Hangar 18

On 2 June 2026, an executive order gave the NSA director responsibility for measuring the offensive cyber capabilities of AI models. The threshold is classified. The framework applying it will not be published. The civilian body that published its evaluations has been told to stop.
Hangar 18
What is stored is not meant to be shown (Hangar 18, Megadeth, 1990).
« ...frontier AI systems made elsewhere that others can suddenly switch off. » — European Commission, COM(2026) 577 final, 7 July 2026

On 2 June 2026, an executive order gave the director of the NSA responsibility for measuring the offensive cyber capabilities of the most advanced AI models¹. The benchmarking process is classified. The threshold that triggers the "covered frontier model" designation is classified. Assessments are shared with developers "as appropriate." Sixty days later, nothing appeared by the 1 August deadline. The framework nonetheless exists: it was presented to industry on 4 August at a closed-door meeting led by National Cyber Director Sean Cairncross, and the White House announced it would not be published². Delivered, unpublished.

An administration that made AI deregulation a political marker has just written a pre-release review regime for frontier models. The contradiction is only apparent. It dissolves once you read what the texts organise: neither a regulation nor a safety regime. An accounting.

Three texts in ten days

Executive Order 14409 of 2 June is titled "Promoting Advanced Artificial Intelligence Innovation and Security"¹. Its section 3 creates the classified benchmarking process and the voluntary framework: developers may submit their models to the federal government up to 30 days before release, and work with it to select "trusted partners" who will receive early access. Its section 2(d) creates an "AI cybersecurity clearinghouse" led by Treasury with the National Cyber Director, the NSA and CISA, tasked with coordinating and deconflicting the search for vulnerabilities, discovering and validating them, and prioritising their remediation. Its section 3(c) expressly rules out any mandatory licensing, preclearance or permitting requirement.

On 5 June, presidential memorandum NSPM-11 revoked the Biden administration's AI directive and ordered the accelerated adoption of frontier models across the military and intelligence apparatus³. On 12 June, NSPM-12 reorganised the governance of National Security Systems, the information systems handling intelligence, military operations or classified data: it revokes a 1990 directive and a 2022 memorandum, and consolidates the director of the NSA as "National Manager" of the whole⁴. The architecture thus replaced predates the creation of CISA by twenty-eight years.

The three texts share an architecture. According to Axios, which obtained the content of the August framework from sources present at the meetings, a "covered frontier model" is defined there as a proprietary model with state-of-the-art capabilities presenting national security risks, with neither the state of the art nor the risk defined². Open-weight models are excluded, and the text specifies that nothing should be read as restricting them after release. Reuters corroborates that scope from independent sourcing: on 4 August, White House advisers told the assembled developers, Meta and Nvidia joining the three labs, that open-weight models, Llama and Nemotron included, would not go through the voluntary testing⁵. During the 30-day window, submitted models are held in a high-security environment with detailed access logging. The content of the framework rests on anonymous sources from two newsrooms with distinct sourcing; no public document exists. The classified benchmark, by contrast, appears in the text of the executive order.

The only named official statement sets the register: spokeswoman Liz Huston describes an arrangement serving the "America First" strategy and aimed at cementing American dominance in AI⁵. Against it, Americans for Responsible Innovation objects that a rule constrains only if those outside the companies know what it says⁵. Opposition came from three directions in six weeks: a records request filed with the Office of the National Cyber Director by the Foundation for American Innovation, a centre-right technology policy group, seeking publication of the framework⁶; a Senate letter of 3 August faulting the administration for an unpredictable approach that strengthens market incentives to adopt open-weight models from foreign vendors⁷; and Republican senator Ted Budd's June letter on the silence imposed on public evaluations. Cairncross for his part described a text seeking a balance, taking care not to be regulatory in nature⁸.

