Start the day here

World — Open Weights — White House

The Problem With Exempting Open Models From Security Review

Washington briefed AI labs on a voluntary cybersecurity review for closed frontier models, then left open-weight releases outside the line. That exemption lasted about a week before officials started walking it back.

A White House official told WIRED that open models will face the same pre-release scrutiny once they reach the cyber capabilities of leading closed systems. The change is expected in the coming months, not as a signed statute.

6 min read
Stacks of multicolored shipping containers under gantry cranes at a port terminal

The two-tier week

On August 4, administration staff presented the current framework to technology companies. Axios and POLITICO reporting from those briefings described a voluntary process aimed at closed, state-of-the-art U.S. models with national-security cyber risk: up to thirty days of federal evaluation, secure storage, detailed access logs. Open-source and open-weight systems were carved out entirely, regardless of capability.

That carve-out matched a louder White House line. The July 2025 AI Action Plan praised open weights for startups, on-prem privacy, and research, and told agencies to keep the environment friendly. The June national-security AI directive even told defense and intelligence shops to adopt advanced commercial and open-source tools, provided the deployments stay controllable.

Controllable is the word that broke the exemption. Once weights can be downloaded, forked, and run without the developer's keys, a thirty-day hold only matters before publication. Afterward, the government is left scanning mirrors and hoping.

Why the exemption looked clever

The original design had a political story attached. Closed labs such as OpenAI and Anthropic already negotiate early access with agencies; putting them in a review queue looked like seriousness without a new statute. Open builders, often smaller and louder about China competition, got a free pass that also kept American downloadable models moving against Chinese releases.

WIRED's sources now say officials worried the two-tier structure would discourage U.S. open development. Enterprise buyers could read the exemption as a quality gap: closed models got inspected, open ones did not. In that reading, the pass arrived dressed as generosity and functioned as a stigma.

What expands with the net

Bring open releases into the same review and you inherit every ambiguity already baked into the closed-model version. The capability threshold that triggers review remains undefined in public. Participation stays voluntary on paper. The full framework text is still withheld; WIRED separately reported that the administration finalized a cybersecurity plan and chose to keep details under wraps.

For an open-weight team, those blanks are calendars. A coordinated drop of weights, evals, and commercial products cannot absorb a surprise thirty-day pause the way a closed API can soft-launch behind a waitlist. Declining the review may still be legal. It may also mean losing federal buyers, contractors, and anyone who treats White House process as a procurement filter. We covered the first voluntary handoff fight in Will Labs Hand Over Models Before Launch?; the open-weight sequel simply widens who sits in that waiting room.

National Cyber Director Sean Cairncross has already talked about scanning and coordination for open-source systems. Semafor reported in mid-July that officials were weighing further open-model measures tied to China concerns. The exemption was never a permanent philosophy. It was a temporary sorting rule that collided with frontier cyber risk the moment open models started looking competitive.

The judgment

Exempting open models was a sorting trick dressed as industrial policy. Washington tried to run two programs on one stack: spread American weights as a geopolitical product, and retain a pre-release veto over systems that can autonomously hit military or financial infrastructure. You can market openness. You cannot download-proof a frontier cyber model after the torrent starts.

Expanding the review does not fix the secrecy. It only admits that capability, not license type, is the thing Washington cares about. Until the threshold is public, open builders still guess whether next month's release is a research drop or a federal hold. Closed labs already live in that fog. Open ones are about to join them with less room to ship around it.

Live scoreboardFollow the AI race on AI Wars

Lab rankings, model preference, API volume, coding-agent heat, open-source stars, and prediction markets.

Related stories

A crowded market table of colorful tin toy robots and miniature cars under bright daylightWorld

Europe Put Roblox Under Its Strictest Platform Rules

Today

A closed metal padlock stamped HARDENED resting on a backlit laptop keyboardWorld

Even OpenAI's Kill Switch Still Needs a Human

Today

White mathematical formulas and scientific diagrams packed onto a black chalkboard surfaceWorld

How a Private Harness Pushed Astra to 99.9% on ARC-AGI-3

Today

Letters

0

No letters yet.

Write a letter