Posted on Leave a comment

Trump AI plan sidelines open models in cybersecurity tests

image thumb 5

The Trump administration’s new AI cybersecurity testing blueprint carves out a broad exemption for open-weight and open-source models, leaving a conspicuous blind spot in federal oversight. For a geek culture increasingly powered by downloadable AI tools, that carveout could determine which systems face government scrutiny—and which remain entirely in the wild.

The framework grows out of a June executive order on “Promoting Advanced Artificial Intelligence Innovation and Security,” which directed agencies to build a voluntary pre-release testing regime for “covered frontier models” with advanced cyber capabilities. Under the order, AI developers are invited to give the federal government access to qualifying models up to 30 days before release so security experts can probe them for software vulnerabilities and offensive hacking potential. Federal News Network reports that agencies are also tasked with creating a classified benchmarking process to decide when a model’s cybersecurity and hacking performance is high enough to trigger review, with White House adviser David Sacks emphasizing that the system is meant for “step-change” advances rather than routine version bumps.

What makes this framework controversial is who it leaves out. Axios’ scoop on the final guidelines notes that “open models” are explicitly excluded from the program and that the text goes so far as to say it cannot be used to restrict open models once they’ve been released. The Wall Street Journal similarly reports that only closed, proprietary U.S. models with state-of-the-art capabilities in cybersecurity and hacking would be expected to come in for voluntary testing, while open-weight systems are exempt. The Washington Post adds that “free tools known as ‘open weight’ models”—systems whose weights can be downloaded and run by anyone—will get a pass from the new vetting regime, even as the White House focuses scrutiny on cutting-edge closed models from labs like OpenAI and Anthropic. Reuters, citing Trump advisers, underscores the point bluntly: the administration does not intend to safety-test open-weight models under this framework.

Despite the carveout, the White House is actively courting major AI players around the new regime. CNBC reports that officials invited executives from leading AI companies to a closed-door meeting to walk through the completed framework for reviewing the cybersecurity capabilities of advanced models. A separate CNBC investigation describes how the administration has begun dictating which “trusted partners” can access certain frontier systems early, shifting power over prerelease access away from tech giants and toward federal gatekeepers. A widely shared thread by an AI policy commentator on X clarifies that the framework is narrowly targeted at models demonstrating state-of-the-art performance in cybersecurity and hacking, and reiterates that open-source developers are “initially” exempt but could be drawn in later if their tools become more powerful.

For the open-source and modding communities that underpin much of geek culture, the exemption is a double-edged sword. On one hand, it means community-driven models—the kinds of open-weight systems hobbyists use to build AI dungeon masters, NPC dialogue engines, visual novel companions, or bespoke image generators—are unlikely to be slowed down by federal safety reviews or access controls. On the other hand, security researchers have long warned that the most dangerous misuse may come from widely available, locally runnable models that bad actors can fine-tune in secret, and the new framework does little to address those risks. If open weights evolve to match or exceed closed systems’ offensive cyber skills, gamers, indie devs, and home-lab tinkerers could find themselves experimenting with tools that foreign adversaries and cybercriminals are also quietly weaponizing.

The carveout also fits into a broader pattern in Trump-era AI policy. Guidance from the Office of Management and Budget on “unbiased AI” and accelerating federal AI use has repeatedly carved out exceptions for models acquired under free, open-source licenses, even as it demands greater transparency and code sharing for proprietary systems used by agencies. A client alert from law firm Crowell & Moring notes that recent White House efforts to rein in so-called “woke AI” likewise exclude open-source models from some contractor-facing requirements, alongside national security systems and incidental administrative uses. Taken together, the policies paint a picture of an administration that wants aggressive oversight of a narrow band of cutting-edge closed models while leaving open-source AI to self-govern.

As first reported by The Verge, the voluntary nature of the framework and its open-model carveout have already sparked debate among AI safety advocates, civil libertarians, and open-source developers. Some see the approach as a pragmatic compromise that targets the models most likely to be used in high-impact cyber operations without choking off the vibrant open-source ecosystem that powers much of today’s experimental AI work. Others worry that the government is building an oversight system with a built-in escape hatch for the very tools that are easiest to copy, modify, and abuse. Until Congress steps in with statutory rules or the administration revises its stance on open weights, the responsibility for policing open-source AI’s darker use cases will largely fall to the same geek communities that are pushing the tech forward.

Our Sponsors

Geeks talk back