<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>AI Executive Order | Haksung</title><link>https://haksungjang.github.io/en/tags/ai-executive-order/</link><description>Haksung Jang — Open Source Program Manager at SK telecom</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Wed, 10 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://haksungjang.github.io/en/tags/ai-executive-order/index.xml" rel="self" type="application/rss+xml"/><item><title>What the US AI Executive Order (2026-06-02) Means for Corporate Open Source Managers</title><link>https://haksungjang.github.io/en/research/2026-us-ai-eo-ospo/</link><pubDate>Wed, 10 Jun 2026 00:00:00 +0000</pubDate><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Haksung Jang</dc:creator><guid>https://haksungjang.github.io/en/research/2026-us-ai-eo-ospo/</guid><description>A primary-source analysis of the US AI executive order (Promoting Advanced Artificial Intelligence Innovation and Security) signed on June 2, 2026. Covers what the AI Cybersecurity Clearinghouse and the voluntary frontier model framework mean for corporate open source managers, the contrast with EU CRA mandatory reporting, and what to do now versus what to watch.</description><content:encoded>&lt;![CDATA[<div class="alert alert-info" role="alert"><p>This article was written with Claude Code, and the key facts cited here were cross-checked against primary sources.</p></div><blockquote><p><strong>Summary</strong></p><p>The executive order &ldquo;Promoting Advanced Artificial Intelligence Innovation and Security,&rdquo; signed on June 2, 2026, imposes no obligations on companies. Its core is the Treasury Department-led AI Cybersecurity Clearinghouse (a relay body that gathers, verifies, and distributes vulnerability information in one place, to be formed within 30 days) and a voluntary pre-sharing framework for frontier models (to be designed within 60 days); mandatory licensing and pre-approval are explicitly excluded<a id="a1-ref-1"/><a href="/en/research/2026-us-ai-eo-ospo/#a1">A1</a>. No provision applies directly to corporate open source managers either. Still, the order is worth reading because of what lies behind it. AI finding open source vulnerabilities faster than humans is already a reality. Before the order, Anthropic&rsquo;s unreleased model found 6,202 high- or critical-severity vulnerabilities in open source projects over two months, and patching has not kept pace<a id="a6-ref-1"/><a href="/en/research/2026-us-ai-eo-ospo/#a6">A6</a>·<a id="c1-ref-1"/><a href="/en/research/2026-us-ai-eo-ospo/#c1">C1</a>. What open source managers need to prepare for is not executive-order compliance but a response system that can handle a patch-processing capacity check, EOL component cleanup, and the EU Cyber Resilience Act reporting obligations that take effect September 11, 2026 — all at once.</p></blockquote><h2 id="1-what-the-executive-order-actually-establishes">1. What the Executive Order Actually Establishes</h2><p>The executive order consists of five sections, all premised on voluntary cooperation. Section 1 declares a stance of &ldquo;refusing to stifle innovation through excessive regulation&rdquo; and an America First approach to cybersecurity, while Section 5 contains standard general provisions. The substantive content sits in the three middle sections<a id="a1-ref-2"/><a href="/en/research/2026-us-ai-eo-ospo/#a1">A1</a>.</p><p>Section 2 addresses strengthening federal and private-sector cyber defense. Within 30 days, it prioritizes defense of national security systems, Department of War systems, and federal civilian systems, and on the same timeline the Treasury Secretary, in consultation with the National Cyber Director, the National Security Agency (NSA), and the Cybersecurity and Infrastructure Security Agency (CISA), forms the AI cybersecurity clearinghouse. A clearinghouse originally refers to an interbank institution for clearing checks — a relay body that gathers, verifies, and distributes information from multiple participants in one place. Here, it takes on the role of coordinating software vulnerability scanning through voluntary cooperation with the AI industry and critical infrastructure operators to eliminate duplication, discovering and verifying vulnerabilities, and prioritizing the fixing and distribution of patches<a id="a1-ref-3"/><a href="/en/research/2026-us-ai-eo-ospo/#a1">A1</a>.</p><p>Section 3 addresses the safe deployment of frontier models. Within 60 days, it establishes a classified benchmarking procedure to assess AI models&rsquo; cyberattack capabilities, and the NSA Director determines, based on those results, the threshold for which models qualify as &ldquo;covered frontier models.&rdquo; Through a voluntary framework, developers consult with the government on whether their models meet the designated criteria, provide the government with model access up to 30 days before the planned public release date, and jointly select trusted partners who will receive early access. Sec. 3(c) explicitly states that nothing in this section establishes mandatory licensing, pre-approval, or permitting requirements for the development, publication, disclosure, or deployment of new AI models<a id="a1-ref-4"/><a href="/en/research/2026-us-ai-eo-ospo/#a1">A1</a>.</p><p>Section 4 addresses investigation and enforcement. The Attorney General prioritizes enforcement of existing federal criminal law — including<code>18 U.S.C. 1030</code> (Computer Fraud and Abuse Act) — against unauthorized computer access and damage carried out using AI, and other crimes committed in the process<a id="a1-ref-5"/><a href="/en/research/2026-us-ai-eo-ospo/#a1">A1</a>.</p><p><img src="/research/2026-us-ai-eo-ospo/policy-timeline-en.png" alt="Policy timeline from the 2023 Executive Order 14110 to the 60-day deadline in August 2026. Following the June 2, 2026 signing of this executive order, clearinghouse formation and framework design follow within two months"/><p><strong>Figure 1.</strong> Policy timeline before and after the executive order<em>(source: official White House documents)</em></p><p>Observers describe the choice of lead agency as unexpected. Given that vulnerability coordination is the function at stake, it would seem natural for CISA or the Office of the National Cyber Director to lead, yet the clearinghouse is led by the Treasury Department. The Council on Foreign Relations (CFR) suggested this may be because Treasury is &ldquo;one of the few agencies with institutional capacity remaining,&rdquo; while the Atlantic Council flagged the risk of overlap with existing vulnerability coordination frameworks<a id="b4-ref-1"/><a href="/en/research/2026-us-ai-eo-ospo/#b4">B4</a>·<a id="b5-ref-1"/><a href="/en/research/2026-us-ai-eo-ospo/#b5">B5</a>. The key term &ldquo;covered frontier model&rdquo; is also left undefined in the text. It will be determined as a result of the classified benchmarking, and WilmerHale expects this definition to be the focus of agency rulemaking over the coming months<a id="b2-ref-1"/><a href="/en/research/2026-us-ai-eo-ospo/#b2">B2</a>.</p><h2 id="2-why-now">2. Why Now</h2><p>The direct backdrop to the executive order is Claude Mythos Preview, which Anthropic announced on April 7, 2026. This unreleased model scored 83.1% on the vulnerability-reproduction benchmark CyberGym (up from 66.6% for the prior model), and rather than a general release, Anthropic chose Project Glasswing, opening access only to 12 partners including AWS, Apple, Google, and Microsoft<a id="a6-ref-3"/><a href="/en/research/2026-us-ai-eo-ospo/#a6">A6</a>. In under two months, participating organizations identified more than 10,000 high- or critical-severity vulnerabilities. Anthropic&rsquo;s own scans alone turned up 23,019 issues across more than 1,000 open source projects, of which 6,202 were high or critical severity, and an independent security firm verified a sample of 1,752 and confirmed that more than 90% were genuine vulnerabilities<a id="c1-ref-2"/><a href="/en/research/2026-us-ai-eo-ospo/#c1">C1</a>·<a id="c2-ref-1"/><a href="/en/research/2026-us-ai-eo-ospo/#c2">C2</a>. Notable examples include a remote crash flaw that had lain dormant in OpenBSD for 27 years, a 16-year-old flaw in FFmpeg that had survived 5 million automated tests, and a privilege-escalation chain in the Linux kernel<a id="a6-ref-4"/><a href="/en/research/2026-us-ai-eo-ospo/#a6">A6</a>.</p><p>This process revealed a sharp mismatch between the speed of finding vulnerabilities and the speed of fixing them. Anthropic itself stated that &ldquo;the bottleneck to fixing these bugs is human capacity to triage, report, and design and ship patches,&rdquo; and as open source maintainers became that bottleneck, it began collaborating with OpenSSF&rsquo;s Alpha-Omega project<a id="c1-ref-3"/><a href="/en/research/2026-us-ai-eo-ospo/#c1">C1</a>·<a id="c2-ref-2"/><a href="/en/research/2026-us-ai-eo-ospo/#c2">C2</a>. Bruce Schneier assessed that, for now, &ldquo;discovery for fixing&rdquo; remains easier than &ldquo;discovery for exploitation,&rdquo; opening a window favorable to defenders — but that this window is temporary, and an era of automated zero-day discovery will arrive before we finish preparing for it. He also noted, citing the security firm Aisle&rsquo;s reproduction of some results with older, publicly available models, that this capability is not the exclusive property of any one company<a id="c3-ref-1"/><a href="/en/research/2026-us-ai-eo-ospo/#c3">C3</a>.