Trump’s AI testing plan is limited and vague
The Trump administration's framework for assessing potential cybersecurity risks posed by advanced AI reportedly has no interest in testing open models. Axios reports that not only do the voluntary guidelines outright exclude open models - meaning anyone can download them and inspect their core components - but the framework explicitly says it can't be used to restrict open models after they've been released.
The White House has published its framework for testing advanced AI systems against cybersecurity threats. The document is voluntary, which is already a concession to the industry. The more revealing detail is what it leaves out.
Open models are excluded from the testing regime entirely. The framework does not merely decline to test them. It states explicitly that it cannot be used to restrict them after release. That is not an oversight. It is a structural decision about where the government believes the risk lies, and where it does not.
The executive order that created this framework asked frontier labs to share their models with the federal government before release. The resulting policy treats closed models as the primary object of concern. Open models, by contrast, are treated as a category that the government has no interest in touching. The logic is consistent with the administration's stated preference for minimal regulation. But it also creates a clear asymmetry.
A closed model can be evaluated before it ships. An open model, once released, is effectively beyond the reach of any pre-release review. The framework acknowledges this reality in writing. It does not try to solve it. It simply declares the limitation and moves on.
For the companies that build open models, this is a favorable outcome. They face no mandatory testing, no pre-release review, and no post-release restriction. For anyone concerned about the security implications of widely available AI systems, the framework offers little comfort. It is a policy that names the risk and then declines to address it.
The document is limited in scope and vague in its commitments. That may be the point. A voluntary framework that excludes the most accessible models is not a security regime. It is a statement of priorities.