The spy agency is taking a key role in the government’s new voluntary model-testing program, though its deputy director did not say which companies are participating. #
The National Security Agency wants access to artificial intelligence models across the commercial market and is holding extensive discussions with leading developers as it moves to carry out new White House directives on the technology, the agency’s deputy director said Thursday.
“We want access to all the models, and we’re going to take advantage of that,” Tim Kosiba said on a panel at an Intelligence and National Security event in Bethesda, Maryland.
Kosiba said NSA has used AI in various forms for decades, but the rapidly improving capabilities of newer systems are driving a more aggressive effort to obtain and deploy the fast-evolving technology.
“The transformative change that we see today is what these models can actually do,” he said.
The remarks offer one of the clearest public indications that NSA is actively engaging major AI developers as it assumes a central role in the government’s new framework for evaluating advanced models. They also follow months of internal deliberations among officials regarding the role the U.S. intelligence community’s primary signals intelligence and cyber organization should play in advancing U.S. AI competitiveness.
“There are a lot of conversations happening amongst industry, especially the frontier model companies,” Kosiba said. He didn’t identify the companies involved, say which models NSA currently uses or disclose whether any developer has provided the agency with access to an unreleased system.
The term “access” may cover several different arrangements. NSA could use a model through a company-controlled service, deploy a version inside a government environment or receive access for security testing of classified networks.
The conversations are occurring as NSA helps implement a sweeping June executive order directing national security agencies to create classified tests for determining when AI systems have developed sufficiently advanced hacking capabilities to warrant additional scrutiny.
The order calls for a voluntary arrangement through which developers can give the federal government access to qualifying models for as many as 30 days before releasing them to other trusted partners. It explicitly prohibits the creation of a mandatory government licensing or approval process for new AI models.
NSA’s director is responsible for deciding which systems meet the threshold for a “covered frontier model,” in consultation with the Office of the National Cyber Director, the Cybersecurity and Infrastructure Security Agency and other government offices.
A related national security directive issued in June instructed intelligence and defense agencies to form “deep, proactive partnerships” with industry and make the most advanced models available to national security personnel without delay. It also encouraged the government to avoid becoming dependent on a single company by obtaining technology from a diverse group of suppliers.
Kosiba’s comments didn’t establish that the voluntary pre-release program is fully operational or that companies have begun providing models through it. The White House told major developers earlier this month that open-weight models would not be included in the testing program. Unlike closed systems controlled by companies like OpenAI, Anthropic and Google, open-weight models make their underlying settings available for others to download and modify.
Government access to advanced AI has expanded. OpenAI’s latest GPT-5.6 models became available to federal customers this month through its FedRAMP-authorized enterprise service after their public release in July.
The push for broad access comes as the Defense Department remains locked in a legal and policy dispute with Anthropic over restrictions the company placed on certain military uses of its models. The Pentagon designated Anthropic a supply-chain risk after the company declined to relax some of those safeguards, prompting a lawsuit in which a federal judge temporarily blocked parts of the government’s action.
Parts of NSA temporarily lost access to Anthropic’s Mythos 5 amid an export control dispute between the company and the Trump administration, demonstrating how government access to commercially controlled systems can be affected by policy decisions outside the agency. The administration has subsequently lifted the restrictions that had affected access.
AI-enabled cyber risks have become an increasing flashpoint in recent months after Anthropic unveiled its first version of Mythos, an advanced model it withheld from public release because of concerns that its ability to find and exploit previously unknown software vulnerabilities could be misused.
Since then, Anthropic, OpenAI and other developers have introduced a growing family of models with similar capabilities, forcing policymakers to consider how to test the systems, control access to them and harness their abilities for cyberdefense without giving attackers the same advantage.
As NSA pushes to adopt AI faster, Kosiba said humans will remain responsible for checking that its use complies with surveillance laws and the agency’s internal rules.
“What the models are putting out, how we’re leveraging technology today, will always require that human to double-, triple-check and make sure we are in complete compliance with the law,” he said.