AI Policy Wiki
Dashboard

Policy Brief: Where does the Trump pre-release-vetting EO actually stand?

medium confidence · updated 2026-06-06

Two reported drafting tracks (broad model-review EO + narrower cybersecurity-only EO that omits mandatory testing). What's known as of May 10, 2026, and what to watch.

Date: 2026-05-10

As of May 10, 2026, the Trump administration is reportedly drafting two AI executive orders in parallel: a broad "FDA-like" pre-release model-review EO and a narrower cybersecurity-only EO that omits mandatory pre-release testing. Reporting indicates both could be published within 90 days. Which one becomes operative — and whether either does — is the central open question this brief addresses.

What is at stake

Pre-release vetting of frontier AI models has been a contested governance mode since the AI Safety Cases and Frameworks frameworks (Anthropic RSP, OpenAI Preparedness, Google Frontier Safety Framework) became the de-facto industry baseline in 2024–2025. Whether the federal government adds a mandatory gate on top, and what that gate measures, bears on several questions: whether NIST CAISI (Center for AI Standards and Innovation) becomes a regulator or remains a procurement-advisory body; whether Procurement-Driven AI Governance remains the binding governance mode; and whether state-level regulations such as California SB 53 and Colorado AI Act (SB 24-205) survive a federal preemption fight.

Evolution of the administration's posture

The administration's stance on pre-release vetting shifted over the course of 2025–2026. In the February 2025 Paris speech, Vice President Vance argued that "excessive regulation of the A.I. sector could kill a transformative industry," an explicitly anti-mandatory-vetting framing. By March 2026, following the departure of Sacks, Scott Bessent and Susie Wiles inherited the AI portfolio; under them CAISI continued voluntary pre-release evaluations with the five major frontier labs (AI Pre-Release Vetting).

In May 2026, two reporting threads described an active drafting cycle. WSJ reported on May 8 that Claude Mythos Preview's offensive-cyber capability triggered an active drafting cycle for a White House frontier-AI oversight EO, with NEC Director Kevin Hassett describing the model as "FDA-like" (Source: politico.com, May 5, 2026). Separately, Bloomberg reported on May 8 that the administration is also drafting a narrower AI Security Order focused on cybersecurity that omits mandatory model tests (Source: Bloomberg, May 8, 2026). The two reports describe two parallel drafting tracks rather than conflicting accounts of a single effort.

The main positions

The broad-EO position, attributed to the Politico-Hassett framing of May 5, would subject frontier models above a defined capability threshold to third-party pre-deployment testing modeled on FDA review, using CAISI's existing five-lab pipeline as the operational vehicle as it graduates from voluntary to mandatory. Reported proponents include the NEC (Hassett) and, reportedly, Anthropic and Anthropic-aligned safety advocates (Dario Amodei, Clawed). The strongest source for this account is Politico, May 5, 2026.

The narrow-EO position, attributed to the Bloomberg framing of May 8, would address AI cyber-capabilities only — the Claude Mythos Preview-IMF-financial-stability framing — and explicitly omits mandatory pre-deployment testing. Reported proponents include industry-aligned voices opposed to mandatory testing and, reportedly, Dean Ball-style lighter-touch advocates (see also Ben Buchanan). The strongest source for this account is Bloomberg, May 8, 2026.

A critique of both tracks comes from Open Problems in Frontier AI Risk Management (Ziosi et al., May 4, 2026), authored by a coalition of 28 or more authors across multiple institutions (Oxford, MIT, Stanford, UC Berkeley, Purdue, and others). The authors argue that both proposed EOs would inherit lab-internal capability evaluations as the operative evidence base, and that those evaluations measure proxies for risk rather than real-world risk. On their reading, even a broad EO that lands as drafted would not change governance outcomes unless it shifts what gets evaluated.

Contested questions

Three points of disagreement remain unresolved as of the brief date.

First, which EO ships first shapes which governance mode becomes operative. If the broad EO ships first and the narrow EO is shelved, mandatory pre-release testing becomes operative. If the narrow EO ships first and the broad one is shelved or delayed, the cybersecurity-only frame becomes the de-facto policy and procurement — CDAO classified-cohort decisions and GSA OneGov USai criteria — becomes the binding gate (Chief Digital and Artificial Intelligence Office (CDAO)). High-confidence evidence supports neither outcome at present.

Second, the scope of CAISI authority is unsettled. The May 5 CAISI agreements with Google, Microsoft, and xAI, joining prior agreements with Anthropic and OpenAI, bring the U.S. pre-release-evaluation pipeline to all five major frontier labs voluntarily. Whether this voluntary pipeline graduates to mandatory under the broad EO, becomes redundant under the narrow EO, or persists as a parallel track is not yet determined.

Third, state-law preemption is a live legal fight independent of the EO question. xAI v. Colorado, in which the DOJ is intervening on 14th Amendment grounds (May 6), and the American Leadership in AI Act (Lieu/Obernolte, May 6) both frame federal preemption of state AI law. Either EO could include preemption language; neither necessarily does (Anthropic v. United States (Pentagon ban challenge)).

Caveats — what this brief is missing

  • No primary text of either EO. Only reported framing is available; the operative legal text remains private. A leaked draft would substantially change this brief.
  • No formal CAISI position. CAISI has not publicly commented on whether it would accept mandatory-evaluation authority if granted.
  • Limited insight into the China-mirror question. The brief does not address whether either EO would extend evaluation requirements to non-U.S. labs (DeepSeek, Mistral, Qwen) as a condition of U.S. deployment access.

Citations

Wiki pages:

External:

  • Politico, May 5, 2026 — broad 16-page EO drafting
  • Bloomberg, May 8, 2026 — narrower cybersecurity-only EO
  • WSJ, May 8, 2026 — Mythos→Cairncross→EO trigger chain
  • IMF financial-stability blog, May 7, 2026 — Mythos as macro-financial-risk vector