</p><p>The executive order is the US government&rsquo;s response to this situation. The clearinghouse is the government&rsquo;s plan to coordinate at a national level what had been done individually in the private sector, as with Glasswing — using AI to find and verify vulnerabilities and coordinate patches<a id="a1-ref-7"/><a href="/en/research/2026-us-ai-eo-ospo/#a1">A1</a>·<a id="b5-ref-2"/><a href="/en/research/2026-us-ai-eo-ospo/#b5">B5</a>.</p><h2 id="3-what-this-means-for-corporate-open-source-managers">3. What This Means for Corporate Open Source Managers</h2><h3 id="31-a-document-that-never-says-open-source">3.1 A Document That Never Says &ldquo;Open Source&rdquo;</h3><p>Neither the executive order&rsquo;s text nor the White House fact sheet contains the phrase &ldquo;open source&rdquo; anywhere<a id="a1-ref-8"/><a href="/en/research/2026-us-ai-eo-ospo/#a1">A1</a>·<a id="a2-ref-2"/><a href="/en/research/2026-us-ai-eo-ospo/#a2">A2</a>. Viewed favorably, this means there is no regulatory burden. The order imposes no obligations on open source developers or open-weight model distributors, and Sec. 3(c)&rsquo;s prohibition on licensing covers &ldquo;development, publication, disclosure, or deployment&rdquo; of models broadly, so distribution via open weights also falls within its protection<a id="a1-ref-9"/><a href="/en/research/2026-us-ai-eo-ospo/#a1">A1</a>. The administration&rsquo;s official stance is consistent with what was stated in the July 2025 AI Action Plan: the choice between open and closed rests entirely with the developer, and the federal government will foster an environment favorable to open models<a id="a5-ref-2"/><a href="/en/research/2026-us-ai-eo-ospo/#a5">A5</a>.</p><p>What remains an open question is the threshold for covered frontier models. Because it is determined through a classified benchmark, it is currently impossible to know what happens if an open-weight model exceeds that threshold. The core mechanism of the voluntary framework — &ldquo;government access 30 days before release&rdquo; — is designed for closed models whose release timing can be controlled, and this approach does not translate to open models, whose weights, once released, cannot be recalled. CFR experts have suggested that frontier-level vulnerability-reasoning capability will likely be reproduced in open-weight systems before long, and similar reproduction studies are already being mentioned<a id="b5-ref-3"/><a href="/en/research/2026-us-ai-eo-ospo/#b5">B5</a>. If the capability spreads to open models, the gap in the voluntary pre-sharing design will become apparent, and further regulatory discussion could then target open models. Companies that internally adopt or fine-tune and deploy open-weight models should watch how the benchmarking procedure and subsequent rulemaking, due by August 1, treat open models.</p><p>Open source foundations have also stayed quiet so far. As of the search conducted on 2026-06-10, no statement from the Open Source Initiative (OSI), the Linux Foundation, or OpenSSF regarding this executive order could be found. With no obligations imposed, the incentive to respond immediately appears to have been weak. The closest official position is OSI&rsquo;s response to the 2025 AI Action Plan public comment period, submitted in March 2025<a id="b7-ref-1"/><a href="/en/research/2026-us-ai-eo-ospo/#b7">B7</a>.</p><h3 id="32-where-the-clearinghouse-meets-corporate-vulnerability-management">3.2 Where the Clearinghouse Meets Corporate Vulnerability Management</h3><p>The clearinghouse&rsquo;s three functions — coordinating scans, discovering and verifying vulnerabilities, and prioritizing patch deployment — overlap precisely with the vulnerability management systems that corporate open source organizations (OSPOs or product security teams) already operate<a id="a1-ref-10"/><a href="/en/research/2026-us-ai-eo-ospo/#a1">A1</a>.</p><p><img src="/research/2026-us-ai-eo-ospo/clearinghouse-flow-en.png" alt="The clearinghouse coordinates scans with voluntary participants, and discovered vulnerabilities flow through open source maintainers into published patches, which corporate open source managers then receive and apply"/><p><strong>Figure 2.</strong> Where the corporate open source manager sits in the clearinghouse and vulnerability information flow<em>(source: Executive Order Sec. 2(d))</em></p><p>Most companies will encounter the clearinghouse as information consumers. Once it is operational, discovery, verification, and patch-priority information for open source component vulnerabilities will flow through a new channel. This effectively adds a US-originated channel to a company&rsquo;s vulnerability intelligence pipeline and adds a coordinating body that influences patch-priority decisions.