Trump’s AI Model Executive Order Poses First Amendment Questions

Trump’s AI Model Executive Order Poses First Amendment Questions


President Trump’s June 2 executive order to accelerate artificial intelligence innovation in the US while strengthening national cybersecurity defenses draws an explicit line around its own authority.

One section directs agencies to design a voluntary framework allowing developers to ask the federal government whether a model qualifies as a “covered frontier model” — a term the order leaves to a classified benchmarking process focused on advanced cyber capabilities, and gives trusted partners pre-release access. But another says nothing in the section authorizes the government to create a permitting requirement for the “development, publication, release, or distribution of new AI models, including frontier models.”

That clause disclaims authority the section might otherwise be read to confer; it doesn’t say such a regime would be unlawful if Congress created one. But the line it draws may prove constitutionally important, with practical consequences for companies weighing open-weight releases. The order makes that line concrete: It brings the government into the process before release while disclaiming any authority to make approval a condition of release.

Congress, and agencies acting within statutory authority, have considerable room to regulate how powerful AI systems are deployed, accessed, and used. But requiring government permission before a developer can publish a model could present First Amendment questions.

Encryption Precedent

Three decades ago, federal efforts to control the export of encryption software produced cases examining whether source code qualified as protected expression.

In Bernstein v. US Department of Justice, Daniel Bernstein challenged export regulations requiring government approval before he could publish encryption source code. The US Court of Appeals for the Ninth Circuit held that code was entitled to First Amendment protection and raised serious concerns about placing government approval ahead of publication. The opinion was withdrawn when the court granted a rehearing en banc, so it’s not binding precedent, but it remains part of the constitutional history surrounding controls on technical information.

Junger v. Daley provides firmer appellate authority. The US Court of Appeals for the Sixth Circuit held that source code can be protected because programmers use it to exchange information and ideas. The court didn’t strike down the export system before it, but it rejected the broader proposition that source code loses constitutional protection simply because it also tells a computer what to do.

These cases don’t resolve the legal status of AI model weights. They simply frame the question as whether model weights, like source code, can be protected expression even though they also perform a function.

Model Weights

Both source code and model weights are technical artifacts whose distribution enables computers to perform specific functions, and both are shared as part of scientific work. Developers release weights so others can study, reproduce, test, and build on AI systems.

But weights differ from source code in a potentially decisive way. Source code is human-written and can communicate how a program works. Model weights are learned numerical parameters, generally unintelligible to a human reader in the same sense.

A government defending restrictions on open-weight releases could argue it’s regulating capability, not expression. Public release of powerful weights could enable advanced cyber operations, assist bioweapon development, or other national-security risks. On that view, regulating release looks less like regulating publication and more like controlling distribution of a technological capability. Developers would respond that a restriction aimed at dissemination burdens expressive activity even when the artifact is highly functional.

No appellate court has decided whether publishing model weights is protected expression, and much of the analysis turns on that. Requiring government approval before public release is not automatically an unconstitutional prior restraint. That concern becomes serious only if publishing weights is itself protected expression.

The encryption cases supply the analogy, not the answer.

Publication vs. Deployment

The operative distinction is between regulating a technology’s use and regulating its publication.

Governments possess broad authority over dangerous activities and technologies. Aircraft operations can be licensed, medical practice regulated, and access to hazardous materials controlled. Government licensing or preclearance of publication can trigger demanding First Amendment scrutiny where protected expression is involved, which is precisely what remains unsettled for model weights.

Export-controlled technical data presents similar tension. In Defense Distributed v. US Department of State, federal export rules required approval before certain firearms-manufacturing files could be posted online, and the Fifth Circuit declined to resolve the First Amendment merits when it denied preliminary relief.

AI complicates the distinction because publishing weights may distribute the AI capability itself rather than merely information describing it. Even so, the categories should be kept separate. Safety evaluations, voluntary pre-release testing, use restrictions, access controls, and downstream deployment rules present one set of legal questions. A mandatory approval gate, a requirement to obtain government permission before public release, presents another.

The stakes are becoming less theoretical. In Anthropic PBC v. U.S. Department of War, Anthropic brought a First Amendment retaliation claim arising from national-security actions against the company. The case doesn’t concern model weights or prepublication approval. But amici have argued that choices involved in designing AI systems can themselves implicate protected expression. That argument may give courts an earlier opportunity to consider when AI development is expressive activity.

Counsel’s Next Steps

Companies with open-weight release programs shouldn’t wait for a publication approval gate before thinking through the distinction. Instead, they should:

  • Preserve contemporaneous documentation of the research, scientific, and technical purposes served by weight releases. That record could establish the research and communicative context surrounding a release.
  • Distinguish internally between obligations governing deployment or use and those governing publication or distribution.
  • Track whether proposed legislation operates through reporting requirements, waiting periods, or approval gates. Those mechanisms can present materially different legal questions even when they appear together in the same AI safety proposal.

Courts eventually will decide whether the government is regulating expression, technological conduct, or some combination. But policymakers and counsel should distinguish between regulating what an AI model can do and requiring government permission before it’s published.

The most consequential boundary in AI regulation may not be technological, but constitutional.

This article does not necessarily reflect the opinion of Bloomberg Industry Group Inc., the publisher of Bloomberg Law, Bloomberg Tax, and Bloomberg Government, or its owners.

Author Information

Joseph Hoefer is chief AI officer and a principal at Monument Advocacy.

Interested in writing? Review our author guidelines and submit pitches to Insights@bloombergindustry.com.



Content Curated Originally From Here