EO 14409
Promoting Advanced Artificial Intelligence Innovation and Security (Executive Order 14409)
US executive order directing federal cyber-defense upgrades and establishing a voluntary framework under which advanced-AI developers may submit 'covered frontier models' for classified national-security benchmarking up to 30 days before release. Expressly prohibits any mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of AI models.
Jurisdiction
United States
Enacted
Jun 2, 2026
Effective
Jun 2, 2026
Enforcement
Executive-branch agencies (Treasury, NSA, DHS/CISA, OMB, OPM, Commerce/NIST); Department of Justice for criminal enforcement against AI-enabled crimes
Signed June 2, 2026; published in the Federal Register June 5, 2026 (91 FR 34565). Agency implementation deadlines fall ~July 2 and ~August 1, 2026.
White House — Presidential ActionsWhy It Matters
Marks a shift toward federal engagement with frontier-AI security while expressly rejecting a mandatory licensing or preclearance regime, in contrast to the EU AI Act's binding pre-deployment obligations. Reliance on a classified benchmarking process and national-security authorities — rather than published rules — leaves the boundary of 'covered frontier model' and the government's leverage over releases undefined, a tension underscored when export-control authority was used days later to restrict a commercial model.
Recent Developments
On June 12, 2026 — ten days after the order — the Department of Commerce's Bureau of Industry and Security issued a non-public export-control directive (signed by Commerce Secretary Howard Lutnick) requiring Anthropic to suspend access to its Fable 5 and Mythos 5 models for any foreign national worldwide, citing military-intelligence end-use risk. Commentators noted the directive imposed a de-facto licensing requirement of the kind this order disclaims; it is being challenged in Legion LegalTech Corp. v. United States (No. 1:26-cv-02225) on ultra vires, IEEPA (Berman exemption), and Administrative Procedure Act grounds. A related National Security Presidential Memorandum (NSPM-11) followed on June 5, 2026.
At a Glance
Applies to
Who Must Comply
- Federal agencies (binding internal obligations)
- Developers of 'covered frontier models' (voluntary engagement)
Obligations fall on:
Safety Provisions
- Voluntary pre-release benchmarking of 'covered frontier models' for advanced cyber capabilities, with up to 30 days of federal access before release
- Classified benchmarking process developed by Treasury, NSA, and CISA
- Federal cyber-defense prioritization for National Security Systems
- AI cybersecurity clearinghouse for vulnerability coordination and patch distribution
- Attorney General directed to prioritize criminal enforcement against AI-enabled computer crimes
Compliance & Enforcement
Key Dates
Jul 2, 2026
30-day federal actions: National Security Systems cyber-defense prioritization; DHS/CISA Binding Operational Directives on AI cybersecurity tools; Treasury/NSA/CISA AI cybersecurity clearinghouse; OMB grant-funding determination
Aug 1, 2026
60-day actions: OPM cybersecurity hiring expansion; Treasury/NSA/CISA/Commerce(NIST) design of the voluntary 'covered frontier model' benchmarking framework (up to 30 days' federal pre-release access)
Penalties
No civil penalties or fines on private-sector AI developers; the frontier-model framework is voluntary. Criminal enforcement is directed only against unlawful use of AI to access or damage computer systems.
View on map
United States
Focus Areas
General regulation
Cite This
APA
United States. (2026). Promoting Advanced Artificial Intelligence Innovation and Security (Executive Order 14409).
Related Regulations
State AG AI Warning
Coordinated state AG warnings: 44 AGs (Aug 25, 2025, led by TN, IL, NC, and SC AGs) and 42 AGs (Dec 2025, led by PA AG) to OpenAI, Meta, and others citing chatbots "flirting with children, encouraging self-harm, and engaging in sexual conversations."
NIST AI RMF
Dominant voluntary AI governance framework in the US. Four functions (Govern, Map, Measure, Manage) operationalize what regulators expect. Not legally binding but heavily referenced.
NE LB 525
Adopts the Conversational Artificial Intelligence Safety Act, imposing disclosure duties on operators of conversational AI services and requiring protocols addressing crisis situations and behavioral health care, enforced by the Attorney General with civil penalties.
IL HB 5511
Requires covered operators of online platforms to apply protective default settings to users they know to be minors, including limits on algorithmic feeds, a 10 p.m. to 7 a.m. notification curfew and no autoplay by default on addictive social media platforms, and establishes a device-level age-bracket signal that Internet-enabled device manufacturers must provide and operators must request. Announced by the Governor as the Children's Social Media Safety Act, the title of the bill as introduced. Enforced by the Attorney General.
NJ Kids Code
Codifies a New Jersey Age-Appropriate Design Code requiring covered online service providers to design services likely to be accessed by minors around minors' safety and wellbeing, including high-privacy defaults, limits on engagement-maximising design features, and data protection impact assessments. Enforced by the Attorney General with a private right of action for minors and their parents.
NY SAFE Act
Restricts algorithmically personalized ("addictive") feeds and overnight notifications for under-18 users without parental consent.
Last updated June 27, 2026. Verify against primary sources before relying on this information.