The White House has told AI companies it completed a voluntary framework for reviewing advanced models’ cyber risks by its self-imposed deadline — but is refusing to make the document, its testing criteria, or its start date public, according to multiple outlets including Axios, CNBC, and Fortune.

Officials from the National Cyber Director’s office briefed representatives from OpenAI, Anthropic, Google, Meta, Microsoft, Nvidia, and several smaller firms on the finished framework at a closed-door meeting in Washington on August 3–4. According to Fortune, companies had not seen the actual document before the meeting began.

What the framework requires

The framework stems from an executive order President Trump signed on June 2, which gave federal agencies 60 days — until August 1 — to build a classified cyber-capability benchmark and a related review process for what the order calls “covered frontier AI models.” Under the plan, developers can voluntarily submit a qualifying model to government reviewers for up to 30 days before its public release, so agencies including the National Security Agency can screen it for advanced hacking or cyberattack capabilities.

Reporting indicates the rules exempt open-weight and open-source releases, focusing instead on closed, state-of-the-art systems from a handful of top developers — chiefly OpenAI, Anthropic, and Google. The order also explicitly bars the framework from becoming a mandatory licensing or preclearance requirement, keeping participation voluntary.

A quiet reversal

AI News previously reported that the administration had missed its own August 1 cutoff, with agencies publishing nothing by that date. The White House now says the framework itself was finished on schedule — what changed is that it briefed companies privately rather than releasing anything publicly.

The secrecy has drawn criticism. Chris McGuire, a senior fellow at the Council on Foreign Relations, called the decision “baffling” on X, adding: “We can’t have secret, voluntary rules to regulate the most important tech in the world.” Fortune reported that some attendees, including Microsoft, were only confirmed to be in the room after the fact, and firms outside the briefing still don’t know what the cybersecurity framework actually requires.

The White House has not said whether or when it will publish the framework, or how it plans to verify compliance with rules that remain unpublished.

Read also