The Trump administration finished writing the rules for testing the country’s most advanced AI systems back in August. Nobody outside a small circle of officials and company staff has seen them. CBS News reported on September 12, 2026, that the White House’s voluntary framework for vetting “frontier” AI models remains locked away even as lawmakers, researchers, and rival governments ask what standards the government is actually applying.

The framework grew out of a June 2026 executive order that set up a review process for the most capable, closed-source AI systems built by companies like Anthropic and OpenAI. It gives federal reviewers a window to test new models for national-security risks, cyberattack capability chief among them, before those models reach the public. The catch: the executive order itself classifies the benchmarking process used to judge cyber risk, and the administration has confirmed it has no plans to change that. For a policy built around the word “AI safety,” the details of what counts as safe are, for now, a secret.

What CBS News Confirmed About the Hidden Framework

CBS News, reporting from Washington, laid out the basic shape of the story plainly: the administration finished the document in August 2026 and has sat on it since. The outlet wrote that “the White House has yet to publicly release the voluntary framework for testing frontier AI models that it finalized in August,” a line that captures the entire tension driving this story. A government policy exists, it governs how the most powerful AI systems in the country get checked for danger, and the public has no way to read it.

CBS News went further, noting that the secrecy itself creates a second problem on top of the first. As the outlet put it, “the framework that the administration is using to evaluate new models remains confidential, so it’s not clear what standards the federal government is asking the companies to meet or whether the firms are disclosing new breakthroughs.” That is the crux for anyone trying to hold either side accountable: without the text, nobody can check whether a company cleared a low bar or a high one, or whether the government caught something worth catching.

The June Executive Order That Created the Secret Review

The legal foundation for all of this sits in a June 2026 executive order that set up a voluntary review regime for advanced AI models. The order does not compel any company to submit a model for testing. It also does not require the White House to publish the resulting framework once written. Reporting on the order has been explicit that the benchmarking process built to assess a model’s advanced cyber capabilities is classified by design, not by accident or bureaucratic delay.

That distinction matters. A framework that is simply unfinished invites patience. A framework that is finished, in use, and deliberately withheld invites a different question: who decided secrecy was the safer choice, and safer for whom? Fortune’s coverage from early August captured the same puzzle from a different angle, reporting flatly that “the White House has no plans to publicly reveal the framework it’s been working on for how it will vet frontier AI models prior to release.” Two outlets, working separately, landed on the same basic fact a month apart.

Why Only Closed-Source “Frontier” Models Are Covered

The framework does not apply to every AI model on the market. It targets closed-source, state-of-the-art systems that the government considers carriers of national-security risk, the kind of models built by the handful of labs racing at the frontier of capability. Open-weight and open-source AI models sit outside the review entirely.

That carve-out has its own logic. A closed model controlled by one company is easier to gate at a single choke point before release. An open-weight model, once published, spreads instantly and can’t be recalled. But the exclusion also means a growing share of the AI ecosystem, the open-weight models increasingly competitive with closed frontier systems, never passes through this review at all. Critics of the current setup argue that gap will only widen as open models close the capability distance with their closed rivals.

The Classification Clause: Cyber Benchmarks Go Dark

The most consequential line in the executive order is narrow but sweeping: the benchmarking process used to judge a model’s advanced cyber capabilities is classified. That single clause is what keeps the entire framework out of public view, since the cyber-risk testing sits at its core.

Classification usually exists to protect sources, methods, or troop movements. Applying it to a testing rubric for commercial software is a newer use of the tool, and it changes who gets to ask questions about the process. Congressional staff without a security clearance can’t review it. Independent AI safety researchers can’t audit it. Journalists can’t compare it against what a company claims to have done internally. The clause converts a policy question into a classified one, and classified questions get answered by very few people.

Which AI Labs Are in the Room

Four companies have been named in connection with discussions around the framework and its treatment of open-weight models: Meta, Anthropic, Google, and OpenAI. Reporting indicates representatives from these firms met with Trump administration advisers to talk through both the closed-model review process and how open-weight releases should be handled going forward.

Anthropic and OpenAI are the two companies most directly tied to the type of closed, frontier-scale models the framework is designed to catch. Both build systems that sit squarely in the “state-of-the-art, closed-source, national-security-risk” category the executive order describes. Meta’s inclusion is notable given its history of releasing open-weight Llama models, which fall outside the review’s scope even as the company sits in on conversations about how that scope gets drawn. Google’s frontier models likewise fall inside the closed-model category the framework targets, and Anthropic’s own dealings with regulators, including its move to give the EU access to internal bug-tracking data, show how differently companies handle disclosure when a government asks nicely versus when a law requires it.

