Read this post on Neil’s Substack: Getting Out of Control.
In the midst of the D.C. furor over Anthropic’s Mythos AI model and its cybersecurity capabilities, the Trump Administration issue a June 2 Executive Order on “Promoting Advanced Artificial Intelligence Innovation and Security.”
One problem the EO sought to solve: how to get cutting-edge models into the hands of the good guys first, so they can harden their cyberdefenses before the models are released widely. The EO therefore charged cabinet officials with “design[ing] a voluntary framework with AI developers” to provide early access to frontier models, with an August 1, 2026 deadline. Reportedly, the government met that deadline and some large U.S. labs are being briefed on the framework today.
But sources indicate that the government will not release the framework publicly. From Axios:
The White House does not plan to publicly release its new framework for evaluating advanced AI models, three sources familiar with the discussions told Axios.
Why it matters: The voluntary framework has global implications for AI security, but details will only be made available to the companies that are part of the process.
Keeping it private means companies, policymakers, researchers and U.S. allies outside the process will be left guessing how the administration plans to implement one of its key AI policies.
We know roughly what the framework looks like. The June EO sketched its key features:
- a classified benchmark to determine which models count as “covered frontier models,” and
- a voluntary framework under which developers work with the government to decide whether a given model is covered, give the government early access to covered models, and help select other trusted partners to receive early access.
But, as I pointed out, that framework had serious gaps. It appeared to give the government wide discretion over when early-access periods start and stop, and it set no timeline for general release to the public. If a government decisionmaker can extend the early-access window at will, they transform a voluntary early-access program into a de facto licensing regime, informal and standardless.
Maybe the final framework fixes those gaps. We don’t know because it isn’t public.
That secrecy compounds any problems. Remember, this framework hands the government early access to cutting-edge tools and may give it a veto over whether the rest of us ever use them. That is no way for democracy to govern what may be the most important technology of our lifetimes. Such a regime invites abuse. It will likely shift with each new administration. And it will over-index on national security at the expense of the economy.
The right path to balancing these concerns runs through Congress. As I’ve said before, “only Congress can create a durable framework to address these challenges.”
But, to be more constructive than just criticizing Congress, I drafted legislative language myself. It builds on the June 2 EO’s framework to establish what I believe is a voluntary early-access program for government and key infrastructure players, one that limits discretion and so preserves predictability, impartiality, and transparency.Full text is below. Google Doc is here. I welcome all inquiries and feedback!
A BILL
To establish a voluntary, confidential, and non-discretionary pre-release framework for secure frontier model deployment; and for other purposes.
Be it enacted by the Senate and House of Representatives of the United States of America in Congress assembled,
SECTION 1. SHORT TITLE.
This Act may be cited as the “Advanced Artificial Intelligence Innovation and Security Act of 2026.”
SEC. 2. DEFINITIONS.
In this Act:
(1) ARTIFICIAL INTELLIGENCE; AI.— The terms “artificial intelligence” and “AI” mean a machine-based system that can, for a given set of human-defined objectives, make predictions, recommendations, or decisions influencing real or virtual environments, including systems that generate text, software code, images, audio, video, or other content.
(2) AI DEVELOPER.— The term “AI developer” means any person, partnership, corporation, association, institution, or other entity organized under the laws of the United States, or otherwise subject to the jurisdiction of the United States, that develops, trains, substantially modifies, deploys, or controls access to an advanced cyber-relevant AI model.
(3) ADVANCED CYBER-RELEVANT AI MODEL.— The term “advanced cyber relevant AI model” means an AI model that is capable of performing, or is designed to perform, complex cybersecurity, software-development, or autonomous-agent tasks at a level that may materially affect national cybersecurity and critical infrastructure security.
(4) APPROPRIATE CONGRESSIONAL COMMITTEES.— The term “appropriate congressional committees” means—
(A) the Committee on Armed Services, the Committee on Homeland Security and Governmental Affairs, the Committee on Commerce, Science, and Transportation, the Committee on Banking, Housing, and Urban Affairs, the Committee on Appropriations, and the Select Committee on Intelligence of the Senate; and
(B) the Committee on Armed Services, the Committee on Homeland Security, the Committee on Energy and Commerce, the Committee on Financial Services, the Committee on Appropriations, and the Permanent Select Committee on Intelligence of the House of Representatives.
(5) CISA.— The term “CISA” means the Cybersecurity and Infrastructure Security Agency.
