This page documents the unsigned predecisional draft of a Trump administration cybersecurity-and-frontier-AI executive order whose signing was postponed on May 21, 2026, hours before a scheduled signing. The draft directs AI-enabled cyber defense of federal systems, establishes an AI cybersecurity clearinghouse, creates a classified benchmarking process to designate "covered frontier models," and sets up a voluntary framework giving the federal government up to 90 days of pre-release access to those models, while explicitly barring any mandatory licensing or preclearance regime.
This draft has been superseded by the signed order at Executive Order: Promoting Advanced Artificial Intelligence Innovation and Security (signed June 2, 2026), which cut the early-access window from 90 to 30 days and made the NSA-designation and NIST roles explicit. The page is retained as the historical record of the order's content before the May 21 postponement and the June 2 signing. The live tracking page is EO — Promoting Advanced AI Innovation and Security (Trump, signed June 2, 2026).
Provenance
The document was marked "DRAFT//PREDECISIONAL//FOR DISCUSSION PURPOSES ONLY" and dated "May XX, 2026." President Trump postponed signing it on May 21, 2026, hours before a scheduled signing, citing "I didn't like certain aspects of it" and concerns that it would be "a blocker on US competitiveness."
The draft frames AI as making the United States stronger while introducing "new national security considerations," and pairs an "America First" cybersecurity posture with continued "AI dominance." It is a cybersecurity-and-frontier-security order rather than a broad AI-policy order, and is deregulatory in tone, repeatedly disclaiming any mandatory licensing or preclearance regime.
Key provisions
- Sec. 2 — Upgrading American Systems for Advanced AI. Within 30 days: the Committee on National Security Systems prioritizes cyber defense of National Security Systems; the Secretary of War (the draft uses the renamed Department of War) prioritizes cyber defense of department systems; CISA (under DHS) issues Binding Operational Directives to expedite cyber defense of civilian federal systems and to "facilitate access to cybersecurity tools and services including, where appropriate, covered frontier models" for federal, state, local, and critical-infrastructure operators (rural hospitals, community banks, local utilities). Treasury, NSA, and CISA form an AI cybersecurity clearinghouse, a voluntary industry collaboration coordinating vulnerability scanning, validation, and patch distribution. OPM expands U.S. Tech Force cybersecurity hiring.
- Sec. 3 — Secure Frontier Model Deployment. Within 60 days, Treasury, NSA, and CISA (with NIST, the National Cyber Director, and the APST) shall (a) develop a classified benchmarking process to assess models' advanced cyber capabilities and set the threshold for designating a "covered frontier model"; and (b) design a voluntary framework under which developers can have the federal government determine whether a model is "covered," provide the government up to 90 days of pre-release access to covered frontier models (subject to confidentiality, cybersecurity, insider-risk, and IP protections), and collaborate on selecting "trusted partners" for early access. Sec. 3(c) explicitly bars construing the section "to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models."
- Sec. 4 — Protection Against Criminal Actors. Directs the Attorney General to prioritize enforcement of 18 U.S.C. §§ 1028, 1030, 1343 and other criminal laws against AI-enabled unauthorized computer access and AI-agent-assisted crime.
- Sec. 5 — General Provisions. Standard non-impairment and no-private-right-of-action language; publication costs borne by the Department of War.
Context and reception
The "covered frontier model" and up-to-90-day voluntary early-access framework is the operative provision. It functions as a lighter-touch alternative to the mandatory ODNI-led pre-release review that a 32-member bipartisan House letter and an ICBA-led industry coalition letter both rejected in May 2026, during the cyber-governance debate that followed Mythos. The draft's voluntary, no-mandatory-licensing design aligned with that opposition.
The draft operationalizes parts of the America's AI Action Plan's information-sharing and frontier-cyber goals without statutory authority.
Relationships
- instance-of: AI and Cybersecurity; AI Pre-Release Vetting
- related: EO — Promoting Advanced AI Innovation and Security (Trump, signed June 2, 2026), America's AI Action Plan, Claude Mythos Preview, Compute Governance, Dual-Use Frontier AI, Cybersecurity and Infrastructure Security Agency (CISA) — regulator role, Donald Trump
- contradicts: proposals for mandatory pre-release licensing / ODNI-led review of frontier models