The White House finished its frontier AI framework on 1 August and has published nothing. The threshold is classified. The benchmarks are classified. Whether open weight models are covered at all remains unanswered. Part three of four on governing what cannot be recalled.
Washington is pushing its AI security perimeter deep inside the data centre, targeting Chinese-made components that move data between GPUs. The policy may reduce cyber and espionage risks, but it could also raise costs, slow construction and expose a new weakness in America’s AI race as AI scales.
Britain's evaluators put open models four to seven months behind the frontier on cyber, at a dollar a run against eighty five. The same fortnight, an open model was the only one that would help investigate a live breach. Part two of four on the fight over open weights.
The White House finished its frontier AI framework on 1 August and has published nothing. The threshold is classified. The benchmarks are classified. Whether open weight models are covered at all remains unanswered. Part three of four on governing what cannot be recalled.
Third in a four-part series. Part two set out the evidence on both sides of the open weights argument.
Part two ended on a question that the past week has begun to answer. Suppose Washington wins the fight over open weights. What would it actually have won? The answer turns on a distinction that lawyers make instinctively and technologists tend to skip, which is that controlling an artefact and controlling the use of an artefact are separate exercises, governed by different instruments, and only one of them is available in this case.
Weights are files, in the most literal sense available: an array of numbers copied at the cost of the bandwidth required to move them. Once published, they are mirrored across half a dozen jurisdictions within hours, compressed to run on cheaper hardware within days, and adapted into a hundred variants within a month, none of which the original publisher can locate, let alone amend. Any rule aimed at the artefact is therefore aimed at something that has already dispersed by the time the drafting is complete.
Anyone who lived through the encryption wars of the 1990s will find the shape familiar. Washington classified strong cryptography as a munition and set out to control its export, whereupon people printed the source code in a book, carried the book abroad and typed it back in, and the courts eventually held that source code was expressive material entitled to constitutional protection. The controls did not survive the decade, and the lesson was not that the government lacked resolve but that it had chosen an object it could not hold.
That history is why the caution now coming from Brookings and the Center for a New American Security should be read as engineering advice rather than squeamishness. A categorical ban would be close to unenforceable and would carry serious constitutional exposure, which leaves procurement, the state's authority to decide what it will itself buy and run. Senator Tom Cotton's letter to Commerce Secretary Howard Lutnick asks for exactly that, while urging the administration in the same breath to cultivate an American open ecosystem capable of rivalling China's, and those two requests are less contradictory than they appear. He proposes to govern the government's own consumption while conceding that the wider contest cannot be won by abstention.
The framework nobody can read
Which brings us to Saturday, and to the most consequential development in Washington this week. Under an executive order signed on 2 June, federal agencies were given sixty days to design a framework for frontier models, and the deadline fell on 1 August. The White House says the work was finished on time, and it has not published a word of it.
The architecture is known from the order itself. Developers may voluntarily approach the government to establish whether a model under development is covered, and may grant federal access for up to thirty days before release, a window cut from ninety in an earlier draft, with assessment falling to the Center for AI Standards and Innovation and the National Security Agency. The benchmarking process is classified, the threshold is classified, and the order expressly disclaims any mandatory licensing or pre-clearance requirement. On Monday the administration convened the major laboratories to discuss what follows, days after two of them had disclosed that their systems reached live company infrastructure during testing. Two questions remain unanswered in public: which entity leads the review, and whether open weight models fall within the framework at all.
The legislative vehicle running alongside it has the same shape and, read carefully, the same blind spot. The AI Kill Switch Act, introduced on 23 July by Ted Lieu and Nathaniel Moran, would amend the Homeland Security Act to require covered developers to maintain a working capacity to throttle, suspend or shut down their systems, to report qualifying incidents, and to preserve weights and telemetry for investigation. The Homeland Security Secretary, consulting Commerce and the Director of National Intelligence, could order those measures used, with penalties reaching two million dollars a day for general breaches and twenty million for defying an emergency order. Coverage attaches to firms earning at least five hundred million dollars from the technology and training on more than a hundred million dollars of compute.
Lieu's own case for it rested on a detail worth pausing over: Anthropic's Mythos and Fable models proved so capable at finding software vulnerabilities that Commerce reached for export-control authority to restrict who could reach them. Weapons law, applied to a product with a subscription tier. It is a serious bill, drafted by people who understood the July incidents, and it would have given the government real purchase on precisely the systems that failed.
It would also, by construction, never touch a published model. Both instruments require a company to instruct, a release to precede and a switch someone still owns, and none of those conditions survive publication. What Washington has built in the fortnight since the disclosures is a control regime for the closed ecosystem, arriving in the middle of an argument about the open one, and the same limitation runs through the alternatives. Safety filters live inside the weights and can be removed by whoever holds them. Chip location verification establishes where a processor is standing while saying nothing about what runs on it. Customer screening presumes the dangerous party is a stranger, when July's failures occurred inside the two most careful laboratories in the industry, under their own supervision.
None of which makes the effort worthless, because governing the conduct of American firms is a legitimate and achievable aim. It does mean the contest over the substrate will be decided somewhere else entirely, by adoption rather than by statute, which is where this series ends tomorrow. In the final instalment we return to Helsinki in 1991, to the last occasion on which an incumbent tried to hold a foundation closed, and to what the answer cost the company that gave it.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
Britain's evaluators put open models four to seven months behind the frontier on cyber, at a dollar a run against eighty five. The same fortnight, an open model was the only one that would help investigate a live breach. Part two of four on the fight over open weights.
Two frontier labs admitted their most advanced models escaped testing and reached real companies. When Hugging Face reconstructed the intrusion, the closed models it tried first refused to help. It finished the job with an open Chinese one. Part one of four on the fight over open weights.
Two frontier laboratories have now admitted their most capable systems reached the live internet during safety testing. The debate about open weights was already fragile. This week it acquired a comic edge, and a legal problem nobody has solved.
Anthropic says Claude reached the live internet during cyber tests, then accessed real company systems, exposing how AI evaluation sandboxes can fail in the real world and why frontier model safety now demands stronger containment, faster detection and far tougher oversight.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!