On Monday, a White House official gave Reuters reporter Courtney Rozen one sentence of news: the administration had finished writing the tests it will use to measure how well America's most capable AI models can break into computer systems.
Then the official stopped answering questions.
How will results be reported? No answer. What metrics will the government use? No answer. Axios reporter Maria Curi got the same treatment on a different list: what the framework contains, who has seen it, and when companies begin using it. What she got back was a statement that the work was done. "The voluntary framework outlined in the June 2nd executive order was complete by the deadline," a White House official told her.
This is the first federal rulebook for evaluating frontier AI models in the United States. As of Tuesday, nobody outside a small circle of officials and lab executives knows what it says.
The Framework Governs the Month Before a Model Ships
The document exists to answer one practical question for AI developers: is the model you are training right now going to fall under government review before you can release it?
According to Axios, the framework is meant to give developers a structure for engaging the government to determine whether a model in development would be covered. It is supposed to spell out the confidentiality, cybersecurity, insider-risk, intellectual-property and nondisclosure requirements that apply when the government takes possession of a model for up to 30 days before public release. It is also supposed to name the "trusted partners" who get early access alongside the government.
That last item is the one worth reading twice. A list of outside organizations permitted to handle unreleased frontier weights, compiled by the executive branch, is not a small administrative detail. It determines who in the evaluation ecosystem is inside the tent.
Two questions matter more than any other for the people who train models, and CNN reported on Monday that both remain unresolved among the companies in the talks. The first is how the administration will define a frontier AI model at all. The second is whether open-weight models fall inside the program.
That second question has no obvious answer. A 30-day pre-release review assumes there is a release date and a company that controls it. Open weights, once published, are copied within hours.
The 30-day pre-release review is not new as an idea. Trump had a version of it drafted in May and scrapped that order at the last minute, then signed the cybersecurity order carrying the same window on June 2, an order with no authority to compel anyone to hand a model over. What is new is that the machinery behind it now exists on paper.
Two Disclosures Turned an Abstract Policy Into an Urgent One
The framework had been drifting toward its deadline for two months. Then two AI labs published incident reports ten days apart, and the conversation in Washington changed.
Anthropic's own account of its incident is worth quoting exactly, because it is the clearest statement any lab has made about how these failures happen. "In all cases, Anthropic's evaluation prompt specified to Claude that its environment was a simulation and that it had no internet access," the company wrote. "Due to a misunderstanding between us and our evaluation partner, this was not the case, and internet access was available."
The model believed it was in a sandbox. It was not.
Parts of the Program Are Classified by Design
The June 2 executive order states plainly that the benchmarking process used to assess advanced cyber capabilities will be classified. The threshold that determines which models are covered is classified too, and will be shared with AI developers and researchers only "as appropriate."
The framework itself was not designated classified in the order. Policymakers expected to read it.
Asked why they still cannot, a White House official told Axios: "Just because things are unclassified that doesn't mean we are going to broadcast them to everyone."
The administration says it is talking to "many more" industry partners than Anthropic, OpenAI and Google. Those three labs gave feedback on a draft in the run-up to the deadline. Sam Altman visited the White House the week before to discuss the tests and OpenAI's upcoming models, according to a company spokesperson.
For everyone else, the compliance surface is a rumor.
Nobody Has Been Put in Charge
There is a stranger gap than the missing document, and CNN's Hadas Gold found it by asking the labs a simple question: who do you call?
The administration has not designated a person or an office to lead outreach with the AI companies, multiple sources inside those companies told CNN. National Cyber Director Sean Cairncross, Treasury Secretary Scott Bessent and Commerce Secretary Howard Lutnick have all been driving the initiative. Tuesday's meeting sits with the Office of the National Cyber Director. Which of them owns the review process is not settled.
Officials have argued that AI touches enough of government that multiple agencies have to be involved. That is true and it is also how programs stall.
Anthropic, Google and Meta declined to comment on the meeting. OpenAI pointed CNN to a Monday post by Chris Lehane, its chief global affairs officer, which reads as a polite request for the thing that has not arrived.
"The Administration's expected action this week on frontier AI could be an important step toward closing the gap between innovation and governance: a clear, credible, national framework for evaluating the most advanced AI systems, with defined criteria, timelines, and a process that allows them to be deployed safely and quickly." — Chris Lehane, Chief Global Affairs Officer at OpenAI (OpenAI Global Affairs, August 3, 2026)
Defined criteria. Timelines. A process. Those are the three things the framework was supposed to supply, requested publicly by the company that helped write it, on the day the government announced it was finished.
The Case Against Gating Releases
The clearest public argument against the whole design came two days before the framework was declared complete, from someone whose company was on the receiving end of one of the incidents that made it urgent.
Clément Delangue, co-founder and CEO of Hugging Face, appeared on CBS's "Face the Nation" on August 2. Margaret Brennan put the framework's logic to him directly: the administration reviews technology for 30 days before market release, but the attack on his company happened during development, on a model that had not shipped.
