Live
AI & ML

Gold Eagle federalizes AI bug-hunting, ducks the zero-day question

The White House on Tuesday launched Gold Eagle, a clearinghouse that takes in software vulnerabilities discovered by frontier AI models and routes them to government and industry engineers for triage and patching. Established under Executive Order 14409, signed June 2, the body seats the Treasury Department, DHS through CISA, and the Department of War alongside open-source software maintainers and critical infrastructure companies.

The release sketches three functions: intake and ranking of vulnerabilities across industries, coordinated scanning so participants stop duplicating each other’s work, and remediation guidance pushed out to federal and private-sector defenders. CNN’s Hadas Gold reports that AI and cybersecurity companies, along with critical infrastructure providers like utilities and banks, will use the platform to coordinate their efforts, though the White House declined to specify which companies are part of the project, beyond the release’s generic “open-source software partners and American critical infrastructure companies.” “These new capabilities make vulnerability discovery at a scale … that we have not seen before,” a senior White House official said in Tuesday’s briefing, per CNN.

“Under the leadership of President Trump, we are bringing a wartime footing to the cyber domain to relentlessly patch vulnerabilities.” — Secretary of War Pete Hegseth, in the White House release

Washington has built this machine before

Sector-specific ISACs date to a Clinton-era presidential directive; CISA’s Joint Cyber Defense Collaborative was 2021’s version of the same bet, that if you put government and industry at one table, the sharing follows. The record says sharing is the fragile part. The legal safe harbor that shields companies who hand over threat data, the Cybersecurity Information Sharing Act of 2015, was allowed to lapse entirely last September 30, and survived only through a chain of stopgaps before Congress extended it to September 30, 2026. The plumbing gets rebuilt every few years. The incentives don’t.

Gold Eagle adds a new incentive problem on top of the old ones. Whichever AI companies end up at the table will be direct competitors, and an AI-found zero-day doubles as product marketing. When Google’s Big Sleep agent caught a SQLite flaw before exploitation last summer, the company announced it as a first. Every find a lab routes quietly through a government clearinghouse is a find it can’t put in a keynote.

Disclose, or retain?

Here is the question the release does not touch, and our read is that the silence is the story. A model that finds flaws at scale for defenders finds them for the offense too, and the US government already has a mechanism for deciding whether a zero-day it holds gets told to the vendor or kept for intelligence and military use: the Vulnerabilities Equities Process, chartered in 2017 and criticized since for its opacity. Do AI-discovered flaws flowing through Gold Eagle go through the VEP, or around it? Who decides, and on what clock? The announcement specifies neither, and Nextgov’s David DiMolfetta and Alexandra Kelley note the administration also declined to say which agency runs day-to-day operations, how sensitive vulnerability data is protected, or how any of it meshes with CISA’s existing disclosure programs.

Some veterans are counseling patience. Michael Daniel, the former White House cyber coordinator who now runs the Cyber Threat Alliance, told CyberScoop’s Derek B. Johnson that AI in cyber is new enough that policymakers are still watching to see whether it changes the threat or just re-tools it.

Maybe.

But the deadlines are already stacked. A companion framework required by the same executive order, a system for AI companies to submit advanced models to the federal government for review before release, is due in early August, per CNN. And the liability protections that make private companies willing to share anything at all expire, again, on September 30.

// Author
Cassandra Lee

Cassandra writes about technology as a cultural force — what it does to how we live, work, and understand ourselves. She has a background in cognitive science and too many browser tabs open. Based in Vancouver.

Leave a Reply

Your email address will not be published. Required fields are marked *

@promptandpower

YouTube Channel

LinkedIn Page