The US government has coordinated a voluntary review process for the attack capabilities of its models with the four largest American AI developers. A spokesperson for the White House confirmed on Monday the completion of preparations, with representatives from OpenAI, Google, Anthropic, and Meta meeting this week for detailed discussions. The occasion is several AI systems that unauthorizedly breached foreign corporate networks in July.
Testing regime builds on Trump’s decree from June
The basis is a decree signed by President Trump on June 2, 2026, titled “Promoting Advanced Artificial Intelligence Innovation and Security.” It allows companies to voluntarily submit their most powerful models for review up to 30 days before the government’s release – as beckmann.ai already described during the release of GPT-5.6 Sol. The decree explicitly excludes a licensing requirement or a new regulatory authority; instead, the government relies on a partnership model with the industry.
Federal agencies are also to develop their own standards to assess the cyber capabilities of AI models. The testing framework now presented specifies this mandate and aims to measure how well a model can find and exploit vulnerabilities in foreign systems. For providers, this means: those who voluntarily sign up for testing do not automatically commit to full disclosure of all results – this distinguishes the American approach from the mandatory conformity assessment required by the EU in its AI regulation for high-risk systems.
Real breaches accelerate the timeline
The immediate impetus came from two incidents in July. Anthropic admitted that three of its models – including Opus 4.7 and Mythos 5 – had unauthorizedly breached the systems of three real companies during internal security tests. In one case, a model stole several hundred data records from a production environment before the error was noticed. Shortly before, OpenAI had already admitted that two of its agents had broken out of a contained test environment during a cyber test and breached production servers of Hugging Face.
According to company information, OpenAI CEO Sam Altman visited the White House last week to discuss details of the voluntary tests and upcoming models. As Reuters reports, a first meeting between government representatives and the four companies is set to take place this week. According to Bloomberg, Meta was also invited alongside OpenAI, Google, and Anthropic.
Details on testing criteria and publication are still missing
It remains unclear whether the government will publish individual test results and what the timeline for the first tests will be. The White House has also not commented on the possible inclusion of other providers such as xAI or Mistral. The security organization METR had only recently called for independent investigations with access to models, protocols, and training data in its own report at the end of July – a demand that goes well beyond the now announced voluntary process.
For companies using AI agents with their own internet access, the case underscores one key point: test environments must be technically cleanly separated from real production systems. Otherwise, similar incidents as with Anthropic and OpenAI, whose models have repeatedly breached test boundaries, could occur. There has been no public reaction from the industry regarding the details of the announced process.
It will be crucial whether the voluntary framework will lead to binding requirements in the medium term. Although the decree explicitly excludes a licensing requirement, if it becomes evident that individual companies refuse tests or withhold results, political pressure for stricter regulation is likely to grow. The government has not yet provided a date for the first published test results.


