Essay · August 5, 2026

Governed in Washington, regulated in Brussels

The frontier-model framework is finished, in force, and unreadable. What that means for European insurers.

The framework exists. It was finished on time. You cannot read it.

I. Finished, in force, unpublished

On 4 August, the White House convened staff-level meetings with OpenAI, Anthropic, Google and Meta to walk them through the voluntary frontier-model framework ordered by the executive order of 2 June — Promoting Advanced Artificial Intelligence Innovation and Security. The administration confirmed the framework is complete and that discussions about next steps are under way. It has not disclosed what the document contains, who reviewed it, or when participating developers begin to work with it. Companies that were not in the room remain in the dark about its contents. Asked whether it would be released, an official offered the operative sentence of the week: unclassified, he said, “doesn’t mean we are going to broadcast them to everyone”.

That sentence rewards a second reading. The executive order classifies the benchmarks against which covered models are assessed. It does not appear to classify the framework document itself — the official’s phrasing concedes as much. Which means the withholding is discretion rather than secrecy law: not we cannot tell you, but we have decided not to.

For several days beforehand the story had been the opposite — a deadline apparently missed, no Federal Register notice, no publication from NIST or CISA, no statement from OSTP. The correction matters less than what it reveals. The framework was not late.

The week that preceded the meeting was noisy in a way that is worth reading alongside it.

II. Two letters, one addressee

Two open letters appeared, pointing in opposite directions.

The first, Open Weights and American AI Leadership, appeared on 24 July with some twenty-five signatories — Nvidia, Microsoft, Meta, Mistral, IBM, Hugging Face, the Linux Foundation among them. Its argument is threefold: open-weight models broaden economic access, they keep the market competitive, and they improve security, because many eyes audit better than few. The more telling fact is who did not sign: the leading closed-model developers.

The second, Pacing the Frontier, followed on 28 July, signed by over a thousand employees of the frontier laboratories in their personal capacity — including named research leadership at OpenAI, Anthropic, Google and Meta. It asks the US government to support international technical and governance tools to “deliberately pace the frontier of automated AI development”. Explicitly not a pause; the option to buy time, should it be needed.

It is tempting to read these as two sides of one argument. They are not. The first is a lobbying document about market structure, aimed at a specific anticipated restriction; it does not concede that frontier capability warrants government oversight — its claim is closer to the opposite, that distributed scrutiny already supplies what oversight would. The second is closer in shape to arms control: an appeal to governments to build, internationally, a capability that does not yet exist.

What the two share is an addressee. Both are written to the United States government, and both proceed on the assumption that what Washington decides about frontier models is what will happen. Nobody contested that assumption, in either letter or in the commentary around them. For a European reader it is the most consequential thing on either page.

The second letter is also something rarer, and it deserves noting on its own terms: an admission from inside the laboratories that the pace of their own work may need to be constrained, signed by the people who would bear the cost of constraining it.

The timing sharpened the point. The meeting came days after both OpenAI and Anthropic disclosed incidents in which AI agents had broken out of their intended scope and accessed other companies’ systems. Whatever one makes of the framework’s substance, the cybersecurity framing it adopts is not a pretext.

III. What the framework formalises

The framework formalises a practice that was already running.

Between mid-June and early July, a Commerce Department export-control directive suspended global access to Anthropic’s most capable models, followed by a staged, government-approved restoration — using statutory authority that predates the executive order by years. GPT-5.6 did not launch to the public; it launched to roughly twenty approved organisations, with the government involved in deciding who received preview access.

What the framework adds is a shape for that practice. Under the executive order, developers may engage the government to determine whether a model under development qualifies as a “covered frontier model” — a designation the NSA director makes, in consultation with defence and cyber officials. Participating developers may then give the government access for up to thirty days before releasing the model to other trusted partners, and collaborate with the government in selecting those partners. The benchmarks are classified. The programme cannot be used to establish mandatory licensing or preclearance — which is the legal ceiling, not a description of the incentives.

There is a further step, and it is the one that matters most to anyone buying these models. Gold Eagle, launched in mid-July and presented as a vulnerability clearinghouse, is reported to be developing into something else: a central body that decides which partners may be admitted to a model rollout at all. If that reporting holds, developers would need Washington’s assent before extending access to their own customers — which puts arrangements like Anthropic’s Project Glasswing and OpenAI’s Daybreak consortium in question. The control point moves from whether a model ships to who is on the list.

The White House rejects that reading. An administration official has said the government issues no approvals for private model releases, that engagement with government experts is voluntary, and that decisions on the timing and scope of releases rest entirely with the companies. The gap between that account and the reported practice is worth leaving open rather than resolving; both cannot be wholly right, and which one describes reality is precisely the uncertainty a European buyer has to plan around.

“Voluntary”, in other words, describes the paperwork. The operative decisions — who may access which model, when, on what terms — are being taken against criteria that are not published, through instruments that require no new law.

IV. Supply and use

The temptation is to call this the American counterpart to the AI Act. It is not, and the difference is the whole argument.

The two regimes act at opposite ends of the same lifecycle. Washington governs supply: which models exist for whom, released when, to which partners, on conditions settled before anything reaches a customer. Its instruments — export controls, staged release, the selection of trusted partners — all operate at or before the moment of distribution. Brussels regulates use: what may be done with a model once it is on the European market, with obligations running down the value chain to the undertaking that operates it.

