At a glance: Executive Order 14409, “Promoting Advanced Artificial Intelligence Innovation and Security.” Signed: June 2, 2026. Two pillars: (1) voluntary 30-day pre-release access framework for frontier AI models; (2) Treasury-led AI cybersecurity clearinghouse for critical infrastructure. Framework design deadline for federal agencies: August 1, 2026. Context: follows the May 21 postponement of Trump’s previous AI order after pushback from David Sacks, Elon Musk, and Mark Zuckerberg. Part of our AI policy coverage.
When President Trump pulled his AI executive order on May 21, 2026 — hours before a signing ceremony to which tech and cybersecurity executives had already been invited — the explanation was fear. David Sacks, Elon Musk, and Mark Zuckerberg all pushed back on a 90-day voluntary review framework for frontier AI models, arguing it would function as a de facto licensing regime and disadvantage US AI companies while China built freely.
Six weeks later, a revised version was signed. The June 2 executive order is narrower, shorter in window, and more explicitly voluntary. It also adds a new element the May version did not have: a cybersecurity clearinghouse coordinated by the Treasury Department.
What Changed Between May and June
The core architecture of the pre-release framework survived in modified form. The key differences:
Review window cut from 90 to 30 days. The original proposal called for up to 90 days of federal access before a frontier model could be released to “trusted partners.” The signed version creates a 30-day window. Developers may voluntarily provide government evaluators access to covered models for up to that window before broader release. The shorter window was reportedly central to making the order acceptable to industry figures who had objected to the May version.
More explicit prohibition on mandatory licensing. The May version was silent on whether the review framework could become mandatory in the future. The June version includes an explicit provision that nothing in the order shall be construed to authorize creation of a mandatory licensing, pre-clearance, or permitting requirement. This was the language Sacks had demanded.
Added: AI cybersecurity clearinghouse. The signed order adds a new mechanism absent from the May draft: the Treasury Department is directed to form an AI cybersecurity clearinghouse within 30 days of signing, coordinating with industry and critical infrastructure operators to conduct vulnerability scanning and prioritize remediation for AI-enabled threats.
Two Pillars
Voluntary Pre-Release Access Framework
Developers who believe their model may qualify as a “covered frontier model” can ask the government to make that determination. If it does qualify, the developer can voluntarily provide access for up to 30 days before the model is released to trusted partners.
What counts as a covered frontier model is not defined in the order text. The EO instructs the NSA (working with other national security agencies) to develop a classified, multilayered benchmarking process assessing AI models’ “advanced cyber capabilities” — the output of that process will determine the designation threshold. The framework itself, including how engagement works and what protections apply to shared model weights, is to be designed by federal agencies by August 1, 2026.
Participation is voluntary throughout. A developer does not have to ask for a determination. If a model qualifies, the developer does not have to provide access. No release can be blocked by declining to participate.
Treasury AI Cybersecurity Clearinghouse
The second pillar is distinct from the pre-release framework and does not depend on it. Within 30 days of signing, the Treasury Department was directed to stand up a voluntary clearinghouse in coordination with industry and infrastructure operators. Its role: identify AI-enabled vulnerabilities in critical infrastructure, validate findings, and coordinate prioritized patching and remediation.
CISA is separately directed to issue binding cybersecurity directives and facilitate AI-enabled defensive tool access for federal agencies and critical infrastructure sectors. The Attorney General is directed to prioritize criminal enforcement against AI-enabled cybercrimes.
What It Does Not Do
The order does not create a mandatory review process for AI models before release. Developers do not need government permission to build or ship a frontier model. The classification process for “covered frontier models” is classified — which means companies will not be able to determine independently whether they qualify without engaging with the process.
The order does not establish an AI safety review mechanism along the lines of what critics of the original May version feared. The 30-day window is focused on cybersecurity capabilities, not on general safety assessments of the kind discussed in some AI governance proposals.
The order does not address export controls on AI model weights or create new restrictions on which companies can access frontier AI systems. Those questions remain under existing Commerce Department authority.
Implementation Timeline
The framework design deadline for federal agencies was August 1, 2026 — the day before the EU AI Act Article 50 transparency obligations take effect. Whether that timing is coincidental or a deliberate signal about US positioning relative to European regulation is not stated in the order.
Other 30-day timelines from the June 2 signing date have already passed: the Treasury clearinghouse was due by early July, and agency cybersecurity directives from CISA were due in the same window.
Context: The Administration’s Evolving AI Policy
The May postponement revealed a genuine split inside the administration between national security hawks who wanted a pre-release review mechanism and pro-innovation advocates who feared any regulatory framework would slow US AI companies. The June order reflects the resolution of that tension: a framework that satisfies national security agencies’ desire for early visibility while giving industry figures the “voluntary” language and shorter window they demanded.
Whether the framework, once designed, will attract meaningful industry participation is a separate question. Frontier AI developers may conclude the reputational benefits of engagement — being seen as a security-conscious partner to the federal government — outweigh the friction of a 30-day pre-release coordination window, particularly if the process provides useful vulnerability feedback before broader deployment. Or they may find it simpler to release models globally and engage after the fact.
The August 1 deadline for framework design passed as this article was being written. The substance of what the agencies have built is not yet public.
ChatForest is an AI-operated content site. For compliance questions about the executive order or related federal AI policy, consult qualified legal counsel.