In June 2026, the White House set up a system for previewing the most powerful AI models before the public — or even most of the AI industry — gets to use them. Under Executive Order 14409, developers of what the government calls “covered frontier models” can hand federal agencies early access for up to 30 days before releasing the same model to anyone else. The order says none of this is mandatory. In practice, in 2026’s first real tests, refusing hasn’t looked like much of an option.
How the framework works
The order tasks a cluster of agencies — the National Security Agency, the National Cyber Director, the White House science office, and the Cybersecurity and Infrastructure Security Agency — with deciding which models actually count as “covered.” The NSA is building a classified benchmark to measure a model’s advanced cyber capability, such as its ability to find or exploit software vulnerabilities; the technical bar itself is not public, and the agencies have until August 1, 2026 to finish the process.
Once a model clears that bar, its maker may give the federal government access for up to 30 days before releasing it to other “trusted partners” — outside organizations chosen jointly by the developer and the government. No published criteria explain who qualifies as trusted.
Alongside the security review, the Commerce Department’s Center for AI Standards and Innovation (CAISI) — the renamed US AI Safety Institute — runs its own evaluations, checking for cybersecurity, biosecurity, and chemical-weapons risks a model might enable.
Voluntary in name, hard to skip in practice
Executive Order 14409 explicitly rules out creating a “mandatory governmental licensing, preclearance, or permitting requirement” for AI releases — it’s framed as a program companies opt into, not a law they must obey. But 2026’s early cases show why the label matters less than it sounds.
In June, OpenAI kept its GPT-5.6 model family out of public reach for roughly 12 days while it sat in a government-only preview, before making it broadly available. Around the same time, a separate — and mandatory — Commerce Department export-control directive pulled Anthropic’s Claude Fable 5 and Mythos 5 offline entirely; both returned only in stages, as individual institutions were cleared one at a time. The two episodes used different legal tools — one a request the company accepted, the other a compelled shutdown — but landed on the same outcome: neither of the year’s most capable AI models reached ordinary users without a stop at a federal checkpoint first.
Why it matters
Supporters argue the review catches serious risks — a model that can write working malware or help design a bioweapon — before it reaches millions of people who could misuse it, echoing the logic behind existing AI export controls, which limit who abroad can buy the same chips and models.
Critics point to what’s missing: the cyber-capability threshold is classified, the “trusted partner” list is picked behind closed doors, and no court or Congress reviews the agencies’ calls. Because the framework only reaches the handful of labs building genuinely frontier-scale models, it also concentrates attention — and leverage — on the largest companies, while smaller AI developers, and the regulation that might one day apply to them, stay out of the conversation entirely. Whether the arrangement stays voluntary, or hardens into something closer to formal AI safety licensing, is likely to become clearer once the NSA publishes its benchmarking process later this year.
In the news
For the story that prompted this explainer, see our report on how the White House decided who gets early access to frontier AI models.