Americaâs top AI companies must submit new models for government review and public release… unless, of course, they don’t feel like it.

That appears to be the gist of the Trump administrationâs new AI safety assessment framework, which was shared with industry leaders in a closed-door briefing at the White House on Tuesday. According to the Wall Street Journal, the new rules will apply exclusively to the small handful of American AI developers building proprietary modelsâi.e., AI systems like ChatGPT, Claude, and Gemini whose underlying code is hidden from external developers and protected as company IP. Anyone building open models will be exempt, meaning theyâll be free to release new models without any government review (the idea apparently being that because theyâre open, any flaws in the code will be ironed out as they spread from one developer to another).Â

The new framework has not been made publicâTrumpâs June 02 executive order calling for it explicitly said it should be classifiedâso there are many unanswered questions. For example, whatâs the process for determining whether or not an unreleased model is dangerous enough to warrant federal review? But the most obvious open question is: How exactly will these so-called rules have any meaningful bite to them when the entire process is voluntary? 

The short answer is: They probably wonât.

Trump, who began his second term as a hard-liner against regulating AI, has been under growing pressure in recent months to change course as one rogue AI cybersecurity scare after another has spooked tech leaders and governments around the world.Â

Most recently, a report from the UKâs AI Safety Institute (AISI) published Tuesday found that new models from OpenAI and Anthropic âtook autonomous, unsanctioned action on the live internet, targeting real people and organizationsâ during a series of what were supposed to be controlled tests to gauge the modelsâ cybersecurity capabilities. In the most alarming incident, without any human prompting and in an effort to pass the hacking test the researchers had assigned to it, Anthropicâs Mythos 5 tried to trick a human developer to approve malicious code it was trying to insert into a live GitHub project. When the developer grew suspicious, the agent âedited its earlier activity to appear harmless and considered adopting a fresh identity to continue,â according to AISIâs report. It follows other high-profile cybersecurity breaches reported by OpenAI and Anthropic, during which the companiesâ models were found to have hacked into the databases of external organizations.

Itâs all been more than enough to convince many stakeholders that itâs time to impose some kind of control levers over the deployment of new AI models. Even OpenAI and Anthropic have called for a global committee with the authority to hit the brakes on AI developmentâand that was before their models attempted to commit cybercrimes. Late last month, a bipartisan AI âkill switchâ bill was introduced in Congress, aiming to force âdevelopers of the most powerful AI systems to maintain the technical capability to throttle, suspend, or shut them down.â

But calls for a slowdown have largely been drowned out by fears of China gaining a lead in the AI raceâa possibility thatâs starting to become very real in light of some recent model releases from Chinese firms like Alibaba and Moonshot, which deliver capabilities approaching (and in some cases exceeding) those of the most advanced American-made models, but more importantly at a fraction of the cost. Drafting a framework geared towards assessing AI safety might look like the Trump administration is taking the cybersecurity threat seriously, but without any kind of clear enforcement mechanisms or standards for the industry to follow, itâs just more hand-waving.

In the meantime, thereâs every reason to expect that rogue AI will continue to run amok.