Anthropic Google Review Trump’s AI Framework, but Open Models Escape the Net
- Olivia Johnson

- Aug 12
- 13 min read
Anthropic and Google have reviewed a federal AI security framework that adds a 30-day checkpoint before certain frontier models reach the public. Yet the framework reportedly excludes open models, creating a major gap between the systems Washington inspects and the risks it wants to control.
The Anthropic Google discussions are not simply another round of voluntary safety commitments. They mark the Trump administration’s attempt to build a federal review process after dismantling much of its predecessor’s AI oversight structure.
The policy also arrives after a remarkable conflict between Anthropic and the federal government. Anthropic’s newest systems reportedly found vulnerabilities in sensitive government networks within hours. Washington later restricted access to those systems, then brought Anthropic back into negotiations over the rules.
That history turns a technical review process into a struggle over control. Closed-model developers face confidential government scrutiny before release. Open-model developers, including companies competing with Google and Anthropic, appear to remain outside the same process.
The central question is therefore not whether advanced AI deserves testing. It is whether a framework focused on cooperative American labs can address comparable capabilities released through open weights, foreign developers, or less cooperative vendors.
The Framework Creates a 30-Day Security Gate
The immediate change is a confidential federal review window for advanced closed models before their public release.
President Donald Trump signed the underlying executive order on June 2, 2026. It directs the government to create a voluntary process for examining national security risks in highly capable AI systems.
The order gives reviewers up to 30 days. That period is intended to let federal specialists test cyber capabilities before a model reaches a broad audience.
A frontier model is an AI system near the leading edge of general capabilities. Under the framework described to industry representatives, coverage reportedly depends on whether a model is closed, highly capable, and relevant to national security risks.
That language leaves important terms unsettled. There is no public threshold for what counts as state of the art. The administration also has not published a clear standard for deciding when a cyber capability becomes a national security concern.
According to the reported review framework, participating companies would submit models close to public release. Government reviewers would examine them inside high-security environments.
Access would be logged, and employees could face limits while the review proceeds. Several administration offices would participate rather than leaving the assessment to one agency.
The model’s timing matters. A lab would not provide a half-finished research system months before launch. It would reportedly deliver something close to the version intended for customers.
That approach gives reviewers a more realistic target. It also places the review directly on the release path, where delays or disputed findings can affect product plans.
The executive order describes participation as voluntary. It focuses on systems with advanced cyber capabilities rather than every new commercial model.
However, “voluntary” does not eliminate government leverage. Frontier labs sell to agencies, depend on access to advanced chips, and work with infrastructure providers subject to federal rules.
A company can decline to participate in principle. In practice, refusal could complicate contracts, security clearances, export decisions, or relationships with national security customers.
Anthropic welcomed the June order and said it expected to support implementation. Google and OpenAI also responded positively, presenting federal evaluation as compatible with continued AI development.
The framework therefore starts with cooperation, not a universal legal requirement. Its reach depends heavily on which developers participate and which systems the government defines as covered.
That creates the article’s central tension. Washington is building a significant checkpoint around companies already willing to discuss safety, while leaving other release paths largely untouched.
Why Anthropic Google Talks Carry More Weight Now
Anthropic and Google are under pressure because their models combine broad commercial use with increasingly consequential cyber capabilities.
The administration did not create this process after an abstract policy debate. It moved after advanced models showed an ability to identify software weaknesses at a speed that alarmed government officials.
An Anthropic model called Mythos reportedly participated in tests involving highly sensitive government systems. A U.S. official told the Associated Press that the model found vulnerabilities within hours.
Finding a flaw is not the same as exploiting it. That distinction matters because vulnerability discovery can help defenders patch systems before an attacker reaches them.
Senator Mark Warner offered a more dramatic account during a June hearing. He said the system had entered almost all the tested classified environments within hours, attributing the information to the NSA and Cyber Command leader.
The official account was narrower. It confirmed that vulnerabilities were found but did not establish that Mythos successfully exploited every affected system.
That verification gap illustrates the difficulty facing policymakers. A model can be useful for defense, dangerous in hostile hands, and hard to evaluate through one headline result.
The reported government testing occurred through Project Glasswing, an Anthropic initiative involving technology companies and other partners. The project focuses on serious software risks that advanced models can uncover or amplify.
