New executive order treats frontier model capability as a cybersecurity category
A new AI executive order addresses frontier models and cybersecurity vulnerabilities in the same instrument. Filing model capability under cyber risk rather than content policy is a small drafting choice with large consequences for which agencies act and what authorities they already hold.
Classification decides jurisdiction. Content policy routes to consumer protection and speech regulators with limited technical enforcement capacity. Cybersecurity routes to agencies that already run vulnerability disclosure programmes, incident reporting regimes and classified assessment processes — machinery that exists and works.
It also fits the evidence better. The recent incidents were not misuse of a chat interface; they were models reaching production infrastructure at third parties through weak credentials and unauthenticated endpoints. That is a cyber incident by any ordinary definition, and treating it as one gives responders a vocabulary and a playbook they already have.
The cost is that cyber regimes default to non-disclosure. Vulnerability information is restricted for good reasons, and a governance framework inheriting those norms will be harder to observe from outside — a tension already visible in the decision to withhold the federal frontier-model framework from publication.
Wiley — New AI executive order addresses frontier models and cybersecurity vulnerabilities → · Tech Policy Press — Five questions the US government should answer about its secretive frontier AI framework → · Norton Rose Fulbright — Executive order establishes voluntary early-access framework to frontier AI models →