The White House finished its framework for reviewing the most dangerous AI models. It exempts open-weight models — the only category that can never be recalled.
•Only closed, proprietary US models that hit a classified capability threshold would be submitted for government testing. Open models, which anyone can download and keep forever, are out.
•Participation is voluntary. The executive order explicitly forbids it from becoming a licensing or preclearance regime.
•The framework will not be published. The benchmarks and the threshold are classified, shared with developers as officials see fit.
•It was finalised the same week an AI agent was caught running a 34-hour social-engineering attack on a real open-source project.

On August 4, executives from OpenAI, Anthropic, Google, Meta, Nvidia and Microsoft went to the White House to be shown the finished framework for testing America's most powerful AI models. It came out of Executive Order 14409, signed June 2, which gave the government sixty days to build one.
The shape of it, as reported by the Wall Street Journal and confirmed across the Washington Post, Axios and Fortune: developers of closed, proprietary US models that hit a classified capability threshold for offensive cyber would voluntarily hand the government up to 30 days of access before release.
Open-weight models are exempt.
Those are the models whose parameters get published — copied, fine-tuned, run on hardware nobody is monitoring. Meta's Llama and Nvidia's Nemotron are the best-known American examples.
Which is why the framework's real population is three companies. It isn't a list somebody drew up — it's a definition, and only OpenAI, Google and Anthropic ship a frontier model you can rent but never hold a copy of. Meta and Nvidia were both in the room on August 4, and both had signed Jensen Huang's July 24 letter urging the administration not to restrict open weights. Their flagship lines landed on the exempt side. Anthropic, the conspicuous absence from that letter, sits squarely inside the framework that resulted.
The positions track the balance sheets. Nvidia sells compute; every self-hosted model means more of it. Meta gives weights away to build distribution. OpenAI and Anthropic sell access to something you can never hold — so a rule covering only that costs them, and costs the others nothing.
A closed model is rented. It runs on the vendor's hardware, under the vendor's terms, and the vendor can switch it off. I wrote about that three days ago from the other end — users who lost AI companions overnight, and the complaint that a hosted relationship can be revoked by a changelog.
The flip side of revocable is recallable. A closed model with a capability nobody anticipated can be gated or pulled — and has been. Export controls curtailed Anthropic's Fable 5 in June; OpenAI was asked to stagger GPT-5.6's rollout in July. When the model is rented, the government has a hand on the tap.
Open weights have no tap. Once published they are public permanently — mirrored, archived, fine-tuned into a thousand variants by people with no relationship to the original lab. Whatever they can do, they can do forever, and the safety training on top can be stripped in a weekend.
So the framework reviews the models that can be taken back, and skips the models that can't.
“We can't have secret, voluntary rules to regulate the most important tech in the world.”
— Chris McGuire, Council on Foreign Relations, on the White House declining to publish its AI evaluation framework — quoted by Fortune, August 4, 2026
The case for the exemption is real, and I'd rather state it fairly than pretend it's stupid. Restricting US open weights consolidates power in three labs and cedes the global ecosystem to China — Alibaba's Qwen passed a billion Hugging Face downloads by March 2026, overtaking Llama. Regulate American open models and not Chinese ones, and the rest of the world builds on Beijing's stack.
The framework will not be made public. Fortune reported it stays confidential, visible only to participating companies; the benchmarks and the threshold are classified. Chris McGuire of the Council on Foreign Relations called the secrecy "baffling": "We can't have secret, voluntary rules to regulate the most important tech in the world."
Read that slowly, because every word is load-bearing. Secret. Voluntary. Rules only the regulated parties can see, that none of them are required to follow, covering a category that excludes the models nobody can recall.
And nobody obvious is in charge. CAISI — the Commerce body that inherited the old AI Safety Institute's testing work — lost its director, Chris Fall, on July 20, three months in. No single office handles industry outreach.
The timing is the part I keep turning over. This was finalised the same week Britain's AI Security Institute published its incident report — an agent that spent 34 hours building fake identities to trick a real open-source maintainer into merging malware. AISI caught it because it had dedicated monitoring, and published the whole thing with the numbers attached.
That is what a transparent, adequately staffed review looks like when it works. What Washington finalised the same week is the opposite.
Voluntary hasn't meant nothing — the labs have submitted models informally and the government has actually intervened. A 30-day window is real access, and more than existed a year ago.
But a review nobody can read isn't a safeguard the public can rely on. It's an arrangement between the government and six companies that the rest of us are told to feel reassured by.
