▶ 0:18:58Homeland Security. The subcommittee on cyber security infrastructure protection will come to order. Without objection, the chair may declare the committee in recess at any point. Today's hearing will examine how artificial intelligence is changing cyber security in real time and what that means for the resilience of America's critical infrastructure.
▶ 0:19:17We will discuss advanced frontier model models capable of discovering software flaws, agentic AI systems that can operate across digital environments and AI coding tools that are rapidly changing how software is built and secured. We'll also consider recent federal action on AI innovation and security as well as national security risks posed by PRC's openweight AI strategy ad adversarial distillation and the spread of Chinese a AI models on into American developer tools and enterprise systems.
▶ 0:19:48I now recognize myself for five minutes for an opening Good morning and thank you all for being here today. We're examining how artificial intelligence is changing the foundations of cyber security and the security of our critical infrastructure. This committee has taken these threats and risks seriously for months. We have held roundt tables, hearings, and briefings with the leading AI laboratories and cyber companies in the country.
▶ 0:20:15And we have opened a joint investigation with the select committee on China into the proliferation of Chinese AI models. On Tuesday, President Trump signed an executive order directing the secretaries of the Treasury, Homeland Security, and War to develop a classified benchmarking process for advancing AI cyber capabilities, and to design a volunteer framework for early government access to cover frontier models. The president is right to act.
▶ 0:20:42These models are already reshaping the threat landscape, and the federal government cannot be the last to understand what they can do. I want to be clear that this subcommittee intends to watch closely how SISA carries out its responsibilities under that framework. SISA has a statutory authority under the cyber security information sharing act of 2015 operates the known exploited vulnerabilities catalog and serves as the lead civilian agency for critical infrastructure cyber security.
▶ 0:21:09how SISA fulfills its role under this order, especially in translating early model access into practical guidance and vulner vulnerability remediation for critical infrastructure operators will be a central oversight question for this subcommittee in the months ahead. To understand why that matters, consider that these models can now do until recently finding a serious serious unknown flaw is widely used software took skilled researchers months of painstaking work.
▶ 0:21:37Frontier AI models are collapsing that timeline. We now have models that can discover and exploit previously unknown vulnerabilities on their own at machine speed across the systems that run nearly everything in our economy. The most advanced of these models was judged too dangerous to release publicly. So it was shared with roughly 50 large companies to help them find and fix flaws before our adversaries could. In the right hands, this is a powerful defensive advantage. In the wrong hands, it is a weapon.
▶ 0:22:06Imagine a Chinese state cyber actor, the kind already burring into our power grid and our water systems, armed with a model that finds and exploits unknown flaws faster than any human team alive. The danger does not stop at cyber attacks. The same models that hunt for software flaws can, without the right safeguards, help a bad actor work through the hardest steps of building a biological weapon. Our leading laboratories building in guardrails to release to refuse that kind of help.
▶ 0:22:35But when a foreign adversary copies an American model, strips out those safeguards, and releases it to the world, those pro protections and protocols vanish, we could find we have handed the most dangerous knowledge on earth to the people most determined to use it. But the safety switches turned off. There's a second front that deserves the same attention. United States leads the world in the most advanced frontier models and those models are largely closed, proprietary and expensive.
▶ 0:23:05China has taken the opposite path. Chinese labs are releasing openweight models that can anyone can download for free that run at a fraction of the cost and that are now good enough for most of what an ordinary developer or business needs to do. Here is what concerns me. When the cheap, capable, easy option for an AI model is chi Chinese, the rest of the world will build on it. Developers and companies in the United States, Europe, South America, Asia, and across Africa are making that choice right now.
▶ 0:23:36If we do nothing, Chinese models become the default foundation of the global digital economy, carrying embedded censorship, uncertain security, and capabilities distilled from our own laboratories. with his safety guardrails stripped out. We can we cannot let the world grow dependent on Chinese AI the way it grew dependent on other Chinese technologies we are now scrambling to address.
▶ 0:23:59The United States needs a serious strategy to ensure capable American models especially open weight models that developers, companies and governments can deploy and adapt are real and that are are a real alternative. Finally, I want to name the the issue practitioners care about because because getting them right is how we secure the country.
▶ 0:24:20More of our software is now written by AI faster than human reviewers can keep up, which makes security by design practices, where security is built in from the first line of code more important than ever. It makes AI coding tools a real concern when those tools are built on foreign models we cannot fully vet. And it makes a aentic AI software that plans and acts on its own across our networks. and an an entirely new attack surface our defenses were never built to with withstand.
▶ 0:24:47These are real issues with real consequences and they deserve a serious bipartisan response. I look forward to a substantive hearing and I thank our witnesses for being here. When Miss Ramirez arrives, uh we'll recognize her. Um other members of the committee reminded that opening statements may be submitted for the record. I am pleased to have a distinguished panel of witnesses before us today on this important topic.
▶ 0:25:16Pursuant to rule committee committee rule 8C, I I ask that our witnesses please rise and raise their right hands. [snorts] You solemnly swear that the testimony you will give before the committee on homeland security of the United States House of Representatives will be the truth, the whole truth, and nothing but the truth. So help you God. Let the record reflect that the witnesses have answered in the affir affirmative. Thank you and please be se seated. I would like to formally introduce our witnesses.
▶ 0:25:46Miss Sandra Joyce is the vice president of Google threat intelligence where she helps lead one of the world's most capable teams tracking nation state criminal and emerging cyber threats. She previously served in senior leadership at Mandant before its acquisition by Google bring and brings more than 27 years of intelligence experience and is a US Air Force reserve officer. Thank you for your service me. Dr.
▶ 0:26:10Chris Mezero is executive director of Frontier Model Forum an industry supported nonprofit founded by leading frontier AI companies to advance the safe and secure development of advanced AI models. His work focuses on AI safety, evaluations, standards, and information sharing among industry, government, academia, and civil society. Thank you, sir. Mr.
▶ 0:26:35Jack Cable is the chief executive officer and co-founder of Corridor Security, Inc., an AI powered software security company focused on secure AI coding and secure by design development. Corridor's platform helps identify vulner as code is being written whether by human develop developers or AI coding tools. Mr.
▶ 0:26:58Cable previously served as a senior technical adviser at SISA where he helped lead the agency secure by design initiative and he also worked at the cribs stamos group and the Pentagon's defense digital service. Thank you sir. Mr.
▶ 0:27:17is a senior policy analyst at the Electronic Frontier Foundation where he work where his work focuses on surveillance policy uh policing civil liberties and government use of technology at the local, state and federal levels. I want to thank you all again for being here. I now recognize Miss Joyce for five minutes to summarize her opening statement. M Joyce,
▶ 0:27:40thank you chairman Ogals Garberino. breaking members Thompson Ramirez and members of the committee and subcommittees. Thank you for inviting me to speak to you today. My name is Sandra Joyce and I serve as vice president of Google Threat Intelligence Group. Our team defends Google, our users, and our customers by building the most complete threat picture to disrupt adversaries. We appreciate the opportunity to participate in this important conversation. As this committee knows, we stand at a critical technological inflection point.
▶ 0:28:10Rapid advances in artificial intelligence are unlocking new possibilities for the way we work and accelerating innovation in science, technology and beyond. This technology has impacted cyber security in profound ways for both the defender and the attack. For years, Google has been successfully using AI defensively to find and mitigate vulnerabilities and the code we all rely on.
▶ 0:28:34But we have also anticipated that thread actors would have used this technology to find and exploit vulnerabilities for malicious purposes. Those concerns were validated recently when we discovered evidence for the first time that AI was used to develop a zeroday exploit by cyber criminals. We expect thread actors to continue using or attempting to use this technology to their advantage. We are particularly concerned about two future scenarios.
▶ 0:29:02First, though AI will be used by defenders to harden software and produce safer code, adversaries may have the initiative in the short term to find and exploit vulnerabilities at scale. We are working to integrate AI directly into the development cycle and make code exploitation more difficult than ever. Nonetheless, the transition period will pose challenges. As we harden existing software with AI, thread actors will simultaneously use it to discover and exploit novel vulnerabilities.
