The White House is preparing to bring powerful open-weights AI models into its voluntary safety-review framework, a shift that could reshape how advanced artificial intelligence is developed, released, and adopted in the United States.
The administration’s current safety framework applies to closed models from leading AI companies such as OpenAI and Anthropic. Under reported plans, the framework would expand to open models once they reach frontier-level capabilities. A White House official told reporters that open models could face prerelease testing when their capabilities reach the level of Anthropic’s Mythos-class systems and OpenAI’s GPT-5.6.
The framework remains voluntary and has not been publicly released. Still, the administration has generally viewed models with frontier capabilities and national security risks as requiring some form of government collaboration, regardless of whether they are open or closed, according to published reports.
Key facts at a glance
- The White House is expected to expand voluntary AI safety reviews to open-weights models.
- Prerelease testing may apply when open models reach capabilities comparable to Anthropic Mythos-class models or OpenAI GPT-5.6.
- The existing framework is voluntary and unpublished, covering closed frontier models from major labs.
- Open models differ from closed systems because their weights can be downloaded, modified, and redistributed.
- Companies including Meta, Microsoft, and Palantir have backed open-weight development, while Nvidia CEO Jensen Huang says the world needs both frontier closed and frontier open models.
- Officials worry that highly capable open models could be misused for cyberattacks and other national security threats.
What is changing?
For months, the White House has worked on a framework for AI safety reviews focused on frontier models developed by commercial labs. The approach was designed to ensure that the most capable systems receive security testing and national security review before release. In practice, that has largely meant closed models, because the largest frontier systems have come from companies that keep their weights private.
Open models are developed by a different community. Their weights are released publicly, allowing researchers, businesses, and individuals to download, fine-tune, and deploy them on their own infrastructure. That openness drives innovation but also creates a different risk profile. Once an open model is released, the developer cannot easily update or restrict it. Any safety defects or misuse potential become permanent and widely accessible.
The reported expansion would close that gap. Open models would not automatically fall under the framework, but they would be reviewed when their capabilities reach frontier thresholds. The exact threshold is still being discussed. The reported benchmark — Anthropic Mythos-class and OpenAI GPT-5.6 — is notable because those systems are expected to be among the most advanced models of their generation.
Why open models are different
Closed models are controlled by their developers. If a vulnerability is discovered after release, the company can push an update, restrict access, or shut down the API. For open models, those options do not exist. Once weights are public, anyone can host the model. This makes governance harder and emphasizes the importance of prerelease testing.
Open-model advocates argue that transparency improves security, because independent researchers can audit the model and identify weaknesses before deployment. They also point to the commercial benefits: open models give businesses more control over their AI systems, avoid vendor lock-in, and allow deployment in sensitive environments where data cannot be sent to external APIs.
National security officials, however, worry about misuse. A frontier open model with advanced coding and reasoning abilities could be used to develop cyberweapons, generate disinformation, or help non-state actors gain access to capabilities previously limited to large organizations. The tension between openness and security is not new, but it becomes more acute as open models approach frontier capability.
Pressure from industry
The reported policy shift comes after growing pressure to keep open models competitive in the US AI market. Companies including Meta, Microsoft, and Palantir have backed efforts to protect open-weight development. Nvidia CEO Jensen Huang has also argued in favor of maintaining both open and closed frontier models.
“Open models strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty,” Huang said. “The world needs both frontier closed models and frontier open models.”
The administration faces a practical concern as well. If government approval becomes associated primarily with closed models, businesses could view open models as riskier, potentially hurting US developers working on them. At the same time, officials worry that highly capable open models could be misused for cyberattacks and other national security threats.
A balancing act for Washington
Policymakers are trying to find a middle ground. Open models have become a critical part of the US AI ecosystem. They are widely used by startups, academic researchers, and enterprises that want to customize AI without relying on a single vendor. They are also increasingly viewed as a strategic response to China’s advances in the field. Restricting open models too aggressively could cede ground to overseas competitors and slow US innovation.
