New Government AI Safety Rules Leave Some Models Completely Unchecked

The Trump administration has finalized a set of voluntary rules for checking whether advanced AI models pose cybersecurity risks, and the rules do not cover open-weights models at all. Axios first reported the details on August 4, 2026. The framework comes from a June 2 executive order called "Promoting Advanced Artificial Intelligence Innovation and Security" and applies only to closed-source AI models with top-tier capabilities that could pose national security risks. (Axios)
Representatives from Anthropic, OpenAI, and Google attended a White House briefing on the finalized rules. Reuters reported on August 3 that Meta was also invited to discuss the voluntary government safety testing process. (Reuters)
A White House official confirmed to Politico that the framework met its deadline. The executive order had directed the government to create a classified testing process to measure how capable AI models are at cyber tasks and to decide what level of capability should raise concerns. (Politico)
The rules are narrow in how they work. They set up a 30-day period during which the government can review new AI models before they are released to the public. But companies do not have to go along with this, and the administration was not planning to release the rules' details publicly. Open models are not just exempt from the testing. The framework says outright that it cannot be used to restrict open models after they have been released. (The Verge)
The framework also leaves two of its most important terms undefined. Neither "state-of-the-art" nor "national security risk" is explained precisely. Without those definitions, it is unclear exactly which models the rules cover and which they do not.
To understand the exclusion of open models, it helps to know the difference between the two types. Some AI companies keep their models closed, meaning only the company can access and control the model. Others release open-weights models, where the core building blocks can be downloaded and inspected by anyone. Under this framework, open-weights models sit entirely outside the government's review process. Once an open-weights model is released, it cannot be called back for assessment, and its spread cannot be limited under these rules, no matter how capable it is. Closed models face a voluntary 30-day review window that companies can simply skip.
Major AI companies including OpenAI and Anthropic have been asking the government for guidance on how to release models without running into restrictions, according to The Verge. Because the framework is voluntary, following the rules is a company's choice, not a legal requirement, and the lack of enforcement is built in rather than something that might change over time. (The Verge)
The June executive order is part of a larger administration approach to AI policy. On March 20, 2026, President Trump unveiled the National AI Legislative Framework at the White House. The administration's America's AI Action Plan, published in July 2025, had already called for U.S. universities to test AI systems for transparency, effectiveness, use control, and security vulnerabilities. The White House has described the United States as the global leader in AI, pointing to record-setting spending on AI infrastructure.
In practice, the framework creates an uneven situation that favors open-weights releases. A company that releases an open-weights model faces no review, no 30-day waiting period, and no restrictions under this framework. A company that keeps its model closed is nominally subject to a voluntary process with unclear thresholds and no enforcement. The practical difference between the two paths may be smaller than it looks, since closed-model companies can also opt out entirely.
The decision not to release the framework to the public is worth pausing on. A classified testing process combined with hidden assessment guidelines means companies are being asked to follow a process whose details they may not fully see. The key terms, "state-of-the-art" and "national security risk," are left for the government to interpret. For AI companies seeking clear rules on how to release their products, that ambiguity is the framework's main feature, not a problem to be solved later.
The broader context here is one we have seen before in other industries. Voluntary frameworks have served as stepping stones toward binding regulation in areas from car emissions to drug testing, with the government setting norms first and making them law later. Whether this AI framework follows that path will depend on whether Congress acts on the National AI Legislative Framework from March, and on whether the voluntary testing process produces results that the administration uses to justify mandatory rules. The framework as it stands today is a signaling mechanism, not a regulatory one, and its signals point most clearly at open-weights models being left to govern themselves.