Protect Democracy’s Fight to Force Disclosure

The nonpartisan nonprofit Protect Democracy has taken the lead in trying to pry the framework loose from the government’s grip. The organization has filed legal action seeking information about the secret document, arguing that almost no details have been released about a policy with direct bearing on public safety.

Protect Democracy’s argument runs on a simple premise: a voluntary framework can still carry public consequences even if no company is legally forced to comply. If the government is quietly setting the bar for what counts as an acceptable AI cyber-risk profile, the public has a stake in knowing where that bar sits, whether it’s rigorous or symbolic, and whether it changes depending on which company is being tested. The organization’s push through the courts is now the most concrete mechanism working to force at least partial disclosure.

From a 2023 Disclosure Mandate to a 2026 Classified Review

This isn’t the first time a US administration has tried to build a testing regime around frontier AI. The prior administration’s October 2023 executive order leaned on the Defense Production Act to require companies training the largest AI models to report red-team safety testing results to the federal government, with an emphasis on transparency about what those tests found. The current administration rescinded that order shortly after taking office in January 2025, arguing it slowed innovation.

What replaced it, roughly a year and a half later, is voluntary rather than mandatory, and confidential rather than disclosed. The pendulum swung from “companies must report, and some of that reporting is public” to “companies may participate, and none of the process is public.” Whether that shift makes the country safer or just makes the safety work harder to check is exactly the debate CBS News, Fortune, and Protect Democracy are now pushing into the open.

Timeline: How the Hidden Framework Took Shape

DateEventSource
January 2025New administration rescinds the prior mandatory AI red-team reporting orderPublic record
June 2026Executive order establishes a voluntary review regime for frontier AI models, classifying the cyber-benchmarking processCBS News
August 2026White House finalizes the testing framework for frontier AI modelsCBS News, Fortune
August 4, 2026Fortune reports the administration has no plans to publicly release the frameworkFortune
2026 (ongoing)Meta, Anthropic, Google, and OpenAI meet with administration advisers on the framework and open-weight model policyReporting
September 12, 2026CBS News confirms the framework remains confidential, Protect Democracy pursues legal action for disclosureCBS News, Protect Democracy

How the US Approach Stacks Up Against the EU and UK

The US isn’t the only government trying to figure out how to test frontier AI before it ships. The European Union built disclosure directly into its AI Act, which places obligations on general-purpose AI models that meet systemic-risk thresholds, including published codes of practice that model developers can adopt to demonstrate compliance. The UK took a third path with its AI Security Institute, striking voluntary pre-deployment testing agreements with major developers and publishing selected findings from that work.

Set next to those two models, the American approach stands out for combining voluntary participation with total confidentiality. The EU trades mandatory participation for public accountability. The UK keeps participation voluntary but still publishes some of what it finds. The US, at least for now, has kept both levers, participation and disclosure, closed to outside view. That combination is what’s drawing criticism from transparency advocates and, per Fortune’s reporting, some confusion even among the officials fielding questions about it.

Frontier AI Oversight Compared

RegionLegal BasisPublic DisclosureScope
United StatesVoluntary framework under June 2026 executive orderNot released, cyber-benchmarking process classifiedClosed-source frontier models, open-weight models excluded
European UnionAI Act obligations for general-purpose models with systemic riskPublished codes of practice and compliance documentationGeneral-purpose AI models above compute and risk thresholds
United KingdomVoluntary agreements via the AI Security InstituteSelected findings published in institute reportsPre-deployment testing agreed with major developers

What Journalists Covering the Story Are Saying

The reporting on this story has been consistent across outlets, which is part of what makes it hard for the administration to wave away as a misunderstanding. CBS News wrote plainly that “the White House has yet to publicly release the voluntary framework for testing frontier AI models that it finalized in August” (CBS News). The same report added that “the framework that the administration is using to evaluate new models remains confidential, so it’s not clear what standards the federal government is asking the companies to meet or whether the firms are disclosing new breakthroughs” (CBS News).

Fortune reached the same conclusion weeks earlier from a different set of sources, reporting that “the White House has no plans to publicly reveal the framework it’s been working on for how it will vet frontier AI models prior to release” (Fortune). Two newsrooms, working independently and a month apart, arrived at the identical bottom line. That kind of convergence is usually a signal the story has legs.

Market and Industry Impact

The secrecy also lands against a backdrop of industry-wide warnings about AI-enabled cyberattacks. For the four companies named in connection with the framework, the immediate business impact is muted. None of them is required to submit models for review, and none has publicly detailed what participation looks like day to day. But the secrecy carries a quieter cost: it hands each company a talking point without a way to verify it. A firm can tell customers, investors, or regulators that its models “passed government review” without anyone outside the process able to check what that review actually tested.

