T1#regulation#security#military#standard
Executive Order 14409 — 'Covered Frontier Models' and a Voluntary Pre-Release Framework

Metadata
- Date
- Decade
- 2020s
- Tier
- T1
- Timelines
- A General History of Information Technology · A History of Artificial Intelligence · A History of Cybersecurity
- Sources
- 09
- Connections
- 00
- Tags
- #regulation#security#military#standard
On 2 June 2026 President Trump signed Executive Order 14409, Promoting Advanced Artificial Intelligence Innovation and Security. It was published in the Federal Register three days later at 91 FR 34565–34567. The order does not hide its posture: Section 1 opens by attributing American leadership in AI to the industry's talent and to the fact that "we refuse to stifle this innovation with overly burdensome regulation."
That same document invented a national-security category for AI systems: the covered frontier model.
The Structure of the Order
Three operative sections carry the substance. Deadlines run from the signing date; by the Congressional Research Service's reckoning, 30 days lands on 2 July 2026 and 60 days on 1 August 2026.
Section 2 (30 days, one item at 60) hardens the government's own posture. The Committee on National Security Systems and the Secretary of War each prioritise cyber defence of their systems. The Secretary of Homeland Security, through the Director of CISA, issues Binding Operational Directives covering civilian federal systems, AI-enabled defensive tooling, and the extension of cyber tools to agencies, state and local authorities, and critical-infrastructure operators — the text names "rural hospitals, community banks, and local utilities" as its examples. The Secretary of the Treasury forms an AI cybersecurity clearinghouse to deconflict vulnerability scanning and prioritise patch distribution. OPM has 60 days to widen the United States Tech Force hiring pathways.
Section 3 (60 days) is the one that matters. The Secretary of the Treasury, the Secretary of War through the Director of the NSA, and the Secretary of Homeland Security through the Director of CISA — consulting the National Cyber Director, the Assistant to the President for Science and Technology, and the Secretary of Commerce through the Director of NIST — shall:
- (a) develop and maintain a classified benchmarking process to assess the advanced cyber capabilities of AI models and set the threshold at which a model should be designated a "covered frontier model". The determination itself is reserved to the Director of the NSA.
- (b) design a voluntary framework under which developers may (i) ask the government whether a model in development meets the designation; (ii) give the government access to covered frontier models, subject to confidentiality, cybersecurity, insider-risk and intellectual-property protections; and (iii) collaborate on selecting the trusted partners who get early access.
- (c) Nothing in the section "shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models."
Section 4 directs the Attorney General to prioritise prosecutions under 18 U.S.C. §§1028, 1030 and 1343 against those who use AI to gain unauthorised access to computers or to further other crimes. No deadline attaches.
Thirty Days Before What
This is the detail that most secondary accounts lose. Plenty of coverage summarised the order as giving the government a thirty-day window to inspect frontier models before public release. The text says something narrower.
Section 3(b)(ii) offers access "for a period of up to 30 days before they plan to release such models to other trusted partners." Those last three words carry the clause. The reference point is not general availability; it is distribution to the vetted third parties that the developer and the government pick together under 3(b)(iii). And it is a ceiling — "up to" — not a floor. CRS preserves the distinction, glossing trusted partners as "critical infrastructure companies". Norton Rose Fulbright's client note keeps it too. Elsewhere the phrase collapses into "before release", and the moment it does, a voluntary consultative arrangement starts reading like pre-publication review.
The Contrast With EO 14110 Is Structural, Not Rhetorical
Set against Biden's Executive Order 14110 of 30 October 2023, the difference resolves into three axes.
| EO 14110 (2023) | EO 14409 (2026) | |
|---|---|---|
| Threshold | Public: 10²⁶ training operations (10²³ for biological sequence data) | Classified, based on cyber capability; the order states no number |
| Participation | Mandatory reporting of training plans and red-team results to the Secretary of Commerce | Voluntary; the framework is something to be designed, with no duty to join |
| Legal basis | Defense Production Act, 50 U.S.C. 4501 et seq. | No coercive authority invoked; §3(c) disclaims mandatory licensing |
| Who decides | Secretary of Commerce, on technical conditions | Director of the NSA |
| Scope of concern | Safety, civil rights, discrimination, labour, privacy | Cyber capability |
CRS characterises the shift as one from AI safety — encoding alignment with human values — to AI security, meaning the protection of AI systems from external threats such as cyberattack. Publishing a numeric threshold was itself a weakness of EO 14110: a fixed operation count decays as training efficiency improves, a criticism made at the time. Classifying the threshold answers that. The price is that a developer has no way to establish in advance whether a model qualifies, and CRS flags for Congress that the order never defines covered frontier model at all.
What "Voluntary" Is Worth
The law-firm analyses converge on the same pressure point. Wiley Rein's 3 June client alert observes that combining federal benchmarking authority, designation power, and early-access incentives produces de facto pressure even where nothing is nominally required. For any lab pursuing federal contracts or the critical-infrastructure market, participation is closer to a precondition than a choice.
CRS points at the reciprocal failure mode: a voluntary structure leaves coverage gaps if major developers decline, if the criteria are narrowly drawn, or if the review period is too short to surface the risks it exists to surface. It adds a second-order worry — concentrating sensitive model details and cyber-threat intelligence inside federal systems creates a target.
How much the voluntary framing was worth got tested ten days after signature. On 12 June the Commerce Department applied export controls to a named company's named models. That action was neither voluntary nor consultative; it ran on the Export Administration Regulations, an entirely coercive instrument that owes nothing to EO 14409. CRS places the two side by side, suggesting Congress may wish to weigh "the Administration's other approaches, such as requiring Anthropic to suspend access to a frontier AI model showing advanced cyber capabilities, in the context of the E.O.'s broader policy and its effects on industry compliance and future policymaking."
Government access to frontier models before release was not itself new in June 2026. CRS notes that existing agreements between NIST and both Anthropic and OpenAI already provided for NIST to "receive access to major new models from each company prior to and following their public release", while observing that those agreements brought no public transparency and did not cover every frontier developer. What 14409 adds is the wiring of that arrangement to a classified threshold and a national-security agency's power to designate.
After the Deadline
A companion instrument, National Security Presidential Memorandum-11, followed on 5 June. It directs the national security enterprise to work with industry to make the most advanced frontier models broadly available to national security professionals, and tasks Defense, Energy, the DNI, and the NSA — through its AI Security Center — with hardening data centres and advanced AI technologies.
So what happened on 1 August? As of this writing, 12 August 2026, a Federal Register search for "covered frontier model" returns zero documents published after the order itself. Forkast reported on 1 August that no Federal Register notice, no NIST or CISA publication, and no OSTP statement had appeared.
That is not proof of non-delivery, and it should not be presented as such. Section 3(a) commissioned a classified benchmarking process; its non-appearance in the public record is the design working as specified. What can be said is narrower and still notable: past the deadline, developers have no more public basis for judging whether their models are covered than they had on 2 June. For now, the covered frontier model exists only inside the text of the order.
Sources
Last updated: