Section 2 (cyber defense of federal systems) and Section 4 (AG enforcement of computer-crime statutes against malicious AI use) are directives to federal agencies and create no private-sector compliance surface; they are not tracked as provisions. Section 3(c) disclaims any mandatory governmental licensing, preclearance, or permitting for AI model development or release, and the general provisions disclaim any enforceable right or benefit. The provisions below are voluntary and their operating frameworks are pending agency design (30–60 days).
Related Regulations and Standards
Related instruments are selected from shared compliance obligations and jurisdiction coverage.
Establishes a voluntary framework under which frontier developers may engage the government to have models designated "covered frontier models" and provide up to 30 days of pre-release access for evaluation before other trusted partners. The framework itself does not yet exist — Treasury, NSA, and CISA must design it within 60 days. Section 3(c) expressly disclaims any mandatory licensing, preclearance, or permitting requirement, so participation is opt-in. Worth watching: a voluntary pre-release evaluation regime can harden into a de facto procurement or trusted-vendor expectation.
Requirements
Requirement
Details
Voluntary pre-release access
Participating developers may provide the federal government access to covered frontier models for up to 30 days before planned release
Confidentiality protections
Access is subject to confidentiality, cybersecurity, insider-risk, and intellectual-property protection, use, and nondisclosure requirements
Trusted-partner sequencing
Designated covered frontier models receive government evaluation before access is extended to other trusted partners
Penalties
Violation
Fine
N/A
Voluntary framework; no penalties. Section 3(c) disclaims mandatory licensing/preclearance/permitting; general provisions create no enforceable rights.
Directs Treasury, NSA, and CISA to develop and maintain a classified benchmarking process that assesses the advanced cyber capabilities of AI models and sets the threshold for designating a "covered frontier model." This is the first federal mechanism defining a frontier-model threshold by capability rather than compute. Developers engage the designation process voluntarily; assessments are shared with developers as appropriate. The benchmark and threshold are pending — agencies have 60 days to develop them.
Requirements
Requirement
Details
Classified benchmarking
Government to develop and maintain a classified process benchmarking the advanced cyber capabilities of AI models
Threshold designation
The benchmark sets the threshold at which a model is designated a "covered frontier model"
Assessment sharing
Capability assessments are shared with AI developers as appropriate
Penalties
Violation
Fine
N/A
Voluntary designation; no penalties. Designation does not trigger any mandatory licensing or permitting (§ 3(c)).
Directs the Secretary of the Treasury to form an AI cybersecurity clearinghouse, in voluntary collaboration with the AI industry and critical-infrastructure operators, to coordinate vulnerability scanning, validate discovered vulnerabilities, and prioritize remediation and patch distribution. To be formed within 30 days. Participation is voluntary, but for AI providers and critical-infrastructure operators it functions as a coordinated channel for software-vulnerability discovery and remediation.
Requirements
Requirement
Details
Coordinated scanning
Participants coordinate and deconflict scanning for software vulnerabilities through the clearinghouse
Vulnerability validation
Discovered vulnerabilities are discovered and validated via the clearinghouse
Remediation coordination
The clearinghouse coordinates and prioritizes remediation and the distribution of vulnerability patches
Penalties
Violation
Fine
N/A
Voluntary collaboration; no penalties. General provisions create no enforceable rights.