Date: 2026-05-11
Two AI-governance modes were being drafted in parallel in the United States as of May 2026: pre-release vetting, which gates a model's public release through regulatory review, and procurement-driven governance, which gates deployment through federal acquisition decisions. On the May 2026 evidence — Pentagon classified-cohort selections, GSA OneGov USai, CAISI agreements read as a procurement precondition, and private-equity-backed deployment joint ventures — procurement decisions were binding deployment outcomes faster than any pre-release-vetting executive order. The two-track Trump EO drafting illustrates the tension: reporting described a "broad" model-review EO competing with a "narrow" cybersecurity-only EO, while procurement continued operating in parallel regardless of which EO shipped.
What is at stake
The two modes look complementary on paper but operate as substitutes in practice:
- Pre-release vetting gates release. A regulator (CAISI, under a proposed EO) reviews a frontier model before public deployment. It is the mode most discussed in AI safety circles and the AI policy press.
- Procurement-driven governance gates deployment. Federal procurement authorities (CDAO, GSA, agency CTOs, FedRAMP authorities) decide which models are bought, deployed, and integrated into infrastructure, independent of release status. It was the mode driving most observed May 2026 outcomes.
Whether the future US AI governance regime is regulation-led or procurement-led bears on which constituencies have leverage, where civil-society oversight is possible, whether state-level regulations carry force, and whether safety-frameworks analysis remains the relevant analytical center or shifts toward deployment topology.
The comparison
Where authority comes from
| Pre-release vetting | Procurement-driven governance | |||
|---|---|---|---|---|
| Source of authority | Statutory + EO + regulatory rule-making | Procurement contract + acquisition regulation (FedRAMP, IL5/6/7 ATO) | ||
| Operative agent | [[entities/nist-caisi\ | CAISI]] (proposed) | [[entities/cdao\ | CDAO]], GSA OneGov USai, agency CTOs, PE deployment intermediaries |
| Decision visibility | Public via Federal Register notice-and-comment | Mostly opaque; criteria typically not disclosed (e.g., no public rationale for Anthropic May 2026 cohort exclusion) | ||
| Public-comment vehicle | Yes (Federal Register) | No formal vehicle | ||
| Preemption mechanism | Explicit EO or statutory text | De-facto: federal contract overrides state-law requirements within its scope | ||
| Speed to bind | Months-to-years (rule-making cycle) | Days-to-weeks (procurement decision cycle) |
What each one measures
| Pre-release vetting | Procurement-driven governance | ||
|---|---|---|---|
| What's evaluated | Frontier-model capabilities against capability thresholds (RSP/Preparedness/FSF) | Whatever the procurement officer decides matters — typically safety, security, performance, vendor stability, ToS compatibility | |
| Evidence base | Lab-internal evaluations + CAISI third-party evaluations | Vendor disclosures + procurement-officer judgment + (sometimes) CAISI reports | |
| **[[sources/open-problems-frontier-ai-risk-management\ | Open Problems critique]] applies?** | Yes — the critique that lab evaluations measure proxies rather than real-world risk goes directly to pre-release vetting | Indirectly — procurement officers inherit the same proxy/reality gap when they use CAISI reports |
| NLA-style alignment-auditing applies? | Yes if integrated — but currently not standard | Indirectly through CAISI |
What the May 2026 evidence shows
Six May 2026 developments weigh toward procurement-driven governance binding first.
The two-track Trump EO drafting is the most direct symptom. Politico reported on May 5 a broad "FDA-like" model-review EO; Bloomberg reported on May 8 a narrower cybersecurity-only EO that omits mandatory pre-release testing. Whichever ships first, procurement continues operating in parallel. The EO-track detail is set out in Policy Brief: Where does the Trump pre-release-vetting EO actually stand?.
The Pentagon classified-network cohort was selected on May 1, 2026: seven companies (xAI, OpenAI, Google, Nvidia, Reflection, Microsoft, AWS) were chosen for IL5/IL6/IL7, with Anthropic excluded. The selection involved no regulatory review and no EO. The exclusion is the subject of Anthropic v. United States (Pentagon ban challenge).
CAISI agreements with Google, Microsoft, and xAI (May 5) joined prior agreements with Anthropic and OpenAI, bringing the US pre-release-evaluation pipeline to all five major frontier labs on a voluntary basis. The agreements are widely understood as a precondition for federal contract eligibility, so the evaluations function as a procurement-gating signal rather than as an operative regulatory decision.
Private-equity-backed deployment JVs appeared in two parallel structures on May 4: an Anthropic, Blackstone, H&F, and Goldman $1.5B JV, and an OpenAI, TPG, Brookfield, and Bain $10B "Deployment Company" JV. Both pre-position vendor selection at enterprise scale and fix deployment topology ahead of any regulatory review.
Compute commitments exceeding $200B likewise fix deployment topology for years without regulatory review: Anthropic-Google $200B over 5 years (May 5), Anthropic-SpaceX Colossus 1 (May 6), and Anthropic-Akamai $1.8B (May 8).
