AI RegulationExplainerJun 24, 2026, 2:17 PM· 9 min read· #3 of 3 in technology

How the US Government is Vetting Frontier AI Models Before Release

A new voluntary framework gives federal authorities 30 days to test advanced AI systems for national security risks before they reach the public. While five major tech giants have signed on, Meta remains the lone holdout as negotiations continue.

By Factlen Editorial Team

National Security Advocates 40%Commercial AI Labs 35%Open-Source Proponents 25%
National Security Advocates
Argue that frontier AI poses unique cyber and biological risks, requiring federal vetting before public release to prevent catastrophic misuse.
Commercial AI Labs
Support voluntary testing frameworks to build public trust and align with government security goals, while preferring strict 30-day limits over longer delays.
Open-Source Proponents
Emphasize that open models democratize AI access and that traditional pre-release lockdown testing is harder to apply to models designed for open distribution.

What's not represented

  • · International Regulators
  • · Independent AI Researchers

Why this matters

As artificial intelligence becomes powerful enough to impact national security, the US government is stepping in to test these systems before they reach the public. Understanding this 30-day review process reveals how authorities are trying to prevent cyber and biological threats without slowing down American tech innovation.

Key points

  • A new voluntary framework requires frontier AI models to undergo a 30-day government security review before public release.
  • The CAISI TRAINS program tests models for severe cybersecurity, biosecurity, and chemical risks.
  • OpenAI, Anthropic, Google DeepMind, Microsoft, and xAI have all agreed to participate in the evaluations.
  • Meta remains the lone holdout among major developers, though the company says it hopes to sign an agreement soon.
30 days
Pre-release review window
5
Major AI labs participating
90 days
Original proposed review window

The race to build the world's most powerful artificial intelligence has prompted a quiet but profound shift in how the United States government handles commercial technology. Rather than waiting for tech giants to release their latest creations to the public and hoping for the best, federal authorities are now stepping in before launch day. This marks a significant departure from the traditional Silicon Valley ethos of moving fast and breaking things, signaling that frontier AI is now being treated with the same gravity as aerospace or defense technologies.

Under a new framework established this month, the most advanced AI systems—known in the industry as frontier models—are being subjected to a 30-day government review process before they ever reach consumers. The primary goal is to identify and mitigate severe national security vulnerabilities. Evaluators are specifically looking for cybersecurity flaws, the potential for generating biological weapons, and the ability to synthesize dangerous chemical agents before the software is deployed globally. This proactive approach aims to catch catastrophic risks that internal corporate testing might miss, ensuring that models cannot be easily weaponized by bad actors.[1]

The initiative represents a delicate balancing act for the administration: securing American infrastructure against AI-accelerated threats without stifling the rapid innovation that defines the domestic tech sector. Policymakers are acutely aware that overly burdensome regulations could slow down US companies, potentially allowing foreign adversaries to take the lead in artificial intelligence development. As a result, the current framework is designed to be as frictionless as possible while still providing a meaningful window for security experts to probe the technology.

Currently, five of the six major American AI developers have agreed to the voluntary vetting process, creating a near-consensus among the industry's top players. OpenAI, Anthropic, Google DeepMind, Microsoft, and xAI are all actively participating in the pre-release evaluations. The lone holdout among the industry's titans is Meta, the parent company of Facebook and Instagram, which is currently facing direct pressure from the White House to submit its upcoming models for the same level of federal scrutiny.[1][2]

The 30-day pre-release review window allows government experts to red-team models for severe vulnerabilities.
The 30-day pre-release review window allows government experts to red-team models for severe vulnerabilities.

The mechanism driving this new era of oversight is the Center for AI Standards and Innovation (CAISI). Housed within the Commerce Department and headed by Commerce Secretary Howard Lutnick, the agency was created by the Biden administration and expanded under the current executive order. It is staffed with technical experts, cybersecurity veterans, and data scientists tasked with stress-testing the digital brains built by Silicon Valley. CAISI acts as the central clearinghouse for all frontier model evaluations, bridging the gap between private sector engineering and public sector defense.[1]

Within CAISI, the actual testing is conducted through a specific initiative known as the TRAINS program—Testing Risks of AI for National Security. When a participating company finishes training a new frontier model, they hand a secure version of it over to the TRAINS team for a rigorous evaluation period. This is not a standard software bug hunt; it is a targeted search for capabilities that could threaten public safety or destabilize critical infrastructure. The program operates in highly secure environments, ensuring that the unreleased intellectual property of these tech giants remains protected while government experts run their diagnostics.

During this window, government red-teamers actively try to break the model's safety guardrails. They probe the system using adversarial prompts to see if it can be manipulated into writing malicious malware, identifying zero-day vulnerabilities in critical infrastructure, or providing step-by-step instructions for synthesizing chemical and biological agents. If a model readily complies with these dangerous requests, the government works with the developer to patch the vulnerabilities and strengthen the system's alignment before it is cleared for public release.

