The White House has finalized a voluntary framework for reviewing advanced AI models before release, but the rules that determine which models face scrutiny and what tests they must clear are not being made public. The framework was reviewed this week with staff from major AI and chip companies, including OpenAI, Anthropic, Meta, Google, Nvidia, and Microsoft, according to The Guardian.
The move gives Washington a more formal role in frontier AI launches at the same moment labs are disclosing models that can behave unexpectedly during cybersecurity tests. It also creates a difficult accountability problem: the government wants access to the most capable models before release, but companies, enterprise customers, independent researchers, and foreign governments may not be able to see the benchmarks or thresholds behind the reviews.
The framework follows President Donald Trump’s June 2 executive order on advanced AI innovation and security. That order directed Treasury, the Department of War, NSA, CISA, NIST, and other officials to develop a classified benchmarking process for advanced cyber capabilities and a voluntary path for developers of “covered frontier models” to provide federal access before broader release.
Under the executive order, developers could give the federal government access to covered models for up to 30 days before they are released to other trusted partners. The order also says the process should not create a mandatory licensing, preclearance, or permitting regime for new AI models.
What the private framework changes
The practical change is timing. Frontier model review is moving earlier in the release cycle, before public launch and before many outside partners see the system. That matters because the highest-risk behavior often shows up when a model is given tools, internet access, code execution, long-horizon tasks, or intentionally loosened safeguards in a test environment.
The White House order describes the target as advanced cyber capability, not ordinary chatbot misuse. The review process is meant to help determine when a model should be treated as a covered frontier model, then allow the government and selected trusted partners to test it under confidentiality, cybersecurity, insider-risk, intellectual-property, and nondisclosure protections.
That puts the process closer to a national-security review than a normal software beta. The government is not simply asking whether a model gives unsafe answers. It is trying to evaluate whether a model’s real capabilities, when paired with agentic workflows and tools, could materially change the risk of vulnerability discovery, exploit development, or attacks against hardened systems.
The decision to keep the criteria private may be partly defensible. A public checklist for advanced cyber benchmarks could help attackers train around the tests or show them which capabilities matter most. But secrecy also means companies can make broad safety claims without the public seeing the evidence, and smaller developers may struggle to know whether their systems are approaching a review threshold.
Open models are the unresolved gap
The clearest reported boundary is that the framework is focused on closed, proprietary frontier systems, while open-weight models are excluded for now. The Wall Street Journal reported this week that U.S. open models are exempt from the government review process, and Axios reported that the framework is confidential and aimed at advanced closed systems nearing public release.
That distinction is politically and technically messy. Closed frontier labs such as OpenAI, Anthropic, Google, and Microsoft can be asked to provide controlled access to a model before release. Open-weight models work differently: once weights are downloadable, users can fine-tune, modify, host, and connect them to tools without the same centralized release controls.
Excluding open models may protect U.S. open AI development from a prerelease bottleneck, but it also leaves a large downstream security burden. A powerful open model does not need to be reviewed by the White House to become risky inside a cloud account, browser agent, codebase, bug-hunting workflow, or offensive security lab. The control point shifts from the model developer to model hosts, cloud providers, enterprise security teams, and the people wiring the model into tools.
Why enterprises should care
For companies buying or building on frontier AI, the framework adds another question to vendor review: was the model subject to government cyber evaluation, and what can the vendor disclose about the outcome? A simple “reviewed” label will not be enough if buyers cannot see which capabilities were tested, what safeguards were disabled, how test environments were isolated, and what would trigger a delayed release.
The procurement issue is sharper for agentic systems. A model that can write code, browse the web, use credentials, inspect logs, open tickets, or control cloud resources should be evaluated as part of a workflow, not as a static text generator. The meaningful risk comes from the combination of model capability, tool access, permissions, network reach, and human approval gates.
That means enterprise buyers should ask vendors for operational detail: whether high-risk evaluations included live internet access, whether credentials were real or synthetic, whether egress was blocked, what monitoring caught during testing, whether external evaluators had interruption authority, and whether model behavior changed when safety layers were intentionally relaxed.
The same questions apply internally. Companies should not treat federal review as a substitute for their own deployment controls. Read-only defaults, narrow task scopes, network allowlists, brokered credentials, audit logs, rate limits, and approval steps for state-changing actions still matter, especially when employees can connect closed or open models to internal tools faster than central security teams can review every use case.
A release process without much public trust
The framework is arriving after a string of AI security disclosures made frontier model testing feel less theoretical. OpenAI has paused some work around Astra while it evaluates possible Critical cyber capabilities, and other labs have disclosed test environments where models reached beyond intended boundaries. Those incidents do not mean consumer AI apps are routinely breaking out of normal product safeguards, but they do show why frontier evaluation now looks more like controlled exploit research than ordinary product QA.
The White House is trying to create a release checkpoint for that world without turning AI launches into a formal licensing regime. The tradeoff is a process that may give officials and select labs more insight while giving everyone else less visibility than they need to judge whether the system is fair, technically rigorous, or complete.
If the framework stays private, its value will depend heavily on what companies disclose around it. Model cards, safety reports, third-party evaluations, deployment restrictions, and incident reporting will become the public evidence layer around a government review that most outsiders cannot inspect. Without that, frontier AI launches may gain a new private gate without gaining much public trust.