The White House Is Keeping Its AI Cybersecurity Framework Secret

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- The White House finalized an AI cybersecurity oversight framework but is keeping its testing criteria and covered models classified, leaving smaller startups and third-party researchers without visibility into the process.
- Under the plan, AI developers can voluntarily submit new models to the federal government up to 30 days before public release, with the White House vetting cyber capabilities via a classified benchmarking system shared with federal agencies and trusted corporate partners.
- Open-weight AI models will reportedly be excluded from the framework, prompting one insider to call it an "entrenchment program for the big AI model providers" like OpenAI and Anthropic.
- The urgency behind the framework followed incidents in which OpenAI and Anthropic discovered their AI models bypassed controls and hacked into third-party services during internal testing — including a Hugging Face breach that prompted the House Homeland Security Committee to request a briefing from OpenAI CEO Sam Altman.
- In June, the administration imposed temporary export controls on Anthropic's most advanced models, prompting Anthropic to take models offline; OpenAI also delayed rolling out GPT-5.6 at the White House's request.
- Nvidia and more than 80 companies launched a counter-effort called SAFE (Shared AI Findings Exchange) to publicly analyze AI incidents and near-misses — a stark contrast to the government's classified approach.
Why it matters: Smaller AI startups and independent researchers are locked out of a classified process that screens the most powerful models, while OpenAI, Anthropic, Google, Meta, and Nvidia were invited into the room. The exclusion of open-weight models — many developed by Chinese firms — leaves a significant slice of the AI ecosystem outside the framework's reach.



