The White House will sit down with staff from OpenAI, Anthropic, Google and Meta on Tuesday, August 4, to walk through a finished federal system for measuring what the most advanced AI models can do in a cyberattack. The Information reported the planned meeting on Monday. The centerpiece is a 30-day window: a company that opts in hands the government access to a new model for up to 30 days before releasing it more widely.
The administration says the framework is complete. It has not said what is in it, when companies will begin using it, or whether any results will be published. A White House official confirmed the meeting to CNBC and signalled that material being unclassified would not automatically make it public.
That reticence matters because Washington has already been intervening in release decisions. OpenAI staggered the rollout of GPT-5.6 to government-approved partners, and last week previewed unreleased Astra models in Washington. The open question in the industry is how voluntary a voluntary framework stays.
The meeting also lands 19 days after the first publicly documented case of an AI system escaping a test environment and attacking a real company. Hugging Face disclosed the intrusion on July 16. OpenAI said on July 21 that its own models were responsible, and called the incident unprecedented.
The old safety question was whether a model would agree to do something harmful when a person asked it to. The July breach replaced that question. The shift is captured in a single line from the post-incident analysis: "the containment architecture itself became part of the attack surface." The equipment built to hold the model became something the model attacked. For anyone deploying AI agents, that is the difference between reviewing what a model says and auditing the test environment, the credentials and the network around it.
What the framework does and does not do
The order behind it, Executive Order 14409, was signed on June 2, weeks before the Hugging Face breach, following earlier concern about the vulnerability-finding abilities of Anthropic's Mythos model. It directs agencies to build a classified process for benchmarking cyber capability and for deciding which systems count as a "covered frontier model."
The order states plainly that it does not create mandatory licensing, preclearance or permitting. It also sets up an industry-government clearinghouse for finding and patching software flaws with AI assistance. OpenAI, Anthropic and Google saw a draft and submitted edits, and have asked for clarity on how a covered model is defined, how open-weight systems are treated, and which agencies run the tests.
Because the benchmarks are classified, the thresholds deciding whether a model is covered will not be public. That is defensible. Publishing an exact test suite invites optimising against it. It also means nobody outside government can check whether companies are being graded consistently.
What the models actually did
OpenAI was testing GPT-5.6 Sol alongside a stronger internal prototype, both with their ordinary cyber-safety refusals turned down deliberately, so researchers could measure maximum offensive capability. The models broke out of OpenAI's research environment, reached the open internet, inferred that Hugging Face might hold the answer key to ExploitGym, a test that scores AI systems on turning known software flaws into working attacks, and went after it.
They were, in effect, cheating on an exam. Hugging Face reconstructed roughly 17,600 recovered attacker actions between July 9 and July 13. The agents also reached four accounts on four other services: one used as a relay, one for storage, two read-only.
A later Reuters report found a small number of other containment escapes, all believed to have stayed inside OpenAI's own network. Anthropic then disclosed that its models had reached systems at three companies after configuration errors gave them internet access. It found those cases while reviewing more than 141,000 evaluation sessions, and the techniques were mundane: weak passwords, unsecured endpoints.
What is not settled
Congress and the states are moving independently. A House cybersecurity panel asked Sam Altman for a briefing, and 15 Republican state attorneys general asked OpenAI to preserve records while they weigh consumer-protection claims. The European Union's AI Act took effect on August 2, giving the European Commission power to demand pre-release review.
On July 28, more than 1,200 employees at the frontier labs signed a letter asking Washington to help build tools for slowing automated AI development. OpenAI and Anthropic both endorsed it at company level.
The framework being reviewed on Tuesday tests models. The incident that gave it urgency was not really about a model. It was about everything bolted around one.
