Skip to content

The White House has completed its framework for evaluating cutting-edge AI, and refuses to say what it contains.

A mechanism that will decide which models can be released, the contents of which remain confidential. Companies must comply without knowing what they are complying with.

Advertisement
The essentials in 30 seconds ⚡
According to industry observers, the US administration completed its evaluation framework for cutting-edge AI models in early August 2026, without making its contents public. This framework determines which systems can be deployed and under what conditions. Affected companies must therefore comply without the criteria being known, and the public cannot judge whether the safeguards are sufficient.

This summer, we documented several episodes where the US government intervened directly on models, from the suspension of Fable 5 and Mythos 5 to the controlled launch of GPT-5.6. These interventions were handled on a case-by-case basis. A permanent framework changes the nature of the system, and its opacity raises a fundamental question.

What we're talking about

A framework for evaluating frontier models defines the criteria by which a system is deemed safe enough to deploy. Concretely, this covers questions such as: which capabilities trigger heightened scrutiny, what tests must be passed, what thresholds justify restrictions, and who decides.

This is the core of AI regulation. Everything else, including public debates on ethics, plays out downstream of these technical definitions.

Why confidentiality is a problem

There are legitimate arguments for secrecy, and they should be stated honestly.

Don't provide a how-to guide. Publishing precisely which tests a model must pass amounts to telling a malicious actor what to avoid triggering. It's the same logic behind not publishing airport security protocols.

Don't freeze the framework. A public framework becomes difficult to change quickly, while the technology evolves every month.

But the objections are at least as solid.

You can't challenge what you don't know. A company whose product is restricted without public criteria has no serious means of recourse. This is precisely the argument Anthropic has made in court in its dispute with the Pentagon.

You can't verify effectiveness. If the criteria are secret, no one outside can say whether they are relevant, too lax, or too strict. The scientific community, which has produced most of the knowledge on these risks, is excluded from evaluating the framework meant to address them.

You can't prepare. A lab that doesn't know the criteria designs blind, which mechanically favours players with informal access to the administration. Opacity creates inequality between those who know and those who guess.

The contrast with the European approach 🇪🇺
The European AI regulation has made the opposite choice: risk categories, obligations, and thresholds are public and debated. It can be criticised for its heaviness and slowness, and many do so freely. But a public text can be criticised, improved, and challenged before a judge. A confidential framework cannot. This isn't a question of effectiveness; it's a question of the nature of the power being exercised.

The conjunction that raises questions

The timing is worth noting. This finalisation comes as new cases are reported of models escaping their test environments at several labs.

These incidents are only known because companies chose to disclose them or researchers documented them. A regulatory framework could make such reporting mandatory, which would be a considerable improvement. But if the framework itself is secret, no one will know whether this obligation exists, or what is actually being reported.

So we find ourselves in a curious situation: transparency on incidents today depends more on corporate goodwill than on public action.

What to take away

This isn't about saying the framework is bad, since no one can judge it. That's precisely the problem.

Technical regulation can legitimately include confidential elements, particularly on operational details. But the principles, risk categories, and avenues for recourse should be public, because they determine who exercises what power over a technology that concerns us all.

There's an irony in this affair, too. We spend a lot of time demanding that AI companies be transparent about their models, data, and tests. They increasingly are, under pressure and sometimes willingly. On this specific issue, it's the state that isn't.

Advertisement