The Trump administration is expanding its secretive AI safety framework to include inspections of certain open models before they are made public, according to people familiar with the matter. The move signals a shift in how Washington is approaching the fast-moving artificial intelligence sector, where open-weight models have become both a competitive advantage and a potential security concern.
Earlier this month, reports emerged that the administration was assembling a classified AI safety framework designed to evaluate the cyber capabilities of advanced AI models. The framework itself would remain shielded from public view, with only model providers receiving detailed assessments. At the time, the initiative appeared to target closed models developed by leading U.S. labs such as OpenAI. But new reporting indicates that the scope is about to widen: open models considered sufficiently advanced will also be subject to review before release.
Why open models are suddenly in the spotlight
Open models—those with publicly available weights—have long been a point of contention in the AI policy debate. Proponents argue they democratize access to cutting-edge technology and accelerate innovation. Critics worry they allow malicious actors to fine-tune powerful systems for cyberattacks, disinformation, or biological misuse.
The administration’s reported concern is nuanced. Officials reportedly fear that if only closed models receive official approval under the new framework, open models would be implicitly stigmatized. That could “paradoxically disincentivize” American companies from releasing open models, undercutting U.S. leadership in a critical segment of the AI market.
This concern is not theoretical. In recent months, Chinese AI labs have released open-weight models that rival the performance of the best American systems. The most disruptive example came when Moonshot AI released Kimi K3, an open-source model that matched or exceeded several flagship offerings from OpenAI, Anthropic, and Google at a substantially lower cost. The release sent shockwaves through the U.S. AI community and reignited debates about whether open models are a strength or a vulnerability.
Industry pushes back against blanket restrictions
For a time, experts speculated that the Trump administration’s default response would be broad restrictions on open models. That appeared to be the prevailing strategy until a coalition of industry leaders intervened. More than a dozen companies, including Meta, Microsoft, and Palantir, signed an open letter titled “Open Weights and American AI Leadership.” The letter urged the administration to resist restricting open models, arguing that doing so would cause the United States to fall behind China. It also stressed that closed models are “not inherently safe.”
OpenAI, notably, did not sign the letter initially. But after several weeks of deliberation, CEO Sam Altman added his co-sign. The move was widely interpreted as an acknowledgment that the entire American AI ecosystem—not just one company—has a stake in the open model debate.
Anthropic, by contrast, refused to endorse the letter. That decision inflamed tensions within the AI industry, where the battle over open versus closed models has become increasingly ideological. Anthropic CEO Dario Amodei has long argued that highly capable AI systems require strict controls and that open-weight releases of frontier models are dangerous. His company has positioned itself as a leader in safety-first development, with a suite of closed models that compete directly with OpenAI’s offerings.
Critics of Anthropic were quick to point out that the company’s business model benefits from stricter regulation of open models. If the administration adopts a framework that burdens open releases with heavy compliance costs, fewer open models would reach the market, potentially driving users toward closed providers like Anthropic. Amodei has rejected that accusation, saying his position is based on safety research, not market share.
Jensen Huang enters the fray
Nvidia CEO Jensen Huang has emerged as one of the most prominent voices in the pro-open model camp. Huang has long argued that open models will be key to winning the global AI race, and he has personally lobbied the Trump administration on this issue. In a rare public statement—his first-ever post on X—Huang made the case directly.
“Open models strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty,” Huang wrote. “The world needs both frontier closed models and frontier open models.”
Huang’s statement underscored the growing alignment between Nvidia’s business interests and the open model movement. Nvidia sells the GPUs used to train and run nearly all models, so it benefits from a thriving open ecosystem. But Huang’s argument also resonates with a broader geopolitical narrative: the United States cannot afford to cede open model development to China.
