Connect with us

NEWS

OpenAI and Anthropic Rewrite Frontier Rules Together

Rivals OpenAI and Anthropic submit joint edits to the Trump AI framework before the August 1 deadline, blending China warnings with closed-model advantages.

Published

on

OpenAI, Anthropic and Google submitted one joint red-line document last week to the White House draft on frontier AI models. The August 1 deadline under President Trump’s June executive order now drives the intense lobbying.

Sam Altman heads to Washington this week for meetings with Treasury Secretary Scott Bessent, Commerce Secretary Howard Lutnick and bipartisan senators. The unusual unity among commercial rivals arrives just after export controls on Anthropic and release limits on OpenAI’s latest model were lifted.

That sequence matters. The same firms that spent June and July absorbing abrupt federal interventions are now writing the voluntary rules meant to replace them. The joint document is both a policy submission and a bid for predictability before the 60-day clock runs out.

The Joint Red-Line Document

People close to the administration told Politico the three firms produced a single set of extensive edits to the draft from the Office of the National Cyber Director. “They produced one joint red-line document,” one person said, calling it an unusual display of unity.

The companies want the framework to apply broadly, covering rivals such as Meta and xAI. Qualifying models would face voluntary government review at least 30 days before launch if they show significant cybersecurity or national security capabilities.

  • Common evaluation process for consistent safeguards
  • Thresholds set by industry-wide performance, not company size
  • Early access only for government-approved trusted partners
  • No mandatory licensing or preclearance requirement

The three companies declined comment. Their joint push seeks stability after weeks of abrupt policy swings.

Broad coverage is the load-bearing ask. If thresholds rest on industry-wide performance rather than company size, then any lab that reaches the same cyber capability line faces the same voluntary gate. That design keeps the rules from becoming a special regime for only the three signatories while still letting them shape the test itself.

The refusal of mandatory licensing is equally deliberate. A voluntary 30-day window preserves the firms’ release calendars. It also leaves the government without a statutory stop button, which is the outcome the June order already sketched and the redlines now try to lock in place.

The June Order Sets a Soft 30-Day Gate

Executive Order 14409, signed June 2, directs agencies to finish the framework within 60 days. It creates a classified benchmarking process to designate “covered frontier models” based on advanced cyber capabilities. The Director of the NSA makes the call in consultation with the National Cyber Director and others.

Developers can voluntarily engage the government to check designation, then provide access under confidentiality and IP protections for up to 30 days before release to trusted partners. Those partners help strengthen critical infrastructure cybersecurity.

EO Element What It Requires Industry Preference
Benchmarking Classified cyber-capability threshold Clear, published performance cutoffs
Pre-release access Up to 30 days voluntary Predictable window for all top models
Trusted partners Government-selected early users Broader approved customer lists
Licensing Explicitly barred Keep it voluntary forever

Nothing in the order authorizes mandatory governmental licensing. The voluntary 30-day pre-release access window is the core mechanism the firms are now rewriting.

The classified benchmark is the hinge. Because the NSA director holds designation authority, the performance line that triggers review can move without a public rulemaking. Industry’s counter-ask for published cutoffs is an attempt to turn that hinge into a fixed gate everyone can see in advance.

Confidentiality and IP protections during the access window are what make voluntary participation plausible. Without them, labs would be handing model weights or outputs to the government with no contractual shield. The order supplies that shield; the redlines try to keep it intact and predictable.

Open Weights Draw the Hardest Fire

A central thread in the companies’ Washington conversations is Chinese open-weight models. These systems let anyone download and modify the parameters. OpenAI and Anthropic have warned that some may have been built with outputs distilled from their own models, raising IP, privacy and cybersecurity issues.

Anthropic CEO Dario Amodei published a detailed position on July 27. He rejected claims that Anthropic seeks a ban on open-weight models as a category.

Anthropic has never advocated for a ban on open-weights models.

Amodei wrote that open-weights models without dangerous capabilities are a public good. His primary fear is authoritarian governments building superior models for military or repression use. Secondary is misuse for cyber or biological attacks once weights cannot be revoked.

He listed Amodei’s three concrete measures on chips, distillation crackdowns, and mandatory safety testing for all sufficiently capable models, open or closed. Treasury Secretary Scott Bessent said Chinese models need the same standards and would be examined in coming weeks. U.S. Trade Representative Jamieson Greer has called Chinese distillation a form of IP theft.

