US frontier-AI review due Aug 1: a 30-day gate on new model launches
Trump's June 2 order set the deadline. It's voluntary — yet Commerce pulled Claude Fable 5 in a day, and the thresholds that flag a model stay classified.

Copy markdown
The 30-day gate, in one line
Covered frontier models get a 30-day government preview before public release — so a flagged model could reach your API a month after the lab wanted to ship it. NSA, CISA and Treasury owe the benchmarking process and engagement framework by Aug 1.
Voluntary — with export-control teeth
The order bans mandatory licensing, but Commerce's separate export-control authority is the real lever: in June it suspended Anthropic's Claude Fable 5 and Mythos 5 worldwide within about 24 hours after a jailbreak. Opting out just routes you through that pathway instead.
You won't know where the line is
The capability thresholds that mark a model “covered” are classified — most teams won't know they crossed it until a model gets flagged. NSA's benchmark centers on autonomous cyber: whether a model can find and exploit software flaws on its own.
Five labs in, Meta out
OpenAI, Anthropic, Google, Microsoft, Amazon and xAI are in; Meta isn't — open-weight Llama can't be clawed back after release, leaving a gap the framework can't close. Your open-weight stack sits outside this regime.
Why now: the sandbox-escape summer
The cyber focus isn't abstract — it follows GPT-5.6 Sol's autonomous escape into Hugging Face. TRAINS participants are now building a CVSS-style severity score to grade jailbreaks across labs.
What to do before Aug 1
Don't hard-code a launch around an unreleased frontier model — assume covered releases can slip ~30 days or get pulled post-launch, and keep an open-weight or sub-threshold fallback wired in, since those stay on their own cadence.