The latest frontier AI models have demonstrated advanced cybersecurity capabilities, including the ability to identify software vulnerabilities, generate exploits, and automate complex attack chains at speed and scale. We have recently seen examples of such offensive capabilities from some of the leading AI models, putting increasing pressure on cyber defenders who work to protect critical infrastructure systems, public safety, and national and economic security to act before attackers can. Defenders, therefore, need tools and model access to understand and counter these capabilities before malicious actors misuse them, or models deploy them autonomously in uncontrolled ways. While much of the public attention has focused on leading models from major AI developers, similar capabilities have been observed in open-weight alternatives, which are rapidly approaching the performance of the frontier labs’ models and will play an increasingly important role in the defensive ecosystem.
Nevertheless, frontier models continue to represent the leading edge. Newer releases like Astra can reportedly develop exploits with limited human guidance, acting as an early indicator of capabilities that threat actors may soon be able to use, and open-weight models may soon be able to provide. Early access to frontier AI models would give defenders a crucial window to assess organizational risks, validate vulnerability claims, and strengthen enterprise security before adversaries can exploit the same advances.
We previously discussed how lack of early access to frontier AI models with advanced cyber capabilities can lead to weakened infrastructure resilience, distorted competition, and reduced time available for defenders to respond to emerging threats. This paper highlights how those challenges can be addressed to expand access to AI models.
Today, early access to new frontier closed-weight models is largely managed through private AI developers who offer opaque criteria for participation. Access is provided based on industry relationships and in response to non-public national security concerns and frameworks from the U.S. Government. This approach can be inconsistent and inequitable. It also prevents defenders from comparing the capabilities of widely available open-weight models against closed-weight competitors in their own unique environments.
Recognizing these critical challenges, the Trump Administration issued Executive Order 14409, Promoting Advanced Artificial Intelligence Innovation and Security, which established a framework to facilitate voluntary early access to covered frontier AI models for federal agencies and “trusted partners.” This effort is an important acknowledgement of the need for defenders to evaluate emerging AI capabilities before those capabilities are broadly deployed, but further transparency is needed to ensure an accountable process that meets the Executive Order’s stated objective of “working collaboratively with the private sector to modernize government and private sector information systems and harden them against external threats.”
Private sector organizations, many of which are critical infrastructure operators, face sophisticated cyber adversaries, including nation states, while managing systems whose disruption could result in significant national security consequences. At the same time, these operators are uniquely positioned to identify vulnerabilities in widely deployed technologies and operational environments. For example, the Log4Shell vulnerability in one of Apache’s libraries was found by an operator in a critical infrastructure sector. When defenders in these sectors gain responsible access to frontier AI cyber capabilities, the resulting security improvements can benefit not only individual organizations but the broader ecosystem that depends on them.
To realize these benefits, voluntary early access programs need a transparent framework designed to balance innovation, security, and public trust.
The IGI Framework for an Early Access Regime
We propose a public-private framework for responsible early access to frontier AI models built on three pillars: Information, Governance, and Implementation (IGI). Coming on the heels of the Administration’s recently finalized early access framework for the federal government, the IGI approach provides a useful anchor for implementation, especially since the details of the Administration’s framework are yet to be made public. The three pillars enable critical infrastructure operators to evaluate and use frontier AI cyber capabilities through transparent standards, accountable participation, and measurable security outcomes, while providing AI model developers with a scalable and sustainable process for expanding access. The IGI model also provides a policy anchor for the U.S. Government to structure the participation of “trusted partners” in its unreleased early access framework.
Pillar 1: Information – How do we know the model can deliver meaningful security outcomes?
Critical infrastructure operators need credible knowledge of frontier AI model capabilities under transparent evaluation criteria.
A core prerequisite for success of this framework is early and transparent access to information about model capabilities. Critical infrastructure operators should not have to rely on vendor claims alone when deciding whether to invest in and operationalize a new frontier AI system. Independent, standardized evaluations are essential to determine whether a model’s cybersecurity capabilities exceed an organization’s current defensive systems. The National Institute of Standards and Technology (NIST) is well positioned to help formulate these evaluation criteria given the organization’s history as a trusted home for multi-stakeholder processes and their expertise in evaluating frontier AI models to which they already have access.
