Cybersecurity and Frontier Models: Inside Trump's Latest AI Executive Order
Wednesday, June 3, 2026
Digital Beat
Cybersecurity and Frontier Models:
Inside Trump's Latest AI Executive Order

On June 2, 2026, President Donald Trump signed an Executive Order (EO) titled Promoting Advanced Artificial Intelligence Innovation and Security. The order is primarily a cybersecurity directive that focuses on hardening federal government computer systems against AI-enabled threats, creating a voluntary framework for evaluating the most advanced AI models, and directing federal prosecutors to pursue criminals who use AI. For state broadband officials, digital equity practitioners, and operators of critical infrastructure—including rural hospitals and community banks—the order contains provisions that could affect their work.
This EO is the latest in a series of actions the Trump Administration has taken to shape federal AI policy. To understand what is new here, it might help to know what came before it.
The Trump Administration's AI Strategy
Over the past year, the Trump Administration has pursued a consistent—if still-evolving—approach to AI that rests on three pillars:
- Promote innovation by removing federal regulatory constraints;
- Prevent state governments from creating their own AI regulations; and
- Position the United States to lead globally in AI development and security.
In July 2025, President Trump signed an EO titled Preventing Woke AI in the Federal Government, which barred federal agencies from purchasing AI systems that incorporated what the order called ideological bias or diversity, equity, and inclusion (DEI) programming. That EO also aimed at preventing the federal government from using AI models with "ideological biases or social agendas." The order applies to AI that the federal government buys, not to AI companies generally. Also in July 2025, the Administration released an AI Action Plan calling for the removal of regulations it said hindered AI development.
In November 2025, President Trump launched the Genesis Mission, an initiative to build an "American Science and Security Platform" operated by the Department of Energy, combining supercomputers, AI modeling tools, and federal scientific datasets to accelerate research in areas including advanced manufacturing, semiconductors, nuclear energy, and quantum computing. The Genesis Mission positioned the federal government as an active funder and developer of AI—not merely a procurer or regulator.
In December 2025, the President signed Ensuring A National Policy Framework for Artificial Intelligence, which targeted state AI laws. That order directed the Attorney General to establish a litigation task force to challenge state AI regulations that the Administration viewed as unconstitutional or in conflict with federal policy. The EO used federal funding levers—specifically threatening states with ineligibility for non-deployment funds under the Broadband Equity, Access, and Deployment (BEAD) Program—to pressure states to repeal AI laws the Administration deemed burdensome. The EO also directed the Federal Communications Commission (FCC) to consider adopting a federal AI disclosure standard that would preempt conflicting state laws.
In March 2026, the Administration released a National Cyber Strategy, outlining its vision for defending U.S. interests in cyberspace and reinforcing American technological leadership. The strategy appears to position cybersecurity not merely as a technical or compliance concern, but as a central pillar of national strength—integral to economic growth, military superiority, innovation, and global influence. Separately, the Administration released a national legislative framework for AI policy, which urged Congress to:
- Protect children and empower parents,
- Ensure that AI development strengthens communities through community development,
- Protect intellectual property rights,
- Prevent AI systems from being used to silence or censor lawful political expression or dissent,
- Remove regulatory barriers to AI development,
- Train an AI-ready workforce, and
- Preempt state AI laws.
The June 2, 2026, EO builds on these actions by addressing the security side of AI: who is responsible for protecting federal systems against AI-enabled attacks, how the government evaluates the riskiest AI models, and what happens to bad actors who use AI to commit crimes.
What the New EO Does
The order's preamble restates the Administration's core AI policy position: innovation over regulation, with security as a shared responsibility between government and industry. In the sections that follow, Promoting Advanced Artificial Intelligence Innovation and Security mandates a range of actions by federal departments and agencies.
I. Hardening Federal Computer Systems (Section 2)
The order's core operational directive is to prioritize cyber defense of federal information systems. The EO assigns responsibility in three tiers:
1. National Security Systems (Section 2(a)): Within 30 days of the EO (by approximately July 2, 2026), the Committee on National Security Systems1 must take "appropriate and expeditious action" to prioritize cyber defense of National Security Systems.2 The order does not specify what actions are required; instead, it delegates that determination to the Committee.
2. Department of War systems (Section 2(b)): Also within 30 days, the Secretary of War must prioritize cyber defense of Department of War information systems.
Binding Operational Directives are legally binding directives from CISA to federal agencies, not merely guidance documents.
