The Trump administration has finalized a framework for assessing cybersecurity risks posed by advanced AI models, but the guidelines contain significant gaps — excluding open-source models entirely and failing to define central terms like "state-of-the-art" and "national security risk," raising questions about the initiative's practical utility.
The framework was developed following an executive order President Trump signed in June, which directed AI companies to share their frontier models with the federal government before release in order to address cybersecurity concerns.
Representatives from Anthropic, OpenAI, and Google reportedly attended a White House briefing on the finalized framework on August 4, though the administration has no plans to release the document publicly.
According to Axios, the guidelines are voluntary and set a 30-day window for the government to review new models prior to their release. They apply only to closed-source AI models deemed to have state-of-the-art capabilities and to carry national security risks.
Open models — those whose weights and core components can be freely downloaded and inspected by anyone — are excluded from the framework altogether. The guidelines also explicitly state they cannot be used to restrict open models after they have already been released, a carve-out that effectively removes a large and growing segment of the AI landscape from federal oversight consideration.
The framework's failure to define what qualifies as "state-of-the-art" or what constitutes a "national security risk" compounds the ambiguity. For an initiative expressly designed to evaluate those very categories, the omission leaves companies with little concrete guidance on where the government's thresholds lie.
That ambiguity could weigh most heavily on smaller AI providers. Frontier labs such as OpenAI and Anthropic have been actively seeking clarity on how to release models without triggering government restrictions, reflecting the degree to which leading developers see regulatory alignment as a strategic priority. Smaller firms with fewer resources to navigate undefined compliance expectations may find themselves in a more precarious position.
Because participation is voluntary, no AI company is legally compelled to submit models for review. The lack of enforcement mechanisms, combined with the definitional gaps, means the framework's practical scope remains uncertain even as it is formally in place.
The administration's decision to keep the framework's details non-public further limits external scrutiny, leaving industry observers and potential participants to rely on secondhand accounts of its contents.
What emerges is a testing regime that, at least in its current form, applies to a narrow slice of the AI market, operates on voluntary compliance, and leaves its own core criteria open to interpretation — a combination that analysts and smaller developers alike will likely watch closely as the government's AI governance posture continues to take shape.
Disclaimer