NEWS
NSA Wants AI to Sift Intercepts It Cannot Finish
NSA wants AI to triage intercepts that still take days, while the same agency writes a 30-day test for models that can hack.
David Imbordino told a Washington panel on September 8 that NSA wants AI to triage intercepts that now take analysts days or weeks. Volume has always been a problem, he said, and the tools offer a way to reach the nuggets faster than the current slog.
The same class of models is the subject of a June order that gives his agency up to 30 days to test whether a system has become too good at hacking before it reaches other trusted partners.
NSA Analysts Still Need Days to Reach the Signal
Imbordino, director of NSA’s Cybersecurity Directorate, spoke on a Five Eyes panel at the 17th Annual Billington CyberSecurity Summit, a three-day meeting running September 8-10. The summit drew more than 3,000 attendees and more than 250 speakers, with 33 sessions tagged for artificial intelligence, under the banner of cutting risk in an age of AI-enabled threats.
His office handles intelligence collection and cyber defense at the same time. The agency takes in intercepted foreign communications every day, plus electronic signals from radar and weapons systems, and the pile has outrun the people assigned to read it.
I think right now we’re looking at how to use an AI where we could triage so much more.
David Imbordino, Director, NSA Cybersecurity Directorate, Billington CyberSecurity Summit
He said analysts will, in the near future, use the tools to look at disparate pieces of information and evaluate them much more quickly than methods that still consume days or weeks. The pitch is speed. The catch inside his own shop is that the models which sort the take are also models that find and open software flaws.
Imbordino’s Own Warning Came in June
On June 22 he signed the Five Eyes warning on frontier models with the cyber heads of Australia, Canada, New Zealand, the United Kingdom, and CISA. The statement said frontier models are expected to beat current industry forecasts and to transform both offensive and defensive cyber work. The timeline, the five agencies wrote, is months, not years.
They also said AI lowers the bar for attackers and shrinks the gap between the discovery of a flaw and its use. Defenders, they argued, have to use the same tools on purpose, not only to work faster. That is the sentence that hangs over the September 8 remarks: the machine that helps an NSA analyst reach a nugget is the machine that helps someone else reach a network.
THE CLOCK FROM JUNE TO SEPTEMBER
- June 2, 2026: President Donald Trump signs Executive Order 14409, Promoting Advanced Artificial Intelligence Innovation and Security.
- June 5, 2026: A presidential memorandum on AI in the national security enterprise calls for putting advanced models in the hands of intelligence professionals without delay.
- June 22, 2026: Five Eyes cyber agencies, with Imbordino among the signers, warn that the offensive shift is months away.
- July 14, 2026: The White House announces GOLD EAGLE, the AI cyber clearinghouse ordered in June.
- Late August 2026: NSA deputy director Tim Kosiba says the agency wants access to all the models and is talking to frontier developers.
- September 8, 2026: Imbordino describes AI triage for intercepts; NSA Cyber posts a joint advisory on China-based distillation of U.S. models.
The June warning and the September pitch are not two policies. They are two jobs for one technology, described by one official, 78 days apart.
What the June Order Asks of Frontier Labs
Executive Order 14409 tells national security agencies to build classified tests for hacking skill and to decide when a system should be named a covered frontier model. Developers may, if they opt in, give the government access for up to 30 days before those models go to other trusted partners. An earlier draft had set that window at 90 days; the signed order cut it by 60 days after industry and White House aides fought over delay.
The order says it does not create a mandatory license, pre-clearance, or permit for new models. The test still sits with NSA. The 60-day clock to build the classified benchmark ran from June 2 through August 1. Kosiba, speaking in late August, described talks with developers and did not say the test was finished or that any lab had opened a still-unreleased model.
THE JUNE ORDER IN THREE PARTS
| Piece | Who runs it | Clock |
|---|---|---|
| Classified cyber test for covered frontier models | NSA director, with CISA and the national cyber director | 60 days from June 2 to build |
| Voluntary early access for opt-in developers | Frontier labs that agree to the arrangement | Up to 30 days before trusted partners |
| AI cyber clearinghouse for finding and patching holes | Treasury, with NSA and CISA | Ordered within 30 days of June 2; announced July 14 as GOLD EAGLE |
The White House later named the clearinghouse the GOLD EAGLE vulnerability clearinghouse, a joint shop meant to deconflict scanning, confirm holes, and push patches. That is the defensive face of the same order that asks labs for a look at models before they ship.
Kosiba Wants Every Model, With a Human in the Loop
In late August in Bethesda, Maryland, deputy director Tim Kosiba said NSA has used forms of AI for years, but the pace of the new systems is forcing a faster buy. He said the agency wants access to all the models on the market and is in talks with companies that build the most advanced ones. He named no firms, named no models, and did not say whether anyone had granted a pre-release look.
What the models are putting out, how we’re leveraging technology today, will always require that human to double-, triple-check and make sure we are in complete compliance with the law.
Tim Kosiba, Deputy Director, National Security Agency, Bethesda remarks
Access, as he described it, could mean a company-hosted service, a model inside a government-controlled environment, or tests against classified networks. A separate June memorandum told defense and intelligence agencies to get capable models to national security staff quickly and to spread suppliers so no single company holds the stack.
WHAT WE KNOW
- The talks: Kosiba said discussions with advanced-system developers are under way to carry out the White House testing directive.
