White House: a 30-day review window for frontier models
The US is finalising a voluntary framework giving agencies up to 30 days to review frontier models before release. We explain what is confirmed and what is still in progress.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 24 July 2026
- READING TIME
- 8 min read
- TOPIC
- AI Security
The White House is finalising a voluntary framework with OpenAI, Anthropic and Google under which federal agencies would get up to 30 days to review the national-security implications of a new “frontier” model before its public release. An announcement is expected before 1 August. Because this is in progress, we carefully separate what is already confirmed from what is yet to be announced.
The foundation: a June executive order
The framework grows out of Executive Order 14409, “Promoting Advanced Artificial Intelligence Innovation and Security,” signed on 2 June 2026. It directed agencies to, among other things: build a framework for the secure deployment of frontier models, upgrade cyber defences, establish a voluntary mechanism for developers to engage the government before deployment, and direct enforcement resources toward criminal misuse of AI.
What the framework would contain
According to reporting, the key elements are:
- A window of up to 30 days of government security review before a model ships, in which technical teams from relevant agencies assess national-security risks;
- A classified benchmarking process run by the NSA;
- A voluntary AI cybersecurity clearinghouse.
An important nuance: the government’s role is described as advisory and flagging, not gatekeeping. This is not approval to release a model, but a window to assess and warn.
Why “voluntary” and “advisory” matter
This distinguishes the US approach from Europe’s binding legal regime. The EU AI Act imposes concrete obligations on companies; here we are talking about voluntary cooperation between the largest labs and the government. Two regulatory philosophies will collide, and organisations operating on both sides of the Atlantic must understand the difference: what is law, and what is an industry arrangement.
The context is worth remembering, too. In June, after the launch of Claude Fable 5 and Mythos 5, the Commerce Department ordered access suspended for foreign nationals on national-security grounds, following reports of a jailbreak. That shows the US government already treats frontier-model capability as a security matter, not just an innovation one.
What we still do not know
This is an unfinalised framework. The exact definition of a “frontier model,” which agencies take part, how the process runs, and what happens if the review flags a risk — these details await the official announcement. An honest account says “expected before 1 August,” not “in force.” Until the final document is published, treat the above as direction, not binding legal status.
What it means for companies
- Track what is law versus voluntary. The AI Act is an obligation; the US framework is (for now) an arrangement with the largest labs. Do not conflate the two in your compliance assessment.
- Assume longer frontier-model release cycles. A review window may lengthen the time between announcement and availability — plan a buffer if you build on the newest models.
- Build your own evaluation process. Regardless of regulation, you need an internal assessment of models — security, provenance, compliance. This aligns with an AI governance approach.
- Do not treat regulation as a shield. A voluntary framework does not relieve you of responsibility for deploying models safely on your own side.
The bottom line
The US frontier-model framework signals that governments want a “window” to assess the most powerful models — but in a voluntary, advisory form, not a gatekeeping one. For companies, the most important thing is distinguishing law from arrangements and building your own model-evaluation process. If you want to organise AI compliance and governance, let’s talk.
Sources: Eastern Herald, Mintz — AI: The Washington Report (July 2026), Executive Order 14409 (2 June 2026). The framework remains unfinalised; the description is marked as in progress.