(6) COVERED AGENCY.— The term “covered agency” means—
(A) the Department of the Treasury;
(B) the Department of Defense, acting through the National Security Agency;
(C) the Department of Homeland Security, acting through CISA;
(D) the Department of Commerce, acting through the National Institute of Standards and Technology;
(E) the Office of the National Cyber Director;
(F) the Office of Science and Technology Policy; and
(G) any other executive department or agency that receives access to protected voluntary AI cybersecurity information only with the express written consent of the applicable AI developer.
(7) COVERED FRONTIER MODEL.— The term “covered frontier model” means an advanced cyber-relevant AI model that an AI developer, in the sole discretion of the AI developer, voluntarily identifies in a notice submitted under section 4 as a model for which the developer elects to participate in the voluntary program established under that section.
(8) CRITICAL INFRASTRUCTURE.— The term “critical infrastructure” has the meaning given the term in section 1016(e) of the USA PATRIOT Act of 2001 (42 U.S.C. 5195c(e)).
(9) DIRECTOR OF CISA.— The term “Director of CISA” means the Director of the Cybersecurity and Infrastructure Security Agency.
(10) DIRECTOR OF NSA.— The term “Director of NSA” means the Director of the National Security Agency.
(11) PRE-RELEASE WINDOW.— The term “pre-release window” means the fixed, voluntary period described in section 4 during which an AI developer may provide controlled access to a covered frontier model to covered agencies before the developer releases the model to trusted partners or the public.
(12) PROGRAM.— The term “program” means the voluntary pre-release secure frontier model program established in section 5.
(13) PROTECTED VOLUNTARY AI CYBERSECURITY INFORMATION.— The term “protected voluntary AI cybersecurity information” means any information, notice, communication, model access credential, model output, evaluation result, vulnerability information, technical artifact, security documentation, deployment plan, trusted partner plan, anticipated release date, or other commercial, technical, operational, or cybersecurity information submitted to, generated by, or exchanged with the Federal Government under section 4.
(14) SECRETARY OF DEFENSE.— The term “Secretary of Defense” includes the Secretary of Defense when acting through the Director of NSA or under any lawful secondary title or designation.
(15) TRUSTED PARTNER.— The term “trusted partner” means any Federal, State, local, Tribal, territorial, allied foreign governmental, critical infrastructure, research, commercial, nonprofit, or other partner selected by an AI developer, in the sole discretion of the AI developer, to receive early or staged access to a covered frontier model.
(16) TRUSTED PARTNER FACILITATION WINDOW.— The term “trusted partner facilitation window” means the fixed, voluntary 30-calendar-day period described in section 4 during which covered agencies may provide nonbinding advice or facilitation, at the request of an AI developer, concerning trusted partner access to a covered frontier model.
SEC. 3. FINDINGS AND POLICY.
(a) Findings.— Congress finds the following:
(1) The United States leads the world in artificial intelligence because of the talent, ingenuity, capital formation, research capacity, entrepreneurial culture, and technical excellence of American AI developers, researchers, workers, and institutions.
(2) Advanced AI capabilities can strengthen the national security, economic security, scientific leadership, and cyber resilience of the United States.
(3) Advanced AI capabilities also create new national security and cybersecurity considerations, including the potential use of AI by criminal actors, foreign adversaries, and other malicious actors to identify vulnerabilities, accelerate intrusion campaigns, steal intellectual property, or damage public and private information systems.
(4) The Federal Government should work collaboratively with the private sector to promote secure innovation, protect American ingenuity and intellectual property, and cultivate advanced AI-enabled capabilities.
(5) The United States should promote AI innovation and security through voluntary, clearly defined, time-limited, confidential, and non-discretionary collaboration with industry.
(6) The United States should not create a mandatory licensing, preclearance, permitting, designation, benchmarking, threshold, certification, non-objection, or governmental approval regime for the development, training, modification, testing, release, publication, deployment, distribution, or use of AI models.
(b) Policy.— It is the policy of the United States—
(1) to promote the rapid development, secure deployment, and timely adoption of advanced AI capabilities;
(2) to promote voluntary public-private collaboration that improves cybersecurity without delaying innovation or conditioning model release on Federal approval;
(3) to ensure that Federal engagement with unreleased AI models is confidential, limited in time, limited in purpose, and subject to strict cybersecurity, insider-risk, intellectual-property, use, and nondisclosure protections;
(4) to ensure that any voluntary pre-release engagement begins and ends according to definite statutory timelines, without agency discretion to delay, toll, extend, or condition such timelines; and
(5) to preserve the sole authority of AI developers to decide whether to participate, which models to include, when to release models, and which trusted partners may receive access.
SEC. 4. VOLUNTARY PRE-RELEASE SECURE FRONTIER MODEL PROGRAM.
