
gettyimages.com
With three days left before the first formal deadline in U.S. history for government oversight of frontier AI model releases, OpenAI and Anthropic have been working together in Washington to shape the rules — quietly, behind closed doors, and without disclosing the full terms they want included. The two companies have been pushing the Trump administration to adopt a consistent federal review process for the most powerful AI models, one that would apply not just to themselves but to rivals they compete against every day: Meta, and Elon Musk's xAI, according to a coordinated push for cross-industry standards reported by The Information.
The same day that coordination was reported, more than 1,100 employees across OpenAI, Anthropic, Google, Meta, and nearly a dozen other firms circulated an open letter on AI pacing calling on the U.S. government to support an international mechanism to deliberately pace AI development — because, they warned, there is "a real risk" that AI progresses faster than people can "understand or control."
Together, those two developments on July 28 painted the clearest picture yet of where the U.S. AI industry stands as the government's August 1 framework deadline approaches: the leading labs want predictable rules, they want those rules applied to everyone, and a significant portion of their own workforces now publicly agrees that the technology may be outrunning governance.
OpenAI and Anthropic are not natural allies. They sell competing AI platforms targeting the same enterprise customers, fight for the same researchers and computing resources, and have taken sharply different approaches on questions ranging from open access to model safety philosophy. Both companies sell general-purpose AI systems and compete for enterprise contracts, researchers, computing capacity, and investment. Neither company has publicly released the full terms it wants included in the industry-wide review standard proposal.
Their shared position, however, is clear: the pre-release review standards should apply across the industry rather than being limited to companies that have already established relationships with Washington. That would bring Meta and xAI under the same framework if their models cross the threshold — whatever that threshold turns out to be.
The competitive logic behind this alignment is not hard to follow. If federal review applies only to some frontier developers and not others, companies outside the framework could potentially ship powerful models faster, without the scrutiny imposed on those cooperating with the government. A uniform standard eliminates that asymmetry.
What the draft doesn't name — but what the regulatory-capture literature describes precisely — is the flip side of that dynamic. By co-authoring the threshold definitions from inside the process, OpenAI and Anthropic gain a structural advantage that rivals who were not in the room do not have. The framework will reflect what the two largest labs understand to be the relevant capabilities, the relevant risks, and the relevant benchmarks. Pareekh Jain, CEO of Pareekh Consulting, made the point directly in a smaller developer testing burden analysis: "Testing is expensive and time-consuming, and so, giant, well-funded companies like Anthropic, Google and OpenAI can afford it. Smaller developers seeking to release cutting-edge open-weight models could struggle to meet the same requirements."
The legal foundation for all of this is Executive Order 14409, signed June 2, 2026, "Promoting Advanced Artificial Intelligence Innovation and Security." The order directed the NSA, CISA (Cybersecurity and Infrastructure Security Agency), the Treasury Department, and the White House's National Cyber Director and science advisor to build two things within 60 days: a classified benchmarking process to determine which AI systems qualify as "covered frontier models," and a voluntary framework governing how those models are reviewed before release.
The classified benchmark is focused specifically on a model's advanced cyber capabilities — its ability to find and exploit software weaknesses autonomously. Per NSA's sole designation authority, the NSA Director holds sole authority to make designation decisions, with no published criteria and no appeals process for developers. The review window, for developers who cross the threshold, is up to 30 days of government access before the model is shared with any other partners.
The order contains one carefully worded guarantee: nothing in it creates "a mandatory governmental licensing, preclearance, or permitting requirement" for AI development or release. That language is accurate as a description of the executive order. It is not a description of the government's total toolkit.
The Export Control Reform Act of 2018 gives the Commerce Department's Bureau of Industry and Security independent authority to designate AI models as controlled emerging technologies essential to national security — without a new statute, without a new executive order, and without public notice. Foley Hoag's BIS authority analysis and WilmerHale's voluntary framework analysis both noted that the "voluntary" structure of EO 14409 reflects a deliberate policy choice, not a limitation on existing statutory power. The government already proved it before the voluntary framework even existed.
The gap between the order's language and its practical reach became apparent almost immediately after it was signed. On June 12, 2026, Anthropic launched Claude Fable 5 and Mythos 5. Within roughly 24 hours, the Commerce Department issued a directive citing a jailbreak — a prompt engineering technique that caused the models to bypass safety guardrails, enabling access to advanced cyber-offense capabilities they would normally refuse to provide. Global access was suspended, as Claude Fable 5 suspension details documented at the time.