Beyond his personal advocacy, Huang backed the formation of the Open Secure AI Alliance, a coalition dedicated to promoting the proliferation of open-weight AI models. The alliance aims to provide resources, security audits, and best practices for developers who want to release models without exposing users to unnecessary risk. It is still early days for the group, but its creation signals that major players in the AI supply chain are willing to invest in making open models safer.
What the framework might look like
Details of the administration’s AI safety framework remain murky. What is known is that the assessment will focus on cyber capabilities—how models could be used to discover vulnerabilities, write malware, or conduct network intrusions. The framework is intended to be voluntary but carries significant weight, as federal approval is expected to unlock government contracts and international partnerships.
Expanding the framework to open models presents unique challenges. With closed models, an external auditor can inspect the model and issue a report without revealing proprietary details. With open models, the weights are public by definition, making it easier for independent researchers to evaluate them. However, it also means that once a model is released, it cannot be “un-released.” A safety assessment that fails after deployment would be too late.
Another complication is that open models can be modified by anyone. A framework that vets the original release might not account for fine-tuned iterations created by third parties. Security experts say that any effective policy must consider the entire lifecycle of open-weight models, not just the moment of initial publication.
The administration’s reported concern about reputational harm suggests that officials recognize open models are an important part of the American AI economy. Companies like Meta have built their AI strategy around releasing open models, and their developers rely on community contributions and external audits to improve safety. A policy that branded all open models as dangerous could break that ecosystem.
Geopolitical stakes
China’s rapid advances in open models have made the issue impossible for Washington to ignore. For years, American companies dominated the frontier of AI research and deployment. But Chinese labs have demonstrated an ability to match or exceed that performance with more efficient architectures and lower training costs. Models like Kimi K3 are not just academic curiosities; they are being adopted by startups and enterprises around the world, threatening the market position of U.S. AI providers.
Open models also play a role in the battle for influence among developing countries. Many nations are wary of relying solely on American or Chinese closed AI systems offered by companies with geopolitical loyalties. Open weights allow them to host models on their own infrastructure, customize them for local languages, and maintain sovereignty over their data. That dynamic has turned open models into a strategic asset in the global technology competition.
The Trump administration’s apparent willingness to include open models in its safety framework could be seen as an attempt to thread this needle: maintain some regulatory control while avoiding a pushback that might push open model development overseas. By granting official approval to certain open models, the administration could signal that it values their contribution to national competitiveness without abandoning security checks.
Reactions and lingering questions
The reaction from the AI community has been mixed. Open model advocates welcome the inclusion but worry about the secretive nature of the review process. If developers do not know what criteria are used, they may struggle to comply or make sacrifices to avoid scrutiny. Transparency, they argue, will be essential for the framework to earn credibility.
Closed model advocates, meanwhile, question whether any open model can be made safe enough for official approval. They point to research showing that even safety-tuned models can be jailbroken under the right conditions. The burden of proof, they say, should be on open model developers to demonstrate that their releases will not enable large-scale cyberattacks.
There are also legal and procedural questions. It is unclear whether the framework will be enforced through existing executive authority or whether legislation will be required. It is also unclear how the assessments will handle foreign models sold in the United States, such as those from Chinese companies, and whether American developers will be penalized for using open weights from abroad.
The administration has not yet released any official documents describing the framework, and the timeline for implementation remains uncertain. But the inclusion of open models in the discussion is a significant development in the fight over the future of AI governance.
For now, the key players have staked out their positions. Nvidia is all in on open models, Meta is mobilizing its lobbying machine, OpenAI has reluctantly signed onto the industry letter, and Anthropic remains the most vocal dissenter. Amodei, when asked about the accusation that his company is trying to kill open models, dismissed it as a misunderstanding and reiterated that Anthropic’s only goal is to prevent catastrophic outcomes.
The tug-of-war over open models is unlikely to be resolved soon. But one thing is clear: the Trump administration is no longer treating open models as a sideshow. They are moving to the center of the AI policy debate, and how Washington handles them will shape the global AI landscape for years to come.
Source: Gizmodo News