</p><p>Whether to participate directly in the clearinghouse is a separate decision. Companies in critical infrastructure sectors (energy, finance, healthcare, telecommunications, and the like) are explicitly named as intended participants<a id="a1-ref-12"/><a href="/en/research/2026-us-ai-eo-ospo/#a1">A1</a>. Participation brings early access to vulnerability information, a voice in patch coordination, and access to the government-supported security tools mentioned in Sec. 2(c)(iii). In exchange, participants take on the legal-review burden that comes with information sharing, and, as Crowell &amp; Moring pointed out, face the uncertainty that liability protection for participants is not specified and the consequences of non-participation are not defined either<a id="b3-ref-1"/><a href="/en/research/2026-us-ai-eo-ospo/#b3">B3</a>. As WilmerHale anticipates, if the voluntary provisions migrate into federal procurement standards, there is a scenario where participation becomes a de facto precondition for companies doing business with the US government<a id="b2-ref-2"/><a href="/en/research/2026-us-ai-eo-ospo/#b2">B2</a>. There is no reason to rush a decision before the operational details are published in early July.</p><h3 id="33-the-most-direct-impact-a-surge-in-patch-demand-and-eol-risk">3.3 The Most Direct Impact: A Surge in Patch Demand and EOL Risk</h3><p>Changes already underway independent of the executive order are now being accelerated by it. As AI-driven discovery becomes institutionalized at the national level, backed by federal funding (Sec. 2(e)), the volume of reported vulnerabilities in open source components can only grow. The Glasswing figures gave an early preview of that scale.</p><p>The first thing companies run into is throughput. As new CVEs multiply across the open source components in a company&rsquo;s own products, triage (impact analysis), patch application, and customer communication must scale up together. Organizations relying on manual triage will be the first to accumulate a backlog.</p><p>EOL (End-of-Life) components present a deeper problem. AI scans code indiscriminately, whether or not it is still maintained, but patches require a maintainer. As HeroDevs, a commercial long-term support (LTS) vendor, has pointed out, the gap between discovery speed and fix speed opens widest in EOL software. If components remain in inventory for which discovery is accelerating while a fix will never arrive, that risk only grows over time<a id="c4-ref-1"/><a href="/en/research/2026-us-ai-eo-ospo/#c4">C4</a>. The 27-year-old OpenBSD flaw and the 16-year-old FFmpeg flaw show that the assumption that older, stable components are safer no longer holds<a id="a6-ref-5"/><a href="/en/research/2026-us-ai-eo-ospo/#a6">A6</a>.</p><p>Pressure on the upstream side ultimately becomes the company&rsquo;s own risk. Anthropic itself confirmed that open source maintainers are becoming the bottleneck in the flood of reports<a id="c2-ref-3"/><a href="/en/research/2026-us-ai-eo-ospo/#c2">C2</a>. When the maintainer of a core component a company depends on is overwhelmed with triage, it is the company that bears the resulting patch delay. Adding upstream maintenance health (maintainer count, security-response track record, foundation affiliation) as an evaluation criterion for core dependencies, and participating in upstream support such as Alpha-Omega where needed, is a path to reducing that risk.</p><h3 id="34-contrast-with-the-eu-cra-handling-voluntary-and-mandatory-regimes-at-once">3.4 Contrast with the EU CRA: Handling Voluntary and Mandatory Regimes at Once</h3><p>The problem the US clearinghouse addresses — discovering and patching software vulnerabilities — is the same area the EU has made mandatory through the Cyber Resilience Act (CRA — Regulation (EU) 2024/2847).</p><table><thead><tr><th>Category</th><th>US Executive Order (2026-06-02)</th><th>EU CRA Article 14 (effective 2026-09-11)</th></tr></thead><tbody><tr><td>Nature</td><td>Voluntary cooperation (company chooses to participate)</td><td>Legal obligation (applies immediately upon placing on the EU market)</td></tr><tr><td>Scope</td><td>AI industry, critical infrastructure operators</td><td>Manufacturers, importers, and distributors of products with digital elements</td></tr><tr><td>Key mechanism</td><td>Clearinghouse scan coordination and patch deployment coordination</td><td>Staged 24-hour/72-hour/14-day reporting of actively exploited vulnerabilities</td></tr><tr><td>Receiving body</td><td>Treasury-led clearinghouse (operational details not yet public)</td><td>ENISA&rsquo;s Single Reporting Platform (SRP) and member-state CSIRTs</td></tr><tr><td>Non-compliance</td><td>No penalty (possible shift to procurement standards is still speculative)</td><td>Fines up to €15 million or 2.5% of global annual turnover</td></tr><tr><td>Model regulation</td><td>Explicit exclusion of mandatory licensing and pre-approval</td><td>CRA is a product-security regulation, not an AI model regulation</td></tr></tbody></table><p><strong>Table 1.