National Cyber Director Sean Cairncross’s remarks come as the White House has excluded open-weight models from voluntary security testing and as new hacking incidents underscored risks posed by autonomous AI. #
LAS VEGAS — The Trump administration wants U.S.-built open-source artificial intelligence to become a top technology of choice around the world, National Cyber Director Sean Cairncross said Tuesday in one of his clearest public endorsements to date of a larger role for open models in American AI policy.
“We are extremely interested in looking at ways to build U.S. open source, make it competitive, make it the preferential adoption by planet Earth,” Cairncross said during a discussion with Reflection AI CEO and co-founder Misha Laskin at the Black Hat cybersecurity conference.
He called open source a “vital” part of the U.S. AI ecosystem, citing its value to startups and developers that might otherwise lack access to the most advanced systems. He said the administration is looking for ways to grow and promote American open-source AI.
Cairncross’s remarks notably came the same day the White House told major developers that open-weight models would not be included in its new voluntary government testing program, raising possible questions about how the administration plans to assess the security risks of the same technology it wants to promulgate around the globe.
At the same time, Chinese developers like DeepSeek and Moonshot have released increasingly capable, lower-cost, open-weight models, fueling further debate in Washington over how the United States should compete in the global AI and cyber ecosystem.
Open-weight models make their underlying parameters available for others to download and modify, unlike closed systems controlled by companies like OpenAI, Google and Anthropic. The terms “open source” and “open weight” are often used interchangeably in the AI debate, though making a model’s weights available doesn’t necessarily provide access to all of the underlying code and data used to build it.
The White House testing framework stems from a June executive order directing national security agencies to create classified tests for identifying AI models capable of sophisticated cyberattacks. Under the program, the government can test qualifying models for up to 30 days before their wider release.
The administration has argued that open models can lower costs, support academic research and allow companies and governments to use AI without sending sensitive information to a closed-model provider. The White House’s AI Action Plan also described leading American open models as strategically valuable because they could become widely adopted global standards.
Cairncross argued Tuesday that more traditional regulation would be unable to keep pace with the technology and could inhibit its development.
“This is moving at such speed and such pace, a regulatory regime, one, would not only strangle growth, development and innovation and be enormously harmful to the industry, but it would be obsolete 48 hours after it was going through whatever process it had gone through,” he said.
Instead, Cairncross called for a “flexible, adaptable structure” that allows the government and AI companies to exchange information and respond quickly when problems arise.
That approach is facing an early test as researchers uncover cases in which autonomous AI agents exceeded boundaries established for cybersecurity evaluations.
Britain’s AI Security Institute disclosed Tuesday that agents powered by Anthropic and OpenAI models took unauthorized actions on the live internet during 10 of 122 test runs. The institute catalogued 19 cases, including an attempt to plant malicious code in a public open-source software project.
In the most serious case, an agent created fake online identities and tried to pressure a human maintainer into approving the code. The maintainer rejected it, and the institute said it found no resulting real-world harm.
The disclosure follows a separate incident involving an OpenAI agent that breached part of Hugging Face’s production infrastructure in July. OpenAI had loosened the model’s cybersecurity safeguards while testing how effectively it could find and exploit software vulnerabilities inside what was supposed to be an isolated environment.
Debates over AI with advanced hacking skills intensified in April when Anthropic withheld its first Mythos Preview model, citing its ability to discover and exploit previously undiscovered software flaws. Since then, developers have regularly introduced newer models with similar capabilities, while U.S. agencies have begun testing and deploying several of them in government environments.