NSA signals a far more aggressive posture on commercial AI access

The National Security Agency is positioning itself for a much deeper relationship with the commercial artificial intelligence sector. Speaking at an intelligence and national security event in Bethesda, Maryland, NSA Deputy Director Tim Kosiba said the agency wants access to "all" AI models and intends to make use of that access as Washington builds a more formal process for evaluating advanced systems.

The remark matters because it moves the discussion beyond general interest in artificial intelligence and into the mechanics of state access, testing, and deployment. The NSA has used AI in various forms for years, according to Kosiba, but he argued that the current generation of models represents a different class of capability. In his description, the change is not simply incremental improvement. It is about what the newest models can actually do, and the operational value that creates for intelligence and cyber missions.

That framing places the agency at the center of a policy shift already underway inside the U.S. government. Rather than treating frontier AI strictly as a private-sector product category, officials are increasingly treating it as infrastructure with direct implications for national security, cyber defense, and strategic competition.

A voluntary testing framework is becoming a national security instrument

Kosiba's comments come as the government implements a June executive order that directed national security agencies to create classified tests for AI systems that may reach advanced offensive cyber capability. The order, as described in the source reporting, sets up a voluntary arrangement through which developers can submit models for scrutiny when those systems may be sufficiently capable to justify additional review.

That structure is notable for two reasons. First, it suggests the U.S. government does not want to wait for public failures or openly demonstrated misuse before building an assessment regime around powerful models. Second, it gives the NSA a concrete operating role, not just an advisory one. The agency is not merely studying AI at a distance. It is helping define how the federal government will evaluate frontier systems when model capabilities may intersect with hacking, classified networks, or broader security risks.

The practical meaning of "access" remains deliberately broad. Defense One reported that access could include use through a company-controlled service, deployment inside a government environment, or availability for security testing. That ambiguity is important. It leaves room for multiple partnership models between developers and the government, from limited interface access to more direct handling inside controlled systems.

What the NSA appears to want from model developers

Although Kosiba did not identify which companies are involved, he said extensive conversations are taking place with frontier model firms. That suggests the government is already in a negotiation phase with leading developers rather than only forming policy in the abstract.

Several strategic goals are visible in that posture:

  • Gain insight into model capabilities before they are widely deployed.
  • Test whether advanced systems meaningfully change cyber offense and defense.
  • Determine what safeguards are needed when models approach sensitive thresholds.
  • Ensure national security agencies are not technologically behind the commercial frontier.

From the NSA's perspective, the case is straightforward. If commercial firms are building systems with meaningful implications for hacking, code generation, automation, and analysis, then a signals intelligence and cyber agency will want direct understanding of those tools. The agency does not appear content to rely on external summaries or public benchmarks alone.

That position also reflects a wider reality in AI governance: the most consequential expertise and computing infrastructure often sit outside government. A testing regime that excludes close contact with frontier developers would leave officials trying to regulate or assess systems they do not fully control and may not fully understand.

The unresolved questions are as important as the headline

The strongest signal from Kosiba's remarks may be the one hidden in what remains unsaid. He did not specify which developers are participating. He did not say which models the NSA already uses. And he did not disclose whether the agency has access to any unreleased systems. Those omissions leave critical policy questions unanswered.

For developers, the core issue is likely to be boundaries. How much visibility should a national security agency receive into commercial models? Under what technical, contractual, and legal conditions? If access includes internal deployment or classified-network testing, what protections govern model weights, system prompts, logs, or proprietary safety methods?

For policymakers, the issue is legitimacy and oversight. A voluntary framework can move faster than formal rulemaking, but it can also create uneven participation and unclear precedents. If some developers cooperate and others do not, the government may end up with a fragmented picture of the frontier. If participation becomes an informal expectation, the distinction between voluntary cooperation and practical obligation could narrow quickly.

Why this matters for the next phase of AI governance

The U.S. debate over AI often swings between innovation policy and safety policy. The NSA's posture shows a third track hardening into place: operational state use. That matters because it changes the terms of the relationship between government and frontier model companies. The conversation is no longer only about how to encourage AI leadership or reduce public harms. It is also about how intelligence agencies obtain, test, and potentially rely on systems developed in the private sector.

That has implications well beyond the intelligence community. Once agencies establish mechanisms for classified evaluation and controlled access, those processes can shape how companies document capability thresholds, internal safeguards, and deployment choices. In effect, a national security testing regime can become part of the commercial product environment for the most advanced models.

It also underscores how quickly frontier AI has moved into strategic territory. Only a few years ago, most public discussion centered on commercial productivity, chat interfaces, and model scaling. Now the deputy director of the NSA is publicly describing broad access to commercial models as an objective tied to White House directives and classified testing.

The immediate takeaway is not that a single access model has been chosen. It is that the U.S. government is building institutional machinery around the possibility that advanced AI systems may alter cyber power in ways that require direct national security involvement. Kosiba's remarks make clear that the NSA does not want to observe that transition from the sidelines.

If the voluntary testing program expands, the next questions will be concrete ones: which companies participate, what forms of access are granted, what capability thresholds trigger deeper review, and how much of the system remains classified from the public. Those answers will determine whether this becomes a narrow technical evaluation effort or the foundation of a lasting state-industry compact around frontier AI.

This article is based on reporting by Defense One. Read the original article.

Originally published on defenseone.com