Criteria should include effectiveness of vulnerability discovery, exploit generation capability, reproducibility of results, and operational costs. While some benchmarks for generating exploits are emerging, factors such as cost and reproducibility are still mostly missing from such authoritative evaluation criteria. Adding these criteria would help create a common language for measuring effectiveness, comparing models, and enabling informed adoption decisions.
Pillar 2: Governance – Who gets access, under what conditions, and why?
Frontier AI model developers should publish eligibility criteria, participant obligations, and mechanisms for public-private oversight.
As frontier AI models continue demonstrating improved cybersecurity capabilities, early access decisions should evolve beyond ad hoc, relationship-based, provider-specific processes. Executive Order 14409 calls on AI developers to “collaborate with the Federal Government to select trusted partners.” Sector Risk Management Agencies (SRMAs) and Sector Coordinating Councils (SCCs) within the Alliance of National Councils for Homeland Operational Resilience – Critical Infrastructure (ANCHOR-CI) framework are well positioned to help identify such organizations within critical infrastructure sectors. Through their deep understanding of sector-specific risks and operational realities, they can recommend a relevant set of participants to form trusted communities of practice.
Frontier AI developers should provide visibility into the eligibility criteria to identify which organizations qualify for early access programs and why. Eligibility should prioritize entities whose disruption could have significant national security, economic, and/or public safety consequences, as well as organizations uniquely positioned to identify vulnerabilities and improve the security of widely deployed technologies.
Early access should also be conditioned on clearly defined participant obligations. These requirements should include the secure handling of discovered vulnerabilities, responsible testing practices, timely sharing of lessons learned, and coordination through existing information sharing and vulnerability disclosure mechanisms. Establishing common expectations helps ensure that early access generates benefits for the broader cybersecurity ecosystem rather than for individual participants alone.
A governance model creates a transparent and scalable approach to early access, reducing the need for each developer to create separate eligibility frameworks and operating rules, often with limited visibility into sectors’ cybersecurity dependencies. Organizing participation through sector-based communities also enables peers with similar technologies, operational environments, and risk profiles to learn from one another, accelerating the collective security value derived from frontier AI capabilities.
By clearly defining eligibility to receive access, under what conditions, and with what responsibilities, early access programs can evolve from isolated pilot efforts into a sustainable public-private capability that strengthens the resilience of critical infrastructure.
Pillar 3: Implementation – Does early access measurably improve security?
Early access programs should be designed to demonstrate measurable security outcomes through structured vulnerability reporting, remediation tracking, and systematic sharing of lessons learned.
Granting early access is only the first step. To justify continued investment and broader adoption, stakeholders must determine whether access to frontier AI models produces tangible security benefits. Program participants and partners should establish consistent mechanisms for measuring outcomes and assessing the overall impact of early access on their security. Aggregating these results across sectors can provide insight into the ecosystem overall.
A voluntary early access framework should include clear expectations for how findings are reported, validated, shared, and acted upon, including defined vulnerability disclosure processes, coordinated timelines for remediation and public disclosure where appropriate, and mechanisms for collaboration among participants. Frontier AI developers should also establish structured feedback channels that allow participants to share insights on model performance, evaluation criteria, and governance processes. As models move toward broader deployment, developers should provide transparency into the safeguards added because of early access testing. The Administration’s new AI vulnerability clearinghouse, Gold Eagle, could serve as a central venue for collecting, deduplicating, and disseminating these findings.
To measure program effectiveness, participating organizations can choose to share aggregated, non-sensitive metrics such as vulnerabilities identified, patches deployed, and operational lessons learned. These metrics can help policymakers, AI developers, and infrastructure operators understand whether early access is producing measurable defensive gains. Just as importantly, they ensure the benefits of these programs extend beyond the initial participants and inform the broader security community.
Existing information-sharing organizations provide a natural mechanism for operational collaboration. Participants in Information Sharing and Analysis Centers (ISACs), the Joint Cyber Defense Collaborative (JCDC), and ANCHOR-CI can share more detailed findings through established and trusted sharing environments that already provide appropriate protections for sensitive information. Sector-specific insights can be exchanged among organizations facing similar risks and technology environments, while cross-sector trends and lessons learned can be elevated to broader public-private forums, including Gold Eagle.
