Summary
- President Trump's executive order directs classified benchmarking of AI cyber capabilities and voluntary early government access to frontier models for CISA oversight.
- Sandra Joyce (Vice President, Google Threat Intelligence, Google LLC) said criminals used AI to build a zero-day exploit and agentic tools now scale attacks faster than patching.
- Rep. Magaziner pressed Jack Cable (CEO and Co-Founder, Corridor) on whether voluntary vetting lets developers sell Mythos-like models to adversaries first.
- Rep. Ogles emphasized Chinese open-weight dominance and CISA defense while Rep. Ramirez demanded mandatory safeguards, transparency, and preserving state AI laws.
- CISA must translate early model access into guidance for rural hospitals and utilities as Congress weighs Section 702 reauthorization and open-source security funding.
Morning digest
Get hearings like this in your inbox
Transcript
Now, Homeland Security, the Subcommittee on Cybersecurity Infrastructure Protection will come to order. Without objection, the Chair may declare the committee in recess at any point. Today's hearing will examine how artificial intelligence is changing cybersecurity in real time and what that means for the resilience of America's critical infrastructure. We will discuss advanced frontier model models capable of discovering software flaws, agentic ai systems that can operate across digital environments and ai coding tools that are rapidly changing how software is built and secured. We'll also consider recent federal action on ai innovation and security, as well as national security risks posed by PRC's open way ai strategy, adversarial distillation and the spread of Chinese ai models on into American developer tools and enterprise systems. I now recognize myself for five minutes for an opening statement. Good morning, and thank you all for being here. Today we're examining how artificial intelligence is changing the foundations of cyber security and the security of our critical infrastructure. This committee has taken these threats and risks seriously for months. We have held round tables, hearings and briefings with the leading AI laboratories and cyber companies in the country and we have opened a joint investigation with the select committee on China into the proliferation of Chinese AI models. On Tuesday, President Trump signed an executive order directing the secretaries of the treasury, homeland security and war to develop a classified benchmarking process for advancing AI cyber capabilities, and to design a volunteer framework for early government access to cover frontier models. The president is right to act. These models are already reshaping the threat landscape and the federal government cannot be the last to understand what they can do. I wanna be clear that this subcommittee intends to watch closely how CISA carries out its responsibilities under that framework. CISA has a a statutory authority under the Cybersecurity Information Sharing Act of twenty fifteen, operates the known exploited vulnerabilities catalog, and serves as the lead civilian agency for critical infrastructure cybersecurity. How CISA fulfills its role under this order, especially in translating early model access into practical guidance, and vulner vulnerability remediation for critical infrastructure operators will be a central oversight question for this subcommittee in the months ahead. To understand why that matters, consider that these models c can now do, until recently finding a serious serious unknown flaw is why widely used software took skilled researchers months of painstaking work. Frontier AI models are collapsing that timeline. We now have models that can discover and exploit previously unknown vulnerabilities on their own. at machine speed across the systems that run nearly everything in our economy. Most advance of these models was judged too dangerous to release publicly, so it was shared with roughly fifty large companies to help them find and fix flaws before our adversaries could. In the right hands, this is a powerful defensive advantage. In the wrong hands, it is a weapon. Imagine a Chinese state cyber-actor, the kind already burrowing into our power grid and our water systems, armed with a model that finds and exploits unknown flaws faster than any human team alive. The danger does not stop at cyber attacks. The same models that hunt for software flaws can, without the right safeguards, help a bad actor work through the hardest steps of building a biological weapon. Our leading laboratories build in guardrails to release, to refuse that kind of help, but when a foreign adversary copies an American model, strips out those safeguards, and releases it to the world, Those prot- protections and protocols vanish. We could find we have handed the most dangerous knowledge on earth to the people most determined to use it. But the safety switches? Turned off. There's a second front that deserves the same attention. United States leads the world in the most advanced frontier models, and those models are lar- largely closed, prop- proprietary, and expensive. China has taken the opposite path. Chinese labs are releasing open-weight models that can anyone can download for free, that run at a fraction of the cost, and that are now good enough for most of what an ordinary developer or business needs to do. Here is what concerns me. When the cheap, capable, easy option for an AI model is Ch- Chinese, the rest of the world will build on it. Developers in companies in the United States, Europe, South America, Asia, and across Africa are making that choice right now. If we do nothing, Chinese models become the default foundation of the global digital economy, carrying embedded censorship, uncertain security, and capabilities distilled from our own laboratories with the safety guardrails stripped out. We can we cannot let the world grow dependent on Chinese AI the way it grew dependent on other Chinese technologies we are now scrambling to address. United States needs a serious strategy to ensure capable American models, especially open weight models, that developers, companies, and governments can deploy and adapt are real and that are are a real alternative. Finally, I wanna name the the issue practitioners care about, because because getting them right is how we secure the country. More of our software is now written by AI, faster than human reviewers can keep up, which makes security by design practices, where security is built in from the first line of code more important than ever. It makes AI coding tools a real concern. When those tools are built on foreign models, we cannot fully vet. and it makes a agentic AI software that plans and acts on its own across our networks. In an an entirely new attack surface, our defenses were never built to withstand. These are real issues with real consequences, and they deserve a serious bipartisan response. I look forward to a substantive hearing, and I thank our witnesses for being here. When Miss Ramirez arrives, uh we'll recognize her. Um, other members of the committee are reminded the opening statements may be submitted for the record. I am pleased to have a distinguished panel of witnesses before us today on this important topic for suing to rule committee Committee Rule eight C. I I ask that our witnesses please rise and raise their right hands. You solemnly swear that the testimony you will give before the Committee on Homeland Security of the United States House of Representatives will be the truth the whole truth and nothing but the truth. So help you God. Let the record reflect that the witnesses have answered any affirm affirmative. Thank you and please be sit seated. I would like to formally introduce our witnesses. Miss Sandra Joyce is the Vice President of Google Threat Intelligence, where she helps lead one of the world's most capable teams tracking nation-state criminal and emerging cyber threats. She previously served in senior leadership at Mandiant before its acquisition by Google bring and brings more than twenty-seven years of intelligence experience. and is a US Air Force Reserve Officer. Thank you for your service, man. Doctor Chris Mesereau is Executive Director of Frontier Model Forum, an industry-supported nonprofit founded by leading frontier AI companies to advance the safe and secure development of advanced AI models. His work focuses on AI safety, evaluations, standards, and information sharing among industry, government, academia, and civil society. Thank you, sir. Mister Jack Cable is the Chief Executive Officer and Co-founder of Corridor Security, Inc., an AI-powered software security company fo- focused on secure AI coding and secure by design development. Corridor's platform helps identify vulner vulnerabilities as code is being written, whether by human develop developers or AI coding tools. Mister Cable previously served as a Senior Technical Advisor at CISA. where he helped lead the agency secure by design initiative, and he also worked at the CRIBS, Stamos group, and the Pentagon's defense digital service. Thank you, sir. Mister Matthew Griglia is a senior policy analyst at the Electronic Frontier Foundation, where he wor- where his work focuses on surveillance, policy uh policing, civil liberties and government use of technology at the local state and federal lev levels. I wanna thank you all again for being here. Um, I now recognize Miss Joyce for five minutes to summarize her opening statement. Miss Joyce?
Thank you, Chairman Ogles, Garbarino, ranking members Thompson, Ramirez, and members of the committee and subcommittees. Thank you for inviting me to speak to you today. My name is Sandra Joyce and I serve as Vice President of Google Threat Intelligence Group. Our team defends Google, our users and our customers. by building the most complete threat picture to disrupt adversaries. We appreciate the opportunity to participate in this important conversation. As this committee knows, we stand at a critical technological inflection point. Rapid advances in artificial intelligence are unlocking new possibilities for the way we work and accelerating innovation in science, technology, and beyond. This technology has impacted cyber security in profound ways for both the defender and the attacker. For years Google has been successfully u- using AI defensively to find and mitigate vulnerabilities in the code we all rely on. But we have also anticipated that threat actors would abuse this technology to find and exploit vulnerabilities for malicious purposes. Those concerns were validated recently when we discovered evidence, for the first time, that AI was used to develop a zero-day exploit by cybercriminals. continue using or attempting to use this technology to their advantage. We are particularly concerned about two future scenarios. First, though AI will be used by defenders to harden software and produce safer code, adversaries may have the initiative in the short term to find and exploit vulnerabilities at scale. We are working to integrate AI directly into the development cycle and make code exploitation more difficult than ever. Nonetheless, the transition period will pose challenges. As we harden existing software with AI, Threat Actors will simultaneously use it to discover and exploit novel vulnerabilities. In addition, agentic orchestration will allow Threat Actors to cheaply scale their operations and operate at unprecedented speed to take advantage of slow patch cycles, beleaguered security teams, and human response time. Threat Actors are able to move rapidly before and after gaining access to a network using AI. They can take advantage of vulnerabilities faster than we can patch, and they can move rapidly through networks using autonomous agents. To effectively tilt the cyber security balance in favor of defenders, we must close the exploit window. Historically, patch management has been a retroactive, human paced race against adversaries. In the current threat landscape, where attackers use AI to discover and target design flaws at scale, traditional siloed security tools fail to keep pace. For critical infrastructure operators and public sector networks, defense at scale requires an automated mechanism that shifts focus away from mere bug hunting and toward comprehensive environmental exposure management. To address this collapse of the ex- exploitation timeline, Google has pioneered an always-on four-step framework designed to help enterprises to implement an autonomous defensive control loop. prepare, scan and prioritize, remediate, and monitor. Our aim is to shift the industry away from reactive response and toward active prediction and accelerated remediation. We believe our approach to the frontier of artificial intelligence must be bold and responsible. This means developing and deploying technology in a way that maximizes positive societal benefits while proactively engineering systems to withstand and mitigate modern adversarial pressures. For more than twenty years, Google has pioneered a secure by design approach, meaning we embed security into every phase of the software development life cycle, not just the beginning and the end. Google's software and AI development pipelines rely on advanced threat modeling to proactively identify emerging threat trends and systemic risks, and to explicitly design our products for inherent safety. Rather than treating safety and security as an afterthought, we continuously enhance our safeguards inside our products to offer scaled, adaptive protections to enterprise users and critical infrastructure operators across the globe. Cyber security has never been an environment where absolute perfection is possible. It will remain a fiercely contested, highly dynamic domain for years to come, demanding continuous innovation, speed, and structural agility to defeat a- adaptive adversaries. As this con- committee looks to secure our homeland and fortify the digital architecture supporting American critical infrastructure, Google stands ready to serve as a committed, transparent partner. By combining public sector authority with private sector technological innovation we can harness the immense potential of artificial intelligence to skip tip the scales of cyber security permanently in the favor of defenders thank you for the opportunity to testify today.
the finalist of the subcommittee, summarize his statement. Memorize his opening statement and, Thank you. if we could, move your mikes um so that the recr it picks up properly. Miss Joyce, move your mike forward a l just a little bit. Thank you so much.
