Treasury sends AI vulnerability clearinghouse plan to White House
Control of the first vulnerability intake determines who owns the clock, and patch timing is where voluntary coordination becomes operational pressure.
TL;DR
Inside Cybersecurity reports that Treasury drafted the AI cybersecurity vulnerability clearinghouse policy required by the June 2 Trump executive order and sent it to the White House after meeting the July 2 internal deadline. Federal primes, managed service providers, C3PAOs, critical-infrastructure operators and agencies should not reroute disclosures yet. The unresolved issues are the operational ones: who receives reports first, how fast patches move, how sector risk management agencies fit, and whether the Cybersecurity and Infrastructure Security Agency has the resources to run its share.
Inside Cybersecurity’s account, based on a banking industry source, gives the first useful outline of the Trump administration’s AI vulnerability clearinghouse: Treasury is drafting the policy, the White House is reviewing it, and CISA is expected to supply operational resources with support from the Office of the National Cyber Director and others. That is not a launch notice. It is the part before launch where the intake diagram gets drawn, which is often where the real authority sits.
The June 2 executive order directed Treasury to form the clearinghouse in voluntary collaboration with the AI industry and critical-infrastructure operators. The job is narrow enough to sound procedural and broad enough to matter: coordinate and deconflict vulnerability scanning, discovery, validation, remediation priorities and patch distribution. The banking source told Inside Cybersecurity the draft is meant to lay the groundwork for infrastructure and answer initial questions about disclosure speed, which agency gets the report first, and how sector risk management agencies are affected.
For practitioners, that is the useful signal. Do not rewrite an incident response plan around a document that has not been released. But do identify where current AI-related vulnerability disclosures go today, who has authority to notify government, and which contracts or customer obligations would be affected if the clearinghouse changes patch-coordination timelines. Primes, managed service providers, C3PAOs and critical-infrastructure vendors will feel this less as an abstract AI policy and more as another clock in the disclosure and remediation workflow.
The structural shift is also worth watching. The source described Treasury as the lead, with CISA and ONCD supporting, while CISA resources would help implement the clearinghouse. That is a different center of gravity from a purely CISA-led vulnerability coordination model. It may be justified by the executive order’s critical-infrastructure and banking-sector frame. It also makes the unanswered resourcing question harder to ignore: if Treasury owns the policy and CISA carries much of the operational load, the final guidance needs to say where the handoff happens, not merely that agencies will coordinate.
The source expects the policy to be released this month, possibly after President Trump returns from the 2026 NATO Summit in Turkey. Until then, the news is not that the clearinghouse exists. The news is that the administration appears to be deciding who gets the first call, who sets the patch tempo, and whether CISA has enough people and money to make the diagram real.
Published ·Deep Fathom