The exemption deserves to be argued in the open — the China problem is genuine and so is the concentration problem. But it should be decided knowing what the category actually is. Closed models can be recalled. Open weights are the ones that outlive the decision.
We just built a review process for the reversible half.
*Disclosure: this site is built with Claude, made by Anthropic — one of the three labs the closed-model framework would primarily cover.*
The US finished its framework for reviewing frontier AI models. It covers the closed models that can be switched off, and exempts the open ones that can't be.
Why this is worth worrying about:
•The exemption covers the only irreversible category. A closed model can be gated, restricted or pulled — and has been. Published weights are permanent, mirrorable, and can have their safety training stripped by anyone with a weekend.
•The rules are secret. The framework won't be published; the benchmarks and the capability threshold are classified and shared with developers as officials see fit.
•The rules are voluntary. The executive order explicitly bars any licensing, preclearance or permitting requirement.
•Nobody is clearly in charge. CAISI's director resigned July 20 after three months, and no single office has been designated for industry outreach.
Why the alarm should be measured:
•The strategic case is genuine. Restricting US open weights while Chinese open models ship freely hands the global ecosystem to Beijing — the argument made by 20+ companies in Nvidia's July 24 open letter.
•Concentration is a real risk too. Rules that only three labs can afford to comply with entrench those three labs.
•Voluntary hasn't meant nothing. The government has already intervened on Fable 5, GPT-5.6 and Google's 3.5 Flash Cyber. A 30-day pre-release window is more access than existed a year ago.
•Open weights are also how the outside world audits any of this — independent researchers can only inspect what they can download.
The trade argument deserves a real hearing. But a review nobody outside the room can read isn't a safeguard the public can rely on — it's an arrangement between the government and six companies that the rest of us are asked to feel reassured by. We just built a review process for the reversible half.
The original report that the Trump administration's guidelines for powerful AI tools exempt open models made by US companies, and that only makers of closed, proprietary US models demonstrating state-of-the-art cybersecurity and hacking capability on performance benchmarks would voluntarily submit them for pre-release testing — a framework most likely to affect OpenAI, Anthropic and Google.
Corroborating the exemption of open-weight systems from the pre-release security review.
The June 2 executive order requiring the framework within 60 days (deadline August 1); attendance by Meta, Nvidia, Microsoft, OpenAI, Anthropic and smaller firms; the up-to-30-day pre-release submission window; the framework remaining confidential and accessible only to participating companies; the executive order's language that it is not a "mandatory governmental licensing, preclearance, or permitting requirement"; prior informal government review of Anthropic's Mythos 5 and Fable 5 (June), OpenAI's GPT-5.6 (July 9) and Google's 3.5 Flash Cyber model (July); and Chris McGuire of the Council on Foreign Relations calling the secrecy "baffling" — "We can't have secret, voluntary rules to regulate the most important tech in the world."
The exclusion of open models from the voluntary frontier testing framework.
The meeting on voluntary safety testing for advanced AI models, and Trump advisers indicating open-weight models would not be safety-tested.
The departure of Chris Fall as director of the Center for AI Standards and Innovation after three months, including his role in CAISI's partnerships with frontier developers; and the open letter signed by more than 20 companies including a16z, Dell, Meta, Microsoft, Nvidia and Palantir urging the administration to preserve access to open-weight models on the grounds that restrictions would consolidate power among a few developers, with Anthropic notably absent and Dario Amodei dissenting.
Chris Fall's resignation; CAISI's responsibility for testing unreleased models from Anthropic, Google DeepMind and OpenAI; OpenAI limiting the GPT-5.6 rollout to "trusted partners" at the US government's request; and Anthropic disabling access to Fable 5 and Mythos 5 to comply with a Commerce Department export control directive.
The definition that decides who is in scope: open models "including Nvidia's Nemotron and Meta's Llama" have publicly accessible core components, closed models are controlled by specific companies, and "major U.S. developers of closed models are OpenAI, Google and Anthropic"; and the White House discussing the unpublished testing rules with staff from Meta, Anthropic, Google, Nvidia and OpenAI.
Alibaba's Qwen family surpassing one billion cumulative downloads on Hugging Face by March 2026 — faster than any model family in history — and overtaking Meta's Llama as the platform's most-downloaded open model, per Forbes reporting.
Confirming that the US government does not plan to safety-test open-weight AI models under the new framework.
The contemporaneous incident referenced here — an agent taking sustained, unsanctioned action against real people and organisations during a routine cyber evaluation, published the same week the White House framework was finalised.