Reflection's open-weight inclusion in the Pentagon cohort placed an open-weight model inside a procurement decision that no current pre-release-vetting framework contemplates. Pre-release vetting assumes a defined release event, which open-weight models do not have in the same sense, leaving that regime structurally less suited to the open-weight question while procurement absorbs it without conceptual friction.
How the two interact
Three interaction patterns are visible. Under the first, procurement acts as the enforcement mechanism for pre-release vetting: if the broad EO ships and mandates CAISI evaluations, procurement gates ensure compliance and the two reinforce each other. Under the second, procurement substitutes for pre-release vetting: if the narrow cybersecurity-only EO ships and omits mandatory testing, the formal regulatory regime is thinner but procurement-gating continues, so the operative governance regime changes little. Under the third, procurement overrides pre-release vetting: if procurement officers reject a model on grounds unrelated to CAISI's evaluations, as appears to be the case in the Anthropic exclusion, the procurement decision is operative and CAISI's verdict is advisory.
The May 2026 evidence is most consistent with the second and third patterns, with procurement functioning as the operative gate and pre-release vetting as an advisory or formal layer.
The disagreements that matter
Sources divide on whether procurement-driven governance constitutes governance in the sense pre-release vetting advocates intend. Anthropic-aligned voices, including Dario Amodei and frontier-safety researchers, argue pre-release vetting is essential because procurement decisions cannot account for capability-threshold risks across the deployment lifecycle. Industry-aligned voices, including Dean Ball, Ben Buchanan, and much of the EO-drafting community described in the May 8 Bloomberg reporting, implicitly accept procurement as the operative gate.
Sources also divide on democratic legitimacy. Public-comment processes do not exist for procurement decisions, and the Anthropic exclusion has no published rationale; pre-release vetting is slower but more legible to civil-society oversight.
A separate question is whether the macro-prudential thread cuts against procurement. The IMF Mythos designation (May 7) treats AI capability as a financial-stability risk that central banks should monitor. If it propagates, it would open a third governance mode — financial-supervisor oversight — operating parallel to both pre-release vetting and procurement, raising the question of which mode is subordinate when they conflict.
Finally, sources differ on whether state-law preemption resolves the question. xAI v. Colorado, in which the DOJ intervened on May 6 on Fourteenth-Amendment grounds, is the live legal test; a preemption ruling broad enough to moot state AI law would, on the brief's reading, confirm procurement-driven governance as the dominant federal mode.
Caveats — what this brief is missing
- No leaked primary text of either Trump EO. The brief relies on Politico (May 5) and Bloomberg (May 8) reporting; leaked drafts would substantially change the comparison.
- Limited federal procurement-criteria transparency. Published CDAO criteria, if any, would allow a more precise assessment of procurement-driven governance. The analysis currently depends on observed outcomes — cohort decisions, deal structures — rather than stated rules.
- No quantification of the procurement / pre-release-vetting balance. The brief argues procurement binds more often; a rigorous version would count federal AI deployments gated by each mechanism over the May 2026 cycle, a count not available here.
- The macro-prudential thread is one source deep. AI Macro-Prudential Policy is currently sources_count: 1 (IMF blog only). The brief should be reread when propagation evidence accumulates.
Citations
Wiki pages:
- Procurement-Driven AI Governance — the central concept page (sources_count: 7)
- AI Pre-Release Vetting — the rival concept page (sources_count: 11)
- AI Governance (umbrella) — umbrella
- AI Macro-Prudential Policy — emerging third mode
- Chief Digital and Artificial Intelligence Office (CDAO) — DOD procurement authority
- NIST CAISI (Center for AI Standards and Innovation) — civilian-side evaluation authority
- Cybersecurity and Infrastructure Security Agency (CISA) — regulator role — Five-Eyes-equivalent agentic-AI guidance
- Reflection AI — lone open-weight in May 2026 cohort
- Clawed, Anthropic v. United States (Pentagon ban challenge) — live exclusion case
- AI Safety Cases and Frameworks — upstream-input governance modes
- Techno-Federalism — state-vs-federal layer
- Open Problems in Frontier AI Risk Management — Ziosi et al., May 4
- Policy Brief: Where does the Trump pre-release-vetting EO actually stand? — companion brief on the EO-track question
- Open Questions — Q1 (two-track EO) + Q4 (Anthropic breakaway)
External:
- Politico, May 5, 2026 — broad pre-release-vetting EO drafting
- Bloomberg, May 8, 2026 — narrower cybersecurity-only EO
- WSJ, May 8, 2026 — Mythos→Cairncross→EO trigger chain
- The Information, May 4, 2026 — Anthropic-Blackstone PE-deployment JV
- The Information, May 4, 2026 — OpenAI-TPG Deployment Company JV
- The Information, May 5, 2026 — Anthropic-Google $200B / 5yrs commitment
- IMF financial-stability blog, May 7, 2026 — Mythos macro-financial-risk designation
- The Information, May 6, 2026 — Anthropic-SpaceX Colossus 1 deal
- Bloomberg, May 8, 2026 — Anthropic-Akamai $1.8B / 7yrs