The White House says its AI framework is finished. It won't say what's in it.
TL;DR: On 3 August the White House said the voluntary frontier-model evaluation framework required by Executive Order 14409 was complete by its 1 August deadline. It has not been published, officials declined to say whether it ever will be, and CAISI has posted nothing since 23 July — verified directly against NIST, not inferred from an absence of coverage. The framework reportedly grants federal agencies a pre-release window of up to 30 days on covered models. Anthropic, Google, Meta and OpenAI met with the Office of the National Cyber Director; the first three reviewed a draft and submitted edits in late July. CNBC reports another meeting Tuesday 4 August. The detail that matters: the executive order explicitly classifies the benchmark and the coverage threshold — and does not classify the framework. Secrecy here is a choice. Two days earlier, the EU switched on transparency rules that anyone can read.
What was actually confirmed
This site has held this story for five consecutive editorial passes, on the grounds that reporting about an imminent announcement is not an announcement. Something has now genuinely changed, and it is worth being precise about what.
A White House official stated that the voluntary framework outlined in the 2 June executive order was complete by the deadline — 1 August, sixty days after signing. That is the confirmation. It is also, very nearly, the entirety of the confirmation.
What was not provided: the contents, the identity of everyone who has seen it, the date companies begin operating under it, or whether it will be published at all. Officials declined to commit either way.
What is independently checkable: CAISI, the NIST body expected to carry this work, has published nothing newer than 23 July — an assessment of Kimi K3’s cyber capabilities conducted with the UK AI Safety Institute. No framework, no voluntary standards, no pre-release review agreement. There are no Federal Register notices and no OSTP statement. That check was run directly against NIST rather than inferred from the absence of press coverage, which matters, because absence of coverage and absence of a document are different claims.
So the accurate description of the current state is: the framework exists as an assertion. It does not exist as a public artefact.
The classification argument does not work
The obvious defence is national security, and for parts of EO 14409 it is a real one.
The executive order deliberately classifies two things: the benchmarking process used to assess advanced cyber capabilities, and the threshold that determines which models are covered. Both designations are defensible — a public benchmark for cyber capability is a roadmap, and a public threshold is a line developers can engineer up to without crossing.
The order does not extend that designation to the voluntary framework.
That is not an oversight; it is a drafting distinction, and it means the framework’s non-publication is discretionary. The administration could release it tomorrow without touching anything the order protects. Policymakers and outside observers expected exactly that, which is why the silence is being noticed.
There is a second problem with the secrecy, and it is structural rather than political. A voluntary framework nobody can read is not voluntary in any operative sense. Voluntariness requires the ability to opt in. Opting in requires knowing the terms. A company that has not been briefed cannot volunteer for something it cannot see, which means participation is determined by who gets invited into the room rather than by who chooses to comply.
Who is in the room
Anthropic, Google, Meta and OpenAI attended the Office of the National Cyber Director meeting. Google, OpenAI and Anthropic reviewed a draft and submitted edits in late July. Another session is reported for Tuesday.
The White House says it is engaging with many more partners than those companies. That may well be true; it has not been independently confirmed, and it is the kind of claim worth marking as unverified rather than repeating.
Take the confirmed part at face value and the shape is clear: the four largest US model developers have seen a document that their competitors have not, and three of them edited it. Whatever the intent, the effect is that the firms with the most capacity to absorb compliance cost helped set the compliance terms — and smaller labs, open-weight projects and foreign entrants will encounter those terms fully formed, if they encounter them at all.
The precedent for what happens when a lab lands on the wrong side of this process is not hypothetical. The same legal authority underpinned the June suspension of Fable 5 and Mythos 5, lifted on 30 June only after Anthropic agreed to a shared voluntary security standard with Amazon, Microsoft and Google. “Voluntary” in this domain has an established track record of being enforced.
The comparison the week set up
Two governments, the same week, opposite theories of how AI governance should work.
The European Union, 2 August. Article 50 of the AI Act became applicable. The Commission published guidelines, last updated 29 July. A Code of Practice on Transparency of AI-generated Content was published on 10 June and had roughly 190 signatories by late July. There was a public consultation. The enforcement structure is named: national market surveillance authorities, the AI Office, the European Data Protection Supervisor. A company anywhere in the world can read the obligation, decide whether it applies, and comply without asking permission. Full breakdown here.
The United States, 1–3 August. The framework is complete, unpublished, undistributed beyond a handful of firms, with a classified coverage threshold and no stated timeline for either implementation or release.
Neither approach is self-evidently correct. The EU’s is slower, more bureaucratic, and produces obligations that apply to a solo publisher in Riga as readily as to Google — a genuine cost. The US approach is faster, more adaptable, and keeps genuinely sensitive capability information out of adversaries’ hands.
But they diverge on one axis that is not a matter of taste: one produces a document you can check yourself, and the other does not. That difference compounds. Vendors build to rules they can read, because those are the rules they can demonstrate compliance with to customers, auditors and procurement teams. A framework that exists only in briefings generates no artefacts, no audit trail, and nothing a buyer can ask a vendor to evidence.
