Trump signed the executive order on June 2, titled "Promoting Advanced Artificial Intelligence Innovation and Security." It is the first major AI policy directive of his second term, and it came out of an internal fight that had been running for weeks.
The original version of the order gave the government up to 90 days to review the most powerful AI models before release. That was killed hours before signing on May 21 after Elon Musk, Mark Zuckerberg, and David Sacks each called Trump directly to block it. The final version cuts that window to 30 days and keeps participation voluntary. The order explicitly states that nothing in it should be read as creating a mandatory licensing or approval requirement for AI companies.
White House chief of staff Susie Wiles and Treasury Secretary Scott Bessent drove the revival of the order over a weekend, working through resistance from Sacks and from Trump himself. The version Trump approved on Monday night and signed Tuesday reflects that compromise: the national security case won, but the industry's preferred timeline won too.
The mechanics matter. Federal agencies have 60 days to define what counts as a "covered frontier model," using a classified benchmarking process run by the National Security Agency. Once a model clears that threshold, the government gets up to 30 days of access before the developer releases it to other trusted partners. Crucially, that 30-day window runs before release to those partners, not before public release, meaning the government sees models earlier in the distribution chain than it first appears.
A new AI cybersecurity clearinghouse, led by the Treasury Department and set up within 30 days, will coordinate scanning for software vulnerabilities and share fixes across critical infrastructure. Rural hospitals, community banks, and local utilities are named explicitly in the order as organizations that will gain access to AI-powered security tools through this process.
The same day the order was signed, Anthropic expanded access to its Mythos model from roughly 50 to 200 organizations across 15 countries. The new group covers power, water, healthcare, communications, and hardware sectors. The Financial Times reported that the New York Stock Exchange, Samsung, Okta, NATO, and the EU's cybersecurity agency ENISA are among the new partners. The 50 original members had already found over 10,000 high or critical severity security flaws using the model.
Anthropix's own warning is the most important number here: within 6 to 12 months, the company expects competitors to release models with comparable security-finding power, potentially without Mythos's restrictions on misuse. That is the clock the executive order is racing against.
The order also directs the Justice Department to prioritize criminal enforcement against anyone using AI to illegally access computer systems. That is a signal that the government views AI-assisted hacking not as a theoretical risk but as an active enforcement priority.
With the domestic order in place, Treasury Secretary Bessent can now open discussions with China on a cross-border framework for advanced AI systems, according to people familiar with the matter. Those conversations had been on hold while Washington settled its internal debate.
For any organisation that depends on digital infrastructure, which in practice means almost every large business, the picture is now clearer. The government has a formal process, even if it is voluntary and not yet fully built. Powerful security-scanning AI is spreading to more sectors. And the period in which only a handful of elite organizations could access these tools is ending fast. The practical question is not whether your systems will face AI-assisted probing, but whether you will have the tools to find the weaknesses first.