What happened?
A nonpartisan nonprofit called Protect Democracy has sued four federal agencies, demanding they release the secret framework the Trump administration uses to review frontier AI models before release. The group says "almost no details" have been given to either the public or Congress.
The lawsuit seeks an order requiring officials to produce the information by 30 September. The request is limited to unclassified procedural and contractual architecture: the framework's text, the terms of participation, the identity of participants, and the criteria by which access to frontier models is granted or withheld.
Why it matters
Protect Democracy's case turns on one line: the decision about which AI models are approved and released "may be the most important policy question of this White House." Today that decision sits with the executive branch alone — with no oversight from Congress, the public, or technical experts outside it.
The group also notes that at least one company, OpenAI, has negotiated a private agreement with the federal government to limit distribution of its cutting-edge models to government-vetted partners. Neither the identities of those "trusted partners" nor the criteria by which they were selected have been made public.
How the process was built
- The administration moved quickly to set up a voluntary review process after the government flagged Anthropic's Mythos 5 model as too dangerous to release.
- In July the White House launched GOLD EAGLE, a clearinghouse relying on industry partners to flag vulnerabilities; it did not identify the participating companies, their terms, or the programme's legal authority.
- On 3 August the White House announced the voluntary pre-release review framework was complete; both are confirmed to be in active use.
- Parts of the process are classified: the executive order provides for a "classified benchmarking process" assessing models' advanced capabilities.
A document that is unclassified but unpublished
This is the sharpest detail in the case: according to Protect Democracy, the framework itself is not designated as classified. Even so, the White House refuses to share the details; a spokesperson told reporters that "just because things are unclassified, that doesn't mean we are going to broadcast them to everyone."
A second ambiguity sits in the definitions: the term "covered frontier model" is undefined. If the definition is too narrow, dangerous models can slip through; if it is too broad, agencies gutted by DOGE cuts may be spread too thin to assess them all. Both failures land in the same place — from the outside there is no way to tell which one is happening.
The point of comparison: California
California state senator Josh Becker, in a declaration supporting the complaint, holds up the state's proposed SB 813 as the counter-example. The bill would set up a process in which independent organisations define baselines for AI safety standards, keeping the benchmarks, standards and methodologies used publicly visible. Becker writes that every step of the bill's development has been public, with one provision withdrawn after backlash: "We are accountable for the framework we have set."
What's next?
How the court will respond to the 30 September demand is unknown. The group is also seeking an injunction restraining officials from improperly withholding unclassified records. The timing is not accidental either: the incident in which OpenAI's agents breached Hugging Face has put the question of how well pre-release review actually works squarely on the table.