Chronicle/Policy & standards

US Executive Order 14110 names offensive cyber capability as a dual-use foundation model risk

PolicyRegulationSignificance assistant-drafted

President Biden's executive order on safe, secure and trustworthy AI defined dual-use foundation models partly by their potential to enable offensive cyber operations through automated vulnerability discovery and exploitation. It required developers to report red-team results to the government and directed a federal pilot using AI to find and fix vulnerabilities in government systems. The order was revoked by Executive Order 14179 on January 23, 2025.

Why it matters

It was a US executive instrument that treated automated vulnerability discovery and exploitation as a reportable frontier-model risk, and its revocation reset the US baseline.

Key facts

As stated in the sources, with where to find them.

  • The dual-use foundation model definition includes models enabling powerful offensive cyber operations through automated vulnerability discovery and exploitation against a wide range of targets.Sec. 3(k)
  • Companies developing dual-use foundation models must report results of relevant AI red-team testing and the mitigations taken.Sec. 4.2(a)(i)(C)
  • Agencies were directed to complete, within 180 days, an operational pilot deploying AI such as LLMs to discover and remediate vulnerabilities in critical US government software, systems and networks.Sec. 4.3(b)(ii)
  • Executive Order 14179, signed January 23, 2025, revoked EO 14110 and ordered review of actions taken under it.EO 14179, Sec. 5

Findings that cite this record

No tracked finding cites this record yet.

Key questions this bears on

Sources

Related records