What was finished on 1 August

On Tuesday, staff from Anthropic, Google, Meta and OpenAI were due at the Office of the National Cyber Director to discuss a document none of them can show a customer. Two days earlier the White House had confirmed that the voluntary framework required by Executive Order 14409 was finished on schedule. "The voluntary framework outlined in the June 2nd executive order was complete by the deadline," an official said. "Discussions with industry about next steps are underway."

The order, signed on 2 June 2026 and titled Promoting Advanced Artificial Intelligence Innovation and Security, carried two dated deliverables: an AI cybersecurity clearinghouse at the Treasury by 2 July, and this framework by 1 August. Under it, the federal government may take up to 30 days with a covered frontier model before that model reaches other trusted partners, who are selected jointly by the developer and the government. The order says plainly that it creates no mandatory licensing, pre-clearance or permitting mechanism.

What is withheld matters more than what was delivered. The framework is unclassified but has not been published. The benchmark used to assess a model's advanced cyber capabilities is classified, and so is the threshold that decides which models are covered, which is shared with developers as appropriate. Asked why an unclassified document is not public, an official replied: "Just because things are unclassified that doesn't mean we are going to broadcast them to everyone." Google, OpenAI and Anthropic reviewed a draft and submitted edits in late July.

The same week, Brussels published its number

On 2 August the Commission began enforcing the AI Act's rules for general purpose models. Article 51 sets out how a model becomes a systemic-risk model: it is presumed to have high-impact capabilities when the cumulative computation used for training exceeds 10^25 floating point operations, or when the Commission decides a model has equivalent capability against the criteria in Annex XIII.

That number is not frozen. Article 51(3) lets the Commission amend the threshold by delegated act to reflect algorithmic improvement and hardware efficiency. But it moves in public, in a published instrument, and until it moves, anyone with a calculator and a vendor's training disclosure can work out which side of the line a model sits on.

The asymmetry is not about strictness. Two jurisdictions hit a deadline in the same week, on the same variable, and made opposite disclosure choices about it. The binding regime published the line that decides scope. The voluntary regime classified it, and had an intelligence agency build the test behind it. That is the reverse of how most buyers assume regulation behaves.

What a classified threshold does to an assurance chain

Why it matters: a vendor sentence of the form "our model went through the federal review process" cannot be tested by the person reading it. You cannot establish that the model was ever in scope, because the criterion for scope is classified. You cannot read the benchmark, because the benchmark is classified. And you cannot tell whether the absence of a review means the model sat below the line or that the developer simply chose not to take part, because participation is voluntary.

This is not ordinary commercial confidentiality. An audit report you are not shown is still a report that an independent party produced against a published standard, and the standard is the thing you rely on. Here the standard itself is the secret and the assessor is a government, with the National Security Agency central to the benchmarking. No third party can attest to conformity, because there is no published thing to conform to.

The practical effect is to push assurance back onto the one regime that prints its criteria. For a European buyer, Article 51 status is a fact about the model rather than a claim about a process: either the training compute crosses the threshold or it does not, and the obligations that follow are written down and enforceable by the AI Office. That does not make a model safe. It makes one line in your vendor questionnaire answerable.

What to do before the next contract

Three questions are worth adding this month. First, ask whether the model is a general purpose model with systemic risk under Article 51 and on what basis, compute or Commission designation. That answer can be checked. Second, ask whether the vendor takes part in the US voluntary early-access programme, and file the answer as an unverifiable representation, not as evidence. Third, ask what the vendor undertakes to tell you if its participation changes, because that notice is the only visibility you will get. British buyers should note that leaving the AI Act's jurisdiction does not produce a second published threshold; it removes the one they had.

The wider point for anyone drafting AI clauses this quarter is simple enough. An oversight claim is worth exactly what its criterion is worth. A regime that publishes a number gives you something to hold a vendor to. A regime that classifies the number gives you a sentence.