President Trump signed Executive Order 14409 on June 2, 2026, creating the first voluntary pre-deployment cybersecurity testing framework for frontier AI models before they reach the public. The order, titled “Promoting Advanced Artificial Intelligence Innovation and Security,” asks the companies building the most advanced AI systems, think OpenAI, Anthropic and Google DeepMind, to volunteer their models for government review. Agencies get up to 30 days to look for national security and cybersecurity flaws before a wider release goes ahead.
The catch, and it’s a significant one, is that none of this is mandatory. The White House’s own text explicitly rules out a licensing or preclearance regime. That single design choice has shaped nearly every piece of commentary since the signing: is a voluntary AI executive order a meaningful first step toward accountable frontier-model testing, or a symbolic gesture that leaves the hardest questions to Congress? Six weeks on, with an August 1 deadline for the full testing framework now approaching, the answer is still being argued in law firm memos, cybersecurity trade press and Capitol Hill hallways alike.
The order lands at a moment when the cybersecurity conversation around AI has shifted from theoretical to operational. Security teams are no longer just worried about AI being misused by outside attackers, they’re increasingly worried about the models themselves becoming an attack surface, capable of writing exploit code, automating reconnaissance, or getting jailbroken into revealing dangerous technical detail. EO 14409 is Washington’s most ambitious attempt yet at building a standing government process for catching that kind of risk before a model ships, following on from the narrower Executive Order 14306 that Trump signed on June 6, 2025, rather than reacting to it after the fact.
Don't miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
What Executive Order 14409 Actually Requires
Strip away the political framing and EO 14409 is a fairly narrow instrument. It directs federal agencies to build a process through which developers of “covered frontier models” can hand over early access to their systems, voluntarily, for government cybersecurity testing. The Latham & Watkins summary of the order lays out the mechanics: the NSA director, in consultation with other officials, decides which models qualify as “covered,” a classified benchmarking process was due within roughly 60 days of signing, and the voluntary engagement framework itself has to be finalized by August 1, 2026.
Access granted under the order runs for up to 30 days before a company’s planned release date, and the text leaves room to extend that access to “other trusted partners” under confidentiality, cybersecurity, insider-risk and intellectual-property protections, according to Crowell & Moring’s client alert. Treasury, Defense, Commerce and the Department of Homeland Security all get named roles in standing the program up. None of it, the order stresses more than once, creates a new licensing or permitting requirement for AI development.
| Provision | Detail | Status / Deadline |
|---|---|---|
| Order number and title | EO 14409, “Promoting Advanced Artificial Intelligence Innovation and Security” | Signed June 2, 2026 |
| Framework type | Voluntary pre-release cybersecurity testing | Not a licensing regime |
| Government testing window | Up to 30 days before public release | Reportedly cut down from a 90-day draft |
| Voluntary engagement framework | Agencies design the formal process for developer participation | Due by August 1, 2026 |
| Classified benchmarking process | NSA director designates “covered frontier models” | Due roughly 60 days after signing |
| Vulnerability clearinghouse | Treasury-led, coordinates disclosure with AI firms and infrastructure operators | Ongoing implementation |
| DOJ enforcement directive | Attorney General to prioritize prosecution of AI-enabled computer crime | Immediate |
| Licensing or preclearance requirement | None created | Explicitly excluded |
Inside CAISI, the Agency Now Doing the Testing
The body actually expected to run point on evaluations is CAISI, the Center for AI Standards and Innovation, housed under the Commerce Department’s National Institute of Standards and Technology. CAISI is the rebranded successor to what was originally stood up as the U.S. AI Safety Institute, repositioned under the current administration with more of an emphasis on competitiveness and standards work alongside its safety-testing mission.
According to Politico’s reporting, OpenAI’s head of global affairs, Chris Lehane, told reporters that CAISI already has the capability to run sophisticated model evaluations, and that OpenAI, Anthropic and other labs already share information about upcoming models with the center on an informal basis. That’s a notable data point on its own: some of the voluntary information-sharing this executive order formalizes was reportedly already happening before the order existed. Politico’s account also describes Lehane raising a separate concern, that the order’s classified benchmarking track could make it harder for companies to know exactly when and how intelligence agencies are scrutinizing their models.
The Frontier Labs in the Crosshairs
EO 14409 doesn’t publish a roster of participating companies, but the “covered frontier model” language points squarely at the same handful of labs that dominate today’s capability rankings. Anthropic’s Claude Opus 4.8, OpenAI’s GPT-5.6 and Google’s Gemini 3.1 Pro currently anchor that top tier, with xAI’s Grok models pushing for a seat at the same table. Coverage from NPR and Politico both describe OpenAI, Anthropic and Google as already engaged in conversations around the framework, though none of the sources reviewed for this article confirm a finalized, formal list of enrolled participants.
