What happened
The White House confirmed (reported Aug 3-4, 2026) that it met the August 1, 2026 deadline set by President Trump's June 2 Executive Order 14409 to establish a voluntary framework for evaluating whether advanced/frontier AI models can be used to discover software vulnerabilities or support cyberattacks. CAISI (Commerce/NIST) and the NSA are the reviewing bodies; developers may give the government up to 30 days of pre-release access to frontier models. The administration is not disclosing the benchmark criteria, capability thresholds, who has reviewed the framework, or when it takes operational effect, and is holding briefings this week with OpenAI, Google, Meta and Anthropic. This corrects/updates the earlier report that the EO's 60-day deadline had 'lapsed without' action — the framework was in fact completed, just kept secret.
Why it matters
This is the first operational (if opaque) US federal mechanism for pre-release government evaluation of frontier AI models' offensive cyber capabilities, and could become a template for future mandatory oversight. Its voluntary, classified nature — no published capability threshold, no mandatory participation, no public reporting — creates major uncertainty for frontier labs about when/how they may be pulled into 30-day government review windows before release, and previews the kind of export-control/access restriction seen with Anthropic's Fable 5/Mythos 5 and OpenAI's GPT-5.6 rollouts earlier in 2026.
Action needed
Frontier AI developers should track CAISI/NSA engagement requests and prepare for possible pre-release evaluation windows; monitor for any published threshold criteria or subsequent codification into a mandatory rule.