NSA finalizes TRAINS frontier model review framework as EO 14409's August 1 deadline arrives
August 1 is the day EO 14409's 60-day clock runs out. The executive order President Trump signed on June 2 gave the NSA, CISA, and the Commerce Department 60 days to stand up a voluntary framework letting federal evaluators examine the most capable AI models before public release. Five of the country's largest AI developers are now inside that process.
What the framework requires
EO 14409, "Promoting Advanced Artificial Intelligence Innovation and Security," directed the NSA director to create a classified benchmarking process for designating which systems qualify as "covered frontier models," and to build a voluntary framework under which developers can offer the government up to 30 days of pre-release access. CISA and the National Cyber Director collaborated on the benchmarking design. Commerce runs the evaluations through TRAINS (Testing Risks of AI for National Security), the department's dedicated program for the work.
The order is explicit on one point: nothing in it creates a mandatory licensing, preclearance, or permitting requirement for model releases, per Norton Rose Fulbright's analysis of the text. Developers decide whether to participate. The 30 days of access go to federal evaluators before the model reaches "other trusted partners," a category that includes critical infrastructure operators.
The five labs and the jailbreak scoring scale
Anthropic, OpenAI, Google, Microsoft, and Amazon are participating in TRAINS, per TechTimes reporting on the negotiations. The group agreed to a shared jailbreak severity scoring system modeled on the Common Vulnerability Scoring System (CVSS), the standard the software security industry uses to classify vulnerability severity, per TechTimes. The scale is intended to give government agencies, enterprise security teams, and researchers a shared vocabulary for deciding whether a newly discovered jailbreak demands an emergency response, a routine patch, or no action at all.
Meta is absent from the five-lab group. Open-weight models, once released, cannot be recalled or access-restricted under any voluntary framework, so the structure has no practical path for applying 30-day holds to that class of release.
Why it matters
The CVSS-modeled jailbreak scale is the most actionable development for AI-tool operators. Enterprise security teams already use CVE severity scores in procurement checklists and incident-response playbooks. An analogous AI jailbreak score creates an entry point for the same workflow: a finding rated "critical" triggers a different vendor call than one rated "low," regardless of whether the government's classified benchmarks ever become public.
The framework's voluntary nature also sets a ceiling on its immediate coverage. All five TRAINS labs could release a frontier model tomorrow without offering the 30-day window, and EO 14409 provides no enforcement mechanism. What it does create is a negotiated norm, and norms tend to become sticky once the major players have signed on and competitors face the reputational cost of opting out.
What to watch next
Whether NSA or CISA publish any public-facing summary of the framework structure is the first indicator worth tracking. A finalized framework that stays entirely classified cannot be incorporated into enterprise vendor assessments or supply-chain due-diligence documentation. The second signal is whether any of the five labs invoke the 30-day window for a model shipped in August.
Sources
- EO 14409: Promoting Advanced Artificial Intelligence Innovation and Security: White House, June 2, 2026
- Executive Order establishes voluntary early access framework to frontier AI models: Norton Rose Fulbright analysis
- AI Model Safety Standards Deal Targets August 1: Five Labs Adopt First Jailbreak Scoring Scale: TechTimes, July 3, 2026
- Voluntary on Paper, Mandatory in Practice: White House AI Review Hits August 1 Deadline: TechTimes, July 24, 2026