The vocabulary states the function

The words these texts choose do not belong to the register of regulation. "Deconflict" comes from targeting: you deconflict fires, operations that risk getting in each other's way. "Clearinghouse" comes from banking settlement, that chamber where flows are cleared between parties. To say that remediation is "prioritised" is to concede a residual category of vulnerabilities left unremediated, and a body that decides. "Trusted partners" are chosen beneficiaries, with no published criteria, and "covered" is the term of export control regimes.

A safety regime sets obligations and publishes its thresholds. An export control regime sets prohibitions and publishes its lists. The June arrangement does neither: it measures in secret, it counts, it allocates. The vocabulary is that of asset management. You do not publish the inventory of an arsenal.

The sequence of instruments confirms this reading. Section 3 measures capability. Section 2(c)(iii) tasks CISA with facilitating access to it for federal agencies, states, local authorities and critical infrastructure operators, down to rural hospitals and community banks. Section 2(d) organises the triage of the vulnerabilities that capability discovers. Section 4 refers the handling of misuse to existing criminal law, once the damage is done. Upstream restricts nothing: section 3(c) says so. Upstream counts, protects and distributes.

The exclusion of open-weight models reads within the same frame. It looks like a gap in scope, since offensive capability does not depend on the mode of distribution and open weights escape any revocation by construction. It reflects instead a division of functions. National Cyber Director Sean Cairncross said in early August that he wanted American open-source AI to become a technology of choice worldwide, at the very moment the White House was leaving those models out of the voluntary testing⁸. Two regimes for two uses: the closed model is an asset you count and whose access you allocate, the open model an instrument you spread. You inventory only what you keep.

The switch clause

NSPM-11 contains the hardest provision of the set. Its section 2(c) requires, through contract clauses or other means, that no commercial entity retain the ability "to prevent the use of, disable, degrade, or materially modify, without the knowledge and approval of the Federal Government," an AI system used by American forces³. The state makes sure the maker cannot switch off what it sold.

Its section 3(b) supplies the leverage: termination of contracts, subcontracts included, with any company showing a "pattern of conduct" inconsistent with the memorandum's policy, waivers capped at one year and reported in writing to the White House⁹. The Council on Foreign Relations identifies the triggering event: the dispute between the Pentagon and Anthropic, arising from the company's refusal to drop two contractual limits, the prohibition on using its models in lethal autonomous weapons and in domestic mass surveillance¹⁰. The Pentagon demanded use for "all lawful purposes" and designated the company a supply chain risk. The termination clause generalises that precedent: a supplier that maintains conditions of use on its own models exposes itself to exclusion from defence and intelligence procurement.

On 27 August 2026, a federal judge in California vacated that designation, which she characterises as unlawful retaliation in violation of the First Amendment and as an arbitrary decision taken in disregard of the process required by the Fifth¹¹. Two findings in the decision carry beyond the case. On the technical fear first: the judge notes that the usage limit is purely contractual, that the company has neither the means to enforce it technically nor visibility into how the model is used, and that nothing in the administrative record describes what means would produce the alleged backdoors or permit a shutdown. In the one case where the state invoked the risk section 2(c) is meant to neutralise, it did not document that the risk existed. On the allocation regime second: a few days before the challenged actions, the Secretary of Defense proposed applying the Defense Production Act to that same company, a 1950 statute allowing the state to compel an industrial supplier to give priority to defence orders, which presumed it essential to national security, while the government was separately discussing collaboration on its most recent model in sensitive contexts. Designating and courting are two uses of one power to designate. An appeal remains possible and a second proceeding is pending in Washington.

Two further sections complete the picture. Section 4(c) organises the protection of "America's most advanced AI technologies" against "malicious distillation attacks," with personnel vetting at the labs and physical security for data centres, on the model of the support given to defence industrial suppliers. Section 4(e) tasks the intelligence community with collecting and analysing foreign AI technologies across the whole technical stack.

The four gestures of a patrimonial policy are in place: measure your stock (executive order, section 3), protect it from theft (NSPM-11, 4(c)), take inventory of the adversary's (4(e)), guarantee that no one can switch it off (2(c)). Each gesture is written into a presidential text of June 2026.

