Policypublished

NSA Seeks All Commercial AI Models as White House Offers 30-Day Pre-Release Tests

The proposed arrangement puts national-security testing nearer to frontier-model releases without creating a licensing system. Whether leading developers will participate—and on what terms—remains unsettled.

By 3 min read
NSA Seeks All Commercial AI Models as White House Offers 30-Day Pre-Release Tests

Listen to this story

The audio brief

About 1:36
0:001:36
Read transcript
The White House has invited OpenAI, Anthropic, Meta, and Google to review a voluntary plan for testing powerful AI models for cybersecurity risks before they reach other trusted partners. At the same time, the National Security Agency says it wants access to all commercial AI models, putting it closer to the systems this plan is meant to scrutinize. The framework follows a June executive order requiring classified tests for models with potentially serious hacking capabilities. Under the proposed arrangement, a developer could provide a qualifying model to the government for up to 30 days before broader release. But this is not a licensing checkpoint: the order explicitly bars mandatory approval for new AI models, so participation remains voluntary. NSA Deputy Director Tim Kosiba will help determine which systems qualify as covered frontier models, working with the Office of the National Cyber Director, the Cybersecurity and Infrastructure Security Agency, and other offices. The benchmark is classified, which means the public may not know who joins the review, which models qualify, or what the tests find. Kosiba has confirmed extensive discussions with companies, but no developer or unreleased model has been publicly identified. Government access can also happen after launch: OpenAI’s GPT-5.6 models reached federal customers through a FedRAMP-authorized service after their July release. The key question now is whether this voluntary framework produces a disclosed pre-release handoff from any major lab.

Story brief

3 key points

A proposed federal testing channel would let AI developers hand qualifying models to the government for up to 30 days before sharing them with other trusted partners. The framework follows a June executive order requiring classified cyber-capability tests, but it is explicitly not a pre-release approval regime. NSA officials are seeking broad commercial access and will help determine which models qualify. The...

  1. 01

    Participation remains voluntary; the June order bars mandatory licensing or approval for new AI models.

  2. 02

    NSA Director Tim Kosiba will help decide which systems qualify, alongside ONCD, CISA and other agencies.

  3. 03

    The benchmark is classified, limiting public visibility into attendees, qualifying models and test results.

The White House has invited OpenAI, Anthropic, Meta and Google to review a voluntary framework for cybersecurity testing of frontier AI models. At the same time, the National Security Agency is seeking access across the commercial AI market, placing the intelligence agency closer to the models the framework is meant to scrutinize before release.

The order came first

The policy effort began with a June executive order directing national-security agencies to develop classified tests for identifying AI systems with hacking capabilities serious enough to need added scrutiny. It sets up a voluntary arrangement: developers may provide qualifying models to the federal government for as long as 30 days before releasing them to other trusted partners.

That structure is deliberately not a federal approval gate. The order prohibits a mandatory licensing or approval process for new AI models, leaving participation to developers. The White House meeting is intended to let the four companies review the finished framework, its classified benchmark and the next implementation steps.

The agency at the center

NSA Deputy Director Tim Kosiba said the agency wants access to all commercial AI models and is in extensive conversations with frontier-model companies. A related June national-security directive also told intelligence and defense agencies to build proactive industry partnerships and draw advanced models from a diverse supplier base.

The NSA director has a formal role in the new program: deciding which systems count as covered frontier models, in consultation with the Office of the National Cyber Director, the Cybersecurity and Infrastructure Security Agency and other government offices. That decision determines which models can enter the voluntary pre-release channel.

Access is not yet participation

Kosiba did not name the companies in those discussions, identify the models the NSA already uses or confirm that any developer has granted access to an unreleased system. The agency’s public comments therefore do not establish that the pre-release program is operating or that companies have begun supplying models through it.

Government access can still arrive after a public launch. OpenAI’s GPT-5.6 models became available to federal customers through its FedRAMP-authorized enterprise service this month, after their July public release. The new framework is aimed at an earlier point: testing qualifying systems before they reach other trusted partners.

What the public cannot yet see

The benchmark’s classified status creates a built-in visibility limit. Outsiders may not know who attended the framework review, and the public record has not identified participating developers or a qualifying unreleased model. The next consequential move is whether the voluntary design produces a disclosed handoff from a lab to the government.

Editorial analysis

Our Read

Our Read: The policy’s central test is not whether Washington can define a cyber benchmark in secret. It is whether leading labs see enough value in voluntary participation to bring sensitive systems into a government review process before release. The executive order rejects formal licensing, so cooperation is the mechanism rather than a fallback. Watch for a concrete sign of uptake: confirmation that a developer has supplied a qualifying unreleased model, or public detail on how the NSA director will apply the frontier-model threshold.

Sources

  1. nextgov.comNSA wants access to ‘all’ AI models, top official says