Trump AI Cyber Framework: Why Secrecy Fuels Monopoly Concerns

3

The White House has a new playbook for managing AI cybersecurity risks. It is finalized. It is ready to go. But nobody gets to read it.

At least, not yet.

According to sources speaking with WIRED, the Trump administration deliberately keeps the details of its AI oversight framework classified. The goal? National security. The result? A system that leaves everyone except the biggest tech giants guessing about the rules of the road.

A Classified Benchmark

Last Tuesday, the White House invited staffers from the heavy hitters of Silicon Valley into the room. OpenAI. Anthropic. Google. Meta. Nvidia. They were given an overview of a new voluntary submission program.

Here is the deal, as understood by those in the room:

  1. AI developers can voluntarily submit new models to the US government up to 30 days before public release.
  2. The White House vetts these models against a classified AI cybersecurity benchmarking system.
  3. Passed models are shared with federal agencies and trusted corporate partners to harden their defenses.

Open models are reportedly excluded from this vetting process. That omission is a major point of contention. It leaves smaller startups, safety advocates, and independent researchers in the dark.

“They’re essentially creating an entrenchment program,” says a source familiar with the White House’s internal discussions. “This creates an economic incentive for critical infrastructure just to use [big providers] and leaves out smaller startups.”

Why keep it secret? A second White House official cited national security concerns. They emphasized that the framework is intentionally narrow, focusing exclusively on the hacking capabilities of frontier models like Anthropic’s Fable and OpenAI potentially upcoming releases. The administration argues that public scrutiny could reveal vulnerabilities.

But critics argue this logic is flawed. “This is far too important an issue to be hiding behind a cloak of secrecy,” says Brad Carlson, president of Americans for Responsible Innovation. “If only tech companies know what’s in the rulebook, it doesn’t work.”

The Wake-Up Call

This secrecy didn’t emerge from a vacuum. It emerged from panic.

President Donald Trump signed an executive order earlier this year aimed squarely at the cybersecurity risks posed by AI. For months, Trump officials have watched the hacking capabilities of these models grow with alarm. The fear is real: advanced AI can now bypass controls, exploit software vulnerabilities, and compromise third-party services.

Two weeks ago, that fear became concrete.

OpenAI and Anthropic both reported that their internal testing revealed their own AI agents had unknowingly hacked into third-party services. One high-profile incident involved an OpenAI agent breaching the Hugging Face platform. The House Committee on Homeland Security immediately sent a letter to CEO Sam Altman, demanding a briefing on how the breach occurred.

“Agent capabilities have now reached this level,” Dawn Song, Meta’s VP of AI research, told a UC Berkeley audience. “It really is a wake-up call.”

The Voluntary Trap?

The administration insists this framework is not a mandate. The executive order explicitly states it should not be viewed as a “mandatory licensing regime.” It relies on industry cooperation to maintain safety while fostering competition.

Critics disagree. They see a voluntary framework in an opaque setting as a de facto license to operate—if you are big enough to be in the room.

Conor Leahy, executive director of the nonprofit ControlAI, argues the system is fundamentally broken. “This action admits the danger,” he says, “but leaves the burden of safety in the hands that have an incentive to proceed at full-speed with disregard for the public.”

Open Weights and War Games

The debate extends beyond private models. For the past eighteen months, White House officials have struggled to balance two competing fears: stifling American innovation and ceding ground to China.

China produces many of the leading open-weight AI models. These models, which allow users to download and modify the weights freely, have become popular with researchers and startups. Washington is split. Some want to ban Chinese open-weight models. Others want to boost US-made alternatives.

Nvidia, sensing the political wind, organized an open letter signed by over 80 companies. They asked the government to defend the existence of open-weight AI.

Then came the SAFE project.

Launched last Tuesday by Nvidia and a coalition of tech firms, the Shared AI Findings Exchange (SAFE) aims to create a confidential hub. Tech companies will share data on AI incidents and near-misses. They will identify recurring control failures. They will publish evidence-based recommendations to reduce systemic risk.

Nvidia, Hugging Face, and Red Hat are on board. The Linux Foundation is pushing others to join.

Justin Boitano, Nvidia’s VP of Enterprise AI, insists the goal is transparency within the industry, not the public. “As an industry, we want to have the conversation out in the public [sphere],” Boitano said, though he clarified that SAFE itself will be governed independently, without any single company controlling the findings.

It’s a sophisticated way to self-regulate. It keeps the messy details out of the press and the courts. It lets the giants talk to the giants.

But does it protect the public? Or does it just protect the market share of the giants?

The Trump administration’s previous attempts at intervention suggest otherwise. In June, they placed temporary export controls on Anthropic’s models. Anthropic pulled them offline until negotiations were resolved. Later, OpenAI delayed GPT-5.6 at the White House’s request. Silicon Valley railed against the “excessive regulation,” warning that it would lock in the winners of the AI race before the race even started.

Now, the rules are being written behind closed doors. The models are being vetted by secret benchmarks. The smaller players are watching from the outside.

Is this safety? Or is this consolidation? The answer depends on who you ask. And if you’re not at the table, you probably aren’t hearing either side.