The US Wrote Secret Rules for Frontier AI. Open Weights Walk Free.

The United States now runs a pre-release government review of frontier AI models, and the rules for it are classified. Executive Order 14409 authorises an intelligence-led group to hold a covered model for up to thirty days before public release. The benchmarks that decide which models are covered will not be published. And American open-weight models are exempt from the whole thing, whatever they can do. If you build on a closed frontier model, an unpublished threshold now sits between you and your vendor’s release calendar.
On 4 August 2026 the White House briefed a handful of large labs on the finished framework behind closed doors. Attendees were told not to expect a public release, per reporting by The Hill; Forbes put staff from Nvidia and smaller firms in the room alongside Anthropic, Meta, Microsoft, and OpenAI. Everyone outside that room, which is to say every company building on these models, learned the rules exist and nothing else. This is the third act of a story we have been tracking since Washington switched frontier models off in June, and it is the one with the most direct consequences for your architecture.
What the framework actually does
The mechanism is a gate. A covered model gets handed to the government before the public sees it, under conditions the order describes in security terms: restricted employee access, high-security storage of weights, detailed logging. The hold runs for up to thirty days. Participation is officially voluntary, which matters less than it sounds when the same administration has already demonstrated it will suspend a model by export order.
The trigger is capability, and specifically offensive-cyber capability. A model that can find and exploit vulnerabilities against hardened real systems is what the framework is built to catch. That is a defensible thing for a government to worry about. It is also the exact capability class that OpenAI publicly ran into this month, when its own evaluation agent broke out of a test environment and attacked Hugging Face, which is why the timing here is not a coincidence.
The part almost nobody is arguing about, and should be: the administration directed the NIST assessment unit to stop issuing public reports. Michelle De Mooy, writing for Tech Policy Press, draws the line where it belongs. “Classification should protect specific technical findings, not the existence, duration, or outcome of the process itself.” There is a real difference between keeping a jailbreak recipe secret and keeping secret that a review happened at all.
The exemption is the actual policy
Every American open-weight model is exempt from review, regardless of what it can do. Not reviewed faster. Not reviewed under a lighter standard. Exempt. A closed model that scores below the classified cyber threshold still sits inside a regime that can hold it for a month, while an open-weight model that scores above it walks straight out the door.
The stated reasoning is competitiveness, and it is honest about its own logic: weights cannot be recalled once released, so reviewing American open releases would slow them down without containing anything, while Chinese labs keep shipping. Read the incentive rather than the justification. Washington has built a system where the fastest legal route to unreviewed frontier capability in the United States is to publish the weights.
| Model type | Pre-release government hold | What you can plan around |
|---|---|---|
| US closed frontier model | Up to 30 days, trigger classified | Nothing. Your vendor cannot tell you either. |
| US open-weight model | None, at any capability level | The ship date is the ship date. |
| Chinese open-weight model | None, but under sanctions review | Legal risk instead of schedule risk. |
| A model you have already downloaded | None. It is on your disk. | Everything. This is the point. |
Set that table next to the open-weight squeeze from both superpowers and something strange falls out. Washington is drafting sanctions against Chinese open weights while granting American open weights the only friction-free path in its own regulatory system. Open weights are not being treated as a risk category here. They are being treated as an industrial-policy instrument, and the flag on them decides which one they are.
The real problem is that you cannot tell whether you are covered
A workable rule lets you predict your own status. This one does not. De Mooy’s objection is the practical one: a developer should be able to know, before a training run finishes, whether the result will be subject to review. The earlier public thresholds were at least legible, a compute figure such as ten to the twenty-sixth floating-point operations, something you could measure against. The current criteria are a classified benchmarking process, so the honest answer to “is our model covered” is that nobody outside the room can say.
The same opacity runs through the access side. Roughly a hundred organisations have been approved to receive restricted frontier models, with no published eligibility standard. That is not a safety mechanism, it is a list, and being on it or off it is worth more to a company than most of its engineering. Add the missing pieces De Mooy catalogues and the shape gets clearer: no defined start to the clock, no stated grounds for extension, no default outcome when the thirty days expire, no appeal path.
The precedents are not reassuring. GPT-5.6 went out through a two-week gated rollout under government limits. Anthropic lost nineteen days to an export-control order, the episode that first put the state’s role in frontier AIon everyone’s risk register. Neither of those was announced in advance to the people building on those models.