That ambiguity is arguably the point. Because the program is opt-in, a company’s participation becomes a signal in itself, evidence that it’s playing along with Washington’s preferred version of AI governance, without anyone being able to point to a rule that forced its hand. Smaller labs and open-weight model developers face a different calculus entirely: fewer resources to manage a federal review process, and less to gain from a trust signal aimed mainly at frontier-scale systems.
That two-tier dynamic is worth watching closely over the rest of 2026. A frontier lab that opts in gets a marketing line and, potentially, an inside track on federal and enterprise contracts. A smaller developer that skips the program faces no penalty today, but could find itself at a disadvantage later if CAISI review becomes an unofficial prerequisite for selling into government or heavily regulated markets. Nothing in the order’s text creates that outcome directly. Market pressure and procurement habits could create it anyway.
The Treasury-Led Vulnerability Clearinghouse
A second, less-discussed piece of the order sets up a clearinghouse, led by the Treasury Department, meant to help AI firms, broader technology companies and critical infrastructure operators find and fix vulnerabilities in widely used software. It extends a pattern the administration had already sketched out in America’s AI Action Plan, released in July 2025, which tied together three separate executive orders around a DHS-led AI Information Sharing and Analysis Center, or AI-ISAC, meant to bolster critical infrastructure cybersecurity. The idea borrows from a decades-old pattern in cybersecurity policy: centralize vulnerability discovery, then coordinate how patches move out to the operators who need them, rather than leaving every sector to handle disclosure on its own.
What’s new is the assumption baked into the design, that AI systems themselves are now capable enough to both find dangerous flaws and get exploited by them at a pace traditional disclosure timelines weren’t built for. Treasury’s involvement also signals that the administration sees this as much as a financial-sector resilience issue as a defense one, given how much of the country’s payments and banking infrastructure Treasury already touches.
Why the Testing Window Shrank From a Reported 90 Days to 30
An earlier draft of the order reportedly gave federal reviewers up to 90 days with a model before release, a window that would have given agencies far more room to run deep evaluations, but also would have handed the government significant influence over a lab’s product-launch calendar. The final text cut that down to 30 days.
Thirty days is enough time to run structured red-teaming and benchmark comparisons against known attack patterns. It is not enough time for the kind of open-ended probing that finds the failure modes nobody thought to test for. That tradeoff, speed versus depth, sits at the center of nearly every piece of expert pushback the order has drawn, and it is likely to be the first thing revisited if a serious incident ever traces back to a model that cleared review in under a month.
There’s also a practical staffing question underneath the calendar math. Running a meaningful cybersecurity evaluation of a frontier model inside 30 days means CAISI and its partner agencies need reviewers who understand both offensive security and how modern large language models actually fail, a skill combination that is scarce and expensive even inside the biggest tech companies. A short government pay scale competing with frontier-lab compensation for that talent is its own quiet risk to how well this framework performs once the paperwork is finished.
Industry and Policy Reaction
The White House’s own framing, via the Office of Science and Technology Policy, leans hard on the voluntary nature of the program. OSTP has described the order as a process for frontier labs “to voluntarily share cutting-edge cyber models in order to secure critical infrastructure and strengthen the government’s own cyber defenses,” according to a Cato Institute analysis of the order. OSTP has also pushed back directly on characterizations of the order as a backdoor regulatory regime, stating: “We are NOT conducting oversight of all new models, as that level of government overreach would have chilling effects on free speech and innovation.”
“President Donald Trump has signed an executive order establishing a voluntary framework for federal vetting of the most advanced frontier AI models before their public release.”
SecurityWeek
SecurityWeek’s own coverage frames the core mechanism in similarly plain terms: “the directive provides government agencies with a 30-day testing window to assess potential national security and cybersecurity risks posed by these cutting-edge systems,” the outlet reported. The publication’s “Feedback Friday” roundup gathered reactions from ten cybersecurity executives spanning firms from PwC to Huntress, and the split was predictable: broad relief that Washington is finally treating AI-specific cyber risk as its own category, paired with skepticism that a voluntary program has enough teeth to matter once the initial news cycle fades.
The Cato Institute, generally skeptical of expanding federal authority, noted more approvingly that “the order calls for several actions to render the federal government and critical infrastructure entities more resilient” in the face of AI-related threats, a rare point of agreement between a libertarian-leaning think tank and an administration usually associated with deregulation.
From EO 14110 to EO 14179 to EO 14409: Three Years of AI Policy Whiplash
EO 14409 doesn’t exist in a vacuum. It’s at least the fourth major swing of federal AI policy in under three years, and the contrast with its predecessors explains a lot of the reaction it’s getting. President Biden’s Executive Order 14110, signed in October 2023, took a broad governance approach, touching everything from safety testing and civil rights to labor impacts, with reporting requirements for developers of the largest models. Days before leaving office, Biden also signed the narrower Executive Order 14144 on January 16, 2025, directing the Pentagon to stand up a program using advanced AI models for cyber defense within 270 days and to fold AI vulnerability management into existing Defense Department, DHS and Director of National Intelligence processes within 150 days. President Trump rescinded EO 14110 during his first days back in office, replacing it in January 2025 with Executive Order 14179, “Removing Barriers to American Leadership in AI,” an explicitly deregulatory document aimed at clearing perceived obstacles to U.S. AI competitiveness.
EO 14409 reads like a course correction on that deregulatory line, not a reversal of it, and it’s not even the administration’s first AI-specific cybersecurity structure. That distinction belongs to Executive Order 14306, which Trump signed on June 6, 2025 and which already pushed federal agencies to open cyber-defense datasets to outside researchers across at least four departments, Commerce, Energy, DHS and the National Science Foundation, by November 1, 2025, while directing DoD, DHS and the Director of National Intelligence to fold AI software vulnerabilities into their existing tracking processes by that same date. EO 14409 builds directly on that foundation a year later, but it keeps the voluntary, industry-friendly posture of EO 14179 rather than reviving anything resembling EO 14110’s mandatory reporting regime.
| Executive Order | Signed | Approach | Core Focus |
|---|---|---|---|
| EO 14110 (Biden) | October 30, 2023 | Broad governance, reporting requirements for the largest models | Safety, equity and cross-sector AI risk management |
| EO 14179 (Trump) | January 23, 2025 | Deregulatory, rescinded EO 14110 | Removing barriers to U.S. AI innovation |
| EO 14409 (Trump) | June 2, 2026 | Voluntary, narrowly scoped to cybersecurity | Frontier-model cybersecurity testing via CAISI |
Market Impact: What This Means for AI Labs and Enterprise Buyers
For the frontier labs themselves, the immediate cost of participation is manageable. Companies already running internal red-teaming programs, which every major lab claims to do before a flagship release, aren’t being asked to build much new infrastructure. The bigger variable is timeline risk: a 30-day government review window sitting on top of an already competitive release cadence is a real scheduling constraint when rivals are shipping model updates every few months.
The more interesting second-order effect shows up on the buyer side. Federal agencies and large enterprise customers, especially in defense, finance and critical infrastructure, tend to favor vendors who can show a paper trail of government engagement. If CAISI clearance becomes a recognizable credential the way FedRAMP authorization did for cloud services, participation could turn into a procurement advantage that has nothing to do with the executive order’s stated cybersecurity goals. That dynamic would push adoption forward even without a mandate attached, and it’s the scenario most likely to determine whether this voluntary AI executive order ends up mattering in practice.
Cloud infrastructure providers sit downstream of all of this. AWS, Microsoft Azure and Google Cloud each host frontier-model inference at massive scale for enterprise customers, and a federal cybersecurity stamp of approval on the models themselves would make it easier for those platforms to sell AI workloads into regulated industries that have historically moved slowly on generative AI adoption. Insurance underwriters covering AI-related liability are another quiet stakeholder here: a documented, government-reviewed testing history is exactly the kind of paper trail that shapes how cyber-insurance premiums get priced for companies deploying frontier models in production.
A Lighter Touch Than Brussels: Comparing the US and EU Approaches
Set next to the European Union’s approach, EO 14409 looks even more restrained. The EU AI Act already imposes mandatory evaluation, adversarial testing and incident-reporting obligations on general-purpose AI models classified as carrying “systemic risk,” enforced through the EU AI Office rather than left to a company’s discretion. Washington’s framework runs the opposite direction: opt-in participation, a 30-day advisory window, and an explicit promise not to build a licensing system at all.
That gap matters for any lab operating in both markets, since it means the EU’s mandatory testing regime effectively sets the compliance floor globally. A model built to satisfy the AI Office’s systemic-risk obligations will, almost by default, clear the bar EO 14409 asks for voluntarily. The U.S. and EU regulatory tracks for AI governance more broadly continue to diverge in exactly this pattern: Brussels legislating first and Washington responding with narrower, industry-negotiated frameworks.
The DOJ’s New Mandate to Prosecute AI-Enabled Cybercrime
Away from the testing framework itself, EO 14409 also directs the Attorney General to prioritize enforcement of existing federal criminal statutes against anyone who uses AI to gain unauthorized access to computer systems, or who deploys AI agents to unlawfully collect data for criminal purposes. Unlike the testing provisions, this piece doesn’t require new legislation. It’s a resourcing and prioritization directive layered on top of laws already on the books, mainly the Computer Fraud and Abuse Act.
The timing lines up with a broader pattern tech companies have already been fighting in civil court. Google’s own lawsuit against an AI-powered phishing operation tied to roughly $1.9 billion in reported losses is the kind of case the DOJ directive seems designed to eventually take over from private plaintiffs, at least for the criminal side of the equation. Whether federal prosecutors actually have the staffing and technical expertise to act on that priority at scale is a separate question the order doesn’t answer.
