AI Policy Wiki
Dashboard

Policy Primer: Draft Trump AI-Cybersecurity Executive Order (Unsigned, May 2026)

high confidence · updated 2026-06-06

Section-by-section primer on the predecisional draft executive order 'Promoting Advanced Artificial Intelligence Innovation and Security,' whose signing President Trump postponed on May 21, 2026 — its provisions, the cyber-governance debate that produced it, and what to watch.

Date: 2026-05-24

This primer covers the predecisional draft executive order titled "Promoting Advanced Artificial Intelligence Innovation and Security" — the cybersecurity-and-frontier-security order whose signing President Trump postponed on May 21, 2026. The draft would direct AI-enabled cyber defense of federal systems and create a voluntary framework under which developers could give the government up to 90 days of pre-release access to designated "covered frontier models," while expressly disclaiming any mandatory licensing or preclearance regime. The signing was pulled hours before a scheduled May 21 ceremony after AI and crypto adviser David Sacks argued that voluntary government testing could become a foothold for mandatory regulation. Whether the order is redrafted and signed, folded into other initiatives, or shelved is unresolved as of this primer's date.

The primer walks through the draft text section by section, describes the policy debate that produced it, and summarizes where it stands. It does not separately cover the broader "FDA-for-AI" model-review order reported earlier in May 2026, except where the two intersect.

Background and context

The draft order emerged from a cyber-governance debate in spring 2026 that followed disclosures of frontier-model offensive-cyber capability. Beginning in April 2026, a series of reports indicated that frontier AI models had reached operationally significant offensive-cyber capability. Anthropic's preliminary testing of its restricted-access Claude Mythos Preview model, reported April 30, found that the model identified a 27-year-old vulnerability in a widely used security package, with the specific successful run costing roughly $50 — compressing into minutes work that would previously have taken advanced-persistent-threat groups months (AI and Cybersecurity). Google's Threat Intelligence Group disclosed on May 11 the first confirmed AI-developed zero-day attributed to an external attacker, and Verizon's 2026 Data Breach Investigations Report, released around May 23, characterized generative AI as a cross-stage force-multiplier for threat actors. These developments created political pressure for a federal response.

That pressure produced two parallel drafting tracks (policy brief, May 10). Politico reported on May 5 that the administration was drafting a broad, roughly 16-page executive order establishing a pre-release vetting regime for frontier models — National Economic Council Director Kevin Hassett described it as working "just like an FDA drug." Bloomberg reported on May 8 that the administration was separately preparing a narrower AI cybersecurity order that directs agencies to partner with AI companies on defense but stops short of requiring government approval of cutting-edge models (AI Pre-Release Vetting). The draft order covered by this primer is the narrower, cybersecurity-focused track.

Drafting of the order was reported by Axios and Politico on May 19–20, 2026, and the White House issued invitations for a signing ceremony with technology and AI chief executives. President Trump postponed the signing on May 21, 2026, hours before the scheduled event, stating that he "didn't like certain aspects of it" and citing concern that it would be "a blocker on US competitiveness" (Source: axios.com). The primary text discussed below is the leaked predecisional draft, marked "DRAFT//PREDECISIONAL//FOR DISCUSSION PURPOSES ONLY" and dated "May XX, 2026"; it is summarized as a primary source on Draft Executive Order: Promoting Advanced Artificial Intelligence Innovation and Security (unsigned, May 2026) and tracked on EO — Promoting Advanced AI Innovation and Security (Trump, signed June 2, 2026).

Overview of the draft

The draft is a cybersecurity-and-frontier-security order rather than a comprehensive AI-policy order. It contains five sections, and its framing is deregulatory throughout: it opens by crediting U.S. AI leadership to a refusal "to stifle this innovation with overly burdensome regulation," and it repeatedly disclaims any mandatory regime. The order frames advanced AI as making the United States stronger while introducing "new national security considerations," and pairs an "America First cybersecurity" posture with continued "global AI dominance." The draft uses the renamed "Department of War" and "Secretary of War," reflecting the administration's redesignation of the Department of Defense.

The order's deadlines are summarized below; the section subheadings that follow describe each provision in detail.

ProvisionLead actor(s)Deadline
Sec. 2(a) — defend National Security SystemsCommittee on National Security Systems30 days
Sec. 2(b) — defend Department of War systemsSecretary of War30 days
Sec. 2(c) — defend civilian federal systemsDHS, via CISA Director30 days
Sec. 2(d) — AI cybersecurity clearinghouseSecretary of the Treasury30 days
Sec. 2(e) — grant-funding reviewOMB Director30 days
Sec. 2(f) — workforce hiring pathwaysOPM Director60 days
Sec. 3 — classified benchmarking + voluntary access frameworkTreasury, NSA, CISA60 days

Section 1 — Purpose and policy

Section 1 states the order's purpose and policy. It credits the administration with "slashing the bureaucratic constraints" placed on AI developers by the prior administration, and states that the United States "will continue to work closely with industry to ensure that the best and most secure technology is deployed rapidly." The operative policy statement commits the United States to three aims: working collaboratively with the private sector to modernize and harden government and private-sector information systems against external threats; protecting "American ingenuity and intellectual property from exploitation and theft by adversaries"; and cultivating "America's advanced AI-enabled capabilities." Section 1 sets the interpretive frame for the rest of the order — collaboration over compulsion — and is the textual anchor for the no-mandatory-licensing disclaimer in Section 3.

Section 2 — Upgrading American systems for advanced AI

Section 2 directs a build-out of AI-enabled cyber defense across federal and critical-infrastructure systems. It assigns six tasks, five of them on a 30-day deadline and one on 60 days.

National security and defense systems (Sec. 2(a)–(b)): within 30 days, the Committee on National Security Systems must prioritize the cyber defense of National Security Systems, as defined in 44 U.S.C. 3552(b)(6)(A); and the Secretary of War must prioritize the cyber defense of Department of War information systems.

Civilian federal systems (Sec. 2(c)): within 30 days, the Secretary of Homeland Security, through the Director of the Cybersecurity and Infrastructure Security Agency ("CISA") — in consultation with the OMB Director, the Assistant to the President for National Security Affairs, and the National Cyber Director — must issue Binding Operational Directives and other guidance to expedite the cyber defense of civilian federal systems, expand federal programs that enhance "AI-enabled defensive tools," and "facilitate access to cybersecurity tools and services including, where appropriate, covered frontier models" for federal agencies, state and local authorities, and operators of critical infrastructure "such as rural hospitals, community banks, and local utilities." This subsection is the first appearance of the term "covered frontier model," which Section 3 defines.

AI cybersecurity clearinghouse (Sec. 2(d)): within 30 days, the Secretary of the Treasury — in consultation with the National Cyber Director, the NSA Director, and the CISA Director — must form an AI cybersecurity clearinghouse, "in voluntary collaboration with the AI industry and operators of critical infrastructure." The clearinghouse would coordinate and deconflict scanning for software vulnerabilities, discover and validate vulnerabilities, and prioritize the remediation and distribution of patches. It is the order's principal standing institution. The decision to seat its formation with the Treasury Department rather than CISA or NIST later drew criticism (see "Postponement of the signing").

Grant funding and workforce (Sec. 2(e)–(f)): within 30 days, the OMB Director, with the National Cyber Director and CISA, must determine whether existing federal grant programs have funding that could be directed to applicants developing "advanced AI vulnerability detection." Within 60 days, the Director of the Office of Personnel Management must expand "U.S. Tech Force Information Cybersecurity Specialist" hiring and placement pathways.

Section 3 — Secure frontier model deployment

Section 3 is the order's central provision. Within 60 days, the Secretary of the Treasury, the NSA Director, and the CISA Director — in consultation with the National Cyber Director, the Assistant to the President for Science and Technology ("APST"), and the Director of the National Institute of Standards and Technology — must take two actions.

A classified benchmarking process (Sec. 3(a)): the agencies must "develop and maintain a classified benchmarking process to assess the advanced cyber capabilities of AI models and determine the threshold at which an AI model should be designated a 'covered frontier model.'" Assessments would be shared with developers and researchers "as appropriate." The designation itself would be made by the NSA Director, in consultation with the National Cyber Director, the APST, the CISA Director, and other Department of War representatives. The threshold defining a "covered frontier model" is thus set by a classified, regulatory process — not by statute and not by a published compute figure. This flexible-definition design is consistent with the argument in Radical Optionality that frontier-AI governance should rely on adaptable definitions rather than fixed statutory thresholds.

A voluntary early-access framework (Sec. 3(b)): the agencies must "design a voluntary framework with AI developers" under which developers would be able to: (i) engage the U.S. government to determine whether a model meets the "covered frontier model" designation; (ii) "provide the Federal Government with access to covered frontier models, subject to appropriate confidentiality, cybersecurity, insider-risk, and intellectual-property" protections, "for a period of up to 90 days before they plan to release such models to other trusted partners"; and (iii) collaborate with the government to select "trusted partners" for early access "to promote secure innovation and strengthen the cybersecurity of critical infrastructure." The framework is opt-in: it imposes no obligation on a developer to seek a designation or to grant access.

The no-mandatory-licensing bar (Sec. 3(c)): Section 3(c) states that nothing in the section "shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models." The disclaimer is explicit. Its presence indicates that the drafters anticipated the objection — pressed by industry-aligned voices throughout May 2026 — that government pre-release access is licensing in disguise, and sought to foreclose it on the face of the order.

Section 4 — Protection against criminal actors

Section 4 directs the Attorney General to prioritize enforcement of 18 U.S.C. 1028 (identity fraud), 1030 (the Computer Fraud and Abuse Act), and 1343 (wire fraud), "and all other applicable Federal criminal laws," against anyone who uses AI to illegally access or damage a computer without authorization, or who uses AI while doing so to further another crime. The section expressly reaches the use of "AI agents to unlawfully access data." It creates no new offenses; it is a prosecutorial-priority directive applying existing computer-crime statutes to AI-enabled and AI-agent-assisted conduct.

Section 5 — General provisions

Section 5 contains standard executive-order boilerplate: a non-impairment clause preserving existing agency and OMB authorities; an instruction that the order be implemented consistent with applicable law and subject to appropriations; and a clause stating that the order creates no right or benefit enforceable at law or in equity. Section 5(d) provides that the costs of publishing the order "shall be borne by the Department of War."

Postponement of the signing

President Trump postponed the signing on May 21, 2026. Subsequent reporting describes the mechanics and the internal disagreements that preceded it.

David Sacks, the AI and crypto adviser, made a last-minute appeal in a May 21 phone call with the President, warning that the draft's voluntary government testing of AI models could become a foothold for mandatory regulation that would slow U.S. firms against Chinese rivals (Source: wsj.com). Sacks has been the administration's most consistent voice against any pre-approval regime; his stated objection was not that the draft created a mandatory regime, but that a voluntary one could evolve into one.

People familiar with the decision said the signing was scrapped mainly because the President "just hates regulation," and characterized the draft as "just something doomers wanted" — consistent with the public line that added oversight could be "a blocker on US competitiveness" (Source: axios.com).

Industry figures questioned why the draft gave the Treasury Department, rather than CISA or NIST, a lead role in identifying AI-model vulnerabilities — a structure visible in the Section 2(d) clearinghouse and the Section 3 working group. Separately, the Office of the National Cyber Director (ONCD) signaled it is pursuing its own AI security initiatives, suggesting the cyber-governance agenda may proceed outside this order (Source: axios.com).

Meta and Elon Musk separately stated that Mark Zuckerberg and Musk did not speak with the President until after the signing was pulled, indicating the postponement was not the product of a Zuckerberg or Musk lobbying call.

Relation to other governance efforts

Throughout May 2026, both a 32-member bipartisan House letter and an industry coalition led by the Independent Community Bankers of America rejected a mandatory, ODNI-led pre-release review of frontier models, and both favored a voluntary framework giving vetted defenders early access (AI Pre-Release Vetting). The draft order's design — voluntary participation, no binding developer obligations, and an explicit no-licensing bar — aligns with that opposition. It is the cybersecurity branch of the two-track effort, not the broader "FDA-for-AI" model-review branch.

The "covered frontier model" early-access framework partly formalizes activity already occurring voluntarily: the Center for AI Standards and Innovation (CAISI) had signed pre-release evaluation arrangements with the five major U.S. labs in early May 2026 (NIST CAISI (Center for AI Standards and Innovation)). The draft order would house that activity in a cyber-and-national-security frame, led by Treasury, NSA, and CISA, with the threshold set by a classified benchmarking process. That re-housing — moving the evaluation function out of Commerce/CAISI and into the national-security agencies — was among the lead-agency objections that contributed to the postponement.

The order would operationalize information-sharing and frontier-cyber goals from America's AI Action Plan without statutory authority. Every substantive mechanism is voluntary or internal to the executive branch — agency directives, a voluntary clearinghouse, an opt-in access framework, a prosecutorial-priority directive — and Section 5 confirms it creates no enforceable rights. By contrast with the EU AI Act, it imposes no binding obligations on developers; and unlike state frontier-model transparency laws such as California's SB 53 and New York's RAISE Act, it targets pre-release cyber security rather than public disclosure of safety practices. Section 3(c)'s express disclaimer of any "mandatory governmental licensing, preclearance, or permitting requirement" was the drafters' attempt to address the slippery-slope critique within the text itself; the postponement turned on the concern that a voluntary regime could evolve into a mandatory one rather than on anything the draft created. That a voluntary, deregulatory cybersecurity order carrying an express anti-licensing clause did not clear internal review indicates that the administration has not resolved whether any formal federal role in frontier-model evaluation, even a voluntary one, is compatible with its competitiveness-first posture.

Caveats and coverage gaps

  • The text is a predecisional draft. It is marked "DRAFT//PREDECISIONAL//FOR DISCUSSION PURPOSES ONLY" and dated "May XX, 2026." A signed order, if one issues, could differ materially. Every provision summarized here should be read as draft language, not enacted law.
  • Postponement reporting rests on secondary sources. The mechanics of the May 21 postponement are drawn from Axios, the Wall Street Journal, and Politico. Those articles are reported as supporting sources and do not have dedicated Wiki/sources/ pages; the draft EO text itself is ingested as a foundational primary source at Draft Executive Order: Promoting Advanced Artificial Intelligence Innovation and Security (unsigned, May 2026).
  • The broader model-review order has no primary text. Only reported framing exists for the separate "FDA-for-AI" order; its operative text is not public.
  • Status is fast-moving. The order's status is a fast-decay fact. This primer reflects a web check current to 2026-05-24; a rescheduled signing or formal withdrawal would supersede the Open questions section.

Sources

Wiki pages:

External (supporting sources):

  • Axios, May 21, 2026 — postponement mechanics — axios.com
  • Wall Street Journal, May 21, 2026 — Sacks's intervention — wsj.com
  • Politico, May 21, 2026 — postponement after Sacks raised industry concerns — politico.com
  • The New York Times, May 21, 2026 — cancellation of the signing — nytimes.com

Relationships