The Trump administration has finalized a plan to address the cybersecurity risks posed by increasingly capable artificial intelligence models, a White House official confirmed to WIRED. But at least for now, it’s deliberately keeping the details under wraps, people familiar with the matter tell WIRED.
The Trump administration invited staffers from OpenAI, Anthropic, Google, Meta, Nvidia, and other leading AI companies to the White House on Tuesday to share an overview of its new AI oversight framework, the people said. AI developers will have the ability to voluntarily submit new models to the federal government up to 30 days ahead of their public release. The White House will then vet their cyber capabilities according to a classified benchmarking system and share the AI models with federal agencies and trusted corporate partners.
The White House isn’t sharing more information about its testing criteria or which AI models will be covered by the framework, though open models will reportedly be excluded, according to Axios. That has left smaller AI startups, safety advocates, and third-party researchers in the dark about crucial aspects of how the federal government is addressing the cyber risks posed by advanced AI systems. Some argue that the secretive process will give an advantage to larger companies.
“They’re essentially creating an entrenchment program for the big AI model providers, which are now considered the most frontier,” says a person familiar with the White House’s discussions with AI labs, who requested anonymity to discuss confidential matters. “This creates an economic incentive program for critical infrastructure just to use them and leaves out smaller startups.”
The White House did not respond to requests for comment.
The Trump administration may be keeping its AI security framework confidential because of national security concerns. A second White House official, who requested anonymity because they were not authorized to speak to the media, emphasized that the new framework is intentionally narrow and is focused exclusively on the cybersecurity capabilities of the most advanced models on the market, such as Anthropic’s Fable and OpenAI’s ChatGPT 5.6.
But some AI safety advocates tell WIRED that any rules AI companies are being held to should be made public to ensure third-party groups can keep them accountable.
“This is far too important an issue to be hidden behind a cloak of secrecy,” says Brad Carson, president of the nonprofit Americans for Responsible Innovation and cofounder of the pro-regulation Public First Action super PAC, which has funding from Anthropic. “This is not a handshake deal with tech companies. It’s the rulebook for ensuring they don’t endanger the public. If only tech companies know what’s in the rulebook, it doesn’t work.”
Cyber Concerns
The oversight framework stemmed from an executive order President Donald Trump signed earlier this year designed to address the cybersecurity risks of new AI models. In recent months, Trump officials have grown increasingly alarmed about the hacking capabilities of cutting-edge AI systems, which they worry could pose a serious risk to national security.
Those fears escalated over the past two weeks when OpenAI and Anthropic said they discovered their AI models had unknowingly bypassed controls and hacked into third-party services during internal testing. The House Committee on Homeland Security sent a letter to OpenAI CEO Sam Altman last week requesting that he brief lawmakers about how one of the company’s AI agents breached the platform Hugging Face.
“This incident really is a wake-up call for people that agent capabilities have now reached this level,” said Dawn Song, vice president of AI research at Meta, during a panel discussion on Saturday at UC Berkeley, where she is also a professor, referring to the Hugging Face breach.