Those capabilities pressure Anthropic in two directions. Customers want better automated security tools, while government agencies want assurance that the same tools will not accelerate offensive operations.
Google faces a related challenge. Its Gemini systems serve consumers, developers, cloud customers, and public institutions. Google DeepMind also maintains its own framework for detecting severe capabilities before deployment.
The Anthropic Google connection matters because both companies already operate internal evaluation systems. Washington is asking them to map private testing practices onto a government-controlled process.
For Anthropic, that request arrives after months of direct conflict with the administration. The company had imposed limits involving autonomous weapons and domestic mass surveillance in its government agreements.
The Pentagon sought access for all lawful purposes. Anthropic argued that legal authorization alone did not resolve every safety or civil liberties concern.
That disagreement eventually widened beyond contract language. The administration treated Anthropic as a procurement risk, while critics questioned whether the government was using national security authority to settle a policy dispute.
The relationship later shifted toward cooperation. Anthropic worked with agencies on cyber testing, restricted access to advanced models after government intervention, and joined talks on shared evaluation rules.
Google enters the framework without the same public confrontation. Its participation gives the process broader legitimacy and prevents the rules from looking like an Anthropic-specific settlement.
OpenAI, Microsoft, Meta, Nvidia, and smaller companies also reportedly attended the August discussions. Their presence shows that the framework is becoming an industry policy rather than a bilateral deal.
Still, Anthropic remains the most important test case. It is both a leading safety advocate and the company whose security warnings helped trigger government action.
If Anthropic accepts the framework, Washington can argue that outside testing complements private safeguards. If the relationship breaks down again, the process will look more like leverage than collaboration.
Anthropic Google Oversight Stops at the Open-Model Line
The framework’s defining tradeoff is that it scrutinizes closed American models while reportedly excluding open releases with similar capabilities.
Closed models keep their underlying weights, which are the learned numerical parameters, under the developer’s control. Users access them through hosted products or programming interfaces.
Open-weight models distribute those parameters more broadly. Developers can download, modify, and run them without routing every request through the original provider.
The government’s proposed process centers on the first category. That makes operational sense because a closed-model company can provide controlled access and delay a release while testing occurs.
Open-weight developers present a harder enforcement problem. Once model weights are public, no central provider can reliably withdraw every copy or restrict every user.
The reported framework addresses that problem by leaving open models outside its review system. It also says the rules should not be interpreted as restricting them after release.
That choice reduces friction for open development. It also creates an obvious incentive problem.
A company keeping tight control over its model must submit to confidential testing. A developer releasing comparable weights might face no equivalent federal checkpoint.
The distinction does not always track risk. Distribution methods affect how easily safeguards can be removed, but they do not determine a model’s underlying ability to discover vulnerabilities.
Google demonstrates why the line is complicated. The company develops closed Gemini systems alongside the open Gemma family. One organization can therefore operate on both sides of the policy boundary.
Anthropic does not publish Claude weights. Its systems remain under centralized control, making the company easier to regulate through access agreements and release reviews.
This asymmetry can reward the model provider that gives the government less control after publication. It can also place American closed-model labs at a speed disadvantage.
A 30-day review is short by regulatory standards. It is long within an industry where launch timing shapes customer commitments, benchmark attention, and developer adoption.
If OpenAI, Anthropic, or Google delays a model for review, an open competitor can use that interval to attract developers. A foreign lab could also release comparable weights without participating.
The administration appears to accept this tradeoff because it wants to preserve American AI development. Trump postponed an earlier version of the order after expressing concern about slowing the United States relative to China.
The final approach therefore targets a narrow set of controllable systems. It seeks advance visibility without building a comprehensive licensing regime.
Google DeepMind’s own safety framework shows how private governance can cover more than one release format. It tracks capability levels and calls for safety reviews when specified risks appear.
Its latest framework covers risks such as harmful manipulation, advanced AI research capabilities, and models that resist operator control. Google says its assessments combine capability testing with explicit decisions about acceptable risk.
Anthropic uses a different internal structure, but it also evaluates severe capabilities and publishes risk documentation. Both companies have institutional processes that smaller developers might lack.
The federal framework could standardize parts of those practices. Yet it does not automatically reach developers outside the participating group.
That means the main opponent is not Anthropic versus Google. It is government-reviewed closed development versus less supervised open distribution.
