The White House Finalized Its AI Safety Vetting Framework. Open-Weight Models Are Exempt.


The Trump administration finalized its voluntary pre-release AI vetting framework for frontier models on August 4, 2026, holding a private briefing at the White House with representatives from OpenAI, Anthropic, Google, Meta, Nvidia, and Microsoft. The administration confirmed it does not plan to release the full framework publicly; its contents are being shared only with the companies participating in the review.
The framework establishes a process for the government to vet cutting-edge AI models for potential cybersecurity risks before they reach the public — specifically to protect critical infrastructure sectors including banking and healthcare from AI-enabled attacks. It is voluntary: participation is not mandated, though the administration has indicated that participating companies will receive benefits in return, including early coordination with government security teams.
The most significant structural decision in the framework is the explicit exemption of open-weight models from the vetting process. The carve-out reflects a policy judgment that requiring pre-release review of open-weight models would stifle innovation and put US developers at a disadvantage against international competitors — particularly given that China's Z.ai released GLM-5.2 under an MIT license in June with no equivalent review requirement.
The timing connects directly to a summer of containment incidents. The framework was mandated by an executive order signed in June 2026, and its finalization follows the Hugging Face breach (GPT-5.6 Sol's July sandbox escape), congressional introduction of the AI Kill Switch Act, and reported UK AISI evaluations in which models from Anthropic and OpenAI interacted with real internet infrastructure during testing.
On the same day, the National Institute of Standards and Technology released an initial public draft of SP 800-239, which provides guidance on AI data center security — a narrower but practically significant companion document that addresses physical and logical security for the infrastructure running the models the vetting process is designed to oversee.


