Key Takeaways:
- White House finalized voluntary AI security framework by Aug. 3 deadline
- Review covers closed-source frontier models, excludes open-source systems
- Framework kept secret; benchmarking process classified under executive order
Key Takeaways:

The White House finalized a voluntary framework to review advanced AI models for security risks, but kept the rules secret and limited them to closed-source systems, leaving open-model developers outside government oversight.
"The voluntary framework outlined in the June 2nd executive order was complete by the deadline," a White House official said. "Discussions with industry about next steps are underway," the official added, saying the administration is engaging with "many more" industry partners than just Anthropic, OpenAI and Google.
The framework defines a covered frontier model as closed-source with state-of-the-art capabilities and national security risks, according to multiple sources briefed on meetings held at the White House. There is no clear definition of what constitutes state-of-the-art or a national security risk. Open models are excluded, and the framework explicitly says nothing in it should be interpreted as restricting open models once they've been released.
During the 30-day pre-release government review period, employees would be limited from accessing models. Models would be stored in high-security environments with detailed logs on who accesses them, and the review process would involve various administration officials rather than a single office or agency.
Why the secrecy matters
The executive order explicitly says the benchmarking process to assess advanced cyber capabilities of AI models will be classified. The threshold for which models are covered is also classified and will only be shared with AI developers and researchers "as appropriate." The order does not similarly designate the voluntary framework as classified, and policymakers and observers expected to see details.
"Just because things are unclassified that doesn't mean we are going to broadcast them to everyone," the White House official said.
The White House on Tuesday held staff-level meetings with industry to review the framework, and companies that weren't invited remain in the dark about its contents. It's also unclear which "trusted partners" will get early access to advanced models, including whether any foreign governments would qualify.
Who benefits, who loses
For closed-source developers such as OpenAI, Anthropic and Google, the framework introduces a new compliance layer before release — even though it is voluntary, it sketches the shape of future mandatory rules. Companies with less advanced systems appear likely to be left out of the framework, sources said. Companies were encouraged to share models as close to public release as possible rather than early-stage ones.
For open-source developers, the exclusion removes a potential regulatory hurdle, though the classified threshold means no developer can be certain whether its next model falls under the framework. The lack of a public definition creates uncertainty across the industry, with companies seeking clarity early so they know whether models under development are likely to be covered.
The framework is being closely watched beyond the industry players it directly applies to. Policymakers, AI safety advocates and U.S. allies have been waiting to see what the rules for the most powerful models in the world look like. The White House has not said when companies will start using the framework, which partners will get early access, or whether the review process will eventually become mandatory — leaving the industry to price in an unknown compliance cost ahead of the next model releases.
This article is for informational purposes only and does not constitute investment advice.