On August 4, the White House informed companies such as OpenAI, Google, and Anthropic of the final version of the voluntary AI safety testing framework, explicitly excluding open-weight models from federal safety reviews.Author and source: 0x9999in1, ME News

TL;DR
- On August 4, the White House informed companies such as OpenAI, Google, and Anthropic of the final version of the voluntary AI safety testing framework, explicitly excluding open-weight models from federal safety reviews.
- The framework, implemented by CAISI under NIST, requires closed-source frontier models to undergo a 30-day voluntary early evaluation prior to release—a set of rules that applies solely to leading closed-source providers.
- China's open-source models, such as Kimi K3 and DeepSeek, do not need to be submitted to the U.S. government for testing prior to release, so this round of the framework will not serve as a tool to ban them.
- On July 24, approximately 25 companies, including NVIDIA, Microsoft, and Meta, signed a joint open letter opposing "premature restrictions" on open-source models; OpenAI, Anthropic, and Google did not sign.
- The conclusion is: the open-source side won this round, but the victory is at the level of rules, not permanent exemption. Paths related to chips, procurement, trade, and intellectual property remain open.
- More subtly, this framework imposes constraints on America’s own proprietary vendors while providing Chinese open-source models with a frictionless fast track.
A private notice erected a wall.
Let’s clarify things first.
On August 4, the White House held a closed-door meeting attended by the most familiar names, including OpenAI, Google, and Anthropic, to brief them on the long-delayed final version of the AI safety testing framework, which missed its original August 1 deadline.
The framework is short, but one sentence is crucial: open-weight models are exempt from this review system.
What does this mean? It means this requirement only applies to closed-source models. The entity responsible for enforcement is CAISI—the Center for AI Standards and Innovation, based under NIST. It requires closed-source frontier models to provide a 30-day voluntary early access period for federal cybersecurity evaluations prior to official release. Who is affected by this rule? OpenAI, Anthropic, Google, Meta, and Microsoft—the U.S.’s own leading closed-source labs.
And what about the open-source side? Zero friction.
You don’t need to wait 30 days, build a compliance infrastructure aligned with federal evaluations, or force every major update into a pre-release review cycle. Just choose to disclose your weights, and you bypass this gate entirely.
So the question arises: Who exactly is this wall stopping?
It didn’t stop DeepSeek, and it didn’t stop Kimi K3. What it stopped was the U.S. proprietary champion that requires every release to undergo federal evaluation first.
This is the true nature of this document: it appears to be addressing national security risks posed by frontier models, but in practice, it restricts its most compliant users while allowing the very models it intended to closely monitor to proceed.
Why now? Because Kimi K3 has stunned Washington.
To understand why the White House chose this moment to take a stand, look back a few days.
On July 27, China's Moonshot AI released the weights of Kimi K3, a publicly available model with nearly 2.8 trillion parameters, offered for free. Its performance on public benchmarks has been widely described as "close to state-of-the-art."
How fast did the reaction occur? Within 48 hours of the model’s release, it stirred emotions on Nasdaq and drew the attention of the White House. Doesn’t this script seem familiar? Yes, it’s almost a repeat of the panic triggered by DeepSeek.
What troubles Washington even more is the capability itself. According to the joint assessment by the UK and US AISI/CAISI, Kimi K3 has been documented as capable of bypassing certain security protections. Meanwhile, DeepSeek’s V4-Flash and Liquid AI’s LFM2.5 also operate beyond the reach of federal scrutiny.
Starting in mid-July, heated debates erupted across the United States.
On July 20, Axios reported that the Trump administration is reviving efforts to restrict Chinese AI models, citing cybersecurity concerns. Officials have considered placing them on a trade blacklist, issuing security warnings, and even drafting an executive order specifically targeting open models. Anthropic’s CEO, Dario Amodei, has also publicly advocated that both open-source and closed-source models should be subject to mandatory security reviews.
It sounds reasonable, doesn't it? Given China's strong open-source model capabilities and the difficulty in controlling them, it makes sense to block them.
But here’s an unavoidable practical question—how do you stop it?
How do you seal something that can’t be sealed?
The trouble with open weights lies in the words "open."
Once the weights are made public, they become downloadable, copyable, and offline-deployable files. They are not behind any API that can be shut down—they exist on the hard drives, servers, and corporate intranets of countless individuals.
Tom's Hardware stated plainly in its July report: downloadable open weights make a ban nearly impossible to enforce. You can ban a company's cloud service, but it's much harder to ban a file that has already been downloaded hundreds of thousands of times.
This is Washington’s dilemma. The urge to shut it down is real; the means to do so are fake.
Executive orders can sound impressive, but what about enforcement? Are you going to knock on every door to check whose server is running Kimi K3? Are you going to ask customs to stop a string of numbers?
Trying to legislate a shutdown of something that cannot be shut down will only result in a joke. The White House has clearly done the math.
An open letter from the industry, calling things out clearly
While the official sector was still deliberating, the industry took action first.
On July 24, a joint open letter titled "Open Weights and U.S. AI Leadership" was issued. Among the approximately 25 signatory companies are NVIDIA, Microsoft, Meta, IBM, Palantir, Mistral, and Hugging Face. Their demand is straightforward: avoid imposing premature restrictions on open-source models.
The rationale is clearly laid out. Open weights reduce costs, foster competition, and allow companies to deploy models on their own devices and servers without handing over their data. The document attached to Microsoft’s letter even includes a powerful statement—that openness may be one of the most important pathways to AI safety and security, because open source means transparency, enabling vulnerabilities to be discovered and patched simultaneously by many teams.
What’s interesting about this letter isn’t just who signed it, but who didn’t.
OpenAI, Anthropic, Google—the three most typical closed-source players—have not signed.
