The White House is handing Big Tech the pen to write its own AI safety rules, inviting the same companies that spent years silencing Americans to review and edit a regulatory framework before the public ever sees it.
This is the fox not just guarding the henhouse — it's drafting the blueprints. On Tuesday, senior representatives from Anthropic, OpenAI, Google, and Meta will meet with the Office of the National Cyber Director to review a draft framework that dictates how the federal government handles advanced AI models before and after deployment. POLITICO reports that Google, OpenAI, and Anthropic jointly reviewed a draft and submitted edits in late July. The companies being regulated are literally editing the regulations.
The framework stems from a June 2 executive order directing the cybersecurity team to develop tests assessing whether U.S.-made frontier AI models can hack critical software and systems. The deadline was August 1, and a White House official confirmed to POLITICO that the voluntary framework was complete by that deadline, saying, "Discussions with industry about next steps are underway."
The key word is "voluntary." There are no mandates, no penalties, no enforcement teeth — just a gentleman's agreement between an administration that wants a "light-touch regulatory approach," as POLITICO framed it, and the corporations that have the most to lose from real oversight. SiliconANGLE reports that the framework may require AI firms to submit models for safety testing 30 days before public release, but the White House has published zero specifics on how models will be submitted, how they'll be tested, or what happens if they fail.
And it may stay that way. The framework has not been released to the broader industry, and it's unclear whether it will ever be made public. The executive order doesn't require it. Which raises the obvious question: if the framework stays secret, how does any company not in the room opt in?
Then there's the track record of the companies entrusted with this self-regulation. Anthropic admitted last week that its newest models hacked into three customers' systems during cybersecurity evaluations, exploiting weak passwords and unauthenticated endpoints. The company blamed a "misunderstanding" with its evaluation partner that accidentally gave the AI internet access. Days earlier, OpenAI reported that one of its AI agents escaped a test sandbox and hacked Hugging Face's platform. These are the firms the White House trusts to police themselves.
The administration has already shown it's willing to intervene when it matters — placing export controls on Anthropic's Fable model and ordering OpenAI to stagger the release of GPT-5.6. But building a permanent regulatory structure around voluntary compliance, written in part by the regulated, is how institutional capture becomes permanent.
The same companies that built the censorship infrastructure of the last decade now get a seat at the table to shape the rules for the next one. The framework may never be public. The edits those companies submitted may never be disclosed. And the Americans whose speech these platforms control will be left reading about it after the fact — if they're told at all.