Action completed!
Comply HQ Banner
AI Economy

U.S. Sets Up AI Pre-Release Testing Framework as Mythos Scare Reshapes Policy

By 11 min read
Claude by Anthropic displayed on a laptop screen, representing frontier AI models, cybersecurity testing, and growing U.S. government oversight of advanced artificial intelligence.

Anthropic’s advanced AI models have become central to the debate over frontier AI security, highlighting how rapidly improving capabilities are pushing governments toward pre-release testing and stronger oversight.

President Donald Trump signed an executive order on June 2, 2026 titled “Promoting Advanced Artificial Intelligence Innovation and Security,” establishing a framework for the federal government to evaluate advanced AI models for national security risks before they are released to the public. The review window is up to 30 days. Participation is voluntary.

The order came ten days after an Anthropic model called Mythos identified vulnerabilities in classified U.S. government computer systems within hours during a testing exercise. That event accelerated a policy debate that had been stalled inside the White House for months, and changed the public tone around whether the U.S. government could afford to wait any longer before building oversight infrastructure for frontier AI.

The framework falls short of a mandatory pre-clearance regime. The executive order explicitly states it does not create licensing, permitting, or approval requirements for new AI models. But the institutional architecture it sets up, including classified benchmarks administered by the National Security Agency and a formal government pre-release review channel, marks the administration’s first direct engagement with pre-deployment AI evaluation.

The Mythos Incident That Changed the Calculation

The pressure behind this order traces back to Anthropic’s Mythos model. A U.S. official told the Associated Press that, working through an Anthropic initiative called Project Glasswing, Mythos had been used alongside U.S. intelligence agencies to test federal systems. It identified certain vulnerabilities within hours, though the official clarified the model was not able to exploit them within that same timeframe.

Democratic Senator Mark Warner of Virginia described the findings before the Senate Committee on Banking, Housing and Urban Affairs, attributing the characterisation to the head of the National Security Agency and U.S. Cyber Command, General Timothy Haugh. Warner said the tool “broke into almost all of our classified systems, not in weeks but in hours.”

Anthropic had already restricted access to Mythos due to cybersecurity concerns, limiting it to a small group of approved organisations. The company released a limited version called Fable 5 more broadly. But the administration went further, issuing a directive requiring Anthropic to prevent foreign nationals from using Fable 5 and Mythos 5. Anthropic said it disabled the models for all customers to comply, while adding it did not believe the government’s steps were warranted by the concern it had flagged.

More than 100 cybersecurity experts and leaders from companies including Adobe and Nvidia signed a letter urging the Trump administration to lift the directive. The letter argued that Mythos models are capable at finding flaws in software and weaponising exploits, but “not uniquely good at these tasks,” and that taking away strong cyber defence tools without good reason could benefit U.S. adversaries.

What the Executive Order Actually Does

The order, formally titled “Promoting Advanced Artificial Intelligence Innovation and Security,” has three main pillars.

The first is cybersecurity across federal systems and critical infrastructure. Within 30 days of signing, the Committee on National Security Systems and the Secretary of Defense were directed to prioritise cyber defence. The Secretary of the Treasury was directed to form an “AI cybersecurity clearinghouse” in voluntary collaboration with the AI industry and critical infrastructure operators, to coordinate vulnerability scanning and remediation.

The second pillar is the voluntary pre-release engagement framework. By August 1, 2026, a multi-agency group led by the Secretary of the Treasury, the NSA Director, and the Secretary of Homeland Security through CISA must develop a classified benchmarking process to assess AI models’ advanced cyber capabilities and determine which systems qualify as “covered frontier models.” The NSA Director holds the authority to make that designation.

The third pillar is AI-enabled defence. Federal agencies are directed to expand access to AI-enabled defensive tools and strengthen hiring pathways for cybersecurity specialists under the U.S. Tech Force programme.

The order explicitly forecloses any reading that treats the framework as mandatory pre-clearance. No government agency has the authority to block or delay a model’s release under this order. Any binding restrictions on AI development or deployment would require new legislation from Congress or action under existing law.

CAISI and the Five-Lab Testing Programme

Even before the executive order, the Commerce Department’s Center for AI Standards and Innovation had been quietly expanding its pre-deployment evaluation programme. On May 5, 2026, CAISI announced agreements with Google DeepMind, Microsoft, and Elon Musk’s xAI to evaluate their AI models before public release.

The three join Anthropic and OpenAI, which signed similar agreements almost two years ago during the Biden administration, when CAISI was known as the U.S. Artificial Intelligence Safety Institute. Every major American frontier AI developer is now under voluntary federal pre-deployment review.

CAISI sits under the National Institute of Standards and Technology within the Department of Commerce. The agency’s director, Chris Fall, said in a statement that “independent, rigorous measurement science is essential to understanding frontier AI and its national security implications,” and that expanded industry collaborations help CAISI scale its work at a critical moment.

CAISI said it had already completed more than 40 evaluations, including on models not yet available to the public. Developers frequently hand over versions of their models with safety guardrails stripped back so the centre can probe for national security risks.

The evaluations run through a body called the TRAINS Taskforce, which stands for Testing Risks of AI for National Security. Convened in November 2024 under the Biden administration, it has carried over. TRAINS pulls evaluators from across the federal government: NIH evaluators handle biosecurity, the national labs handle chemical and nuclear proliferation risks, and the Department of Defense and Department of Homeland Security handle cybersecurity work.