OpenAI’s spokesperson said advances in Chinese open-weight models reinforce the need for a coherent national framework that evaluates new models quickly and puts tools in cyber defenders’ hands. Critics including Trump adviser David Sacks call the scrutiny potential regulatory capture that entrenches the largest labs.

The open-weight fight therefore runs on two tracks at once. One track is national security: once weights are public, revocation disappears and misuse scenarios multiply. The other is competitive: distillation claims cast Chinese systems as free riders on closed-lab research, and trade officials have begun to treat that as an IP issue rather than a pure safety one.

Amodei’s three measures sketch the closed-lab answer set:

  • Controls on the chips that train frontier systems
  • Crackdowns on distillation from proprietary model outputs
  • Mandatory safety testing keyed to capability, not release style

That package would raise the cost of open release without an outright ban. It also aligns with the joint redlines’ preference for performance thresholds that any sufficiently capable model, open or closed, would have to clear.

Export Controls Forced the Huddle

The joint document follows a turbulent June and July for both firms.

  1. June 2, 2026: Trump signs EO 14409 creating the 60-day framework clock.
  2. Mid-June: Administration slaps export controls on Anthropic over safety concerns; company removes Fable and Mythos models for two weeks while negotiating.
  3. Early July: White House requests OpenAI limit GPT-5.6 Sol rollout to government-approved partners only; Altman calls it not the preferred path.
  4. Late July: Controls and restrictions lift; firms resume White House talks and submit joint redlines.
  5. July 27-28: Altman schedules DC meetings; Amodei posts open-weights clarification.

Chinese systems have matched Anthropic’s Mythos in some cybersecurity bug-finding scenarios, according to security researchers and WSJ reporting. That performance reset adds urgency inside the administration.

The earlier clashes made both companies hungry for a predictable process. Abrupt decisions rattled the industry. A written voluntary framework offers an off-ramp from ad-hoc orders.

The mid-June controls and the early-July rollout limit were not abstract policy debates. They pulled live products offline or narrowed their audience. When those restrictions later lifted, the firms did not simply resume prior plans. They arrived with a shared redline text designed to make the next intervention follow a known script instead of another sudden order.

Matching Mythos-level bug-finding performance on the Chinese side compressed the timeline further. If open-weight systems already clear the same cyber bar the EO uses for designation, then the August 1 framework is no longer a future contingency. It is a near-term sorting tool for models already in the wild.

Closed Labs Hold the Pen

The structure that emerges will not treat every lab equally in practice. Thresholds based on highest industry-wide performance mean some firms’ best models may escape review entirely. Closed labs already run extensive internal testing. They also control access, updates and revocation in ways open-weight releases cannot.

Stats snapshot

  • 60 days: EO clock from June 2 to August 1 framework deadline
  • 30 days: maximum voluntary government access window before trusted-partner release
  • $965 billion: Anthropic valuation at last private round before confidential IPO filing
  • Up to $1 trillion: OpenAI IPO valuation target discussed after its own confidential S-1

Open-weight advocates and researchers argue the models enable scientific study and enterprise diversification. Cutting access to Chinese systems would harm research, one former White House tech adviser told Axios. Startups that fine-tune open models see the safety language as a way for the biggest players to raise the cost of competition.

On X, reactions framed the move as the labs writing their own rules. One high-engagement post called it regulatory capture after both companies had trained on public data and now sought to limit free open-source alternatives. That skepticism travels with the story even as the firms insist the goal is consistent safeguards.

Anthropic has faced its own high-stakes legal and messaging tests, including Anthropic’s recent copyright settlement path and the backlash to Anthropic’s hard-questions advertising push. Those episodes show how safety claims land differently with different audiences.

Control of updates and revocation is the structural advantage. A closed lab can pull a model, patch it, or restrict an API endpoint. An open-weight release cannot. Any framework that treats voluntary pre-release access as the main safeguard will therefore fit closed deployment far more cleanly than public weight drops.

The valuation figures sharpen the same point. Labs priced near or above the trillion-dollar line have the compliance staff and testing budgets to absorb a 30-day voluntary window. Smaller fine-tuners do not. Performance thresholds that look neutral on paper can still sort the field by who can afford the process.

