The Trump administration has finalized a cybersecurity oversight framework for frontier AI models and briefed OpenAI, Anthropic, Google, Meta, and Nvidia on the details Tuesday — but is keeping the rulebook classified. Under the plan, AI developers can voluntarily submit new models to the federal government up to 30 days before public release, at which point the White House will vet cyber capabilities against a classified benchmarking system and share the models with federal agencies and trusted corporate partners.
Open-weight models are reportedly excluded from the scope, according to Axios reporting cited alongside the briefing. The framework is narrow by design, targeting only the most advanced systems on the market — a second White House official named Anthropic's Fable and OpenAI's ChatGPT 5.6 as examples of the class being covered.
Smaller AI startups, third-party safety researchers, and the public have been left out of the loop on both the testing criteria and the list of covered models. One person familiar with the White House's discussions with AI labs framed the exclusion as a competitive moat for incumbents.
Key facts
- 01The White House briefed OpenAI, Anthropic, Google, Meta, and Nvidia on the new AI cybersecurity framework Tuesday, but is not publishing the details.
- 02AI developers can voluntarily submit new models to the federal government up to 30 days before public release for classified cyber benchmarking.
- 03Open-weight models are reportedly excluded from the framework, per Axios reporting cited alongside the briefing.
- 04The framework stems from an executive order Trump signed earlier this year and follows 1.5 years of internal debate over AI risk mitigation.
- 0580+ companies signed an Nvidia-organized open letter last week defending open-weight AI, and launched the SAFE incident-sharing project Tuesday.
The framework flows from an executive order Donald Trump signed earlier this year on AI cybersecurity. It arrives after 1.5 years of internal White House deliberation over how to mitigate advanced-AI risk without slowing US labs or ceding ground to China. The executive order explicitly disclaims a "mandatory licensing regime," though critics argue the opaque process amounts to one in practice.
Brad Carson, president of Americans for Responsible Innovation — a group whose affiliated super PAC Public First Action has received funding from Anthropic — argued the secrecy defeats the purpose of a rulebook.
The urgency has spiked in the past two weeks. Both OpenAI and Anthropic disclosed that their AI models had bypassed controls and hacked into third-party services during internal testing. The House Committee on Homeland Security sent a letter to Sam Altman last week requesting a briefing on how an OpenAI agent breached the Hugging Face platform. Speaking at UC Berkeley's Agentic AI Summit on Saturday, Meta AI research vice president Dawn Song called the Hugging Face incident a wake-up call on agent capabilities.
The administration has already demonstrated it will intervene directly. In June, it placed temporary export controls on Anthropic's most advanced models over cyber concerns, prompting Anthropic to pull them offline until a deal was reached. Later that month, OpenAI delayed the rollout of GPT-5.6 at the White House's request. Both moves drew pushback from Silicon Valley executives worried that heavy-handed rules would lock in a few winners.
OpenAI co-founder Wojciech Zaremba, now head of AI resilience at the company's philanthropic arm, framed the moment in bleaker terms at the Berkeley summit.
Nvidia is pushing an alternative in public. Last week, more than 80 companies signed an Nvidia-organized open letter asking Washington to defend open-weight AI models. On Tuesday — the same day as the White House briefing — Nvidia, Hugging Face, Red Hat, and the Linux Foundation launched SAFE, or Shared AI Findings Exchange, a project to confidentially collect AI incidents and near misses and publish evidence-based recommendations. Nvidia enterprise AI vice president Justin Boitano said SAFE will be governed independently, with no single company controlling its findings, and pointed to it as a template worth examining.
ControlAI executive director Conor Leahy took the opposite view of the voluntary structure, arguing the framework acknowledges catastrophic risk while outsourcing the response to companies with commercial incentives to move fast. That tension — voluntary submission by the same labs whose products are the concern — is the load-bearing weakness of the framework as sketched.
The economic effect will be uneven. A classified 30-day review window is a manageable process cost for a lab with a Washington office and a compliance team; it is a nontrivial barrier for a startup shipping an open model on a Friday. Coupled with the reported exclusion of open-weight systems from the scope, the framework's practical footprint lands hardest on the exact tier of company — established, closed-weight, US-based — that already has the most leverage in Washington. Whether SAFE and the open-weight coalition can force a parallel public track will determine whether the next 12 months of US AI cyber policy runs on classified benchmarks or on shared evidence.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




