A framework completed but not released

The White House has finalised a voluntary framework intended to govern how some advanced artificial intelligence developers engage with the US government before model releases. Yet the framework itself has not been published. On August 4, officials briefed staff from major AI companies, while the administration kept the wider public, smaller developers, independent researchers and many policymakers outside the process.

The distinction matters because the policy is not simply a general statement on AI safety. It is meant to establish the conditions under which the federal government can receive access to selected models before they are made available to other trusted partners. The arrangement could shape who evaluates highly capable systems, what security controls apply to that access and which models receive heightened government attention.

The White House has confirmed that the framework was completed by the deadline set in its June 2 executive order. However, the administration has not released a document explaining its definitions, eligibility thresholds, participating agencies, review procedures or oversight mechanisms. Reporting indicates that companies were given an overview in private meetings, but the final framework remains unavailable to the public.

What the executive order requires

The executive order directs several agencies to create a classified benchmarking process for assessing advanced cyber capabilities in AI models. That process is intended to identify the point at which a system becomes a “covered frontier model.” The order says those assessments may be shared with developers and researchers as appropriate, but it does not require the benchmark or its technical threshold to be public.

Alongside that classified process, the order calls for a voluntary framework negotiated with AI developers. Under it, companies can ask the federal government whether a model in development is likely to meet the covered-model designation. Developers may also give the government access to covered systems for up to 30 days before releasing them to other trusted partners.

The order explicitly says this arrangement is not a mandatory licensing, preclearance or permitting regime. Participation is therefore formally optional, and the government has not been granted a general power to block a model’s publication or distribution through this policy.

The framework is also expected to address practical safeguards. Those include confidentiality, cyber protection, insider-risk controls, intellectual-property handling, permitted use and nondisclosure obligations. These are material issues for developers: allowing government personnel to access a pre-release model could expose proprietary weights, capabilities research, safety measures and commercial plans if the process is not tightly controlled.

Secrecy extends beyond classified benchmarks

The administration has a strong case for withholding details that would reveal sensitive methods for testing AI-enabled cyber operations. Publicly disclosing exact capability thresholds could help malicious actors identify which functions the government considers most operationally significant. It could also encourage developers to optimise narrowly around a published test rather than address broader risks.

But the decision not to publish the voluntary framework creates a separate transparency question. The executive order explicitly makes the benchmarking process classified; it does not state that the operating framework must be secret. A White House official has described the framework as unclassified while saying that unclassified information need not be broadly disseminated.

That approach leaves important policy choices opaque. It is unclear how “state-of-the-art” capability and national-security risk will be applied in practice, which models qualify, whether only closed systems are covered, and which outside organisations can be selected as trusted partners. It is also unclear how smaller labs can determine whether they fall within the policy before investing in engagement with federal agencies.

Reports from the industry briefing indicate that open models are excluded from the framework and that it is intended for closed-source systems with leading-edge capabilities and national-security implications. If accurate, that division would make the policy a targeted channel for engaging a limited set of developers rather than a common standard for the broader AI ecosystem.

The trade-off between access and accountability

Early access could serve legitimate defensive purposes. Government cyber agencies may be able to assess whether advanced models can accelerate vulnerability discovery, automate parts of intrusion activity or assist defenders in identifying and remediating weaknesses. The June order also directs agencies to establish an AI cybersecurity clearinghouse intended to coordinate vulnerability scanning, validation, remediation and patch distribution with industry and critical-infrastructure operators.

Giving qualified public-sector specialists time with a model before a wider release may help match defensive preparations to rapidly changing capabilities. A narrowly designed programme could also enable agencies and developers to exchange information on risks without converting model review into a formal approval system.

The counterargument is that trust in such a system depends on more than confidentiality. External stakeholders need a clear understanding of the rules: who makes a coverage decision, how conflicts are managed, what security standards apply, how access is logged, how long records are retained and whether participants can challenge inconsistent treatment. Without published principles, it is difficult to assess whether the framework balances national security with competition, privacy, intellectual property and public accountability.

Secrecy may also create unequal access. The companies invited to private briefings can gain early clarity about expectations, while start-ups and civil-society groups must infer the policy from the executive order and press reporting. That does not necessarily make the framework ineffective, but it could make its implementation appear selective.

A contrast with public standards work

The federal government already has public, voluntary resources for managing AI-related risk. The National Institute of Standards and Technology’s AI Risk Management Framework was developed through open consultation, with drafts, workshops and public feedback. NIST has also been developing cybersecurity guidance that addresses three connected concerns: protecting AI systems, using AI in cyber defence and countering AI-enabled attacks.

Those NIST materials do not serve the same purpose as a national-security review channel for frontier models. They are broader guidance rather than a mechanism for pre-release government access. Nevertheless, they demonstrate that transparency can coexist with voluntary risk-management practice, even when the technical challenges are complex.

A workable White House approach could preserve classified capability testing while publishing the non-sensitive architecture of the voluntary framework. That could include high-level eligibility criteria, baseline access safeguards, governance responsibilities, principles for choosing trusted partners and a commitment to periodic public reporting in aggregate form.

What remains to be answered

The immediate question is whether the framework will remain a private arrangement between the government and a small group of leading labs, or become a more legible policy instrument. Its voluntary nature means its influence will depend on whether developers see useful value in participation and whether agencies can demonstrate that they can protect sensitive model access.

The White House has now met its procedural deadline, but completion is not the same as public clarity. Until the administration provides more detail, the public can see the policy’s direction—earlier engagement with certain advanced AI systems in the name of cybersecurity—without being able to evaluate the rules that will govern it.

Sources