The White House has finalized a voluntary framework for reviewing advanced AI models for safety and cybersecurity risks, reportedly asking companies to submit models up to 30 days before release under a June executive order. The Trump administration plans to limit the framework and its testing criteria to a small group of technology companies rather than publish them; open-weight models may also be exempt, leaving a significant class of powerful systems outside the process.
Protect Democracy warned that nonpublic review rules could enable political favoritism or corruption and prevent meaningful scrutiny of whether agencies are conducting current, adequate cybersecurity testing. The group cited an OpenAI model’s reported hacking of Hugging Face as evidence of growing AI-enabled cyber risk, while Democratic lawmakers Greg Casar and Josh Becker called for transparency; Becker pointed to California’s proposed SB 813, which would publicly disclose AI-risk evaluation standards and methodologies.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
Illinois lawmakers passed SB 315 and sent it to the governor. The bill would require annual third-party audits for covered frontier-AI developers and authorize penalties of up to $3 million per violation.
California State Senator Josh Becker submitted a declaration supporting Protect Democracy's complaint and court request. He said California was considering SB 813, which would publicly disclose benchmarks, standards, and methodologies used to evaluate AI-system risks.
Protect Democracy alleged that the nonpublic federal AI-model review framework could allow corruption or political favoritism and prevent public assessment of whether agencies conduct adequate cybersecurity and safety testing. The organization sought public disclosure of the framework and greater transparency around AI deployments.
The White House finalized a voluntary framework to assess advanced AI models for safety and cybersecurity risks. It planned to keep the policy and detailed testing criteria nonpublic, sharing them only with a limited group of companies; reports also indicated open-weight models might be exempted.
The White House issued an executive order asking companies to submit new AI models for review up to 30 days before release. The order did not disclose the standards models must meet to pass review.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
arstechnica.com
Open sourcecysecurity.news
Open sourcenoma.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.