AI Policy Wiki
Dashboard

EO — Promoting Advanced AI Innovation and Security (Trump, signed June 2, 2026)

high confidence · updated 2026-07-20

Trump executive order on AI cybersecurity and frontier-model security, SIGNED June 2, 2026 after a May 21 postponement. Establishes AI-enabled federal cyber defense, a Treasury-led voluntary clearinghouse, a classified 'covered frontier model' benchmarking process (NSA-determined), and a voluntary 30-day government pre-release access framework (cut from 90 days in the draft) — with an explicit bar on mandatory licensing or preclearance.

TypeExecutive Order
TitlePromoting Advanced Artificial Intelligence Innovation and Security
StatusSigned June 2, 2026 (after a May 21, 2026 postponement of an earlier, stronger draft)
Issuing bodyThe White House (Trump administration)
Primary text (signed)Executive Order: Promoting Advanced Artificial Intelligence Innovation and Security (signed June 2, 2026) (whitehouse.gov)
Primary text (draft)Draft Executive Order: Promoting Advanced Artificial Intelligence Innovation and Security (unsigned, May 2026) (superseded)

President Trump signed the executive order Promoting Advanced Artificial Intelligence Innovation and Security on June 2, 2026, after postponing the signing of an earlier, stronger draft on May 21, 2026. The order seeks government visibility into advanced AI without creating an approval process: it directs AI-enabled federal cyber defense, a Treasury-led voluntary clearinghouse, a classified "covered frontier model" benchmarking process determined by the NSA, and a voluntary framework under which developers are encouraged to give the government 30 days of pre-release model access (cut from the draft's 90-day window). It explicitly bars any mandatory licensing or preclearance requirement for AI models. The signed text front-loads a pro-innovation framing: "The United States continues to lead the world in Artificial Intelligence … because we refuse to stifle this innovation with overly burdensome regulation" (Source: nextgov.com; npr.org). The signed order is read as the administration moving from an earlier hands-off stance toward limited oversight, catalyzed by the cyber-capability surge from Anthropic's Mythos and OpenAI's GPT-5.5-Cyber. The same day, Sen. Gillibrand introduced the contrasting, guardrails-first Secure and Accountable Military AI Act (Gillibrand, June 2026) (Source: nextgov.com; npr.org).

The signed EO has been ingested as a foundational primary-text source, Executive Order: Promoting Advanced Artificial Intelligence Innovation and Security (signed June 2, 2026), which supersedes the predecisional Draft Executive Order: Promoting Advanced Artificial Intelligence Innovation and Security (unsigned, May 2026). The signed-text source page carries the provision-level summary and the draft-vs-signed comparison.

History and postponement

The draft document was marked "DRAFT//PREDECISIONAL//FOR DISCUSSION PURPOSES ONLY" and dated "May XX, 2026." Drafting was reported by Axios and Politico on May 19–20, 2026. On May 21, 2026, Trump postponed signing, reportedly stating "I didn't like certain aspects of it" and citing concern it would be "a blocker on US competitiveness." Until the June 2 signing it was unresolved whether the order was shelved or merely delayed.

Subsequent reporting reconstructed the postponement. AI and crypto adviser David Sacks made a last-minute plea in a May 21 phone call with Trump, warning that the draft's voluntary government testing of AI models could become a foothold for mandatory regulation that would slow US firms against Chinese rivals — and, in his framing, hand a win to "so-called AI doomers" (Source: wsj.com). People familiar with the decision said the signing was scrapped mainly because Trump "just hates regulation," and characterized the draft as "just something doomers wanted," consistent with the public line that added oversight could be "a blocker on US competitiveness" (Source: axios.com). Industry figures questioned why the draft gave the Treasury Department — rather than CISA or NIST — a lead role in finding AI-model vulnerabilities, referring to the Section 2 clearinghouse standing up "Treasury + NSA + CISA." The Office of the National Cyber Director (ONCD) signaled it was working on separate AI security initiatives, suggesting the cyber-governance agenda might proceed outside the order (Source: axios.com). Meta and Elon Musk separately said that Mark Zuckerberg and Musk did not speak with Trump until after the signing was pulled, indicating the postponement was not the product of a Zuckerberg/Musk lobbying call (Source: axios.com).

Lawfare's May 26, 2026 piece "AI Governance by Phone Call" added primary-text and procedural detail. Trump killed the planned signing roughly three hours before an Oval Office ceremony at which OpenAI, Google, Anthropic, Meta, and Microsoft executives were expected; Sacks's morning phone call "derailed it," and Trump told reporters he "didn't like certain aspects" because the order would "get in the way" of the U.S. lead over China. Per the Lawfare account, the leaked draft would have directed CISA to issue binding cyber directives, expanded OPM cybersecurity hiring, created a Treasury-led "AI cybersecurity clearinghouse," and stood up a voluntary NSA-led classified benchmarking process for pre-release "covered frontier model" vetting, with Section 3(c) explicitly disclaiming any mandatory licensing regime. Lawfare also reported counter-pressure from the populist right: Steve Bannon and more than 60 MAGA-aligned figures had separately urged Trump days earlier to require mandatory testing of advanced models. Treasury Secretary Scott Bessent — described as having played an outsized AI-policy role since Anthropic's Mythos launch — reportedly still wanted the order signed, an internal-administration split that complicated the shelved-versus-delayed question (Source: lawfaremedia.org).

Charlie Mitchell's Inside AI Policy reporting (May 22, 2026) gathered anonymous but concordant industry-source views on the path forward. One source called the late pull "a pretty surprising development … it could be substance, it could be personalities… But if the goal is to get this out, there's a pretty easy fix, it's far enough along I think they can still move it if they want." The same reporting identified the proposed pre-release window as the operative friction point: "The postponement was around the proposed 90-day pre-release assessment window, which some in industry felt was too long and [David] Sacks reportedly raised concerns about. The way forward is to shorten the review period or leave the number of days TBD. The order would leave details to be described in a framework to be released later." A second industry source framed the episode as "a classic policy tug-of-war between those who want to regulate, even if only marginally, and those who see it necessary to let AI run loose. It appears that what was proposed for the executive order, at least in the eyes of the president, certain advisors and some in industry, leaned too close to the side of regulation." Sources also described genuine lead-agency ambiguity — "questions about who should be involved — Treasury versus CISA versus the White House, and the complexity of how it would work in practice" — and noted that "high-profile tech CEOs were unable to make the planned Oval Office signing ceremony," pointing toward a process failure as much as a substantive one. The industry framing was that the substantive disagreement was small (the 90-day window), that the order was a "positive sign" in establishing a framework, but that "one problem is there is not one clear owner of the process." The industry-side preferred resolution was a shortened-but-retained voluntary pre-release window rather than a full withdrawal of the cyber-governance framework (Source: insideaipolicy.com).

Draft-to-signed changes

The signed order is scaled back from the draft. The pre-release access window was cut from 90 to 30 days. Developers of cutting-edge models are encouraged, not required, to give the federal government — and select critical-infrastructure operators (hospitals, banks, utilities, state and local governments) — 30 days of pre-public model access, down from the draft's 90-day window that was the operative friction point in the May postponement. The order explicitly prohibits any licensing or preclearance requirement, a visibility-not-approval posture favorable to industry. The Treasury lead role for the voluntary clearinghouse, criticized in May, survived into the signed order. In the signed text, the Commerce Secretary assists "through the Director of NIST," a caveat not in the initial draft.

Key provisions

The signed order operates on a set of agency deadlines and standing programs.

  • Federal AI cyber defense (Sec. 2). Within 30 days, CNSS, the Department of War, and CISA prioritize AI-enabled cyber defense of national-security, defense, and civilian federal systems, and CISA issues Binding Operational Directives. Agencies must secure DoD/national-security networks within 30 days; a binding operational directive to secure federal civilian networks (and to facilitate frontier-model access across critical infrastructure) must issue within 30 days. Treasury, with ONCD, NSA, DHS, and CISA support, establishes a voluntary coordination clearinghouse among government, AI companies, and critical-infrastructure operators for vulnerability scanning and patch coordination. OPM expands cyber hiring.
  • "Covered frontier model" regime (Sec. 3). OSTP, NIST, CISA, and others have 60 days to stand up a classified evaluation process that sets the cyber-capability threshold for designating a model "covered"; the NSA then formally determines which systems meet the "covered frontier model" threshold. A voluntary framework lets developers give the federal government pre-release access to covered models — up to 90 days in the draft, encouraged at 30 days in the signed order — and collaborate on selecting "trusted partners" for early access.
  • No mandatory licensing (Sec. 3(c)). The order explicitly bars construing it to create "a mandatory governmental licensing, preclearance, or permitting requirement" for AI models, including frontier models.
  • Criminal enforcement (Sec. 4). The order directs DOJ to prioritize computer-crime enforcement against AI-enabled unauthorized access.

Funding and hiring

OMB has 30 days to identify grant funding for AI vulnerability-detection. OPM has 60 days to expand cyber hiring via the U.S. Tech Force, which had onboarded only about 10 of a planned 1,000 technologists as of late May 2026.

Implementation

Under the order, the administration directed the Pentagon, NSA, and other agencies to build a frontier AI security framework, including the voluntary channel for frontier developers to give the government pre-release model access (Source: insideaipolicy.com).

June 12, 2026 reporting laid out the order's first concrete deadlines. By July 2, 2026, DHS owes a plan to prioritize federal cyber defense and push frontier models to critical infrastructure, Treasury owes an "AI cybersecurity clearinghouse," and OMB owes grant funding for AI vulnerability detection. By August 1, Treasury, NSA, and CISA must build a classified benchmarking process for AI cyber capabilities and a voluntary framework giving the government access to models up to 30 days before release; the order assigns Commerce's CAISI no role in this process. The companion memo NSPM-11 orders a frontier-lab–national-security-agency partnership program by October and an update to DOD's autonomy-in-weapons directive within three months (Source: axios.com; whitehouse.gov).

