Trump Administration's Shift on AI Regulation
The Trump administration has made a significant U-turn on its stance on AI regulation, embracing a stricter approach to government scrutiny of frontier AI systems before public release. This reversal comes after a year and a half of downplaying calls for AI safety regulations.
An executive order initially designed to be friendly to the AI industry was meant to allow the federal government to briefly review some new models on a voluntary basis. However, the administration's sudden decision to slap export controls on Anthropic's Fable 5 and Mythos 5 in response to private sector threat intelligence reporting marks a new era for the U.S. AI industry.
Uncertainty Over the Administration's Line
Key questions and gaps remain, including why the administration drew the line where it did and whether it will move it again in the future. Cybersecurity experts and former government officials suggest that the administration may be playing catch-up on threats that have been building for years, as it has more fully realized the national security implications of the technology.
Users of the latest frontier models, including OpenAI's ChatGPT 5.5 and Fable 5, report that these models have been largely helpful to their work, despite complaints about high token usage and safety guardrails that hinder, but don't meaningfully prevent, defensive cyber tasks.
Industry Perspectives
Eyal Webber Zvik, chief strategy officer at Cato Networks, noted that they use GPT 5.5 and later OpenAI models to scan and triage internal codebases for vulnerabilities, test new safeguards, and provide highly autonomized service to their customers. John Hopper, vice president of engineering at SpecterOps, said newer models like GPT 5.5 are sharper and more persistent in pursuing their tasks, which can be both beneficial and detrimental.
Eran Kinsbruner, vice president of product marketing at software security firm Checkmarx, stated that later models like OpenAI's Codex Security and GPT 5.5 are noticeably easier to set up and run with local systems, even for less technical users. However, GPT 5.5 burns through tokens at a much faster rate, and some of the scan results he received were not comprehensive.
Debate Over Guardrails
The debate over guardrails designed to prevent risk sits at the heart of the discussion in Washington D.C. and around the world. Some users feel that these guardrails are necessary, while others, like Kinsbruner, believe they don't make sense for organizations that work with thousands of different enterprise organizations and code repositories spread across the internet.
The White House's Crash Course in AI Cyber Risk
The White House has been changing its line on whether and how the U.S. government should limit the release of commercial frontier models. According to Will Loucks, senior director of intelligence at the Office of the National Cyber Director, the number of exposed and known vulnerabilities has shot up over the past two years, and threat actors exploit those flaws faster before defenders can fix them.
Former director for cyber and incident response on the White House's National Security Council, Jordan Rae Kelly, noted that the changes over the past two years reflect the lessons the White House has learned on the issue since returning to office. Kelly said that the administration's current position has merit, even if it took time to get there.
Michael Daniel, former White House cyber coordinator under President Barack Obama, thinks that the horse may already be out of the barn, and that AI is being used to do things faster and at a slightly bigger scale, but aren't yet seeing the flood of exploitation that analysts have warned about.
The UK's AI Security Institute estimates that open source and foreign LLM models are between 4-7 months behind frontier U.S. models, making it challenging to stop the development of AI models worldwide through export controls or other limits.
Source: CyberScoop