Editorial illustration for Trump's AI Testing Plan Excludes Open Models
Trump's AI Safety Plan Excludes Open Models
Open models are sitting outside the Trump administration's new AI safety net entirely. Axios reports that the government's voluntary framework for testing advanced AI systems for cybersecurity risks applies only to closed-source models, and goes further by explicitly stating it can't be used to restrict open models once they're released to the public. That's a notable carve-out for systems anyone can download and pick apart, given the framework's stated purpose is catching national security threats before they spread.
The plan traces back to an executive order Trump signed in June, which asked AI companies to share their frontier models with federal officials before launch. Representatives from Anthropic, OpenAI, and Google reportedly sat in on a White House briefing this week where the finalized framework was presented, though the administration has no plans to make the details public. Companies that agree to participate get a 30-day review window before releasing new models.
None of it is mandatory. And the terms used to justify the whole exercise, like what actually counts as a "national security risk," are left undefined.
According to Axios, the framework sets a 30-day grace period for the government to review new models, and will only apply to closed-source AI models that have state-of-the-art capabilities and carry national security risks. The guidelines don’t actually define what “state-of-the-art” or “national security risk” means in this context, however, which is bizarre for an initiative that’s supposedly designed specifically to analyze such things.
Why this matters
For anyone building on Llama, Mistral, or DeepSeek, this framework tells us the federal government isn't watching your layer at all. Open-weight models, the ones any grad student, startup, or state actor can download and modify, sit entirely outside the testing regime, and the guidelines say explicitly they can't be used to restrict those models once released. That's a real gap, not a rounding error.
Closed labs like OpenAI and Anthropic get a voluntary framework with no teeth and no definition of "national security risk." Open developers get nothing at all, not even the illusion of oversight. If you're a founder shipping products on open models, don't mistake this silence for a green light. No testing regime means no shared baseline for what "safe" looks like, which means liability, procurement standards, and export rules will get decided elsewhere, probably in a courtroom or a foreign capital, later and more expensively.
Vague rules that exempt the fastest-growing part of the ecosystem aren't really rules. Watch whether Congress or state AGs try to fill that hole before the next open-weight release makes headlines for the wrong reason.
Common Questions Answered
Does Trump's AI safety framework apply to open-source models like Llama and Mistral?
No, the Trump administration's voluntary AI safety framework explicitly excludes open-source models and cannot be used to restrict them once released to the public. This means open-weight models that anyone can download and modify sit entirely outside the government's testing regime for cybersecurity and national security risks.
What is the 30-day grace period in the Trump administration's AI testing framework?
According to the framework, the government has a 30-day grace period to review new advanced AI models for cybersecurity risks before they can be deployed. However, this review period only applies to closed-source AI models with state-of-the-art capabilities, not to open models.
Why is the lack of definitions for 'state-of-the-art' and 'national security risk' problematic in this framework?
The framework fails to define what constitutes 'state-of-the-art' capabilities or 'national security risk,' which creates ambiguity for an initiative supposedly designed to analyze these specific threats. This vagueness undermines the framework's ability to consistently and fairly evaluate which AI models actually pose security concerns.
What is the key difference in how closed-source labs versus open models are treated under this framework?
Closed-source labs like OpenAI and Anthropic are subject to a voluntary testing framework with a 30-day review period, while open-source models face no government oversight or restrictions whatsoever. The framework explicitly prevents the government from using it to restrict open models once they are released to the public.
How does this framework affect state actors and startups building on open-weight models?
State actors, startups, and grad students can download and modify open-weight models like DeepSeek without any federal government monitoring or restrictions. The framework creates a significant gap in oversight by leaving these accessible models entirely outside the national security testing regime.
Further Reading
- White House will exempt 'open' AI systems from security review - The Washington Post
- Scoop: Inside Trump's AI framework - Axios
- Trump advisers tell AI firms they will not safety-test open-weight models - Reuters
- Trump Administration Won't Safety-Test Open-Weight AI Models - Benzinga
- Trump restrictions on private AI models turn attention to open source - The Hill