Europe’s enforcement arrived the same week, which is worth stating precisely because the coincidence invites overreading. The GPAI obligations themselves have applied since August 2025. What changed on 2 August 2026 is that the Commission may now enforce them: compel technical documentation, evaluate models directly, order corrective measures, restrict or withdraw a model from the European market, and fine a provider up to three percent of worldwide annual turnover or fifteen million euros. For a year those duties existed largely on paper. They do not any more.

But this is market supervision, not a gate. The AI Office acts on models that are on the market or being placed on it; no European approval stands between a model and its existence. Which means the sequence runs one way only. By the time Brussels can act on a model, Washington has already settled whether, when and to whom it was supplied.

The asymmetry extends to what can be read. The European regime is a published statute with public criteria, named addressees, an identified authority and judicial review. The American one is a completed document nobody outside the room has seen, administered by no designated office — the National Cyber Director, the Treasury Secretary and the Commerce Secretary have been sharing the file between them — against benchmarks that are classified. One regime you can contest. The other you can only observe.

And the timing carries its own irony: Washington is building supply-side control at precisely the moment Brussels defers the obligations it had planned, with the Digital Omnibus moving the standalone high-risk deadlines to December 2027 and the embedded ones to August 2028, while leaving the general-purpose and transparency dates untouched.

This is the position a European insurer occupies, and it is not a position between two comparable authorities. It carries the full obligations of a regime that governs what it does with these models — for models whose availability is decided in a jurisdiction where it has no standing whatever. Neither regime was designed with the other in mind. No institution owns the seam. The insurer does, by default.

One regime you can contest. The other you can only observe. The asymmetry in brief · August 2026

V. Three consequences

Three consequences follow, all of them practical.

First, frontier model supply is now a third-party dependency with a political failure mode. DORA has taught the industry to ask about concentration risk, substitutability and exit strategies. The June suspension was a live test of a scenario few risk registers contained: for several weeks, the operative question was not whether the provider was reliable, but whether the provider was permitted.

The framework sharpens this considerably, because of a phrase in the executive order that has attracted little attention: trusted partners. Early access to a covered frontier model runs to trusted partners selected in collaboration with the US government. What nobody can currently say is who qualifies — including whether any friendly government will receive early access at all. Asked to comment, the European Union declined; the United Kingdom did not respond. So the category that determines which European organisations reach the frontier first is undefined, unpublished, and awaiting occupants, and Europe’s institutions have so far said nothing about it at all.

Provider due diligence should acquire two questions accordingly. Under which jurisdiction’s discretionary controls does this model sit? And what notification reaches us if access is restricted or delayed by government decision rather than commercial one — a contractual question, since standard force-majeure and service-level language rarely anticipates a supplier who is willing but not permitted.

Second, the open-weight question cuts both ways, and it is worth being honest about that. Open weights are the obvious sovereignty answer: weights running on your own infrastructure cannot be switched off from Washington — which is precisely why Mistral signed the letter, why the Commission is funding a European open-source frontier model across all twenty-four official languages, and why sovereign AI has become a European growth industry. But sovereignty is a transfer of control, not an escape from it. With a self-hosted near-frontier model there is no provider-side lever left at all: no upstream usage policies, no provider safety team, no staged rollback, nobody to revoke a key. Every control the provider used to operate becomes the deploying organisation’s job. For a regulated undertaking, open weights are therefore simultaneously the answer to the supply problem and the hardest governance case on the books. The letter’s signatories are right that openness distributes power. They are quieter about the fact that it distributes responsibility with it.

Third, the two regimes are about to collide on evidence, and the collision lands on the deployer. Since 2 August the AI Office may request technical documentation, evaluate general-purpose models and require corrective measures; obligations run down the value chain, and an undertaking deploying such a model must be able to show what it knows about it. On the American side, the executive order provides for assessment against classified benchmarks — but whether any model has yet been reviewed, against what, and with what result is not observable from outside. The foreseeable consequence is an undertaking asked by a European authority to evidence properties of a model whose most rigorous safety assessment, if it exists, sits inside another state’s classification regime.

That gap will not close by asking the provider more politely. What can be done is to document the boundary rather than paper over it: record what the provider can attest to, what it cannot and why, and where the undertaking’s own testing has to stand in. Supervisors have generally proved willing to accept a well-reasoned limit. They are considerably less forgiving of a silent one.

None of which is exotic work. It is inventory, provenance and documented testing — governance as a design principle rather than a downstream compliance filter.

VI. What to do before the text appears

The instinct is to wait for the document. It would be a mistake — not because publication is impossible, but because nobody will say whether it is coming. The framework is complete and is being briefed to the companies that supply Europe with its most capable models, and the White House has left the question of release unanswered. Planning around a text that may or may not appear is not a compliance strategy.

What can be done instead is unglamorous and available now. Know which application depends on which model through which supply chain — an inventory with provenance, not a vendor list. For the critical cases, hold a documented fallback, and price it honestly, especially where it leads to open weights and the governance load that comes with them. Write the state-ordered restriction into the contract, since commercial language does not cover it. And document the point at which the evidence runs out, rather than hoping nobody asks.

There is a second task, and it belongs further up. Somebody in Brussels should be asking who counts as a trusted partner, and whether Europe intends to be one. On the evidence of this week, nobody is.

Read next