Trump Signs AI Cybersecurity Order, Reviving the Pre-Release Review Provisions His Team Killed Two Weeks Ago
The new directive creates a voluntary framework for government review of frontier AI models and spins up a Treasury-led vulnerability clearinghouse — while going out of its way to say none of this is mandatory.

The administration signed an executive order titled "Promoting Advanced Artificial Intelligence Innovation and Security" this week, resurrecting most of the cybersecurity provisions from a broader AI initiative that Trump canceled on May 21 after internal complaints that it could hurt US competitiveness against China. Same provisions, softer framing.
In practice, the order does three distinct things.
First, it pushes AI-enabled defensive tooling into federal networks. CISA gets directed to issue guidance accelerating adoption of AI-based defensive technologies across civilian agencies. The Committee on National Security Systems and the Department of Defense each receive 30-day deadlines to prioritize hardening their respective environments. That part is uncontroversial — CISA has been pushing AI-augmented threat detection for a while, and this gives it cleaner authority to move.
Second, the order creates an AI cybersecurity clearinghouse housed at Treasury, built in consultation with NSA and CISA. The mandate covers coordinating vulnerability scanning, validating discovered flaws, deconflicting redundant discovery efforts, and pushing patches. The failure mode here is the same one that plagued earlier information-sharing programs: voluntary participation produces voluntary data, which means the organizations that most need visibility opt out. Community banks and rural hospitals get a specific callout in the order as intended beneficiaries. Whether a Treasury-led clearinghouse actually reaches a 40-bed regional hospital's IT team is a different question.
Third — and this is the piece that got the previous draft killed — the order establishes a process for evaluating the cyber capabilities of "frontier AI models." NSA leads that evaluation, with CISA, Treasury, and NIST involved. Within 60 days, those agencies must produce classified benchmarking criteria defining what makes a system a "covered frontier model." The classification of those criteria is doing a lot of work here; developers won't know exactly where the threshold sits.
The voluntary pre-release access window landed at 30 days. Earlier drafts reportedly proposed 90 days; industry pushed for 14. Thirty is the compromise. Developers who opt in can give the government early access before models reach trusted partners, and both sides collaborate on which organizations get that early-access tier for security research purposes.
One thing the post-mortem on the canceled May 21 order will say is that the word "voluntary" wasn't in enough places. This version uses it constantly. The order explicitly prohibits mandatory licensing, preclearance, or permitting requirements. That language is pointed directly at the AI companies that lobbied hardest against the earlier draft.
The broader Biden-era AI governance apparatus — the safety reporting requirements, the red-teaming mandates, the NIST framework integrations — stays dismantled. This order is narrowly scoped to cybersecurity and national security. Whether NSA's classified benchmarks eventually create de facto mandatory review by making non-participation a reputational or procurement liability is the more interesting long-term question.
Get your pre-release access windows documented and your vulnerability-disclosure workflows mapped to this clearinghouse structure before the 60-day clock runs out.