</strong> Comparison of US executive order and EU CRA vulnerability reporting regimes<em>(sources: original text of the executive order<a id="a1-ref-13"/><a href="/en/research/2026-us-ai-eo-ospo/#a1">A1</a>, Regulation (EU) 2024/2847<a id="a7-ref-1"/><a href="/en/research/2026-us-ai-eo-ospo/#a7">A7</a>, separate report<a id="d1-ref-1"/><a href="/en/research/2026-us-ai-eo-ospo/#d1">D1</a>. As of 2026-06-10)</em></p><p>For Korean companies shipping products into both markets, the priority is clear. Whichever regime carries binding force, deadlines, and fines comes first. The CRA Article 14 reporting workflow must be operational by September 11, three months from now, and it has already been confirmed that, because ENISA does not currently offer an SRP integration API, the workflow must be designed as a manual, human-submitted process<a id="a7-ref-2"/><a href="/en/research/2026-us-ai-eo-ospo/#a7">A7</a>·<a id="d1-ref-2"/><a href="/en/research/2026-us-ai-eo-ospo/#d1">D1</a>. The US clearinghouse comes next. Still, both regimes run on the same underlying internal capabilities — a component inventory (SBOM), vulnerability triage, a Coordinated Vulnerability Disclosure (CVD) intake channel, and a patch deployment process. A system built to prepare for the CRA becomes the foundation for voluntary participation on the US side, so there is no need to build a separate system twice.</p><h3 id="35-policy-divergence-us-voluntary-cooperation-eu-institutionalization">3.5 Policy Divergence: US Voluntary Cooperation, EU Institutionalization</h3><p>The day after the executive order, on June 3, the European Commission published its Tech Sovereignty package, placing open source at the center of digital policy. Its core elements are mobilizing roughly €2 billion in public and private funding over seven years, establishing an Open Source Maintenance Instrument, and opening up public procurement<a id="a8-ref-1"/><a href="/en/research/2026-us-ai-eo-ospo/#a8">A8</a>·<a id="d2-ref-1"/><a href="/en/research/2026-us-ai-eo-ospo/#d2">D2</a>. The two documents, published a day apart, reveal contrasting institutional designs for the same technological landscape. The US model excludes regulation and has government coordinate the private sector&rsquo;s voluntary capacity; the EU model institutionalizes the open source ecosystem itself through public funding and legal obligation (including the CRA&rsquo;s steward regime).</p><p>Global companies&rsquo; open source management policy needs to be built with this divergence as a given. In the US market, they must decide whether to enter the voluntary cooperation channel; in the EU market, they must respond to the obligations of CRA compliance and the steward regime. Since the same team within a company will end up operating both modes, it is more realistic to build market-specific modules on top of shared capabilities than to keep policy documents and response organizations separated by market.</p><h3 id="36-a-different-axis-from-ai-generated-code-management">3.6 A Different Axis from AI-Generated Code Management</h3><p>A separate analysis addressing the inflow of AI-generated code into open source and snippet inspection<a id="d3-ref-1"/><a href="/en/research/2026-us-ai-eo-ospo/#d3">D3</a> and this matter both sit at the intersection of AI and open source management, but along different axes. That analysis addressed inflow management — the licensing and provenance problems that arise when AI coding tools bring code fragments not declared as packages into a codebase. What this executive order points to is operations — the response problem in an environment where vulnerabilities in open source components already present in the codebase are being surfaced faster and in greater volume because of AI. AI is now affecting both the stage where code enters and the stage where vulnerabilities surface, and the response systems for both axes need to be checked separately.</p><h2 id="4-what-to-prepare">4. What to Prepare</h2><p>Since the executive order makes no direct demands of companies, preparation splits into what to do now and what to watch.</p><h3 id="what-to-do-now">What to Do Now</h3><p>The starting point is an inventory of your own AI exposure surface. Bring together, in one place, the models you develop or fine-tune internally (especially open-weight-based ones), the AI coding and security tools you&rsquo;ve adopted, and the current state of AI-generated code that has entered your codebase. This puts you in a position to judge quickly, once the covered-frontier-model criteria take shape after August 1, whether your company falls near that boundary.