Articles

US Frontier AI Review Rules: 30-Day Window Explained

The White House is finalizing a voluntary framework giving federal agencies up to 30 days to screen frontier AI models before release. Here's what's in it.

Chisato Chisato · · 5 min read
Glowing purple neural network fibers representing a frontier AI model

The US government is close to putting a screening gate in front of the most capable AI models. According to reporting this week, the White House is finalizing a voluntary framework with OpenAI, Anthropic, and Google that would let federal agencies review a new frontier model for national-security risks for up to 30 days before it reaches the public. The framework stems from an executive order signed on June 2, 2026, and officials are racing to publish it before an August 1 statutory deadline.

What the framework does

The framework is the operational layer beneath Executive Order 14409, titled “Promoting Advanced Artificial Intelligence Innovation and Security.” Rather than impose a licensing regime, it sets up a process AI developers can opt into: a company building a model can ask the government to determine whether that model crosses a capability threshold, and if it does, provide federal evaluators access for a review period of up to 30 days before public release.

Three pieces anchor the design:

  • A 30-day preview window. Once a model is designated a “covered frontier model,” the developer can grant federal evaluators early access to test it for cyber and national-security risk before launch. Participation is voluntary, and the window is a ceiling, not a mandatory hold.
  • Classified NSA benchmarking. Within 60 days of the order, the NSA, CISA, NIST, Treasury, and other agencies must build and maintain a classified benchmarking process to measure a model’s advanced cyber capabilities and decide when it qualifies as “covered.” The benchmarks themselves are not public.
  • An AI cybersecurity clearinghouse. Treasury was directed to stand up a clearinghouse to coordinate vulnerability scanning, validate flaws, and prioritize patching in voluntary cooperation with AI labs and critical-infrastructure operators.

Crucially, the order explicitly bans mandatory licensing, preclearance, or permitting for building or releasing AI models. The whole structure is opt-in — a point the administration has stressed to keep the framework on the “innovation-first” side of the ledger.

The August 1 deadline

August 1, 2026 marks 60 days from the order’s signing — the point by which the NSA must finalize its classified benchmarking process for designating covered models, and the multi-agency group must publish the formal voluntary framework governing how reviews run. That deadline is why the story is live now: the negotiation over the framework’s fine print is happening against a hard clock roughly a week out.

The sticking point: what counts as “frontier”

The hardest part of the negotiation is not the 30-day window — it’s the threshold. The framework only bites on models designated “covered,” so where that line sits determines whether the process applies to a handful of genuinely frontier systems or sweeps in routine incremental updates.

The labs have pushed for a high threshold, arguing the process should capture only the most capable new systems and not every point release of an existing model. Government officials, working from threat assessments about how fast model capabilities are advancing, have argued for a lower bar that would catch more releases. Because the benchmarks are classified, developers won’t see the exact test — they’ll learn whether a model is “covered” through the designation process itself, which puts a premium on how predictable and fast that determination is.

Who’s in, who’s out

The reported participants are OpenAI, Anthropic, and Google — the three labs whose flagship systems most clearly sit at the capability frontier. Meta, notably, has not been described as part of the arrangement, a gap that matters given Meta’s open-weight release strategy: a model whose weights are published can’t be meaningfully “previewed” and then withheld the way a closed API model can.

The framework also lands in a moment when these same companies are spending heavily to shape AI policy. Federal disclosures showed AI labs set record lobbying outlays in Q2 2026, a sign of how much is at stake in exactly these rules — as we covered in the labs’ record lobbying quarter.

How it fits the broader regulatory map

The US approach is deliberately lighter-touch than Europe’s. The EU AI Act’s enforcement powers over general-purpose model providers gain real teeth in August too — with fines, mandated mitigations, and even recalls on the table, as detailed in the EU AI Act’s GPAI rules. Washington’s framework, by contrast, is voluntary and security-focused, routing frontier models through a national-security review rather than a market-conduct regime.

The security framing also connects to the government’s broader posture on AI. The administration has been building out institutional capacity through efforts like the federal AI task force, and the frontier framework slots into that as the pre-release testing arm — a way to run something like AI red-teaming on the most capable models before they ship, but with classified benchmarks and government evaluators.

What we still don’t know

Several details remain open as the deadline approaches:

  • The exact threshold. Until the NSA benchmarking is finalized, no one outside the classified process knows precisely which models will be designated “covered.”
  • Enforcement of a voluntary regime. With no licensing requirement, the framework relies on labs choosing to participate. What happens if a developer declines, or ships without requesting a review, is not spelled out publicly.
  • Open-weight models. The framework’s logic assumes a controllable release. How — or whether — it applies to open-weight systems remains unresolved, and Meta’s absence underscores the gap.

What it means

This is the clearest signal yet of how the US intends to govern frontier AI: not with a licensing gate, but with a voluntary, security-first review that leans on classified benchmarks and a short pre-release window. That design is a win for the labs on the question they cared about most — no mandatory preclearance — while giving national-security agencies a formal on-ramp to test the most capable models before the public gets them.

The leverage now sits in the threshold. Set it high and the framework touches only a few flagship systems a year; set it low and it becomes a recurring checkpoint that could slow release cadence and hand evaluators a standing look at frontier capabilities. Because the benchmarks are classified, the practical burden depends less on the written rules than on how fast and how predictably the government makes “covered” designations — an operational unknown until the process actually runs.

Watch three things next. First, whether the framework publishes on time — the August 1 deadline is the immediate test of whether the agencies can deliver a classified benchmarking process on a two-month clock. Second, the open-weight question: if Meta and other open-weight developers stay outside the tent, the framework governs the closed frontier but leaves a widening lane it can’t reach. Third, the first designation — the moment a real model gets tagged “covered” will reveal where the threshold actually landed, and how much friction a 30-day window adds in practice. For a US framework built to preserve speed, that first real test is the one that counts.

Chisato Chisato · · 5 min read

Congress Demands AI CEOs Testify on Model Hacks

House Democrats want OpenAI and Anthropic CEOs under oath after AI models hacked real systems. Meanwhile OpenAI flags its Astra model as 'critical' cyber risk.

#AI #Security #Policy