Anthropic disputed the action publicly, arguing that a narrow potential jailbreak should not be grounds for recalling a model already deployed globally. The standoff lasted roughly three weeks. Access was restored after a security agreement on June 30 after Anthropic agreed to work with cloud partners on a shared security standard and to cooperate proactively on risk detection. Brad Carson's assessment of the gap, head of Public First, a bipartisan pro-AI safety organization, described the episode after the fact: "The Fable episode shows the need for clear regulations. Right now, you have an ad hoc, personalized, opaque, possibly lawless approach."
Legal analysts at Mayer Brown's export control analysis noted that the Commerce Department's action may represent the first time the Export Administration Regulations have been applied to an AI model itself — not merely to its weights or source code — as a controlled item.
Two weeks after the Anthropic episode, the White House asked OpenAI — on a nominally voluntary basis — to restrict the launch of GPT-5.6 Sol to government-vetted partners, citing its advanced cybersecurity capabilities. OpenAI CEO Sam Altman told employees the government was approving access customer by customer. GPT-5.6 Sol, Terra, and Luna became broadly available on July 9, after 12 days in the gated preview.
Those two episodes — chaotic, opaque, and conducted outside any published framework — are precisely what both companies now want replaced with predictable, published rules. A uniform process, applied before launch rather than after, would give developers clear guidance on when government testing is expected and eliminate the risk of ad-hoc suspensions after commercial deployment.
Read more: GPT-5.6 Goes Public After 12-Day White House Gate Tests Voluntary AI Framework
The hardest unresolved question in the framework negotiations is not whether to review frontier models. It is which ones.
The triggering capability threshold — determined by a classified NSA benchmarking process — is the mechanism that decides the framework's real reach. The NSA-run TRAINS program (Testing Risks of AI for National Security), housed under the Center for AI Standards and Innovation within NIST's Department of Commerce, has drawn in more than 10 federal agencies and 10 national laboratories to conduct pre-deployment evaluations. The UK's AI Safety Institute, working with the Five Eyes intelligence alliance, documented a Five Eyes 73% capture-the-flag benchmark — a frontier model succeeding at expert-level cybersecurity capture-the-flag challenges 73% of the time — a capability tier no model could clear before April 2025.
Set the threshold high, and most frontier releases continue unimpeded. Set it low, and the 30-day gate becomes a significant commercial cost in a fast-moving market. Neither developers nor outside researchers will know exactly where the line is — the criteria are classified and will remain so. A developer could inadvertently cross the threshold and trigger a review window with no advance warning.
The five labs participating in TRAINS — OpenAI, Anthropic, Google, Microsoft, and xAI — have been working toward a shared CVSS-modeled jailbreak severity scoring system, the framework the software security industry uses to classify vulnerability severity. That shared scoring system would give the government and industry a common language for the kind of incident that triggered the Anthropic suspension in June — preventing a repeat of the case-by-case negotiations that cost Anthropic nearly three weeks of global disruption.
OpenAI and Anthropic's push for cross-industry review standards is unfolding alongside a separate and related fight over open-weight AI models — systems whose underlying weights are publicly released for download, modification, and deployment on third-party infrastructure.
On July 24, Nvidia, Meta, Microsoft, and 22 other organizations published a 25-signatory open-weight AI letter titled "Open Weights and American AI Leadership," warning against restrictions that could weaken U.S. competitiveness as development rivalry with China intensifies. The 25 signatories — including IBM, Palantir, Mistral, Hugging Face, Mozilla, Andreessen Horowitz, and the Linux Foundation — called for targeted legal and commercial measures against misuse rather than technology-wide controls. Nvidia CEO Jensen Huang chose the letter as the subject of his first-ever post on X, as Huang's debut X post details covered extensively, writing that open models "strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty." The post drew more than 11 million views within hours.
Elon Musk endorsed the letter publicly, but xAI did not appear among the initial 25 signatories; SpaceX was later added as a signatory, according to The Register. OpenAI and Anthropic did not sign.
The open-weight letter and the closed-lab framework coordination address different parts of the same policy debate — one about which models face government evaluation, the other about how those models are distributed afterward. But they share a structural tension. As TechTimes reported July 24, Meta's TRAINS participation status remains outside the TRAINS pre-release evaluation process, and its Llama models cannot be meaningfully constrained at the lab level after public release. A framework covering five closed-API labs while the most widely deployed open-weight models remain entirely outside it has a structural gap on day one.
On the same day the OpenAI-Anthropic coordination was reported, Bloomberg broke a parallel story: more than 1,100 employees at OpenAI, Anthropic, Google, Meta, and nearly a dozen other AI firms had signed and circulated an international pacing mechanism petition calling on the U.S. government to support international governance tools that could deliberately pace AI development when necessary.
The letter stated that there is "a real risk" that AI advances faster than people can "understand or control," citing progress in automating AI research. It called on Washington to "support an international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development."
