Qualified organizations would use the models to find and fix security flaws before those capabilities become broadly available.
The Business Software Alliance (BSA), an enterprise software trade group, proposed giving trusted cybersecurity organizations early access to powerful AI models before releasing them more widely.
Under the proposal, governments, AI developers, and cybersecurity organizations would form a voluntary partnership to oversee these phased releases. BSA’s announcement did not name a government body to run the partnership, any AI developer that had agreed to participate, or a timetable for creating it.
Defenders would get a head start
The proposal would apply to the most powerful AI cybersecurity models, which BSA said can find security flaws, determine which are most urgent, and exploit them with limited human direction. BSA cited GPT-6 Astra and Mythos as examples but did not say exactly how capable a model would need to be to qualify for the program.
BSA said the same capabilities can help defenders identify weaknesses more quickly or help attackers exploit them. Its proposal would give selected defenders time to locate vulnerabilities and coordinate fixes before attackers gain broad access to the models.
The early users would include cybersecurity providers, software companies, critical infrastructure operators, and organizations working to secure widely used open-source software. BSA also wants to deploy these capabilities more broadly through security platforms that organizations already use. The proposal says the partnership should eventually support both organizations protecting their own systems and providers protecting their customers, but it does not explain how that wider rollout would work.
BSA sets tests for early access
Organizations would need more than cybersecurity experience to qualify. BSA said applicants should show that they have followed applicable laws and accepted practices for reporting and fixing security flaws. The partnership would also examine whether they have the people and resources to use the models effectively and whether their work protects critical infrastructure or widely used technologies. BSA did not say what evidence applicants would need to provide.
Applicants would also need to show that they could prevent unauthorized access to the models. They would have to disclose who owns or controls the organization and identify any other parties with substantial influence. The partnership would also consider whether the organization has ties to a country of concern that could make granting access risky.
Priority access would be temporary
The proposed partnership would first decide which AI models are powerful enough to require a phased release. Most AI security tools would remain outside the program because they do not materially expand what cybersecurity teams can already do.
The restricted-release period would end once similar models became widely available or the security risks no longer justified limiting access. BSA said participants should know the expected length of the early-access period, but its proposal does not set a maximum duration.
The full proposal also calls for clear application rules and explanations when an organization is denied access. It does not specify who would make those decisions or what steps governments and AI developers will take next to establish the partnership.

