President Biden's executive order on safe, secure and trustworthy AI defined dual-use foundation models partly by their potential to enable offensive cyber operations through automated vulnerability discovery and exploitation. It required developers to report red-team results to the government and directed a federal pilot using AI to find and fix vulnerabilities in government systems. The order was revoked by Executive Order 14179 on January 23, 2025.
Why it matters
It was a US executive instrument that treated automated vulnerability discovery and exploitation as a reportable frontier-model risk, and its revocation reset the US baseline.
Key facts
As stated in the sources, with where to find them.
- The dual-use foundation model definition includes models enabling powerful offensive cyber operations through automated vulnerability discovery and exploitation against a wide range of targets.Sec. 3(k)
- Companies developing dual-use foundation models must report results of relevant AI red-team testing and the mitigations taken.Sec. 4.2(a)(i)(C)
- Agencies were directed to complete, within 180 days, an operational pilot deploying AI such as LLMs to discover and remediate vulnerabilities in critical US government software, systems and networks.Sec. 4.3(b)(ii)
- Executive Order 14179, signed January 23, 2025, revoked EO 14110 and ordered review of actions taken under it.EO 14179, Sec. 5
Findings that cite this record
No tracked finding cites this record yet.
Key questions this bears on
- Is AI shifting the balance between finding and fixing vulnerabilities?Discovery is ahead. AI finds real vulnerabilities faster than they are fixed, and simple checks overstate how often AI patches work.
- How are attackers using AI agents in real operations?Increasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs.
Sources
Related records
Jun 2, 2026
Jun 30, 2026
Sep 29, 2025
Jul 10, 2025
Oct 15, 2024
Sep 2, 2026