</p><p>Also review your open source vulnerability response system. Check whether SBOMs are current across all products, whether new-CVE triage can absorb a two- to three-fold increase in volume, and whether the CVD intake channel is functioning. This review is the same work as preparing for CRA Article 14 (deadline September 11), so there is no need to spin up a separate project — fold it into CRA preparation<a id="d1-ref-3"/><a href="/en/research/2026-us-ai-eo-ospo/#d1">D1</a>.</p><p>The most urgent item is cleaning up EOL components. Identify end-of-maintenance components in your SBOM, set a schedule for those with an upgrade path, and for those that cannot be removed immediately, arrange a patch source such as commercial LTS or in-house patching. For items where you can demonstrate no impact, document them using Vulnerability Exploitability eXchange (VEX) to reduce the triage burden<a id="c4-ref-2"/><a href="/en/research/2026-us-ai-eo-ospo/#c4">C4</a>.</p><p>Finally, assess the health of critical upstream dependencies. Check the maintainer base size and security-response track record of the upper-level components that your revenue-critical products depend on, and consider support measures such as sponsorship or contribution for projects where a bottleneck is a concern<a id="c2-ref-4"/><a href="/en/research/2026-us-ai-eo-ospo/#c2">C2</a>.</p><h3 id="what-to-watch">What to Watch</h3><table><thead><tr><th>Item to track</th><th>Timing</th><th>What to check</th></tr></thead><tbody><tr><td>Clearinghouse formation announcement</td><td>By 2026-07-02</td><td>Operating body and participation process, scope of information sharing expected from companies, whether liability protection exists<a id="a1-ref-14"/><a href="/en/research/2026-us-ai-eo-ospo/#a1">A1</a>·<a id="b3-ref-2"/><a href="/en/research/2026-us-ai-eo-ospo/#b3">B3</a></td></tr><tr><td>Classified benchmarking and voluntary framework</td><td>By 2026-08-01</td><td>Contours of the covered-frontier-model threshold, treatment of open-weight models<a id="a1-ref-15"/><a href="/en/research/2026-us-ai-eo-ospo/#a1">A1</a>·<a id="b2-ref-3"/><a href="/en/research/2026-us-ai-eo-ospo/#b2">B2</a></td></tr><tr><td>Subsequent rulemaking</td><td>Over a period of months</td><td>Whether voluntary provisions migrate into federal procurement standards<a id="b2-ref-4"/><a href="/en/research/2026-us-ai-eo-ospo/#b2">B2</a></td></tr><tr><td>NSPM-11 classified annex and implementation</td><td>By early 2026-09</td><td>Treatment of open source AI in national security procurement<a id="a3-ref-2"/><a href="/en/research/2026-us-ai-eo-ospo/#a3">A3</a></td></tr><tr><td>Open source foundation responses</td><td>From July onward</td><td>Statements and participation approach from OSI, the Linux Foundation, and OpenSSF<a id="b7-ref-2"/><a href="/en/research/2026-us-ai-eo-ospo/#b7">B7</a></td></tr><tr><td>EU CRA SRP going live</td><td>2026-09-11</td><td>Reporting workflow going into actual operation (tracked in the separate report<a id="d1-ref-4"/><a href="/en/research/2026-us-ai-eo-ospo/#d1">D1</a>)</td></tr></tbody></table><p><strong>Table 2.</strong> Items to track and their timing<em>(as of 2026-06-10)</em></p><h2 id="5-conclusion">5. Conclusion</h2><p>This executive order imposes no new obligations on corporate open source managers, but it is a signal that the premises of the operating environment are shifting. An era in which AI finds open source vulnerabilities in bulk has been demonstrated, and the US government has decided to institutionalize that trend through coordination rather than regulation. Discovery is accelerating while patching still moves at human speed. The only thing companies can control in this gap is the processing capacity of their own inventory. Because the EU CRA reporting obligation taking effect three months from now requires SBOM, triage, and CVD capabilities regardless, preparing for both markets with a single system is the most efficient path. As for the executive order itself, only two dates need to go on the calendar: July 2 (clearinghouse) and August 1 (benchmarking criteria).</p><hr><h2 id="references">References</h2><p>All URLs were confirmed accessible and matching their cited content on 2026-06-10 (except where noted otherwise).</p><h3 id="a-primary-sources-official-government-documents-direct-party-statements">A. Primary Sources (Official Government Documents, Direct-Party Statements)</h3><p><a id="a1"/><strong>A1.</strong> The White House (2026).<em>Promoting Advanced Artificial Intelligence Innovation and Security</em> (Executive Order). Signed 2026-06-02.