Civil-liberties and defense attorneys are likely to watch this piece closest of all. “AI-enabled” is not a precisely defined legal term, and prosecutors given a political mandate to prioritize a category of crime tend to interpret that category broadly. Expect defense counsel in ordinary computer-fraud cases to start arguing, within a year or two, about whether a defendant’s use of any AI tool at any stage of an alleged offense qualifies a case for this heightened enforcement priority.
What Happens Next: 5 Predictions for the Voluntary AI Testing Framework
- The August 1 deadline slips or lands vague. Federal rulemaking on fast-moving tech topics has a well-worn habit of missing self-imposed deadlines or publishing frameworks light on operational detail. A delay into Q4 2026 would not be a surprise.
- CAISI’s mandate grows. With OpenAI publicly pushing for the center to take on a larger testing role, expect the administration to funnel more authority and funding toward CAISI rather than standing up a competing body.
- Participation splits along a two-tier line. Frontier labs with existing federal relationships, OpenAI, Anthropic, Google DeepMind, likely opt in early. Smaller and open-weight developers mostly sit this one out, since the trust-signal benefit is smaller and the compliance overhead is proportionally larger.
- Congress stays on the sidelines until something breaks. NPR’s coverage of the order already flags that binding AI regulation would require new legislation. That’s unlikely to happen without a triggering incident, a serious breach or misuse case that a voluntary review process failed to catch.
- State-level AI rules keep advancing regardless. California, Colorado and New York have shown no sign of waiting on Washington. A voluntary federal framework doesn’t preempt any of that activity, and the resulting patchwork will keep fueling industry calls for federal preemption legislation, calls this executive order does nothing to resolve.
Frequently Asked Questions
What is Executive Order 14409?
Executive Order 14409, “Promoting Advanced Artificial Intelligence Innovation and Security,” is a directive President Trump signed on June 2, 2026. It creates a voluntary framework letting developers of advanced AI models submit them to federal agencies for cybersecurity testing before public release.
Is AI model testing under the executive order mandatory?
No. The order explicitly states it does not create a licensing, preclearance or permitting requirement. Participation by AI developers is voluntary, and the White House has stressed it is not conducting oversight of all new models.
What is CAISI and what role does it play?
CAISI, the Center for AI Standards and Innovation, is the Commerce Department body expected to lead most model evaluations under the new framework. It is the rebranded successor to the original U.S. AI Safety Institute and already receives informal information-sharing from labs including OpenAI and Anthropic, according to Politico’s reporting.
How long do federal agencies have to test frontier AI models?
Up to 30 days before a company’s planned public release. An earlier draft of the order reportedly allowed as much as 90 days, before the window was shortened in the final version.
Which AI companies are involved in the voluntary framework?
The order does not name specific companies. Coverage from NPR and Politico describes OpenAI, Anthropic and Google as engaged in early conversations, and the “covered frontier model” language is widely understood to target the same handful of labs producing today’s most capable systems.
How does EO 14409 differ from Biden’s 2023 AI executive order?
Biden’s EO 14110 (October 2023) was a broad governance order covering safety, equity and labor impacts, with reporting requirements for large models. Biden also signed the narrower EO 14144 on January 16, 2025, pushing the Pentagon toward AI-driven cyber defense, before Trump rescinded EO 14110 later that January via EO 14179. Trump’s administration then issued its own cybersecurity-focused EO 14306 on June 6, 2025, ahead of EO 14409. EO 14409 is narrower still, focused specifically on voluntary frontier-model cybersecurity testing rather than the mandatory reporting regime EO 14110 once proposed.
When does the full voluntary engagement framework take effect?
Federal agencies are directed to finalize the framework by August 1, 2026. A classified benchmarking process for designating “covered frontier models” was due roughly 60 days after the order’s signing.
Does the order create new AI regulations or enforcement powers?
It creates no new licensing regime. It does direct the Attorney General to prioritize prosecuting AI-enabled cybercrime under existing statutes, and it sets up a Treasury-led clearinghouse for coordinating vulnerability disclosure across AI firms and critical infrastructure operators.
Related Coverage
- Opus 4.8 vs GPT-5.6 vs Gemini 3.1 Pro: $18 Price Gap [2026]
- Google Sues AI Phishing Ring Tied to $1.9B in Losses [2026]
- Privacy-First AI Assistants Are Emerging as a Distinct Product Category
- GhostApproval Flaw: 3 of 6 AI Coding Tools Unpatched [2026]
- ChatGPT Market Share Falls to 46.4% as Rivals Gain [2026]
- Splunk Zero-Day: CVSS 9.8, 3-Day CISA Deadline [2026]
- More Cybersecurity Coverage