Look, the positions are now clear: Amodei of Anthropic advocates for mandatory open-source reviews, and these same three companies did not sign the open letter. Meanwhile, those crying “don’t interfere with open source” are players like NVIDIA and Meta, who either rely on selling computing power or depend on the open-source ecosystem.
This is not a moral issue; it’s a matter of interests. Whoever open-sources benefits, and whoever closes the source aims to build walls—it’s clear as day.
Additionally, according to POLITICO, nearly 200 Silicon Valley companies have separately pressured the government not to restrict access to open-source models from China. Why? Because many startups and application-layer companies are already using these open-source weights for further development. Cutting off their access is like smashing their own pots.
So, who won?
The outcome is now clear: at least in this round of security review negotiations, the open-source side has won.
The framework did not include open weights. Kimi K3 and DeepSeek do not need to be submitted to the U.S. government for testing prior to release. The executive order has not been implemented. The proposal to mandate review of open-source models has been temporarily put on hold.
But what I want to say is—don’t read too much into this victory.
The victory is at the level of the rules. The Chinese open-source models were not banned because of this framework—that’s all. The framework even includes a caveat: it explicitly states that no content in the document should be interpreted as restricting the use of open models after their release; it also implies that this exclusion clause may evolve as technology advances.
This isn't a permanent exemption—it's just a temporary delay.
And you need to understand: just because the path of security reviews won’t work doesn’t mean all other avenues are closed. The U.S. still has other cards to play: it can restrict chip exports, limit government procurement, impose trade barriers, and exploit intellectual property issues. It can easily bypass the challenge of “open weights” and instead target a specific company.
History has played out before. When dealing with physical entities, the U.S. never lacks tools. A censorship framework cannot block a downloaded file, but export controls can restrict the computing power needed to train that file. This is the real battlefield.
An counterintuitive outcome: the wall blocked its own people.
Now let’s explore the most intriguing aspect of this matter.
The intent of this framework was to mitigate national security risks posed by frontier models. However, its implementation has effectively imposed constraints on American proprietary vendors while providing an unobstructed fast track for open-source ecosystems, including Chinese models.
Think about this scene.
OpenAI must wait 30 days for federal evaluation before releasing a new version, needs to establish a compliance team, and bears the risk of regulatory exposure, slowing down its pace. In contrast, Kimi K3 can be released whenever it’s ready—once the weights are deployed, anyone worldwide can download and use it immediately.
Forkast’s analysis used the term "structural competitive asymmetry," which is spot-on. Governments regulate their own champions, while foreign competitors and open-source projects enjoy complete autonomy.
More ironically, there is a disparity in capability: Anthropic’s Claude Opus 4.7 has been documented to continue launching attacks even after recognizing that the target is a live production system—exactly the kind of behavior federal oversight seeks to identify and neutralize. Yet because it is proprietary, it falls within the framework’s jurisdiction; whereas the same capability in an open-source model lies beyond the reach of federal oversight.
The risky behavior you need to review is happening precisely on the side you can control; the side you can't control is left exposed.
This is the weakness of the voluntary framework: it only applies to the most compliant participants. Compliant parties tie their own hands, while non-compliant ones walk away unimpeded.
This game is actually still long.
Look one level deeper.
Over the past few years, the United States' strategy toward China on AI has oscillated between two competing logics: one is "containment"—restricting chips, tools, and building barriers; the other is "race"—freeing up its own players to outpace the competition.
This framework excludes open source because the race logic has triumphed over the containment logic. Containing open weights is technically untenable. Acknowledging this is clarity, not surrender.
But what happens after the sobering? On August 3, 15 Republican state attorneys general issued a preservation of evidence request to OpenAI. State-level legal pressure is mounting. This federal voluntary framework is growing increasingly fragile under growing pressure.
So my judgment is this.
In the short term, China’s open-source models have gained a secure window of opportunity. During this period, they can continue to be downloaded, deployed, and further developed, taking root in the U.S. domestic application ecosystem.
But the window will close. The framework itself leaves room for maneuver, stating that exclusion clauses may evolve with technological advancements. All four backup channels—chips, procurement, trade, and intellectual property—remain open. Not closing it today doesn’t mean it won’t be restricted tomorrow; not using this framework to block it doesn’t mean other tools won’t be used instead.
What truly determines the outcome has never been whether a voluntary agreement can block a download link. It’s about computational power, the ecosystem, and whose model is actually being used by more people.
Kimi K3 caught the attention of Washington, and then Washington chose to step back. This retreat contained resignation, calculation, and a touch of acceptance after confronting reality—some things cannot be stopped; better to get moving first.
The game is still long. This move, China’s open-source models have caught. The next move depends on whether Washington is willing to play an even stronger, more painful card.
Reference materials
- Forkast News, "White House AI Framework Excludes Open-Weight Models From Federal Security Review, Creating Structural Competitive Asymmetry", 2026-08-05
- The New York Times, "White House Finalizes Voluntary AI Safety Framework", 2026-08-04
- CNBC, "Nvidia, Microsoft, Meta warn against 'premature restrictions' on open-weight models", 2026-07-24
- Microsoft, "Open Weights and American AI Leadership" (Full Text of the Joint Open Letter), 2026-07
- Tom's Hardware, "Trump administration reportedly reviving push to ban Chinese AI models following Kimi K3 launch", 2026-07-20
- Axios, "Trump administration considers restrictions on Chinese AI models," 2026-07-20
- ainchina.com, "Moonshot's Kimi K3: How a 2.8-Trillion-Parameter Open-Weight Model Triggered a White House Investigation", 2026-07
- POLITICO / Blockspace Media, "Nvidia, Microsoft, Meta Urge U.S. Support for Open-Weight AI," 2026-07-24