The policy can reduce risk among compliant frontier labs while leaving the fastest distribution channel untouched. Both outcomes can be true at the same time.
A Secret Standard Creates Its Own Security Risk
The framework asks companies and the public to trust an evaluation system whose key thresholds and procedures remain hidden.
Some secrecy is unavoidable. Publishing a detailed benchmark for offensive cyber capabilities could help attackers optimize models against the test.
The executive order allows the benchmarking process to remain classified. Sensitive findings also belong in protected environments when they concern government networks or exploitable software.
However, secrecy around test content differs from secrecy around governance. The public can understand who makes decisions, what evidence counts, and how companies appeal without seeing every exploit.
The administration reportedly does not plan to release the complete framework. Companies excluded from the August meetings may therefore have little guidance about whether future systems qualify.
This uncertainty affects more than policy specialists. Enterprise customers build roadmaps around model availability, regional access, and expected security controls.
A delayed model can disrupt software launches or procurement reviews. A restricted model can force teams to change vendors after integrating a particular programming interface.
Organizations already need a dependable way to retain internal evaluations, vendor statements, and policy updates. A searchable AI knowledge base can keep those materials connected as rules change.
The larger governance concern involves discretion. The government appears able to decide which systems qualify, who receives early access, and what response follows an adverse finding.
Juan Londoño of the Cato Institute welcomed preparation for advanced-model risks but questioned the policy’s vagueness. He warned that broad discretion might be used against a company already in conflict with the administration.
That possibility cannot be dismissed because Anthropic’s relationship with Washington has already moved between partnership and confrontation.
The national security dispute also involves a deeper authority question. A model provider may want to limit surveillance or autonomous weapon use even when a government customer claims the activity is legal.
The Trump administration has argued that deployed systems should remain under the government’s operational control. Anthropic has treated some use restrictions as an essential safety boundary.
A national security analysis from the Council on Foreign Relations describes this as a question of who controls a fielded system. Contracts, technical safeguards, and government authority all intersect.
Pre-release review does not settle that conflict. It can reveal what a model does, but it cannot decide who should control every permitted use.
The framework also risks confusing capability with intent. A model that finds severe vulnerabilities can strengthen defenders when deployed through a monitored security program.
The same capability can help an attacker when safeguards fail. Evaluators therefore need to test both technical performance and the surrounding access controls.
Anthropic’s experience demonstrates why simple labels are inadequate. Its model reportedly found serious weaknesses, yet outside security leaders argued that other available models had similar abilities.
More than 100 cybersecurity specialists reportedly opposed removing Anthropic’s defensive capabilities without a clear reason. Their argument was not that Mythos posed no risk.
They questioned whether restricting one American provider would reduce that risk when substitutes remained accessible. That is the same weakness created by excluding open releases.
A secret framework can still work if its outcomes are consistent and its authority is constrained. Without those qualities, voluntary review can become unpredictable gatekeeping.
The administration has not yet provided enough public evidence to distinguish those outcomes. That uncertainty should remain central to any assessment of the policy.
The Policy Reverses Washington’s Deregulatory Message
Trump’s framework restores a form of pre-release oversight after his administration spent months arguing that federal AI rules threatened American competitiveness.
Trump revoked major elements of the Biden administration’s AI policy after returning to office. His broader agenda emphasized rapid deployment, reduced regulation, and competition with China.
The new review process does not recreate the old framework. Biden’s approach relied heavily on reporting duties, standards work, and evaluation through civilian institutions such as NIST.
Trump’s system brings advanced cyber testing closer to national security agencies. It also limits coverage and presents participation as collaboration with industry.
Still, the direction has changed. Washington once treated advance review as an obstacle. It now treats advance visibility into certain models as necessary for national security.
The catalyst was capability, not a general change in regulatory philosophy. Anthropic’s models made the security debate concrete by performing tasks associated with skilled cyber operators.
The reversal also reflects federal dependence on private laboratories. Government agencies use infrastructure and models they did not build and cannot quickly replace.
That dependence gives companies technical control. Procurement authority, export controls, and security classifications give Washington a different kind of leverage.
The framework tries to combine those strengths. Labs provide near-release systems and technical support, while agencies contribute classified environments, threat information, and national security expertise.