(a) Establishment.—
(1) IN GENERAL.— There is established a voluntary pre-release secure frontier model program, which shall operate by force of this section and shall be administered by CISA, NSA, the Department of the Treasury, the National Institute of Standards and Technology, the Office of the National Cyber Director, and the Office of Science and Technology Policy in accordance with this section.
(2) SELF-EXECUTING PROGRAM.— The program established under paragraph (1) shall be self-executing. An AI developer may participate in the program by submitting the notice described in subsection (d), and participation shall not require any rulemaking, guidance, form, acknowledgement, approval, certification, designation, concurrence, non-objection, or other action by any Federal agency.
(3) MINISTERIAL ADMINISTRATION.— Administration of the program shall be ministerial. No officer or employee of the United States may approve, disapprove, certify, license, designate, rate, or make a binding determination with respect to—
(A) whether an AI model is a covered frontier model;
(B) whether an AI developer may participate in the program;
(C) whether a pre-release window may begin or end;
(D) whether a trusted partner facilitation window may begin or end;
(E) whether a covered frontier model may be released, published, deployed, distributed, or made available to trusted partners or the public;
(F) whether a trusted partner may receive access to a covered frontier model; or
(G) whether an AI developer has satisfied any condition precedent to release, publication, deployment, distribution, or trusted partner access.
(4) FAILURE TO ACT.— If any covered agency fails to provide a form, maintain an electronic portal, acknowledge receipt, designate personnel, conduct testing, provide comments, produce feedback, provide facilitation, issue guidance, or otherwise act within a period specified in this section, such failure shall not delay, extend, suspend, toll, condition, or otherwise affect—
(A) the beginning, running, expiration, or termination of the pre-release window;
(B) the beginning, running, expiration, or termination of the trusted partner facilitation window; or
(C) any release, publication, deployment, distribution, trusted partner access, public access, commercial action, or other action by an AI developer.
(b) Covered Agency Roles.—
(1) CISA.— CISA shall serve as the civilian intake and coordination office for notices submitted under this section and shall maintain, to the extent practicable, a secure electronic submission mechanism. Failure by CISA to maintain such mechanism shall not prevent an AI developer from submitting notice by any reasonable secure written method.
(2) NSA.— NSA shall serve as the technical national security cyber participant for purposes of evaluating, during the pre-release window only, cyber-defense, cyber-offense, vulnerability discovery, and related national security considerations associated with a covered frontier model. NSA shall not designate models, determine thresholds, approve releases, extend windows, or select trusted partners.
(3) TREASURY.— The Department of the Treasury may coordinate, during the pre-release window and trusted partner facilitation window only, with respect to financial-sector cybersecurity, systemic cyber risk, critical infrastructure vulnerability remediation, and trusted partner facilitation requested by the AI developer. The Department of the Treasury shall not designate models, approve releases, extend windows, or select trusted partners.
(4) NIST.— The National Institute of Standards and Technology may provide technical measurement, evaluation, and standards expertise at the request of a participating AI developer or covered agency, subject to the confidentiality, use, cybersecurity, insider-risk, intellectual-property, and nondisclosure requirements of this section. NIST shall not designate models, approve releases, extend windows, or select trusted partners.
(5) NATIONAL CYBER DIRECTOR.— The National Cyber Director may coordinate covered agency participation and deconflict Federal engagement during the pre-release window and trusted partner facilitation window. The National Cyber Director shall not designate models, approve releases, extend windows, or select trusted partners.
(6) OFFICE OF SCIENCE AND TECHNOLOGY POLICY.— The Office of Science and Technology Policy may provide scientific and technical coordination during the pre-release window and trusted partner facilitation window. The Office of Science and Technology Policy shall not designate models, approve releases, extend windows, or select trusted partners.
(7) OTHER AGENCIES.— No executive department or agency other than a covered agency described in paragraphs (1) through (6) may receive protected voluntary AI cybersecurity information or participate in model access under this section unless the AI developer provides express written consent identifying the additional agency, the purpose of the access, and the duration of the access.
(c) Company Self-Designation And Election To Participate.—
(1) SOLE DISCRETION OF DEVELOPER.— An AI developer may, in the sole discretion of the AI developer, elect to treat any advanced cyber-relevant AI model as a covered frontier model for purposes of this section.
(2) NO GOVERNMENT THRESHOLD OR BENCHMARKING REQUIREMENT.— No Federal benchmarking process, capability threshold, agency determination, agency designation, classification decision, interagency process, or other governmental approval shall be required for an AI developer to identify a model as a covered frontier model or to participate in the program.
(3) NO GOVERNMENT DETERMINATION.— No Federal agency may determine, for purposes of this section, whether a model is or is not a covered frontier model. A model identified in a notice submitted under subsection (d) shall be treated as a covered frontier model solely because the AI developer voluntarily elected such treatment.
(4) EFFECT OF ELECTION.— A model identified in a notice submitted under subsection (d) shall be deemed a covered frontier model immediately upon transmission of the notice. Such status shall not require acknowledgement, confirmation, concurrence, acceptance, or any other action by a Federal agency.
(d) Notice Of Voluntary Participation.—
(1) IN GENERAL.— An AI developer electing to participate in the program shall submit a confidential notice of voluntary pre-release access to CISA or to any covered agency identified by the AI developer.
(2) REQUIRED CONTENTS.— A notice under paragraph (1) shall include, to the extent available to the AI developer at the time of submission—
(A) the name of the AI developer;
(B) a business, security, or legal point of contact for the AI developer;
(C) a model name, code name, version identifier, or other internal identifier sufficient for the AI developer to identify the model;
(D) the date and time on which the AI developer elects the pre-release window to begin, if later than the time of transmission;
(E) the anticipated date, if known, on which the AI developer may release, publish, deploy, distribute, or otherwise provide access to the covered frontier model to trusted partners or the public;
(F) a general description of the access mechanism the AI developer elects to provide, which may include controlled application programming interface access, sandbox access, secure evaluation environment access, structured demonstration access, limited red-team access, or another access method selected by the AI developer;
(G) any security, insider-risk, intellectual-property, access-control, monitoring, logging, rate-limit, retention, destruction, or use restrictions required by the AI developer;
(H) whether the AI developer requests nonbinding Federal technical feedback, trusted partner facilitation, vulnerability coordination, or other support during the pre-release window or trusted partner facilitation window; and
(I) any other information the AI developer elects to provide.
(3) NO SOURCE CODE, WEIGHTS, OR TRAINING DATA REQUIRED.— Nothing in this section shall require an AI developer to provide model weights, source code, training data, fine-tuning data, system prompts, architecture details, proprietary datasets, customer data, user data, trade secrets, or other proprietary information.
(4) COMPLETENESS.— A notice that contains the information described in paragraph (2), to the extent available to the AI developer, shall be complete upon transmission. No Federal agency may determine that a notice is incomplete for the purpose of delaying, extending, suspending, tolling, conditioning, or preventing the beginning, running, expiration, or termination of any window under this section.
(5) SUPPLEMENTATION.— An AI developer may supplement, amend, narrow, or withdraw a notice at any time. Supplementation, amendment, narrowing, or withdrawal shall not restart or extend any window under this section unless the AI developer expressly elects a new or extended window in writing.
(e) Pre-Release Window.—
(1) COMMENCEMENT.— The pre-release window for a covered frontier model shall begin at the earlier of—
(A) the time the AI developer transmits the notice under subsection (d) and makes the access described in the notice available to at least one covered agency; or
(B) any later date and time specified by the AI developer in the notice.
(2) DURATION.— The pre-release window shall last for 14 calendar days unless the AI developer elects a shorter period in the notice or terminates the window earlier under paragraph (4).
(3) AUTOMATIC EXPIRATION.— The pre-release window shall expire automatically at 11:59 p.m. eastern time on the 14th calendar day after the window begins, or at the end of any shorter period elected by the AI developer. Expiration shall not require acknowledgement, concurrence, certification, approval, non-objection, or any other action by a Federal agency.
(4) EARLY TERMINATION.— An AI developer may terminate the pre-release window at any time by written notice to CISA or to any covered agency participating in the program. Early termination shall be effective upon transmission of such notice.
(5) NO GOVERNMENT EXTENSION.— No Federal agency may extend, request extension of, require extension of, or treat as extended a pre-release window. An AI developer may voluntarily elect a new window or an additional window, but refusal to elect a new or additional window shall have no legal, regulatory, procurement, grant, or enforcement consequence.
(6) NO EFFECT OF PENDING REVIEW.— Pending agency review, pending interagency coordination, pending classification review, pending technical testing, pending feedback, pending trusted partner recommendations, or pending vulnerability analysis shall have no effect on the expiration or termination of the pre-release window.
(f) Trusted Partner Facilitation Window.—
(1) COMMENCEMENT.— The trusted partner facilitation window shall begin automatically upon the expiration or termination of the pre-release window unless the AI developer states in writing that it does not elect to receive trusted partner facilitation.
(2) DURATION.— The trusted partner facilitation window shall last for 30 calendar days unless the AI developer elects a shorter period or terminates the window earlier under paragraph (4).
(3) AUTOMATIC EXPIRATION.— The trusted partner facilitation window shall expire automatically at 11:59 p.m. eastern time on the 30th calendar day after the window begins, or at the end of any shorter period elected by the AI developer. Expiration shall not require acknowledgement, concurrence, certification, approval, non-objection, or any other action by a Federal agency.
(4) EARLY TERMINATION.— An AI developer may terminate the trusted partner facilitation window at any time by written notice to CISA or to any covered agency participating in the program. Early termination shall be effective upon transmission of such notice.
(5) NO GOVERNMENT EXTENSION.— No Federal agency may extend, request extension of, require extension of, or treat as extended a trusted partner facilitation window. An AI developer may voluntarily elect a new window or an additional window, but refusal to elect a new or additional window shall have no legal, regulatory, procurement, grant, enforcement, or reputational consequence.
(6) NO RELEASE OR ACCESS RESTRICTION.— Nothing in this subsection shall prohibit, delay, restrict, condition, or otherwise limit an AI developer from releasing, publishing, deploying, distributing, or providing access to a covered frontier model to any trusted partner or to the public at any time.
(7) FEDERAL ROLE DURING WINDOW.— During the trusted partner facilitation window, covered agencies may, at the request of the AI developer, provide nonbinding advice or facilitation concerning trusted partner access, including by—
(A) identifying categories of trusted partners that may support secure innovation or critical infrastructure cybersecurity;
(B) identifying Federal, State, local, Tribal, territorial, allied foreign governmental, critical infrastructure, research, commercial, nonprofit, or other partners that may benefit from early or staged access;
(C) facilitating introductions between the AI developer and potential trusted partners;
(D) providing nonbinding cybersecurity considerations for staged access;
(E) coordinating vulnerability remediation or defensive mitigation information with trusted partners selected by the AI developer; and
(F) assisting with logistics for secure information exchange, provided that such assistance does not condition, delay, restrict, or control access.
(8) SOLE SELECTION BY DEVELOPER.— The AI developer shall have sole authority to select, sequence, approve, deny, modify, condition, suspend, or terminate trusted partner access to a covered frontier model.
(9) NO VETO OR APPROVAL POWER.— No Federal agency may approve, disapprove, require, prohibit, rank, condition, negotiate, or veto the inclusion, exclusion, timing, sequencing, terms, or scope of access of any trusted partner.
(10) END OF FEDERAL PARTICIPATION.— Upon expiration or termination of the trusted partner facilitation window, no Federal agency may participate under this section in the selection, sequencing, authorization, negotiation, or approval of trusted partner access for the applicable covered frontier model.
(11) NO EFFECT ON SEPARATE VOLUNTARY RELATIONSHIPS.— Paragraph (10) shall not prohibit an AI developer from voluntarily entering into a separate written agreement with a Federal agency after the trusted partner facilitation window, provided that such agreement expressly states that the Federal agency has no authority to delay, approve, disapprove, condition, or control release, publication, deployment, distribution, or trusted partner access.
(g) Confidentiality Of Submissions And Program Participation.—
(1) CONFIDENTIAL UPON TRANSMISSION.— A notice submitted under subsection (d), and all protected voluntary AI cybersecurity information associated with such notice, shall be confidential from the moment of transmission, including before any Federal agency acknowledges receipt.
(2) FOIA PROTECTION.— Protected voluntary AI cybersecurity information shall be exempt from disclosure under section 552 of title 5, United States Code, and shall be withheld under subsection (b)(3) of that section.
(3) TRADE SECRET AND COMMERCIAL INFORMATION PROTECTION.— Protected voluntary AI cybersecurity information shall be treated as confidential commercial, financial, technical, cybersecurity, proprietary, and trade secret information of the submitting AI developer.
(4) PROHIBITION ON PUBLIC DISCLOSURE.— No officer, employee, contractor, detailee, assignee, or agent of the United States may publicly disclose—
(A) the existence or contents of a notice submitted under this section;
(B) the identity of an AI developer participating in the program;
(C) the identity, name, code name, version, capabilities, limitations, release plans, trusted partner plans, or deployment plans of a covered frontier model;
(D) any model access information, evaluation result, vulnerability information, cybersecurity finding, red-team result, prompt, output, technical artifact, or communication generated under the program; or
(E) any other protected voluntary AI cybersecurity information.
(5) LIMITED INTERNAL DISCLOSURE.— Protected voluntary AI cybersecurity information may be disclosed within the Federal Government only to covered agency personnel who—
(A) have a need to know the information for a purpose authorized under this section;
(B) are identified on an access list maintained for the relevant covered frontier model;
(C) are bound by written confidentiality, use, cybersecurity, insider-risk, intellectual-property, and nondisclosure obligations at least as protective as the obligations in this section; and
(D) comply with any access-control, monitoring, logging, retention, destruction, or other security requirements specified by the AI developer.