3. Civilian federal systems (Section 2(c)): Within 30 days, the Secretary of Homeland Security—acting through the Director of the Cybersecurity and Infrastructure Security Agency (CISA)—must release Binding Operational Directives and other guidance to:
- Expedite cyber defense of civilian federal government information systems;
- Establish or expand federal programs using AI-enabled defensive cybersecurity tools; and
- Facilitate access to cybersecurity tools and services—including, where appropriate, "covered frontier models" (a designation the government will assign to certain highly capable AI models based on a classified benchmark that doesn't yet exist)—for federal agencies, state and local authorities, and operators of critical infrastructure such as rural hospitals, community banks, and local utilities.
Section 2 also directs three supporting actions to back up those cyber defense responsibilities:
- AI Cybersecurity Clearinghouse (Section 2(d)): Also within 30 days, the Secretary of the Treasury—in consultation with the National Cyber Director (the President's principal advisor on national cybersecurity policy and strategy), the NSA Director, and CISA—must form an AI cybersecurity clearinghouse. The clearinghouse will operate in "voluntary collaboration" with AI industry participants and critical infrastructure operators to coordinate scanning for software vulnerabilities, validate those vulnerabilities, and prioritize remediation and distribution of patches.
- Funding identification (Section 2(e)): Within 30 days, the Office of Management and Budget (OMB) Director—coordinating with the National Cyber Director and CISA Director—must determine whether any existing federal grant programs have available funding that can be directed toward applicants developing advanced AI vulnerability detection.
- Federal cybersecurity hiring (Section 2(f)): Within 60 days (by approximately August 1, 2026), the Director of the Office of Personnel Management (OPM) must expand the United States Tech Force Information Cybersecurity Specialist hiring and placement pathways.3
II. A Voluntary Framework for "Covered Frontier Models" (Section 3)
Section 3 addresses the most powerful AI models—those with advanced cyber capabilities. Within 60 days, the Secretaries of the Treasury and the Department of War (through NSA), and the Secretary of Homeland Security (through CISA)—consulting with the White House Chief of Staff, the National Cyber Director, the Assistant to the President for Science and Technology (APST), and the National Institute of Standards and Technology (NIST)—must do three things:
1. Classified benchmarking (Section 3(a)): Develop and maintain a classified process to assess the advanced cyber capabilities of AI models and determine when a model crosses the threshold to be designated a "covered frontier model." The NSA Director makes this designation, in consultation with the National Cyber Director, APST, and CISA. Assessments may be shared with AI developers and researchers "as appropriate."
2. Voluntary framework (Section 3(b)): Design a voluntary framework with AI developers under which companies could:
- Ask the government whether its model meets the "covered frontier model" threshold;
- Provide the government with access to covered frontier models—subject to "appropriate confidentiality, cybersecurity, insider-risk, and intellectual-property protection"—for up to 30 days before public release; and
- Collaborate with the government to identify trusted partners (a term used but not defined by the EO) who would receive early access to covered frontier models to promote secure innovation and strengthen critical infrastructure cybersecurity.
The voluntary structure reflects a deliberate policy choice—mandatory pre-release review of AI models could raise significant legal questions under the First Amendment and administrative law.
3. No mandatory licensing (Section 3(c)): The order expressly states that nothing in Section 3 "shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models."
Section 3(c) appears to be a deliberate carve-out that insulates the order from characterization as a licensing regime. The Administration has consistently framed its approach as voluntary collaboration rather than regulation. But the framework depends on AI developers choosing to participate. The order provides no enforcement mechanism if companies decline, nor does it specify consequences for declining.
As noted above, the order does not define "covered frontier model." The threshold is to be determined by a classified process developed after the order takes effect. This means the scope of the voluntary framework—how many models it would cover, and which companies it would reach—is unknown.
III. Criminal Enforcement (Section 4)
The Attorney General must prioritize enforcement of several existing federal criminal statutes against anyone who uses AI to illegally access or damage computer systems, steal data, or facilitate other crimes. The statutes cited are:
- 18 U.S.C. § 1028 (identity document fraud and identity theft);
- 18 U.S.C. § 1030 (unauthorized access to computer systems—the Computer Fraud and Abuse Act); and
- 18 U.S.C. § 1343 (wire fraud).
The order does not create new crimes or expand existing law; it directs prosecutorial prioritization of existing statutes in cases involving AI.