The publishing layer goes dark

The Center for AI Standards and Innovation, part of NIST, the federal standards institute, evaluated frontier models before release and made its findings public. Created in 2023 as the US AI Safety Institute, it was renamed and its mission narrowed to what the administration calls demonstrable risks: cybersecurity, biosecurity, chemical and biological weapons¹². As of 5 May 2026, it had run more than forty evaluations, including on models never publicly released, and had just signed agreements with Google DeepMind, Microsoft and xAI, bringing to five the number of labs under agreement¹³. On 26 June, Senator Ted Budd wrote to the National Cyber Director and the director of OSTP regarding reports that the centre had been directed to cease publishing its findings¹⁴. His letter ties the instruction to the executive order of 2 June and to the power it gives the NSA director to decide when sharing assessments with developers and researchers is appropriate. The senator asks that this work be allowed to resume, to the extent possible.

Forty public evaluations, then silence. The sequence is complete: the designation threshold is classified, the framework that applies it is unpublished, and the body that published has been told to stop. Three gestures, one effect.

NSPM-12 sets the composition of the Committee on National Security Systems: four members, including the NSA as National Manager⁴. The director of CISA appears on the list of officials permitted to recommend advisers, in eighth position. The agency created in 2018 to be the civilian pivot of American cyber defence is not a member of the body that governs national security systems.

The division of labour runs through the three texts. The NSA sets the threshold, runs the AI Security Center, handles emergency directives, conducts liaison with foreign governments. CISA facilitates access and distributes. One agency decides, the other conveys.

This shift has a consequence documented in this series. Since January 2026, CISA's KEV catalogue, the public list of vulnerabilities whose exploitation by attackers is confirmed, has been the last sharing channel available to allies, a minimal, declassified flow fed according to American priorities (article 7). That channel now issues from an agency demoted to advisory status within its own system. A flow can keep running while ceasing to be connected to what its source knows, once the source itself has stopped knowing.

The two movements are one. A civilian agency pushed out of governance, a civilian evaluation centre deprived of publication: what is going dark is not an institution but a layer, the one that made public what the state was learning. On model capability, what remains is the voluntary publications of the labs and of their evaluators under agreement. The question posed by article 7 returns word for word, one storey up: never the quality of what passes, always what does not.

Intent beyond settling

The inventory reading, developed above, credits the executive with a coherent intent: AI capability treated as a strategic asset, measured in secret, allocated by designation. Two competing readings explain the same texts.

Next comes the dependency reading, formulated from the inside. Vinh Nguyen, the NSA's first AI lead before joining the Council on Foreign Relations, describes a national security apparatus running on infrastructure it does not own: the hyperscalers built the compute, the labs built the models, and the state has become the customer of a technology it did not design and cannot replicate¹⁰. On that grid, the switch clause and the threat of termination manufacture leverage where ownership is missing. The state is not managing its patrimony, it is managing its dependency. The August ruling weighs on this side: a clause forbidding a shutdown whose technical feasibility the administrative record fails to establish reflects apprehension as much as accounting.

Then there is a capture reading, which looks at who held the pen. Three labs, Anthropic, OpenAI and Google, reviewed the draft framework before it was finalised¹⁵. The result establishes them as strategic suppliers with no enforceable obligation, leaves their open-weight competitors outside the scope, and reserves early government access for players already dominant. Companies with less advanced systems will remain outside the arrangement². No state intent is required to produce this text: an industrial balance of power suffices.

The three readings predict the same documentary record. The text alone does not allow them to be separated. They do converge on one point: in all three, what Washington manages has ceased to be the risk. It is the stock.

Europe downstream

The UK AI Security Institute, created in November 2023 as the AI Safety Institute and renamed in February 2025¹⁶, evaluates frontier models before release under voluntary agreements with OpenAI, Anthropic, Google and others¹⁷. Around a hundred people drawn from intelligence, academia and the labs, 360 million pounds of funding, no binding powers. Its December 2025 report aggregates two years of evaluations across more than thirty models and measures a doubling roughly every eight months in the length of the cyber tasks a model completes on its own, from analysing a single component to chaining a full intrusion¹⁸.

On the Union side, ENISA, the European Union Agency for Cybersecurity, is negotiating the technical and legal conditions for a first frontier model test¹⁹. The Commission's action plan of 7 July 2026 sets the catch-up schedule: a "European Blueprint" for structured access with ENISA in the fourth quarter of 2026, a European evaluation capacity targeted for 2027²⁰. Between the first British test and an operational European capacity, three to four years elapse. At the rate the AISI measures, that gap represents four to six doublings of capability. The distance between London and Brussels is not counted in years: it is counted in generations of models.

British access rests on the discretion of the labs. It stems from the summit London convened at Bletchley Park on 1 and 2 November 2023, the first international meeting devoted to the risks of frontier models, where twenty-eight states and the European Union signed a joint declaration and the leading labs agreed to submit their models to government testing before release²¹. No binding instrument came out of it; the United Kingdom simply created its institute first and signed first. The executive order of 2 June changes the basis of that regime: trusted partners are now selected "in collaboration with the Federal Government"¹. What London obtained from the goodwill of the labs will have to pass through designation by Washington. The Commission's plan does criticise "provider-specific" access programmes and their opaque criteria²⁰: its target moved while it was being drafted. The Blueprint planned for the fourth quarter answers the previous regime, the one where the labs decided. The decider has changed.

The same document holds the plainest admission in the file. The Commission writes that without compute, models and infrastructure of its own, Europe will remain "a vulnerable user of frontier AI systems made elsewhere that others can suddenly switch off"²⁰. Thirty-two days earlier, NSPM-11 was contractually prohibiting anyone from switching off American systems. The same switch, seen from both sides: Washington demands control of it, Brussels writes down its fear of being subject to it. And the responses differ by the tools available: termination clauses on one side; a guidance document with "no new obligations for providers," contingency measures against withdrawal of access, and exploration of joint purchasing on the other²⁰. For frontier models, the Union is equipping itself with the instruments of energy supply security: a rupture clause, a strategic stock, joint procurement. That choice of tools states the position Brussels assigns itself in the chain.

A cascade takes shape. Washington manages by contract and by coercion its dependency on labs it does not own; Brussels manages by guidance and by contingency its dependency on an allocation regime Washington has just nationalised. Two positions in the same chain, the same problem, two balances of power. Even the international evaluation channel the European plan mentions (the network for measuring advanced AI capabilities) is coordinated by the British institute²⁰.

What I don't know

The content of the August framework rests on anonymous sources, gathered by two newsrooms with distinct sourcing. The exclusion of open-weight models is the only element corroborated by both; the exact scope, the designation criteria and the list of trusted partners are confirmed by no public document. Only the executive order, the two memoranda and the Commission's plan can be cited as primary sources.

I do not know which of the three readings is right. Inventory, dependency management and industrial capture produce the same texts, and nothing in the available record allows one to be falsified against another. Nor do I know whether the Treasury clearinghouse will produce a real arbitration between retention and remediation, or whether it will join the list of structures created by executive order and left as shells.

I do not know whether the marginalisation of CISA is a cause or a consequence: the agency had been emptied of its leadership before these texts, a year without a confirmed director, and it is still led on an acting basis at the moment its head publicly presents the vulnerability triage desk²². The NSA may have occupied a space left vacant as much as conquered it. Both chronologies fit the facts.

I do not know, finally, who will set the limit of the lawful in the use of these systems. The dispute between the Pentagon and its supplier turned on two prohibited uses; the memorandum settles the question of technical control without settling that of authority. The lab, the executive, the courts or Congress: the line exists, the authority to draw it remains undetermined¹⁰. The August ruling supplies a first element of an answer without closing the question. It bears on an earlier designation, not on the memorandum's termination clause, which has yet to be tested before a judge. I do not know whether that clause would survive the same review.

