Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
White House AI Testing Framework Skips Open-Source Models, Skips Defining 'National Security Risk'

The Trump administration has finalized a voluntary framework for testing advanced AI models for cybersecurity risks, and briefed major AI companies on it at the White House this week, according to Axios. The framework grew out of an executive order President Trump signed in June asking AI companies to share frontier models with the federal government before public release.
Here's the catch. The framework only applies to closed-source models. Open-source AI, the kind anyone can download and inspect, is excluded entirely. Axios reports the guidelines go further than just leaving open models out. They explicitly state the framework cannot be used to restrict open models after they've been released.
That's a real policy choice, not an oversight. Open-weight models from companies like Meta and various Chinese labs are proliferating fast, and plenty of national security officials worry about foreign adversaries fine-tuning open models for weapons design, cyberattacks, or disinformation. Carving those models out of the only federal testing regime that exists is a decision with consequences, whatever the administration's reasoning.
What the framework actually says, and doesn't
The rules set a 30-day window for the government to review new closed-source models before release. But the framework only kicks in for models that are "state-of-the-art" and carry a "national security risk." Neither term is defined, according to Axios's reporting on the document.
An initiative built entirely around identifying national security risks that never explains what a national security risk actually is isn't really a framework. It's a placeholder. Companies like OpenAI and Anthropic have reportedly been asking the government for clearer guidance on how to release models without tripping restrictions they can't even see clearly defined. Vague standards create exactly the kind of regulatory uncertainty that companies say they don't want and that critics of big government say invites arbitrary enforcement down the line.
There's a legitimate case for keeping the rules flexible. AI capabilities move fast, and a rigid definition written today could be obsolete by the time a new model ships. The administration may be betting that ambiguity lets regulators adapt case by case rather than getting boxed in by a definition that doesn't fit tomorrow's technology. That's a coherent argument for discretion. It's also an argument that puts a lot of trust in unelected reviewers to decide, on the fly, what counts as dangerous.
The framework is voluntary. No AI company is legally required to comply. But frontier labs have strong incentive to play along anyway, since running afoul of an undefined national security standard could mean unpredictable blowback, and staying on good terms with the White House matters if you're trying to avoid future restrictions nobody has written yet.
Who gets squeezed
Smaller AI providers are the ones most exposed here. Big labs like OpenAI, Anthropic, and Google have the lawyers and government-relations teams to navigate ambiguous rules through direct dialogue with the White House. Smaller companies don't have that kind of access. If the rules aren't written down publicly, and Axios reports the administration has no plans to release the framework's full details, then guidance ends up flowing informally to whoever has a seat at the briefing table.
Regulatory frameworks that exist mostly as verbal understandings between government officials and the biggest players in an industry tend to lock in the biggest players' advantages. It's the kind of dynamic that conservatives normally flag when regulators get too cozy with incumbents, and it's worth flagging here too.
The Verge's own framing calls the plan "limited and vague," and on the facts reported by Axios, that description fits. Excluding open models outright while leaving core terms undefined isn't a minor technical gap. It's the two biggest structural questions in AI safety policy right now, left unanswered in the one document meant to answer them.
None of this means the administration is acting in bad faith. Cybersecurity risk assessment for AI is genuinely hard, and no country has cracked how to regulate this technology well. But a voluntary, undefined, publicly unreleased framework isn't a rulebook. It's a conversation the government is having with a handful of companies, and everyone else is guessing at the terms.
The open question now is whether Congress or the administration follows up with anything enforceable, or whether "state-of-the-art" and "national security risk" stay undefined indefinitely while frontier labs keep shipping models under a rulebook nobody outside the briefing room has actually seen.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.