Security to Model: Securing Artificial Intelligence to Strengthen Cybersecurity

US-China Technology CompetitionHomeland Security Subcommittee on Cybersecurity and Infrastructure Protection · 2025-06-12 · 119th Congress
The Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection held this hearing to examine the intersection of artificial intelligence and cybersecurity — both how AI systems themselves can be secured and how AI can improve cyber defense. Begins at 0:16:01
Transcript
Highlights

Title

Securing AI systems while using AI to strengthen cyber defense

Purpose

The Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection held this hearing to examine the intersection of artificial intelligence and cybersecurity — both how AI systems themselves can be secured and how AI can improve cyber defense. Four industry witnesses testified on securing AI models, agentic AI risks, workforce shortages, and federal policy needs, including reactions to a new Trump administration cybersecurity executive order. Begins at0:16:01

Who spoke

Chairman Andrew Garbarino (R-NY)0:16:01: Opened by describing the hearing's purpose to examine AI's dual role in cyber offense and defense0:16:01, warned that phishing attacks have risen nearly 1,200% since generative AI's rise in late 20220:17:31, and raised concern about a "brain drain" as foreign governments recruit top US cyber talent0:18:55; later questioned witnesses on secure-by-design principles0:52:28, data set access1:02:40, and vulnerability disclosure1:06:45.

Mr. Kiran Chinnagangannagari ("Casey"), Securin Inc.0:22:13: Said Securin's research shows AI models with higher reasoning capability are paradoxically more exploitable0:23:52, described Chinese AI models as prioritizing speed while Western models prioritize security0:24:39, and proposed a federal baseline "much like PCI or HIPAA" developed with states0:25:55; later noted an analysis of 15,000 MCP servers found old input-validation vulnerabilities (CWE-20) still common0:53:26 and proposed an FDA-style "label" disclosing an AI model's training data and biases1:03:29.

Mr. Steve Faehl, Microsoft0:27:20: Said Microsoft tracks over 600 nation-state threat actors, double year-over-year, against 600 million daily cyberattacks0:27:20; cited Security Copilot results of a 34% drop in mistakes, 17% fewer breaches, and 30% faster incident resolution0:28:43; gave an example where an AI-led investigation cost $80 versus $640,000 for a human-led one0:29:13; and flagged that OMB M-21-31 data-logging requirements remain unfunded, limiting agency AI adoption0:30:59.

Mr. Gareth Maclachlan, Trellix0:32:27: Said Trellix does not build its own AI models but uses commercial models within secure frameworks0:32:47, warned generative AI is changing attackers' economics by lowering the skill/resource threshold for attacks0:33:18, and said adding generative AI to security operations delivers roughly a tenfold increase in analyst capability1:10:38.

Mr. Jonathan Dambrot, Cranium AI, Inc.0:37:30: Argued security must be built into AI "by design" and monitored continuously across its operational lifecycle0:38:22, warned that compromised autonomous AI agents could conduct cyberattacks "at machine speed"0:40:14, and said Cranium's code-sensor tool found one client's agentic system actually contained 126 models versus the four developers believed they used, plus 300 additional connected technologies1:23:36.

Rep. Clay Higgins (R-LA)0:41:43: Raised concern that private equity firms buying small critical-infrastructure businesses often eliminate cybersecurity contracts post-acquisition0:43:21, asked witnesses about the risk this poses given possible Chinese investor ties0:44:50, and got both Faehl and Chinnagangannagari to agree it constitutes a security risk0:45:500:46:49.

Rep. Nellie Pou / "Miss McIver" (D-NJ)0:47:19: Referenced flight disruptions at Newark Liberty Airport as an example of fragile infrastructure0:48:19 and asked Faehl how critical infrastructure operators can use AI for defense0:48:19, how AI can close the cyber skills gap0:49:39, and what testing Microsoft applies to its AI tools0:51:07.

Rep. Eric Swalwell (D-CA), Ranking Member0:57:27: Asked Dambrot how AI red-teaming (Cranium's "Arena" platform) works and what legal protections researchers need0:57:46; asked Faehl about obstacles to federal AI adoption and Microsoft's approach to quantum computing and post-quantum cryptography0:59:19; later asked witnesses about R&D investment, talent competition with China1:12:57, and at what age children should be introduced to AI1:16:10.

Key moments

Faehl said an AI-led investigation at Microsoft achieved the same result as a human-led one costing $640,000, for just $80 — an 8,000-times increase in throughput0:29:130:29:37.

Faehl said Microsoft's spoof-domain detection using generative AI achieves greater than 99% accuracy for a few dollars a day, versus a previous "multi-million dollar a day whack-a-mole" problem0:30:07.

Rep. Higgins pressed witnesses on private equity firms stripping cybersecurity from acquired small infrastructure businesses before resale; both Faehl and Chinnagangannagari confirmed this is a real security risk, especially where firms have Chinese investment ties0:45:19.

Chinnagangannagari said Securin's research found most AI models can be jailbroken "if you have the patience and will," and an analysis of 15,000 MCP servers found the old CWE-20 input-validation vulnerability still widely present0:53:260:53:55.

Dambrot disclosed that Cranium's code-sensor tool found a client's supposedly four-model agentic system actually used 126 models plus 300 additional connected technologies1:23:36.

Chinnagangannagari proposed an FDA-style label for AI models disclosing training data, ingredients, and bias, comparing it to food/drug labeling1:03:29.

Faehl noted federal agencies' limited adoption of OMB M-21-31 (currently unfunded) is hampering the data logging needed for AI-driven cyber defense0:30:59.

Maclachlan said applying agentic AI to security operations has produced roughly a tenfold increase in customers' security-operations capability1:10:38.

Chinnagangannagari cited a Palo Alto Networks report finding 14% of all data security incidents are caused by generative AI, and called poor access controls the top cause1:11:381:12:08.

All four witnesses agreed the US faces a severe AI/cybersecurity talent shortage — Chinnagangannagari cited roughly 500,000 unfilled cybersecurity jobs before even adding AI-specific gaps1:15:40.

Metadata

CommitteeHomeland Security Subcommittee on Cybersecurity and Infrastructure Protection
Chamber / CongressHouse · 119th Congress
Date2025-06-12
TypeHearing
Witnesses
Mr. Kiran Chinnagangannagari — Co-Founder and Chief Product & Technology Officer, Securin Inc.
Mr. Steve Faehl — U.S. Government Security Leader, Microsoft
Mr. Gareth Maclachlan — Chief Product Officer, Trellix
Mr. Jonathan Dambrot — Chief Executive Officer, Cranium AI, Inc.
Videoyoutube
Transcript159 caption blocks · 12,527 words · 1:28:07 runtime
EventCongress.gov 118340