The finding

In ten days of June 2026, Washington wrote a policy whose object changed in kind. The earlier doctrines were doctrines of employment, they said how to act in cyberspace. The Pentagon's 2018 cyber strategy had set out the two terms: defend forward, which means disrupting malicious activity at its source, on foreign infrastructure, before it reaches American networks, and persistent engagement, continuous presence in contact with the adversary below the threshold of armed conflict²³. The industrial disruption of criminal infrastructure is its later variant (article 20). The June texts organise something else: what you hold, who gets access, who can switch it off. The yardstick has gone into secrecy, the agency that published has left the table, and access to the most advanced capabilities is now distributed by designation.

For a European security officer, the consequence fits in a sentence: no usable indicator will come out of this arrangement. The characterisation of the offensive cyber capabilities of frontier models will remain dependent on the voluntary publications of the labs and their evaluators, with the incentive to under-report that this situation carries. Any threat model incorporating these capabilities must treat the public figures as a floor. The ceiling is in the classified texts, and there is no longer a desk to ask at.


Twenty-fourth article in a series on the structural failures of Western cybersecurity:


Sources

¹ Executive Order 14409, "Promoting Advanced Artificial Intelligence Innovation and Security," 2 June 2026. Section 2(c)(iii): access facilitation by CISA. Section 2(d): clearinghouse formed by the Secretary of the Treasury, in consultation with the National Cyber Director, the Secretary of War through the director of the NSA, and the Secretary of Homeland Security through the director of CISA; "coordinates and deconflicts scanning for software vulnerabilities." Section 3(a): classified benchmarking, threshold determination by the director of the NSA. Section 3(b): voluntary framework, 30 days, trusted partners. Section 3(c): exclusion of any mandatory licensing. https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/ (Federal Register publication: 91 FR 34565, https://thefederalregister.org/documents/2026-11415/promoting-advanced-artificial-intelligence-innovation-and-security)

² Curi, M., "Scoop: Inside Trump's AI framework," Axios, 4 August 2026. Content of the framework according to briefed anonymous sources: "closed-source" definition, exclusion of open models, high-security storage, access logging, non-publication of the document. https://www.axios.com/2026/08/04/trump-ai-framework-open-models

³ National Security Presidential Memorandum NSPM-11, "Artificial Intelligence in the National Security Enterprise," 5 June 2026. Section 2(c): clause prohibiting any commercial capability to disable without federal approval. Section 3(b): termination for "pattern of conduct." Section 4(c): protection against "malicious distillation attacks." Section 4(e): collection on foreign AI technologies. Revokes NSM-25 (October 2024). https://www.whitehouse.gov/presidential-actions/2026/06/national-security-presidential-memorandum-nspm-11/

⁴ National Security Presidential Memorandum NSPM-12, "National Policy for the Cybersecurity of National Security Systems," 12 June 2026. Section 3(a): CNSS composition, four members, CISA director among the advisers. Section 5: NSA as National Manager, emergency directives, cryptologic authority, foreign liaison (5(c)(viii)). Revokes NSD-42 (1990) and NSM-8 (2022). https://www.whitehouse.gov/presidential-actions/2026/06/national-security-presidential-memorandum-nspm-12/

⁵ Rozen, C., "Trump advisers tell AI firms they will not safety-test open-weight models," Reuters, 4 August 2026. Exclusion of open weights (Nemotron, Llama) on two sources; composition of the meeting (Meta, Anthropic, Google, Nvidia, OpenAI) on five sources; sourcing distinct from that of Axios. Named statements by Liz Huston (White House) and Americans for Responsible Innovation. Dispatch consulted through full syndication, the reuters.com original being paywalled. https://www.yahoo.com/news/politics/articles/meta-anthropic-google-openai-meet-143841106.html

