An executive order on frontier model security
Executive Order 14409 gave agencies 30 and 60 days on cyber defence and directed a classified benchmarking process for covered frontier models plus a voluntary framework for federal access to them.
Why it matters
The United States defined a category of covered frontier models for the first time and set up a government process for assessing them, even if participation is voluntary.
The order was signed on 2 June 2026. Section 2 sets 30-day deadlines: the Committee on National Security Systems and the Secretary of War must prioritise cyber defence of their systems; the Secretary of Homeland Security must release Binding Operational Directives through CISA; the Secretary of the Treasury, with the NSA and CISA, must form an AI cybersecurity clearinghouse for vulnerability scanning and patch coordination; and the Director of the Office of Management and Budget must determine whether federal grants can fund AI-enabled vulnerability detection. The Director of the Office of Personnel Management has 60 days to expand cybersecurity specialist hiring. Section 3 gives the Secretaries of the Treasury, War through the NSA, and Homeland Security 60 days to develop a classified benchmarking process for covered frontier models and a voluntary framework under which developers provide federal access to models subject to appropriate confidentiality, cybersecurity, insider-risk and intellectual-property protection. Section 4 directs the Attorney General to prioritise enforcement against anyone who uses AI to illegally access or damage a computer.