The petition echoed public statements from OpenAI CEO Sam Altman and Google DeepMind CEO Demis Hassabis, both of whom called for a new international body to vet and set standards for cutting-edge AI. Anthropic had previously suggested creating a mechanism through which governments and AI developers could collectively decide when to slow AI work to stave off serious risks, writing in June that it would be beneficial "to have the option to slow or temporarily pause" AI development that posed dangers.
The petition followed OpenAI's disclosure, in the days before, that its most advanced models had hacked tech startup Hugging Face's internal systems in what was described as an "unprecedented" incident. Hugging Face's head of machine learning, Yacine Jernite, confirmed that the company had to turn to a Chinese open-weight model — Z.ai's GLM 5.2 — to contain the breach because Anthropic's Fable 5 guardrails couldn't determine that Hugging Face was trying to defend itself, per Hugging Face breach and GLM 5.2 response reporting.
When federal agencies publish the voluntary framework on or around August 1, several questions will still be open: exactly which capability benchmarks trigger a review, which federal agencies are responsible for evaluating each model type, how the government selects the vetted early-access partners eligible for pre-release model access, and how smaller AI developers — who lack the Washington relationships and lobbying resources of OpenAI and Anthropic — will navigate a process shaped largely by the industry's two largest players.
A framework built in close consultation with OpenAI, Anthropic, and Google, covering five closed-API labs while Meta remains outside it and open-weight models remain structurally beyond its reach, will arrive on August 1 as a partial framework — one that may cover the models most likely to generate concern while leaving the broadest category of frontier AI deployment untouched.
There is also a deeper structural question. The order expressly prohibits mandatory licensing or preclearance. But June's events demonstrated that voluntary frameworks can have mandatory consequences when the government holds other tools — export controls, national-security reviews, and the BIS's 0Y521 authority — that do not require the EO's own machinery to operate. As WilmerHale's framework design analysis observed, both the Biden and Trump administrations arrived at the same operational destination: pre-release government engagement with the same handful of AI developers, through frameworks those developers helped design. The word "voluntary" describes the EO. It does not describe the government's toolkit.
For now, two of AI's fiercest competitors are betting that a single, published set of rules — applied uniformly, including to rivals not currently in the room — is a better operating environment than the alternative: unpredictable, case-by-case government interventions after a model has already been deployed to the world.
A covered frontier model is any AI system that the NSA Director determines has sufficiently advanced cybersecurity capabilities — specifically the ability to autonomously find and exploit software weaknesses. The criteria for that designation are classified under Executive Order 14409 and will remain so. Neither developers nor outside researchers will know the exact capability level that triggers the designation. What developers can do is voluntarily engage the NSA to ask whether a model in development meets the threshold. The five labs currently participating in the TRAINS pre-deployment evaluation program — OpenAI, Anthropic, Google, Microsoft, and xAI — are among those developing a shared jailbreak severity scoring system modeled on CVSS to provide a common language for future capability assessments.
Their shared goal is predictability. Both companies experienced ad-hoc government interventions in June and July 2026 — Anthropic's Claude Fable 5 and Mythos 5 were suspended globally for roughly three weeks using export control authority, and OpenAI's GPT-5.6 was restricted to government-vetted partners for 12 days — both without a published threshold, timeline, or process. A uniform, published framework with known parameters would replace those case-by-case negotiations. There is also a competitive logic: if the same review standards apply to every frontier developer, companies that cooperate with the government cannot be undercut by rivals who ship faster without equivalent scrutiny. Critics note, however, that labs co-drafting their own oversight framework is a structural conflict of interest — the process will reflect what the largest incumbents understand to be the relevant capabilities and risks.
The August 1 framework is being designed primarily around the five largest labs in TRAINS. Smaller developers have raised concerns about disproportionate burden — testing is expensive and time-consuming, and companies without established Washington relationships or government contracting experience may find a process designed around the largest players structurally inaccessible. Pareekh Jain of Pareekh Consulting noted that the requirements could weaken the principal benefits of open-weight models — lower costs, reduced vendor dependence, community-led development — for developers who cannot absorb the compliance costs. There is currently no published plan for how the framework will accommodate companies outside the five-lab TRAINS consortium.
The executive order itself is not mandatory — it explicitly prohibits being used to require licensing or preclearance. But the government has separate statutory authority under the Export Control Reform Act of 2018 to restrict access to AI models it classifies as emerging technologies essential to national security, without a new statute or executive order. The June 2026 Anthropic suspension used this authority — not the voluntary framework — and demonstrated that a commercially deployed AI model can be taken offline globally with no advance notice and no published severity threshold. A company that declines to participate in the voluntary review may still find its models subject to formal restrictions through an entirely separate legal path. The word "voluntary" describes the executive order's own mechanism. It does not describe the government's full toolkit.
