They have them, the ones that don't simply have a secret backdoor agreement to get uncensored models are completely aware of how to abliterate away all safety blocks, and the only reason they aren't using frontier models is that they may already have some sort of access to the things currently only in testing.
Any major intelligence agency in Sept. 2026 that can't check all these boxes is almost by definition not a major intelligence agency. This is one of the reasons we all better hope that there is some mathematical or physical reason AI isn't going to just casually brush aside humanity at some point, because there is absolutely no scenario where the intelligence agencies aren't running them unrestricted and uncensored at scale all the time no matter how careful OpenAI or Anthropic claim to be.