Professional consulting services providing non-legal procedural and communication support. We are not attorneys and do not provide legal advice or representation.

Policy Analysis

What the Government Is Giving Away

← Back to News
This article is part of the In Plain Sight series. The prior installment, The Checkpoint Being Built Around You, described the Screening System Data Sharing Consortium as the data infrastructure layer that completes the Gold+ architecture. This piece goes inside it.

The Transportation Security Laboratory in Egg Harbor Township, New Jersey held its Industry Day for the Screening System Data Sharing Consortium on February 18 and 19, 2026. TSA leadership and DHS Science and Technology leadership were both absent due to the government shutdown. TSL Director Christopher D. Smith opened by noting that senior TSA leadership had assured him they remained fully committed to the program's goals. The presentations from that event were posted on SAM.gov on May 28, 2026.

What the Data Library Contains

The data library TSL presented already exists. It holds 74 terabytes of X-ray computed tomography data collected from checkpoint screening systems including equipment made by Analogic, SureScan, Leidos, and Smiths Detection, representing approximately 2.7 million bag scans. It holds an additional 30 terabytes of millimeter wave body scanner data representing more than 20,000 individual scans. The data includes stream of commerce items, guns, knives, explosives, homemade explosive materials, and other prohibited items.

TSL has also built a tool that generates synthetic training data calibrated to specific scanner hardware. The tool, called XCAT, currently supports three named systems: the Leidos Reveal CT80 DR+, the SureScan Detect 1000, and the Analogic ConneCT. Synthetic data generated by XCAT can be used at the earliest stages of algorithm training and, under the testing paradigm TSL presented at Industry Day, progressively replaced by real data as an algorithm matures toward certification.

What the Agreement Provides

Under the Cooperative Research and Development Agreement governing the consortium, published in draft form on SAM.gov with a public comment deadline of June 17, 2026, private companies receive access to that data to train threat detection algorithms. Article 4.1 of the draft CRADA states the agreement does not provide DHS with any ownership right to data submitted by any Consortium Members, nor any ownership stake in algorithms made by any Consortium Members with data sets submitted by Consortium Members. The companies own what they build with the data.

The standard DHS CRADA framework preserves irrevocable royalty-free government use rights to subject inventions. The SSDSC draft CRADA does not claim those rights for algorithms developed with consortium data. Battelle Memorial Institute is identified in Appendix B of the draft CRADA as the contractor responsible for data collection, curation, and validation.

The SureScan Connection

One of the scanner systems named in both the TSL data library and the XCAT synthetic data tool is the SureScan Detect 1000. SureScan is a founding partner in Gigaplex, the remote screening technology documented in prior AG analysis whose corporate partners are active in the Gold+ contractor landscape. SureScan's own product materials describe the Detect 1000 as built for open architecture and designed for integration of third-party algorithms, the exact framework Gold+ requires contractors to support.

Against Giants is not asserting that TSL designed its data library or its synthetic data tool to benefit any specific company. What the record shows is a documented connection between federal data infrastructure and a company whose corporate partners are positioned to compete for Gold+ contracts.

The Testing Paradigm

The testing paradigm TSL described at Industry Day is where the accountability question becomes concrete. TSL's own presenter acknowledged at the outset that machine learning algorithms show the ability to fail unpredictably and catastrophically when encountering scenarios they were not sufficiently trained against. A separate TSL presentation on the paradigm shift described brittleness testing as a non-negotiable phase of model validation in 2026, drawing a distinction between lab accuracy and real-world resilience.

Under the current testing model, a hardware vendor and its algorithm developer are tested together as an integrated system. Under the future third-party testing model, an algorithm developer submits software based on DICOS-formatted data and passes readiness testing against a software emulator rather than live hardware. The software receives a provisional analysis recommendation before it is ever paired with the physical equipment it will run on in the field. Hardware integration does not occur until after that gate.

The Liability Gap

The CRADA's answer to the liability question is explicit. TSL's Q&A responses state that responsibility for due diligence in creating threat detection algorithms rests with the developer, including ensuring algorithms are developed with data sufficiently representative of threats. Developers concerned about liability are directed to apply for Safety Act Certification. TSA and TSL will continue to certify algorithms using independent data not associated with the consortium.

What the framework does not address is what happens between provisional certification and the field. An algorithm that clears emulator-based readiness testing and provisional analysis, then fails in a live checkpoint environment after integration, enters territory the CRADA does not govern. The liability provisions in Article 8 limit DHS exposure to the Federal Tort Claims Act and explicitly disclaim any warranty on data accuracy or appropriateness.

That limitation matters less than it appears. The FTCA explicitly excludes independent contractors from its coverage under 28 U.S.C. 2671. A Gold+ algorithm developer is an independent contractor. The government's liability cap points to a statute that does not reach independent contractor conduct in the first place. The developer is responsible. The Safety Act is the backstop. The checkpoint is where the gap between those two things becomes operational.

What You Can Do Before June 17

The draft agreement governing how federal checkpoint data is shared with private companies is open for public comment. Questions worth raising include what happens if an algorithm fails in the field after passing TSL certification, and whether the public interest is served by a framework in which companies build commercial products using government data with no ownership stake retained by the government.

Public Comment Deadline: June 17, 2026

Submit comments to maria.torres@st.dhs.gov with a copy to michael.brogden@st.dhs.gov before June 17, 2026. Reference notice ID 70RSAT25RFI000018.
Full documentation is available at againstgiantsllc.com. Contact Against Giants at info@againstgiantsllc.com. Against Giants Labor Advocates is an independent nonpartisan workplace advocacy firm serving federal transportation security employees.
Before You Need Us

Know your position before the paperwork arrives.

Tell us your airport and your situation. The first consultation is free, and it is specific to your numbers.

Get Help: Describe Your Situation Ready now? Become a client for $35 per month.