Section 3(c) of Executive Order 14409 says the order is not a licensing, preclearance, or permitting regime for model release. President Trump signed it 2 June 2026. Agencies got 30-day and 60-day clocks. Labs should not pause a public drop on the theory that this file is a license.
The news
The White House published EO 14409 dated 2 June 2026. Section 1 states it is U.S. policy to promote AI innovation and security by modernizing information systems, protecting intellectual property, and cultivating "advanced AI-enabled capabilities," while refusing "overly burdensome regulation."
Section 2 orders, within 30 days of the order date: the Committee on National Security Systems to prioritize cyber defense of National Security Systems as defined in 44 U.S.C. 3552(b)(6)(A); the Secretary of War to prioritize cyber defense of Department of War information systems; the Secretary of Homeland Security, through CISA, in consultation with OMB, the National Security Advisor, and the National Cyber Director, to release Binding Operational Directives and other guidance to expedite civilian federal cyber defense, expand programs for AI-enabled defensive tools, and facilitate access to cybersecurity tools including, where appropriate, covered frontier models for agencies, state and local authorities, and critical-infrastructure operators such as rural hospitals, community banks, and local utilities; the Secretary of the Treasury, in consultation with the National Cyber Director, NSA, and CISA, to form an AI cybersecurity clearinghouse, in voluntary collaboration with industry and operators, to coordinate vulnerability scanning, validation, remediation, and patch distribution; and OMB to determine whether any federal grant programs have funding that can be directed toward advanced AI vulnerability detection.
Section 3, also on a 60-day clock, directs Treasury, NSA, and CISA, in consultation with named White House and NIST officials, to develop and maintain a classified benchmarking process to assess advanced cyber capabilities of AI models and to determine the threshold at which a model should be designated a "covered frontier model." That determination "shall be made by the Director of NSA," in consultation with listed officials. The same section directs design of a voluntary framework under which developers could engage the government on that designation, provide access to covered frontier models for up to 30 days before release to other trusted partners, subject to confidentiality and related protections, and collaborate on selecting trusted partners for early access.
Section 3(c) states: "Nothing in this section shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models."
Section 4 directs the Attorney General to prioritize enforcement of 18 U.S.C. 1028, 1030, 1343, and other applicable federal criminal laws against anyone who uses AI to illegally access or damage a computer, including employing AI agents to unlawfully access data.
Who is bound
The President shipped the order. Bound to act on the clocks are CNSS, the Secretary of War, DHS/CISA, Treasury, OMB, OPM, NSA, NIST (consulted), and the Attorney General. Model developers are not commanded to submit models. Participation in the Section 3 framework is described as voluntary.
What's new
The order creates a named category, covered frontier model, whose threshold is a classified NSA-led benchmark, and a voluntary pre-release window of up to 30 days for federal access. It pairs that with operational cyber directives and a Treasury clearinghouse rather than a public licensing bureau. It also tells DOJ to prioritize existing computer-crime statutes when AI is used in the offense.
What it does not settle
Date: 2 June 2026. Thirty-day actions are due about 2 July 2026; sixty-day actions about 1 August 2026. Region: United States executive branch; no extra-territorial clause. Price: none stated; implementation is "subject to the availability of appropriations." Hardware: none. Data: classified benchmark process; sharing of assessments with developers is "as appropriate." License: not a software license; Section 3(c) bars reading it as model-release permitting. The covered-frontier-model list does not exist in the order.
What to do now
Federal CISOs under CISA should watch for Binding Operational Directives in the 30-day window rather than inventing a private checklist from Section 1 prose. Frontier labs' policy counsel should decide whether to enter the voluntary 30-day access path if invited.