The National Security Agency is spending billions of dollars this year evaluating and testing advanced artificial intelligence models, according to two sources familiar with classified intelligence estimates. The figure — significantly higher than any publicly known number — has reshaped how lawmakers think about the potential cost of comprehensive AI regulation, with some now projecting a federal oversight regime could run into the tens of billions annually. The spending is driven by two brutal cost realities. First, computing power: running and stress-testing frontier models requires enormous processing capacity on chips that are globally scarce and ferociously expensive. For context, Anthropic alone has lined up computing deals potentially worth $517 billion. Second, personnel: top AI engineers command salaries in the hundreds of millions of dollars, a pay scale the federal government cannot match even at the NSA, widely considered the deepest technical bench in government. Previous legislative proposals dramatically underestimated the cost. The Congressional Budget Office scored the AI Security and Innovation Act — a bipartisan House bill to establish an AI risk center — at roughly $20 million per year. A separate House tracking-and-reporting bill was estimated at $36 million total over five years. The NSA's actual classified spending dwarfs both by orders of magnitude, exposing the gap between legislative imagination and operational reality. President Trump has resisted federal AI oversight, rejecting proposals from both Congress and the frontier labs. But a string of high-profile hacking and security incidents forced the NSA's Artificial Intelligence Security Center into action, testing frontier models for national security vulnerabilities. The work is currently funded through classified portions of the national security budget; the Pentagon declined to comment on specifics, citing security. The cost revelation intensifies a structural question: who should pay? Elon Musk has floated peer review among frontier labs without government involvement. Google, OpenAI, and Anthropic are reportedly working on a joint safety standards body. AI safety experts have rejected self-policing as a category error. Anthropic and OpenAI have signaled openness to paying for independent federal oversight, and some experts advocate levying a tax on AI companies to fund government testing operations. Nathan Calvin of Encode captured the core problem: the government is competing in bidding with 'some of the most price-insensitive customers' on the planet. Nat Purser of the AI Verification and Evaluation Research Institute argued the government must fund computing resources and expertise, but acknowledged 'reasonable questions about if taxpayers should foot the bill,' suggesting an assessment on frontier developers could fund independent audits. The Pentagon's annual budget approaches $1 trillion, and some existing military allocations could theoretically be redirected to AI spending. But this is reallocation, not creation — every dollar shifted to AI testing is a dollar not spent on something else. The underlying dynamic is clear: the cost of verifying AI safety scales with the models themselves, and those models are growing faster than any budget line item in government history.