“We want access to all AI models and intend to exploit it.” Tim Kosiba, deputy director of the US National Security Agency, said this during an Intelligence and National Security Alliance event on August 27.
The stated objective is to test new models, understand their cybersecurity capabilities and identify vulnerabilities before others can exploit them.
It is easy to understand why an intelligence agency would be interested. Frontier models are becoming increasingly capable of finding software vulnerabilities and automating tasks that until a few years ago required advanced technical skills.
But the agency now asking to look inside the most powerful systems of the next digital infrastructure is the same one that, through documents disclosed by Edward Snowden 13 years ago, was found to have built a global surveillance system.
What does the Snowden case teach us?
In 2013, Edward Snowden worked as an NSA contractor and had access to classified documents that revealed surveillance programmes far more extensive than the public knew. He decided to give them to several journalists, exposing activities that had remained secret until then. The United States charged him under the Espionage Act and Snowden has effectively lived in exile in Russia ever since.
Among the tools revealed by Snowden’s documents was GUMFISH, an NSA component that could secretly activate the webcam of a compromised computer and take photographs. There was also CAPTIVATEDAUDIENCE, which could take control of a target computer’s microphone and record what happened around the device.
From 2008, the UK’s GCHQ, with NSA support, developed Optic Nerve, a programme that intercepted Yahoo users’ video chats and periodically stored images from them. During just six months in 2008, images from more than 1.8 million Yahoo accounts worldwide were collected, regardless of whether individual users were intelligence targets. A substantial portion of the images contained sexually explicit material.
Today, the NSA is seeking early access to the most advanced AI models.
On June 2 this year, the White House signed an executive order on the security of the most advanced AI systems, assigning the NSA a central role.
The agency will contribute to the assessment of models’ cybersecurity capabilities and the identification of the most advanced and potentially risky systems. At the same time, the government wants to allow companies to voluntarily grant federal agencies early access to their models, up to 30 days before they are made available to other trusted partners.
The official rationale is security. But the Snowden case showed what can happen when an intelligence agency simultaneously has three things: a “threat” to counter, exceptional technical capabilities and the ability to operate away from public scrutiny.
The surveillance revealed in 2013 did not originate outside the rule of law. It was built within a democracy, in the name of national security and through programmes that most citizens did not even know existed for years.
For a company, finding a vulnerability almost always creates an interest in fixing it. For an intelligence agency, the same vulnerability can become an operational capability to retain and use for its own purposes. The security of systems and the ability to penetrate them therefore coexist within the same institution.
Today, the access provided for by the White House order is voluntary and regulated. No one can know how the NSA will use these capabilities in the future. The precedent exists.





