The loudest unsettled question in American AI policy this year has been whether Washington would try to gate AI models that anyone can download and run on their own hardware. On Tuesday it got an answer. Axios reported that open models are excluded from the voluntary framework the White House finished last weekend and presented to company staff in meetings that day, citing multiple sources briefed on those meetings.

The framework is the operating document behind an executive order President Trump signed on June 2. Its central mechanism is a 30-day window: a company that opts in gives federal agencies access to a new model for up to 30 days before releasing it more widely, so officials can measure what it could do in a cyberattack. The Information first reported that the White House would brief OpenAI, Anthropic, Google and Meta on the finished version, and a White House official confirmed the meeting to CNBC. Until Tuesday, nobody outside the room knew who the framework covered.

The answer is narrower than the industry expected. The framework defines a covered frontier model as "closed-source with state-of-the-art capabilities and national security risks," meaning a system whose inner workings stay on the developer's servers and are reachable only through a paid connection. Before Tuesday, the working assumption was that raw capability would decide what got reviewed, and that a downloadable model clearing that bar could be pulled in. It will not be. The framework goes further and says nothing in it should be read as restricting open models once they have been released. How a model is distributed, not how powerful it is, now determines whether the government sees it before launch.

The models that fall outside it

This is not a theoretical carve-out. Open models, meaning ones whose weights are published for anyone to download, now sit within months of the closed frontier and sometimes inside it. Weights are the numerical settings a model learns during training, and publishing them lets anyone run the system on hardware they control, with no company watching the prompts. Moonshot AI released the full weights for Kimi K3 on July 27, a 2.8 trillion parameter system that independent trackers placed behind only Claude Fable 5 and GPT-5.6 Sol Max.

Alibaba added to that on Monday, saying it will publish the weights for Qwen3.8-Max next week. Its Hong Kong shares closed 7% higher on the news, and the model leads some benchmarks while trailing on others. A US company, Reflection AI, argued at earlier meetings that open models should be exempt from review based on their capabilities, The Information reported on July 27. Open models got the exemption. The labs building closed models now carry a review burden their downloadable competitors do not.

What the White House still has not said

The framework does not define what counts as state-of-the-art or as a national security risk, which leaves the two tests that decide coverage to the discretion of officials. The review will run through several administration offices rather than a single agency. During the 30-day window, government access would itself be restricted, with models held in high-security environments and detailed logs kept of who opened them.

The document is not going public. Axios reported separately on Tuesday that the White House has no plans to release the framework, leaving companies that were not invited, along with policymakers, researchers and allied governments, guessing at one of the administration's main AI policies. The executive order does not require publication, and it classifies the benchmarking process used to judge cyber capability. It is also unclear which "trusted partners" get early access to reviewed models, including whether any foreign government qualifies. Nvidia staff attended Tuesday's meetings and open-source models were discussed, according to Axios.

One practical instruction did land. Companies were encouraged on Tuesday to submit models as close to public release as possible rather than early prototypes, according to people familiar with the discussions cited by Axios. That turns the review into a final check rather than a look at what a lab is building. The framework answers the question of what gets examined by looking at how a model ships. The systems most likely to strain that answer are already downloadable.