The White House Finished Its Frontier AI Review Framework—But Hasn’t Published It
The United States now has a voluntary path for pre-release review of the most cyber-capable models. The public still cannot see the framework that defines how that path works.

Sources: White House Executive Order 14409, Axios reporting on the completed framework, OpenAI statement on federal AI safety discussions.
The White House says it completed a voluntary framework for reviewing advanced AI models by its early-August deadline. The process was ordered in June as part of a broader cybersecurity initiative and is intended to help developers determine whether a model qualifies as a “covered frontier model.”
What the public knows comes mostly from Executive Order 14409 and reporting by Axios. A covered developer may give the federal government access to a model for up to 30 days before release to trusted partners. The order calls for confidentiality, cybersecurity, insider-risk, intellectual-property, use, and nondisclosure protections. The administration has not published the completed framework or explained when participation will begin.
The review is voluntary, but the stakes are real
The executive order explicitly says the process does not create mandatory licensing, preclearance, or a permit to release AI models. That distinction matters. A voluntary review is cooperation between labs and government, not a general legal power to approve every new model.
Even so, participation can shape market access and expectations. If the largest labs use the process, enterprise buyers, insurers, infrastructure operators, and foreign governments may begin treating government-tested models differently. A voluntary framework can become a de facto standard long before Congress writes a binding one.
Some secrecy is defensible; total opacity is not
The order makes the benchmarking process and capability threshold classified. Publishing a detailed cyber test could teach attackers what evaluators measure or how to train around a boundary. The government also has to protect unreleased model weights, technical findings, customer data, and commercial secrets.
But operational secrecy does not require silence about governance. The public can reasonably ask who is eligible to test models, how conflicts of interest are handled, what evidence a lab receives, whether failed mitigations are documented, and how a trusted early-access partner is selected. Those rules can be described without exposing an exploit or a model.
A 30-day window needs disciplined testing
A month is short for evaluating a model that may behave differently across tool access, scaffolds, fine-tunes, and deployment settings. Reviewers will need repeatable tests, secure infrastructure, incident escalation, and clear limits on what conclusions the evidence supports.
The most useful output would not be a binary “safe” stamp. It would be a scoped assessment: which configurations were tested, which capabilities appeared, which mitigations were verified, what uncertainty remains, and what monitoring is required after release. Buyers should be wary if a limited government evaluation is later marketed as a blanket guarantee.
Transparency is part of resilience
Frontier-model testing is meant to reduce national-security risk, but public legitimacy matters too. A framework designed only in conversations between government officials and a few dominant labs could entrench those companies and leave smaller researchers unsure how the rules apply.
The next step should be publication of the unclassified governance layer: scope, roles, appeal paths, reporting expectations, and aggregate results. Sensitive benchmarks can stay protected. The rules governing who gets trusted, what gets recorded, and how mistakes are corrected should not disappear behind the same door.
Quick questions
Does the White House approve AI models before release?
No. Executive Order 14409 describes a voluntary framework and explicitly says it does not create mandatory licensing, preclearance, or permitting for new AI models.
How long can the government receive early model access?
The order allows participating developers to provide access to covered frontier models for up to 30 days before release to other trusted partners.
Why is part of the testing classified?
The covered-model threshold and cyber benchmarking process can reveal sensitive capabilities and evaluation methods. Governance details can still be published without disclosing operational tests or vulnerabilities.