the most important part of this debate.
Tiered access itself is not automatically unfair. We already accept different levels of access in other areas where expertise, security, or potential harm matters.
The bigger issue is whether the rules become transparent and accountable.
If companies are going to decide that some users deserve greater AI capabilities than others, what qualifies someone as trusted?
Should independent researchers receive the same opportunities as researchers at major institutions?
Should a small cybersecurity company receive the same advanced tools as a Fortune 500 company?
When governments receive early access, what oversight should exist over that relationship?
And if AI becomes a major advantage in science, education, business, security, and eventually entire professions, how much inequality can appear simply because some people reach the next level of capability before everyone else?
The era when an AI company could announce a model and simply say, “Here it is,” may be ending.
The next era could be defined by access tiers, trusted-user programs, secure research environments, government evaluation, open-weight alternatives, and constant arguments over where the gates belong.
The question isn't only whether the most powerful AI should be open or closed.
It's who gets the keys.
And if the most capable AI becomes too powerful to give everyone the same access at the same time, who should be allowed to decide what “trusted” means?