EO 14409 — Promoting Advanced Artificial Intelligence Innovation and Security

Jurisdiction:
United States
voluntary
Effective:
Jun 2, 2026
Authority:
Executive Office of the President
Official text

Obligations Covered

Conformity Assessment Risk Assessment Incident Reporting

Timeline

MilestoneDateNotes
SignedJun 2, 2026President signed; assigned EO 14409
Published in Federal RegisterJun 5, 2026FR Doc. 2026-11415 (federalregister.gov/documents/2026/06/05/2026-11415/)
30-day agency deadlinesJul 2, 2026CNSS, Dept. of War, CISA directives; Treasury AI cybersecurity clearinghouse; OMB grant determination; (OPM Tech Force expansion within 60 days)
GOLD EAGLE clearinghouse operational launchJul 14, 2026White House announced the operational vulnerability-coordination clearinghouse; intake and prioritization had begun
60-day agency deadlinesAug 1, 2026Treasury/NSA/CISA classified frontier benchmarking + voluntary covered-frontier-model framework
Section 2 (cyber defense of federal systems) and Section 4 (AG enforcement of computer-crime statutes against malicious AI use) are directives to federal agencies and create no private-sector compliance surface; they are not tracked as provisions. Section 3(c) disclaims any mandatory governmental licensing, preclearance, or permitting for AI model development or release, and the general provisions disclaim any enforceable right or benefit. The frontier-model framework remains pending publicly documented agency design; the GOLD EAGLE clearinghouse launched operationally on 2026-07-14.

Related Regulations and Standards

Related instruments are selected from shared compliance obligations and jurisdiction coverage.

Voluntary Frontier Model Pre-Release Government Access #

Obligation:
Conformity Assessment
voluntary
Effective:
Jun 2, 2026
Risk tier:
general-purpose
Scope:
AI industry participants, open-source software partners, and critical-infrastructure operators participating in GOLD EAGLE vulnerability coordination
upcominghigh-impact
Establishes a voluntary framework under which frontier developers may engage the government to have models designated "covered frontier models" and provide up to 30 days of pre-release access for evaluation before other trusted partners. The framework itself does not yet exist — Treasury, NSA, and CISA must design it within 60 days. Section 3(c) expressly disclaims any mandatory licensing, preclearance, or permitting requirement, so participation is opt-in. Worth watching: a voluntary pre-release evaluation regime can harden into a de facto procurement or trusted-vendor expectation.

Requirements

RequirementDetails
Voluntary pre-release accessParticipating developers may provide the federal government access to covered frontier models for up to 30 days before planned release
Confidentiality protectionsAccess is subject to confidentiality, cybersecurity, insider-risk, and intellectual-property protection, use, and nondisclosure requirements
Trusted-partner sequencingDesignated covered frontier models receive government evaluation before access is extended to other trusted partners

Penalties

ViolationFine
N/AVoluntary framework; no penalties. Section 3(c) disclaims mandatory licensing/preclearance/permitting; general provisions create no enforceable rights.

Covered Frontier Model Designation and Benchmarking #

Obligation:
Risk Assessment
voluntary
Effective:
Jun 2, 2026
Risk tier:
general-purpose
Scope:
providers
upcoming
Directs Treasury, NSA, and CISA to develop and maintain a classified benchmarking process that assesses the advanced cyber capabilities of AI models and sets the threshold for designating a "covered frontier model." This is the first federal mechanism defining a frontier-model threshold by capability rather than compute. Developers engage the designation process voluntarily; assessments are shared with developers as appropriate. The benchmark and threshold are pending — agencies have 60 days to develop them.

Requirements

RequirementDetails
Classified benchmarkingGovernment to develop and maintain a classified process benchmarking the advanced cyber capabilities of AI models
Threshold designationThe benchmark sets the threshold at which a model is designated a "covered frontier model"
Assessment sharingCapability assessments are shared with AI developers as appropriate

Penalties

ViolationFine
N/AVoluntary designation; no penalties. Designation does not trigger any mandatory licensing or permitting (§ 3(c)).

AI Cybersecurity Clearinghouse for Vulnerability Coordination #

Obligation:
Incident Reporting
voluntary
Effective:
Jun 2, 2026
Risk tier:
all
Scope:
providers
cross-domain
The White House launched the clearinghouse as GOLD EAGLE on 2026-07-14. Open-source software partners and critical-infrastructure companies built the coordinated system, which had already begun receiving and prioritizing vulnerabilities from across sectors, coordinating scanning verification, and distributing prioritized threat and remediation information. Participation remains voluntary and creates no reporting mandate.

Requirements

RequirementDetails
Vulnerability intake and prioritizationGOLD EAGLE receives identified cybersecurity vulnerabilities from across industries and sectors and prioritizes action
Coordinated scanning verificationGovernment and industry coordinate scanning verification and reduce duplicative scanning
Remediation informationGOLD EAGLE distributes prioritized and actionable threat and remediation information to federal and private-sector defenders
Patch coordinationOpen-source software and critical-infrastructure participants coordinate to receive and patch vulnerabilities

Penalties

ViolationFine
N/AVoluntary collaboration; no penalties. General provisions create no enforceable rights.
Cite this regulation

Permalink: https://everyailaw.com/regulation/us-eo-ai-innovation-security/

JSON: https://everyailaw.com/api/v1/regulations.json

Attribution: EveryAILaw, PAICE.work PBC. “EO 14409 — Promoting Advanced Artificial Intelligence Innovation and Security”, EveryAILaw.com, Sep 1, 2026. https://everyailaw.com/regulation/us-eo-ai-innovation-security/

Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.