“Neither the identities of those entities nor the criteria by which they were selected have been made public,” Protect Democracy said.
The group is seeking records by September 30, including the framework’s procedural structure, participation terms and criteria for granting or denying access to advanced AI models. It also wants the court to prevent the agencies from withholding responsive records that are not classified.
Protect Democracy sent identical Freedom of Information Act requests to all four agencies. According to the complaint, none has produced records. The Office of the National Cyber Director was the only agency to respond, rejecting the organization’s request for expedited processing.
At the center of the dispute is GOLD EAGLE, a White House clearinghouse introduced in July that uses industry partners to help federal agencies identify cybersecurity vulnerabilities. The administration then announced on August 3 that it had completed a voluntary framework for reviewing frontier AI systems ahead of public release. The White House has confirmed that both efforts are being used.
Parts of the broader government evaluation system are classified, including a benchmarking process intended to assess advanced AI capabilities. Protect Democracy argues, however, that the framework governing participation is not classified and therefore should not remain inaccessible simply because the administration does not want to release it.
A White House spokesperson previously told reporters that “just because things are unclassified, that doesn’t mean we are going to broadcast them to everyone.”
The complaint also points to OpenAI, which Protect Democracy says has negotiated an agreement with the federal government limiting distribution of some advanced models to government-vetted partners. The lawsuit does not identify additional confirmed participants, leaving unclear which other AI companies are working within the framework.
Protect Democracy argues that the lack of disclosure makes it difficult to determine whether model reviews are being applied consistently or whether important stakeholders have been excluded. The group specifically cites AI safety organizations, independent researchers and smaller AI companies as parties that do not appear to have visibility into the process.
Another unresolved question is what qualifies as a “covered frontier model.” Protect Democracy argues that an overly narrow definition could leave some systems outside the review process, while an overly broad one could create more evaluation work than federal agencies can effectively handle.
The administration accelerated development of the review system after Anthropic’s Mythos 5 model was flagged as too dangerous for release earlier this summer. Federal teams at the Center for AI Standards and Innovation were expected to evaluate prerelease models with safeguards reduced or removed so they could examine national security capabilities and risks more directly.
Protect Democracy says the secrecy surrounding that process also makes congressional oversight more difficult. Lawmakers are considering whether to extend liability protections under the Cybersecurity Information Sharing Act of 2015, which the complaint describes as the apparent legal basis for information sharing through GOLD EAGLE. The earliest congressional action cited in the complaint could come September 30, with a later deadline of December 11 also under discussion.
A senior administration official acknowledged when GOLD EAGLE was introduced that failure to renew those protections would create problems for the program, saying that without reauthorization, “this effort is fundamentally challenged.”
Deana El-Mallawany, director of Impact Programs and Counsel at Protect Democracy, said the lack of information leaves both the organization and Congress unable to fully evaluate what they are being asked to support. “Our concern is that the White House is putting Congress in the position of voting on a CISA extension without knowing how the GOLD EAGLE program is operating, who’s involved, or what statutory authority is being invoked,” El-Mallawany said. “That’s why we’re seeking these records.”
California state Senator Josh Becker has also backed the disclosure effort, contrasting the federal system with SB 813, a proposed California framework that would use independent organizations to establish AI safety baselines while making evaluation standards and methodologies public. U.S. Representative Greg Casar has separately criticized the administration for operating a voluntary review process whose details have not been released.
Protect Democracy also points to the administration’s previous conflict with Anthropic, arguing that secrecy increases the risk that executive discretion could be used inconsistently across AI companies. The organization does not allege that specific misconduct has already occurred through the framework, but says the lack of visibility prevents outsiders from determining whether decisions are being made fairly or whether the review process itself is effective.
“We deserve to know what’s in the framework,” Protect Democracy said.
The lawsuit asks the court to make that information available before Congress makes decisions that could affect GOLD EAGLE’s legal foundation. Protect Democracy says it intends to publish any records it obtains, potentially giving lawmakers, AI companies and the public their first detailed look at how the administration decides which frontier systems receive government review and which organizations are allowed to participate.
This analysis is based on reporting from arsTECHNICA.
Images courtesy of NPS / Kelsey Graczyk.
This article was generated with AI assistance and reviewed for accuracy and quality.