Trump's AI Safety Framework Skips Open-Source Models Entirely
The White House has a new plan for testing AI before it reaches the public. It only covers a narrow slice of the market, and key terms are left undefined.

Key points
- The Trump administration's AI cybersecurity testing framework, finalized in mid-2025, excludes all open-source AI models from its scope.
- The framework applies only to closed-source, frontier-level AI models, meaning models only their developers can fully inspect, that carry national security risks.
- AI companies get a 30-day window for the government to review a model before release, but compliance is entirely voluntary.
- The framework does not define what "state-of-the-art" or "national security risk" means, leaving critical terms open to interpretation.
- The White House has no plans to release the framework's details to the public.
The Trump administration has completed a framework for testing whether advanced AI systems pose cybersecurity dangers before they go public. But as first reported by Axios, the framework leaves out a large and growing part of the AI world before it even gets started.
What does the framework actually cover?
It covers only closed-source AI models with frontier capabilities that carry national security risks. A closed-source model is one where the underlying code and components are kept private, the way a recipe is locked in a vault. Open-source models, where anyone can download and inspect the inner workings, are excluded entirely.
The framework also explicitly states it cannot be used to restrict an open-source model once it has been released. That is a notable carve-out, given that several of the most capable AI systems available today, including Meta's Llama family, are open-source.
AI companies including Anthropic, OpenAI, and Google attended a White House briefing on the finalized framework. The meeting followed an executive order President Trump signed in June directing AI companies to share their most advanced models with the federal government before public release.
What does it mean for AI companies?
In practice, companies are not legally required to comply. The guidelines are voluntary.
Under the framework, the government has 30 days to review a new model after a company submits it. That review period applies only to closed-source models that are both cutting-edge and judged to carry national security risk.
The problem is that neither of those conditions is defined anywhere in the document. The framework does not explain what qualifies as "state-of-the-art" or what counts as a "national security risk." For a policy built specifically to evaluate those things, that is a significant gap.
Large labs like OpenAI and Anthropic have reportedly been pushing for clearer guidance on this, hoping to understand where the line sits before they release something that draws government scrutiny. Smaller AI companies face a similar problem: without clear definitions, it is hard to know whether a new model falls under the framework at all, or whether releasing it quietly could damage their standing with the administration.
What happens next?
The administration is not planning to publish the framework publicly, which means outside experts, researchers, and the general public cannot scrutinise the standards being applied to AI models before they reach everyday users.
That matters. AI models are already used in medical records, hiring tools, and customer service systems that affect millions of people. A testing framework with undefined terms and no public accountability offers limited reassurance that those systems have been genuinely stress-tested for risk.
The voluntary nature of the rules also means a company that wants to move fast can simply choose not to participate.
Common questions
Does this affect AI tools I already use?
Not directly. The framework targets new models before release, not ones already on the market. Tools you use today are unaffected.
Why does it matter that open-source models are excluded?
Open-source AI models can be downloaded and modified by anyone, including people with harmful intentions. A framework that cannot address those models leaves a significant portion of the risk landscape untouched.
Is this a law?
No. The framework is voluntary guidance, not legislation. Companies face no legal penalty for ignoring it.



