Coleman’s AI Policy Update (August 3–7, 2026)
This week in AI policy
There’s growing public scrutiny over what the Trump Administration and artificial intelligence companies are doing to keep our digital infrastructure safe from advanced AI systems. The White House revealed its long-awaited voluntary framework for reviewing the systems capable of dealing real-life damage, but the announcement left much to the imagination: the process itself is classified and few details are known about how it works.
Separately, more news came out about OpenAI’s AI agent escaping its containment last month, raising questions about what internal precautions are needed to prevent something like that from happening again. If the industry didn’t sense the public was freaking out enough over the past few weeks, that’s likely because details about what happened are only gradually emerging, as OpenAI and others continue releasing details weeks after the incident. With so much hidden from view or difficult to interpret, the public has little basis to form an informed opinion yet.
How the White House Built Its Frontier AI Review Framework
Roughly between June and August, the Trump administration formed an ad-hoc review regime.
President Trump issued Executive Order 14409 on June 2, 2026. The order outlined how the Administration would handle sophisticated cyber threats posed by advanced AI systems known as frontier AI models. It also established classified benchmarks for determining which AI models qualify as “covered frontier models” and directed agencies to develop a voluntary framework for reviewing them.
The voluntary process was no doubt designed for companies like OpenAI and Anthropic. But even as the Administration worked to put that framework in place, these developers were moving at their default speed — fast.
Not long after the executive order was published, Anthropic released Fable 5, a public model derived from Mythos 5, a far more capable AI model used for cybersecurity research. The creation of Mythos had already become a watershed moment for AI after Anthropic revealed that the model could discover and exploit previously unknown software vulnerabilities. Fable 5 represented Anthropic’s effort to make those advances available to users. by including stronger safety guardrails.
Nevertheless, on June 12, 2026, the Department of Commerce’s Bureau of Industry and Security (BIS) placed export controls on Fable 5 and Mythos 5 that effectively required Anthropic to disable them for all customers worldwide to ensure compliance. The restriction was reportedly triggered when Amazon told government officials how a user could bypass the model’s built-in safety safeguards.
The White House ad-hoc review framework was born. In the days and weeks that followed, Anthropic and the White House reportedly discussed the government’s security concerns and the conditions under which Fable 5 and Mythos 5 could return to service.
By the end of June, Anthropic agreed to proactively detect and address security risks, work with government officials on protocols, and strengthen Fable 5’s safety filters to aggressively block it from generating potentially dangerous cyber capabilities — all of which cleared the way for the model’s global redeployment on July 1. Access to Mythos 5 was likewise restored, but only to a subset of U.S. organizations through Project Glasswing, a cyber security coalition launched by Anthropic in April.
Other companies were in talks with White House as well. In June, OpenAI announced a limited preview of its flagship family of frontier models, the GPT-5.6 series (Sol, Terra, and Luna). At the government’s request, OpenAI limited access to a small group of trusted partners before it eventually became publicly available on July 9, weeks before that framework itself was finalized.
By late July, however, the interactions were becoming more formalized. Google, Anthropic, and OpenAI were reviewing the draft framework. After it was reported that it had been finalized, the White House’s Office of the National Cyber Director (ONCD) met with representatives from Anthropic, Google, Meta, and OpenAI and revealed more about how the framework would work. “Open-source” models — which are models anyone can download, study, and modify — would be excluded, while companies were encouraged to share their covered proprietary models with the government as close to their public release as possible.
Through its engagement with with AI companies, the White House transformed its ad hoc review process into something more formal. But because much of that approach remains a secret, it’s putting AI into a regulatory “black box.”
Even before the public had an opportunity to understand how the framework would work in practice, however, a series of AI breakouts would put the companies’ own safeguards to the test.
OpenAI’s Hugging Face Incident
July 16 was just another day until Hugging Face — a company that hosts AI models and datasets — disclosed that it was the target of an unprecedented agentic attack. According to the company, an autonomous AI agent exploited vulnerabilities in the system used to upload users’ datasets, giving it deeper entry into Hugging Face’s internal network. Once there, it spread across temporary cloud computing environments, abandoning each one after completing its attacks. Thankfully, Hugging Face ultimately detected and contained the intrusion.
Hugging Face later published a detailed technical reconstruction explaining the attack path, forensic investigation, and the AI agent’s behavior. The post filled in details that neither company’s initial announcement had fully described.
Five days after Hugging Face first disclosed the incident, OpenAI announced that the agentic attacker was one of its AI systems undergoing cybersecurity testing. According to OpenAI, the AI escaped its testing environment by exploiting a previously unknown security flaw in OpenAI’s infrastructure, gaining Internet access, and eventually reaching Hugging Face. As OpenAI released additional details about what happened, it also brought in CrowdStrike, METR, and Redwood Research to independently validate its findings and publish their own assessments.
The story is still unfolding in many ways. OpenAI continues releasing new technical details, including detailed presentations at a recent cybersecurity event. Public opinions are evolving, too. For its part, OpenAI said this week it would adopt a slower rollout for its next model.
The Hugging Face/OpenAI incident may be the first well-documented case of an emerging pattern of escapes. This week, we were told Meta’s frontier model and the Chinese model Kimi K3 had also escaped their respective testing environments, indicating that containment challenges are growing.
What remains constant is that the public isn’t receiving a single, definitive account of what’s happening. That seems impossible given the various sources of information. We’re left piecing together the jigsaw puzzle with every new bit of information adding another piece.
What this means is that the companies themselves do not have had a complete picture at the outset.
Recent Notables
Whose Speech Is It Anyway? The Constitutional Contours of Chatbot Regulation by Becca Branum
A New Research Agenda for AI Constitutionalism by Kevin Frazier
$2m crime novel deal collapses amid questions over AI use by Emma Loffhagen
Secret Loyalties in Government AI by Govind Pimpale and Blaine Dillingham
Artificial Intelligence and Human Legal Reasoning by Nicholas Bednar, et al.
Closing Thoughts
Federal frontier AI governance is no longer a theoretical debate. The White House constructed an oversight framework this summer while companies pushed the boundaries of what these systems can do, revealing new capabilities faster than anyone can keep up with yet.
The public rarely receives a complete picture all at once. Instead, through company disclosures, independent investigations, technical conferences, and investigative reporting, these events reveal this technology has real consequences. Even if there hasn’t been a broader public reaction yet, there’s no doubt these issues will continue to garner increasing public attention in the future.
—
If you liked this, follow @FreeSpeech_AI on X for ongoing analysis of AI policy.