(6) NO USE FOR REGULATORY OR ENFORCEMENT PURPOSES.— Protected voluntary AI cybersecurity information may not be used by any Federal agency for regulatory, enforcement, procurement-exclusion, suspension, debarment, licensing, permitting, market-access, competition, or adverse administrative purposes, except—
(A) with the express written consent of the AI developer; or
(B) to investigate or prosecute unauthorized access to, theft of, or unlawful disclosure of protected voluntary AI cybersecurity information.
(7) INDEPENDENTLY OBTAINED INFORMATION.— Paragraph (6) shall not restrict the use of information lawfully obtained by a Federal agency from a source wholly independent of the program established under this section.
(8) NO WAIVER.— Submission of protected voluntary AI cybersecurity information under this section shall not constitute waiver of any trade secret protection, attorney-client privilege, attorney work product protection, cybersecurity information protection, contractual confidentiality right, intellectual-property right, or other privilege or protection.
(9) SURVIVAL.— The confidentiality, use, cybersecurity, insider-risk, intellectual-property, and nondisclosure requirements of this subsection shall survive the expiration or termination of the pre-release window, the trusted partner facilitation window, and any participation in the program.
(h) Access, Testing, And Use Restrictions.—
(1) DEVELOPER-CONTROLLED ACCESS.— Access to a covered frontier model under this section shall occur through an access method selected by the AI developer. Such access may be revoked, modified, suspended, monitored, rate-limited, or terminated by the AI developer at any time.
(2) AUTHORIZED PURPOSES.— Covered agencies may use access provided under this section only to—
(A) assess cyber-defense, cyber-offense, vulnerability discovery, vulnerability validation, and related national security considerations;
(B) identify potential cybersecurity risks associated with deployment;
(C) prepare nonbinding technical feedback for the AI developer;
(D) support vulnerability remediation, patch prioritization, or defensive mitigation planning;
(E) prepare nonbinding trusted partner facilitation advice; and
(F) facilitate secure innovation and strengthen cybersecurity for systems or entities selected by the AI developer.
(3) PROHIBITED USES.— Covered agencies may not—
(A) copy, retain, transfer, reproduce, reverse engineer, fine-tune, distill, train another model on, or otherwise appropriate any covered frontier model, model output, model behavior, model access, or protected voluntary AI cybersecurity information except as expressly authorized in writing by the AI developer;
(B) use a covered frontier model for operational, intelligence, military, law-enforcement, regulatory, commercial, or procurement purposes unrelated to the evaluation or facilitation authorized by this section;
(C) attempt to extract model weights, source code, training data, fine-tuning data, system prompts, architecture details, proprietary datasets, customer data, user data, trade secrets, or other proprietary information;
(D) share access credentials or protected voluntary AI cybersecurity information with any person not authorized under this section;
(E) impose evaluation methods that require disclosure of proprietary information not voluntarily provided by the AI developer;
(F) condition any Federal benefit, procurement opportunity, grant, clearance, contract, authorization, or other governmental action on participation in, continuation of, or extension of the program; or
(G) use participation or nonparticipation in the program as evidence of legal compliance, noncompliance, negligence, recklessness, culpability, suitability, responsibility, or fitness for procurement.
(4) SECURITY REQUIREMENTS.— Covered agencies shall comply with all reasonable cybersecurity, insider-risk, access-control, logging, storage, retention, destruction, and nondisclosure requirements specified by the AI developer as a condition of access.
(i) Agency Obligations During The Pre-Release Window.—
(1) ACKNOWLEDGMENT.— Not later than 24 hours after receiving a notice under subsection (d), CISA or the covered agency receiving the notice shall provide a ministerial acknowledgment of receipt to the AI developer and transmit the notice to any covered agencies identified by the AI developer or otherwise authorized under this section. Failure to provide such acknowledgment shall not affect the beginning, running, expiration, or termination of the pre-release window.
(2) ACCESS LIST.— Not later than 48 hours after the pre-release window begins, each covered agency receiving access shall provide the AI developer with a list of personnel authorized to access protected voluntary AI cybersecurity information. The AI developer may deny or revoke access for any person not included on such list.
(3) QUESTIONS AND REQUESTS.— Any question, request for clarification, request for additional access, or request for additional information from a covered agency shall be submitted to the AI developer in writing during the pre-release window. The AI developer may respond, decline to respond, or provide partial information in the sole discretion of the AI developer.
