Written and maintained by CASRAI Editorial Board
Last updated
There is now a third Trump administration executive order on artificial intelligence, and it is structurally different from the first two. Executive Order 14409, “Promoting Advanced Artificial Intelligence Innovation and Security,” signed 2 June 2026 and published at 91 FR 34565 on 5 June 2026, does not treat frontier AI models primarily as a thing to be regulated, deregulated, or shielded from state law. It treats them as cyber defence infrastructure the federal government wants to deploy on its own networks — and, in a single sixty-day tasking buried in Section 3, it creates a classified government benchmarking process for a new statutory-style category called “covered frontier models.” This guide walks through what the order actually directs, which deadlines attach to which agencies, and why the classified-benchmarking provision sits awkwardly beside every transparency mechanism the rest of this cluster documents.
Where EO 14409 Sits Among the Trump AI Orders
The two orders covered in our explainer on Trump’s AI executive orders, EO 14179 and EO 14365 are both, in different ways, about clearing away constraints. EO 14179 (January 2025) revoked Biden’s EO 14110 in full, taking the Defense Production Act reporting requirement for large foundation model training runs with it. EO 14365 (December 2025) pointed outward at state legislatures, standing up an AI Litigation Task Force and directing preemption strategy against state AI disclosure rules.
EO 14409 does something else. Its Section 1 restates the familiar policy frame — American leadership through industry innovation and minimal regulation, “working collaboratively with the private sector” — but the operative sections are procurement, deployment, and hiring directives aimed at the executive branch itself, plus one frontier-model assessment regime. Read the three orders together and the sequence is: remove the reporting requirement (14179), block the states from reimposing one (14365), then build a government evaluation capability that is voluntary on the developer side and classified on the government side (14409).
The Section 2 Taskings: Deadlines and Owners
Section 2, “Upgrading American Systems for Advanced AI,” is a list of dated instructions. Five land at thirty days and one at sixty:
| Deadline | Who | What the order directs |
|---|---|---|
| 30 days | Committee on National Security Systems | Prioritise cyber defence of National Security Systems, citing the CNSS authority at 44 U.S.C. 3552(b)(6)(A) |
| 30 days | Secretary of War | Prioritise cyber defence of Department of War information systems |
| 30 days | Secretary of Homeland Security / CISA | Issue directives to expedite civilian federal cybersecurity, establish AI-enabled defensive programs, and facilitate “access to cybersecurity tools and services including, where appropriate, covered frontier models” |
| 30 days | Secretary of the Treasury | Form an AI cybersecurity clearinghouse coordinating vulnerability scanning, discovery, validation and patch distribution with industry and critical infrastructure operators |
| 30 days | Director of OMB | Determine whether federal grant funding may support development of advanced AI vulnerability detection |
| 60 days | Office of Personnel Management | Expand United States Tech Force Information Cybersecurity Specialist hiring pathways |
Two of these are worth pausing on. The CISA directive in Section 2(c) is the first place in federal AI policy where a frontier model is named as a tool the government wants access to rather than a risk surface it wants documented; it is a natural complement to the operational-technology work described in our guide to what CISA’s OT guidance on AI in the power grid actually says, which addresses the same agency approaching AI from the defensive side. And the Treasury clearinghouse in Section 2(d) is a vulnerability-coordination body, not an incident-reporting body — it handles scanning, discovery, validation and patching, which is a different function from the safety-incident channels documented elsewhere in this cluster.
“Covered Frontier Models” and the Classified Benchmark
Section 3, “Secure Frontier Model Deployment,” is the part that belongs to frontier AI safety rather than to federal IT modernisation. Within sixty days, designated agencies — Treasury, War, and Homeland Security — are to develop a classified process for assessing AI models’ cyber capabilities and determining when a model qualifies as a “covered frontier model.” The designation itself is made by the Director of the National Security Agency, in consultation with relevant officials.
Three things follow from that sentence that are easy to miss.
The scope test is capability-based and secret. Every other scope test catalogued in our comparison of eleven “frontier AI” scope tests is published: compute thresholds, parameter counts, capability-evaluation triggers, revenue tests. A model either crosses a stated line or it does not, and an outside reader can check the arithmetic. A classified cyber-capability benchmark administered by NSA produces a scope determination nobody outside the clearance perimeter can reproduce, contest, or audit.
The evaluating body is a signals-intelligence agency, not a standards body. The obvious institutional home for model benchmarking would have been CAISI, whose published evaluation work on open-weight and PRC-origin models we cover in CAISI’s evaluation cadence for open-weight and PRC-origin AI models. CAISI publishes its methodology and its results. EO 14409 routes the covered-frontier-model determination elsewhere.
The output is a designation, not a report. Nothing in Section 3 requires that a developer be told its model was assessed, that a result be published in any form, or that an assessed model’s designation status be disclosed to downstream deployers. The order is silent on all three.
The Voluntary Access Framework
Section 3(b) directs the same agencies to design a framework letting developers do three things, all optional: engage the government to assess whether a model meets covered-frontier-model status; provide the federal government with access to covered frontier models “for a period of up to 30 days before they plan to release such models,” subject to confidentiality, cybersecurity, insider-risk and intellectual-property protections and nondisclosure requirements; and collaborate on identifying trusted early-access partners.
Functionally, this is a pre-deployment testing arrangement. Structurally, it is the opposite of the arrangements described in our guide to how CAISI and UK AI Security Institute pre-deployment testing agreements work. Those agreements are announced; the institutes publish findings, at least in summary; the fact that testing occurred is itself public. The EO 14409 framework is built around nondisclosure by design, with a classified assessment process upstream of it. A developer could grant thirty days of pre-release access, receive a covered-frontier-model designation, and have no obligation — and possibly no permission — to say any of that happened.
The thirty-day window is also short. Thirty days before a planned release, against a classified benchmark whose criteria the developer has not seen, is not a timeline that supports iterating on findings. It supports a go/no-go signal.
The No-Licensing Disclaimer, Read Carefully
Section 3(c) says: “Nothing in this section shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models.”
This is a real and deliberate limit, and it should be read as one. It is also narrower than it first appears in two respects. First, it disclaims authorisation for a mandatory regime; it constrains how Section 3 is construed, not what other authorities permit. Second, the order pairs a voluntary framework with a Section 2(c) directive telling CISA to facilitate federal access to covered frontier models “where appropriate.” A model that has not been through the voluntary process may simply be harder to sell into federal cybersecurity procurement. That is not licensing. It is not nothing, either, and the distinction between a permit and a procurement precondition is exactly the sort of thing that gets litigated later.
Section 4 adds a separate instruction to the Attorney General to prioritise criminal enforcement against AI-enabled unauthorised computer access and data theft. Section 5 carries the standard general provisions: no impairment of existing agency authority or OMB budgetary functions, implementation subject to appropriations, no enforceable rights created, and publication costs borne by the Department of War.
Why the Classified Benchmark Is a Transparency Problem
Most of this cluster documents mechanisms built on the premise that safety claims should be inspectable by someone other than the claimant. California SB 53 requires published frontier AI frameworks. The evaluator-independence literature argues about who is structurally free to disagree with a lab. Third-party evaluator standards turn on what access an outsider actually received. A classified government evaluation regime does not contradict any of that, but it does not interoperate with it either: it produces a finding that cannot enter any of those records.
The sharpest version of the problem is comparative. If a lab’s published safety framework says its model does not cross an uplift threshold for offensive cyber capability, and a classified NSA benchmark has designated the same model a covered frontier model on cyber-capability grounds, both statements can be live simultaneously and no reader can see the conflict. The public record is not falsified. It is simply incomplete in a way that is invisible from outside.
The NIKOLAI Angle
NIKOLAI, CASRAI’s independent frontier-AI-safety dictionary, has two elements on the N8 (Transparency and Review) track that this order lands directly on. Neither is endorsed by any government or lab, and every crosswalk row in NIKOLAI is a shadow mapping — CASRAI’s own reading of a published document — unless the named organisation has filed a Mapping Declaration. No organisation has filed one covering EO 14409, and nothing below should be read as a government position.
Evaluator access attestation is NIKOLAI’s proposed record of what access an evaluator received or was denied: model versions, safeguard states, reasoning traces, weights, documents, personnel and systems, plus duration and confidentiality terms. Section 3(b) of EO 14409 describes an access arrangement with a stated duration (up to thirty days) and stated confidentiality terms, which is more than most published arrangements specify — and then places the whole thing inside a nondisclosure structure, so the attestation that the element contemplates could never be published. It is the shape of the record without the disclosure.
Redaction, on the same track, is defined around a distinction this order makes concrete: a redaction record documents that information was removed, why, and by whom, which is what separates redaction from silent omission. A classified benchmark result is not a redacted publication. There is no published document with a gap in it. Whether that counts as an omission worth marking, and what a developer subject to an NDA could even say, is an open question the element’s controlled vocabulary does not currently answer.
Research Administration Relevance
Two provisions have direct consequences for university research offices.
The Section 2(e) tasking to OMB — determine within thirty days whether federal grant funding may support development of advanced AI vulnerability detection — is an allowability question aimed squarely at sponsored programs. An affirmative determination would open a funding line for AI-assisted vulnerability discovery research; whatever guidance OMB issues will be the document a pre-award office cites when a PI proposes that work. It is worth watching for as OMB guidance rather than as an AI policy development, because that is the form it will take.
The Section 3 classified benchmarking process raises a familiar research-security problem in a new setting. University AI groups that release open-weight models are, in principle, within the conceptual scope of a cyber-capability assessment, and a classified designation is not something an academic developer can respond to, appeal, or discuss with collaborators. Institutions running model releases through export-control review already have to reason about whether a release implicates controlled technology; EO 14409 adds a federal determination process whose criteria and outputs are unavailable to the institution making the release decision. Research security offices should treat “we cannot know our own designation status” as the planning assumption.
What to Watch
The thirty-day deliverables under Section 2 fell due in early July 2026 and the sixty-day deliverables under Sections 2(f) and 3 in early August 2026. The CISA directives, the Treasury clearinghouse charter and the OMB grant-funding determination are the three that should generate public artefacts; the Section 3 benchmarking process, by construction, may not. The most informative near-term signal will be whether any frontier developer publicly confirms participation in the voluntary access framework — and whether the nondisclosure terms leave room for them to.
Sources
- Executive Order 14409, “Promoting Advanced Artificial Intelligence Innovation and Security,” signed 2 June 2026, published 91 FR 34565 (5 June 2026), Federal Register document 2026-11415. Federal Register record and full text.
This guide describes US federal executive action. It is not legal advice, and an executive order’s practical effect depends on the implementing directives agencies issue under it — several of which, in this case, may not be public.








