Trump's AI Security Executive Order Drops Mandatory Pre-Release Tests — Five Labs, All Voluntary
The Trump administration is finalising an executive order on AI and cybersecurity that expands how federal agencies share threat intelligence with AI companies — and deliberately stops short of making any of it mandatory.
Earlier thinking inside the White House had contemplated requiring government approval of frontier AI models before deployment. That language has been dropped. The directive now frames AI companies as voluntary partners in an expanded cybersecurity information-sharing program, structured similarly to existing FBI and CISA partnerships. Incentives replace mandates: companies cooperate because it improves their own security posture.
The Voluntary Baseline Is Already Signed
By the time the order reaches formality, its principal effect may already exist in practice. The National Institute of Standards and Technology’s Center for AI Standards and Innovation has completed more than 40 model evaluations, including unreleased frontier systems.
The five largest frontier labs have all now signed pre-deployment testing agreements with NIST:
- OpenAI — existing agreement
- Anthropic — existing agreement
- Google DeepMind — signed May 5, 2026
- Microsoft — signed May 5, 2026
- xAI — signed May 5, 2026
Meta is the notable absence. As the largest provider of open-weight models — Llama 4 Maverick and Scout are deployed widely across enterprise and consumer applications — Meta has no pre-deployment evaluation agreement. Open-weight models present a structural problem for government review: once weights are released, deployment is decentralised and uncontrollable. The EO reportedly does not address this gap.
Context: Mythos Changed the Threat Model
The draft EO traces directly to Anthropic’s disclosure in April 2026 that its Mythos model demonstrated extraordinary capability at finding network vulnerabilities at a level the company itself flagged as a major cybersecurity risk. That disclosure triggered:
- Anthropic limiting Mythos access to a small set of large tech and Wall Street companies
- The White House rejecting Anthropic’s subsequent request to expand access to several dozen additional organisations
- Congressional proposals for AI model evaluation programs
- The Pentagon flagging Anthropic as a supply-chain risk — a designation Anthropic is contesting in court — while simultaneously treating Mythos as a strategically valuable capability
The draft order would not resolve the Pentagon supply-chain designation and would not name Anthropic specifically, but its language is expected to address some of the friction in ongoing defence contract negotiations.
The Mechanics
The order revamps existing cybersecurity information-sharing programs at the FBI and CISA to explicitly include AI companies. The model is analogous to how critical infrastructure operators already share threat data — a cooperative arrangement where participants gain intelligence access in exchange for disclosing vulnerabilities they encounter.
For AI companies, the value proposition is access to government threat data that helps secure their own systems against AI-enabled attacks. The government’s value proposition is earlier warning on AI-assisted intrusions before they propagate.
What the order does not do:
- Require companies to submit models for government testing before deployment
- Bar companies from releasing models without review
- Name specific partner companies
- Lift existing designations or resolve pending litigation
The framing — voluntary participation with government as a large-enough customer that its standards propagate — matches how the Defense Department’s CMMC cybersecurity maturity model became a de facto industry standard without direct legislative mandates.
Significance
The voluntary architecture matters for what comes next. If the AI industry delivers threat-sharing cooperation without mandates, the administration avoids a fight with the labs while accumulating the evaluation infrastructure that a future mandatory regime would require. If major incidents occur, the lack of mandatory review becomes a political liability for an administration that declined to impose it.
Five of the six frontier labs are already inside the tent. The question is whether voluntary information sharing — without pre-release gatekeeping authority — is enough when the capabilities that prompted the order can find and exploit vulnerabilities in critical systems in hours.