President Trump's June 2 executive order on artificial intelligence and cybersecurity draws an explicit line around its own authority - one that may prove constitutionally significant for companies weighing open-weight model releases. The order directs agencies to design a voluntary framework letting developers ask whether a model qualifies as a "covered frontier model" through a classified benchmarking process, but it also states that nothing in the section authorizes a government permitting requirement for AI model development, publication, release, or distribution.
That clause disclaims authority the section might otherwise be read to confer. It doesn't say such a regime would be unlawful if Congress created one. But it brings the government into the process before release while disclaiming any authority to make approval a condition of release.
Congress and agencies acting within statutory authority have considerable room to regulate how powerful AI systems are deployed, accessed, and used. Requiring government permission before a developer can publish a model, however, could present First Amendment questions.
The Encryption Precedent
Three decades ago, federal efforts to control the export of encryption software produced cases examining whether source code qualified as protected expression. In Bernstein v. US Department of Justice, Daniel Bernstein challenged export regulations requiring government approval before he could publish encryption source code. The US Court of Appeals for the Ninth Circuit held that code was entitled to First Amendment protection and raised serious concerns about placing government approval ahead of publication. The opinion was withdrawn upon rehearing en banc, so it isn't binding precedent, but it remains part of the constitutional history surrounding controls on technical information.
Junger v. Daley provides firmer appellate authority. The Sixth Circuit held that source code can be protected because programmers use it to exchange information and ideas. The court didn't strike down the export system before it, but it rejected the broader proposition that source code loses constitutional protection simply because it also tells a computer what to do.
These cases don't resolve the legal status of AI model weights. They frame the question: can model weights, like source code, be protected expression even though they also perform a function?
Model Weights vs. Source Code
Both source code and model weights are technical artifacts whose distribution enables computers to perform specific functions, and both are shared as part of scientific work. Developers release weights so others can study, reproduce, test, and build on AI systems.
But weights differ from source code in a potentially decisive way. Source code is human-written and can communicate how a program works. Model weights are learned numerical parameters, generally unintelligible to a human reader in the same sense.
A government defending restrictions on open-weight releases could argue it's regulating capability, not expression. Public release of powerful weights could enable advanced cyber operations or assist bioweapon development. On that view, regulating release looks less like regulating publication and more like controlling distribution of a technological capability. Developers would respond that a restriction aimed at dissemination burdens expressive activity even when the artifact is highly functional.
No appellate court has decided whether publishing model weights is protected expression. Requiring government approval before public release is not automatically an unconstitutional prior restraint - that concern becomes serious only if publishing weights is itself protected expression. The encryption cases supply the analogy, not the answer.
Publication vs. Deployment
The operative distinction is between regulating a technology's use and regulating its publication. Governments possess broad authority over dangerous activities and technologies: aircraft operations can be licensed, medical practice regulated, and access to hazardous materials controlled. But government licensing or preclearance of publication can trigger demanding First Amendment scrutiny where protected expression is involved - precisely what remains unsettled for model weights.
Export-controlled technical data presents similar tension. In Defense Distributed v. US Department of State, federal export rules required approval before certain firearms-manufacturing files could be posted online, and the Fifth Circuit declined to resolve the First Amendment merits when it denied preliminary relief.
AI complicates the distinction because publishing weights may distribute the AI capability itself rather than merely information describing it. Even so, the categories should be kept separate. Safety evaluations, voluntary pre-release testing, use restrictions, access controls, and downstream deployment rules present one set of legal questions. A mandatory approval gate - a requirement to obtain government permission before public release - presents another.
The stakes are becoming less theoretical. In Anthropic PBC v. US Department of War, Anthropic brought a First Amendment retaliation claim arising from national-security actions against the company. The case doesn't concern model weights or prepublication approval, but amici have argued that choices involved in designing AI systems can themselves implicate protected expression.
Counsel's Next Steps
Companies with open-weight release programs shouldn't wait for a publication approval gate before thinking through the distinction. They should preserve contemporaneous documentation of the research, scientific, and technical purposes served by weight releases - a record that could establish the communicative context surrounding a release. They should also distinguish internally between obligations governing deployment or use and those governing publication or distribution.
Legislative tracking matters too. Proposed AI safety measures can operate through reporting requirements, waiting periods, or approval gates. Those mechanisms present materially different legal questions even when they appear together in the same proposal.
Courts eventually will decide whether the government is regulating expression, technological conduct, or some combination. The most consequential boundary in AI regulation may not be technological, but constitutional.
Why This Matters for Government and Legal Professionals
For government lawyers and policy advisors, the distinction between regulating use and requiring pre-publication approval isn't academic - it determines how agencies can structure AI oversight without inviting First Amendment challenges. For counsel advising AI developers, the practical takeaway is to build the legal record now: document the research and scientific purposes of weight releases, separate deployment obligations from publication restrictions, and track whether proposed legislation operates through reporting requirements or approval gates. Those choices will shape which constitutional questions reach the courts and how they're answered.
Your membership also unlocks: