Media companies spent the last two years building a permission system around what AI models may take from them. They filed suits, signed licensing deals, sent cease-and-desist letters, and negotiated with labs from the position that the training layer was theirs to grant or withhold. That work is not finished and it has not stopped mattering. What this week showed is that the labs are building a permission system of their own, pointed the other way, around what customers may have. Anthropic released its newest model in two forms, a general version anyone can buy and a vetted version for partners it selects with the U.S. government involved in the program. OpenAI confirmed its next model has crossed a capability threshold that requires it to limit who gets the most advanced features at first. A federal judge ruled the Pentagon broke the law when it blacklisted Anthropic for refusing military terms, which confirmed the government has been trying to shape who gets frontier capability by other means. And OpenAI told Cursor, one of its oldest customers, that it will stop supplying models because SpaceX bought the company and OpenAI does not trust the new owner to honor a contract. Underneath all of that, the Justice Department filed a brief siding with OpenAI against The New York Times, telling a federal court that training on copyrighted articles is fair use.
What connects those stories is that permission now runs in both directions. Media may own what goes into the model. It increasingly rents what comes back out, on terms set by the labs, their contracts, and their relationships with Washington. What does not connect them is any coordinated plan. The labs, the Justice Department, and a district judge are each acting on their own logic. Read together, they describe an industry that holds two positions at once, owner at the content layer and tenant at the model layer, and that has spent most of its energy on the first while the second was being built around it.
The Justice Department picks a side in the Times case
Source: Reuters, September 2, 2026
The Trump administration filed a brief in Manhattan federal court supporting OpenAI in its dispute with The New York Times and other newspapers over the use of their articles to train the models behind ChatGPT. The brief says AI training generally makes fair use of copyrighted material and calls the process “extraordinarily” transformative. It appears to be the first time the federal government has weighed in on any of the dozens of copyright cases brought by authors, publishers, labels, and news outlets against AI developers.
The government framed its interest in terms of scientific progress and national security, and Associate Attorney General Stanley Woodward said on X that the administration would not let the country fall behind foreign adversaries on what he called a plainly incorrect reading of copyright law. Commerce Secretary Howard Lutnick separately told G20 officials that their countries should adopt the same fair use posture. The Times responded that the administration was siding with a handful of trillion-dollar companies against creators whose work was taken without payment. A brief carries advisory weight, not legal force, and the two judges who have ruled on the fair use question so far went in opposite directions.
Why it matters
The case the government chose to enter is a newspaper’s case. That is the detail media executives should sit on. Every publisher, studio, and label with a pending claim against a lab now knows the federal government’s position on the core question, and that position is on the other side of the table. The brief does not decide anything, but it changes the odds a general counsel assigns to litigation as a strategy, and it changes what a lab is willing to offer in a licensing negotiation when the alternative is a fight the government has already said it wants the lab to win.
The ownership lever still exists. Courts, unions, estates, and licensing desks are not going anywhere. What the brief says is that the lever does not necessarily control training, and that the government would prefer it did not.
Anthropic gates its top tier, and OpenAI arrives at the same door
Source: The Verge, September 1, 2026
Anthropic released Claude Fable 5.1 to general availability and Claude Mythos 5.1 to what it calls trusted partners. The two are the same underlying model. Fable ships with safeguards that route cybersecurity, biology, and chemistry requests to an older model; Mythos lifts some of those safeguards for vetted cyber defenders and infrastructure providers through Project Glasswing, a program Anthropic runs in collaboration with the U.S. government, with a separate program for life sciences researchers. Fable 5.1 holds the same list price as its predecessor while cutting cache read pricing by 75 percent. Anthropic also said the new models are its first to watermark text output, with a detection API available to eligible groups as required under EU law, according to PCWorld.
OpenAI is arriving at the same access problem from a different direction. Two weeks ago it paused frontier training because it could not rule out that Astra had reached the “Critical” cybersecurity threshold in its Preparedness Framework. This week it confirmed that Astra has, having found and chained zero-day exploits in testing, and said it will release the model soon anyway. The Wall Street Journal reported OpenAI plans broad availability but will limit Astra’s most advanced cyber capabilities to a set of testers at first, expanding access through its Daybreak defensive program over time. Sam Altman said the company is pacing its progress to meet the safety standards new capability levels require.
Why it matters
Anthropic made the architecture explicit. One model, two access levels, and the difference between them is not price. It is whether the lab, in coordination with the government where it chooses, has vetted you. OpenAI has not shipped a second model, but it has described a release where the most capable features are held back from the general tier until it decides who can have them. Both labs are saying the same thing about the frontier. Money alone does not buy the full capability.
The watermark makes the smaller version of the point. Detection is available to eligible groups, which Anthropic defines broadly, so media is not being kept out. What is new is that even the verification infrastructure now has an access policy attached to it. That is the direction everything at this layer is moving.