How the Labs Responded

Microsoft’s Chief Responsible AI Officer Natasha Crampton said in a statement that agreements like this are essential to building trust and confidence in advanced AI systems. Microsoft said it will work with government scientists to test AI systems “in ways that probe unexpected behaviors.” Google declined to comment further on the agreement. xAI did not respond to requests for comment.

Fritz Jean-Louis, principal cybersecurity advisor at Info-Tech Research Group, told CIO that the CAISI agreements signal a shift toward proactive security for agentic AI, adding that the initiative “pushes the industry toward security-by-design for increasingly autonomous AI systems.” He also flagged an open question: how intellectual property would be protected under this approach.

The political dynamics are notable. xAI has been publicly sceptical of AI safety regulation and still signed the CAISI agreement. Microsoft, the most exposed to government procurement, signed the longest-term agreement. The pattern across all five labs suggests that federal procurement relationships are a quiet but significant incentive, even where companies disagree with the broader regulatory direction.

Anthropic displayed on a smartphone resting on a laptop keyboard, representing frontier AI development, cybersecurity testing, and growing government scrutiny of advanced AI models.
Anthropic’s advanced AI models have become a key part of the U.S. debate over frontier AI security, helping accelerate calls for government testing of powerful models before public release.

A Voluntary Framework With Binding Implications

The word “voluntary” in the executive order should not be read as consequence-free. As legal analysis from Ropes and Gray noted, while the order is voluntary in form, it builds significant institutional architecture that may establish de facto compliance expectations for frontier AI developers.

ElementDetails
Framework namePromoting Advanced Artificial Intelligence Innovation and Security
SignedJune 2, 2026
Review windowUp to 30 days before public release
ParticipationVoluntary
Classified benchmarksNSA-administered, due by August 1, 2026
AI clearinghouseTreasury-led, launched within 30 days of signing
Labs under CAISI reviewOpenAI, Anthropic, Google DeepMind, Microsoft, xAI

A vendor that has refused or failed a CAISI evaluation looks worse on a federal government contract than one that has not. The Pentagon signed AI procurement deals with eight major vendors this year. In that context, “voluntary” carries a pressure that does not show up in the text of the order.

A national poll by Morning Consult found that 47 percent of Republican voters strongly support testing AI models before public release, compared to just 5 percent who strongly oppose it. A separate poll by the Institute for Family Studies found more than 80 percent of Americans support the plan. That bipartisan public sentiment gives the administration political room to tighten the framework over time, even if the current order avoids mandatory language.

The framework document is due to be finalised by August 1, 2026. The classified benchmarking criteria, the terms of the voluntary pre-release channel, and the operational rules governing the cybersecurity clearinghouse will determine whether this order remains a collaborative exercise or begins to set expectations that are difficult to ignore, even without legal force behind them.

Frequently Asked Questions

What is the U.S. AI pre-release testing framework signed in June 2026? President Trump signed an executive order on June 2, 2026 called “Promoting Advanced Artificial Intelligence Innovation and Security.” It creates a voluntary system in which AI developers can submit their most advanced models for up to 30 days of government review before public release. The NSA administers classified benchmarks to assess cybersecurity risks, and CAISI conducts the actual evaluations. The framework does not create any mandatory licensing or approval requirements.

Why did the U.S. government move toward AI pre-release testing? The immediate catalyst was Anthropic’s Mythos model, which identified vulnerabilities in classified U.S. government computer systems within hours during a testing exercise conducted through Project Glasswing. The findings alarmed national security officials and accelerated a policy debate inside the White House that had been stalled for months. The Trump administration had previously delayed signing an earlier version of the order over concerns it would stifle AI innovation.

What is CAISI and what does it do? CAISI stands for the Center for AI Standards and Innovation. It is a division of the Commerce Department housed within NIST, and serves as the government’s main hub for AI model testing. CAISI signed agreements with all five major U.S. frontier AI developers, covering pre-deployment and post-deployment evaluation. By May 2026, the agency had completed more than 40 evaluations, including on models not yet publicly available.

Is the AI pre-release testing in the U.S. mandatory? No. The executive order explicitly states it does not create a mandatory licensing, permitting, or approval process for AI models. However, legal analysts note the framework carries implicit pressure for companies that rely on federal procurement contracts. A developer that declines or fails a CAISI evaluation may face disadvantages in government contract bidding, even without formal legal obligation.

What is the TRAINS Taskforce? TRAINS stands for Testing Risks of AI for National Security. It is a multi-agency government body convened in November 2024 that runs the actual evaluations under CAISI agreements. It draws evaluators from NIH, the national laboratories, the Department of Defense, and the Department of Homeland Security, each handling their area of expertise such as biosecurity, chemical and nuclear proliferation, and cybersecurity.

What happens next with U.S. AI oversight policy? The classified benchmarking process and the voluntary pre-release engagement framework are both due to be finalised by August 1, 2026. Those documents will define which AI systems qualify as “covered frontier models” and what the terms of government review actually look like in practice. Congress has also been signalling interest in stronger legislation. The current executive order framework may be a floor, not a ceiling.


Sources


Stay in the Loop

For more stories, breakdowns, and unfiltered takes on what is really happening in Indian and global business and tech, follow TheFounder Nation.

Instagram: thefoundernation

We cover what the mainstream business press won’t.


© TheFounder Nation | All rights reserved

Sign In to TFN

Join the community of founders, creators, and leaders.