- The human check: He said a person must still double- and triple-check model output for legal compliance.
- The buy: He framed the push as a way to field top commercial systems faster than NSA’s usual acquisition path.
WHAT IS UNCONFIRMED
- Pre-release access: He did not confirm that any developer has given NSA a model that is not yet public.
- The test’s status: He did not say the classified cyber benchmark is finished or in regular use.
- The roster: He did not identify which models the agency already runs.
That gap matters because Imbordino’s triage pitch assumes the tools are close enough to put in an analyst’s workflow. Kosiba’s own account still describes a shopping trip, not a finished pipe.
A Classified Test Decides Which Systems Count
Under the order, the NSA director names covered frontier models after a classified test of advanced cyber skill, in consultation with the national cyber director, the president’s science adviser, and CISA. James Sanders, a research associate at the Center for a New American Security, noted that keeping the benchmark classified is unusual, because evaluators usually publish methods even when they hide the questions, and that the order’s scope is cyber risk rather than other hazards such as biological risk.
Vivek Chilukuri, a senior fellow who directs the center’s technology and national security program, wrote that a voluntary setup can work, then asked for how long, if firms building the equivalent of cyber weapons can choose whether to share them before a public release.
If private companies developing the equivalent of cyber weapons can elect to work with the government (or not) before releasing those capabilities publicly, we are essentially ceding national (and international) security to the judgment and goodwill of a few companies.
Vivek Chilukuri, Senior Fellow and Director, Technology and National Security Program, Center for a New American Security
Daniel Remler, another senior fellow there, questioned why an intelligence agency should sit at the center of those designations rather than the Commerce Department’s standards shop, and said that choice may land badly with allies who want U.S. technology. Michelle Nie, a visiting fellow, wrote that CISA has lost about a third of its workforce since 2025 and that the president’s fiscal 2027 budget proposes cutting CISA’s funding by $707 million, even as the order gives CISA new work on binding directives and model access for civilian systems.
The order also tells CISA to help agencies, states, and operators of critical infrastructure, including rural hospitals, community banks, and local utilities, get cyber tools and, where appropriate, covered frontier models. Access is not the same as being able to use what the models spit out. The hospitals and utilities named in the text are already behind on older patching, and a 30-day look in Fort Meade does not install a patch in a county clinic.
Five Eyes Partners Heard the Pitch in Washington
Imbordino’s September 8 panel sat with officials from the same alliance that signed the June warning. The summit agenda billed allied-nation sessions on a shared analytic framework, attribution, and threat ranking. Richard Horne, chief executive of the United Kingdom’s National Cyber Security Centre, was on the speaker list. The Five Eyes cyber statement in June had already told vendors, not only boards, to move.
WHO THIS HITS FIRST
- NSA analysts: Their days-or-weeks slog is the public reason for putting models on the intercept pile, and they remain the people Kosiba says must still check the output.
- Frontier developers: They are asked, without a license mandate, to open qualifying models for up to 30 days and to help pick trusted partners who get them next.
- Five Eyes cyber shops: They signed the months-not-years warning with Imbordino and then sat in the same Washington room while he described triage as the near-term use.
- Civilian operators named in the order: Rural hospitals, community banks, and local utilities are listed as intended recipients of defensive tools and, where appropriate, covered models they may not have staff to run.
The old limit on bulk intercept was never disk space. It was how many trained people could read what came in, and how long each pass took. AI triage goes at that limit. If the models work as Imbordino sketched them, more of the take becomes usable, which changes what is worth keeping, not only how fast a single report is written.
The Distillation Alert Landed That Afternoon
While the Billington panel talked about nuggets, NSA Cyber posted a joint product with the FBI and CISA. The agencies said China-based AI companies are illicitly distilling U.S. frontier AI capabilities, and they published a China-based AI distillation advisory on tactics and mitigations.
China-based AI companies are illicitly distilling U.S. frontier AI capabilities. Read NSA’s new report, co-sealed with @FBI, @CISAgov, highlighting AI knowledge distillation, TTPs used, and recommended mitigations: https://t.co/IgBFOnjXeg pic.twitter.com/JUYg5I08GP
— NSA Cyber (@NSACyber) September 8, 2026
Distillation, in this fight, means training a weaker model on the answers of a stronger one until the copy close enough to matter. U.S. labs have spent the year asking Washington for help against that copying. The same afternoon the cyber directorate’s chief talked about using those models to sort intercepts, the agency’s public cyber arm warned that the capabilities themselves are being siphoned.
Kosiba still has not said whether any lab has opened a model before release. The analysts Imbordino described still need days or weeks unless those systems actually show up in the workflow, under the same legal double-check he and Kosiba both refuse to drop.
-
LIFESTYLE3 weeks agoAlfalfa Sprouts Outbreak Follows 16 Months Without Reinspection
-
NEWS2 weeks agoInstagram First Draft Pulls the Rough Cut In-House
-
NEWS6 days agoRene Haas Ties an AI Cancer Cure to Scarce Chips
-
NEWS6 days agoHimalayan Glacial Flood Risk Outran Nepal’s Lake Maps
-
NEWS6 days agoLinkedIn Finds Gen Z Too Afraid to Use Its Network
-
NEWS6 days agoAI Influencer Labels Fail to Protect Body Image
