If your business or agency is adopting GPT-5.6 this month, two documents are worth reading before the rollout plan is signed: OpenAI's system card for the model family, and Australia's National AI Plan. Read together, they answer the question most coverage has skipped: who, in Australia, checked this thing? The answer is nobody, and the second document explains that this is deliberate.
What OpenAI's own paperwork says
GPT-5.6 is a family of three models: Sol, the flagship; Terra, the mid-tier;
and Luna, the small, fast, cheap one. OpenAI's
system card states:
Under our Preparedness Framework, we are treating Sol, Terra and Luna as High
capability in both Cybersecurity and Biological and Chemical risk.
The framework
uses that High threshold, in OpenAI's words, to assess whether models can provide
meaningful assistance to “novice” actors to create known severe threats.
Treat a vendor's safety card with the same scepticism as a vendor's benchmark:
it is the company grading its own homework. But note the direction of this claim.
This is OpenAI stating, against interest, that even its smallest new model clears
its own severe-risk capability bar in two domains. The card also reports the
limits its testing found: Sol and Terra were unable to carry out autonomous,
end-to-end attacks against hardened targets
, and the company describes
mitigations including cyber safeguards that block roughly ten times more
potentially harmful activity
than the previous generation and "over 700,000 A100e
GPU hours" of automated red-teaming. Those are claims we can quote, not verify.
What Washington did about it
According to reporting by Axios
and TechCrunch,
the US administration asked OpenAI in late June to restrict GPT-5.6's release to a
set of government-vetted partners while the Commerce Department's Center for AI
Standards and Innovation ran additional testing, reportedly the first time the US
government has asked a lab to hold a model before public launch. OpenAI complied,
and objected on the record: We don't believe this kind of government access
process should become the long-term default,
the company said in a statement
quoted by TechCrunch. On 8 July the hold lifted and the global rollout resumed,
per Axios
and CNBC.
We could not verify the hold against a primary US government document, none has
been published, so the above is attributed reporting, marked as such.
What Australia did about it
- 25 JUN 2026US administration reportedly asks OpenAI to limit the release to vetted partners pending CAISI testing (attributed: Axios, TechCrunch).
- 26 JUN 2026OpenAI publishes the GPT-5.6 system card: all three models High capability, cyber and bio/chem (primary, OpenAI).
- 8 JUL 2026Hold reportedly lifted; global rollout proceeds (attributed: Axios, CNBC).
- 9 JUL 2026GPT-5.6 generally available, including to every Australian business, agency and user. Australian AI-specific pre-release checks passed: none exist.
Timeline entries marked "attributed" rest on the named press reports; no primary US government document on the hold has been published. Australian entries rest on the National AI Plan and AISI announcement, linked below. All sources accessed 11 July 2026.
Australia had a mechanism on the drawing board that could, in principle, have
asked the same questions Washington asked: the ten mandatory guardrails for
high-risk AI proposed by DISR in September 2024, with a possible AI Act to enforce
them. As we set out in detail in
our companion piece on the National
AI Plan, that proposal was not carried forward. The
plan
commits instead to Australia's robust existing legal and regulatory frameworks
,
and the new AI
Safety Institute is, on its own announcement, a body that will "monitor, test
and share information", a hub and an adviser. No Australian body has the power to
gate, delay or condition a frontier model's availability here.
Does that matter? A view, anchored to the documents
The honest version of the government's position is defensible: general law is
technology-neutral, misuse of a model to attack systems or synthesise pathogens is
already criminal, and a country of Australia's size buying models built elsewhere
arguably free-rides on US and UK testing anyway. The plan itself promises that
if more regulation is needed to address bad actors or broader harms, the
government will not hesitate to intervene.
Our view: GPT-5.6 is the first concrete test of that promise's plumbing, and the plumbing is untested. Intervening after harms emerge assumes you can see them emerging; the body built to do the seeing, the AI Safety Institute, became operational only months ago and holds advisory powers only. The US, which hosts the labs and their testing centres, decided this release warranted a check before the public got it. Australia, which hosts neither, has chosen to find out afterwards. That is a coherent policy. It is also a bet, and it is worth knowing that it was placed on your behalf, in a plan that never quite says so.