White House AI Framework Is Done. It Won’t Say What’s In It

The White House says its voluntary AI framework for frontier models is complete. It won't say what's in it, who's seen it, or when companies start using it.

White House AI Framework Is Done. It Won’t Say What’s In It

The White House says its AI framework is done. It won’t say what’s in it.

Officials confirmed Monday that the voluntary AI framework required by the June executive order is complete, per The Next Web.

What the AI framework contains, who has seen it, and when companies will start using it are all still unanswered.

The AI framework is the mechanism that decides which models count as covered frontier models under the order. Those models get a 30-day government review window before release to trusted partners.

The benchmarks used to assess cyber capabilities are classified. The threshold for coverage is classified too, shared only with developers as appropriate.

What the AI framework actually says

Nobody outside the government knows. The framework itself isn’t designated classified, but the White House isn’t making it public.

A White House official said the voluntary AI framework outlined in the June 2nd executive order was complete by the deadline, and that discussions with industry about next steps are underway.

Here’s the operative detail. The executive order explicitly says the benchmarking process to assess advanced cyber capabilities will be classified. The threshold for which models are covered under the order is also classified.

OpenAI, Anthropic, and Google provided feedback on a draft. A staff-level meeting with companies is scheduled for Tuesday.

The Next Web notes the administration is engaging with many more industry partners beyond those three.

What does a covered frontier model designation actually trigger? Under the order, the government gets access to the model up to 30 days before the developer plans to release it to trusted partners.

That’s the window where the AI framework’s classified benchmarks get applied.

The developer doesn’t get to see the test, just the verdict. If the model clears review, it ships. If it doesn’t, the release stalls while the lab argues with an evaluator it can’t inspect.

That dynamic is the whole story. A voluntary review that a company can’t audit isn’t voluntary in any meaningful sense, and the AI framework makes that structure permanent.

Here’s what I’ll be watching at Tuesday’s meeting. Whether the companies get to see the benchmarks after review, whether the thresholds move, and whether anyone pushes to make the framework itself public. So far the White House has given no indication any of that happens.

The de facto gate nobody can challenge

Trump’s June executive order framed the review as voluntary. The combination of classified benchmarks, undisclosed thresholds, and a 30-day preview window creates a de facto gating mechanism that companies can’t publicly evaluate or challenge.

A framework nobody outside government can read, built on benchmarks nobody outside the NSA can see, is the transparency question at the center of this whole fight.

This is the machinery that has been circling frontier labs all summer. After the rogue agent incidents and Anthropic’s hack disclosures, the government’s answer is a classified review process.

That review is run by the NSA.

The NSA director determines which models qualify as covered frontier models, in consultation with the War Department, the National Cyber Director, and CISA.

Why this matters to anyone using frontier models

The AI framework sits alongside Gold Eagle, the White House’s AI-powered cyber defense program launched this month. Gold Eagle finds vulnerabilities.

The AI framework decides which models are powerful enough to require government review before release. Together they’re the enforcement spine of the executive order.

For builders, the practical effect is still unclear because the thresholds are secret. You don’t know if the model you’re building on is a covered frontier model until the government tells you.

The order does say nothing in it creates a mandatory licensing or preclearance requirement. But a voluntary AI framework with classified thresholds is a strange kind of voluntary.

There’s a timing wrinkle worth noting. The executive order gives agencies 60 days to build the classified benchmarking process, which put the deadline at August 1.

The White House now says the AI framework was complete by the deadline, per The Next Web. Nobody outside the building can confirm what that means, because the deliverable isn’t public.

The transatlantic angle makes this bigger. The EU AI Act enforcement powers went live the same weekend, and Brussels can now inspect models and fine labs up to 3% of global revenue.

American labs face two governments demanding pre-release review from opposite sides of the Atlantic, each with its own thresholds, timelines, and penalties.

Here’s my read. A classified AI framework might be the right call for genuinely sensitive cyber benchmarks. The problem is I can’t verify that, because nobody outside the government can see the benchmarks, the thresholds, or the framework itself.

The White House says the voluntary AI framework is complete. That’s the only fact I’ve got. Everything else about the most consequential review process in AI right now is a secret, and that’s exactly the point.

Tony Simons

Reviewed & Written By

Tony Simons

Independent tech reviewer and creator of Tony Reviews Things. 14 years of hands-on testing, software auditing, and workflow automation. I test the gear so you don't waste your money on junk.

Submit a Take

Your email address will not be published. Required fields are marked *