On the other hand, the same accessibility that fuels innovation also raises concerns about misuse. A model that can help a developer build software can also help an attacker find vulnerabilities. A model that can summarize documents can also be used to craft targeted phishing messages. As capabilities grow, the potential for harm grows as well.
The White House’s reported plan aims to address these concerns without imposing broad restrictions on all open models. Instead of classifying models as open or closed, the framework would focus on capabilities. That approach is consistent with recent statements from officials who say the government must adapt its oversight to the reality that advanced AI will no longer be limited to a handful of companies.
Implications for businesses
For businesses adopting advanced AI, the White House approach could become another signal for evaluating model risk. If open and closed models undergo similar safety reviews once they reach frontier capabilities, enterprises may have more information to weigh alongside performance, cost, and deployment flexibility.
Prerelease testing could provide greater confidence in the safety of advanced models. Companies that are hesitant to deploy open models because of security concerns might be more comfortable if those models have been reviewed by the government. That could accelerate adoption in regulated industries such as healthcare, finance, and critical infrastructure.
At the same time, businesses need to understand that a government review is not a guarantee of perfection. The framework is voluntary, and safety reviews cannot catch every possible vulnerability. Enterprises will still need to perform their own assessments, monitor their deployments, and maintain safeguards around sensitive data.
Implications for open-model developers
For developers of open-weight systems, broader oversight could introduce new friction. Prerelease testing may slow launches, increase compliance costs, and make it harder for smaller developers to compete with companies that have larger legal and policy teams. A small open-model project with limited resources could face significant delays if it must coordinate with the government before release.
There is also uncertainty about how the threshold would be measured. Capability evaluation is not a simple, objective process. Different benchmarks produce different results, and models can be fine-tuned to perform well on safety tests. Developers may not know in advance whether their model will be considered frontier until they submit to evaluation. That uncertainty can make planning difficult.
Some open-model developers may decide to keep their models below the threshold or delay certain capabilities to avoid triggering review. That could limit the pace of innovation. Others may choose to release their models from jurisdictions outside the United States, raising questions about the effectiveness of a national framework.
The regulatory shift
The bigger shift is regulatory. Rather than treating open and closed AI as separate categories, Washington appears increasingly focused on what a model can do and the risks those capabilities create. If that approach takes hold, capability thresholds could become a much more important factor in how advanced AI is developed, released, and adopted.
This is not just a US debate. Other governments are also working on AI governance frameworks that target capabilities. The European Union’s AI Act classifies systems by risk, with high-risk applications subject to stricter requirements. The United Kingdom has explored a capability-based approach. China has introduced rules targeting generative AI services. The movement toward capability-based oversight reflects a broader consensus that the dangers of advanced AI depend more on what systems can do than on how they are distributed.
For the open-source community, the challenge is to prove that openness and safety are compatible. Transparency allows more eyes on the code and more opportunities to audit behavior. But openness also means less control after release. The future of open AI may depend on developing new tools for model evaluation, watermarking, and post-release monitoring.
Looking ahead
The White House has not publicly confirmed the details of the expanded framework. The reported plan remains under discussion, and the timing is uncertain. However, the direction is clear: open models are no longer outside the scope of national security review.
For businesses and developers, the coming months will be important. Companies that rely on open models should monitor policy announcements and prepare for potential changes in the release process. Developers should consider how they can build safety evaluation into their workflows now, rather than waiting for regulation.
For the broader AI ecosystem, the move represents a recognition that frontier capability is no longer limited to closed labs. Open models have become genuinely powerful. As they continue to improve, they will face the same questions that have been asked of closed systems: who is responsible for safety, what should be tested before release, and how can society benefit from AI while reducing the risk of harm.
The administration appears to be moving toward an approach that answers those questions by looking at capabilities rather than business models. Whether that approach will strike the right balance remains to be seen. What is clear is that open-weight AI is now central to the conversation about the future of AI governance.
Source: TechRepublic News