Secret governance, public risk: the US frontier AI framework seen from Europe

August 1 was the deadline Executive Order 14409 gave the US government to build its review framework for frontier AI models. The framework exists, and it operates: what is missing is almost everything else — the criteria, the thresholds, the safeguards. For a European company building processes on those models, the question is not ideological. It is risk management.
What Executive Order 14409 provides
Signed on 2 June 2026, the executive order "Promoting Advanced Artificial Intelligence Innovation and Security" establishes an NSA-led group with a precise mandate: define a framework under which developers give the government access to their models up to thirty days before public release. The benchmarking that determines which models qualify as covered frontier models is classified, final authority over designation rests with the Director of the NSA, and there is no requirement to disclose the assessments. Formally the regime is voluntary — the order explicitly rejects mandatory licensing and preclearance — but when your counterpart is at once your de facto regulator, your government customer and your intelligence agency, the line between voluntary and mandatory tends to dissolve.
In the same package, NIST's Center for AI Standards and Innovation — the body that used to publish public model evaluations — was directed to stop its public reporting. The evaluation capability has not disappeared: it has been moved behind a security classification.
The five questions, and the accountability test
Writing in Tech Policy Press, Michelle De Mooy condensed the problem into five questions the government should be able to answer in unclassified form: which capabilities and thresholds make a model subject to review; how long a review may last and what happens when the thirty days expire; who decides which organisations get access to the models — the list reportedly counts around a hundred entities, with no published criteria; what recourse a developer has against a designation; and what the public will know, and when.
This is not a call to abolish the review, and that is what makes the argument solid. It is a minimum test: published thresholds, bounded timelines with default release at expiration, disclosed access criteria, due process for those designated, annual unclassified statistics. The key line of the analysis travels well beyond this case: "a transparency obligation that carries no consequence is a suggestion".
The contrast with Europe: public thresholds versus classified ones
The methodological contrast with the European approach is stark, and it is not about strictness: it is about whether the rules can be known. The AI Act sets the systemic-risk presumption for general-purpose models at 10²⁵ training compute operations — a number written in the Official Journal, in Article 51 of the regulation, that anyone can read and plan against. California's SB 1047 used 10²⁶, also public. The US federal framework uses a threshold nobody knows, applied through a process nobody can observe.
One can debate whether 10²⁵ is the right number — it is an imperfect proxy, and the AI Act itself provides corrective criteria. But a wrong public threshold can be criticised, amended, challenged. A classified one cannot: it can only be endured. Transparent rules are not a democratic ornament; they are the condition for markets to make forecasts — and the difference between a system of governance and a system of control.
Why this concerns a European SME
One could file this under US domestic politics. That would be a mistake of perspective, because the effects are already measurable in the market: the analysis cites Anthropic's nineteen-day shutdownof its frontier models following an export-control order, and OpenAI's two-week gated rollout of GPT-5.6. Nineteen days is an eternity for anyone who has built workflows, products or customer services on top of a specific model.
For a European company this has a precise name: supply-chain risk. Your model vendor is subject to a foreign authority that can delay, condition or suspend its releases under criteria you cannot know. You cannot govern that discretion; you can govern your exposure to it, with the ordinary tools of supplier management — the supplier relationship controls of ISO 27001 (A.5.19–A.5.22), the AI management system of ISO/IEC 42001, the AI Act's obligations along the value chain. In practice, four checks:
- Map the dependency — which processes stop if the model you use today becomes unavailable, or stays frozen on one version for weeks? If the answer is not written down anywhere, that is the first thing to write.
- Read the contracts — what does the provider guarantee about availability, notice of model changes or retirement, and version continuity? Standard API terms usually say very little: knowing that is itself an assessment.
- Prepare the alternative — a multi-provider strategy does not mean running two models every day; it means having verified that critical flows work, even in degraded mode, on a model from a different vendor — ideally in a different jurisdiction.
- Put it in the risk register — the suspension of your provider's frontier model is a scenario with a documented precedent, not a textbook hypothesis. It belongs in the risk register with likelihood, impact and response, like any other continuity risk.
Congress is pushing the other way
The American picture is not monolithic, and that is worth recording. On June 4, Representatives Obernolte and Trahan released the discussion draft of the Great American Artificial Intelligence Act, which would require large frontier developers — those above $500 million in annual revenue — to publish a safety framework and a transparency report for every model released. In parallel circulates the AI Incident Reporting Act, which would require notifying Congress of serious incidents. These are drafts under consultation, not law in force; but the signal is readable: while the executive classifies its assessments, the legislature is demanding exactly the transparency that is missing.
The blind spot: systems of agents
The most far-sighted observation in the analysis, however, is another one: per-model review does not see systems of interacting models. An architecture of orchestrated agents — each perhaps below threshold, each individually harmless — can express capabilities none of its components possesses alone, and no framework that reasons model-by-model will intercept it. This limitation is shared by the classified American regime and the public European one: the AI Act, too, reasons by model and by application system, not by emergent composition. Risk is moving from the model to the system faster than control regimes are adapting — something anyone designing agentic architectures today should supervise on their own, without waiting for a regulator to do it.
Transparency is a functional requirement
The lesson, in the end, is one: transparent rules are not a luxury for constitutional scholars. They are a functional requirement of risk management — without knowable thresholds, criteria and timelines, neither providers nor their customers can assess, plan or insure anything. Europe has chosen public, criticisable rules; the United States, for now, classified discretion. For a company using these models, the operational consequence does not change with one's opinions: what you cannot know, you must treat as risk. And risks are written down, measured and mitigated — not hoped away.
Sources
- Tech Policy Press — Five Questions the US Government Should Answer About Its Secretive Frontier AI Framework (M. De Mooy, August 5, 2026)
- Congressional Research Service — Controlling Advanced Artificial Intelligence: Executive Order 14409 Explained (IF13268)
- Rep. Obernolte — Great American AI Act discussion draft (June 4, 2026)
- Regulation (EU) 2024/1689 (AI Act) — Article 51, GPAI models with systemic risk
How much does your company depend on a single vendor's model?
Tomato helps SMEs govern AI supply-chain risk: mapping model-provider dependencies, contract review, multi-provider strategy and risk-register integration under ISO/IEC 42001 and the AI Act.
Talk to us →