On June 2, 2026, President Trump issued an executive order (the “Order”) on artificial intelligence innovation and cybersecurity. The Order focuses on the cyber risks and defensive potential of advanced frontier AI models, including their ability to accelerate both malicious vulnerability discovery and cyber defense.
Although directed primarily to federal agencies, the Order offers important signals for AI developers, critical infrastructure operators, cybersecurity vendors, and other companies seeking to understand evolving federal expectations around AI-enabled cyber risk. It also provides a signal to companies: the federal government is developing a plan for dealing with frontier AI models and their impact on cyber, and the private sector should be doing the same.
The President also directed the Department of Justice to prioritize the investigation and prosecution of identity theft and wire fraud that is committed with the aid of AI.
In this blog post, we outline key aspects of the Order and explore implications for private companies.
Overview of the Order
As we have written, U.S. and U.K. regulators in the financial services sector are focusing on frontier AI models in the wake of the release of Anthropic’s Mythos Model. The Order reflects a broader federal focus on frontier AI cybersecurity risk, while preserving a stated commitment to avoiding “overly burdensome regulation.” Notably, the Order does not authorize any mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models.
Key elements of the Order include the following:
1. Development of Benchmarking for Covered Frontier Models
The Order directs Treasury, NSA, CISA, NIST, and other federal stakeholders to develop and maintain a classified benchmarking process to assess the advanced cyber capabilities of AI models and determine when a model should be designated a “covered frontier model.” This process is significant because it is the gateway to the Order’s voluntary early-access framework (described below). Although the Order does not publicly define the technical criteria for designation, companies may wish to monitor whether agencies later issue unclassified guidance, procurement expectations, or other signals that help explain how covered frontier models will be identified and treated.
2. Expanded Access to AI-Enabled Cybersecurity Tools
The Order directs CISA and other federal stakeholders to expand or establish programs and cybersecurity services that enhance AI-enabled defensive tools and facilitate access to those tools for federal agencies, state and local authorities, and critical infrastructure operators, including rural hospitals, community banks, and local utilities. For private companies, this directive may create opportunities to participate in federal cybersecurity services or pilot programs, while also shaping future expectations for cyber resilience as AI-enabled defensive capabilities become more widely available.
3. Establishing an AI Cybersecurity Clearinghouse
The Order directs the Secretary of the Treasury, in consultation with the National Cyber Director, NSA, and CISA, to form an AI cybersecurity clearinghouse in voluntary collaboration with the AI industry and critical infrastructure operators. The clearinghouse is intended to coordinate and deconflict software vulnerability scanning, validate vulnerabilities, and coordinate and prioritize remediation and the distribution of patches.
4. Voluntary Early Access to Covered Frontier Models
The early access framework would allow AI developers to voluntarily provide the federal government with access to covered frontier models for up to 30 days before release to trusted partners, subject to confidentiality, cybersecurity, insider-risk, intellectual-property, use, and nondisclosure protections. The framework also contemplates collaboration between AI developers and the federal government to select trusted partners that may receive early access to covered frontier models.
5. Prioritized Enforcement of AI-Enabled Criminal Acts
The Order directs the Attorney General to prioritize enforcement of federal criminal laws against actors that use AI to unlawfully access or damage computers, commit identity theft or wire fraud. This includes unlawful access to public or private IT systems and the use of AI agents to access data later used for criminal or unlawful purposes.
Implications for Private Companies
Although the Order is directed primarily at executive agencies and AI developers, it carries implications for other private companies including.
1. Heightened Cyber Threat Environment. The Order only requires federal departments to prioritize cyber defense, but companies may nonetheless want to follow suit, including by evaluating whether their existing cybersecurity programs, (e.g., threat detection, incident response, and employee training), account for AI-enhanced attack vectors. Over time, agency guidance, procurement expectations, or industry practices developed under the Order could influence expectations of “reasonable security” under risk-based cybersecurity frameworks in the United States and abroad. Companies may also consider whether AI-enabled cyber risk should be addressed in board or senior management reporting, incident response tabletop exercises, and cyber-risk assessments.
2. AI Model Provider Risk. Companies that rely on AI-enabled services from third-party vendors should consider how the Order’s emphasis on frontier model security may affect their supply chain. As the voluntary frameworks contemplated by the Order develop, vendors’ participation (or non-participation) in government cybersecurity coordination efforts may become a relevant due diligence consideration.
3. Confidentiality, Intellectual Property, and Information-Sharing Considerations. Companies that participate in voluntary model-access, vulnerability-scanning, or clearinghouse activities will need to consider how sensitive technical information, vulnerability data, model information, and intellectual property will be protected. Companies considering participation in any voluntary framework should evaluate information-sharing protocols, contractual protections, privilege considerations, disclosure controls, and internal approval processes before sharing sensitive technical information with government or industry partners.
4. Critical Infrastructure Considerations. The Order’s reference to rural hospitals, community banks, and local utilities suggests that implementation may focus not only on large infrastructure operators, but also on smaller entities that provide important community or sectoral functions. Companies in sectors such as financial services, healthcare, and energy should monitor whether agency guidance or clearinghouse participation opportunities become available.
The authors would like to thank Debevoise Summer Associate Rachel Fuzaylov for her contribution to this blog post.
* * *
To subscribe to the Data Blog, please click here.
The cover art used in this blog post was generated by ChatGPT.
The Debevoise STAAR (Suite of Tools for Assessing AI Risk) is a monthly subscription service that provides Debevoise clients with an online suite of tools to help them responsibly fast-track their AI adoption. Please contact us at STAARinfo@debevoise.com