Skip to content
AI PolicyRegulationGovernanceVendor RiskAgentsSmall Business

The White House seated the AI executives. Keep a vendor file that works under either answer.

On Tuesday, September 29, 2026, President Trump and House Speaker Mike Johnson hosted a White House luncheon with leading AI executives. Afterward, Trump talked up data centers and called for AI self-regulation, CNBC reports. Palantir CEO Alex Karp told CNBC outside the White House that tech leaders must take responsibility for known dangers. No comprehensive bill or executive order was announced from the lunch. For a small team, the useful move is still a vendor file that holds up whether the rules end up voluntary or required.

Steve Defendre
September 29, 2026
8 min read
The White House seated the AI executives. Keep a vendor file that works under either answer.

This is the first of our weekly notes, and the week's biggest AI governance story is a meeting that happened. On Tuesday, September 29, 2026, President Trump and House Speaker Mike Johnson hosted a luncheon with the heads of the leading AI companies at the White House.

A note on timing: the meeting took place Tuesday afternoon. The post-lunch reporting I rely on below is mainly CNBC's account, published Tuesday at about 1:08 p.m. ET and updated after. Pre-meeting framing (Johnson's Monday Fox Business interview, the expected-guest advance) stays labeled with those earlier dates. I will not invent a bill, executive order, or agreement nobody has reported.

What happened

The luncheon happened. CNBC reports that afterward Trump talked up the benefits of data centers and called for artificial intelligence self-regulation.

A seating chart posted to Trump's Truth Social account, as CNBC describes it, showed the president seated next to Nvidia CEO Jensen Huang and Tesla and SpaceX CEO Elon Musk, followed by Meta CEO Mark Zuckerberg and Google CEO Sundar Pichai. Vice President JD Vance sat opposite the president, between Amazon founder Jeff Bezos and Johnson. Other attendees CNBC lists include Microsoft CEO Satya Nadella, Anthropic CEO Dario Amodei and Tom Brown, OpenAI President Greg Brockman, and senior administration officials such as Treasury Secretary Scott Bessent. OpenAI was also hosting DevDay in San Francisco the same day. Apple's new CEO, John Ternus, did not appear on the list.

Palantir CEO Alex Karp spoke to CNBC outside the White House:

"The main issue that you have and I have is we have to take responsibility for the dangers we're aware of. All of us do. And by the way, American people don't want separate rules for tech people and for themselves."

Johnson had set the pre-meeting frame in a Monday interview with Fox Business. As CBS quotes him:

"Instead of just smothering this with red tape, which is always the government's reflex, and I think would be wrong and frankly dangerous to national security if we did it here, we want to continue the innovation. A balance is what we're after. I think the conversation tomorrow will help us along that way."

AFP quotes another line from the same Monday interview: "We do not need a moratorium. We do not need to jump in and hyper-regulate this, because we'll lose the race to China."

That Monday posture still describes the administration's public line. It is not a substitute for a written readout.

The week that set the table

The meeting came at the end of a crowded few days, and the dates matter.

  • Sunday, September 27. President Trump had a private dinner with Amodei late Sunday night, CBS reports. The White House has not released details. Before the dinner, Trump said they would "talk about" AI regulations, adding, "I'm for let's go and let's win." The same day, Meet the Press aired Bill Gates's call for required AI monitoring, which we covered on Sunday.
  • Monday, September 28. OpenAI said it would not release its GPT-6.1 Astra model to the public. Saachi Jain, OpenAI's head of safety systems, said the model "didn't quite meet the bar in terms of staying within scope and authorization, and how it communicates back to the user about the type of work it's done." The Wall Street Journal was first to report the decision; CBS carried Jain's statement.
  • Monday, September 28. Nvidia launched an Open Agent Safety Platform, AP reports. It pairs open-source software called OpenShell, which Nvidia says lets developers "formally verify an agent has enough authority to do its job and no more," with an on-chip monitoring layer called Sentry that Nvidia says "can quarantine a suspicious agent in milliseconds." Nvidia says more than 100 organizations are using it at launch.

The people at the table do not agree with each other. CBS notes that Anthropic and OpenAI executives have called for limits on the speed of AI development, while others, including Huang, argue the warnings are overblown and guardrails could cost the US its edge over China. Trump has called some of the fears a "hoax."

And the calendar still limits what Washington can do soon. AFP reports the House is on recess through early November and that Congress is all but certain not to pass comprehensive AI legislation before the midterm vote.

An antique balance scale resting level on dark stone, with glowing cyan orbs in one pan and amber-lit stone blocks in the other

What came out (and what did not)

Here is what CNBC and same-day coverage actually reported after the lunch, and what is still missing:

  • Self-regulation and data centers. Trump's post-lunch message, per CNBC, favored AI self-regulation and highlighted the benefits of data centers. That matches the growth-first posture Johnson previewed Monday. It is not the same as a statute.
  • Responsibility, from the sidewalk. Karp's on-camera remarks put the onus on industry to own known dangers and rejected "separate rules for tech people." Useful color. Still not a written White House commitment.
  • America.gov, same day. The luncheon coincided with an all-day event where the administration unveiled America.gov, an AI-powered chatbot and portal for government websites. That is a product announcement tied to the day's program, not a private-sector regulatory package from the East Room table.
  • No comprehensive legislation from the lunch. As of the CNBC report, no bill text, executive order, or negotiated agreement from this luncheon had been announced. Axios-style advance coverage had also expected few firm regulatory proposals. If a written readout or EO appears later, treat that as a separate fact with its own date.

What I would still watch for in follow-up coverage: a White House or Speaker's office written statement, anything that reads like industry pledges versus a request for legislation versus an executive action, and any specific mention of testing, evaluation, or limits on autonomous agents.

Why a small team should care

You were not in that room. Your vendors were, or their vendors were. Whatever "right balance" means after this luncheon, it will still reach you through procurement before it reaches you through law: customer questionnaires, vendor terms, and the defaults on the agent tools you already use.

That is why I would not wait for a winner. The growth-first, self-regulation posture from the White House and the calls for required monitoring from people like Gates can both be true at once for a while. A good vendor file works under either.

The dual-path file

  1. Write down both paths. Path one: rules stay voluntary, and your larger customers turn industry standards into contract requirements. Path two: something required arrives, federal or state. For each AI vendor you rely on, note what would change for you under each path. Most of the work is the same.

  2. Define "right balance" for your own agents. For every agent or assistant that can act on its own, write one line each: what it is allowed to touch, what it can reach on the internet, and what needs a human to approve. OpenAI's own reason for holding Astra was scope and authorization. Hold your tools to the same test.

  3. Allowlist egress by default. If an agent runs on your systems, block outbound traffic by default and allow only what the job needs. This is the plainest version of "enough authority to do its job and no more," and it is cheap to explain to a customer.

  4. Put human gates where the damage is. Sending email, pushing code, moving money, changing permissions, writing to shared drives. Those actions should wait for a person. Everything else can run.

  5. Ask vendors how they would answer. Add two questions to your next AI vendor review: what testing do you run before releasing a new model or agent capability, and would you tell us if you held one back? Keep the answers in the file.

A single glowing path from the horizon splitting into two lit roads across a dark reflective plain at dusk, one edged in blue and one in warm amber

After the East Room luncheon, the questions your customers ask next year will still look a lot like the list above. If you want help building a vendor file and agent permission map that holds up under either path, DefendResolutions does that kind of practical operator work.

Was this article helpful?

Share this post

Copy the link or send it across your usual channels.

Newsletter

Get the weekly field notes

One concise email each week with the latest insights on defense tech, AI, and software engineering.

Get the latest field notes once a week.

Discussion

Comments

Leave a comment

Loading comments…