President Trump signed Executive Order 14409, "Promoting Artificial Intelligence Innovation and Security," on 2 June. Most of what it does is unremarkable by the standards of a cybersecurity executive order: it tells CISA to expedite federal defensive upgrades within 30 days, tells Treasury to stand up an industry information-sharing clearinghouse, and tells the Office of Personnel Management to expand cyber hiring. The provision worth reading twice sits further in. It directs a working group spanning Treasury, the NSA, CISA and, in consultation, NIST to build a classified benchmarking process for identifying "covered frontier models" - and a channel through which the developers of those models can voluntarily hand them over for up to thirty days of government review before public release. Latham & Watkins' summary of the order confirms both pieces had an 1 August deadline: not for developers to comply with anything, but for the government to finish building the process in the first place.
The order is unusually direct about what it isn't
To its credit, EO 14409 doesn't disguise the voluntary framework as something firmer. It states plainly that it "does not create any mandatory governmental licensing, pre-clearance, or permitting requirement" for developing or releasing an AI model. Nobody reading the text in good faith could come away thinking Washington has just imposed a pre-market approval regime on frontier AI, the way the FDA operates one for drugs. That's a meaningfully different posture from the EU, where Article 50 transparency duties and GPAI enforcement powers became legally binding on 2 August regardless of what any individual developer prefers. The American version runs on a different mechanism entirely: access, not law.
What "voluntary" doesn't answer
The trouble starts exactly where the order stops being specific. Ridgeline Research's Maria de Mooy laid out five open questions that the order itself leaves unanswered nearly two months after signing. What counts as a "covered frontier model" is still undefined in public - existing compute-based thresholds like 10^26 floating-point operations are the kind of number a developer can route around with efficiency gains or post-training changes rather than a hard technical line. The thirty-day review window has no published rule for what happens if it runs long, or what a developer's options are if it does. Roughly 100 organisations reportedly sit on the list approved to access reviewed models, with no published criteria for how that list was built or how to join it. There's no disclosed appeals process for a developer who disagrees with an outcome it doesn't fully understand - a due-process gap de Mooy points out doesn't exist in comparably consequential regulated industries like pharmaceuticals or aviation. And the administration has reportedly stopped publishing the model assessment reports that would let anyone outside government judge whether the process is working as described.
Why voluntary access can function like a requirement anyway
None of this makes the framework illegal or even necessarily bad policy - de Mooy's own critique is aimed at the opacity, not the underlying goal of catching dangerous model capabilities before release. But "voluntary" is doing different work here than it does in most contexts. A frontier lab weighing whether to submit its next flagship model isn't just weighing a compliance cost against a legal obligation, because there isn't one. It's weighing the commercial and reputational cost of being the developer that visibly declined a government security review, in a market where its two or three biggest competitors already submitted theirs. That's a real incentive structure, just one built from market pressure and government discretion rather than statute - which is precisely de Mooy's point: it operates with the practical force of a requirement while carrying none of the procedural protections a real one would have to provide.
- Don't read "voluntary" as "optional in practice" when briefing leadership - competitive pressure among frontier labs is likely to produce near-universal participation regardless of the legal framing.
- Ask your AI vendors directly whether their frontier models have gone through this review, and if so, what commitments or conditions came with it - none of that is currently disclosed by default.
- Track the "covered frontier model" definition once it's published rather than assuming today's compute thresholds will hold, since the order's own critics flag them as easy to route around.
- Don't confuse this framework with a safety guarantee - it's a pre-release government look, not a certification, and no public assessment reports currently exist to verify how it's being applied.
- If you operate in both the US and EU, keep the two regimes conceptually separate in your governance documentation - one runs on access and discretion, the other on statute and fixed dates, and they will not move in step.
Executive orders age fast in this administration's AI policy, and this one leaves enough undefined - the model threshold, the access list, the appeals process - that its practical shape in twelve months could look quite different from its text today. What won't change is the underlying test worth applying to any framework marketed as voluntary: ask what happens to the party that declines. If the answer involves a competitive or reputational cost nobody wants to absorb, the word "voluntary" is describing the legal mechanism, not the actual pressure. For help mapping what this framework and the EU's parallel obligations mean for your specific AI vendor relationships, email sales@halfteck.com.