A judge rules the Pentagon cannot blacklist Anthropic
Source: Al Jazeera, August 28, 2026
U.S. District Judge Rita Lin issued a 59-page order finding the Defense Department acted illegally when it designated Anthropic a supply chain risk to national security. The designation followed Anthropic’s refusal to remove restrictions on the use of Claude for autonomous weapons and domestic surveillance. Lin found the government had retaliated against the company for its public criticism of Pentagon policy, called the designation arbitrary and capricious, and wrote that invoking national security is not a blank check to punish government critics. The government is expected to appeal, and a second Anthropic suit over a separate designation is pending in Washington.
The ruling landed four days before Anthropic’s launch announcement, which says the company is coordinating with the U.S. government to expand Mythos access to a broader set of domestic and international partners.
Why it matters
Read the two documents together. The government tried to cut a frontier lab off for setting its own terms and lost in court. Within a week, that same lab described government coordination as part of how it decides who gets its top model. The court blocked one instrument. It did not remove Washington’s interest in how frontier capability gets distributed, and Anthropic’s own announcement says that interest remains part of its access programs.
Government policy is becoming part of the access architecture, sometimes through the front door and sometimes through the back. Media companies negotiating with labs this year were negotiating with one party. The restricted tier is now allocated with a second party in the loop, and there is no seat at that table for a studio or a publisher. The clearance runs between labs and the state. Everyone else is a customer.
OpenAI pulls its models from Cursor over the SpaceX deal
Source: CNBC, August 29, 2026
OpenAI told SpaceX it intends to wind down the contract supplying its models to Cursor, with a proposed shutoff of November 12. SpaceX closed its $60 billion acquisition of the coding tool on August 14, and OpenAI said it cannot be confident SpaceX will use its technology within its terms of service, citing prior contract disputes with Elon Musk’s companies. Cursor itself had not violated anything. The agreement included a change-of-control clause that opened a window to cancel, and OpenAI used it. OpenAI said it would not supply future models during the wind-down. Cursor’s CEO said OpenAI models account for about 5 percent of user traffic and that the companies are talking.
Anthropic, meanwhile, has been SpaceX’s largest compute tenant since May, paying $1.25 billion a month through 2029 for capacity at the Colossus facility in Memphis, according to Axios.
Why it matters
Cursor was an early OpenAI customer, a distributor with real scale, and it lost its supplier because of who bought it. The counterparty didn’t change what it does. It changed who owns it, and that was enough. Anthropic’s relationship with the same counterparty shows the variable isn’t Elon Musk. Each lab’s relationship with a given counterparty is the variable, and that relationship can be revoked on a change of control.
Cursor’s contract was bespoke and the Musk history is singular, so this is not a template every customer should expect. What it proves is narrower and harder to dismiss. Model dependency can carry counterparty risk that has nothing to do with price, uptime, or technical performance. For streamers, publishers, and studios building AI features on frontier model APIs, that belongs in M&A diligence now, on the list a CTO, a general counsel, and a corporate development lead all have to sign off on. In a consolidation cycle, a change of control is not a hypothetical.
The frontier gets a clearance level
Four Ways to Reach the Model covered the instruments that decide what a lab can take from you. This week is about the inverse transaction, what you are allowed to take from the lab. The spine is simple. The Justice Department said the ownership lever does not necessarily control training. Anthropic and OpenAI said money alone does not necessarily buy the full capability. The Pentagon ruling and Anthropic’s own announcement said government policy is now part of the access architecture. Cursor said a contractual relationship can determine continued access after you have already built on the model.
The industry’s productive conversation with Washington this week happened somewhere else. Trump endorsed a federal film and television production incentive on Truth Social after meeting with Jon Voight, and the MPA, which has been lobbying for exactly that, welcomed it. The same administration’s intervention on AI copyright cuts the other way. Both things are true in the same week, and the asymmetry in where media has leverage with this government is worth noticing on its own.
The finding is additive, not a replacement. Media spent the last two years building a permission system around what models may take. The labs are now building a permission system around what customers may have. The industry therefore occupies two positions at once. It is an owner downstream of its archive and a tenant upstream of its AI infrastructure. Tenants can negotiate, and some of them are large, but they do not set the terms of occupancy, and they can be asked to leave.
Closing note
None of this is finished. The brief is advisory, the Pentagon ruling will be appealed, the Cursor shutoff is a proposed date, and Astra had not shipped as of Thursday morning. What has settled is the shape of the question. For most of 2026 the media industry asked what it was owed for training. That question is still open and still worth asking. The one arriving next to it is who gets the model, on what terms, and who is in the room when that is decided. The answer this week is the labs and the government, with everyone else waiting to hear.