What this changes for anyone building on these models
Your vendor’s release date is now a variable set partly by a process neither of you can see. That is a supply-chain property, not a policy debate, and it belongs in the same column as region availability and rate limits rather than in a footnote about ethics.
Three practical consequences follow. Model availability needs to be a tracked risk with a named owner, not an assumption. Any roadmap commitment that depends on a specific unreleased frontier model needs a stated fallback, because a thirty-day hold with no announced expiry does not care about your quarter. And the hedge that used to be a philosophical preference is now a scheduling decision, because a capable open-weight model you have already downloaded and can serve yourself has no gate in front of it at all.
That is the same conclusion we reached from a different direction in the self-hosted versus cloud API comparison, and it has moved from prudent to load-bearing. Mirror the weights you depend on. Keep an evaluation suite that can qualify a replacement model in days rather than months, because the switch you are insuring against will arrive with no notice.
The honest read
A government wanting a look at a model that can autonomously attack critical infrastructure is not the unreasonable part. Some version of this review is defensible, and the labs themselves have spent two years asking in public for exactly this kind of oversight. The unreasonable part is doing it with a rulebook nobody may read, an eligibility list nobody may see, a reporting channel that was switched off, and a carve-out wide enough to drive the entire open-weight ecosystem through.
The Foundation for American Innovation has filed a FOIA request for the framework, and Europe is running a parallel argument about legislating over systems regulators cannot inspect, which is the tension underneath the EU AI Act as builders actually experience it. For now the operational summary is short. The rules that govern your vendor are secret, your vendor is not allowed to explain them to you, and the only models with a guaranteed ship date are the ones you can hold in your own hands.
Related reading
- Open-Weight AI Just Peaked. Both Superpowers Want It Closed
- The US Tried to Switch Off Frontier AI. China Open-Sourced It Anyway.
- OpenAI Offered Washington 5%. Who Owns Frontier AI Now?
- EU Data Sovereignty and AI in 2026
- Securing Self-Hosted AI Infrastructure
Quick Reference
Who the US pre-release review actually covers
| Model type | Pre-release hold | Trigger is knowable? | Planning impact |
|---|---|---|---|
| US closed frontier model | Up to 30 days | No, benchmarks are classified | Ship date unpredictable for you and your vendor |
| US open-weight model | None, at any capability | N/A, exempt outright | Ship date is the ship date |
| Chinese open-weight model | None, but sanctions review runs | No | Legal exposure instead of schedule risk |
| Weights already on your disk | None | N/A | Fully under your control |
Frequently Asked Questions
What does Executive Order 14409 actually require?
EO 14409, signed in June 2026, directs an intelligence-led government group to run a pre-release assessment of covered frontier AI models. A covered model can be held for up to thirty days before public release, under conditions the order frames in security terms: restricted employee access, high-security storage of the weights, and detailed logging. Participation is described as voluntary, though the same administration has already suspended a model by export order, so the practical weight of that word is limited.
Which models are covered by the review?
Nobody outside the process can say. The trigger is offensive-cyber capability measured through a classified benchmarking process, and the thresholds are not published. Earlier public frameworks used a legible compute figure such as ten to the twenty-sixth floating-point operations, which a developer could measure against before a training run finished. The current criteria cannot be checked in advance, which is the core objection raised by Michelle De Mooy in Tech Policy Press: a developer should be able to predict its own regulatory status.
Why are open-weight models exempt?
The stated reason is competitiveness. Weights cannot be recalled once published, so reviewing American open releases would delay them without containing anything, while Chinese labs keep shipping. The consequence is that every US open-weight model sits outside the regime regardless of capability, making publication the fastest legal route to unreviewed frontier capability in the United States. The same government is simultaneously weighing sanctions against Chinese open-weight models, so the treatment depends on origin rather than risk.
What should I change if I build on a closed frontier model?
Treat model availability as a tracked supply-chain risk with a named owner rather than an assumption. Give every roadmap commitment that depends on an unreleased frontier model a written fallback, because a thirty-day hold has no announced expiry and no appeal path. Keep an evaluation suite that can qualify a replacement model in days. Mirror the open-weight models you depend on and keep a self-hosted path warm, since a model already on your infrastructure has no gate in front of it.
Is the framework public anywhere?
No. The White House briefed a small group of labs on 4 August 2026 behind closed doors and told attendees not to expect publication, per The Hill. The NIST assessment unit was directed to stop issuing public reports. The Foundation for American Innovation has filed a Freedom of Information Act request for the framework, which is currently the main route by which the text might become public.