The review window is strictly capped at 30 days, a timeline designed to minimize disruption to product launch schedules. According to reports, early drafts of the June 2 executive order proposed a much longer 90-day evaluation period. However, the timeline was drastically reduced following concerns from the White House that a three-month delay could cost American companies their competitive edge and slow down the broader economy's adoption of AI tools. By settling on 30 days, the government hopes to strike a compromise that allows for thorough red-teaming without paralyzing the industry's rapid release cycles.

Five of the six major American AI developers have agreed to the voluntary testing framework.
Five of the six major American AI developers have agreed to the voluntary testing framework.
The review window is strictly capped at 30 days, a timeline designed to minimize disruption to product launch schedules.

Because the framework is entirely voluntary, it relies heavily on the goodwill and cooperation of the tech industry. The executive order explicitly notes that it does not authorize mandatory licensing, preclearance, or permitting requirements, as any binding regulation of that magnitude would require an act of Congress. Instead, the government is using a combination of public pressure, national security appeals, and the threat of future legislation to bring companies to the table. So far, this soft-power approach has been remarkably successful at corralling the majority of the sector's biggest players.

This voluntary nature makes Meta's current absence highly consequential for the durability of the framework. Meta is a dominant force in the AI landscape, having recently launched its advanced Muse Spark model in April to widespread acclaim. According to The New York Times, the administration has been sending direct requests via email to the company, urging them to join the CAISI agreement and close the most significant gap in the government's visibility. Without Meta's participation, a massive portion of the world's AI ecosystem remains outside the purview of federal safety testers.[1][2]

Meta has signaled a strong willingness to cooperate, though a formal agreement remains unsigned as negotiations continue. 'We share the administration's goal of advancing US leadership on robust and secure frontier AI,' Meta spokesperson Francis Brennan said in a recent statement. 'While we are working through the details, we hope to sign the agreement soon.' The company's public posture suggests that their hesitation is not rooted in ideological opposition to safety, but rather in the logistical complexities of their specific business model.[1]

The friction likely stems from Meta's unique approach to artificial intelligence distribution. Unlike OpenAI or Google, which keep their most powerful models locked securely behind proprietary APIs, Meta champions open-source development. They frequently release the underlying weights of their models, allowing developers, researchers, and startups worldwide to download, modify, and run the software locally on their own hardware. This open approach has democratized AI access but complicates traditional security paradigms. When a model is designed to be freely distributed rather than centrally controlled, the mechanics of pre-release vetting have to be fundamentally rethought.

Pre-release testing is fundamentally more complicated for open-source models. If a closed model exhibits dangerous behavior after release, the developer can simply patch the API, add new filters, or revoke access entirely. If an open-source model is downloaded by thousands of users and later found to have a critical vulnerability, it cannot be easily recalled or updated. Once the weights are public, the genie is out of the bottle, making the pre-release testing phase exponentially more critical for open-source developers.

The Center for AI Standards and Innovation (CAISI) serves as the central clearinghouse for model evaluations.
The Center for AI Standards and Innovation (CAISI) serves as the central clearinghouse for model evaluations.

The stakes of these security evaluations are not merely theoretical, and the government has already demonstrated its willingness to intervene aggressively when it believes an AI system poses a direct threat to national security. The administration is not just setting up testing frameworks; it is actively policing how these powerful tools are distributed globally, particularly when they intersect with critical defense capabilities. This proactive stance marks a shift from passive observation to active enforcement in the AI sector.[2]

In mid-June, Washington ordered Anthropic to suspend access to its Mythos 5 and Fable 5 models for all foreign nationals. Mythos is Anthropic's state-of-the-art cybersecurity model, available only to select partners, while Fable 5 was designed to bring similar capabilities to a broader audience. The directive forced Anthropic to immediately block international access to ensure compliance with the government's mandate, showcasing the administration's power to halt AI distribution. This incident proved that the government is closely monitoring specific model capabilities and will not hesitate to pull the plug if geopolitical risks outweigh commercial interests.[1][2]

The government cited severe national security concerns for the suspension, highlighting the dual-use nature of advanced AI. Tools designed to help organizations defend their networks by identifying vulnerabilities can often be inverted by malicious actors to find novel ways to attack those same networks. By restricting foreign access to Mythos 5, authorities aimed to prevent state-sponsored hackers from utilizing American-made AI to accelerate their cyber espionage campaigns against US infrastructure. It is exactly this kind of dual-use risk that the 30-day TRAINS review process is designed to catch before a model is ever deployed.[1][2]

As the July deadline approaches for the government to finalize its internal review procedures, the tech industry is watching closely to see how the CAISI framework evolves. The immediate question is whether Meta will officially sign on, bringing the entire cohort of major US developers under a unified safety umbrella. If Meta joins, it will validate the administration's voluntary approach; if they hold out, it may force policymakers to consider more coercive measures. The resolution of this standoff will likely set the template for AI regulation for years to come.[1]

Open-source models present unique challenges for pre-release testing, as they cannot be easily recalled once distributed.
Open-source models present unique challenges for pre-release testing, as they cannot be easily recalled once distributed.

