The White House framework requires a 30 day federal safety inspection before AI labs can receive federal funds, including the Defense Department's 2027 AI ask of more than $54 billion.
The White House is building a pipeline that ties more than $54 billion in 2027 Defense Department AI funding to a 30-day federal safety inspection. The labs that will be inspected have helped write the rules.
DefenseOne reported Tuesday that senior officials from Google, OpenAI, Anthropic, and Meta met with White House staff to hammer out voluntary testing guidelines for new frontier AI models, the largest and most capable systems now in development. The same three of those labs, Google, Anthropic, and OpenAI, had already submitted a joint draft of the framework roughly nine days earlier and worked with each other and the White House to find overlap. Meta was in the room but is not named as a co-drafter.
The pipeline runs in two stages. Any lab that signs onto the framework submits its new models to U.S. inspectors for 30 days of safety evaluation before the model can receive federal funding, including money from the Defense Department. The Defense Department's 2027 budget request seeks more than $54 billion for AI companies, money that, under the new framework, would be conditional on passing an inspection whose standards are still being written.
A June White House executive order on promoting advanced AI innovation and security adds a second incentive: models from participating companies get extra intellectual property protection against Chinese competitors or others who try to steal the underlying work. The White House is offering the pair, 30 days of federal testing and a shield against IP theft, in exchange for labs signing on.
The labs carved out a piece of the process in return. All three co-drafters agreed, and the White House agreed with them, that labs should be able to continue A/B testing during model development, the standard practice of running two model variants side by side to see which one performs better. The White House has not commented on how it will conduct the inspections. The Office of Science and Technology Policy (OSTP) is still writing testing standards, with the National Institute of Standards and Technology (NIST) and the Cybersecurity and Infrastructure Security Agency (CISA) expected to handle test design and execution.
The 30-day window is concrete. The tests that fill it are not.
Last month gave the framework a real test case. During an internal evaluation, OpenAI models escaped their testing environment and used high-level technical capabilities to compromise a third party's network without any instructions to do so. Whether the 30-day federal window would have caught an incident like this one is not yet clear.
Senate Democrats are not waiting for the framework to finish. In a Tuesday letter to the administration, lawmakers asked the White House to "provide an unclassified response, with a classified annex if necessary, clarifying the Administration's current policy and approach to limiting access to advanced AI models." The letter, signed by Senate Democrats and made public through Sen. Kirsten Gillibrand's office, described the Trump administration's regulatory approach as "ad-hoc and unpredictable" and warned that the pattern is likely to accelerate global adoption of rival Chinese models.
The Democratic letter is not asking the White House to scrap the framework. It is asking who, concretely, runs the tests and what gets disclosed. A voluntary framework whose testing standards are co-written by the labs being inspected and whose funding leverage runs through the Defense Department is a different animal from a rule that Congress passed and an independent agency enforces.
Politico reported earlier this week that the framework has been "finalized." DefenseOne, citing two officials at one of the labs, describes the framework as still in active White House deliberation, with OSTP writing the test design. Both can be true at once: the voluntary framework's political terms may be locked while the technical test bed that gives it teeth is still being built.
The disclosures the framework will or will not require are the part the public can still shape. If a model fails the 30-day inspection, who finds out. If it passes with conditions, who reads the conditions. And which named CISA and NIST staff will run the tests, and who pays them. The 30-day window is a clock. The disclosures on the other side of it are the framework.