Meta Is the Only Major US Lab Without a Pre-Release AI Safety Deal
The White House is pressing Meta to submit its AI models for pre-release government review — and Meta is the only major US lab that has not agreed.
OpenAI, Anthropic, Google, xAI, and Microsoft have all signed up for the voluntary review system. The program lets government evaluators assess frontier models before public release, testing whether they can assist with sensitive cybersecurity operations, expose security vulnerabilities, or create national security risks. Meta has not joined it. Four people familiar with the discussions confirmed the pressure campaign to the New York Times on June 23. Reuters separately corroborated the accounts.
Why Meta Is Different
Meta’s AI strategy diverges from the other labs in one structural way: open weights. Llama 4 Maverick and Llama 4 Scout are downloadable, modifiable, and runnable on private hardware anywhere in the world. Pre-release government review is built around a model the lab controls — one that can be delayed, restricted, or conditioned on clearance before it reaches users.
That model fits a closed API business. It sits awkwardly against a model you are planning to publish on Hugging Face.
OpenAI, Anthropic, Google, xAI, and Microsoft all operate primarily through controlled API endpoints. A government review window adds friction but doesn’t require them to redesign their distribution architecture. Meta releasing open weights under those conditions creates a different problem: the government can evaluate the model, but once the weights are public, evaluation is no longer a meaningful control mechanism.
What the Review Covers
Under the current framework, government reviewers receive access to models in a configuration that bypasses normal safety filters. The testing evaluates three specific risk categories: assistance with sensitive cyber tasks, the ability to expose security weaknesses in critical systems, and the potential to create national security risks at scale.
The framework was accelerated by Anthropic’s Mythos situation earlier this year. The US restricted Anthropic’s ability to release Mythos internationally after evaluations showed it could execute end-to-end cyberattacks against critical infrastructure. That episode prompted the White House to build a structured pre-release review process — a mechanism to catch those capabilities before restrictions became the only available response.
The Holdout Calculus
Meta has not publicly commented on the pressure campaign. Llama 5 is expected later this year.
If Meta signs, it faces a problem none of the other five labs have solved: how do you subject an open-weights model to pre-release review when the practical consequence of release is that the weights enter the global commons within hours? The government review can produce an assessment. It cannot produce a gate.
That gap — between knowing what a model can do and preventing that capability from spreading once the weights are out — is the unresolved structural question the voluntary framework has not yet addressed. Meta joining would expose it immediately. Meta not joining creates a different exposure: the only major US lab whose frontier models skip federal vetting before release.