The White House finalized a first version of its frontier AI model review framework last weekend, in line with the executive order President Trump signed on June 2. Central to the framework is a pathway for developers to offer federal agencies previews of new models up to 30 days before wider release, giving them time to assess their cyber capabilities.
Representatives from leading AI firms Anthropic, Nvidia, OpenAI, Meta, Google and others were the first to be briefed on the framework’s contents this week. The firms were reportedly instructed to submit their models for review as close to public release as possible, so that the assessment results accurately reflect their final capabilities.
The document itself will not be made public, meaning that analysts and developers not invited to these talks are still largely left in the dark regarding its contents. However, some details of its terms and scope have since become public knowledge.
One major question was whether open-weight models - those that can be freely downloaded and run on local hardware - would be covered by the new rules. An August 4 report from Axios confirmed that this will not be the case.
The scope of the White House’s framework
The new framework is concerned only with what it calls “covered frontier models” - an ambiguous term that some assumed would include open-weight models, provided they met a certain threshold of cyberattack capability. However, the exact wording in the document excludes these models from consideration, defining its target as models that are “closed-source with state-of-the-art capabilities and national security risks.”
This essentially means only closed-weight models will be subject to its terms: those whose model weights are held back by the company. These models are typically hosted on the developers' own servers and accessed via API.
Although the definition clearly omits open-weight models, some ambiguity remains over the terms “state-of-the-art” and “national security risk.” The exact thresholds for these labels are unclear and will inevitably shift over time, leaving these judgements open to federal officials to make these judgements. These officials will have the opportunity to test the models within secure environments, with strict access controls and activity logs.
Chinese open-weight models are serious contenders
Weights are the result of a model’s training: a set of numerical values that essentially comprise the knowledge base of the AI. Publishing these theoretically allows any user to run the model on local hardware, without the developer holding any control over access or input monitoring. In practice, however, doing so is impractical for most users; running the more advanced open-weight models requires a rack of processing units, with few able to run effectively on normal consumer hardware.
Their omission from the White House framework is significant because open-weight models compete very closely with their closed counterparts. Kimi K3, released by Chinese firm Moonshot AI in July, ranks behind Claude Fable 5 and GPT-5.6 Sol Max on Artificial Analysis’ Intelligence Index, meaning its capabilities are greater than the vast majority of AI models both, open and closed.
This open-weight approach is more common in China than the United States; Alibaba this week announced that it will publish the weights for its own Qwen3.8-Max model, driving its shares to close 7% up that day.
Models such as these will be exempt from the White House’s review framework, even though their capabilities can match or exceed their closed-weight competitors.