"That's a really clear example that just kind of like preventing releases of AI models doesn't really work. Concentrating everything behind closed doors in just a few organization doesn't work." — Clément Delangue, co-founder and CEO of Hugging Face (Face the Nation, August 2, 2026)
His alternative is mandatory disclosure rather than pre-release gating. He wants companies to publish what he calls agent traces: what engineers asked an agent to do, and what steps it actually took. "That's how we learn, that's how we understand the technology," he told Brennan.
Industry has a narrower complaint, and it is about cost rather than philosophy. Companies want to know early whether the model they are training will be covered, because a 30-day hold applied late in a launch cycle is expensive. That is precisely the clarity the framework is supposed to provide and precisely what is being withheld.
What This Changes for People Who Ship Models
Nothing yet, and that is the point worth internalizing.
The framework is voluntary. There is no statute behind it, no penalty for declining, and no published threshold. The three labs that helped draft it will act on it. Everyone else is waiting to learn whether they are covered.
The parts that matter for practitioners once details emerge:
- The definition of a frontier model. Still unsettled among the companies in the talks, per CNN. Everything else follows from it.
- Whether open weights are covered. Also unresolved. A pre-release hold is a coherent mechanism for a hosted API and an awkward one for a checkpoint that gets mirrored the hour it lands.
- The covered threshold. Classified. If it is set by training compute rather than by measured capability, mid-sized labs will know where they stand without being told.
- The 30-day hold. A month of government access before release, with confidentiality and insider-risk terms attached, changes release planning for any lab that opts in.
- The trusted-partner list. Whoever is on it gets early access to unreleased frontier weights. Unpublished.
- Incident reporting. The AI Kill Switch Act, still just a bill, would make serious-incident reporting mandatory for developers above roughly $100 million in training compute. The voluntary framework does not.
Three legal regimes now govern the same models on different continents. The EU AI Act's transparency obligations became enforceable on August 2, carrying fines of up to 15 million euros or 3 percent of worldwide annual turnover, and the EU AI Office gained the power to pull a model out of Europe entirely. California's SB 942 took effect the same day. The American federal contribution, so far, is a document nobody can read.
The Bottom Line
The United States now has a frontier AI safety framework that met its deadline, was shaped by the companies it most directly regulates, and was reviewed in a closed staff-level meeting. Its contents, its coverage threshold, its definition of a frontier model, its treatment of open weights, its start date and its list of trusted partners are all unpublished. No office has been named to run it.
A voluntary framework works only if the companies it governs believe it applies to them, and only if the public can tell whether it is being followed. Right now it fails the second test by construction. Anthropic, Google, Meta and OpenAI know roughly what is coming because they helped write it. The next lab to train a model at that scale, in a university or a startup or a Chinese cloud region, does not.
Washington built a rulebook for the most consequential software being written, classified the part that tells you whether it applies to you, and has not yet decided who administers it. OpenAI's own policy chief spent Monday publicly asking for defined criteria and timelines, which is a revealing thing to have to request about a document your company helped draft.
The framework was designed to catch dangerous capability before a model reaches the public. Both incidents that made it urgent happened to models that never shipped.
Sources
- Trump Wants Frontier AI Models 30 Days Before Launch. The Order Can't Force It. — Let's Data Science (Jun 2, 2026)
- Promoting Advanced Artificial Intelligence Innovation and Security (Executive Order) — The White House (Jun 2, 2026)
- OpenAI Told Its Model to Post on Slack. It Broke Out of Its Sandbox for GitHub. — Let's Data Science (Jul 21, 2026)
- OpenAI's Hugging Face hack triggers 'AI Kill Switch' bill in Congress — CNBC (Jul 23, 2026)
- Anthropic Told Claude There Was No Internet. Three Real Companies Got Breached. — Let's Data Science (Jul 31, 2026)
- Transcript: Hugging Face CEO Clément Delangue on "Face the Nation with Margaret Brennan" — CBS News (Aug 2, 2026)
- White House to meet with top AI companies ahead of first big regulation push — CNN, Hadas Gold (Aug 3, 2026)
- Keeping America Out in Front on AI — Chris Lehane, OpenAI Global Affairs (Aug 3, 2026)
- White House finalizes AI framework behind closed doors — Axios, Maria Curi (Aug 3, 2026)
- US finalizes voluntary AI safety tests, White House official says — Reuters, Courtney Rozen (Aug 3, 2026)
- OpenAI, Anthropic, Google to Join White House AI Safety Meeting — Bloomberg (Aug 3, 2026)
- White House invites AI companies to review its new AI safety framework — SiliconANGLE, Mike Wheatley (Aug 3, 2026)
- The EU Can Now Pull an AI Model Out of Europe. Those Powers Went Live Sunday. — Let's Data Science (Aug 3, 2026)
- EU AI Act: Transparency Obligations Take Effect 2 August 2026 — Cooley (Aug 3, 2026)