Field note · AI & Technology

The Frontier AI Review That Only Runs If a Developer Asks For It

Executive Order 14409 lets AI developers opt into a classified cyber-capability review - but creates no way for the government to reach a model that doesn't.

AP
Anuraag Paul
Co-Founder & Chief Sustainability Officer, Newtral
Published
August 13, 2026
Last reviewed
August 13, 2026
Read time
6 min · 1,057 words
Current

On June 2, 2026, President Trump signed Executive Order 14409, "Promoting Advanced Artificial Intelligence Innovation and Security." Its third section, titled "Secure Frontier Model Deployment," gave the Secretaries of the Treasury, War, and Homeland Security 60 days to build a classified process for identifying the AI models capable enough to count as a national-security concern - what the order calls "covered frontier models." That deadline landed on August 1, 2026, twelve days before this piece was written.

Read the section's title and you'd expect a review mechanism: agencies checking AI models against a security bar the way regulators check drugs or aircraft. Read the section itself, and the mechanism is narrower than the title suggests. Every path into it starts with a developer choosing to walk through it. Nothing in the order tasks any agency with finding a covered frontier model on its own - and a separate clause rules out ever requiring one to submit.

01

A Threshold, Not a List

Section 3(a) is where the classified process lives. It directs the Treasury Secretary, the Secretary of War (through the Director of the NSA), and the Secretary of Homeland Security (through the Director of CISA) to "develop and maintain a classified benchmarking process to assess the advanced cyber capabilities of AI models and determine the threshold at which an AI model should be designated a 'covered frontier model.'" The designation itself is made by the NSA Director, in consultation with a short list of named officials, and - this is a real provision, not nothing - assessments get "shared with AI developers and researchers as appropriate."

What Section 3(a) builds, in other words, is a yardstick: a classified answer to "how capable does a model have to be before it's a national-security matter." It does not build a census. The order does not direct anyone to go find every model that might clear that bar and measure it.

02

The Only Door In Is the One a Developer Opens

That's what Section 3(b) is for, and it's explicit about the mechanism. Agencies are told to "design a voluntary framework with AI developers" through which a developer can: engage the government to find out whether a model it's building meets the covered-frontier threshold; hand the government access to that model for up to 30 days before releasing it to other parties; and help pick which "trusted partners" get that early look.

Read all three sub-clauses together and the shape is consistent: this is a service a developer requests, not an inspection a regulator conducts. Nowhere in Section 3 - read in full, all five sections of the order - is any agency told to monitor model releases, request access unprompted, or apply the classified threshold to a model whose developer hasn't opted in. If a lab never engages Section 3(b), the classified benchmarking process built under Section 3(a) has, as far as the order's own text goes, nothing to say about that lab's model at all.

Section 3(c) closes the loop on the "surely this becomes mandatory eventually" reading: "Nothing in this section shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models." And the order's general provisions add that it "does not create any right or benefit, substantive or procedural, enforceable at law or in equity by any party" - so there's no legal hook on either side: the government can't compel entry, and a developer can't sue over how, or whether, it was assessed.

This next point is inference, not something the order states directly: because nothing requires public disclosure of which models have been benchmarked, assessed, or designated, there is no way to determine from the outside whether the classified process was actually finished by its August 1 deadline, or which models - if any - have gone through it. The process is classified by design; that a compliance milestone landed with no public confirmation either way is a structural feature of how the order was written, not evidence that anything went wrong.

03

What This Changes, and What It Doesn't

For a frontier lab weighing whether to engage: Section 3(b) is a real offer with a real cost attached. Thirty days of pre-release government access, and a role in selecting which "trusted partners" get early visibility into an unreleased model, are not small asks - they're the kind of thing a lab agrees to for a reason, whether that's access to threat intelligence CISA and the NSA hold, standing with agencies that will later matter for procurement, or genuine belief the benchmarking is useful. Nothing in this order forces that calculation; it just makes the offer.

This is also inference, though a narrower step: a lab that skips the offer entirely is not, on this order's own terms, exposed to any obligation or penalty for having skipped it. That reading follows directly from Sections 3(b), 3(c), and 5(c) - a voluntary framework, an explicit bar on making it mandatory, and no enforceable right of action attached to any of it - but it describes a legal consequence, not a quotation, so it's flagged as such rather than stated as fact.

For governance teams outside the frontier tier, the practical upshot is simpler: this order does not create a new compliance obligation to track. Coverage that frames Executive Order 14409 as a government review regime for advanced AI risks conflating "a mechanism exists" with "the mechanism reaches you" - and for any lab that hasn't opted in, it doesn't.

One caveat worth stating plainly: this order's silence on independent review doesn't mean frontier AI developers sit entirely outside government reach. Other federal authorities - classified national-security directives, general intelligence-collection powers, export-control mechanisms - exist independently of Executive Order 14409 and aren't addressed by it either way. What this order's own text supports is a narrower claim: that this specific mechanism, the one its own Section 3 heading calls "Secure Frontier Model Deployment," only ever reaches a model whose developer decided to bring it forward.


Source note: This Article is based on the full text of Executive Order 14409, signed June 2, 2026, read in its entirety (all five sections) and verified against raw HTML fetched directly from whitehouse.gov rather than a summarized excerpt.

Noa · ESG compliance

Map your disclosures against AI & Technology.

Noa reads your disclosures, traces every number to its source, and flags what's missing.

Book a demo
AP
About the author
Anuraag Paul
Co-Founder & Chief Sustainability Officer, Newtral
View LinkedIn profile →