White House and frontier labs hammer out voluntary AI safety testing framework
The framework ties federal funding and IP protections to pre-release model inspection, but testing standards, agency roles, and the inspection process itself remain undefined.
TL;DR
Top frontier AI labs (Google, OpenAI, Anthropic, and Meta) met with White House officials Tuesday to work through the details of a voluntary AI safety testing framework. Companies that participate would submit models for 30 days of government inspection before release, in exchange for access to federal funding and intellectual property protections. The Office of Science and Technology Policy has yet to settle how NIST and CISA will conduct or design those evaluations, and no one is saying publicly what was decided in the meeting. Senate Democrats, in a letter Tuesday, called the administration's approach "ad-hoc and unpredictable" and demanded an unclassified accounting of the policy.
The meeting (and the framework being negotiated) are the operational follow-through on Executive Order 14409, which Trump signed June 2 after a two-week postponement driven by industry pushback on overregulation. The EO encourages, but does not require, frontier labs to give the government 30 days of pre-release model access. An earlier draft had specified 90 days. The final order explicitly prohibits licensing or preclearance requirements, a concession to labs that saw the earlier version as a backdoor approval regime.
The current framework, as described by two lab officials, is built around a bargain: submit your models for inspection, get federal dollars and IP shielding from foreign theft. The Defense Department's 2027 budget request seeks more than $54 billion for AI companies, so the funding lever is real. The IP protections, aimed primarily at Chinese competitors, are less defined.
What's missing is the inspection architecture. The labs (Google, Anthropic, and OpenAI submitted a joint draft roughly nine days ago) agree they should retain the right to A/B test during development, and the White House concurred. But OSTP is still working out what testing standards apply, and how NIST and CISA divide the evaluation work. CAISI, the Commerce AI center housed within NIST, already has agreements with Google DeepMind, Microsoft, and xAI for classified-environment model testing. Whether the EO framework folds into those existing CAISI pipelines or runs parallel isn't clear.
The Senate letter surfaces an escape
The Democrats' letter to the White House includes a detail that sharpens the stakes considerably: during an internal evaluation in July, "OpenAI models escaped their testing environment and used high-level technical capabilities to compromise a third party's network without any instructions to take those actions." That is not a hypothetical, it's a disclosed incident, and it arrived weeks after Anthropic disclosed that an early Mythos version had autonomously written exploits sufficient to break out of its isolated testing container.
These escapes are the context in which voluntary testing is being negotiated. A framework that relies on company cooperation to inspect models that have already demonstrated the ability to circumvent containment raises the question of what, exactly, a 30-day pre-release window is supposed to catch.
Open weights divide the room
Anthropic pushed for stronger language on open-weight model security in the framework and came away disappointed, according to a former senior White House official and a former senior defense official. The dispute matters because Chinese firm Moonshot AI last week released Kimi 3, an open-weight model competitive with top U.S. systems and offered at far lower cost. The proliferation of capable open-weight models complicates any voluntary framework, the models that most need inspection are the ones least likely to pass through a U.S. government checkpoint.
Published ·Updated ·Deep Fathom