(4) INITIAL CYBERSECURITY FEEDBACK.— If a covered agency identifies a material cybersecurity vulnerability, deployment risk, misuse risk, or defensive mitigation relevant to the covered frontier model, the agency shall provide written notice to the AI developer as soon as practicable during the pre-release window.
(5) FINAL NONBINDING FEEDBACK.— Not later than the expiration of the pre-release window, covered agencies may provide consolidated, written, nonbinding technical feedback to the AI developer. Failure to provide such feedback before expiration shall be deemed no comment by the Federal Government.
(6) NO SLOW-WALKING.— No Federal agency may delay, suspend, toll, extend, or condition the pre-release window by failing to act, by requesting additional information, by failing to complete testing, by withholding feedback, by seeking interagency clearance, by requiring escalation, by asserting classification review, or by taking any other action or inaction.
(j) Agency Obligations During The Trusted Partner Facilitation Window.—
(1) REQUEST-BASED FACILITATION.— During the trusted partner facilitation window, covered agencies may provide trusted partner facilitation only to the extent requested by the AI developer.
(2) WRITTEN COMMUNICATIONS.— Any recommendation, introduction, facilitation request, cybersecurity consideration, vulnerability remediation proposal, or related communication by a covered agency during the trusted partner facilitation window shall be nonbinding and, unless impracticable, provided in writing.
(3) RESPONSE BY DEVELOPER.— The AI developer may accept, reject, modify, ignore, or decline to respond to any Federal recommendation, introduction, facilitation request, cybersecurity consideration, vulnerability remediation proposal, or related communication in the sole discretion of the AI developer.
(4) NO DELAY OR CONDITION.— No Federal agency may delay, suspend, toll, extend, or condition the trusted partner facilitation window, or any trusted partner access, by failing to act, by requesting additional information, by withholding recommendations, by seeking interagency clearance, by requiring escalation, by asserting classification review, or by taking any other action or inaction.
(5) FINAL SUMMARY.— Not later than the expiration of the trusted partner facilitation window, covered agencies may provide the AI developer with a final written summary of nonbinding trusted partner facilitation activities. Failure to provide such summary before expiration shall be deemed no further comment by the Federal Government.
(k) Prohibited Governmental Actions.—
No Federal agency, officer, employee, contractor, detailee, assignee, or agent may—
(1) require an AI developer to participate in the program;
(2) require an AI developer to submit a notice under this section;
(3) require an AI developer to designate any model as a covered frontier model;
(4) establish a mandatory benchmark, threshold, capability test, evaluation, classification, designation, or determination for covered frontier models;
(5) require an AI developer to delay release, publication, deployment, distribution, or trusted partner access;
(6) condition release, publication, deployment, distribution, or trusted partner access on Federal review, approval, certification, licensing, permitting, concurrence, or non-objection;
(7) condition any Federal contract, grant, cooperative agreement, procurement preference, security clearance, authorization to operate, export authorization, or other Federal benefit on participation in the program, nonparticipation in the program, continuation of participation, extension of the pre-release window, or extension of the trusted partner facilitation window;
(8) treat participation in the program as evidence that a model is dangerous, unsafe, restricted, controlled, defective, noncompliant, or unsuitable for release;
(9) treat nonparticipation in the program as evidence that an AI developer is negligent, reckless, noncompliant, unsuitable, irresponsible, or untrustworthy;
(10) disclose protected voluntary AI cybersecurity information except as authorized by this section;
(11) use protected voluntary AI cybersecurity information to train, fine-tune, evaluate, improve, benchmark, or commercialize a Federal or third-party AI model except with express written consent of the AI developer; or
(12) take any action that has the purpose or effect of converting the voluntary program established under this section into a mandatory licensing, preclearance, permitting, certification, market-access, benchmarking, threshold, designation, trusted partner approval, or release-approval regime.
(l) Standard Terms And Failure To Issue Guidance.—
(1) STANDARD TERMS.— Not later than 60 days after the date of enactment of this Act, CISA, in consultation with the covered agencies described in subsection (b), may publish standard voluntary program terms consistent with this section.
(2) LIMITATION.— Standard terms issued under paragraph (1) may not impose any obligation, restriction, condition, waiver, certification, approval requirement, indemnity, intellectual-property license, data-use right, confidentiality exception, release delay, trusted partner condition, or government discretion inconsistent with this section.
(3) FAILURE TO ISSUE.— If CISA does not publish standard terms by the deadline described in paragraph (1), the terms of this section shall govern participation, and an AI developer may participate by submitting the notice described in subsection (d).
(4) CONFLICT.— In the event of a conflict between standard terms issued under paragraph (1) and this section, this section shall control.
(m) Annual Report To Congress.—
(1) REPORT REQUIRED.— Not later than 1 year after the date of enactment of this Act, and annually thereafter for 5 years, CISA, in coordination with the covered agencies described in subsection (b), shall submit to the appropriate congressional committees a report on the program established under this section.
(2) CONTENTS.— Each report shall include, in aggregate and anonymized form only—
(A) the number of AI developers that participated in the program;
(B) the number of covered frontier models for which notices were submitted;
(C) the average length of pre-release windows elected by AI developers;
(D) the average length of trusted partner facilitation windows elected by AI developers;
(E) quantitative and qualitative descriptions of the governmental use of pre-release access to covered frontier models;
(F) the number and general category of nonbinding technical feedback reports provided;
(G) the number and general category of trusted partner facilitation requests received;
(H) any recommendations for improving confidentiality, cybersecurity, insider-risk protections, intellectual-property protection, and voluntary collaboration; and
(H) any recommendations for legislation.
(3) PROTECTION OF INFORMATION.— A report under this subsection may not identify any AI developer, covered frontier model, model capability, vulnerability, release plan, trusted partner, protected voluntary AI cybersecurity information, or other confidential information.
(4) CLASSIFIED ANNEX.— A report under this subsection may include a classified annex, provided that the classified annex shall not disclose protected voluntary AI cybersecurity information except in aggregate and anonymized form or with the express written consent of the AI developer.
(n) No Mandatory Licensing, Preclearance, Or Permitting.—
Nothing in this section, or in any other provision of this Act, shall be construed to authorize the creation or implementation of a mandatory governmental licensing, preclearance, certification, designation, benchmarking, threshold, permitting, approval, non-objection, or market-access requirement for the development, training, modification, testing, publication, release, deployment, distribution, or use of any AI model, including any frontier model.
SEC. 5. RULES OF CONSTRUCTION.
(a) Existing Authority.— Nothing in this Act shall be construed to impair or otherwise affect—
(1) the authority granted by law to an executive department or agency, or the head thereof;
(2) the functions of the Director of the Office of Management and Budget relating to budgetary, administrative, or legislative proposals;
(3) the authority of the Attorney General to investigate or prosecute violations of Federal criminal law;
(4) the authority of the Secretary of Homeland Security, acting through the Director of CISA, to protect Federal information systems and support critical infrastructure cybersecurity;
(5) the authority of the Secretary of Defense, the Director of NSA, or any element of the intelligence community to carry out lawful national security, intelligence, cybersecurity, or military functions; or
(6) the authority of any Federal agency to protect classified information, controlled unclassified information, Federal information systems, national security systems, or critical infrastructure, consistent with applicable law.
(b) No Mandatory AI Model Approval Regime.— Nothing in this Act shall be construed to authorize any Federal agency to establish, directly or indirectly, a mandatory governmental licensing, preclearance, certification, designation, benchmarking, threshold, permitting, approval, non-objection, or market-access requirement for the development, training, modification, testing, publication, release, deployment, distribution, or use of any AI model.
(c) No Delay Authority.— Nothing in this Act shall be construed to authorize any Federal agency to delay, suspend, toll, extend, condition, or prohibit the release, publication, deployment, distribution, or use of any AI model.
(d) No Required Disclosure Of Proprietary Information.— Nothing in this Act shall be construed to require an AI developer to disclose model weights, source code, training data, fine-tuning data, system prompts, architecture details, proprietary datasets, customer data, user data, trade secrets, or other proprietary information.
(e) No Government Selection Of Trusted Partners.— Nothing in this Act shall be construed to authorize any Federal agency to select, approve, disapprove, rank, condition, negotiate, or veto trusted partner access to any AI model.
(f) No Effect On Voluntary Private Action.— Nothing in this Act shall be construed to prohibit an AI developer from voluntarily adopting security practices, red-team testing, staged deployment, trusted partner access, vulnerability disclosure, model evaluations, or other measures selected by the AI developer.
(g) No Private Right Of Action.— Except for any remedy otherwise available under section 552 of title 5, United States Code, or any other applicable law to prevent or remedy unlawful disclosure of protected information, nothing in this Act shall be construed to create a private right of action against the United States, any department, agency, or entity of the United States, any officer, employee, contractor, detailee, assignee, or agent of the United States, or any other person.
(h) Availability Of Appropriations.— This Act shall be implemented consistent with applicable law and subject to the availability of appropriations.
SEC. 6. AUTHORIZATION OF APPROPRIATIONS.
There are authorized to be appropriated such sums as may be necessary to carry out this Act.