The White House AI cybersecurity framework is complete, according to an administration official, but the public still cannot see the tests that determine which advanced models fall within it. The distinction matters: President Donald Trump’s June executive order publicly lays out the program’s structure, while requiring the cyber-capability benchmark and the designation threshold to stay classified.
The White House official said the voluntary framework met its August 1 deadline and that discussions with industry on next steps were under way, Politico reported August 3. CNBC separately reported that the administration had not released the finished framework or its testing metrics publicly.
That leaves a policy with three different levels of visibility. The executive order is public. Its operating framework was reported as unpublished as of August 3. The rules used to assess a model’s advanced cybersecurity capability, including the line at which it becomes a “covered frontier model,” are expressly classified under the order.
What does the White House AI cybersecurity framework do?
The June 2 order directs the Treasury Department, the National Security Agency and the Cybersecurity and Infrastructure Security Agency, working with other officials, to maintain the classified assessment process. The NSA director makes covered-frontier-model determinations after consulting specified officials, according to the order.
A developer can voluntarily ask the government whether a model in development meets that designation. If it does, the developer may give the federal government access to the model for as long as 30 days before providing it to other trusted partners. The government and developers can also choose trusted partners for early access.
The stated goal is to test whether increasingly capable AI models could help find software flaws or support sophisticated cyberattacks, while making those systems available for defensive work. The order also calls for an AI cybersecurity clearinghouse to coordinate vulnerability discovery and patching, along with measures involving federal cyber defense, hiring and enforcement against illegal AI-assisted intrusions.
“Voluntary” has a legal boundary in the order. Section 3 says the framework cannot be read as permission to impose federal licensing, preclearance or permitting requirements on the development, publication, release or distribution of AI models. That does not answer the practical question of how an unbriefed developer would join a program whose finalized operating details have not been released. Politico reported that this was unclear.
Which parts of the policy are still secret?
The government has not disclosed the benchmark criteria, the threshold for covered status or a definitive public list of models that qualify. The order requires the first two to be classified. Reporting has not established whether the completed voluntary framework itself will eventually be published.
That gap has prompted questions about transparency and access. WIRED reported that critics, including AI-safety advocates and people familiar with White House discussions, warned that a closed process could make outside accountability harder and favor large developers already in the room. Those are concerns, not demonstrated outcomes. For now, the public gets the program’s outer shell, while the test and the cutoff remain behind the government door.
This story draws on original reporting from WIRED.