IAPS Urges Federal Action to Secure Frontier AI Models

The Institute for AI Policy and Strategy (IAPS) published a May 14, 2026 policy memo, "After Mythos: A National Security Playbook for Frontier AI," recommending that federal agencies secure frontier AI model weights and expand cyber-defense automation, according to PYMNTS and the memo itself. The memo, by researchers Joe O'Brien, Brianna Rosen, and Christopher Covino, cites the cyber capabilities of Anthropic's Mythos Preview model and OpenAI's GPT-5.5 as evidence: "Risks beyond cyber, including biosecurity threats, are likely to emerge without additional safeguards." Notably, many of its asks overlap with Executive Order 14409, which President Trump signed on June 2, 2026, creating a voluntary framework for early federal access to "covered frontier models" and directing agencies to accelerate AI-specific cyber defenses.
For teams operating or securing frontier AI systems, the notable part of this story is not just a policy research memo's wishlist: many of its core recommendations, including expedited frontier-model security standards and early government access to models that cross a capability threshold, appeared roughly three weeks later in a real executive order. That gives the memo predictive weight for practitioners tracking where federal AI-security requirements are headed.
What happened
The Institute for AI Policy and Strategy (IAPS), a nonprofit AI policy research organization, published a May 14, 2026 policy memo titled "After Mythos: A National Security Playbook for Frontier AI," authored by researchers Joe O'Brien, Brianna Rosen, and Christopher Covino, according to PYMNTS reporting and the memo itself. The memo argues that the cyber capabilities Anthropic disclosed in its Claude Mythos Preview model, and similar capabilities OpenAI's GPT-5.5 reportedly demonstrated, justify a coordinated federal security response: "Risks beyond cyber, including biosecurity threats, are likely to emerge without additional safeguards," the authors wrote. The memo lists ten recommendations across four areas: securing model weights and datacenters (including a new NSA industry partnership modeled on its AI Security Center), expanding intelligence collection on adversary AI capabilities, scaling automated cyber defense, and building federal capacity such as a National AI Reserve Corps and statutory authority for NIST's Center for AI Standards and Innovation (CAISI).
Timeline
Anthropic began giving select partners early access to its Claude Mythos Preview model to identify vulnerabilities before wider release.
IAPS published its "After Mythos" policy memo recommending federal action to secure frontier AI models.
Anthropic said its Mythos Preview model had surfaced more than 10,000 cybersecurity vulnerabilities.
President Trump signed Executive Order 14409, "Promoting Advanced Artificial Intelligence Innovation and Security," directing agencies to accelerate AI-specific cyber defenses and establish a voluntary framework for early government access to covered frontier models.
Regulatory context
The memo's recommendations substantially overlap with Executive Order 14409: both call for accelerating AI-specific cyber defenses, a voluntary mechanism for government access to models that cross a capability threshold, and stronger enforcement against criminal misuse of AI for hacking. The order stops short of several IAPS asks, however. It does not create the National AI Reserve Corps IAPS proposed, does not give CAISI the statutory authority and roughly $84 million in annual funding IAPS requested, and does not mandate the third-party evaluation ecosystem the memo calls for; those remain open policy questions.
For practitioners
Frontier labs and downstream deployers should expect the voluntary early-access mechanism in Executive Order 14409, up to 30 days of government access to models the NSA designates as "covered frontier models," to become a real compliance touchpoint, alongside emerging federal guidance on agent identifiers for tracking and revoking autonomous-agent permissions. Teams building agentic systems should also watch CAISI's evaluation remit, which IAPS wants expanded to cover loss-of-control risks and AI-driven R&D automation, since standards set there are likely to shape future model-release and procurement requirements.
What to watch
Key signals to track: whether Congress appropriates the roughly $84 million IAPS wants for CAISI's statutory authority, whether OMB and NIST publish the agent-identifier guidelines both EO 14409 and the IAPS memo call for, and how many frontier developers opt into the voluntary covered-frontier-model access framework once the order's 60-day implementation windows close.
Editorial analysis
That an executive order landed within three weeks of the memo's most substantive asks does not necessarily mean IAPS drove the policy; both plausibly responded to the same underlying signal, Anthropic's Mythos disclosure and GPT-5.5's cyber capabilities. But the overlap is a useful practitioner signal in its own right: memos from frontier-security-focused AI policy research organizations are increasingly a leading indicator of near-term federal AI-security requirements, not just advocacy.
Key Points
- 1The Institute for AI Policy and Strategy urged federal agencies to secure frontier model weights and expand AI-specific cyber defenses in a May 14 memo.
- 2Many of the memo's recommendations overlap with Executive Order 14409 (June 2), creating a voluntary framework for early government access to frontier models.
- 3Frontier labs and agentic-system builders should watch for federal agent-identifier guidance and expanded third-party evaluation standards emerging from CAISI.
Scoring Rationale
Notable policy story with unusually concrete follow-through: IAPS's May 14 memo recommendations substantially overlap with Executive Order 14409 (signed June 2, 2026), which creates a real voluntary framework for federal access to covered frontier models and directs agencies to accelerate AI-specific cyber defenses. Directly relevant to frontier labs and practitioners tracking upcoming compliance requirements; kept below major-tier since the EO stops short of several IAPS asks (CAISI statutory authority, National AI Reserve Corps).
Sources
Public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems

