August 17, 2026 — The US Administration plans to expand its voluntary pre-release cybersecurity testing system to include open artificial intelligences. According to reports emerging at the end of last week, the White House intends to include open-source models in the testing program once they reach the capability level of advanced closed systems.
A new regulatory milestone: from closed systems to open weights
As reported by Wired, citing sources familiar with the discussions and administration representatives, the program expansion will be a response to the evolution of the AI market. Currently, the existing scheme applies exclusively to closed models developed by American companies. However, with the growing power of open models (open weights), regulators have recognized the need to change their approach. According to the plan, open models must be included in the system as soon as they reach the same "advanced level" currently attributed to the most powerful systems, including models in the class of Anthropic Mythos and OpenAI GPT-5.6.
The essence of the proposed mechanism remains the same: voluntary transfer of the model to the government for up to 30 days prior to public release. During this time, specialists will evaluate the AI's advanced cyber capabilities using a classified benchmark system. It is important to note that the directive explicitly prohibits interpreting this procedure as mandatory licensing or a permission regime for the development, publication, or distribution of models. Nevertheless, for the industry, this becomes a de facto security standard for "heavy" AI.
Why do open models require special attention?
For open models, pre-release verification has a fundamentally different significance than for proprietary systems. After publication, their weights can be downloaded, modified, and run independently of the original developer. This creates a unique dilemma: while a closed model can be turned off or updated centrally, an open model quickly escapes the author's control once published.
Therefore, evaluating such systems before distribution is significantly more important than trying to restrict them after release. The White House sees this as a way to close a significant gap in national security. The current system allows access to the model before its release, whereas an open model, once publicly available, could be used by malicious actors for cyberattacks if vulnerabilities were not identified during the testing phase.
Technical nuances and limitations of verification
Experts emphasize that passing federal verification itself does not replace testing of a specific deployment. Risks also depend on network permissions, agent tools, data access, and other infrastructure settings. Even a safe model can become dangerous in the hands of an inexperienced administrator or with incorrect server configuration.
Nevertheless, having a "seal of approval" from federal agencies will become an important marker for corporate clients and government customers. This will create a two-tier trust system: models that have passed verification will be considered safe for critical infrastructure, while unverified systems may face restrictions when implemented in the public sector.
Contradictory data
At present, there are discrepancies in understanding the timing and mandatory nature of the new measures. On the one hand, administration representatives state that this is a planned expansion, not an introduced requirement. Wired reports that changes are expected in the coming months, however, the updated framework text, public thresholds, list of corresponding models, and the official announcement of the procedure launch for open systems have not yet been published.
On the other hand, some market analysts believe that even the voluntary nature of the verification could become a de facto barrier to market entry. If major players (such as Meta or Mistral) begin to voluntarily undergo verification to confirm the safety of their models, this could create pressure on smaller developers who cannot afford a 30-day release delay or do not wish to disclose architectural details. For now, it cannot be considered that manufacturers of such models are already obligated to undergo verification before release, but the de facto standard may form faster than the official document is adopted.