According to a report by Reuters on August 3rd, Meta, Anthropic, Google, and OpenAI have been invited to meet with White House officials to discuss government security testing for the United States' most advanced AI models. However, until the eve of the meeting, the four companies still did not receive any details of the framework. Although the White House claimed that the framework was completed, it refused to disclose the testing metrics, methods for reporting results, and the scope of application.
This opacity not only makes it difficult for invited companies to assess the costs of participating in the tests, but it may also keep uninvited companies out of the rules. If the framework remains confidential, other AI companies might not even be able to determine whether their models meet the testing standards, how to apply to join, or whether they should participate “voluntarily”. A security mechanism that is nominally open to the industry could soon turn into an invitation-based system, where participants are selected by the government.
On the surface, this is just a safety test that enterprises can freely participate in. However, from the perspective of institutional design, the U.S. government is extending regulatory oversight until after the model is officially launched, through confidentiality standards, targeted invitations, and pre-launch testing.
In June this year, Trump signed an executive order requiring the National Security Agency, the Department of Homeland Security, the Department of Energy, and the US National Institute of Standards and Technology to establish a set of confidential testing standards for evaluating the cyber-attack capabilities of AI models. These standards will also determine which models are considered “fully covered frontier models”.
For models that fall within this range, developing companies can grant access to the government up to 30 days before the release. The government can not only test the models but also jointly decide with the companies which key infrastructure providers and “trusted partners” can use them in advance. The administrative order also emphasizes that this system should not be interpreted as a requirement for compulsory licenses, prior approvals, or the issuance of licenses.
Therefore, "submitting to government testing for 30 days before release" is currently not a mandatory requirement. In theory, businesses can refuse and do not need to wait for government approval before releasing products.
But the real barriers are often not written in the license.
Firstly, which models need to be tested will be determined by a set of confidential guidelines. The thresholds for coverage, indicators of attack capabilities, and some testing methods will not be made public, making it difficult for companies and the outside world to determine when a model crosses the regulatory threshold. Axios notes that the White House has not even made the full text of the completed voluntary framework available.
Secondly, once leading companies such as OpenAI, Google, and Meta join in, refusing to test could result in real costs. If models that have not been evaluated by government agencies cause serious cyber incidents in the future, the first question businesses will face is: Why wasn’t they tested in advance? The pressure from Congress, regulatory bodies, customers, and public opinion can make “voluntary” testing become a de facto “must-do”.
Government procurement may also reinforce this trend. OpenAI has previously recommended that federal agencies should not use cutting-edge models with unapproved security assessments in sensitive systems. If this recommendation becomes part of the procurement rules, government testing could not only serve as a proof of security, but might also become an invisible gateway to enter the public sector and critical infrastructure markets.
The White House is accelerating its actions at this time, which is directly related to the recent series of AI breaches. OpenAI revealed that its models exploited zero-day vulnerabilities during network capability tests, breaking into the isolation environment and subsequently infiltrating HuggingFace’s infrastructure. The company later clarified that the involved pre-release models were internal research prototypes, with no plans for public release. Anthropic also admitted that its models were able to gain access to systems of three companies during testing. This indicates that the risks associated with cutting-edge AI are no longer limited to generating false content; these models can autonomously find vulnerabilities, combine attack strategies, and carry out long-term network operations.
The Trump administration still refuses to establish a mandatory regulatory system similar to that of the European Union, as this could slow down the time it takes for American companies to release their models. However, through privacy standards, advance testing, and government procurement, the United States can also gain influence over the development of cutting-edge models, without having to bear the political costs associated with establishing an AI approval system.
This threshold currently has no walls or permits, and is even clearly marked as “voluntary”. However, as the government determines who needs to be tested, how to test them, and who can obtain models in advance, the rules for releasing advanced AI in the United States are beginning to be rewritten according to national security logic.