Executive Order 14409 sets 30- and 60-day agency compliance deadlines

The Executive Office of the President put a binding instrument into effect with Executive Order 14409, "Promoting Advanced Artificial Intelligence Innovation and Security," on June 2, 2026 [1]. This order establishes immediate compliance deadlines for multiple federal agencies, directing specific work streams related to AI security and innovation within 30 and 60 days of its issuance [1]. The order outlines a series of actions to modernize government and private sector information systems, protect intellectual property, and cultivate advanced AI capabilities [1].

Immediate Agency Actions

Within 30 days of the order's date, several agencies received directives to prioritize cyber defense and establish new initiatives [1]

  • Committee on National Security Systems — This committee must prioritize the cyber defense of National Security Systems by taking "appropriate and expeditious action" [1].
  • Secretary of War — The Secretary of War must prioritize the cyber defense of Department of War information systems through "appropriate and expeditious action" [1].
  • Secretary of Homeland Security (through CISA) — In consultation with the Director of OMB, the Assistant to the President for National Security Affairs, and the National Cyber Director, the Secretary of Homeland Security, through the Director of the Cybersecurity and Infrastructure Security Agency (CISA), must release Binding Operational Directives and other guidance [1]. This guidance aims to expedite and prioritize the cyber defense of civilian Federal Government information systems, establish or expand federal programs for AI-enabled defensive tools, and facilitate access to cybersecurity tools and services, including covered frontier models, for agencies, state and local authorities, and critical infrastructure operators [1].
  • Secretary of the Treasury — In consultation with the National Cyber Director, the Secretary of War (through the Director of NSA), and the Secretary of Homeland Security (through the Director of CISA), the Secretary of the Treasury must form an AI cybersecurity clearinghouse [1]. This clearinghouse will coordinate and deconflict software vulnerability scanning, discover and validate vulnerabilities, and prioritize remediation and distribution of vulnerability patches, in voluntary collaboration with the AI industry and critical infrastructure operators [1].
  • Director of OMB — The Director of the Office of Management and Budget (OMB), in coordination with the National Cyber Director and the Director of CISA, must determine if any federal grant programs have available funding that can be directed toward applicants developing advanced AI vulnerability detection [1].

Further Directives

Beyond the 30-day requirements, the Executive Order also establishes a 60-day compliance deadline for additional agency work [1]

  • Director of the Office of Personnel Management — The Director of the Office of Personnel Management must expand the United States Tech Force Information Cybersecurity Specialist hiring and placement pathways [1].

Framework for Frontier Models

Within 60 days, a multi-agency effort is directed to address secure frontier model deployment [1]. The Secretary of the Treasury, the Secretary of War (through the Director of NSA), and the Secretary of Homeland Security (through the Director of CISA), in consultation with other White House and Commerce officials, must undertake specific actions [1]

  • Develop and maintain a classified benchmarking process to assess the advanced cyber capabilities of AI models and determine the threshold for designating an AI model as a "covered frontier model" [1]. These assessments are to be shared with AI developers and researchers as appropriate [1].
  • Design a voluntary framework for AI developers [1]. This framework would allow developers to engage the Federal Government to determine if models under development meet the "covered frontier model" designation [1]. It would also provide a mechanism for developers to grant the Federal Government access to covered frontier models for up to 30 days before their release to other trusted partners, subject to confidentiality, cybersecurity, insider-risk, and intellectual-property protection [1]. The framework also aims to facilitate collaboration with the Federal Government to select trusted partners for early access to covered frontier models [1].

The order expressly states that nothing in this section should be construed to authorize a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models [1].

Protection Against Criminal Actors

The order also directs the Attorney General to prioritize the enforcement of specific federal criminal laws against individuals who use AI to illegally access or damage computers without authorization, or who use AI to further other crimes [1]. This includes breaching information technology systems or employing AI agents for unlawful data access [1].

Potential enterprise implications

  • What data governance and intellectual property protection protocols must be in place for voluntary engagement with the Federal Government regarding pre-release access to covered frontier models? [1]

  • What specific enforcement priorities or precedents might arise from the Attorney General's directive to prioritize federal criminal laws against AI misuse, and how might this affect potential organizational exposure? [1]

  • Which enterprise AI systems or use cases fall within the scope of CISA's directives to expedite cyber defense of civilian Federal Government information systems and facilitate access to cybersecurity tools for critical infrastructure operators? [1]

  • What specific control expectations will arise from CISA's Binding Operational Directives for civilian Federal Government information systems, and how will they affect private sector partners? [1]

  • Given the voluntary framework for "covered frontier model" designation, what is the legal status of engaging with the Federal Government for AI developers, and what are the implications of choosing not to participate? [1]