A Plan for AI, in Three Pillars
On July 23, 2025, the White House published its AI Action Plan, a 28-page policy document outlining the administration's priorities for artificial intelligence. The plan follows a Request for Information issued in February 2025, which drew over 10,000 public comments from industry, academia, and the public.
The plan is structured around three main pillars:
- Accelerate AI Innovation: Focuses on removing regulatory hurdles, promoting AI adoption, and ensuring the availability of open-source and open-weight AI models.
- Build American AI Infrastructure: Prioritizes high-security data center construction, bolstering critical infrastructure cybersecurity, and promoting Secure-by-Design AI technologies.
- Lead in International AI Diplomacy and Security: Centers on providing allies with access to AI and strengthening enforcement of AI compute export controls.
Each pillar assigns policy recommendations to specific federal agencies. Several elements of the plan deserve particular attention.
The Case for Open Ecosystems
The plan positions U.S. technological leadership in AI as a national priority and explicitly endorses open-source and open-weight models as a means to spur innovation. These models give companies flexibility, freeing them from dependence on closed providers and enabling AI use with sensitive data where exporting to external, closed models would be impractical.
However, open-source model availability alone is insufficient. A complete ecosystem, including distributed compute and inference infrastructure, is required to build and deploy AI applications. Access to GPU-powered inference at the edge is critical for fast and efficient AI development. This democratized access lets developers experiment freely with many different models and build applications without relying on gatekeepers.
The Security Dimensions of AI
The plan addresses cybersecurity in two principal ways. First, it endorses AI as a force multiplier for defending critical infrastructure. Predictive AI and machine learning are already deployed at scale to block cyberattacks, and newer tools even use AI to trap malicious AI-driven crawlers by directing them into endless mazes of AI-generated decoy pages rather than simply blocking them.
Second, the plan tasks the government with ensuring AI technologies themselves are secure-by-design. This work builds on existing federal efforts. The National Institute of Standards and Technology has been developing a Cybersecurity Profile for Artificial Intelligence, and private feedback on that initiative has supported the broader Secure-by-Design movement. The plan also proposes establishing an AI information sharing and analysis center and a vulnerability information exchange.
The plan also sees a key role for the federal government in accelerating its own AI adoption. Most federal agencies now have Chief AI Officers, signaling institutional commitment. Encouraging information sharing between agencies, promoting best practices, and training the workforce are all cited as ways to maximize efficiency gains.
Walking the Export Tightrope
The international strategy presents two aims that pull in opposite directions: aggressive AI export to allies and partners, and stringent restrictions on exporting AI compute and semiconductors.
The rationale for the first approach is to prevent allies from turning to rival nations for their AI technology stack, thereby solidifying a global alliance around American technology. The second approach seeks to deny foreign adversaries access to sensitive compute resources for national security reasons.
The tension is clear: overly stringent export controls aimed at adversaries could inadvertently restrict exports to allies or stifle innovation and the open exchange of ideas. The plan recognizes the private sector's essential role here, consistently calling for industry collaboration. It specifically directs the Department of Commerce to gather proposals from industry consortia for AI export packages, and it advises exploring new enforcement measures "in collaboration with industry."
This partnership approach is essential if export policies are to be technically feasible, globally effective, and avoid unintended consequences for the digital economy and cybersecurity. The implementation of these controls must be calibrated to target adversaries without hampering the innovation and open, globally distributed AI infrastructure that U.S. leadership depends on.



