In the week since his inauguration, President Trump has signed a flurry of executive orders. One important order that went missing was what to do about over-classification and the formal adoption of an Obama administration effort to control unclassified information. This awkward information management tool, known as CUI, has roiled the information technology and space industry as unnecessary and harmful. The Biden administration wanted to straighten it out with an executive order of its own. That order, however, never was issued.
Now, the Federal Acquisition Regulation Council has proposed a uniform controlled unclassified information regulation. It is open for comment through March 17th.
President Trump has made it clear that he wants more classified information to be made available to the public. That’s why he just ordered the release of thousands of classified documents related to the assassinations of John F. Kennedy and Martin Luther King Jr.
Meanwhile, John Ratcliffe, Trump’s former Director of National Intelligence, has just been sworn in as his new CIA director. This is an important development. Ratcliffe, in 2020, formally opposed implementing controlled unclassified information restrictions. This was not a partisan swipe. Not much longer afterwards, Frank Kendall, Biden’s Secretary of the Air Force, echoed Ratcliffe’s concerns, saying, “kill this monster before it gets any bigger.”
NPEC’s newest report, “Senseless Secrecy: Controlled Unclassified Information,” attached below, explains why formalizing CUI with a uniform general rule that applies to national security matters will be a costly ($4 to $10 billion/year) mistake. It already is hobbling America’s competitiveness in high-tech, AI, cyber, and space pursuits and has disrupted critical flows of information to defense contractors, trusted security allies, and even US military commands. Further formalizing this information management restriction to national security concerns will only make matters worse.
NPEC has examined these costs and risks over the last two years by commissioning research briefs and discussing them in a battery of 11 private workshops. Bottom line: our government already has an established national security classification system. For all of its faults, it is far more robust, sensible, and transparent than controlled unclassified information restrictions could ever be.
In this regard, we should heed Mr. Ratcliffe’s and Mr. Kendall’s advice: our government needs to review the bidding before adopting any uniform rule that would further formalize the use of controlled unclassified information restrictions for national security matters.
As always, curious to get your take on the detailed findings of NPEC’s report. You can access a full copy of the paper below.
January 27, 2025
Editor: Henry Sokolski
Senseless Secrecy: Controlled Unclassified Information
January 27, 2025
By Henry Sokolski
Two years ago, NPEC released “Over-classification: How Bad Is It, What’s the Fix?” Several of that study’s key recommendations were subsequently dialed into the Sensible Classification Act of 2023. This report builds on that analysis, which concluded that failing to lower restrictions on national security information undermines our nation’s competitiveness and ability to collaborate with allies and private firms to deter and defeat our adversaries.
Almost as soon as NPEC released its first report, though, a new challenge emerged: the government’s application of controlled unclassified information (CUI) restrictions on documents and information that previously were unrestricted. The Pentagon is now in the business of restricting unclassified information when it shouldn’t. This is different and far more Orwellian than placing too high a level of classification on certain national security secrets or failing to declassify such information in a timely manner. It is restricting public access to information that our government admits isn’t classified.
This didn’t happen overnight. It took 14 years and what all too often comes from good intentions—the reverse of what’s desired. Back in 2010, the Obama administration launched CUI as an information management tool to reduce government restrictions on access to government information. The aim was to consolidate the large number of low-level information restrictions – e.g. For Official Use Only (FOUO), Personal Private Information (PPI), etc. – so that such restrictions might not be used as frequently or as arbitrarily.
That was the intention. As soon as the administration asked the various government departments and agencies what topics should be subject to CUI restrictions, though, matters ran off the rails: The Federal Register cataloged no less than 112 possible applications. This, in turn, expanded the use of CUI information restraints.
Of course, such restrictions arguably make sense to protect information unrelated to national security – Internal Revenue Service filings, personal medical records, personnel files, etc. Where applying CUI becomes surreal, though, is when it’s used for national security matters. The reason why is simple: for defense information, an established classification system already exists. This system designates individuals with classification authority, details rules for classifying and declassifying information, and has an established appeals process.
Using CUI on top of this classification system is excessive: it adds an overwhelming administrative burden on contractors, who already protect proprietary information as well as national security secrets. It also keeps the public, our allies, and contractors in the dark about matters that they ought to have access to – routine logistical and test information, information that has already formally been declassified, and, too frequently, open-source information critical to informed national security policy and military operations. It also will be quite expensive to fully implement. By one account, the Pentagon conservatively estimated annual costs will run into the billions.
Various agencies have already tried their hand at implementing CUI now for more than a decade. Yet only this month did the Federal Acquisition Regulatory Council issue a proposed uniform Federal Acquisition Regulation (FAR) for CUI. Many of the speakers and attendees of NPEC’s last 11 workshops favored dropping the use of CUI for national security matters (for a listing of all the participants and speakers, see Appendix A).
They had cause. NPEC’s workshops revealed several worrisome abuses of CUI:
- In February 2022, the Pentagon released its annual weapons test report (i.e. the director of operational test and evaluation report) with 22 programs redacted as CUI. Senator Armed Services Committee member Elizabeth Warren objected to the decision, arguing that the Pentagon was abusing the CUI designation to avoid public criticism of embarrassing technical and safety failures caused by design deficiencies. As Congressional criticism mounted, the Pentagon finally relented and said it would not use CUI in the future for such reports.
- In December 2024, CUI was used to restrict a routine, typically public audit by the Government Accountability Office of the Missile Defense Agency, which oversees more than 11 billion dollars of funded activities. This use of CUI prevented subsequent press coverage of the audit and the opportunity to critique the report’s CUI-protected findings.
- At one of NPEC’s over-classification workshops, a former government information management senior official noted that there are no fewer than 112 official categories of information where CUI can be applied and 10 different dissemination controls which govern that information’s releasability. Over the last decade, this complexity effectively has doubled the volume of CUI-marked materials. Meanwhile, this injury is compounded by the insult that individual agencies, departments, program offices, and individuals can interpret the rules on how to mark this information for themselves. As of yet, there is no authoritative CUI guide nor is there a clear regulation as to who can make these decisions or how they might be appealed. Bottom line: CUI compounds an already stressed information management system. This will make any hope of automating the classification and declassification process even more distant (For more, see page 7 of this volume, “Overcoming Over-classification,” for this presenter’s written memo. Click here for a recording of the meeting).
- Another NPEC workshop featured an archivist of military history and war games who revealed that the U.S. government is using CUI to make declassified materials and historical documents inaccessible to military analysts and historians. When attempting to view a declassified war game that was originally conducted 50 years ago, the war college that archived the declassified game told her she could not see it as the college had marked it CUI. The war college offered no information as to why they marked the entire game this way. Unfortunately, the appeal process proved to be anything but transparent or straightforward. Her recommendation: make it easier to decontrol CUI information. Perhaps, but this suggestion ultimately recommends not applying CUI for declassified information in the first place (For more, see page 11 of this volume, “Views from the Field: Observations about the Declassification Process and Historical Research,” for this presenter’s written memo. Click here for a recording of the meeting).
- A third NPEC workshop presenter was an advisor to the Central Intelligence Agency and an Ivy League professor of management. He argued that national security classifications make it extremely difficult for small, innovative firms to supply the Pentagon with services and advanced technologies. These smaller firms often lack the high-level clearances and sensitive compartmented information facilities needed legally to contract with the Pentagon. This reduces competition against larger, more established (expensive) defense firms. CUI only compounds this problem (For more, see page 15 of this volume, “Over-classification and Innovation,” for this presenter’s written memo. Click here for a recording of the meeting).
- A fourth NPEC workshop presenter – a former deputy undersecretary of defense for industrial policy – explained how expensive implementing CUI would be. The Defense Department estimated contractors will have to spend some four billion dollars to comply with CUI requirements. This estimate is almost certainly an underestimate. The presenter noted that these costs will simply increase what the Pentagon and public will have to pay. If the rest of the government puts the same level of effort to protect CUI as the Department of Defense is now imposing on defense contractors, he estimated the cost will be, at a minimum, in the tens of billions of dollars each year (For more, see page 20 of this volume, “Controlled Unclassified Information: Its Harmful Effects on Cybersecurity,” for this presenter’s written memo. Click here for a recording of the meeting).
- One NPEC workshop held in October 2024 generated a lively discussion about the ultimate merits of continuing to implement CUI. A former Trump administration senior Pentagon intelligence policy official was skeptical that President Biden would follow through on his promise to issue an executive order updating Obama’s Executive Order 13556 (the order that launched CUI in 2010). In fact, Biden never did issue the promised order. The presenter further noted that if Trump came into office, Trump’s former Director of National Intelligence, John Ratcliffe, would likely demand reconsidering applying CUI to national security matters. (For more, click here for a recording of the meeting).
- A sixth NPEC workshop presenter – a two-decade career open-source intelligence analyst and manager – revealed that, during the Trump administration, U.S. officials weren’t able to share cyber threat intelligence with trusted NATO allies because of CUI designations, more so than any national security classification. This restriction only helped Russia hack into more U.S. systems than otherwise would have been the case (For more, see page 30 of this volume, “Improving the Use of Open-Source Intelligence: Addressing the Challenges of Over-classification,” for this presenter’s written memo. Click here for a recording of the meeting).
- At the last and, perhaps, the most important NPEC workshop, two senior Senate aides explained the key provisions of the Over-classification Reform for Transparency Act of 2024. At the very top of this legislation is a prohibition on withholding information to “1) conceal a violation of law, inefficiency, mismanagement, or administrative error; 2) to prevent embarrassment to a person, organization, or element of the Federal Government; 3) to restrain competition; or 4) to prevent or delay the release of information that does not require protections in the interest of national security.” CUI has arguably already been misused in support of all four of these illicit purposes (For a copy of this legislation, see page 37).
What should be done? The Federal Acquisition Regulation Council just released a proposed uniform CUI regulation that is open for comment through March 17th, 2025. As noted previously, Trump’s former director of National Intelligence, John Ratcliffe, formally opposed implementing CUI restrictions in the first Trump administration in 2020. Only a few months later, Biden’s Air Force Secretary, Frank Kendall, recommended that our government “kill this [CUI] bureaucratic monster before it gets any bigger.” Mr. Kendall just left the government. Mr. Ratcliffe was just sworn in as the new Director of the Central Intelligence Agency.
All of this recommends that the new administration and Congress review the case for continuing to apply CUI for national security matters. Certainly, the case now for continuing to do so is less than weak.
To read the full paper, click here.

