The White House has finalized a voluntary framework for cybersecurity testing of advanced AI models, completing a process that began with an executive order signed earlier this year. The framework gives federal agencies access to frontier AI systems for up to 30 days before those models go public, a window meant to catch security vulnerabilities before they become everyone’s problem.

It is, notably, entirely optional. No penalties exist for companies that decline to participate, and no mandatory requirements were written into the final rules.

What the framework actually does

Executive Order 14409, signed on June 2, 2026, established the roadmap. The finalized rules, completed August 3, 2026, translate that roadmap into a working process.

In practice, companies developing the most capable AI models can voluntarily submit those systems for government review. The NSA and CISA are the primary federal agencies involved in conducting the evaluations.