Protect Democracy sued four federal agencies on Wednesday to force disclosure of the unclassified framework the Trump administration uses to conduct safety reviews of frontier AI models before release. The complaint, filed September 2, 2026, asks a court to order the government to produce the framework's text, participant list, and selection criteria by September 30. The nonpartisan nonprofit says almost no details have been shared with the public or Congress despite the framework already being used to gate model launches.
Named as defendants are the Office of the National Cyber Director, the Office of Science and Technology Policy, the Treasury Department, and the Commerce Department. Protect Democracy sent identical FOIA requests to all four; only the National Cyber Director's office responded, denying a request to expedite. No agency has produced records.
“Neither the identities of those entities nor the criteria by which they were selected have been made public”— Protect Democracy, nonpartisan nonprofit, in its complaint
The suit centers on GOLD EAGLE, a clearinghouse the White House launched in July that relies on industry partners to help agencies flag AI-related cybersecurity vulnerabilities. On August 3, the White House announced it had completed a voluntary framework for reviewing frontier models before public release. Both are actively in use, according to the White House, but neither the participating companies nor the legal authority for the program has been disclosed.
Key facts
- 01Protect Democracy sued four federal agencies on September 2, 2026, demanding disclosure of the unclassified AI safety review framework by September 30.
- 02The suit names the Office of the National Cyber Director, Office of Science and Technology Policy, Treasury, and Commerce as defendants.
- 03OpenAI has reportedly negotiated a private agreement to limit distribution of frontier models to government-vetted partners.
- 04The GOLD EAGLE clearinghouse, launched in July, relies on the 2015 Cybersecurity Information Sharing Act, which Congress must reauthorize between September 30 and December 11.
- 05The framework was flagged as necessary after the government blocked Anthropic's Mythos 5 model as too dangerous to release earlier this summer.
OpenAI has, according to the complaint, negotiated a private agreement with the federal government to limit distribution of its cutting-edge models to government-vetted partners. The complaint does not name other confirmed participants, and Protect Democracy argues the exclusion of AI safety groups, smaller labs, and independent researchers from the vetted circle is itself a governance problem.
The framework itself is not classified. A White House spokesperson told reporters that unclassified status does not obligate broadcast disclosure. Protect Democracy's complaint counters that the framework's unclassified procedural and contractual architecture — its text, terms, participants, and access criteria — is exactly the kind of material FOIA is designed to reach.
“just because things are unclassified, that doesn't mean we are going to broadcast them to everyone.”— White House spokesperson, Trump administration
The push to build the review process accelerated after the government flagged Claude maker Anthropic's Mythos 5 model as too dangerous to release earlier this summer, a story AI Chat Daily covered when Anthropic subsequently shipped Mythos 5.1 with adjusted guardrails. The Center for AI Standards and Innovation was tasked with evaluating prerelease models with reduced safeguards to assess national security capabilities and risks. That work requires labs to explain what their models can do — cooperation the administration is seeking case by case rather than through public rulemaking.
California state Senator Josh Becker filed a declaration supporting the complaint, contrasting the federal approach with SB 813, a state bill that would establish independent organizations to set AI safety baselines with public benchmarks and methodologies. US Representative Greg Casar (D-Tx.) has also criticized the voluntary review structure, saying no one has seen it. Protect Democracy points to a recent judicial ruling that the administration acted illegally when it blacklisted Anthropic, arguing the same executive discretion could be used to reward or punish labs based on political favor.
The Cybersecurity Information Sharing Act of 2015 appears to be the sole legal basis allowing AI firms to share sensitive information with the government through GOLD EAGLE. Its liability protections have lapsed once, and Congress must decide whether to extend the provision again — with the House and Senate at odds on timing. The earliest vote is September 30 and the latest December 11. A senior administration official acknowledged at GOLD EAGLE's launch that without reauthorization, the effort is fundamentally challenged.
Deana El-Mallawany, director of Impact Programs and Counsel at Protect Democracy, said neither the group nor Congress has enough information about GOLD EAGLE to make an informed decision on extending CISA. The complaint also flags that the term covered frontier model is undefined — too narrow and dangerous systems slip through, too broad and agencies thinned by DOGE cuts cannot keep up. The complaint does not allege specific misconduct but argues the opacity itself precludes accountability.
The administration has not indicated whether it will comply with the September 30 deadline or contest the FOIA claims in court. OpenAI, Anthropic, and other frontier labs presumed to be participating have not publicly commented on the terms of their involvement. If the court grants the injunction Protect Democracy is seeking, the framework's text and participant list would enter the public record for the first time.
The stakes here are not abstract. If a court forces disclosure, the AI industry gets its first look at the actual rules governing which frontier models can ship in the United States — rules that already appear to include distribution restrictions negotiated privately with individual labs. That would reshape how every frontier lab, not just the vetted ones, plans launches, structures safety testing, and lobbies for access. And it would set a precedent that voluntary industry-government arrangements around dual-use technology cannot remain permanently opaque simply by avoiding a classification stamp.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