Chairman Ogles, ranking member of Ramirez, distinguished members of the subcommittee. Thank you for the opportunity to testify today on the AI security landscape. I serve as Executive Director of the Frontier Model Forum, an industry-supported non-profit, whose mission is to advance frontier AI safety and security. Since our founding, we have worked with our six member firms, Anthropic, Amazon, Google, Meta, Microsoft, and OpenAI to develop the security practices, scientific research, and information sharing channels we need to responsibly manage the potential large-scale risk to public safety and security from frontier AI. My aim this morning is not to advocate for particular policies, but to help inform your discussion of the security challenges and opportunities presented by the most advanced cyber capabilities of the latest AI models and agents. My comments will touch on three key issues, the trajectory of frontier AI capabilities, the potential risks associated with them, and how we can manage those risks effectively. Let me start with the trajectory of advanced AI. As impressive as the cyber capabilities of the latest frontier models are, they do not represent a sudden or discontinuous jump. The ability of today's models to autonomously identify and exploit vulnerabilities is clearly in line with empirical forecasts from over a year ago. I say this not to downplay those capabilities, but to underscore that they should not have come as a surprise. If the most recent models caught us off guard, that should serve as a wake-up call to strengthen our private partnerships and information sharing channels, on which I'll share more in a moment. The second issue I'd like to touch on concerns the security challenges posed by frontier capabilities. While the most advanced models hold enormous promise for strengthening the resilience of our cyber security and critical infrastructure they also pose credible threats. An agent that finds zero day vulnerabilities can protect us in the hands of a defender, but expose us in the hands of an attacker. And the attackers are real. State-linked actors have already used advanced agents across the attack life cycle and less sophisticated criminals are now using AI to generate and sell ransomware. This is especially concerning for small, under-resourced operators in critical sectors like water, health care, and local government, where targets that may not have been worth an attacker's time before now may well be. Significantly, all of those threats are compounded by adversarial distillation. For those unfamiliar with the term, distillation is a method for training an AI model on the outputs of a larger, more capable model, and has many legitimate and beneficial use cases. But when carried out at industrial scale and outside a developer's terms of service, disti- distillation amplifies the security challenges of frontier AI because it transfers the advanced capabilities of a model but without any safeguards attached. foreign actors can use distillation to accelerate their own AI development and leverage the capabilities they gain against US critical infrastructure. And when adversarial di- adversarily distilled models are made widely available, malicious actors of every kind can exploit advanced cyber capabilities with relevant security mitigations stripped away. Any serious effort to secure US critical infrastructure must address adversarial distillation. The good news here, and this is the main the third main issue I'd like to touch on, uh is that we have a strong foundation for managing all of these threats. Let me highlight several areas in particular. First, as I noted earlier, frontier models hold enormous potential for cyber defense. Since cyber capabilities are dual use, the same agents that find vulnerabilities for attackers can find and patch them for defenders. Thankfully, leading developers have already begun putting these tools in the hands of trusted defenders and critical Second, there are many existing information sharing channels we can leverage. Leading developers have already have bilateral information sharing agreements with government agencies, while the FMF maintains a multilateral information sharing mechanism among industry. All of that is in addition to the ISACs, ISAUs, and sector coordinating councils that already exist. We should strengthen and build on these mechanisms where we can, including through clearer guidance on antitrust and export controls. Third, we should build on established practices and standards. Securing frontier AI doesn't require starting over. Foundational controls like red teaming, access controls, and continuous monitoring still apply. But we do need to update and adapt those practices, which is why efforts like the NIST AI Agent Initiative are so welcome. Finally, we also need to redouble existing investments in AI measurement and metrology. Many cyber benchmarks are nearing saturation, so developing the next generation of evaluations and technical safeguards, work that Casey and others, including the FMF, are already pursuing will be essential. By leveraging AI for defense, strengthening existing information sharing channels, updating and adapting cyber security practices, and investing in better measurement, we can meaningfully improve our resilience. Thank you for the opportunity to speak today, and I look forward to your questions.
Thank you, Doctor Mesrell, and I'll recognize Mister Cable for five minutes to summarize his opening statement.
Chairman Ogles, Ranking Member Ramirez, and distinguished members of the committee, thank you for the opportunity to testify today. I am the CEO and Co-Founder of Corridor, where our mission is to prevent a new wave of vulnerabilities by securing AI coding. Before this, I helped build the Secure by Design initiative at CISA and was a top-ranked ethical hacker. We're living in a time of profound change in cybersecurity. Coding agents, not human engineers, are writing our code, and growing more autonomous every day. They produce code at unprecedented rates and, without guardrails, will introduce more vulnerabilities than ever. At the same time, frontier models like Mythos are increasingly capable of finding and exploiting vulnerabilities, though as Anthropic's own data shows, their ability to find flaws has far outpaced the ability to fix them. Before I talk about what's changing, let me note what's staying the same. Attackers generally aren't exploiting new kinds of vulnerabilities. They're exploiting the same old flaws we've known about for decades. Even mythos is surfacing issues like buffer overflows first discovered in nineteen seventy-two. Similarly, long-standing defense mechanisms still matter. The case we built at CISA around secure-by-design is more relevant than ever. Rewriting critical code in newer, memory-safe languages will yield dividends for years to come. The central challenge is not that AI creates new categories and vulnerabilities. It's that AI dramatically increases the speed and scale at which vulnerabilities can be introduced, found, and exploited. Our response must shift from patching individual bugs to preventing entire classes of vulnerabilities at the source. Today, I'll make three key points. First, hackers have more powerful tools than ever. Mythos and GPT-five-five are just the latest iteration of models that can run robust end-to-end exploit change. These models aren't just hype. They are truly starting to rival or exceed humans on security tasks, and do so at an unprecedented scale. We won't be able to patch our way out of this. Of the fifteen hundred vulnerabilities Anthropic has disclosed via mythos, only six percent of them have been fixed. Instead, we must get ahead of vulnerabilities at the source by shifting to prevention and wide-scale remediation. This is especially acute for open-source software. It underpins every software service we rely upon, yet as a public good it will be hit the hardest. Second, as AI is the dominant code writer today, with scale comes more vulnerabilities. The most productive engineers no longer write code. They instruct fleets of AI agents to do so. Today, you can start a coding agent from your phone, and it will produce a significant code change while you eat lunch.
Mm.
fourteen times more code committed in twenty twenty six than twenty twenty five. Google says seventy five percent of its new code is AI generated. At Corridor, agents write the vast majority of our code. While coding agents write more secure code per line than humans, they still often introduce vulnerabilities, and those scale with volume. Academic benchmarks find that even the best models introduce vulnerabilities roughly a third of the time. Our own data shows thirteen percent of agent generated code changes have vulnerabilities. Between AI empowering adversaries and coding agents writing more code than ever, we're stuck between a rock and a hard place. To prevent the bugpocalypse, we need a new path forward. Third, the good news is that properly guided, AI coding offers a more secure feature. At Corridor, we find that coding agents follow security instructions better than most humans. Across our customers, giving the coding agent the right context at the planning stage reduces vulnerabilities by sixty percent. For existing code, frontier models can accelerate security refactors that once cost millions of dollars and years of efforts, now achievable for thousands of dollars in weeks. Initiatives like DARPA's TRACTOR program, translating unsafe code into memory-safe languages, are exactly the right investment. Let me close with my recommendations. One, prevent vulnerabilities in new code. The highest leverage step is to stop entire classes of vulnerabilities at the point of code generation. Congress should enable AI coding among the federal government and its contractors, while requiring security guardrails that prevent these vulnerabilities up front. Two, harden the open-source software foundation. Rather than one-off fixes, Congress should fund a multi-billion dollar nonprofit initiative for large-scale security-oriented refactors and maintenance of critical open-source components. I also encourage the committee to bolster CISA's capabilities to partner with the open-source ecosystem. by passing the Securing Open Source Software Act. Three, maintain America's lead through open weight models. A thriving AI industry demands both the cutting edge performance of closed weight models and the low cost and flexibility of open weight models. Today, there are no frontier open weight models from the United States. The US government should fund and support the development of open weight models. And we should keep allowing US businesses to access frontier models. Restricting access only sets us back. Thank you for the opportunity to testify today. I look forward to your questions.
Thank you, Mister Cable, and I'll recognize Doctor Griglia for five minutes to summarize his opening statement.
Chair Ogles, rank Chair Ogles, Ranking Member Ramirez, members of the committee, thank you for the opportunity to speak today. My name is Doctor Matthew Griglia and I'm a Senior Policy Policy Analyst at the Electronic Frontier Foundation. The Electronic Frontier Foundation is a non-profit organization dedicated to protecting privacy, innovation, and free expression in the digital world. For thirty-five years, EFF has represented the users of technology, both in court and in policy debates, to ensure that law, technology, and su- support our civil liberties. Today I am urging caution on the use of artificial intelligence in the national security and cyber security arenas. AI can be an incredible tool for cyber security, but without proper guardrails in place, it can amplify threats to civil liberties and make us less safe. I urge the committee to consider narrowly tailored regulation that promotes transparency and accountability while protecting innovation. Guardrails are especially important because the national security state already has tools that can aggregate and infer sensitive information about individuals without pre-existing probable cause. We're talking about making inferences about a person's politics, personal life, religion, and geolocation sometimes inaccurately with major consequences. Before there was a smartphone in every pocket. Our privacy relied in large part on the practical cost of surveillance. You couldn't watch all people all the time. It took effort, it took hundreds of employees, it even took airline hangers to store all of the physical files. AI combined with the exponential growth of electronic surveillance tools has totally upended this. Thanks to those tools, AI's increased capacity can expose every American to granular levels of surveillance with the click of a button. This departure from the prior default, which is individualized surveillance based on individualized suspicion, poses a major threat to civil liberties and one that Congress and the courts have yet to address in any meaningful privacy-preserving way. AI also has a track record of getting things wrong, from false citations on legal briefs to a major AI mistake that sent DHS recruits to the field without proper training. There are likely more consequential examples that we don't even know about, because of classification that would prevent a more thorough accounting. There are, however, solutions to threats posed by irresponsibly deployed AI. The first is to answer the urgent need for transparency within the military or the intelligence community in which AI would be deployed. And the second is a general reduction of the amount of warrantless data collected by taking actions like reforming section seven O two of FISA, or closing the data broker loophole. For decades, the national security apparatus has been overburdened by impenetrable layers of classification. Secrecy would prevent the public from knowing about or seeking accountability when AI hallucinates or makes vital mistakes in the national security or cyber security spaces. Hidden by this secrecy is the practice of zero-day hoarding, where government-deployed AI might find vulnerabilities in critical infrastructure but that information is withheld from affected parties in an attempt to preserve future opportunities for surveillance. This has already happened a number of times, where NSA discovered vulnerabilities like Eternal Blue, exploited by bad actors in foreign nation-states. I will end by noting that we should be concerned about the way the executive branch's current posture toward AI not only jeopardizes civil liberties, but the cyber security and resilience of our critical infrastructure. The government has insisted that the technology it procures be made available for use as a mass surveillance tool despite company's internal ethical commitments and the best use guidelines for their products. When a company does not comply, they have been labeled But making companies enablers of civil liberties violations will eventually make them reluctant to sell cutting edge tools that we need for maintaining digital infrastructure. Even the White House's brand new executive order, while it does direct resources to cyber security, does not ensure that its early access to frontier models will not be used to hoard and exploit vulnerabilities. It also creates a tiered regime where some companies in good standing with the administration could be granted cutting edge cyber security tools while others are rele relegated to susceptibility. The lesson here is that government must not let political whims stifle technological progress for the public good. One of EFF's core values is the belief that technology can create a safer and more just world. AI holds immense promise in many areas, but it is up to Congress to step in and provide necessary and balanced regulations. Thank you again for the opportunity to speak today, and I look forward to your questions.
Thank you, Doctor Griglia. I now recognize the ranking member for five minutes for her opening remarks.
Thank you, Chairman. Well, first I wanna thank our witnesses for being here today. Today's hearing about the security concerns raised by artificial intelligence comes at a very important moment. Artificial intelligence development is speeding ahead with nearly no standards, rules or regulations for how powerful AI tools will be responsibly used. It does not seem to be a point of debate that we should do something about that, it's actually why we're here today. The advent of new models like anthropics, mythos, has moved even the president to admit that there are security risks associated with artificial intelligence and that the federal government has a role to address them. But as you might expect, I take issue with the most recent executive order on artificial intelligence. Now, I rarely look to the Vatican for a policy inspiration. But when Pope Leo himself publishes a two hundred page encyclical calling for AI regulation and warning that data cannot be left in private hands and that is a more comprehensive AI policy than what's coming out of the White House, well, I think we should be concerned. In contrast to the EO, uh the previous presidential executive order on AI noted that AI makes it easier to extract, re-identify, link, infer, and act on sensitive information. about people's identities, locations, habits and even desires. Bottom line, AI makes it easier to surveil, target and violate our rights and privacy. And the executive order that was just recently issued is silent on how to mitigate those risks and protect the public's right to privacy. Am I shocked? No. The administration has already demonstrated it will use every tool available to find track and deport immigrants and those who defend their rights. In my own district, DHS has used AI-powered facial recognition, software, and predictive tools to target, intimidate immigrants and rapid responders alike. And now we're watching AI-powered monitoring systems spread to schools, to public housing, to hospitals with no transparency about how they work, no ability to challenge them, and no recourse when they're wrong. So I'm clear that we cannot settle for unregulated, unaccountable AI, there's gotta be rules, there's gotta be limits, and it's our responsibility to ensure oversight. We have to set standards for AI's responsible use. Move fast and break things, it's not an acceptable innovation strategy when things being broken are people's lives, their rights, their privacy, and their safety. Fortunately, states across the country, including my home state of Illinois, are leading the way. Just recently, last week lawmakers in Illinois sent SB three one five, the strongest AI bill in the country, to the governor's desk. Among other things, the bill requires frontier AI developers to have their safety practices audited by a third party a major and much needed check on AI companies. The effort builds on laws already enacted in states like New York and California that require AI labs to provide information about guardrails to ensure the safety of their models and to publish reports on any safety incidents. Bottom line, at the federal level we have to one enforce the laws we already have, civil rights, privacy, and consumer protection. Two, we have to define clear rules and guardrails with real consequences that companies are statutory required to abide by, no voluntary pledges as we've seen. Three, make companies prove their systems are safe before release at every step. Because the burden of proof should not be on the companies, not the the burden of proof should be on the companies, not the consumer, and certainly not the public. So until the federal government can do that work and demonstrate it will develop AI policies that prioritize the well-being of the people over the profits of AI companies Congress must not undermine state laws that insure responsible AI. I wanna know as we go through our questions today, we might have I think more than one round, you know, what you are doing right now to make sure that AI technology will not become another instrument of surveillance, exploitation or control, dressed up in language of progress and national security. We've already endured those who would ask us to sacrifice our rights and liberties to secure our safety. We're done with the false choice. Uh, we think that we could regulate AI and actually benefit from the advancements and progress that it brings, but we have to ensure that we do our own work and the oversight necessary. With that, Chairman, I yield back so that we can start the questions.
Thank you, Ranking Member Ramirez. Members will be recognized by order of seniority for their five minutes of questions. I now recognize myself for five minutes. President Trump's executive order directs CISA to facilitate access to cyber security tools and services including where appropriate covered frontier models for agencies state and local authorities uh and criti critical infrastructure operators such as rural hospitals community banks and local utilities. That could be a major opportunity to get better tools into the hands of the defenders who need them most. At the same time, many smaller organizations still struggle with basic cyber hygiene, patch management, asset inventory, identity security, and limited staffing. How should this work in practice? What basic foundations n need to be in place so advanced AI enabled cyber security tools help these organizations r reduce real risk instead of creating more alerts, more confusion or more unmanaged responsibility. Miss Joyce?
Thank you so much for the question. And we are want to um uh compliment and uh the administration for uh really leading the way on the executive order. We have just received it, we're still looking at how we're going to be implementing it, we're looking at the details, but one thing we have often said is that we do believe that AI needs to be regulated and in we also think it's too important to not be regulated and it's too important not to be regulated well. So, when we look at s- critical infrastructure and those individuals who are on the front lines of providing services to day-in-day uh, you know, water, electricity, we think it's really important that we are able to support them with cyber security uh that they need. One of the ways that we think that can happen is through cyber security grants um that are going to be able to provide the know-how and the funding. No front-line defender in critical infrastructure should be left to their own devices to go toe-to-toe with nation states and cyber criminals. So we look forward to being a good partner in this, and we look forward to being supportive of American leadership in this space.
Mister Cable, would you like to res- uh also respond?
Yes. Thank you, Chairman, for the question. The good and bad news is that so much of security is low hanging fruit, and you do not need frontier models to address that. If we look at the stay in local governments, critical infrastructure owners and operators out there today, as you mentioned, there are many basic vulnerabilities that are on their networks that are open to exploitation from our adversaries. For instance, we continue to see a string of um exploitation of network edge devices um by foreign adversaries. And ultimately what many of these issues come down to is vulnerabilities in underlying software products in use by these entities. And my response to that is that these entities who produce these products in line with um Secure by Design ought to be doing more to deploy frontier models um in order to shore up the security of their products. And as I mentioned my opening statement, in particular, to do these large scale refactors needed in order to root out these entire classes of vulnerabilities. uh from their products. We called this SECURE by demand, by which critical infrastructure owners and operators, consumers of technology products could do more to put pressure on software vendors. I believe Congress has a role there as well, and this also underscores the passage of the the Pillar Act in order to give necessary resources to uh state and local governments.
Now this is just kind of a a a general thought, you know, that when you when you think about a regulatory framework for AI, how do we regulate AI in such a way to protect the consumer, the public, but yet not hinder ourselves against this arms race that essentially is against China? Miss Joyce?
I think that's the the work of today and the work of our generation right now. It's so important that we get this right. And this technology is so important to regulate in a way that's going to balance the safety and security of the models, and of the users that are using them, but also is going to support American leadership in this space. What we're seeing in my role as the Threat Intelligence Lead at Google, we are seeing every day how threat actors are uh attempting to abuse the uh AI models in order to carry out their schemes. And we publish very regularly, in an attempt to be transparent, the threats that we're seeing. In our quarterly AI threat tracker, for example, we recently published how threat actors are doing everything from d a prompt injection, to trying to manipulate um and and to create exploits using AI. And so we can see that the threat landscape is rapidly evolving, and we need to be able to meet the moment in that while balancing uh safety and security with bold and responsible regulation.
Thank you, ma'am. Uh, I now recognize the ranking member, the gentlewoman from Illinois, uh, Miss Ramirez, for her five minutes of questions.
Thank you, Chairman. Doctor Gorg Can you pronounce your last name again?
Uh, Gorglia.
Gorglia.
Gorglia.
Gorglia. Did I get it right?
Yes.
Good, good. You did an exceptional job, Chairman. Um
I had notes, I'm gonna be honest.
Even with mine, I still struggled here. Your work documents how the government's expansion of data collection surveillance capacity has justified repeatedly as a security or public safety necessity, has consistently been turned against the most marginalized communities. The question to you is, when we talk about building resilience in critical infrastructure through AI-powered monitoring and threat detection, how do we ensure that the architecture we're building in the name of protection doesn't become the next iteration of that same pattern?
Yeah, I Data, the storage, the Capacity to store data and to analyze data is infrastructure. It it by definition has multiple purposes.
Mm-hmm.
Um, it can be used for uh building critical re- uh resilience in critical infrastructure or it could also be used for compute power force surveillance. I think one of the things we've been thinking about is specifically narrowly terri uh tailoring the types of models that we deploy specifically for cyber security so that they are less general persi uh purpose models, that can be redeployed in other purposes for surveillance.
Mm.
Uh, so I think uh thinking about uh how to tailor both the digital infrastructure and AI models so that they serve one purpose without very easily being uh co-opted by DHS or other agencies for the purposes of surveillance and policing.
Mm-hmm. And you've written that America's privacy is currently being decided by contract negotiations between tech companies and the White House. not by congress we're watching that play out in life between the pentagon and anthropic right now so i guess my follow-up question to you is what does congress need to do to put in statue so that civil liberties protection doesn't depend on morality of billionaire ceos
yeah i mean at this level the question is not how do we reign in ai it's how do we reign in the agencies that would unleash ai on the american public Um, so with the Anthropic deal, what we have is a a contract negotiation uh in which one party does not want to do mass surveillance against Americans or claims not to, and the other party is insisting that their technology, their multiple purpose technology, be made available to them for exactly that purpose. And absent in that is Congress saying what the rules should be for how the government can deploy technology against Americans.
Mm.
So things like Uh, as I said, um, closing the Data Broker loophole, uh, reforming section seven O two of FISA, long-standing issues of American privacy and the Amer- the government's ability to collect data, need to be addressed first so that when AI is deployed, it does not drastically amplify those civil liberties violations.
Mm-hmm. Thank you. Well, let me ask you one last question and I I'll give you a little bit more time. We probably will have another round maybe? Okay. So, we're hearing a lot about a Gentec AI. the systems that can detect and respond to threats on their own, without waiting for a human to approve each decision. You've written about how technology vendors sell governments and tools, before anyone has actually even figured out what happens when something goes wrong. So I wanna ask you directly. If a autonomous AI system managing the cyber security of a city's water infrastructure makes a bad call, flags a clean system as compromise, shuts down access causes an operational failure who is responsible under current law
uh i i don't know who's responsible under current law yeah
yeah
and and i think part of the problem that we have is this transparency piece is that when when something goes wrong like like how does the um public find out about it where does the accounting come from i would i imagine have to rely on the transparency of the city because the proprietary models and the corporations are not going to be forthcoming with the american public and this is made exponentially worse once you take it out of the municipal level and you get to
mmm
the federal government where the national security has its own history of very impenetrable classification
so you're hoping for transparency of the city but that doesn't actually get to the accountability of who ends up being responsible it's the last question and see if you have any answer to and this is if the community is harmed as a result of this and has limited resources to demand the accountability, what realistic recourse would they even have?
Uh, I'm not sure.
Yeah, that's what I figured. Well, Chairman, uh, I have another question we can do next round, but I'll yield back.
The gentlewoman yields back. I now recognize the gentleman from uh California, Mister Fong.
Uh, thank you, Mr. Chairman. I wanna thank the witnesses for being here. Uh, certainly a very important uh topic with everything going on right now, um, in this upper security space. my first question i wanted to pose to mister cable um you know i had the i i chairman garbarino in my district we pulled together a round table um with schools hospitals energy providers water districts i represent urban centers and rural communities as well um and then i i i read that in the the time from a from a breach to an escalation is probably now mere seconds and so our cyber security defenders have to meet these machine speed attacks with machine speed defenses. So, a company like yours probably could take thousands of AI generated vulnerability findings and turn them into patches pretty quickly um but a rural hospital, a small utility, a county government, a water district, um they may see the same list and may not have a realistic way to keeping up. So how do you propose or what's what advice do you have in terms of how we prevent frontier AI from creating a world where companies can get uh patches, but smaller critical infrastructure operators may fall behind.
Thank you, Congressman, for the question. In order to get ahead of these issues, I I think about it in two ways, right, we have to both uh shift further right up the attack chain to deploy AI in order to better detect attacks better defend systems, while also shifting further left, right, into the very ways in which software products are being built to make them fundamentally more resilient. Our focus at Corridor is on the latter, at working with manufacturers of technology products to help them identify and prevent vulnerabilities in the development cycle. And we are seeing by doing that we can prevent vulnerabilities before they make it out into deployed products that are used by any consumers of software such as critical infrastructure owners and operators. But I think that there is also, right, this need for an increased focus to give these defenders who are increasingly both under-resourced and also subject to attackers who have more and more capabilities at their hand we really do need to foundationally shore up the security of these systems both in the short term through deploying AI capabilities that can prevent detect cyber-attacks but then in the long term by making sure that the products that they rely on are fundamentally more secure
And I wanted to probably pose the same question to you, Miss Joyce, uh, the the chairman uh mister ogles and i have talked about this i have military installations in rural communities out in a remote areas for a reason and so uh a cyber attack that affects the water supplier the electricity grid uh not only impacts the community but of course um our national security as well and so i wanted to maybe post the same question but then also add a second question which is um you know in terms of the integrity of our ai systems uh that is of course uh becoming a national security issue uh if our adversaries can manipulate the models, poison data, uh abuse AI tools for cyber operations, and undermine the trust in AI uh generated outputs, that certainly um uh those risks extend well beyond one company. So how do you how does your work um how do you work to secure the integrity of AI systems to advance our national security and what should congress do to understand the connection between model security, infrastructure security, and American technology leadership?
Thank you so much for that important question, and from a threat intelligence perspective, I can say that it is truly important to look at this. We have already seen Russia, China, Iran, and North Korea in some cases trying to or succeeding in embedding themselves in our critical infrastructure. So we know that this threat is happening. As we sit here today, we are looking at how these threat actors are embedding themselves, groups l from China, typhoon, for example, have already demonstrated capability and intent in this space. In my role at Google, what we're doing is actually looking at our Gemini model we have embedded inside of Google Deep Mind and personnel so that we can be on the front lines, and looking at the threats as they come in. When we find and get gain insights that we think will be helpful for defenders, it's p- particularly the ones who are in critical infrastructure, we publish those. We attempt to be very transparent about it. And so, as I said, you can look at our AI threat tracker that we have been publishing every quarter. We have years of AI threat reporting that we have done publicly to ensure that we're putting this these insights out and to those who need to use them.
Uh, my time is running out. Maybe we'll do it. I have some additional questions, so I'll wait for my second round. Thank you, Mr. Chairman. I'll get back.
The gentleman yield is back and I recognize the gentleman from Rhode Island, Mister Magaziner, for five minutes.
Thank you to the chairman and the and the panelists. Um, you know, as we think about the risks and opportunities posed by frontier AI models in the cyber security realm, the thought that keeps recurring for me is that we are very fortunate that Anthropic did the right thing with mythos, and that before this product that is incredibly powerful and and has demonstrated an ability to facilitate cyber attacks in in a manner that no other tool has been able to do before, before releasing this out into the world where bad actors could use it. They did the right thing by alerting the government, alerting key players in the tech space, including I I assume uh your employer, Miss Joyce, and working with them so that they could shore up their defenses before this product becomes available. But what if they hadn't chosen to do that? what if they or anyone else had chosen to just release this out into the world, where anybody could use it to extort ransom, to make critical infrastructure inoperable, to cause mass chaos, or what if they had decided to, you know, sell it to Putin first, or sell it to the highest bidder. I'm not saying that they would do that, but the point I'm making is that there is a real risk for all of us to just be crossing our fingers and hoping that the next time there is a new advancement in in frontier AI that whoever did that, you know, made that advancement just does the right thing again. And so, you know, I'm encouraged by the executive order this week, which establishes at least a framework for new frontier AI models to be vetted before they are released to the public. However, this framework in the executive order is still only voluntary. So we are still in a place where we are just crossing our fingers and hoping that the developers of ai are just gonna do the right thing and participate so i'll just ask any of our witnesses to to weigh in what do you see as the positives in this executive order what still needs to be done in order to ensure the safety of the american people as new frontier ai models are released and should we be moving toward a system a vetting system that is a mandatory one as opposed to just an optional one and I'll open it up to anybody who'd like to answer first.
Happy to take that first. Thank you, Congressman, for the question. It's my belief that the best approach to protecting our systems from continued improvements in frontier models is to deploy state-of-the-art models today to shore up our defenses. The best uh defenses that we have um can be made um such that for instance if we do a refactor of a critical piece of software into memory safe language we can ensure that that is uh free of certain types of vulnerabilities that frontier models today find and frontier models of tomorrow. Um so there are some of these secure by design principles right that if we build software products in the right way we can ensure that they are protected against whatever might come uh with future models. As to your question on the executive order I was glad to see that the White House took a voluntary approach uh to um securing the these frontier models. While I agree that it is crucial to make sure these capabilities get in the hands of the right defenders, um I believe that ultimately the um advantage does lean towards making these models more widely accessible to allow defenders to make use of them ahead of adversaries exploiting.
But let me ask you, I mean again, like say, and I don't wanna call out Anthropic here, any developer in this space, if they developed a very powerful technology that could be used to to cripple to cripple critical infrastructure to cripple financial institutions, what's to stop them today from just selling it to the highest bidder, and not giving defenders an opportunity to shore up their defenses with it first?
I I think part of the the answer there, sir, is that the open weight models, while they are not quite as good as the frontier models, they are quite close. They lag a couple months behind. But these capabilities are already out there and can be wielded by
i don't know i mean i uh just for cleaning my time i i don't wanna betray anyone's confidentiality here but i've met with some of the largest financial institutions in the world in recent weeks who have told me that with mythos they found thousands of vulnerabilities that they didn't know they had and if anthropic had not done the right thing and given them a chance to build up their defenses first the damage could have been incredible and so once again uh i'm glad to see that there's at least some federal framework being set up now in this executive order but to just keep kind of voluntary and let everybody make their own decision about whether to give defenders a head start or say sell this to Putin first for the high or to the highest bidder, I think is very dangerous. And it doesn't have to be an onerous vetting process. I think the executive order, you know, says a thirty day vetting process, but there needs to be some kind of a process. And uh we'll dig into this a little bit more when I get another round. So thank you.
The gentleman yields back. Um. You know, one of my concerns uh is China, so you know, AI coding tools are quickly becoming part of how software is written. If a coding tool is built on a PRC origin open weight model, the issue is not only who made the model, it is whether that model becomes part of a software supply chain for American companies. Should companies treat model provenance the same way they treat software? What qu- what questions should a company ask before allowing a PRC origin model into its developer environment? Mr. Royce, were you gonna lead off and we'll just go down the line?
Well, like I said, we really believe that um regulation is really important in this space, and we're seeing a lot of threats to the supply chain uh as we go along. I wanted to clarify one uh issue about the threat before we move forward, and that is that while certain tools that have been introduced recently are very um very prominent and we're talking a lot about them. The truth of the matter is we have seen cyber criminals and threat actors already be able to create harnesses, which is basically the software scaffolding around a model. It doesn't have to be a very powerful model to be able to already write exploits. So as we move along in this uh in this space what I what I want to clarify is the threat that these threat actors will be able to use these m- you know, new models. They don't even need to use new models to do what they're doing. They can use existing models, and we already observed how a cyber criminal had developed their own harness and was already writing their own exploit. They did not have access to the models that we've been talking about.
Doctor?
Um, I would actually um even move upstream a little bit to how those models are developed in the first place, and suggest that there's a lot more that I think needs to be done to be able to uh counter the use of adversarial distillation so that um the capabilities of those models if we're worried about them and the capabilities they have, um we need to protect the um integrity of the models we have and the capabilities we have by um uh trying to prevent uh the the distillation of American models uh by foreign-linked actors. Uh, and I would encourage uh, a robust discussion on on that front.
Mr. Kiel?
Thank you, Chairman. Um, I would say that, right, the reason that companies today are using these models from China is because these models offer the best performance. Like I mentioned in my opening statement, there are no frontier open weight models from the United States, and there are use cases where as a company building AI systems, you want to be able to, for instance, fine-tune models to work best on your use case. I would argue that the best answer here is to foster an ecosystem of open weight models coming from the United States that have safeguards in place that can then become the norm by which um others uh whether within or outside the US can build their technology and that is where I think that we can can counteract um some of the these um other models by having a competitive ecosystem here.
Mister uh Doctor Griglia?
Yeah uh I would just urge that um we think about US-based models in the same vein that we would those coming from places overseas like China in the sense that absent consumer privacy laws, absent more laws that govern how the US United States conducts surveillance on American citizens, both models run some sort of threat of jeopardizing civil liberty and the integrity of the American people.