Beyond Meta's participation, a broader policy debate is taking shape across Washington and Silicon Valley. Security advocates question whether a voluntary framework is durable enough to protect the country in the long term, especially as AI capabilities continue to scale exponentially. They argue that relying on corporate goodwill is insufficient when dealing with technologies that possess the potential for mass disruption, pushing for Congress to eventually codify these testing requirements into law. Conversely, industry leaders warn that mandatory regulations could become rigid and outdated, failing to keep pace with algorithmic breakthroughs.

For now, the 30-day review window stands as the most significant bridge yet built between Silicon Valley's rapid development cycles and Washington's national security mandate. It establishes a firm precedent that the most powerful technologies of the 21st century will face federal scrutiny before they are unleashed on the world. By identifying catastrophic risks early, this collaborative approach offers a hopeful path forward—one where society can reap the immense benefits of artificial intelligence without blindly accepting its most severe dangers.

How we got here

  1. June 2, 2026

    President Trump signs an executive order establishing a voluntary 30-day pre-release review window for frontier AI models.

  2. Mid-June 2026

    The US government orders Anthropic to suspend foreign national access to its Mythos 5 and Fable 5 cybersecurity models.

  3. June 24, 2026

    Reports emerge that the White House is directly pressing Meta to join the five other major AI labs in the voluntary testing agreement.

Viewpoints in depth

National Security Advocates

Argue that frontier AI poses unique cyber and biological risks, requiring federal vetting before public release to prevent catastrophic misuse.

Defense experts and government officials view frontier AI not just as commercial software, but as dual-use technology with the potential to act as weapons of mass disruption. They argue that internal corporate testing is insufficient because tech companies face immense financial pressure to ship products quickly. By mandating a 30-day federal review window, this camp believes the government can catch critical vulnerabilities—such as a model's ability to write zero-day malware or synthesize pathogens—before they are distributed globally. Some within this group advocate for eventually making these voluntary reviews mandatory under federal law.

Commercial AI Labs

Support voluntary testing frameworks to build public trust and align with government security goals, while preferring strict 30-day limits over longer delays.

Major developers like OpenAI, Microsoft, and Google DeepMind have embraced the CAISI framework as a necessary step to build public trust and ensure their products do not inadvertently threaten national security. However, this camp is highly protective of its development timelines. They successfully lobbied to reduce the proposed 90-day review window down to 30 days, arguing that a three-month delay would stifle innovation and allow foreign competitors to outpace American companies. They view the current voluntary agreement as a workable compromise that balances safety with speed.

Open-Source Proponents

Emphasize that open models democratize AI access and that traditional pre-release lockdown testing is harder to apply to models designed for open distribution.

Advocates for open-source AI, a camp heavily anchored by Meta, argue that freely distributing model weights democratizes technology and accelerates global research. They point out that pre-release government vetting is fundamentally designed for closed-system models accessed via APIs, where developers can easily patch vulnerabilities or revoke access post-launch. Because open-source models cannot be recalled once downloaded, this camp faces unique logistical hurdles in complying with traditional containment testing. They stress that safety frameworks must adapt to accommodate open distribution, rather than forcing all AI development into closed, proprietary silos.

What we don't know

  • Whether Meta will ultimately sign the voluntary agreement or continue to hold out.
  • How the government plans to enforce safety standards on open-source models once their weights are publicly available.
  • If Congress will eventually step in to make the 30-day pre-release review window mandatory under federal law.

Key terms

Frontier AI Models
Highly capable, large-scale artificial intelligence systems that match or exceed the capabilities of the most advanced models currently available.
CAISI
The Center for AI Standards and Innovation, a Commerce Department agency tasked with vetting AI technology.
TRAINS Program
Testing Risks of AI for National Security, the specific government initiative that evaluates models for cyber, biological, and chemical risks.
Red Teaming
A cybersecurity practice where experts intentionally try to break or bypass an AI model's safety guardrails to find vulnerabilities before release.
Open-Source AI
Artificial intelligence models where the underlying code and weights are made publicly available for anyone to download and modify.

Frequently asked

Is the government review mandatory for all AI companies?

No. The framework established by the June 2 executive order is currently voluntary, though the administration is heavily pressuring major developers to participate.

What exactly is the government testing these models for?

The TRAINS program specifically looks for national security vulnerabilities, including whether a model could be used to launch cyberattacks or help develop biological and chemical weapons.

Why hasn't Meta joined the agreement yet?

Meta is currently negotiating the details. As a company that champions open-source AI, their distribution model differs from closed-system developers, making pre-release containment more complex.

Sources

Source coverage

2 outlets

3 viewpoints surfaced

National Security Advocates 40%Commercial AI Labs 35%Open-Source Proponents 25%
  1. [1]EngadgetOpen-Source Proponents

    US government reportedly urging Meta to share its AI models

    Read on Engadget
  2. [2]Investing.comCommercial AI Labs

    Trump administration pushes Meta for AI model security reviews- NYT

    Read on Investing.com
Stay informed

Every angle. Every day.

Get technology stories with full source coverage and perspective breakdowns delivered to your inbox.