<a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/">https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/</a> (accessed: 2026-06-10). —<em>The primary source for this report.</em><a href="#a1-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="a2"/><strong>A2.</strong> The White House (2026).<em>Fact Sheet: President Donald J. Trump Promotes Advanced Artificial Intelligence Innovation and Security</em>. 2026-06-02.<a href="https://www.whitehouse.gov/fact-sheets/2026/06/fact-sheet-president-donald-j-trump-promotes-advanced-artificial-intelligence-innovation-and-security/">https://www.whitehouse.gov/fact-sheets/2026/06/fact-sheet-president-donald-j-trump-promotes-advanced-artificial-intelligence-innovation-and-security/</a> (accessed: 2026-06-10).<a href="#a2-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="a3"/><strong>A3.</strong> The White House (2026).<em>National Security Presidential Memorandum/NSPM-11 — Artificial Intelligence in the National Security Enterprise</em>. 2026-06-05.<a href="https://www.whitehouse.gov/presidential-actions/2026/06/national-security-presidential-memorandum-nspm-11/">https://www.whitehouse.gov/presidential-actions/2026/06/national-security-presidential-memorandum-nspm-11/</a> (accessed: 2026-06-10).<a href="#a3-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="a4"/><strong>A4.</strong> The White House (2025).<em>Removing Barriers to American Leadership in Artificial Intelligence</em> (Executive Order 14179). 2025-01-23.<a href="https://www.whitehouse.gov/presidential-actions/2025/01/removing-barriers-to-american-leadership-in-artificial-intelligence/">https://www.whitehouse.gov/presidential-actions/2025/01/removing-barriers-to-american-leadership-in-artificial-intelligence/</a> (accessed: 2026-06-10).<a href="#a4-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="a5"/><strong>A5.</strong> The White House (2025).<em>Winning the Race: America&rsquo;s AI Action Plan</em>. 2025-07.<a href="https://www.whitehouse.gov/wp-content/uploads/2025/07/Americas-AI-Action-Plan.pdf">https://www.whitehouse.gov/wp-content/uploads/2025/07/Americas-AI-Action-Plan.pdf</a> (accessed: 2026-06-10, passage confirmed directly against the PDF original).<a href="#a5-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="a6"/><strong>A6.</strong> Anthropic (2026).<em>Project Glasswing: Securing critical software for the AI era</em>. Announced 2026-04-07 (subsequently updated).<a href="https://www.anthropic.com/glasswing">https://www.anthropic.com/glasswing</a> (accessed: 2026-06-10).<a href="#a6-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="a7"/><strong>A7.</strong> European Parliament and Council (2024).<em>Regulation (EU) 2024/2847 — Cyber Resilience Act</em>. OJ L, 2024/2847, 20.11.2024.<a href="https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng">https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng</a> (accessed: 2026-05-12, confirmed during verification of this workspace&rsquo;s CRA report).<a href="#a7-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="a8"/><strong>A8.</strong> European Commission (2026).<em>Communication on European Tech Sovereignty, accompanied by an EU Open Source Strategy</em>. COM(2026) 503 final, 2026-06-03.<a href="https://digital-strategy.ec.europa.eu/en/library/communication-european-tech-sovereignty-accompanied-eu-open-source-strategy">https://digital-strategy.ec.europa.eu/en/library/communication-european-tech-sovereignty-accompanied-eu-open-source-strategy</a> (accessed: 2026-06-10).<a href="#a8-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><h3 id="b-legal-and-policy-analysis">B. Legal and Policy Analysis</h3><p><a id="b1"/><strong>B1.</strong> Wiley Rein LLP (2026).<em>New AI Executive Order Addresses Frontier Models and Cybersecurity Vulnerabilities</em>.<a href="https://www.wiley.law/alert-New-AI-Executive-Order-Addresses-Frontier-Models-and-Cybersecurity-Vulnerabilities">https://www.wiley.law/alert-New-AI-Executive-Order-Addresses-Frontier-Models-and-Cybersecurity-Vulnerabilities</a> (accessed: 2026-06-10).<a href="#b1-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="b2"/><strong>B2.</strong> WilmerHale (2026).<em>New Executive Order Addressing Early Government Access to Frontier AI Models</em>. 2026-06-02.<a href="https://www.wilmerhale.com/en/insights/client-alerts/20260602-new-executive-order-addressing-early-government-access-to-frontier-ai-models">https://www.wilmerhale.com/en/insights/client-alerts/20260602-new-executive-order-addressing-early-government-access-to-frontier-ai-models</a> (accessed: 2026-06-10).<a href="#b2-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="b3"/><strong>B3.</strong> Crowell &amp; Moring LLP (2026).<em>Executive Order Creates Voluntary Regulatory Regime of Frontier AI Models</em>.