The White House is ending open AI models' security-review exemption
The expected revision would end an exemption for open models once they reach the capabilities of the strongest closed systems.
By RuntimeWire Staff · Published
Primary source: Wired
Why it matters
Open-model developers may face the same federal release delays as closed labs, adding an uncertain security checkpoint before weights can be published.

The White House expects to bring powerful open AI models into its prerelease security review framework, reversing an exemption that officials outlined to AI developers earlier this month.
A White House official told Wired that open models would become subject to federal testing once they reach the frontier capabilities of leading closed systems. The change is expected in the coming months, according to the report.
The framework currently covers closed models from developers such as Anthropic and OpenAI. It calls for the federal government to evaluate the national security risks of advanced systems before their broader release. Participation remains voluntary, and the administration has kept the full framework out of public view.
The planned expansion would place open-model developers inside a process that was initially designed around labs that control access to their systems. Open-weight models can be downloaded, modified and run independently, making restrictions harder to enforce once the weights have been published.
An exemption with an expiration date
Administration officials presented the current framework to technology companies on August 4th. Axios reported that the version discussed at those meetings excluded open models and defined covered systems as closed, state-of-the-art models that present national security risks.
That version contemplated a review period of up to 30 days, with models stored in secure environments and access recorded through detailed logs. It left key terms undefined, including the capability threshold that would make a model subject to review.
The reported revision would preserve that ambiguity while extending its consequences. A model developer may not know whether an upcoming release crosses the government's frontier threshold until officials evaluate its performance. For open-model builders, the timing matters because a 30-day delay can disrupt coordinated releases of weights, code, evaluations and commercial products.
The expansion also addresses a credibility problem created by the original exemption. A federal approval process applied only to closed systems could give enterprise customers the impression that open alternatives had received less scrutiny. Wired reported that administration officials were concerned this two-tier structure could discourage American developers from producing open models.
Applying the same review to open releases creates a different problem. Once a downloadable model passes the capability threshold, the government could slow its publication even though participation is formally voluntary. The framework's practical force will depend on what access federal agencies, contractors and regulated customers require from developers that decline to participate.
Washington's open-model conflict
The expected change cuts against the administration's published support for open AI. The White House's July 2025 AI Action Plan said open-source and open-weight systems give startups flexibility, allow organizations to keep sensitive data away from closed-model vendors and support academic research. It called on the federal government to create a supportive environment for open models and help smaller businesses adopt them.
The White House has since faced a harder technical problem: an open model approaching frontier-level cyber capabilities can be copied and deployed by users outside the developer's control. Wired reported that officials are particularly concerned about systems capable of autonomously attacking military or financial infrastructure.
The administration had already left room for further action. On July 15th, Semafor reported that officials were considering additional measures involving open models and China-related security concerns. National Cyber Director Sean Cairncross said the government's work included scanning and coordination for open-source systems.
Federal scrutiny has also begun affecting how closed-model developers release products. The Associated Press reported in June that OpenAI and Anthropic limited access to new systems during government reviews. OpenAI said at the time that it did not want government access to become the long-term default.
The White House's June 5th national security AI directive separately instructed defense and intelligence agencies to adopt advanced commercial and open-source technologies while ensuring deployed systems remain controllable and accountable.
Those policies leave open-model developers between two federal objectives: Washington wants American open models to spread as alternatives to Chinese systems, while security officials want the ability to examine capable models before anyone can download them. Bringing open releases into the review framework gives security agencies a checkpoint. Keeping the process voluntary, secret and based on an undefined frontier threshold leaves developers without a stable rule for when that checkpoint applies.