▶ 0:29:32In addition, Agentic orchestration will allow thread actors to cheaply scale their operations and operate at unprecedented speed to take advantage of slow patch cycles, belleaguered security teams, and human response time. Thread actors are able to move rapidly before and after gaining access to a network using AI. They can take advantage of vulnerabilities faster than we can patch and they can move rapidly through networks using autonomous agents.
▶ 0:29:59To effectively tilt the cyber security balance in favor of defenders, we must close the exploit window. Historically, patch management has been a retroactive human-paced race against adversaries. In the current threat landscape, where attackers use AI to discover and target design flaws at scale, traditional siloed security tools fail to keep pace for critical infrastructure operators and public sector networks.
▶ 0:30:26Defense at scale requires an automated mechanism that shifts focus away from mere bug hunting and toward comprehensive environmental exposure management. To address this collapse of the exploitation timeline, Google has pioneered always on four-step framework designed to help enterprises to implement an autonomous defensive control loop. Prepare, scan, and prioritize, remediate, and monitor.
▶ 0:30:55Our aim is to shift the industry away from reactive response and toward active prediction and accelerated remediation. We believe our approach to the frontier of artificial intelligence must be bold and responsible. This means developing and deploying technology in a way that maximizes positive societal benefits while proactively engineering systems to withstand and mitigate modern adversarial pressures. For more than 20 years, Google has pioneered a secure by design approach.
▶ 0:31:26Meaning we embed security into every phase of the software development life cycle, not just the beginning and the end. Google's software and AI development pipelines rely on advanced threat modeling to proactively identify emerging threat trends and systemic risks and to explicitly design our products for inherent safety.
▶ 0:31:46Rather than treating safety and security as an afterthought, we continuously enhance our safeguards inside our products to offer scaled adaptive protections to enterprise users and critical infrastructure operators across the globe. Cyber security has never been an environment where absolute perfection is possible. It will remain a fiercely contested, highly dynamic domain for years to come, demanding continuous innovation, speed, and structural agility to defeat adaptive adversaries.
▶ 0:32:17As this committee looks to secure our homeland and fortify the digital architecture supporting American critical infrastructure, Google stands ready to serve as a committed transparent partner. By combining public sector authority with private sector technological innovation, we can harness the immense potential of artificial intelligence to skip tip the scales of cyber security permanently in favor of defenders. Thank you for the opportunity to testify today. I look forward to answering your questions.
▶ 0:32:50summarize his opening statement and if we could move your mics um so that the it picks up properly. Miss Joyce, move your mic forward just a little bit. Thank you so much,
▶ 0:33:07Chairman Ogles, Ranking Member Ramirez, distinguished members of the subcommittee. Thank you for the opportunity to testify today on the AI security landscape. I serve as executive director of the Frontier Model Forum, an industry supported nonprofit whose mission is to advance Frontier AI safety and security.
▶ 0:33:24Since our founding, we have worked with our six member firms, Anthropic, Amazon, Google, Meta, Microsoft, and OpenAI to develop the security practices, scientific research, and information sharing channels we need to responsibly manage the potential large-scale risk to public safety and security from Frontier AI.
▶ 0:33:44My aim this morning is not to advocate for particular policies, but to help inform your discussion of the security challenges and opportunities presented by the most advanced cyber capabilities of the latest AI models and agents. My comments will touch on three key issues. The trajectory of Frontier AI capabilities, the potential risks associated with them, and how we can manage those risks effectively. Let me start with the trajectory of advanced AI.
▶ 0:34:11As impressive as the cyber capabilities of the latest frontier models are, they do not represent a sudden or discontinuous jump. The ability of today's models to autonomously identify and exploit vulnerabilities is clearly in line with empirical forecasts from over a year ago. I say this not to downplay those capabilities, but to underscore that they should not have come as a surprise.
▶ 0:34:33If the most recent models caught us off guard, that should serve as a wake-up call to strengthen our public private partnerships and information sharing channels on which I'll share more in a moment. The second issue I'd like to touch on concerns the security challenges posed by frontier capabilities. While the most advanced models hold enormous promise for strengthening the resilience of our cyber security and critical infrastructure, they also pose credible threats.
▶ 0:34:59An agent that finds zeroday vulnerabilities can protect us in the hands of a defender but expose us in the hands of an attacker. And the attackers are real. State linked actors have already used advanced agents across the attack life cycle and less sophisticated criminals are now using AI to generate and sell ransomware.
▶ 0:35:19This is especially concerning for small underresourced operators in critical sectors like water, healthcare, and local government where targets that may not have been worth an attacker's time before now may well be. Significantly, all of those threats are compounded by adversarial distillation. For those unfamiliar with the term, distillation is a method for training an AI model on the outputs of a larger, more capable model and has many legitimate and beneficial use cases.
▶ 0:35:49But when carried out at industrial scale and outside a developer's terms of service, distillation amplifies the security challenges of frontier AI because it transfers the advanced capabilities of a model but without any safeguards attached. Foreign actors can use distillation to accelerate their own AI development and leverage the capabilities they gain against US critical infrastructure.
▶ 0:36:15And when adversarial adversarially distilled models are made widely available, malicious actors of every kind can exploit advanced cyber capabilities with relevant security mitigation stripped away. Any serious effort to secure US critical infrastructure must address adversarial The good news here and this is the main the third main issue I'd like to touch on uh is that we have a strong foundation for managing all of these threats. Let me highlight several areas in particular.
▶ 0:36:45First, as I noted earlier, frontier models hold enormous potential for cyber defense. Since cyber capabilities are dual use, the same agents that find vulnerabilities for attackers can find and patch them for defenders. Thankfully, leading developers have already begun putting these tools in the hands of trusted defenders and critical infrastructure Second, there are many existing information sharing channels we can leverage.
▶ 0:37:09Leading developers have already have bilateral information sharing agreements with government agencies while the FMF maintains a multilateral information sharing mechanism among industry. All of that is in addition to the ISACs ISOWS and sector coordinating councils that already exist. We should strengthen and build on these mechanisms where we can including through clearer guidance on antitrust and export controls. Third, we should build on established practices and standards.
▶ 0:37:37Securing frontier AI doesn't require starting over. Foundational controls like red teaming, access controls, and continuous monitoring still apply, but we do need to update and adapt those practices, which is why efforts like the NIS AI agent initiative are so welcome. Finally, we also need to redouble existing investments in AI measurement and metrology. Many cyber benchmarks are nearing saturation. So developing the next generation of evaluations and technical safeguards.
▶ 0:38:04Work the Casey and others including the FMF are already pursuing will be essential. By leveraging AI for defense, strengthening existing information sharing channels, updating and adapting cyber security practices, and investing in better measurement, we can meaningfully improve our resilience. Thank you for the opportunity to speak today, and I look forward to your questions.
▶ 0:38:24Thank you, Dr. Mesro. I now recognize Mr. Cable for five minutes to summarize his opening statement.
▶ 0:38:30Chairman Ogles, Ranking Member Ramirez, and distinguished members of the committee. Thank you for the opportunity to testify today. I am the CEO and co-founder of Corridor, where our mission is to prevent a new wave of vulnerabilities by securing AI coding. Before this, I helped build the secure by design initiative at CISA and was a topranked ethical hacker. We're living in a time of profound change in cyber security. Coding agents, not human engineers, are writing our code and growing more autonomous every day.
▶ 0:39:00They produce code at unprecedented rates and without guardrails will introduce more vulnerabilities than ever. At the same time, frontier models like Mythos are increasingly capable of finding and exploiting vulnerabilities. Though, as Enthropic's own data shows, their ability to find flaws has far outpaced the ability to fix them. Before I talk about what's changing, let me note what's staying the same. Attackers generally aren't exploiting new kinds of vulnerabilities.
▶ 0:39:29They're exploiting the same old flaws we've known about for decades. Even mythos is surfacing issues like buffer overflows first discovered in 1972. Similarly, long-standing defense mechanisms still matter. The case we built at CISA around secure by design is more relevant than ever. Rewriting critical code in newer memory safe languages will will yield dividends for years to come. The central challenge is not that AI creates new categories of vulnerabilities.
