A framework moving beyond closed models
The White House is expected to broaden its approach to frontier artificial intelligence, potentially bringing powerful open models into a voluntary federal security framework that initially focused on systems controlled by leading US laboratories. Reporting by WIRED on August 12 said officials were likely to revise the arrangement in the coming months as openly available models approach the cyber capabilities of the most advanced proprietary systems.
The distinction matters. A closed model is generally accessed through a provider’s service, allowing the developer to control distribution, monitor use and update safeguards. Open models make their underlying parameters more widely available, enabling companies, researchers and developers to run and adapt them independently. That can lower costs and widen access, but it also reduces the original developer’s practical ability to restrict downstream use.
The reported expansion is therefore not simply a technical amendment. It addresses a central gap in a policy designed around the idea that the highest-risk capabilities would remain concentrated in a small number of commercial providers. If comparable capability can be downloaded, modified or hosted outside those providers’ systems, an oversight model confined to closed products becomes less complete.
What the executive order already requires
The policy has an official foundation in Executive Order 14409, issued on June 2, 2026. The order directed federal agencies to create a classified benchmarking process for assessing advanced cyber capabilities and deciding whether a system qualifies as a “covered frontier model”. It also required them to design a voluntary framework through which developers could consult the government, provide secure access to covered models for as long as 30 days before release to other trusted partners, and work with the government on early access for cybersecurity purposes.
The order explicitly rejects a mandatory licensing, pre-clearance or permitting regime for AI models. That limitation is important: participation may influence market expectations and government relationships, but it is not a legal condition for developing or publishing a model.
The White House has also tied the framework to a wider cyber-defence agenda. The order called for an AI cybersecurity clearinghouse involving industry and critical-infrastructure operators, intended to coordinate the discovery, validation and remediation of software vulnerabilities. Its premise is that highly capable models could strengthen defensive security work while also making sophisticated offensive cyber activity easier.
The reported framework itself has not been published. As a result, important operational questions remain unanswered, including the exact capability threshold, how testing would be conducted, which agencies would gain access and what information, if any, would be disclosed to the public.
Why open models complicate the policy
Applying the same approach to open models would be difficult. A voluntary pre-release evaluation can be meaningful before a developer distributes a model’s parameters widely. Once that happens, copies can be replicated and adapted by third parties, including outside US jurisdiction. A later withdrawal, patch or service restriction is far less feasible than it is for a model delivered through a centralised cloud service.
At the same time, treating open models as inherently more dangerous would create policy and commercial trade-offs. Open releases support research, allow businesses to deploy models in more controlled local environments, and give smaller organisations alternatives to paid access to dominant providers. A regime that confers a recognised security status only on closed systems could encourage customers to favour large proprietary platforms, regardless of whether an open alternative is suitable and secure for a particular use.
WIRED reported that officials were considering this risk of a two-tier market, while also recognising that a 30-day testing period could slow development. The tension reflects the broader challenge facing the administration: a framework meant to provide security assurance can become a market signal, even where it is formally voluntary.
An innovation-first policy acquires safeguards
The possible expansion illustrates a shift in emphasis rather than a wholesale reversal. The administration’s March national AI legislative framework presented AI as an economic and strategic competition, arguing for a nationally uniform approach rather than differing state rules. It paired that objective with proposals concerning child protection, intellectual property, energy and infrastructure, free speech, and workforce development.
In June, the administration went further in the national-security sphere. A presidential memorandum instructed the national security enterprise to accelerate adoption of commercial and open-source AI while ensuring that systems are reliable, controllable and subject to clear accountability. It also required testing, evaluation, validation and verification for AI systems used across that enterprise.
Together, these measures show that the federal approach is not one of non-intervention. Instead, it uses procurement, national-security policy, cybersecurity coordination and voluntary industry arrangements rather than a general AI licensing law. That distinction may be politically significant, but it can be less clear in practice for companies whose access to government contracts, security partnerships or early technical guidance depends on cooperation.
The test is transparency and implementation
The next step will determine whether this becomes a credible system of assurance or mainly a private coordination mechanism between the government and the largest AI developers. Classified cyber benchmarks may be justified where disclosure would reveal sensitive defensive methods. Yet excessive secrecy would make it hard for smaller developers, customers, researchers and the public to understand which models are covered, what standards apply and whether participation has meaningful consequences.
A workable expanded framework would need to distinguish among model capabilities, modes of distribution and realistic mitigations. A model that is openly distributed cannot be governed in the same way as a centrally hosted service. Conversely, excluding open models purely because enforcement is harder could move high-capability development outside the framework’s intended perimeter.
For now, the proposed extension remains reported rather than formally announced. Its significance lies in the direction of travel: the White House is attempting to preserve rapid AI development while building a security process that reaches the technologies most capable of changing the cyber-risk landscape. Whether a voluntary, partly confidential system can do both will depend on the technical criteria, the willingness of developers to participate and the degree of public accountability built into its implementation.
Sources
- The White House Is Going to Expand Its AI Policy — WIRED
- Promoting Advanced Artificial Intelligence Innovation and Security — The White House
- National Security Presidential Memorandum/NSPM-11 — The White House
- President Donald J. Trump Unveils National AI Legislative Framework — The White House



