The White House finalized a voluntary cybersecurity framework for advanced AI models following a June 2026 executive order, which directed the creation of a benchmarking process to assess AI cyber capabilities within 60 days [1, 2].

Under the new framework, AI companies can submit new models to the government for cybersecurity review up to 30 days before public release, though participation is optional [1, 3, 2]. A classified benchmarking process will evaluate the cyber risks of submitted AI models, but the government has refused to disclose the testing criteria or which models are covered [1, 3, 2].

On August 4, 2026, the White House held a staff-level briefing with AI industry leaders including OpenAI, Anthropic, Google, Meta, and Nvidia to present the completed framework [1, 3, 2]. Despite this, many AI developers and the public remain in the dark about the framework’s specifics. Open-source models are reportedly excluded from review under the framework [1, 3, 2].

The White House has not clarified which "trusted partners" receive early access to the framework’s details or whether foreign governments are involved [1, 2]. Officials cite national security concerns and the need to protect classified cyber capabilities as reasons for maintaining secrecy around the program [1, 3].

Some AI safety advocates and smaller startups have criticized the lack of transparency. An anonymous insider said, "They're essentially creating an entrenchment program for the big AI model providers, which are now considered the most frontier. This creates an economic incentive program for critical infrastructure just to use them and leaves out smaller startups" [3]. Brad Carson, president of the nonprofit American, added, "This is far too important an issue to be hidden behind a cloak of secrecy" [3].

The framework’s requirement for companies to submit AI models for voluntary cybersecurity vetting up to 30 days prior to public release aims to reduce risks from AI’s cyber capabilities but stops short of a mandatory regime [1, 3, 2]. The government’s next step will likely involve implementing the classified benchmarking process to assess submitted models.