ai-cybersecuritytrade-pressNewsThe Broadside2 min read

Cairncross bets on open source, not regulation, for AI security

The administration's "no rules" posture runs into the reality of export controls it already imposed.


TL;DR

National Cyber Director Sean Cairncross used Black Hat 2026 to frame the administration's AI security approach as voluntary information-sharing, not regulation. "A regulatory regime would be obsolete 48 hours after it had gone through whatever process," he told the Las Vegas conference. He also committed the U.S. to making its open-source AI "the preferential adoption by planet Earth." Two months after Executive Order 14409 scaled back an earlier draft, the no-rules posture is under strain: the administration has imposed export controls on Anthropic's frontier models and stood up the Gold Eagle clearinghouse, both of which look regulatory to the companies navigating them.

National Cyber Director Sean Cairncross stood on a Black Hat stage Tuesday and argued that AI security doesn't need new rules, it needs a network. "The design of this is that when there is a breach, when there is an event, that system, that network of connections can exist, adapt to that, and seek to remedy that as quickly as possible," he said. The vision: government and industry sharing threat intelligence voluntarily, with open-source U.S. models carrying American AI norms abroad. No licensing regime. No new regulatory apparatus.

It's a clean pitch. It's also at odds with what the administration has already done.

Executive Order 14409, signed June 2, was itself a retreat. An earlier draft would've given the government 90 days of pre-release access to frontier models. Industry pushed back, Trump adviser David Sacks called the revision "a game changer," and the final order cut the window to "up to" 30 days and explicitly stated nothing in the program "will be construed as mandatory or part of a federal licensing or permitting regime."

Then came the export controls. Without warning, the administration restricted Anthropic's Fable 5 and Mythos 5, a move that's a regulatory gate in function if not in name. Meanwhile, the Gold Eagle clearinghouse, run by Treasury with CISA and DOD input, is already receiving vulnerability reports and prioritizing patches using closed-source frontier models.

Cairncross's open-source bet is the genuinely new element. Making U.S. open-source AI "the preferential adoption by planet Earth" is ambitious, and it aligns with the administration's instinct to compete rather than regulate. But for the contractors and security engineers who have to navigate this landscape, the operational reality is already more complicated than the rhetoric. Voluntary doesn't mean optional when export controls can land on your model without notice, and Gold Eagle is standing by to scan it.


Published ·Updated ·Deep Fathom