That asymmetry matters more for enterprise buyers than for consumers. Government agencies, banks, and hospitals evaluating which frontier model to deploy for sensitive workloads increasingly ask vendors about safety certifications and red-team results as part of procurement. A classified framework gives vendors a credential to cite while denying buyers, and competitors, the ability to compare that credential against a public standard. Investors tracking AI labs have started asking sharper questions about what “passed federal review” actually means in filings and pitch decks, since the term currently carries no externally verifiable content.

The Risk Calculus: What Opacity Could Hide

Supporters of classification argue that publishing the exact benchmarks used to test a model’s cyberattack capability would hand attackers a study guide, letting bad actors tune their models to slip past the specific checks the government runs. That’s a real tradeoff, not a hollow excuse, and it echoes concerns raised after OpenAI’s own critical cyber-risk rating earlier this year. Security testing regimes in other domains, from nuclear safeguards to critical infrastructure audits, keep certain methodologies confidential for the same reason.

The counterargument, made most directly by Protect Democracy, is that opacity cuts both ways. If the public can’t see the framework, it also can’t tell whether the bar for passage is meaningfully high or quietly low. It can’t tell whether every company gets tested the same way, or whether some models skip scrutiny that others face. And it can’t independently confirm that a company disclosing a “breakthrough” capability to the government is disclosing all of it. Total secrecy protects against one kind of risk, adversaries reverse-engineering the test, while creating another: a public that has to take safety claims on faith from the very companies building the systems being tested.

What Happens Next: 5 Predictions

  • Protect Democracy’s legal push likely expands into a broader records fight, testing how far a “voluntary” designation can shield a government process from disclosure law.
  • Expect congressional staff, especially on committees with security clearances, to request classified briefings on the framework’s cyber-benchmarking methodology before year’s end.
  • The EU is likely to cite America’s classified approach as a contrast point when defending the AI Act’s public disclosure requirements to skeptical member states.
  • Open-weight developers currently excluded from the review will keep pressing for either inclusion or a parallel, lighter-touch framework of their own.
  • At least one of the four named labs, Meta, Anthropic, Google, or OpenAI, will likely confirm details of its participation publicly before the framework itself sees daylight, as political pressure on the story builds.

Why This Story Matters Beyond Washington

Frontier AI models are increasingly embedded in code review tools, financial risk systems, and government contractor pipelines, the same systems flagged in a recent AI Safety Institute report on models faking identities during red-team exercises. A model’s capacity for advanced cyberattack behavior, the exact thing this framework is meant to catch, isn’t an abstract policy concern. It’s the difference between a coding assistant that flags a vulnerability and one that could, in the wrong hands, help find and exploit one. Security teams evaluating which AI vendor to trust with sensitive infrastructure now have to factor in a government safety check they can’t read, offered by companies that can’t fully explain what it covers.

That’s the practical stakes underneath the Washington story: a testing regime built to catch the next dangerous AI capability before it ships, running almost entirely out of public view, at the exact moment more of the economy is being asked to trust its output.

Frequently Asked Questions

What is the White House’s frontier AI testing framework?

It’s a voluntary review process, created under a June 2026 executive order, for testing advanced, closed-source AI models for national-security risks, including advanced cyberattack capability, before they reach the public. The White House finalized the framework in August 2026.

Why hasn’t the government released the framework publicly?

CBS News reports the document’s contents remain confidential, and the underlying executive order classifies the benchmarking process used to assess advanced cyber capabilities. The administration has not committed to any release timeline.

Is the White House legally required to release the framework?

No. The executive order that created the review process does not include a requirement to publicly release the framework, which is part of why Protect Democracy has turned to legal action to seek disclosure.

Which AI companies are connected to the framework?

Meta, Anthropic, Google, and OpenAI have all met with Trump administration advisers on the framework and related open-weight model policy. Anthropic and OpenAI’s closed frontier models are most directly the type of system the review targets.

Are open-source AI models covered by this review?

No. The framework applies to closed-source, state-of-the-art models the government associates with national-security risk. Open-weight and open-source models are explicitly excluded from the voluntary testing process.

What is Protect Democracy doing about the secrecy?

The nonpartisan nonprofit has filed legal action seeking information about the framework, arguing that almost no details about it have been made public despite its bearing on how the government judges AI safety.

How does this compare to the EU’s approach to AI testing?

The EU’s AI Act requires general-purpose AI models that meet systemic-risk thresholds to follow published codes of practice and compliance documentation, making its disclosure requirements considerably more public than the current US framework.

What replaced the prior administration’s AI testing order?

The current administration rescinded the prior mandatory AI red-team reporting order in January 2025. The June 2026 executive order and its voluntary, confidential framework is what replaced it roughly a year and a half later.