Implementation activity accelerated in the week after signing. On June 8, 2026, Homeland Security Secretary Markwayne Mullin said he was comfortable with Treasury serving as the clearinghouse for mitigating AI-related software vulnerabilities, an area typically led by DHS's CISA (Source: insideaipolicy.com). CISA Acting Director Nick Andersen previewed, in remarks made public June 10, 2026, a forthcoming directive instructing civilian agencies to take a risk-based approach to vulnerability management, tied to the order (Source: insideaipolicy.com). Separately, the White House — through National Cyber Director Sean Cairncross and with Treasury Secretary Scott Bessent — directed the Center for AI Standards and Innovation to halt publication of its model assessments while the order is implemented, a pause reported June 9, 2026 that threw the unit's public-facing future into doubt (Source: wsj.com). The Bank Policy Institute, citing frontier models' ability to speed vulnerability identification, urged the SEC on June 8, 2026 to rescind its 2023 cyber incident-disclosure rule, arguing the disclosure calculus had changed (Source: insideaipolicy.com).

By July 9, 2026, Treasury had drafted the policy document establishing the software-patching clearinghouse required under the order and sent it to the White House for review, according to a banking-industry source (Source: insideaipolicy.com).

The clearinghouse launched on July 14, 2026 as the "Gold Eagle" initiative — a federal clearinghouse for AI-discovered cybersecurity vulnerabilities that uses frontier AI models, including Anthropic's Mythos, to help federal agencies, critical-infrastructure operators, and AI developers find and patch software flaws, with coordinated patching across participants (Source: whitehouse.gov; politico.com). The launch was the first program implementing the order and arrived more than a week past its July 2 deadline; Treasury, DHS/CISA, and the Department of War are participating. National Cyber Director Sean Cairncross credited open-source AI developers at the launch, amid reports of a possible follow-on executive order addressing open-source AI security risks (Source: politico.com; theinformation.com). Coverage of the launch identified the signed order's number as Executive Order 14409 (Source: politico.com).

Congress began examining a statutory follow-on: a Congressional Research Service review of legislative options for implementing the order's directives became public on July 13, 2026 (Source: insideaipolicy.com). Will Loucks, senior director for intelligence in the Office of the National Cyber Director, highlighted the newly announced AI clearinghouse as a key cybersecurity benefit of the order, in remarks published July 20, 2026 (Source: insideaipolicy.com).

Reactions

IBM CEO Arvind Krishna endorsed the narrowed order at the Axios AI+NY Summit on June 3, saying it "hits the Goldilocks spot" of light regulation without "a big bureaucracy that can slow things down," and suggested IBM/Red Hat's Project Lightwell could inform federal AI-security efforts (Source: axios.com). Americans for Responsible Innovation and major tech groups praised the order on June 4 even as ARI pressed transparency concerns (Source: insideaipolicy.com). The law firm Venable raised clearinghouse-coordination questions on June 4 about how voluntary participation in the Treasury-led channel would work in practice (Source: insideaipolicy.com). Sen. Bernie Sanders called the order largely symbolic, while the Council on Foreign Relations described it as a notable shift for an administration that had resisted AI regulation (Source: cfr.org). Elham Tabassi, who led NIST's AI portfolio during the Biden administration, said on June 8, 2026 that the order's voluntary framework for pre-release government review is flawed by a lack of transparency, and separately criticized Biden-era compute thresholds (Source: insideaipolicy.com). Security researchers concluded on June 9, 2026 that the order falls short of the vulnerability-management ecosystem's needs for accelerating remediation, even as it addresses frontier-model risks (Source: insideaipolicy.com). Industry sources said on July 6, 2026 that the administration's policy processes on frontier AI models and cybersecurity — including the order's voluntary review channel — open a path to long-term government-industry collaboration that moves past blunt-force export controls (Source: insideaipolicy.com).

Context and comparison

The order was the administration's lighter-touch alternative to the mandatory ODNI-led pre-release review that a 32-member bipartisan House letter and an ICBA-led industry coalition both rejected in May 2026, during the post-Mythos cyber-governance debate. Its voluntary, no-mandatory-licensing design operationalizes information-sharing goals from the America's AI Action Plan without statutory authority. Unlike the EU AI Act and the GPAI Code of Practice, it imposes no binding obligations on developers; access is opt-in. Unlike state transparency laws such as SB 53 and the NY RAISE Act, it targets cyber capability and pre-release security rather than public disclosure of safety policies. Its "covered frontier model" threshold is set by a regulatory and classified process rather than statute, consistent with the flexible-definition argument in Radical Optionality.

Relationships