How the 30-Day Look Is Built on Numbers No One Outside the NSA Can See
The mechanics of the framework are, on paper, simple: a developer can voluntarily hand the federal government access to a 'covered frontier model' for up to 30 days before releasing it to other trusted partners [1]. What counts as 'covered' is where things get opaque. The order defines it as closed-source, state-of-the-art, and posing a national security risk, but the actual thresholds - the benchmarks, the capability cutoffs - are set by a classified system built by the NSA Director in consultation with CISA, the National Cyber Director, and the Assistant to the President for Science and Technology [6]. Developers do not get to see the criteria that will determine whether their own model gets pulled into review.
That secrecy extends past the technical threshold into the framework itself. Even though a White House official acknowledged the document is not formally classified, the administration chose not to release it, arguing selective disclosure is a deliberate choice: 'Just because things are unclassified that doesn't mean we are going to broadcast them to everyone' [2]. Critics see that as a distinction without a difference. Chris McGuire of the Council on Foreign Relations put the core objection bluntly: 'We can't have secret, voluntary rules to regulate the most important tech in the world' [4]. Coverage of the framework has framed the same tension as an open question - whether a framework that nobody outside government can read, built on benchmarks nobody outside the NSA can see, qualifies as the transparency the executive order promised [2]. The order also tasks Treasury, the NSA, and CISA with standing up an 'AI cybersecurity clearinghouse' to coordinate vulnerability scanning and patch distribution with industry [1].



