White House Finalizes Voluntary AI Cybersecurity Framework for Frontier Models
The Trump administration is coordinating with tech giants to test the hacking capabilities of advanced AI models without imposing formal licensing requirements.
The Trump administration has finalized a voluntary framework designed to evaluate the security risks of advanced artificial intelligence models. The initiative aims to identify and mitigate the potential for AI to be used in cyberattacks against critical infrastructure.
On Tuesday, the White House convened a meeting with executives from leading AI firms, including OpenAI, Google, Anthropic, and Meta, to review the framework's controls before their official rollout. The program focuses specifically on measuring the hacking capabilities of so-called "covered frontier models." Under the terms of the agreement, participating companies may provide these models to the federal government for testing for up to 30 days before granting access to trusted partners.
A Shift in AI Strategy
This framework follows a June 2 executive order that brought together the U.S. Treasury, Defense, and Homeland Security departments, in consultation with the Commerce Department. The move marks a notable pivot in the administration's approach to AI governance. Upon beginning the second term, the administration initially adopted a laissez-faire stance, revoking a Biden-era AI order on the first day.
President Trump had previously postponed a similar executive order in May, expressing concern that a 90-day review window would impede the United States' technological edge. "We’re leading China, we’re leading everybody, and I don’t want to do anything that’s going to get in the way of that lead," Trump stated, highlighting the tension between security oversight and global competitiveness.
Balancing Security and Innovation
By keeping the framework voluntary, the administration ensures that the government does not have the authority to license AI models or block their public release. This structure is intended to prevent the imposition of regulatory burdens that could slow the pace of American innovation relative to China. However, the administration is keeping the specific technical details of the framework confidential, citing national security concerns.
This approach attempts to create a safety valve for national security—preventing AI-driven breaches of banks, hospitals, or government systems—without creating a bureaucratic bottleneck. By focusing on "frontier models," the government is targeting the most capable systems that possess the highest potential for dual-use in both productivity and cyber-warfare.
What to Watch
As the framework is rolled out, the industry will be watching to see how "voluntary" the participation remains and whether the lack of formal licensing leads to inconsistent security standards across the sector. While the existence of highly capable models like Anthropic's Mythos has raised concerns regarding the exploitation of vulnerabilities in critical infrastructure, the administration has not officially confirmed if specific models triggered the June executive order. The primary focus moving forward will be the effectiveness of the 30-day government testing window in identifying critical flaws before models reach the public.