This is the same pattern that ran through Monday’s coverage of Astra’s formally verified proofs, and it generalises well past mathematics: a claim you can check independently is worth categorically more than a claim you must take on trust. Governance is not exempt.
Why this matters
The deadline was met in the narrowest possible sense. A document exists. Nobody outside a small circle can read it, no company can act on it, and no observer can evaluate whether it does what the executive order asked. Whether that counts as meeting a deadline is a definitional question the administration has answered in its own favour.
The classified threshold is the sharpest practical problem. A developer cannot know in advance whether a model crosses the coverage line, because the line is secret. That risk is trivially absorbed by a firm with a government-affairs team and a standing relationship with ONCD. It is not trivially absorbed by anyone else — which effectively makes access to the process a precondition for operating safely near the frontier.
It changes model release timing more than model capability. A pre-release window of up to 30 days on covered models means what reaches you may reach you later. The government-gated preview that delayed GPT-5.6 is the shape of things, and that was under an ad-hoc arrangement rather than a standing framework.
It sits alongside a wider US turn toward restriction. Read with the proposed open-source curbs and chip provisions, the direction is consistent: control at the point of release, negotiated privately with a small number of large firms.
Self-governance keeps outrunning state governance. OpenAI published its own frontier governance framework in May. Anthropic disclosed its own evaluation failures in July. The FLI safety index found nobody passing but the labs at least publishing. On present evidence, the most detailed public information about frontier model safety continues to come from the companies rather than the regulator.
Honest caveats
This may be temporary. The framework could be published this week, which would make most of the above moot. Officials declined to rule publication out; they simply would not commit.
The 30-day window comes from the executive order and reporting, not from the framework. Until the text is public, every specific claim about triggers, scope and obligations is second-hand — including the ones in this article.
The broader-engagement claim cannot be checked. The White House says many more partners are involved than the four named. That may be accurate. It is unverified.
“Structural failure” is one analyst’s framing, published on 1 August before the White House statement, and is quoted here as opinion rather than finding. Some of the delay may be ordinary interagency friction across Treasury, NSA, CISA and NIST rather than anything deliberate.
No critic is on the record yet. The reporting reviewed for this article quotes no named policymaker objecting. Expect that to change; treat its current absence as a fact about the reporting, not about the level of concern.
What to do about it
If you buy AI tools: nothing this week. The effects are second-order and arrive as release timing, not as features or prices.
If you sell software into regulated buyers: the EU regime is the one to build against, for the practical reason that it is the only one with a published document to evidence compliance against. Building to the readable standard and inheriting the rest is the cheaper path.
If you are a smaller lab or an open-weight project: the coverage threshold is classified and you are probably not in the room. That is a risk to track deliberately rather than assume away.
If you are following this story: the thing to watch is not the next announcement. It is whether a document ever appears. This site has held the framework story for five weeks on the principle that reporting about a document is not a document — and by that standard, the wait is not over.
Related: The EU AI Act’s transparency rules are live · Trump’s AI executive order on frontier review · July 2026 in AI — what changed for buyers
Frequently asked questions
Has the White House actually published the AI framework?
No. A White House official said the voluntary framework outlined in the 2 June executive order was complete by the 1 August deadline. It has not been released publicly, officials declined to say whether it ever will be, and CAISI — the NIST body expected to carry it — has published nothing newer than 23 July. What exists publicly is a statement that a document exists.
Isn't the framework classified?
Not according to the executive order. EO 14409 explicitly designates two things as classified: the benchmarking process for assessing advanced cyber capabilities, and the threshold determining which models are covered. It does not apply that designation to the voluntary framework itself. That distinction is why the non-publication is a discretionary choice rather than a legal constraint.
What is the 30-day window?
The framework is reported to give federal agencies a pre-release window of up to 30 days on covered frontier models, so that government evaluators can assess them before public launch. Because the framework text is unpublished, the precise trigger conditions, scope and obligations are known only from the executive order and reporting — not from the framework itself.
Which companies have seen it?
Anthropic, Google, Meta and OpenAI attended a meeting with the Office of the National Cyber Director. Google, OpenAI and Anthropic reviewed a draft and submitted edits in late July. CNBC reports the White House will host AI companies again on Tuesday 4 August to review the framework. The White House says it is engaging with many more industry partners than those named; that broader engagement has not been independently confirmed.
Does this affect which AI tools I should buy?
Not directly or immediately. The practical effects are second-order: a 30-day government pre-release window can delay when frontier models reach you, and a classified coverage threshold means a developer can cross it without warning. The more durable consequence is competitive — a framework negotiated privately with the largest labs is easier for those labs to comply with than for anyone else.
Sources
- Axios — White House finalizes AI framework behind closed doors
- CNBC — White House to host AI companies Tuesday to review new model-testing framework
- NIST — Center for AI Standards and Innovation (CAISI) publications
- Latham & Watkins — President Trump Signs Executive Order Establishing AI Cybersecurity and Frontier Model Framework
- Forkast News — White House AI Framework Deadline Lapses Without Public Deliverables
Related tool reviews
Questions or corrections? Email Pick Right. Want the full list? See all news.