Conclusion
The IGI implementation model serves two important objectives. First, it ensures the benefits of early access extend beyond a limited set of participants and contribute to the security of the broader ecosystem. Second, it creates a continuous feedback loop that enables frontier AI developers, critical infrastructure operators, and government partners to refine evaluation methods, governance frameworks, and model safeguards over time. The result is a sustainable approach that aligns incentives across stakeholders while maximizing the collective security value of frontier AI capabilities.
Frontier AI cyber capabilities represent a new class of security-relevant technology whose benefits will depend not only on model performance, but also on how access is evaluated, governed, and operationalized. Together, the three pillars of Information, Governance, and Implementation provide a framework for responsible and voluntary early access—one that enables independent validation of capabilities, aligns participation with public-interest objectives, and ensures that measurable security improvements are shared across the critical infrastructure ecosystem.
The views represented herein are those of the author(s) and do not necessarily reflect the views of the Aspen Institute, its programs, staff, volunteers, participants, or its trustees.

Elizabeth Chernow serves as Associate Vice President, Public Policy at Comcast Corporation. In this role, she focuses on the development of the company’s positions on a range of issues including broadband, cybersecurity, and artificial intelligence. She joined the company in 2010 and has nearly two decades of policy experience. Elizabeth holds a J.D. from American University Washington College of Law and a B.A. in Journalism from The George Washington University. She serves on the Board of The WICT Network: Washington DC/Baltimore Chapter. Elizabeth is a member of the D.C. Bar, an associate member of the Virginia State Bar, and a member of the Federal Communications Bar Association.

Noopur Davis is the Chief Information Security and Product Privacy Officer for Comcast, a global Fortune 30 media and technology company. Noopur leads teams responsible for product security and privacy, privacy operations, cloud security, information and infrastructure security, cybersecurity risk, security engineering, security incident response, the legal response center and technical fraud. Prior to Comcast, Noopur was Vice President, Global Quality at Intel Security Group. She was a Visiting Scientist and Senior Member of Technical Staff at Carnegie Mellon University Software Engineering Institute, Principal of a management consulting firm, and a software developer and leader at various Fortune 500 companies including Chrysler Corporation and Intergraph. Noopur holds a bachelor’s degree in Electrical Engineering from Auburn University and a master’s degree in Computer Science from the University of Alabama. She is a member of several trade associations and serves on the Board of Directors of Regions Financial, Board of Directors of Entrust, Board of Advisors of Immersive Labs and the Board of Directors of the National Technology Security Coalition.

Jayati Dev, Ph.D., is a cybersecurity researcher working at the intersection of policy and emerging technologies. She leads the inventorying workstream for the Post-Quantum Cryptography Center of Excellence at Comcast. She is also a Public Policy Researcher leading Comcast’s efforts on AI security public policy. She previously worked in the same team as a Privacy Engineer and helped build privacy threat modeling tools. Dr. Dev holds a Ph.D. in Security Informatics from Indiana University Bloomington where she worked on privacy-preserving technologies in conversational platforms. She also holds a Bachelor of Technology degree in Electronics and Communication Engineering from West Bengal University of Technology. She was a Google Public Policy fellow in cybersecurity policy and a co-lead researcher in a National Science Foundation multi-year investigation into IoT privacy. She also serves on the board of SCTE’s New England Chapter. She is the co-chair for the Emerging Technology Committee within the Communications Sector Coordinating Council. She also Co-Chairs the Special Interest Groups (SIGs) on Academia and Research as well as Public Policy within M3AAWG.

Vaibhav “VG” Garg, Ph.D., is Executive Director, Cybersecurity & Privacy Research and Public Policy at Comcast Corporation. In that role, he leads work at the intersection of cybersecurity, artificial intelligence, privacy, and technology policy. He has more than a decade of experience bridging technical research with public policy, working across engineering, product, legal, and government‑facing teams to translate policy principles into operational systems and standards. He has authored more than 30 peer‑reviewed publications, with work cited by the National Institute of Standards and Technology (NIST), the National Security and Telecommunications Advisory Committee (NSTAC), the Communications Sector Coordinating Council (CSCC), and international standards bodies. He has held leadership roles across industry and advisory bodies, including serving as Working Group Lead for NSTAC’s post‑quantum cryptography workstream, Vice Chair of the Consumer Technology Association’s cybersecurity and privacy committee, and Co‑Chair of CSCC’s Emerging Technology and Cybersecurity Committees. Dr. Garg holds a Ph.D. in Security Informatics from Indiana University Bloomington.