This arrangement can produce better evaluations than either side could conduct alone. A company cannot fully reproduce the intelligence government agencies hold about active adversaries.
Government evaluators also need a lab’s engineers to understand model behavior, system controls, and the limitations of a particular test. Cooperation is therefore more useful than a simple compliance checklist.
Yet cooperation becomes fragile when the parties disagree about acceptable use. Anthropic’s Pentagon dispute shows that shared security goals do not guarantee shared policy boundaries.
Google has avoided an equivalent public rupture, but it faces the same structural question. A private lab can identify unacceptable risk while a government buyer prioritizes operational flexibility.
OpenAI faces it as well. So do cloud providers that host models and enterprise customers that depend on stable access.
The competitive context adds another complication. Anthropic revised its flagship safety policy in early 2026, removing a categorical commitment that might have stopped training without adequate safeguards.
Company leaders argued that unilateral pauses would not improve safety if competitors kept advancing. The revised policy emphasizes roadmaps, recurring risk reports, and efforts to match or exceed peer protections.
That change made coordinated rules more important. A company cannot sustain strict limits indefinitely when rivals face lower costs for moving faster.
The Trump framework attempts to supply coordination, but only for selected participants. It does not establish one binding threshold across Anthropic, Google, OpenAI, open-model developers, and foreign labs.
This leaves the government in a hybrid position. It has reintroduced oversight while preserving a strong presumption against broad regulation.
The result is neither pure deregulation nor a comprehensive safety regime. It is a negotiated checkpoint built around the companies Washington can reach.
That approach can respond quickly to a specific cyber threat. It is less suited to governing capabilities that spread across model formats and national borders.
The Anthropic Google review is therefore a policy experiment. Its success depends on whether narrow cooperation can produce real security without simply shifting risky development elsewhere.
Three Signals Will Show Whether the Framework Works
The next test is whether Washington can turn a closed-door agreement into consistent security outcomes across releases, companies, and model formats.
The first signal is the treatment of the next advanced closed-model launch. A participating lab should submit a system close to release, complete the review, and explain any resulting restrictions.
The government does not need to reveal classified exploits. It should disclose whether the process changed access controls, release timing, or the model’s available capabilities.
A clear outcome would strengthen the case for targeted pre-release testing. An unexplained delay or sudden restriction would reinforce concerns about discretionary enforcement.
The second signal is how the administration handles an open model with comparable cyber capabilities. This is the largest unresolved weakness in the current design.
Washington could create voluntary evaluation tools for open developers, establish distribution safeguards, or focus on downstream infrastructure providers. Each path carries technical and political costs.
Doing nothing would weaken the framework’s security logic. It would suggest that release format matters more than the capability officials claim to fear.
The third signal is whether Anthropic and the administration maintain cooperation during the next disagreement. Their relationship has already moved from contract conflict to model restrictions and back toward joint rulemaking.
A stable process would let technical findings survive political tension. A breakdown would show that the framework depends too much on informal trust between current officials and company leaders.
Google’s behavior will provide a useful comparison. If both companies receive similar treatment for similar systems, the policy will look more like a standard.
If Anthropic faces different consequences because of its earlier dispute, critics will see the review as a tool of executive leverage.
Enterprise buyers should watch these signals instead of assuming that “voluntary” means inconsequential. Model access, launch dates, and regional availability can change when national security reviews intervene.
Developers should also track which capabilities trigger attention. Automated vulnerability discovery, exploit generation, autonomous action, and resistance to operator control are likely to receive close scrutiny.
Knowledge workers face a related problem. A model can remain available while particular tools, connectors, or advanced modes receive limits.
Teams should document which model version supports each workflow and retain alternatives for critical tasks. They should also separate vendor claims from government findings and independent evidence.
The Anthropic Google discussions have created a genuine federal checkpoint, but they have not created a complete security system. Closed-model reviews cover only one route through which advanced capabilities reach users.
A credible framework must eventually explain why similar capabilities receive different treatment. It must also separate necessary secrecy from unaccountable decision-making.
For now, readers should ask three practical questions whenever a major model approaches release. Was it covered, what changed after testing, and could an equivalent open system bypass the process?
Those answers will reveal whether the Anthropic Google framework reduces national risk or merely concentrates oversight on the most cooperative companies. Keep watching the next model launch, the next open release, and the next dispute between a frontier lab and Washington.


