← All posts

The AI Executive Order's "Voluntary" Framework: Why Your Board Can't Afford to Ignore It

On June 2, the White House signed an executive order titled "Promoting Advanced Artificial Intelligence Innovation and Security." The word that keeps showing up in the coverage is voluntary. Developers of frontier AI models can voluntarily give the government access before public release. Companies can voluntarily participate in a new AI cybersecurity clearinghouse. Nobody has to do anything.

I've seen this movie before. And I can tell you how it ends.

"Voluntary" Is the New Mandatory

In my experience, when the federal government builds a voluntary framework with a classified benchmarking process, 30-day government access windows, and a "trusted partner" designation for early participants — that's not optional. That's a soft mandate with a grace period.

Here's what the EO actually does. By August 1, 2026, the NSA — in coordination with the Treasury Department and CISA — must develop a classified benchmarking process to designate "covered frontier models" based on their advanced cyber capabilities. Once a model gets that designation, its developer can grant the government up to 30 days of access before releasing it to trusted partners. The government then collaborates with the developer to select those trusted partners.

The EO explicitly says it does not create a licensing or preclearance requirement. Skadden's analysis put it plainly: companies that decline to participate "may find themselves at a disadvantage in securing government contracts, gaining early access to federal cybersecurity resources, or being selected as 'trusted partners' for early model access."

That's the quiet part out loud. You don't have to participate. You just lose if you don't.

What This Means for the Boardroom

If your organization builds, deploys, or depends on advanced AI — and at this point, whose doesn't — this EO creates three questions your board should be asking right now.

First: Are any of our AI tools built on frontier models that could be designated "covered"? Most enterprises don't build their own frontier models, but they buy from companies that do. If your AI vendor's next model release gets delayed by a 30-day government review window, that affects your roadmap. If your vendor opts out of the framework and loses "trusted partner" status, that affects your risk posture. Your procurement team needs to know where you sit in this supply chain.

Second: Does our AI governance framework account for this new regulatory signal? The EO also directs the Attorney General to prioritize criminal enforcement under existing statutes — 18 U.S.C. §§ 1028, 1030, and 1343 — against anyone using AI to illegally access computer systems. That's not new law. It's existing law with a new enforcement priority. If your organization uses AI agents that interact with external systems, you need to be certain those interactions are authorized. The line between "automated efficiency" and "unauthorized access" just got a lot sharper.

Third: What's our exposure if voluntary becomes mandatory? The EU's AI Act already imposes binding obligations on general-purpose AI systems. The U.K.'s AI Security Institute conducts pre-deployment testing of frontier models. As DLA Piper noted, there have already been calls for Congress to codify the standards in this EO into permanent law. If your board isn't preparing for a world where AI pre-release review is mandatory, you're going to be scrambling when that day arrives.

The Cybersecurity Clearinghouse Nobody's Talking About

Buried in the EO is a provision that should matter to every CISO in America. Within 30 days of the order — so by early July 2026 — the Treasury Department, in consultation with the National Cyber Director, NSA, and CISA, was directed to form an "AI cybersecurity clearinghouse." This body coordinates vulnerability scanning, validates discoveries, and prioritizes remediation and patch distribution across the AI industry and critical infrastructure.

This is the government building a centralized nervous system for AI vulnerability management. If your organization operates critical infrastructure — and the EO specifically names rural hospitals, community banks, and local utilities — you should be tracking how this clearinghouse takes shape and whether participation gives you access to vulnerability intelligence you can't get elsewhere.

The Pattern You Should Recognize

I wrote about this dynamic in Cyber Risk Is Business Risk: the gap between compliance and actual security is where most organizations get hurt. This EO is a compliance signal. The organizations that treat it as just another box to check will miss the point entirely.

The real question isn't whether to participate in the voluntary framework. The real question is whether your organization has the governance maturity to evaluate these kinds of evolving regulatory signals — and respond before they become mandates.

That means asking your CISO this week: Do we know which of our AI vendors would be affected by this framework? Do we have a governance process that flags regulatory signals like this before they become emergencies? And are we building relationships with the agencies that will shape how this framework evolves — or are we going to be reacting after the rules are written?

The August 1 deadline for the classified benchmarking process is less than a month away. The clearinghouse should already be forming. This isn't a future problem. It's a now problem — and boards that treat "voluntary" as "ignorable" are going to learn the same lesson companies learned with GDPR, with the SEC's cyber disclosure rules, and with every other regulation that started as guidance and ended as law.