⁶ The Hill, "Trump administration's closed-door AI framework catches tech policy sector off guard," August 2026. FOIA request by the Foundation for American Innovation to the Office of the National Cyber Director. https://thehill.com/policy/technology/6017847-trump-closed-door-ai-framework-withheld/

⁷ Senate letter of 3 August 2026 to Secretaries Rubio, Bessent and Lutnick, the White House chief of staff, and Directors Kratsios and Cairncross, on access to frontier models. https://www.gillibrand.senate.gov/wp-content/uploads/2026/08/Senate-AI-Model-Access-Letter.pdf

⁸ Nextgov/FCW, "Top cyber official wants US open-source AI adopted worldwide," August 2026; CyberScoop, "National cyber director lays out White House plans to secure AI without writing new rules," 5 August 2026. Statements by Sean Cairncross on the worldwide spread of American open source and on the non-regulatory nature of the executive order. https://www.nextgov.com/artificial-intelligence/2026/08/top-cyber-official-wants-us-open-source-ai-adopted-worldwide/415222/ ; https://cyberscoop.com/trump-ai-executive-order-open-source-strategy-sean-cairncross/

⁹ Crowell & Moring LLP, "NSPM-11: Trump's National Security Memorandum on AI — What Defense Contractors Must Know," 12 June 2026. Contractual analysis: termination "for default or for convenience," subcontractors included, waivers capped at one year. https://www.crowell.com/en/insights/client-alerts/national-security-memorandum-aims-to-accelerate-deployment-of-ai-and-streamline-procurement-aligned-to-administration-policies

¹⁰ Nguyen, V. and Horowitz, M., "What Trump's National Security AI Memo Gets Right — and Leaves Unresolved," Council on Foreign Relations, 9 June 2026. Pentagon/Anthropic dispute: refusal of two contractual limits (lethal autonomous weapons, domestic mass surveillance), "all lawful purposes" requirement, supply chain risk designation. Nguyen's "assured intelligence" reading; he was the NSA's first AI lead. https://www.cfr.org/articles/what-trumps-national-security-ai-memo-gets-right-and-leaves-unresolved

¹¹ Ruling of Judge Rita Lin, US District Court, Northern District of California, 27 August 2026. Unlawful retaliation under the First Amendment, "arbitrary and capricious" decision, denial of pre-deprivation process under the Fifth; purely contractual nature of the usage limit and absence, in the administrative record, of any description of technical means of disabling; proposed application of the Defense Production Act days before the challenged actions. Ruling not consulted in full text; facts reported by several converging news outlets. https://www.computerworld.com/article/4215393/federal-judge-rules-for-anthropic-in-pentagon-dispute-nullifies-government-supply-chain-risk-designation.html ; https://www.npr.org/2026/08/28/nx-s1-5947951/judge-says-the-pentagon-cant-designate-ai-company-anthropic-a-supply-chain-risk ; https://techcrunch.com/2026/08/28/anthropic-gets-its-first-court-win-over-the-pentagons-supply-chain-risk-label/

¹² Center for AI Standards and Innovation (NIST): institute created in 2023 as the US AI Safety Institute, renamed in June 2025 by the Secretary of Commerce, mission narrowed to demonstrable risks (cybersecurity, biosecurity, chemical and biological weapons). Evaluations partly conducted in classified environments through the TRAINS Taskforce. https://labs.cloudsecurityalliance.org/research/csa-research-note-agentic-ai-governance-cisa-nist-caisi-2026/

¹³ NIST, Center for AI Standards and Innovation: pre-deployment testing agreements announced on 5 May 2026 with Google DeepMind, Microsoft and xAI, bringing to five the labs under agreement alongside OpenAI and Anthropic; more than forty evaluations completed, including unreleased models. https://labs.cloudsecurityalliance.org/research/csa-research-note-agentic-ai-governance-cisa-nist-caisi-2026/