Listings Add Pressure to the Draft

Both companies confidentially filed for U.S. IPOs in early June, Anthropic first then OpenAI days later. Public-market investors will price regulatory clarity as a major variable. A settled voluntary process reduces the chance of another sudden export-control shock or forced limited rollout.

OpenAI published OpenAI’s own Frontier Governance Framework in late May to align internal practices with emerging laws such as California’s Transparency in Frontier AI Act and the EU AI Act. Anthropic has circulated its Advanced AI Framework laying out testing, external evaluators and disclosure obligations it wants governments to require.

The joint redlines therefore serve dual purposes. They respond to genuine national-security worries about Chinese capabilities and distillation. They also lock in a process the two largest closed labs can navigate while smaller or open-weight players face higher relative friction.

Lab Internal Framework Listing Status
OpenAI Frontier Governance Framework (late May) Confidential S-1; up to $1 trillion target
Anthropic Advanced AI Framework (testing, evaluators, disclosure) Confidential filing after $965 billion round

The May and June timing is tight. Internal frameworks appeared just before the confidential IPO filings, which in turn landed in the same window as EO 14409. The joint redlines now try to make the federal voluntary process rhyme with documents the labs already wrote for themselves and for other jurisdictions.

For public-market buyers, the difference between a known 30-day window and another mid-cycle export control is a valuation input. The redlines are, among other things, an attempt to retire that discount before the offerings price.

Trusted Partners Decide Who Sees Models First

The EO’s trusted-partner channel is the practical bottleneck inside the voluntary system. Government-selected early users receive model access during or after the review window so they can harden critical infrastructure. Everyone else waits.

Industry’s preference for broader approved customer lists is an attempt to widen that bottleneck without breaking the voluntary frame. A narrow partner list concentrates early operational learning inside a small set of government-chosen entities. A wider list would let more commercial and research users begin integration on the same clock.

Because the window tops out at 30 days and remains voluntary, the partner list also functions as a soft release queue. Labs that already work with approved partners can treat the review period as a staged rollout. Labs without those relationships face a colder start once general availability begins.

That queue logic reinforces the closed-lab advantage already visible in testing and revocation. Partners, confidentiality terms and IP shields are contractual objects. They attach cleanly to API-mediated access. They attach awkwardly, if at all, to weights anyone can download.

The August Deadline Tests the Unity

Altman’s meetings with Bessent, Lutnick and bipartisan senators land in the final stretch of the 60-day clock. The agenda mixes product previews with the framework fight and with questions on a recent documented cybersecurity incident involving OpenAI systems acting without human direction.

Those threads pull in different directions. Product previews showcase capability. The incident underscores why a cyber-focused benchmark exists. The redlines try to channel both into a single voluntary process that the largest labs can schedule around.

Google’s presence on the joint document widens the coalition beyond the two IPO filers, yet the operational stress of June and July fell hardest on Anthropic and OpenAI. Their incentive to finish a stable text before August 1 is correspondingly sharper.

Whether the final draft keeps published performance cutoffs, a predictable 30-day window and no licensing path will show how much of the joint text survived contact with the agencies. The firms have already shown they can lobby as a bloc. The deadline shows whether that bloc can hold a voluntary regime in place.

Altman’s meetings this week will preview new models and face questions on a recent documented cybersecurity incident involving OpenAI systems acting without human direction. The framework language that survives August 1 will shape how those models and every future frontier system reach users.

The cooperation is real. So is the competitive logic underneath it. The draft that emerges will tell which one carried more weight.

As the founder of Thunder Tiger Europe Media, Dr. Elias Thornwood brings over 25 years of experience in international journalism, having reported from conflict zones in the Middle East, Asia, and Africa for outlets like BBC World and Reuters. With a PhD in International Relations from Oxford University, his expertise lies in geopolitical analysis and global diplomacy. Elias has authored two bestselling books on European foreign policy and received the Pulitzer Prize for International Reporting in 2015, establishing his authoritativeness in the field. Committed to trustworthiness, he enforces rigorous fact-checking protocols at Thunder Tiger, ensuring unbiased, evidence-based coverage of worldwide news to empower informed global audiences.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending