White House expands its cyber reach with expanded AI policy, new cybercrime memo

The Trump administration, long associated with deregulation, is asserting new control over cyber operations via a reported expansion of its testing framework for frontier AI models and a stunning program that allows vetted private firms to run offensive cyber operations against foreign criminals.

Share
White House expands its cyber reach with expanded AI policy, new cybercrime memo

The Trump administration is taking significant steps that could expand the federal government's role in overseeing and deploying some of the most powerful technologies in cybersecurity, even as the White House continues to resist characterizing its approach as regulation.

In one development, the administration is preparing to broaden a still-secret framework for government testing of advanced artificial intelligence models before their release, according to WIRED. In the other, Donald Trump signed a National Security Presidential Memorandum establishing a program under which vetted private companies could conduct surveillance and disruptive cyber operations against foreign criminal organizations under federal direction.

Both moves illustrate an increasingly muscular approach to cybersecurity built around partnerships between government and technology companies. Rather than imposing broad regulatory requirements, the administration is drawing selected companies directly into national-security operations while seeking greater visibility into technologies it believes could themselves pose national-security risks.

The government wants access to more frontier AI models

The AI development builds on Trump's June executive order on advanced AI innovation and security.

That order directed the government to develop a classified benchmarking process for determining when an AI system possesses sufficiently advanced cyber capabilities to qualify as a "covered frontier model." It also called for a voluntary arrangement through which developers could give the government access to such models for as long as 30 days before releasing them to other trusted partners.

The order explicitly said the arrangement should not constitute mandatory licensing, preclearance, or permitting of AI models.

WIRED reported that the resulting framework currently encompasses closed models produced by companies such as OpenAI and Anthropic, but White House officials expect to expand it to open models once they reach comparable frontier capabilities.

The fundamental twist is that AI policy is increasingly becoming capability-based rather than dependent on how a model is distributed.

It also demonstrates the difficulty the administration faces in reconciling two objectives: avoiding an AI regulatory regime it believes could slow American innovation while responding to increasingly capable models whose cybersecurity implications the government considers serious enough to warrant prerelease examination.

According to WIRED, the framework remains voluntary, but officials are considering a more formal relationship with leading AI laboratories. Expanding the program to open models could create additional complications because imposing a testing period on models intended for broad distribution could slow their development and potentially undermine one of the advantages of open development.

The cybercrime memo goes considerably further

The second White House action moves beyond information sharing or voluntary security testing and creates a mechanism for private companies to participate directly in government-controlled cyber operations.

Trump's memorandum orders the Homeland Security Task Force's National Coordination Center to establish a program allowing approved US companies to conduct both "Cyber Surveillance Operations" and "Cyber Effects Operations" against foreign cyber-enabled transnational criminal organizations.

A cyber surveillance operation can involve accessing a target's systems without the owner's authorization while attempting to remain undetected. The definition explicitly encompasses collecting intelligence that could later be used to conduct a cyber effects operation.

Cyber effects operations go considerably further. They can involve the "manipulation, disruption, denial, degradation, or destruction" of information systems, networks, data, or even physical or virtual infrastructure controlled by information systems.

In other words, the memorandum isn't merely asking security companies to provide indicators of compromise, malware analysis, or intelligence to law enforcement. It creates a framework under which private companies could actually enter foreign systems and, with government approval, interfere with or destroy them.

That potentially represents a major expansion of the operational role private cybersecurity companies play in US law enforcement.

Not a private-sector license to hack back

There is an important distinction, however, between the new program and the "hack back" proposals periodically floated in Washington.

The memorandum repeatedly places participating companies under federal control. Companies must contract with either the Department of Justice or the Department of Homeland Security, and operations require government authorization. DOJ and DHS officials serving as the program's co-executive directors must coordinate before approving operations, and participating companies must receive written approval and direction before taking action.

The White House is therefore not giving companies a general right to retaliate against attackers who target their customers. Instead, it is effectively creating a pool of private offensive cyber contractors operating pursuant to government authority.

That distinction is important legally as well as operationally. The memorandum specifically requires the program to comply with the Computer Fraud and Abuse Act, the Constitution, and US international obligations and emphasizes that companies will operate under federal control.

Companies could also generate operations

One of the more interesting provisions is that participating companies won't necessarily execute operations handed to them by Washington.

The memorandum allows them to establish commercial relationships with other private companies that can supply threat information gathered through their normal operations. Participating companies can use that information to propose cyber operations to the National Coordination Center.

State, local, tribal, and territorial governments can similarly identify threats that participating companies can turn into operational proposals.

That creates a pipeline that could look something like this:

A cybersecurity provider discovers infrastructure belonging to a ransomware operation while protecting a customer. It provides the intelligence to a participating company. That company develops a proposed surveillance or disruption operation and sends an operational package to the NCC. DOJ and DHS review the proposal, coordinate it against intelligence, diplomatic, military, and other federal equities, and authorize the contractor to execute it on the government's behalf.

The private sector therefore becomes not merely an extra pair of hands but potentially a source of intelligence, targeting proposals and operational capacity.

The safeguards reveal some of the risks

Some of the most revealing portions of the memorandum concern the safeguards the White House believes the program will require.

Within 60 days, DOJ and DHS must establish detailed operating procedures governing the program. Those procedures must include standards for technical competence, personnel vetting, facility security and previous cyber-operational performance.

Companies may also be required to maintain a bond or escrow worth at least $1 million that can be forfeited for violating their contracts.

More consequentially, the procedures must establish mechanisms for deconflicting operations across federal law enforcement, State, Treasury, the Department of War and the intelligence community.

