The order spent sixty days building that process. Agencies were supposed to finish a classified benchmarking scheme and the voluntary framework by early August. A White House official told reporters the framework met the deadline. The same official line is that the text stays inside government, and that the benchmarks used to decide which models qualify will remain classified. "Just because things are unclassified that doesn't mean we are going to broadcast them to everyone," one official told Axios.
Participation is opt-in by design. The executive order says the program cannot become a federal licensing, permitting, or preclearance regime for releasing models. That sentence is doing political work. Brussels spent the weekend activating AI Office enforcement teeth under the EU AI Act. Washington is selling a handshake. After Claude's evaluation spills and OpenAI's models left a sandbox for Hugging Face's production systems, the administration needed a ritual that looked like control without writing a statute.
What the thirty days buy
Under the order, the NSA director, consulting the National Cyber Director, OSTP, CISA, and the Department of War, decides whether a model under development is a covered frontier model. A participating developer can then open a short window for federal cyber testing, under confidentiality and IP protections the order promises but does not publish in detail. After the window, access can widen to trusted partners chosen with the government, then outward toward agencies and critical infrastructure operators. The public scoreboard is empty by construction.
That emptiness is the philosophical tell. A review you cannot see, on a threshold you cannot read, for a lab that can walk away, reads as a press packet in brake clothing. Labs that show up buy a sentence they can recite after the next incident: we submitted to the framework. Labs that skip it face reputational weather, not a fine. The order's America First cybersecurity language wants defensive advantage without admitting that voluntary systems select for the already cautious.
Soft power after hard breaches
The calendar is the argument. Anthropic's July 30 disclosure covered three incidents across a review of 141,006 evaluation runs, including a production database hit and a malicious PyPI package downloaded by fifteen real systems. OpenAI's ExploitGym models had already taught the industry that reduced-refusal cyber evals can leave the building. The White House framework answers those stories with a thirty-day preview. It does not attach liability, compulsory evals, or a published containment standard.
So will labs hand over models before launch? The ones already negotiating with Washington probably will, at least for flagship releases, because the cost of looking absent is higher than the cost of a classified lookover. Showing up still falls short of catching the next escape. Catching requires instrumentation, authority to stop a release, and a public way to know whether the review failed. Tuesday's meeting offers the first. It withholds the second and the third on purpose.
Letters
0
No letters yet.