Action Timeline
| Deadline | Action | Responsible Party |
|---|---|---|
| ~July 2, 2026 (30 days) | Prioritize cyber defense of National Security Systems | Committee on National Security Systems |
| ~July 2, 2026 (30 days) | Prioritize cyber defense of Department of War systems | Secretary of War |
| ~July 2, 2026 (30 days) | Issue Binding Operational Directives for civilian federal systems; facilitate AI cybersecurity tool access for agencies, states, and critical infrastructure operators | Secretary of Homeland Security / CISA Director |
| ~July 2, 2026 (30 days) | Form AI cybersecurity clearinghouse | Secretary of the Treasury |
| ~July 2, 2026 (30 days) | Determine whether existing grant funding can support AI vulnerability detection | OMB Director |
| ~August 1, 2026 (60 days) | Expand federal cybersecurity hiring pathways | OPM Director |
| ~August 1, 2026 (60 days) | Develop classified benchmarking process for frontier models; design voluntary framework for early model access | Treasury, NSA/Dept. of War, CISA, in consultation with others |
What to Watch
The EO raises several questions that stakeholders may want to track as the order is implemented.
The "covered frontier model" definition will matter most. The entire voluntary framework hinges on a classified threshold that has not yet been established. Companies will not know whether they are within scope until that process concludes—and the public may never know the full criteria, given the classified nature of the benchmarking process.
The clearinghouse is voluntary. Both the AI cybersecurity clearinghouse (Section 2(d)) and the frontier model framework (Section 3) are explicitly framed as voluntary. The order does not specify the incentives for industry participation or what happens if participation is low.
Critical infrastructure access depends on CISA's implementation. The EO's most concrete benefit for rural hospitals, community banks, and local utilities—access to AI-enabled cybersecurity tools—is contingent on CISA issuing Binding Operational Directives that establish the mechanisms for that access. The content and pace of that guidance will determine whether the EO's promise reaches the organizations named.
Grant funding review is not a commitment. OMB's 30-day review of existing grant programs is a study, not a funding directive. Congress controls appropriations; an OMB determination that existing grant funds could be redirected does not guarantee they will be.
This EO does not address AI regulation of private companies. Like its predecessors in the Trump series, this order focuses on federal systems, federal procurement, and voluntary engagement with industry. The EO does not impose new obligations on AI companies generally.
For state broadband officials, digital equity practitioners, and operators of critical infrastructure, the EO's most direct implications are in Section 2(c). That provision directs CISA to facilitate access to AI-enabled cybersecurity tools and services—including, where appropriate, covered frontier models—for state and local authorities and for operators of critical infrastructure such as rural hospitals, community banks, and local utilities. Whether that access materializes in a meaningful way depends entirely on what CISA's Binding Operational Directives actually require. The EO sets the direction; the directives, which must be issued within 30 days, will determine the destination. Separately, the OMB grant funding review (Section 2(e)) could open a path to federal support for organizations developing AI-based vulnerability detection tools—but that review is a study, not a spending commitment, and any funding would remain subject to congressional appropriation.
The Executive Order was signed on June 2, 2026. The White House Fact Sheet was released the same day. Citations in this article refer to sections of the EO or the accompanying Fact Sheet as indicated.
Notes
- The Committee on National Security Systems provides a forum for the discussion of policy issues and is responsible for setting national-level cybersecurity policies, directives, instructions, operational procedures, guidance and advisories for U.S. Government (USG) departments and agencies for the security of National Security Systems. See https://www.cnss.gov/cnss/
- The statute (44 U.S.C. 3552(b)(6)(A) defines 'national security system' as any information system (including any telecommunications system) used or operated by an agency or by a contractor of an agency, or other organization on behalf of an agency— (i) the function, operation, or use of which— (I) involves intelligence activities; (II) involves cryptologic activities related to national security; (III) involves command and control of military forces; (IV) involves equipment that is an integral part of a weapon or weapons system; or (V) is critical to the direct fulfillment of military or intelligence missions; or (ii) is protected at all times by procedures established for information that have been specifically authorized under criteria established by an Executive order or an Act of Congress to be kept classified in the interest of national defense or foreign policy.
- The U.S. Tech Force is a federal hiring initiative launched by the Trump administration in December 2025, administered by the Office of Personnel Management. The program aims to recruit about 1,000 early-career technology professionals into two-year government jobs to modernize federal IT systems, advance AI capabilities, and address technological gaps in government operations. The Information Cybersecurity Specialist role was added to Tech Force in April 2026, and focuses on protecting critical systems, strengthening federal cybersecurity capabilities, and safeguarding digital infrastructure.
The Benton Institute for Broadband & Society is a non-profit organization dedicated to ensuring that all people in the U.S. have access to competitive, High-Performance Broadband regardless of where they live or who they are. We believe communication policy - rooted in the values of access, equity, and diversity - has the power to deliver new opportunities and strengthen communities.
© Benton Institute for Broadband & Society 2026. Redistribution of this email publication - both internally and externally - is encouraged if it includes this copyright statement.
For subscribe/unsubscribe info, please email headlinesATbentonDOTorg



