The Trump administration has significantly altered its approach to artificial intelligence regulation, moving from a stance that downplayed calls for AI safety to one that embraces stricter government scrutiny of frontier AI systems before their public release. This shift, which occurred over the past two years, is a departure from the Biden administration's more industry-friendly regulations, which focused on voluntary reviews of new models.
A key turning point in the administration's policy was the imposition of export controls on Anthropic's Fable 5 and Mythos 5 models. This action, taken suddenly and without extensive prior warning, was reportedly in response to private sector threat intelligence reports, effectively ushering the U.S. AI industry into a new era of regulation. However, the specific criteria for these controls and their potential future application remain unclear.
While newer models like Mythos and OpenAI's Daybreak are acknowledged to possess enhanced cybersecurity capabilities, the private sector intelligence that prompted the export controls described capabilities already present in older commercial, open-source, and even Chinese models, which are widely accessible. This suggests the administration may be reacting to threats that have been developing for some time, as it more fully grasps the national security implications of AI.
Users of advanced models, such as OpenAI's ChatGPT 5.5 (released in April) and Fable 5, report that these tools are generally helpful for their work, despite issues like high token usage and safety guardrails that can impede defensive cyber tasks without entirely preventing them. For instance, Cato Networks, a participant in OpenAI's Trusted Access in Cyber program, utilizes GPT 5.5 and subsequent OpenAI models to scan internal codebases for vulnerabilities, test new safeguards, and provide highly automated customer service. The company integrates these models into its development cycles to minimize vulnerabilities in its released services.
John Hopper, Vice President of Engineering at SpecterOps, an identity security firm, noted that newer models like GPT 5.5 exhibit greater persistence and sharpness in their tasks. He highlighted that the ability of an AI agent to work longer without human intervention allows a single operator to manage more agents, providing significant value to defenders. Hopper also cautioned against overstating the offensive advantages of AI, arguing that while these tools may lower the barrier to entry for certain cyber activities, the underlying problems have always existed.
Eran Kinsbruner, Vice President of Product Marketing at Checkmarx, a software security firm, found later models like OpenAI's Codex Security and GPT 5.5 to be easier to set up and integrate with local systems, even for less technical users, which offers an advantage over many cybersecurity tools with interoperability challenges. However, he observed that GPT 5.5 consumes tokens at a rapid rate. In one instance, scanning a medium-sized repository across three programming languages nearly exhausted his tokens in 26 minutes without providing comprehensive results.
Kinsbruner also expressed frustration with certain safety guardrails, such as the restriction on scanning only local files rather than remote code repositories like GitHub. He argued that such limitations are impractical for organizations working with numerous enterprise clients and their distributed codebases, making it difficult to adopt these solutions as enterprise-grade cybersecurity tools. OpenAI has since released GPT 5.6, which it claims offers more efficient token usage.
The White House's evolving stance on AI regulation stems from lessons learned since January 2025. Initially, the administration discarded Biden-era regulations aimed at promoting safer AI models, with officials like Vice President JD Vance arguing against restricting industry progress. However, less than two years later, concerns have grown regarding the speed and scale at which AI can impact cyberspace.
Will Loucks, Senior Director of Intelligence at the Office of the National Cyber Director, indicated that over the past two years, the number of exposed vulnerabilities has surged, and threat actors are exploiting these flaws more rapidly. This acceleration means that the time from initial access to full network control for attackers has decreased, placing immense pressure on defenders to triage alerts more quickly. Loucks emphasized that AI's ability to lower barriers for threat actors, even without a significant increase in sophistication, poses a threat due to the sheer speed and volume of potential attacks.






