Policy

Trump Administration's Secret AI Cybersecurity Framework Excludes Smaller Startups From Review Process

The White House has finalized a classified AI security framework but is withholding testing criteria and model coverage details, raising concerns about competitive advantage for large vendors.

Last verified:

The Trump administration has finalized a classified artificial intelligence cybersecurity framework that allows voluntary pre-release security vetting of frontier models, according to Wired AI. A White House official confirmed the plan’s completion, though the government is deliberately withholding testing criteria, coverage scope, and benchmarking methodology from the public record.

White House Invites Industry to Classified Briefing

According to Wired AI, the Trump administration invited staffers from OpenAI, Anthropic, Google, Meta, Nvidia, and other leading AI companies to the White House on Tuesday to present an overview of the new framework. The briefing centered on a voluntary submission process: AI developers may submit new models to federal reviewers up to 30 days ahead of public release.

Wired AI reports the White House will then evaluate submitted models against a classified benchmarking system and distribute results to federal agencies and “trusted corporate partners.” Open-weights models will reportedly be excluded from the framework, per Axios reporting cited by Wired AI.

Details Remain Classified; Smaller Competitors Excluded

The classified nature of the testing criteria and model-coverage boundaries has left smaller AI startups, safety advocates, and independent researchers without visibility into how the federal government is vetting advanced AI systems for cybersecurity risks. According to Wired AI, a person familiar with White House discussions with AI labs expressed concern that the structure creates “an entrenchment program for the big AI model providers…This creates an economic incentive program for critical infrastructure just to use them and leaves out smaller startups” (anonymity granted to discuss confidential matters).

A second White House official, speaking anonymously due to lack of authorization to engage media, told Wired AI that the framework is intentionally narrow and focused exclusively on cybersecurity capabilities of the most advanced models currently in deployment.

Advocates Call for Transparency and Accountability

Brad Carson, president of nonprofit Americans for Responsible Innovation and cofounder of the pro-regulation Public First Action super PAC, criticized the secrecy to Wired AI, arguing: “This is not a handshake deal with tech companies. It’s the rulebook for ensuring they don’t endanger the public. If only tech companies know what’s in the rulebook, it doesn’t work.”

Carson’s concern reflects a core tension in AI governance: whether safety rules can be enforced equitably when compliance frameworks and evaluation criteria remain hidden from public oversight bodies and competitors.

Why This Matters

The classified framework creates asymmetric information between incumbent vendors (who attend White House briefings and know evaluation criteria) and excluded stakeholders (smaller startups, open-weights projects, third-party auditors). Without published benchmarks or test protocols, enterprises and governments cannot independently verify whether their AI vendors meet cybersecurity standards—they must trust federal certification of vendors’ own models. The 30-day advance-notice window also concentrates federal vetting power in the hands of large model providers who can afford compliance infrastructure, potentially locking smaller competitors out of federal and critical-infrastructure procurement channels. If the Trump administration intends this framework to set industry standards, publishing at least the testing methodology—if not the classified threat models—would establish enforceable norms rather than vendor-specific advantages.

Frequently Asked Questions

Which AI companies are subject to the White House's new cybersecurity framework?

According to Wired AI, the framework targets the most advanced models on the market, with open-weights models reportedly excluded per Axios. Testing criteria and precise model coverage remain classified.

Why is the White House keeping the framework secret?

A White House official cited national security concerns, emphasizing the framework is narrowly focused on cybersecurity capabilities of frontier models. Critics argue transparency is essential for public accountability.

How does the 30-day advance-notice window work?

According to Wired AI, AI developers can voluntarily submit new models up to 30 days before public release, and the White House will vet them using a classified benchmarking system before sharing results with federal agencies and trusted corporate partners.

#ai-policy #cybersecurity #regulation #transparency