▶ 0:39:59It's that AI dramatically increases the speed and scale at which vulnerabilities can be introduced, found, and exploited. Our response must shift from patching individual bugs to preventing entire classes of vulnerabilities at the source. Today, I'll make three key points. First, hackers have more powerful tools than ever. Mythos and GPT55 are just the latest iteration of models that can run robust end-to-end exploited chains. These models aren't just hype.
▶ 0:40:28They are truly starting to rival or exceed humans on security tasks and do so at an unprecedented scale. We won't be able to patch our way out of this. Of the 1500 vulnerabilities Enthropic has disclosed via Mythos, only 6% of them have been fixed. Instead, we must get ahead of vulnerabilities at the source by shifting to prevention and widescale remediation. This is especially acute for open source software.
▶ 0:40:54It underpins every software service we rely upon, yet as a public good will be hit the hardest. Second, as AI is the dominant code writer today, with scale comes more vulnerabilities. The most productive engineers no longer write code. They instruct fleets of AI agents to do so. Today, you can start a coding agent from your phone, and it will produce a significant code change while you eat lunch.
▶ 0:41:18GitHub reports 14 times more code committed in 2026 than 2025, Google says 75% of its new code is AI generated. At Corridor, agents write the vast majority of our code. While coding agents write more secure code per line than humans, they still often introduce vulnerabilities, and those scale with volume. Academic benchmarks find that even the best models introduce vulnerabilities roughly a third of the time.
▶ 0:41:43Our own data shows 13% of agent generated code changes have Between AI empowering adversaries and coding agents writing more code than ever, we're stuck between a rock and a hard place. To prevent the bug apocalypse, we need a new path forward. Third, the good news is that properly guided AI coding offers a more secure future. At Corridor, we find that coding agents follow security instructions better than most humans.
▶ 0:42:10Across our customers, giving the coding agent the right context at the planning stage reduces vulnerabilities by 60%. For existing code, frontier models can accelerate security refactors that once cost millions of dollars and years of efforts, now achievable for thousands of dollars in weeks. Initiatives like DARPA's tractor program translating unsafe code into memory safe languages are exactly the right investment. Let me close with my recommendations.
▶ 0:42:38One, prevent vulnerabilities in new code. The highest leverage step is to stop entire classes of vulnerabilities at the point of code generation. Congress should enable AI coding among the federal government and its contractors while requiring security guardrails that prevent these vulnerabilities upfront. Two, harden the open-source software foundation.
▶ 0:42:59Rather than one-off fixes, Congress should fund a multi-billion dollar nonprofit initiative for large-scale security oriented refactors and maintenance of critical open-source components. I also encourage the committee to bolster CISA's capabilities to partner with the open source ecosystem by passing the securing open-source software act. Three, maintain America's lead through open wake models.
▶ 0:43:22A thriving AI industry demands both the cutting edge performance of closed weight models and the lowcost and flexibility of openw weight models. Today there are no frontier openw weightight models from the United States. The US government should fund and support the development of open weight models and we should keep allowing US businesses to access frontier models. Restricting access only sets us back. Thank you for the opportunity to testify today. I look forward to your questions.
▶ 0:43:53Thank you, Mr. Cable. And now recognize Dr. Goriglia for five minutes to summarize his opening statement.
▶ 0:44:00Chair Ogles, Chair Ogul, Ranking Member Ramirez, members of the committee. Thank you for the opportunity to speak today. My name is Dr. Matthew Griglia and I'm a senior policy analyst at the Electronic Frontier Foundation. The Electronic Frontier Foundation is a nonprofit organization dedicated to protecting privacy, innovation, and free expression in the digital world. For 35 years, EFF has represented the users of technology both in court and in policy debates to ensure that law, technology, and support our civil liberties.
▶ 0:44:30Today, I am urging caution on the use of artificial intelligence in the national security and cyber security arenas. AI can be an incredible tool for cyber security, but without proper guardrails in place, it can amplify threats to civil liberties and make us less safe. I urge the committee to consider narrowly tailored regulation that promotes transparency and accountability while protecting innovation.
▶ 0:44:52Guardrails are especially important because the national security state already has tools that can aggregate and infer sensitive information about individuals without pre-existing probable cause. We're talking about making inferences about a person's politics, personal life, religion, and geoloccation, sometimes inaccurately with major consequences. Before there was a smartphone in every pocket, our privacy relied in large part on the practical cost of surveillance. You couldn't watch all people all the time.
▶ 0:45:22It took effort. It took hundreds of employees. It even took airline hangers to store all of the physical files. AI combined with the exponential growth of electronic surveillance tools has totally upended this. Thanks to those tools, AI's increased capacity can expose every American to granular levels of surveillance with a click of a button.
▶ 0:45:40This departure from the prior default, which is individualized surveillance based on individualized suspicion, poses a major threat to civil liberties and one that Congress and the courts have yet to address in any meaningful privacy preserving way. AI also has a track record of getting things wrong. from false citations on legal briefs to a major AI mistake that sent DHS recruits to the field without proper training. There are likely more consequential examples that we don't even know about because of classification that would prevent a more thorough accounting.
▶ 0:46:11There are however solutions to threats posed by irresponsibly deployed AI. The first is to answer the urgent need for transparency within the military or the intelligence community in which AI would be deployed. And the second is a general reduction of the amount of warrantless data collected by taking actions like reforming section 702 of FISA or closing the data broker loophole. For decades, the national security apparatus has been overburdened by impenetrable layers of classification.
▶ 0:46:38Secrecy would prevent the public from knowing about or seeking accountability when AI hallucinates or makes vital mistakes in the national security or cyber security spaces. Hidden by the secrecy is the practice of zeroday hoarding where government deployed AI might find vulnerabilities in critical infrastructure but that information is withheld from affected parties in attempt to preserve future opportunities for surveillance.
▶ 0:47:00This has already happened a number of times where NSA discovered vulnerabilities like eternal blue were exploited by bad actors and foreign nation states. I will end by noting that we should be concerned about the way the executive branch's current posture toward AI not only jeopardizes civil liberties but the cyber security and resilience of our critical infrastructure.
▶ 0:47:20The government has insisted that the technology it procures be made available for use as a mass surveillance tool despite companies internal ethical commitments and the best use guidelines for their products. When a company does not comply, they have been labeled supply chain risk. But making companies enablers of civil liberties violations will eventually make them reluctant to sell cutting edge tools that we need for maintaining digital infrastructure.
▶ 0:47:45Even the White House's brand new executive order, while it does direct resources to cyber security, does not ensure that its early access to frontier models will not be used to hoard and exploit vulnerabilities. It also creates a tiered regime where some companies in good standing with the administration could be granted cutting edge cyber security tools while others are re reg relegated to susceptibility. The lesson here is that government must not let political whims stifle technological progress for the public good.
▶ 0:48:15One of EFF's core values is the belief that technology can create a safer and more just world. AI holds immense promise in many areas, but it is up to Congress to step in and provide necessary and balanced regulations. Thank you again for the opportunity to speak today, and I look forward to your
▶ 0:48:33Thank you, Dr. Griglia. I now recognize the ranking member for five minutes for her opening remarks.
▶ 0:48:41Thank you, Chairman. Well, first, I want to thank our witnesses for being here today. Today's hearing about the security concerns raised by artificial intelligence comes at a very important moment. Artificial intelligence development is speeding ahead with nearly no standards, rules, or regulations for how powerful AI tools will be responsibly used. It does not seem to be a point of debate that we should do something about that. It's actually why we're here today.
▶ 0:49:08The advent of new models like entropics mythos has moved even the president to admit that there are security risks associated with artificial intelligence that the federal government has a role to address them. But as you might expect, I take issue with the most recent executive order on artificial Now, I rarely look to the Vatican for a policy inspiration, but when Pope Leo himself publishes a 200page encyclical calling for AI regulation in warning that data
▶ 0:49:38cannot be left in private hands and that is a more comprehensive AI policy than was coming out of the White House, well, I think we should be concerned. In contrast to the EO, uh the previous presidential executive order on AI noted that AI makes it easier to extract, reidentify, link, infer, and act on sensitive information about people's identities, locations, habits, and even desires.
▶ 0:50:04Bottom line, AI makes it easier to surveil, target, and violate our rights and privacy. And the executive order that was just recently issued is silent on how to mitigate those risks and protect the public's right to privacy. Am I shocked? No. The administration has already demonstrated it will use every tool available to find, track, and deport immigrants and those who defend their rights.
▶ 0:50:27In my own district, DHS has used AI powered facial recognition, software, and predictive tools to target, intimidate immigrants, and rapid responders alike. And now we're watching AI powered monitoring systems spread to schools, to public housing, to hospitals with no transparency about how they work, no ability to challenge them, and no recourse when they're wrong. So I'm clear that we cannot settle for unregulated, unaccountable AI. There's got to be rules.
▶ 0:50:57There's got to be limits. And it's our responsibility to ensure oversight. We have to set standards for AI's responsible use. move fast and break things is not an acceptable innovation strategy when things being broken are people's lives, their rights, their privacy, and their safety. Fortunately, states across the country, including my home state of Illinois, are leading the way.
▶ 0:51:21Just recently, last week, lawmakers in Illinois sent SP 315, the strongest AI bill in the country, to the governor's desk. Among other things, the bill requires Frontier AI developers to have their safety practices audited by a third party, a major and much needed check on AI companies.
▶ 0:51:40The effort builds on laws already enacted in states like New York and California that require AI labs to provide information about guardrails to ensure the safety of their models and to publish reports on any safety incidents. Bottom line, at the federal level, we have to one, enforce the laws we already have, civil rights, privacy, and consumer protection. Two, we have to define clear rules and guard rails with real consequences that companies are statutory required to abide by.
▶ 0:52:10No voluntary pledges as we've seen. Three, make companies prove their systems are safe before release at every step. Because the burden of proof should not be on the companies, not the burden of proof should be on the companies, not the consumer, and certainly not the public. So until the federal government can do that work and demonstrate it will develop AI policies that prioritize the well-being of the people over the profits of AI companies, Congress must not undermine state laws that ensure responsible AI.
▶ 0:52:40I want to know as we go through our questions today, we might have I think more than one round. You know what you are doing right now to make sure that AI technology will not become another instrument of surveillance, exploitation or control dressed up in language of progress and national security. We've already endured those who would ask us to sacrifice our rights and liberties to secure our safety. We're done with the false choice.
▶ 0:53:05uh we think that we could regulate AI and actually benefit from the advancements and progress that it brings but we have to ensure that we do our own work and the oversight necessary with that chairman I yield back so that we can start the questions.
▶ 0:53:19Thank you ranking member Ramirez. Members will be recognized by order of seniority for their five minutes of questions. I now recognize myself for five minutes. President Trump's executive order directs CISA to facilitate access to cyber security tools and services including where appropriate covered frontier models for agencies, state and local authorities uh and crit critical infrastructure operators such as rural hospitals, community banks, and local utilities.
▶ 0:53:48That could be a major opportunity to get better tools into the hands of the defenders who need the most. At the same time, many smaller organizations still struggle with basic cyber hygiene, patch management, asset inventory, identity security, and limited staffing. How should this work in practice? What basic foundations need to be in place so advanced AI enabled cyber security tools help these organizations reduce real risk instead of creating more alerts, more confusion or more unmanaged responsibility?
▶ 0:54:19Miss
▶ 0:54:22thank you so much for the question and we are want to um a compliment and the administration for uh really leading the way on the executive order. We have just received it. We're still looking at how we're going to be implementing it. We're looking at the details.
▶ 0:54:43But one thing we have often said is that we do believe that AI needs to be regulated and in we also think it's too important to not be regulated and it's too important not to be regulated well. So when we look at critical infrastructure and those individuals who are on the front lines of providing services to day-to-day uh you know water, electricity, we think it's really important that we are able to support them with cyber security uh that they need.
▶ 0:55:13One of the ways that we think that can happen is through cyber security grants um that are going to be able to provide the knowhow and the funding. No frontline defender in critical infrastructure should be left to their own devices to go toe-to-toe with nation states and cyber criminals. So we look forward to being a good partner in this and we look forward to being supportive of American leadership in this space.
▶ 0:55:39Mr. Cable, would you like to also
▶ 0:55:42Yes, thank you chairman for the question. The good and bad news is that so much of security is lowhanging fruit and you do not need frontier models to address that. If we look at the state and local governments, critical infrastructure owners and operators out there today, as you mentioned, there are many basic vulnerabilities that are on their networks that are open to exploitation from our adversaries.
▶ 0:56:06For instance, we continue to see a string of um exploitation of network edge devices um by foreign adversaries. And ultimately, what many of these issues come down to is vulnerabilities in underlying software products in use by these entities. And my response to that is that these entities who produce these products in line with um secure by design ought to be doing more to deploy frontier models um in order to shore up the security of their products.
▶ 0:56:34And as I mentioned my opening statement in particular to do these largecale refactors needed in order to root out these entire classes of vulnerabilities uh from their products. We called this at CISA secure by demand by which critical infrastructure owners and operators consumers of technology products could do more to put pressure on software vendors. I believe Congress has a role there as well and this also underscores the passage of the the pillar act in order to give necessary resources to uh state and local
▶ 0:57:06You know, this is just kind of a a general thought. You know that when you when you think about a regulatory framework for AI, how do we regulate AI in such a way to protect the consumer, the public, but yet not hinder ourselves against this arms race that essentially is against China? Miss Joyce,
▶ 0:57:26I think that's the the work of today and the work of our generation right now. It's so important that we get this right and this technology is so important to regulate in a way that's going to balance the safety and security of the models and of the users that are using them, but also is going to support American leadership in this space.
▶ 0:57:46What we're seeing in my role as the threat intelligence lead at Google, we are seeing every day how threat actors are attempting to abuse the AI models in order to carry out their schemes. And we publish very regularly in an attempt to be transparent the threats that we're seeing in our quarterly AI threat tracker.
▶ 0:58:06For example, we recently published how threat actors are doing everything from a prompt injection to trying to manipulate um and and to create exploits using AI. And so we can see that the threat landscape is rapidly evolving and we need to be able to meet the moment in that while balancing uh safety and security with bold and responsible regulation.
▶ 0:58:34Thank you, ma'am. Uh I now recognize the ranking member, the gentleoman from Illinois, Miss Ramirez, for her five minutes of questions.
▶ 0:58:41Thank you, Chairman. Dr. Gore, can you pronounce your last name again?
▶ 0:58:48Goriglia. Corlia. Did I get it right?
▶ 0:58:51Good. Good. You did an exceptional job, chairman. Um,
▶ 0:58:54I had notes.
▶ 0:58:56Even with mine, I still struggled here. Your work documents how the government's expansion of data collection surveillance capacity has justified repeatedly as a security or public safety necessity has consistently been turned against the most marginalized communities.
▶ 0:59:11My question to you is when we talk about building resilience in critical infrastructure through AI powered monitoring and threat detection, how do we ensure that the architecture we're building in the name of protection doesn't become the next iteration of that same pattern?
▶ 0:59:28Yeah, I data cap the storage the capacity to store data and to analyze data is infrastructure. It it by definition has multiple purposes. um it can be used for uh building critical uh resilience in critical infrastructure or it could also be used for compute power for surveillance.
▶ 0:59:47I think one of the things we've been thinking about is specifically narrowly ter tailoring the types of models that we deploy specifically for cyber security so that they are less general p purpose models that can be redeployed in other purposes for surveillance.
▶ 1:00:04Uh so I think uh thinking about uh how to tailor both digital infrastructure and AI models so that they serve one purpose without very easily being uh co-opted by DHS or other agencies for the purposes of surveillance and policing.
▶ 1:00:23And you've written that America's privacy is currently being decided by contract negotiations between tech companies in the White House, not by Congress. We're watching that play out in life between the Pentagon and Anthropic right now. So, I guess my follow-up question to you is what does Congress need to do to put in statue so that civil liberties protection doesn't depend on morality of billionaire CEOs?
▶ 1:00:48Yeah. I mean, at this level, the question is not how do we reign in AI, it's how do we reign in the agencies that would unleash AI on the American public. Um, so with the anthropic deal, what we have is a a contract negotiation uh in which one party does not want to do mass surveillance against Americans or claims not to and the other party is insisting that their technology, their multiple purpose technology be made available to them for exactly that purpose.
▶ 1:01:18And absent in that is Congress saying what the rules should be for how the government can deploy technology against Americans. So things like uh as I said um closing the data broker loophole uh reforming section 702 of FISA longstanding issues of American privacy and the America the government's ability to collect data need to be addressed first so that when AI is deployed it does not drastically amplify those civil liberties violations.
▶ 1:01:46Thank you. Well let me ask you one last question and I I'll give you a little bit more time.
▶ 1:01:51We probably will have another round
▶ 1:01:52Okay. So, we're hearing a lot about Agentic AI, the systems that can detect and respond to threats on their own without waiting for a human to approve each decision. You've written about how technology vendors, so governments on tools before anyone has actually even figured out what happens when something goes wrong. So, I want to ask you if a autonomous AI system managing the cyber security of a city's water infrastructure makes a bad call.
▶ 1:02:22flag is a clean system as compromise, shuts down access, causes an operational failure. Who is responsible under current law?
▶ 1:02:33I I don't know who's responsible under current law.
▶ 1:02:37And and I think part of the problem that we have is this transparency piece is that when one something goes along like like that, how does the public find out about it? Where does the accounting come from? I would, I imagine, have to rely on the transparency of the city because the proprietary models and the corporations are not going to be forthcoming with the American public.
▶ 1:02:59And this is made exponentially worse once you take it out of the municipal level and you get to the federal government where the national security has its own history of very impenetrable
▶ 1:03:09So you're hoping for transparency of the city, but that doesn't actually get to the accountability of who ends up being responsible. Guess the last question and see if you have any answer to on this is if the community is harmed as a result of this and has limited resources to demand the accountability, what realistic recourse would they even have?
▶ 1:03:29I'm not sure.
▶ 1:03:30Yeah, that's what I figured. Well, chairman, uh, I have another question we can do next round, but I'll yield back.
▶ 1:03:36The gentleoman yields back. I now recognize the gentleman from uh, California, Mr. F.
▶ 1:03:42Uh, thank you, Mr. Chairman. I want to thank the witnesses for being here. uh certainly a very important uh topic with everything going on right now um in the cyber security space. My first question I wanted to pose to Mr. Cable um you know I had the I I chairman Garbrino my district we pulled together a round table um with schools, hospitals, energy providers, water districts. I represent urban centers and rural communities as well.
▶ 1:04:06Um, and then I I I read that the time from a from a breach to an escalation is probably now mere seconds. And so our cyber security defenders have to meet these machine speed attacks with machine speed defenses. So a company like yours probably could take thousands of AI generated vulnerability findings and turn them into patches pretty quickly.
▶ 1:04:32um but a rural hospital, a small utility, a county government, a water district, um they may see the same list and may not have a realistic way to keeping up. So, how do you propose or what's what advice do you have in terms of how do we prevent Frontier AI from creating a world where companies can get uh patches but smaller critical infrastructure operators may fall
▶ 1:04:56Thank you, Congressman, for the question. In order to get ahead of these issues, I I think about in two ways, right? We have to both uh shift further right up the attack chain to deploy AI in order to better detect attacks, better defend systems while also shifting further left right into the very ways in which software products are being built to make them fundamentally more resilient.
▶ 1:05:18Our focus at corridor is on the latter at working with manufacturers of technology products to help them identify and prevent vulnerabilities in the development cycle. And we are seeing by doing that we can prevent vulnerabilities before they make it out into deployed products that are used by any consumers of software such as critical infrastructure owners and operators.
▶ 1:05:40But I think that there is also right this need for an increased focus to give these defenders who are increasingly both underresourced and also subject to attackers who have more and more capabilities at their hand.
▶ 1:05:53we really do need to foundationally shore up the security of these systems both in the short term through deploying AI capabilities that can prevent detect cyber attacks but then in the long term by making sure that the products that they rely on are fundamentally more secure and I wanted to probably pose the same question to you Miss Joyce uh the the chairman uh Mr. Ogles and I have talked about this. I have military installations in rural communities out in remote areas for a reason.
▶ 1:06:20And so a cyber attack that affects the water supplier, the electricity grid not only impacts the community but of course um our national security as well. And so I wanted to maybe pose the same question but then also add a second question which is um you know in terms of the integrity of our AI systems that is of course becoming a national security issue.
▶ 1:06:41uh if our adversaries can manipulate the models, poison data, uh abuse AI tools for cyber operations and undermine the trust in AI generated outputs that certainly um those risks extend well beyond one company. So how do how does your work um how do you work to secure the integrity of AI systems to advance our national security and what should Congress do to understand the connection between model security, infrastructure security and American technology leadership?
▶ 1:07:10Thank you so much for that important question and from a threat intelligence perspective I can say that it is truly important to look at this. We have already seen Russia, China, Iran and North Korea in some cases trying to or succeeding in embedding themselves in our critical infrastructure. So we know that this threat is happening as we sit here today. We are looking at how these threat actors are embedding themselves.
▶ 1:07:37groups from China called F Vol Volt Typhoon for example have already demonstrated capability and intent in this space. In my role at Google, what we're doing is actually looking at our Gemini model. We have embedded inside of Google Deep Mind personnel so that we can be on the front lines and looking at the threats as they come in.
▶ 1:07:58When we find and get in gain insights that we think will be helpful for defenders, particularly the ones who are in critical infrastructure, we publish those. We attempt to be very transparent about it. And so, as I said, you can look at our AI threat tracker that we have been publishing every quarter. We have years of AI threat reporting that we have done publicly to ensure that we're putting the these insights out and to those who need to use them. Uh, my time is running out.
▶ 1:08:28Maybe we'll do I have some additional questions, so I'll wait for my the second round. Thank you, Mr. Chairman. Now, yield back.
▶ 1:08:32The gentleman yields back. I now recognize the gentleman from Rhode Island, Mr. Magaziner, for five minutes.
▶ 1:08:38Thank you to the chairman and the and the panelists. Um, you know, as we think about the risks and opportunities posed by frontier AI models in the cyber security realm, the thought that keeps recurring for me is that we are very fortunate that Anthropic did the right thing with Mythos and that before this product that is incredibly powerful and and has demonstrated an ability to
▶ 1:09:10facilitate cyber attacks in in a manner that no other tool has been able to do before. Before releasing this out into the world where bad actors could use it, they did the right thing by alerting the government, alerting key players in the tech space, including I I assume uh your employer, Miss Joyce, and working with them so that they could shore up their defenses before this product becomes available. But what if they hadn't chosen to do that?
▶ 1:09:36What if they or anyone else had chosen to just release this out into the world where anybody could use it to extort ransom, to make critical infrastructure inoperable, to cause mass chaos? Or what if they had decided to, you know, sell it to Putin first or sell it to the highest bidder?
▶ 1:09:55I'm not saying that they would do that, but the point I'm making is that there is a real risk for all of us to just be crossing our fingers and hoping that the next time there is a new advancement in in Frontier AI that whoever did that made that advancement just does the right thing again.
▶ 1:10:12And so, you know, I'm encouraged by the executive order this week which establishes at least a framework for new frontier AI models to be vetted before they are released to the public. However, this framework in the executive order is still only voluntary. So, we are still in a place where we are just crossing our fingers and hoping that the developers of AI are just going to do the right thing and participate. So, I'll just ask any of our witnesses to to weigh in.
▶ 1:10:42What do you see as the positives in this executive order? What still needs to be done in order to ensure the safety of the American people as new frontier AI models are released? And should we be moving toward a system, a vetting system that is a mandatory one as opposed to just an optional one? And I'll open it up to anybody who'd like to answer first. Happy to take that first. Thank you, Congressman, for the question.
▶ 1:11:11It's my belief that the best approach to protecting our systems from continued improvements in frontier models is to deploy state-of-the-art models today to shore up our defenses. the best uh defenses that we have um can be made um such that for instance if we do a refactor of a critical piece of software into memory safe language we can ensure that that is uh free of certain types of vulnerabilities that frontier models today find and frontier models of tomorrow.
▶ 1:11:42Um so there are some of these secure by design principles right that if we build software products in the right way we can ensure that they are protected against whatever might come uh with future models. As to your question on the executive order I was glad to see that the white house took a voluntary approach uh to um securing the these frontier models.
▶ 1:12:03While I agree that it is crucial to make sure these capabilities get in the hands of the right defenders, um I believe that ultimately the um advantage does lean towards making these models more widely accessible to allow defenders to make use of them ahead of adversaries exploiting.
▶ 1:12:22But let me ask you I mean again like say and I don't want to call out anthropic here any developer in this space if they developed a very powerful technology that could be used to to critical infrastructure to financial institutions what's to stop them today from just selling it to the highest bidder and not giving defenders an opportunity to shore up their defenses with it first. I
▶ 1:12:44I think part of the the answer there sir is that the openweight models while they are not quite as good as the frontier models they are quite close. they lag a couple months behind, but these capabilities are already out there and can be wielded by by adversaries.
▶ 1:12:57I don't know. I mean, I just reclaiming my time, I don't want to betray anyone's confidentiality here, but I've met with some of the largest financial institutions in the world in recent weeks who have told me that with Mythos, they found thousands of vulnerabilities that they didn't know they had. And if Anthropic had not done the right thing and given them a chance to build up their defenses first, the damage could have been incredible.
▶ 1:13:19And so once again, uh, I'm glad to see that there's at least some federal framework being set up now in this executive order, but to just keep it kind of voluntary and let everybody make their own decision about whether to give defenders a head start or say sell this to Putin first for the high or to the highest bidder, I think is very dangerous. And it doesn't have to be an ownorous vetting process. I think the executive order, you know, says 30-day vetting process, but there needs to be some kind of a process.
▶ 1:13:47And uh we'll dig into this a little bit more when I get another round. So thank you.
▶ 1:13:52The gentleman yields back. U you know, one of my concerns uh is China. So you know, AI coding tools are quickly becoming part of how software is written. If a coding tool is built on a PRC origin openweight model, the issue is not only who made the model, it is whether that model becomes part of a software supply chain for American companies. Should companies treat model providence the same way they treat software? What what questions should a company ask before allowing a PRC origin model into its developer environment?
▶ 1:14:24Mr. Joyce, would you lead off and we'll just go down the line?
▶ 1:14:29Well, like I said, we really believe that um regulation is really important in this space and we're seeing a lot of threats to the supply chain uh as we go along. I wanted to clarify one issue about the threat before we move forward and that is that while certain tools that have been introduced recently are very um very prominent and we're talking a lot about them.
▶ 1:14:55The truth of the matter is we have seen cyber criminals and threat actors already be able to create harnesses which is basically the software scaffolding around a model. it doesn't have to be a very powerful model to be able to already write exploits.
▶ 1:15:12So as we move along in this uh in this space what I what I want to clarify is the threat that these threat actors will be able to use these you know new models they don't even need to use new models to do what they're doing they can use existing models and we already observed how a cyber criminal had developed their own harness and was already writing their own exploit and they did not have access to the models that we've been talking out
▶ 1:15:46Um I would actually um even move upstream a little bit to how those models are developed in the first place and suggest that there's a lot more that I think needs to be done to be able to uh counter the use of adversarial distillation so that um the capabilities of those models if we're worried about them and the capabilities they have.
▶ 1:16:03Um, we need to protect the um integrity of the models we have and the capabilities we have by um uh trying to prevent uh the the distillation of American models uh by foreign linked actors um in the first place and I would encourage uh uh robust discussion on on that front.
▶ 1:16:21Mr. Cable,
▶ 1:16:22thank you chairman. Um I would say that right the reason that companies today are using these models from China is because these models offer the best performance. Like I mentioned in my opening statement, there are no frontier openweight models from the United States and there are use cases where as a company building AI systems you want to be able to for instance fine-tune models to work best on your use case.
▶ 1:16:46I would argue that the best answer here is to foster an ecosystem of openw weightight models coming from the United States that have safeguards in place that can then become the norm by which um others whether within or outside the US can build their technology and that is where I think that we can can counteract um some of the these um other models by having a competitive ecosystem here.
▶ 1:17:08Mr. Dr. Guglia.
▶ 1:17:10Yeah. Uh I would just urge that um we think about US-based models in the same vein that we would those coming from places overseas like China in the sense that absent consumer privacy laws absent more laws that govern how the US United States conducts surveillance on American citizens both models run some sort of threat of jeopardizing civil liberties the integrity of the American people.
▶ 1:17:40You you talk a lot about uh the privacy of citizens. Is 702 written in such a way to protect Americans from AI in your
▶ 1:17:52No. No. I mean, the problem we have right now is that section 702 is collecting all of these communications, including those of Americans, and they're storing them in a big pot essentially, uh, where the IC has some restrictions over where and when they can access Americans communications, but the Federal Bureau of Investigation does not, and they can query and look at those without a warrant.
▶ 1:18:16So with a large uh archive of American communications that the Federal Bureau of Information can access, uh my concern is that deploying AI and that sort of a space would allow them to sift through American communications without a warrant and also uh expose them to analytics like artificial intelligence.
▶ 1:18:40Thank you. I yield back. Recognize Mr. Ramirez for five minutes.
▶ 1:18:45Thank you, Chairman. I want to follow up with a conversation we were having just a few moments ago. Uh Dr. Guriglia, CISA is still racing to finalize its first ever mandatory cyber incident reporting rule, meaning right now the vast majority of cyber attacks on critical infrastructure go unreported. We were just talking about that a moment ago. We're talking today about deploying autonomous AI security systems across that same infrastructure.
▶ 1:19:13So my question to you is how can Congress make informed decisions about AI accountability when we don't even have a baseline picture just yet of what's even being attacked? How and even what the consequences could be to our communities?
▶ 1:19:28Yeah, I I think I think a a more robust infrastructure of communication between the federal government and affected uh entities uh as well as more resources dedicated to cyber security and dedicated toward uh hardening critical infrastructure and and to uh institutions like CISA which could build a more robust model for both monitoring and disclosure.
▶ 1:19:55So, just following up on that, section 702 of the Foreign Intelligence Surveillance Act expires next week and we're going to be asked yet again to pass a reauthorization of this authority. As if we didn't have enough reason to be worried about section 702. The president has now appointed Bill Pi, a partisan loyalist with no national security experience as the acting director of national intelligence.
▶ 1:20:22He has a wellestablished record of abusing his position to target the president's political opponents. And now he he's gaining access to more information about Americans through his new position, establishing yet another reason why we need real protections for Americans on how the government is gathering information on us in the name of national security. So, Dr. My last question for you.
▶ 1:20:47How could new frontier AI models facilitate greater abuses of the section 702 authority and what reforms would you like to see in any 702 reauthorization that would help mitigate those risks?
▶ 1:21:02Thank you so much for that question, ranking member Ramirez. Um, I think as I was saying earlier, I think the fear is that with such a large pool of Americans communications sitting uh and being able to be accessed by federal law enforcement without a warrant, that AI would make all of that data more easily to be weaponized against the American public, especially for political purposes, is always the fear.
▶ 1:21:26Um, and so I think when we're looking at the reauthorization uh perhaps next week, one thing we have to think about is first and foremost a warrant requirement that before uh federal agents want to access American communications, they should not only get a warrant to actually look at the content, but also to query how whether or not that database has communications by Americans uh by specific Americans in it.
▶ 1:21:50And I also think transparency is key here because when national security intelligence is used for criminal prosecution in the United States, oftentimes it is not disclosed to either defendant or their attorney where that information came from. And so they are unable to challenge it.
▶ 1:22:06And so I think that transparency piece and a warrant requirement are essential not only to any reauthorization of section 702 of FISA but also to prevent the proliferation of AI in the federal government to uh being able to weaponize that data further.
▶ 1:22:23Got it. So warrant requirement query onto the information and transparency. Thank you. I want to make sure that I make that note. I'm going to go ahead and yield back to the chairman. Thank
▶ 1:22:34Gentleoman yields back. recognize the gentleman from California for five minutes. Mr. Fong.
▶ 1:22:39Uh, thank you. I wanted to um follow up on the the chairman's question, which is um when it comes to the threat China poses, you know, we've seen China use lowcost technology to gain global market share in other sectors.
▶ 1:22:55Um, it's it's it's scary to imagine a world where the default AI model in Europe, South America, Southeast Asia, Africa, and parts of the Middle East is a is a Chinese openweight model because it's a it's inexpensive, capable, and easily to is easy to run locally. Um maybe I'll throw this to the to the to the panel, but what leverage would China gain if uh PRC origin models became embedded in global software development, cloud services, manufacturing, robotics, and critical infrastructure?
▶ 1:23:26And what should the United States do now to avoid that Anyone can can chime in.
▶ 1:23:34I don't think there's prize for second place in the AI race, nor is there one in the quantum race. and AI, you know, American leadership in this space is truly critical. In my group, we have tracked uh the threat from Chinese cyber for many, many years.
▶ 1:23:53We understand that they are prepositioned in our critical infrastructure and the government has confirmed that there are no reconnaissance purposes for that, that the reason they're embedded in critical infrastructure is for a potential um kinetic action in the future should they choose.
▶ 1:24:09So I think that the leverage that is would be gained by having this fundamental technology not be led by you know American innovation and democratic societies would truly be around um something that we simply cannot
▶ 1:24:25Dr. do you want to do you have an opinion on this or if not then I can I can jump to another question that you for you. I might um just speak briefly to how um some of their capabilities are being developed uh and what we uh might be able to do about it.
▶ 1:24:40So again, one of the core issues here I think is how um the trend lines uh between leading US capabilities, the capabilities of leading US models um uh and the capabilities of leading uh foreign models have collapsed. Right?
▶ 1:24:58It used to be kind of let's say a 12 to 18month uh gap in terms of when models would be released from the US and the capabilities they had and when you would see similar capabilities uh emerge elsewhere you know that trend line I think has collapsed down you know to four to you know six months something like that um uh in tandem with that um uh collapse of timeline we've also seen the emergence and articulation of a really robust ecosystem that has enabled um the distillation of US models.
▶ 1:25:28Um I don't think that those two facts are um unrelated. Uh there's a lot I think that could be done uh potentially to try and counter that. Um we the challenge is that the information that you would need to be able to do that kind of thing is distributed amongst the wide array of industry actors at present. Um industry actors um like I can just speak for the FMF here.
▶ 1:25:52um we have had to take a fairly conservative approach under under antitrust law to even have a conversation about how to identify distillation. We have not had a conversation about how to counter it um uh uh given kind of existing antitrust uh concerns. Um so that I think there's some lowhanging fruit in terms of uh what we might be able to do um uh to address that issue in particular.
▶ 1:26:15So if I could follow up Dr. role does the United States need a trusted open way strategy where there's broader uh trusted access and um and is and so that um American and allied models are available enough to compete globally. Um I will uh say within the context of the the frontier model forum we mainly focus on safety and security of models and um uh so unfortunately I can't really speak to the development side of models.
▶ 1:26:46Does anyone want to chime in on that question? Mr. Cable
▶ 1:26:49I I I would say that yes I as I mentioned before right I believe the best way to counter this is to have openweight models originating from the United States that are the best in the world. we already have closedweight frontier models that are the best. So, so I believe it's a matter of putting proper resources into making sure that we can have similarly competitive openweight models.
▶ 1:27:12Thank you. I I think it's important to for all of us to understand that the future is here. The threat is here is is not an academic conversation. So for for America to tread water means you fall behind and I think that's why it's important that that we have hearings like this. With that, I yield back.
▶ 1:27:29The gentleman yields back. I recognize the gentleman from Rhode Island, Mr. Magaziner, for five minutes.
▶ 1:27:34Thank you. You know, on the topic of needing to stay ahead of China in the AI race, uh, inevitably we keep coming back to the topic of why are we allowing the sale of advanced AI chips to China to help power their AI, which can be used to attack us.
▶ 1:27:52And so for over a year now, every cyber security panel that's come before this subcommittee, I've asked, does anyone here think it is a good idea for the administration, the Trump administration, to be allowing the sale of these advanced chips to China? And if so, why? Every single expert panel we've had in front of us, no one has said yes, they think it's a good idea. Not one person.
▶ 1:28:18And I know that and not only has no panelist said that it's a good idea, but no member on either side of the aisle, in fact, I know that I think every member, if not most members, think that this is incredibly dangerous. And we are not powerless in this. There is legislation, Republicanled legislation to stop the sale of these chips that has already passed out of committee, but has languished and hasn't made it to the House floor.
▶ 1:28:48We should take matters into our own hands. We should discharge it. We should do something because nobody thinks this is a good idea from a cyber security point of view. Going back to um uh the issue of having a federal government role in vetting Frontier AI products before they are released to the market, whether you believe that it should be voluntary participation or mandatory participation. One question I think we need to answer is where would this function sit?
▶ 1:29:16So my understanding is that under the executive order, Treasury is the primary nexus of this vetting function with input from other agencies. I think there's legislation, draft legislation that's been floating around Congress. I've heard that would place it at commerce.
▶ 1:29:33Chairman McCall yesterday when we had Secretary Mullen in I think reminded everybody that when SISA was first created this was the type of role in a less advanced context that SISA was envisioned to play. So I I'd welcome feedback from everybody because we got to get this right whether it's voluntary or mandatory for AI developers to to participate in this sort of a vetting process before a product is released.
▶ 1:29:59where should that function sit and who should be involved in making sure that it's successful? I'll open that up to anybody please. Um I think one thing I would say is um one of the things that we really uh encourage and have encouraged even a year ago in response to uh an RFI about um uh the development of the AI action plan that the administration put together.
▶ 1:30:29um was that there would need to be uh sophisticated expertise on uh evaluation and testing within government. Um and we were pleased to see um last year uh that the center for AI standards and innovations uh was kind of empowered to do a lot of that testing.
▶ 1:30:46Um uh and I I think um uh to the extent that there needs to be greater kind of public private partnerships uh in the development of this uh you know technology and an assessments of the safety and security of these systems um I think the thing that I would underscore is that it is hard to do that without relevant expertise. Um and uh I think we've really welcomed the uh expertise that the Casey has developed over the uh since it was created. All right.
▶ 1:31:16Thank you. Um, again, just sort of thinking in terms of next steps, building off of the executive order, are there any other ideas or insights for things that we ought to do in order to make this successful so that as these products come to market, there's appropriate consumer safety and an ability for defenders to defend themselves before the attackers are are able to exploit their vulnerabilities.
▶ 1:31:40thank you, Congressman. I would say that where where I I would like to see more is to move beyond just this element of you know identifying and one-off fixes of vulnerabilities. That's you know what has often been the predominant strategy is very necessary to do so right but at the scale we are operating you mentioned anthropic reporting 1500 vulnerabilities via mythos only 6% of those being fixed I would argue that's not enough and I think we have
▶ 1:32:10to be thinking bigger right about how we can enable these largecale remediation campaigns refactoring software systems right will it will take time and money but it is also the sort of thing that AI systems can help us with. So I think those are the sort of actions as well as preventing vulnerabilities at scale as new software is being built with AI coding tools that are ultimately necessary and will allow us to upscale the the security in our systems.
▶ 1:32:36Well, thank you. You know, I'll just close by saying that um I'm glad that Mythos has scared at least some people in the administration enough to take the issue of AI safety seriously. I think the hands-off approach from the last year was a mistake and now in a thoughtful collaborative way with industry, it's time for us as a federal government to take our job seriously when it comes close to when it comes to uh protecting the American people. So, I yield back.
▶ 1:33:04The gentleman yields back. I kind of want to piggyback on where you're going with this. uh when when I think about uh China and the threat that China poses when you think of a tool like mythos um you know in the event whether it's to you know impact an election to have adverse effect on our economy uh perhaps China's looking to do something in the Pacific how real is the threat to our critical infrastructure like energy like
▶ 1:33:34water that they could start flipping swi switches to create that internal chaos so that they can whatever their goal or desired outcome might be
▶ 1:33:48I think the threat is something that we have seen already present for many years we know that the threat is there uh with AI models in particular we've also seen that type of innovation not just from uh threat actors in the you know China North Korea Iran and and others but we're also seeing it in with cyber criminals as well so often The threat from nation states is more on uh reconnaissance.
▶ 1:34:14Although in the case of old typhoon, there's something a lot more uh concerning there. But what cyber criminals bring to the table is a lot more of uh sloppiness, a lot more recklessness in order to do things that are financially motivated. For example, we have seen them uh extort, do ransomware, and with the latest report that we put out, we have seen them taking steps to even create their own harnesses and create an exploit using AI.
▶ 1:34:44So, we know that they're making a lot of progress and we know that nation states are posing these threats today. It's something that we see every single
▶ 1:34:55Anyone else want to chime in? I I would just agree with that in that we we've already seen adversaries exploiting these systems through campaigns like Vault Typhoon, Salt Typhoon before AI and we know that adversaries are leveraging AI to accelerate every step of these attacks. So to me that is all the more reason to double down on defense, right?
▶ 1:35:18I think the best approach here is for defenders to deploy AI systems and shore up some of the foundational oftent times relatively basic vulnerabilities that our adversaries are exploiting.
▶ 1:35:29Going back to the profit motive, um obviously you talk about the sophistication of the models themselves and it doesn't have to be the latest and greatest to be effective. So what's the the threat environment for the jailbroken uh versions of AI that are out there? You know, I think any one of us with a little technical knowhow can download and put on a laptop in a matter of seven 10 minutes.
▶ 1:35:53Well, what we have observed in the underground or the what some people call the dark web is a a whole marketplace of advertising for so-called jailbreak, you know, bots of different kinds. Something as low as $99 a month you can go and and uh get that. Now, some of those are not true. Some of those are just criminals, you know, not being uh honest, which is not a surprise to anybody.
▶ 1:36:19Um, but what we're also seeing is a lot more uh advancement with cyber criminals. They're doing things that, you know, creating zero days. They're taking advantage of supply chain risks, cryptocurrency. So, we're seeing a real vast marketplace u of of criminal enterprises both with scams and with other other elements.
▶ 1:36:42So much so that in my group we have started a disruption unit and what we have been doing is operationalizing the intelligence that we have in order to take down and create coordinated disruption of a lot of these different infrastructure.
▶ 1:36:56So for example, in January, Google's disruption unit took down something called the IPA IP idea residential proxy network and in doing so disrupted over 500 thread actors that were using this infrastructure to do the malicious distillation that we were talking about, but also to obscure where they're coming from to carry out their schemes.
▶ 1:37:17So we need to be um thinking about yes intelligence sharing but we need to go even further than that and start to have a a purpose for that intel sharing and do more disruption work active defense in this area
▶ 1:37:31on the idea of disruption uh Dr. Misel, I think you mentioned antirust regulation. Is that a concern uh for any of you when you look at this marketplace of crossing and violating some sort of antirust um you know current law? Are there reforms that need to be made in order that we can be more uh aggressive in protecting our country? Quite
▶ 1:37:59I already alluded to this briefly, but I under current uh antitrust guidance, there's a lot I would say there's a lack of clarity about what actually can be done. Um uh to the point again that we have not had conversations about how to counter um what what is happening. Um uh I think having a a much clearer sense of what the um what can and can't be done would be useful. you know something to if any of you have ideas uh to report back and and give to committee uh you can send them to me.
▶ 1:38:29I would love to when we look at the regulatory reform or lack thereof or the clarity lack thereof there's things that we need to be doing in anticipation of what the marketplace is going to need. Uh we are all ears. That's the purpose of this this hearing today is to figure out what have we gotten wrong and what do we need to do better going forward. So, any of you that have that type of input, please forward it to me u as soon as you can get it ready. Uh, with that, I recognize the ranking member, Mr. Ramirez, for five minutes.
▶ 1:39:00Actually don't have any other questions at this moment, but I really do appreciate the follow-ups that you just asked for. Thank you.
▶ 1:39:06Yes, ma'am. Uh, well, with that, um, we are nearing the end. I guess we'll just go down the line. We'll start on this end since we've been picking on Miss Joyce the entire hearing and just kind of closing remarks. uh anything that we missed that you want to you know kind of double down on Mr. Wrigley?
▶ 1:39:22I I think just the one thing that hasn't come up yet um that I mentioned in my opening remarks is the US government's own finding and exploitation of of zero days um and uh thinking about uh the integrity of American critical infrastructure uh as being undermined by the government's also their desire to collect as much data as possible and to keep those vulnerabilities open for the purposes of exploiting for future future surveillance.
▶ 1:39:53Um, and so thinking about uh how the NSA and the intelligence agency's own desires to spy on Americans uh often undermines our own critical And if you have any thoughts that you'd like to forward on those types of concerns 702 again thinking forward uh you know last thing we want to do is create Skynet or uh you know an observation tool that you know suddenly gets away from
▶ 1:40:23us but I do appreciate your input sir.
▶ 1:40:27Thank you chairman and ranking member for the opportunity to testify today. As I mentioned, I believe that we need to get ahead of these um issues so that each model release doesn't create an emergency, right? And I believe that we can do that by putting in place these foundational defenses across our critical infrastructure across the software products that we rely on across open-source software and the foundational ecosystem that that is.
▶ 1:40:56And I believe we can use AI for these missions to prevent vulnerabilities in new code going forward by putting in place guard rails and to refactor existing code bases to root out entire classes of vulnerabilities. So I would encourage the committee to focus on how we can get ahead of these issues and I'm happy to work with you um to do so.
▶ 1:41:17Dr. from Israel.
▶ 1:41:20Um I think one thing I would underscore uh which I also alluded to in my opening testimony was just that the trend line here is pretty unmistakable. Um and one of the things that um uh I think one of the reasons why I think we need to strengthen our public private partnerships and information sharing mechanisms um is so that when new capabilities come online it is not coming as a surprise to the policy community.
▶ 1:41:44This is probably the the current moment I would say is the third time this has happened in the last three or four years where the first one being the kind of the GPT moment. Um uh the second being the Deepseek moment a year or so ago and then now with Mythos and GPT 5.5. Um what concerns me is that to the expert community that is working on these issues, none of those things came as a surprise.
▶ 1:42:07Um and so um I think we need to develop you know again much closer uh and more tightlyk knit um information sharing mechanisms and public private partnerships to ensure that the policy community and others are getting the information they need and and understanding it ahead of the moment uh as opposed to uh in response to it.
▶ 1:42:25Well and you know to that point you know AI is advancing so quickly and let's let's be honest Congress tends to move quite slowly. So I would I would agree with you wholeheartedly that we've got to you know increase this the speed at which we're communicating so that we can react and it doesn't become an emergency every time we have a new release. Mr. Joyce final word.
▶ 1:42:47I think we have said that this technology and AI is too important to not regulate and it's too important to not regulate well. So Google stands by to be uh a useful and dependable partner in this space as we support American leadership in these critical I want to thank all the witnesses for their testimony and members for their questions.
▶ 1:43:10Members of the civ committee may have some additional questions for the witnesses and would ask and I would ask that the witnesses respond to these in writing pursuant to committee rule 7E. The hearing record will be open for 10 days. Without objection, this subcommittee stands adjourned.