¹⁴ Budd, T. (Senator, R-NC), letter to the National Cyber Director and the director of OSTP, 26 June 2026, and press release of 30 June. Instruction to CAISI to cease publishing its findings; link drawn by the senator to the executive order of 2 June and to the NSA director's power over the sharing of assessments. https://www.budd.senate.gov/2026/06/30/budd-calls-for-caisi-to-resume-publishing-research-on-frontier-ai-models/ (letter text: https://www.budd.senate.gov/wp-content/uploads/2026/06/CAISI-Letter_.pdf)

¹⁵ Curi, M., "White House finalizes AI framework behind closed doors," Axios, 3 August 2026. Framework completed on schedule; draft reviewed by Anthropic, OpenAI and Google; non-publication acknowledged by the White House. https://www.axios.com/2026/08/03/white-house-finalizes-ai-framework-behind-closed-doors

¹⁶ UK AI Security Institute: created in November 2023 as the AI Safety Institute following the Bletchley summit, renamed AI Security Institute in February 2025. https://www.aisi.gov.uk/

¹⁷ Reuters, "Britain Says it Is Open to AI Regulation if Voluntary Safeguards Fall Short," 4 August 2026. AISI pre-deployment access under voluntary agreements with OpenAI, Anthropic, Google. https://www.insurancejournal.com/news/international/2026/08/04/880112.htm

¹⁸ UK AI Security Institute, "Frontier AI Trends Report," 18 December 2025. Two years of evaluations, more than thirty models, doubling of the length of autonomous cyber tasks over a period of roughly eight months. Cited by the European Commission in COM(2026) 577 final, note 1. https://www.aisi.gov.uk/frontier-ai-trends-report

¹⁹ IAPP, "OpenAI grants European Commission access to new model as EU considers frontier AI cybersecurity risks," 28 May 2026. ENISA negotiation of access conditions; Commission spokesperson's statement on access through the AI Office's enforcement powers from 2 August 2026. https://iapp.org/news/a/openai-grants-european-commission-access-to-new-model-as-eu-considers-frontier-ai-cybersecurity-risks

²⁰ European Commission, "Action Plan on Cybersecurity and Artificial Intelligence," COM(2026) 577 final, 7 July 2026. Section 2.3: criticism of "provider-specific" access programmes, Blueprint with "no new obligations," contingency measures, joint procurement. Section 4.2: "vulnerable user of frontier AI systems made elsewhere that others can suddenly switch off." Section 5: evaluation network coordinated by the UK AISI. Key Actions 1 to 3: evaluation capacity (2027), Blueprint (Q4 2026), testing platform (Q4 2026). https://digital-strategy.ec.europa.eu/en/library/eu-action-plan-cybersecurity-and-artificial-intelligence (press release: https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1544)

²¹ "The Bletchley Declaration by Countries Attending the AI Safety Summit, 1-2 November 2023," GOV.UK, 1 November 2023. Twenty-eight countries and the European Union as signatories; first international summit devoted to frontier AI risks; commitment by the leading labs to submit their models to government testing before release. https://www.gov.uk/government/publications/ai-safety-summit-2023-the-bletchley-declaration/the-bletchley-declaration-by-countries-attending-the-ai-safety-summit-1-2-november-2023

²² CyberScoop, 5 August 2026: Nick Andersen, acting director of CISA, publicly presents the Gold Eagle desk created under section 2(d). https://cyberscoop.com/trump-ai-executive-order-open-source-strategy-sean-cairncross/

²³ US Cyber Command, "Achieve and Maintain Cyberspace Superiority: Command Vision for US Cyber Command," 2018, and Department of Defense Cyber Strategy, October 2018. Definition of defend forward: disrupt malicious activity at its source, including below the threshold of armed conflict. USCYBERCOM doctrinal briefing "Cyber 101: Defend Forward and Persistent Engagement." https://nsarchive.gwu.edu/sites/default/files/documents/semon9-giki0/2022-10-25-USCYBERCOM-Cyber-101-Defend-Forward-Persistent-Engagement.pdf