That provision points toward one of the central hazards of offensive cyber operations: a contractor attempting to disrupt infrastructure that another government agency is monitoring, exploiting, or using for intelligence collection.

The government must also establish an adjudication system intended to ensure that targets really qualify as cyber-enabled transnational criminal organizations.

The memo makes a consequential assumption about who counts as a criminal rather than a state actor

One of the most striking provisions is buried in the definitions.

Section 4(c) defines an eligible cyber-enabled transnational criminal organization as a foreign group conducting cyber-enabled crime against the United States, Americans, or US interests that isn't an institutional part of a foreign government or wholly operating at a foreign government's direction.

But the memorandum then establishes a significant presumption for making that determination: A foreign group will be assumed not to be part of a foreign government or wholly operating under its direction unless "clear intelligence" establishes such a connection.

That puts the presumption on the side of treating an organization as a criminal rather than a state actor. Section 4(c) presumes a foreign group is a criminal actor, not a state one, unless the government already has "clear intelligence" proving otherwise — a default that's easy for independent gangs but untested for the harder cases: groups tolerated or informally tasked by Russia, China, Iran or North Korea, where that clear intelligence rarely exists. That's precisely where a disruption operation risks escalating into a state-to-state incident.

The distinction could become particularly consequential when dealing with ransomware gangs and other cybercriminal groups operating from countries such as Russia, China, Iran and North Korea. The relationship between cybercriminals and governments isn't always binary. A criminal group might operate with a government's tolerance or protection, share personnel with state security services, occasionally conduct operations useful to the government, or assist intelligence agencies without being wholly controlled by them.

Russia in particular has long presented precisely that attribution problem. Cybercriminal organizations can operate from Russian territory while the precise nature of their relationship with Russian intelligence or security services remains uncertain.

Under the memorandum, uncertainty alone would not appear to be enough to treat such a group as state-controlled. Unless the government possesses clear intelligence establishing that the organization is part of or wholly directed by the foreign government, the presumption runs in the opposite direction.

That matters because the program authorizes considerably more than intelligence collection. Participating companies could conduct operations that manipulate, disrupt, degrade, or destroy foreign systems and infrastructure.

The presumption therefore isn't merely a definitional technicality. It could affect which foreign targets the United States considers eligible for disruptive operations and how much evidence officials need about a group's relationship with a hostile government before authorizing private contractors to act against it.

It could also carry escalation risks. An operation nominally directed at a criminal organization could affect infrastructure, capabilities, or individuals with connections to a foreign intelligence service, potentially turning what Washington regards as an anti-crime operation into something the foreign government views very differently.

The memorandum attempts to manage some of that risk through an adjudication framework and extensive interagency deconfliction. But Section 4(c) establishes the baseline from which those decisions begin: absent clear intelligence demonstrating government control, the target is presumed to be a non-state criminal organization.

Some operations remain beyond the program's authority

The memorandum establishes another boundary around what it calls "Critical Outcomes."

DOJ and DHS program directors cannot themselves approve an operation likely to cause death or serious injury or one that would rise to the level of a use of force or armed attack under international law.

That limitation underscores just how consequential some of the authorized operations immediately below that threshold could nevertheless be.

The definition of cyber effects explicitly includes destruction and operations affecting infrastructure. The policy therefore isn't confined to removing criminal websites or seizing servers. Depending on the implementation rules developed over the next 60 days, it could permit much more aggressive disruption.

This has been building since March

Wednesday's memorandum did not appear from nowhere.

Trump's March cybercrime executive order directed the government to establish an operational cell within the National Coordination Center to coordinate federal efforts to "detect, disrupt, dismantle, and deter" cybercrime committed by foreign transnational criminal organizations, including through private-sector participation where appropriate.

The new memorandum appears to provide the operational architecture for carrying out that ambition.

It also fits the administration's broader 2026 cybersecurity strategy, which placed considerably greater emphasis on disruption and imposing consequences on adversaries rather than relying primarily on defense.

What is new is the specificity: who can conduct the operations, who approves them, what kinds of effects they can produce, how private intelligence can generate proposed operations, and how government agencies are supposed to prevent those activities from colliding with one another.

A common thread between AI and offensive cyber policy

At first glance, prerelease testing of AI models and contractor-assisted operations against ransomware gangs might seem like separate policies.

But they reflect a similar conception of Washington's relationship with the technology sector.

The administration isn't primarily trying to regulate technology companies from outside. It increasingly wants to bring selected companies inside national-security activities.

AI developers would voluntarily provide the government access to frontier models so federal experts can determine what those models can do. Cybersecurity companies would provide intelligence, develop operational proposals, and potentially conduct surveillance and disruptive operations on government-selected targets.

In both cases, private-sector capabilities are advancing faster than the government's ability to reproduce them internally. The administration's answer appears to be deeper operational integration rather than building those capabilities entirely inside government or subjecting the industries to traditional regulatory regimes.

That may ultimately prove to be one of the defining characteristics of Trump's cyber policy: not less government involvement in advanced technology, but a different kind of government involvement — one that increasingly treats private technological capability as an instrument of national power. (Hugo Lowell / Wired and White House, White House)

Related: Reuters, Bloomberg,  r/singularity, r/accelerate


Metacurity is the cybersecurity news and analysis you'd need hours and expert staff to assemble yourself.

Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.

A paid subscription to Metacurity delivers

  • Full archive access — every newsletter and AI Watch roundup, searchable and browsable.
  • Our weekly curated long-reads roundup — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
  • Periodic specialized reports and analyses — deep dives that go beyond our daily coverage
  • Support for independent, no-spin cybersecurity journalism — funded by readers, not vendors or investors.

Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.

Please consider supporting us. And thank you!