<a href="https://www.crowell.com/en/insights/client-alerts/executive-order-creates-voluntary-regulatory-regime-of-frontier-ai-models">https://www.crowell.com/en/insights/client-alerts/executive-order-creates-voluntary-regulatory-regime-of-frontier-ai-models</a> (accessed: 2026-06-10).<a href="#b3-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="b4"/><strong>B4.</strong> Atlantic Council (2026).<em>Reading between the lines of Trump&rsquo;s new executive order on AI</em>.<a href="https://www.atlanticcouncil.org/dispatches/reading-between-the-lines-of-trumps-new-executive-order-on-ai/">https://www.atlanticcouncil.org/dispatches/reading-between-the-lines-of-trumps-new-executive-order-on-ai/</a> (accessed: 2026-06-10).<a href="#b4-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="b5"/><strong>B5.</strong> Council on Foreign Relations (2026).<em>Assessing Trump&rsquo;s Executive Order on AI Oversight</em>.<a href="https://www.cfr.org/articles/assessing-trumps-executive-order-on-ai-oversight">https://www.cfr.org/articles/assessing-trumps-executive-order-on-ai-oversight</a> (accessed: 2026-06-10).<a href="#b5-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="b6"/><strong>B6.</strong> CSO Online (2026).<em>OpenAI responds to White House executive order on AI governance</em>.<a href="https://www.csoonline.com/article/4181294/openai-responds-to-white-house-executive-order-on-ai-governance.html">https://www.csoonline.com/article/4181294/openai-responds-to-white-house-executive-order-on-ai-governance.html</a> (accessed: 2026-06-10).</p><p><a id="b7"/><strong>B7.</strong> Open Source Initiative (2025).<em>OSI and Apereo Foundation Respond to White House on AI Action Plan</em>.<a href="https://opensource.org/blog/osi-and-apereo-foundation-respond-to-white-house-on-ai-action-plan">https://opensource.org/blog/osi-and-apereo-foundation-respond-to-white-house-on-ai-action-plan</a> (accessed: 2026-06-10).<a href="#b7-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><h3 id="c-industry-and-security-community">C. Industry and Security Community</h3><p><a id="c1"/><strong>C1.</strong> CyberScoop (2026).<em>Anthropic expanding access to Project Glasswing</em>. 2026-06-02.<a href="https://cyberscoop.com/anthropic-project-glasswing-expansion-critical-infrastructure-claude-mythos/">https://cyberscoop.com/anthropic-project-glasswing-expansion-critical-infrastructure-claude-mythos/</a> (accessed: 2026-06-10).<a href="#c1-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="c2"/><strong>C2.</strong> Help Net Security (2026).<em>Anthropic: Claude Mythos identified 10,000+ software flaws</em>. 2026-05-26.<a href="https://www.helpnetsecurity.com/2026/05/26/anthropic-project-glasswing-update/">https://www.helpnetsecurity.com/2026/05/26/anthropic-project-glasswing-update/</a> (accessed: 2026-06-10).<a href="#c2-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="c3"/><strong>C3.</strong> Schneier, Bruce (2026).<em>On Anthropic&rsquo;s Mythos Preview and Project Glasswing</em>. Schneier on Security, 2026-04.<a href="https://www.schneier.com/blog/archives/2026/04/on-anthropics-mythos-preview-and-project-glasswing.html">https://www.schneier.com/blog/archives/2026/04/on-anthropics-mythos-preview-and-project-glasswing.html</a> (accessed: 2026-06-10).<a href="#c3-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="c4"/><strong>C4.</strong> HeroDevs (2026).<em>AI Cybersecurity Executive Order 2026: What It Means for EOL Software</em>.<a href="https://www.herodevs.com/blog-posts/ai-cybersecurity-executive-order-2026-what-it-means-for-eol-software">https://www.herodevs.com/blog-posts/ai-cybersecurity-executive-order-2026-what-it-means-for-eol-software</a> (accessed: 2026-06-10). —<em>Cited with awareness of the vendor&rsquo;s commercial-LTS interest.</em><a href="#c4-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><h3 id="d-related-analysis-this-blog">D. Related Analysis (This Blog)</h3><p><a id="d1"/><strong>D1.</strong><a href="/en/research/2026-eu-cra-vulnerability-reporting/">EU Cyber Resilience Act (CRA) Vulnerability Reporting Obligations — Preparing for the 2026-09-11 Effective Date</a> (updated 2026-06-09).<a href="#d1-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="d2"/><strong>D2.</strong><a href="/en/research/2026-eu-open-source-strategy/">EU Open Source Strategy: Institutionalizing Open Source for Tech Sovereignty</a> (2026-06-05).<a href="#d2-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="d3"/><strong>D3.</strong><a href="/en/blog/2026/06/08/ai-generated-code-how-far-should-open-source-scanning-go/">AI-Generated Code: How Far Should Open Source Inspection Go</a> (2026-06-08).<a href="#d3-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></content></p>
]]></content:encoded></item></channel></rss>