White House issues executive order promoting advanced AI innovation and security
On June 2, 2026, the White House issued Executive Order 14409, "Promoting Advanced Artificial Intelligence Innovation and Security." The order focuses on three areas: (1) upgrading the cyber defenses of government information systems, (2) establishing a voluntary framework for developers of frontier AI models to engage with the government prior to deployment to promote cybersecurity, and (3) directing enforcement resources toward criminal misuse of AI. Below, we break down the key provisions and what they may mean for the relevant governmental agencies, AI developers, and critical infrastructure operators.
Section 2 of the order directs federal agencies to take rapid action to modernize and harden information systems against AI-related cyber threats, with an aggressive 30-day timeline for several key actions:
Additionally, the Office of Personnel Management must expand the U.S. Tech Force cybersecurity specialist hiring and placement pathways within 60 days of the order’s issue date.
Perhaps the most significant aspect of the order for AI developers is Section 3, which directs senior officials to develop a voluntary framework for the secure deployment of frontier AI models within 60 days. The framework has two main components:
Classified benchmarking: Agencies must develop and maintain a classified benchmarking process to assess the advanced cyber capabilities of AI models and determine the threshold at which a model should be designated a "covered frontier model." The NSA director will make the ultimate designation, in consultation with other senior officials.
Voluntary developer engagement: The framework will create a process through which AI developers may engage with the government to:
No mandatory actions: The order expressly states that it does not authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models. This reinforces the administration's stated policy of avoiding "overly burdensome regulation" of AI development and is consistent with the U.S. government’s emphasis on voluntary information-sharing in cybersecurity policy.
Section 4 of the order directs the U.S. attorney general to prioritize enforcement of federal criminal laws, such as the Computer Fraud and Abuse Act (18 U.S.C. § 1030), against anyone who uses AI to engage in cybercrime.
Notably, the order specifically calls out the use of AI agents to unlawfully access data or compromise IT systems, consistent with growing concern among policymakers about autonomous or semi-autonomous AI systems that could conduct cyberattacks or facilitate unauthorized access.
The order carries several practical implications across industries:
The order's aggressive timelines—30 days for the cybersecurity directives and clearinghouse, 60 days for the frontier model framework—mean that concrete details could emerge as early as July 2026. Companies should watch for the forthcoming classified benchmarking criteria and the details of the voluntary engagement framework, both of which will shape how the government defines and interacts with frontier AI models going forward.
More broadly, this order is the latest in a series of federal actions that underscore the growing intersection of AI policy and national security. Companies that develop, deploy, or rely on advanced AI systems should be proactive in understanding how these initiatives may affect their operations and compliance obligations.
The information provided is not intended to be a comprehensive review of all developments in the law and practice, or to cover all aspects of those referred to.
Readers should take legal advice before applying it to specific issues or transactions.
Ashurst Perkins Coie practises law in Singapore through Ashurst Perkins Coie UK LLP and also maintains a Formal Law Alliance with ADTLaw LLC, known as Ashurst ADTLaw.
Ashurst Perkins Coie UK LLP is regulated in Singapore by the Attorney-General's Chambers of Singapore and is registered under the LLP Registration Act, Registration No. LL0701574M.
Ashurst ADTLaw is a Formal Law Alliance licensed and regulated by the Legal Services Regulatory Authority of Singapore under number LSRA/FLA/2017/00001. ADTLaw LLC is a limited liability company registered in Singapore under number 201324473R, licensed and regulated by the Legal Services Regulatory Authority of Singapore under number LSRA/LLC/2013/00191.