The NSA Is Spending Billions to Test AI Models, Classified Estimates Show

NSA’s classified AI testing dwarfs Congress’s $20 million civilian proposal, forcing a fight over whether developers should foot the bill

Alex Barrientos Avatar
Alex Barrientos Avatar

By

Image: Deposit Photos

Key Takeaways

Key Takeaways

  • NSA reportedly spends billions annually testing frontier AI models for national-security vulnerabilities.
  • Compute costs and private-sector pay gaps make government AI evaluation structurally expensive.
  • Lawmakers debate whether frontier AI companies should fund independent safety evaluations they face.

A report based on anonymous sources says the NSA told lawmakers it is spending billions of dollars this year alone to test and evaluate frontier AI models. Two people familiar with classified intelligence estimates provided that account; no public budget document has confirmed the amount, and the Pentagon has not commented on the allocation of NSA resources.

The claim rests entirely on anonymous sourcing.

What the NSA Is Actually Doing

Reported spending is tied to the NSA’s Artificial Intelligence Security Center, which was established to examine frontier models for national-security vulnerabilities.

Frontier models are the most capable AI systems currently available. These are systems sophisticated enough to potentially assist with advanced cyberattacks, exploit sensitive information, or take actions that could affect national security.

The reported connection between this spending and the center has not been confirmed by an official NSA, Defense Department, or congressional source. The precise scope of any evaluations remains unconfirmed in public records.

Why Testing AI Costs This Much

Compute infrastructure and specialist personnel are the two primary cost drivers identified in the sourced reporting, though no itemized NSA budget has been made public.

Compute refers to the chips and data-center capacity required to run repeated, adversarial stress tests against systems that themselves demand enormous processing power. Personnel costs present a separate challenge: AI engineers in the private sector can command compensation packages reaching tens or hundreds of millions of dollars, creating a structurally difficult recruiting environment for any government agency.

The NSA carries one of the government’s deepest technical talent pools, but the gap between public-sector pay scales and frontier-lab compensation is not a rounding error.

Nathan Calvin of Encode said, according to the sourced reporting, that in-house AI evaluation capability “is extremely important and necessary. But it is genuinely expensive.” Nat Purser of the AI Verification and Evaluation Research Institute said the government needs to “fund the computing resources and expertise that requires.” Neither quotation has a publicly verifiable canonical source URL, and both should be treated as unverified direct quotes from the supplied reporting.

Who Should Pay the Bill

The reported NSA figure is dramatically larger than what Congress has proposed for civilian AI oversight, and that gap has opened a pointed debate about financing.

You can get a sense of the scale by comparing it with existing proposals. The Congressional Budget Office estimated that H.R. 9363, the AI Security and Innovation Act, would authorize $20 million for each fiscal year 2027 through 2032 for a civilian NIST center focused on AI risk measurement, with estimated implementation costs of $80 million over the 2026–2031 period.

The two efforts serve different purposes: classified national-security testing on one side, civilian standards and research on the other. But the reported cost difference is stark regardless of the comparison’s limits.

That gap has reportedly prompted some lawmakers to consider a developer-assessment model, essentially a fee on frontier AI companies to fund independent evaluations. Anthropic and OpenAI have reportedly expressed openness to federal oversight, though the available sources do not establish that either company has agreed to finance it.

Separately, Anthropic, Google, and OpenAI have reportedly been discussing a shared AI safety standards body, with conversations continuing through September 2026. Google DeepMind chief Demis Hassabis reportedly proposed a U.S.-led body combining government oversight, industry funding, and independent technical experts.

OpenAI confirmed those discussions. Its global affairs chief stated that industry-led standards would complement rather than replace federal safeguards and democratic oversight.

Critics point to a structural concern worth noting: companies helping to define the standards against which their own systems are judged face an inherent conflict of interest. No public charter, governance model, or funding structure for the proposed body had been identified at the time of reporting.

The unresolved question is not whether AI oversight is expensive. According to people familiar with classified discussions, it already is. What remains unsettled is whether the institutions capable of independently challenging safety claims made by the most powerful AI developers will be built by governments, funded by the companies they are meant to scrutinize, or left without sufficient resources as the models keep advancing.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →