Technology & The Future

Washington Is Writing the Rules for Frontier AI Without Calling Them Rules

The White House is finalizing a pre-release review framework for the most powerful AI models ever built — and the benchmarks that determine who qualifies are secret.

Elias VossJuly 14, 20269 min read
Washington Is Writing the Rules for Frontier AI Without Calling Them Rules

There is a concept in observational astronomy called the detection threshold — the minimum signal strength an instrument must register before a scientist can say, with confidence, that something is actually there. Below the threshold, you have noise. Above it, you have a candidate. The threshold is not arbitrary. It is a technical decision, made in advance, that determines what the instrument will and will not find. Everything discovered, and everything missed, flows from where that line is drawn.

Washington is currently in the process of drawing exactly that kind of line for artificial intelligence — and the politics of where to draw it look almost exactly like the physics. The U.S. government is in advanced talks with AI companies to create voluntary standards for the release of new models, with an announcement possible as soon as next week. At the center of those talks is a deceptively simple question: what makes an AI model powerful enough to require government review before it ships? The answer will determine which systems get scrutinized, which labs get pulled into a federal process, and which capabilities the government is even looking for. And — critically — there is significant uncertainty regarding the definition of a "covered frontier model," as the designation process will be developed through classified benchmarking procedures, limiting developer visibility into the threshold that would trigger federal interest.

That phrase — classified benchmarking — deserves to be held up and examined. It means the instrument specifications are secret. The government will know what it is scanning for. The companies will not, at least not in full. They will build their systems, submit them if they choose, and wait to learn whether their model crosses the threshold. This is the operational reality of the framework that has been taking shape since June, and it is more structurally peculiar than most coverage has suggested.

The Executive Order That Started the Clock

On June 2, 2026, President Donald Trump issued an executive order titled "Promoting Advanced Artificial Intelligence Innovation and Security."[2] The order outlines two approaches: strengthening U.S. government and private industry cyber defenses in response to "advanced AI," and developing voluntary benchmarking and review frameworks for secure development and release of "frontier" AI models. The language is careful throughout. The order emphasizes that its approach is voluntary and should not be construed as a mandatory licensing, permitting, or preclearance requirement.

Agencies must develop and maintain a classified benchmarking process to assess the advanced cyber capabilities of AI models and determine the threshold at which a model should be designated a "covered frontier model." The director of the NSA will make such determinations in consultation with the national cyber director, the assistant to the president and director of the White House Office of Science and Technology Policy, and the CISA director. When a model receives that designation, its developer may provide the government with access to the model — subject to confidentiality, cybersecurity, insider-risk, and intellectual property protections — for up to 30 days before releasing it more broadly.

The 30-day window is notable not because it is long, but because it exists at all. The EO is similar to a draft the president had planned to sign on May 21, before he abruptly pulled back over concerns that the prior order would "get in the way of" U.S. competitiveness. The version that emerged was already a retreat from an earlier draft with a much longer review window. What arrived on June 2 was a negotiated instrument — tighter, more carefully worded, more deliberately limited than the version that almost became law. The voluntary standards now being finalized are essentially an attempt to operationalize that instrument before the gap between the order's ambitions and its machinery becomes too visible.

“The benchmark that determines whether a model triggers federal review is classified. The companies will know the process exists. They will not know where the line is drawn.”

What 'Voluntary' Actually Means in This Context

The word voluntary is doing a great deal of work in this framework, and it is worth being precise about what it does and does not mean. It does not mean inconsequential. Developers of highly capable models may face growing pressure from customers, policymakers, and industry partners to participate in voluntary government-led security assessments. A voluntary standard that most major labs sign up to would let the White House claim a functioning regime without defending a mandatory one in court. These two facts point in the same direction: the incentive structure around "voluntary" participation is not neutral. It is shaped by procurement relationships, reputational exposure, and the implicit threat that a company conspicuously absent from the framework invites a harder conversation later.

The framework's construction also involves the three companies whose models currently define the frontier. The Trump administration is in the final stretch of negotiations with OpenAI, Google, and Anthropic — the three companies that dominate frontier AI development — to establish a voluntary framework for pre-release testing of advanced AI models. Each of those companies has a different calculus. Alphabet has tens of billions in annual revenue tied to government cloud contracts, and a framework that gave Google preferential treatment in national security AI deployment would be worth far more than the reputational cost of accepting voluntary pre-release review. Anthropic's participation carries a particular weight given its recent history. The company had a $200 million Pentagon contract terminated in early 2026 after refusing to accept contract language that would have permitted use of Claude for autonomous weapons systems without human intervention — a standoff that resulted in the Trump administration briefly designating Anthropic a "Supply Chain Risk to National Security." Its participation in the voluntary framework talks is, in effect, a managed rehabilitation of that relationship.

This is not unique to AI. It resembles the structure of financial regulation after 2008, where voluntary engagement with stress-testing frameworks preceded binding requirements, and where participation itself became a signal that regulators used to distinguish cooperative from adversarial institutions. After the 2008 financial crisis, leaders of the G7 created the Basel Committee on Banking Supervision, which established standards to reduce future financial crises. In practice, those standards were not truly voluntary: to be noncompliant with FATF meant blacklisting in the financial markets. The Brookings Institution, among others, has drawn exactly this parallel in commentary on the current AI governance moment, arguing that voluntary compliance means the outcome is only a suggestion, not a standard. The White House framework has not reached that level of enforceability, and may never reach it. But the architecture being assembled now is not designed to stay still.

The Classified Telescope Problem

Return, for a moment, to the detection threshold. In observational science, a classified instrument specification would be a strange thing. Science depends on reproducibility — on other researchers being able to examine not just your findings but your methods, your calibration, your noise floor. A telescope whose sensitivity parameters are state secrets could still produce real detections. But the detections would be unverifiable by anyone outside the system. You would have to trust the institution, not the method.

Within 60 days, Treasury, NSA, CISA, NIST, and other federal officials must develop and maintain a classified benchmarking process to assess the advanced cyber capabilities of AI models and determine when a model should be designated a "covered frontier model." The NSA Director, in consultation with other federal officials, will determine whether a model meets that threshold. The NSA — an agency whose operational mandate is signals intelligence and whose institutional culture is oriented toward secrecy — now sits at the center of a process that will determine which civilian AI products get flagged for national security review. That is a meaningful institutional choice, and it represents a notable shift for an administration that previously championed a nearly hands-off approach to AI governance, elevating the National Security Agency and the U.S. Department of the Treasury into central oversight roles.

Significant discretion is left to federal agencies regarding the criteria used to make such determinations, including the cyber capabilities that trigger designation, the benchmarks used to evaluate those capabilities, the thresholds for government engagement, and the categories of AI systems that may be subject to review. In practice, this means that until the classified benchmarking process is developed and begins producing designations, the framework is more a declaration of intent than an operational system. The order exists. The machinery to implement it is still being built. The voluntary standards being negotiated this week are an attempt to give that machinery something to run on before the classified process is ready — a set of shared expectations that can function as a working norm even before the formal threshold is defined.

A Precedent Regardless of Outcome

Those who prioritize safety and international coordination generally welcome any formal government review mechanism, however limited. The 30-day pre-release review creates a precedent, they argue: even if the current iteration has no binding power, it establishes the principle that frontier AI releases are a matter of public interest requiring government visibility. Those who prioritize innovation and U.S. competitiveness are more skeptical. A 30-day review window, even a purely advisory one, adds friction to release timelines in a market where the gap between first and second mover is measured in weeks. Both readings are defensible. They are also not mutually exclusive.

The geopolitical dimension runs through all of this. Washington has tightened oversight of new model releases to flag risks amid concerns that advanced AI could be misused by military intelligence in China, Russia, or other countries of concern. The Commerce Department this week lifted export controls on Anthropic's Fable and Mythos models, weeks after imposing them, having earlier allowed Mythos releases only to certain approved partners — a demonstration that access controls on frontier models are already functioning at the export level, regardless of what the voluntary domestic framework eventually looks like. The standards being finalized will clarify, among other things, benchmarks for advanced models and timelines, while clarifying who can access them inside the U.S. and overseas. Access geography is now part of the specification.

“Voluntary compliance means the outcome is only a suggestion, not a standard — and the history of financial regulation suggests that suggestions have a way of becoming requirements.”

The larger context here is a genuinely contested question about how democratic societies govern technology that advances faster than legislative processes can follow. The White House voluntary framework represents a specific American answer to the AI governance question that every major democracy is wrestling with: how do you build oversight mechanisms for technology advancing faster than regulatory processes can follow, in a market where the leading companies are American private enterprises, in a geopolitical context where being second is strategically unacceptable? The EU's approach — its AI Act[1], which includes binding requirements on high-risk systems and mandatory evaluation capacity for advanced models — is structurally different, and the U.S. framework remains materially less prescriptive than the regulatory regimes the European Union and China have adopted. Whether the American bet on voluntary compliance with strategic incentives achieves comparable safety outcomes is the question that the next several years will answer. For now, the detection threshold is being set in the only place it can be set in this political environment: in negotiations between the government and the industry it is trying to see.

The algorithm already deciding your risk profile in consumer contexts and the frontier model being handed to a national security reviewer for 30 days are different instruments at different scales — but they are products of the same fundamental question about who gets to look inside the system, and when. What is being finalized this week is not a safety guarantee. It is a framework for the government to be in the room when the most consequential AI systems are released. Whether being in the room is enough depends entirely on what they do once they get there.

References

  1. AI Act (digital-strategy.ec.europa.eu)
  2. Promoting Advanced Artificial Intelligence Innovation and Security (whitehouse.gov)
    Establishes the June 2, 2026 executive order requiring classified benchmarking to determine which AI models trigger federal review.

About Elias Voss

Elias Voss writes about astronomy, space missions, telescope discoveries, and cosmic anomalies - and why it matters to us here on Earth. When the universe's physics reaches down and touches life on our planet, he follows it there too. He specializes in translating dense data into vivid, precise stories without sacrificing accuracy.

More like this

They're Teaching Robots to Do Your Job — By Paying You to Film Yourself Doing It

They're Teaching Robots to Do Your Job — By Paying You to Film Yourself Doing It

Julian Cross 10 min
The U.S. Government Is Watching You More Efficiently Than Ever — and Outsourcing the Hard Part

The U.S. Government Is Watching You More Efficiently Than Ever — And Outsourcing the Hard Part

Julian Cross 9 min
Democracies Don't Warn You Before They Stop Being One

Democracies Don't Warn You Before They Stop Being One

Paul Wardell 10 min