If your business or agency is adopting GPT-5.6 this month, two documents are worth reading before the rollout plan is signed: OpenAI's system card for the model family, and Australia's National AI Plan. Read together, they answer the question most coverage has skipped: who, in Australia, checked this thing? The answer is nobody, and the second document explains that this is deliberate.

What OpenAI's own paperwork says

GPT-5.6 is a family of three models: Sol, the flagship; Terra, the mid-tier; and Luna, the small, fast, cheap one. OpenAI's system card states: "Under our Preparedness Framework, we are treating Sol, Terra and Luna as High capability in both Cybersecurity and Biological and Chemical risk." The framework uses that High threshold, in OpenAI's words, "to assess whether models can provide meaningful assistance to 'novice' actors to create known severe threats."

Treat a vendor's safety card with the same scepticism as a vendor's benchmark: it is the company grading its own homework. But note the direction of this claim. This is OpenAI stating, against interest, that even its smallest new model clears its own severe-risk capability bar in two domains. The card also reports the limits its testing found: Sol and Terra "were unable to carry out autonomous, end-to-end attacks against hardened targets", and the company describes mitigations including cyber safeguards that "block roughly ten times more potentially harmful activity" than the previous generation and "over 700,000 A100e GPU hours" of automated red-teaming. Those are claims we can quote, not verify.

What Washington did about it

According to reporting by Axios and TechCrunch, the US administration asked OpenAI in late June to restrict GPT-5.6's release to a set of government-vetted partners while the Commerce Department's Center for AI Standards and Innovation ran additional testing, reportedly the first time the US government has asked a lab to hold a model before public launch. OpenAI complied, and objected on the record: "We don't believe this kind of government access process should become the long-term default," the company said in a statement quoted by TechCrunch. On 8 July the hold lifted and the global rollout resumed, per Axios and CNBC. We could not verify the hold against a primary US government document, none has been published, so the above is attributed reporting, marked as such.

What Australia did about it

Two jurisdictions, one model family
  • 25 JUN 2026US administration reportedly asks OpenAI to limit the release to vetted partners pending CAISI testing (attributed: Axios, TechCrunch).
  • 26 JUN 2026OpenAI publishes the GPT-5.6 system card: all three models High capability, cyber and bio/chem (primary, OpenAI).
  • 8 JUL 2026Hold reportedly lifted; global rollout proceeds (attributed: Axios, CNBC).
  • 9 JUL 2026GPT-5.6 generally available, including to every Australian business, agency and user. Australian AI-specific pre-release checks passed: none exist.

Timeline entries marked "attributed" rest on the named press reports; no primary US government document on the hold has been published. Australian entries rest on the National AI Plan and AISI announcement, linked below. All sources accessed 11 July 2026.

Australia had a mechanism on the drawing board that could, in principle, have asked the same questions Washington asked: the ten mandatory guardrails for high-risk AI proposed by DISR in September 2024, with a possible AI Act to enforce them. As we set out in detail in our companion piece on the National AI Plan, that proposal was not carried forward. The plan commits instead to "Australia's robust existing legal and regulatory frameworks", and the new AI Safety Institute is, on its own announcement, a body that will "monitor, test and share information", a hub and an adviser. No Australian body has the power to gate, delay or condition a frontier model's availability here.

Does that matter? A view, anchored to the documents

The honest version of the government's position is defensible: general law is technology-neutral, misuse of a model to attack systems or synthesise pathogens is already criminal, and a country of Australia's size buying models built elsewhere arguably free-rides on US and UK testing anyway. The plan itself promises that "if more regulation is needed to address bad actors or broader harms, the government will not hesitate to intervene."

Our view: GPT-5.6 is the first concrete test of that promise's plumbing, and the plumbing is untested. Intervening after harms emerge assumes you can see them emerging; the body built to do the seeing, the AI Safety Institute, became operational only months ago and holds advisory powers only. The US, which hosts the labs and their testing centres, decided this release warranted a check before the public got it. Australia, which hosts neither, has chosen to find out afterwards. That is a coherent policy. It is also a bet, and it is worth knowing that it was placed on your behalf, in a plan that never quite says so.