You you talk a lot about uh the privacy of citizens, is seven O two written in such a way to protect Americans from uh AI in your opinion?
No, no, I mean the problem we have right now is that section seven O two is collecting all of these communications including those of Americans, and they are storing them in a big pot essentially uh where the IC has some restrictions over where and when they can access Americans' communications but the federal bureau of investigation does not. and they can query and look at those without a warrant. So with a large uh archive of American communications that the Federal Bureau of Information can access, uh my concern is that deploying AI in that sort of a space would allow them to sift through American communications without a warrant and also uh expose them to analytics like artificial intelligence.
Thank you. I yield back, recognize Miss Ramirez for five minutes.
Thank you, Chairman, I wanna follow up with the conversation we were having just a few moments ago. Uh, Doctor Gureglio. CISA is still racing to finalize its first ever mandatory cyber incident reporting role. Meaning right now the vast majority of cyber attacks and critical infrastructure go unreported. We were just talking about that a moment ago. We're talking today about deploying autonomous AI security
Yeah, I I think I think a a more robust infrastructure of communication between the federal government and affected uh entities uh as well as more resources dedicated to cyber security and dedicated toward uh hardening critical infrastructure uh and and to uh institutions like CISA which could build a more robust model for both monitoring and disclosure.
Mm-hmm. Mm-hmm. So, just following up on that, section seven O two of the foreign intelligence surveillance act expires next week and we're gonna be asked yet again to pass our reauthorization of this authority. As if we didn't have enough reason to be worried about section seven O two, the President has now appointed Bill Pulte, a partisan loyalist with no national security security experience as the acting director of national intelligence. He has a well-established record of abusing his position to target the President's political opponents. And now he, he's gaining access to more information about Americans through his new position. establishing yet another reason why we need real protections for Americans on how the government is gathering information on us in the name of national security. Doctor, my last question for you.
Well
How could new frontier AI models facilitate greater abuses of the section seven O two authority? And what reforms would you like to see in any seven O two reauthorization that would help mitigate those risks?
Thank you so much for that question, ranking member Ramirez. Um, I think, as I was saying earlier, I think the fear is that with such a large pool of Americans communications sitting uh and being able to be accessed by federal law enforcement without a warrant, that AI would make all of that data more easily to be weaponized against the American public,
Mm-hmm.
especially for political purposes is always the fear. Um, and so I think when we're looking at the reauthorization, uh, perhaps next week, one thing we have to think about is first and foremost a warrant requirement, that before uh federal agents want to access American communications, they should not only get a warrant to actually look at the content, but also to query how whether or not that database has communications by Americans uh by specific Americans in it. And I also think transparency is key here because when national security intelligence is used for criminal prosecution in the United States, oftentimes it is not disclosed to either the defendant or their attorney where that information came from and so they are unable to challenge it and so I think that transparency piece and a warrant requirement are essential not only to any reauthorization of section seventy-two of FISA but also to prevent the
Mm-hmm.
proliferation of AI in the federal government to uh being able to weaponize that data further.
Got it. So warrant requirement query into the information and transparency. Oh, the three. Thank you. I wanna make sure that I make that note. I'm gonna go ahead and yield back to the chairman. Thank you.
Gentlewoman yields back. Recognize the gentleman from California for five minutes, Mister Fong.
Uh, thank you. I wanted to um go follow up on the the chairman's uh question, which is um, uh, when it when it comes to the threat China poses, you know, we've seen China use low-cost technology to gain a global market share in other sectors. Um, it's it's it's scary to imagine a world where the default ai model in europe south america southeast asia africa and parts of the middle east is a is a chinese open way model because it's a it's inexpensive capable and easily to uh it's easy to run locally um maybe i would throw this to the to the to the panel but what leverage would china gain if uh prc origin models became embedded in global software development cloud services manufacturing robotics and critical infrastructure and what should the United States do now to avoid that dependency? I'll I'll anyone can can chime in.
I don't think there's prize for second place in the AI race, nor is there one in the quantum race. And AI, you know, American leadership in this space is truly critical. In my group, we have tracked uh the uh threat from Chinese cyber uh for many, many years. We understand that they are pre-positioned in our critical infrastructure, and the government has confirmed that there are no reconnaissance purposes for that, that the reason they're embedded in critical infrastructure is for a potential, um, kinetic action in the future, should they choose. So I think that the leverage that is would be gained by having this fundamental technology not be led by you know American innovation and democratic societies, would truly be around um something that we simply cannot tolerate.
Doctor, do you wanna have a do you have opinion on this, or if not then I can I can jump to another question that you for you.
I might um just speak briefly to how um some of their capabilities are being developed, uh and what we uh might be able to do about it. So uh again one of the core issues here I think is how um the trend lines uh between leading US capabilities or the capabilities of leading US models um uh and the capabilities of leading uh foreign models have collapsed right it it used to be kind of let's say a twelve to eighteen month uh gap in terms of when models would be released from the US uh and the capabilities they had and when you would see similar capabilities uh emerge elsewhere you know that trend line i think has collapsed down you know to four to you know six months something like that um uh In tandem with that um uh collapse of timeline, we've also seen the emergence and articulation of a really robust ecosystem that has enabled um the distillation of US models. Um, I don't think that those two uh facts are um unrelated. Uh, there's a lot I think that could be done uh potentially to try and counter that. Um, we the challenge is that the information that you would need to be able to do that kind of thing is distributed amongst a wide array of industry actors at present. Um, industry actors, um, like I can just speak for the FMF here, um, we have had to take a fairly conservative approach under - under antitrust law to even have a conversation about how to identify distillation. We have not had a conversation about how to counter it, um, uh, uh, given kind of existing antitrust, uh, concerns. Um, so the - I think there's some low hanging fruit in terms of, uh, what we might be able to do. um uh to address that issue in particular.
so if i can follow up doctor messerl does the united states need a trusted open way strategy uh where there's broader uh trusted access and um it is in so that um american allied models are available enough to compete globally
Um i will uh say within the context of the the frontier model form we've mainly focused on safety and security of models, and um uh So unfortunately I can't really speak to the development side uh of models.
Does anyone wanna chime in on that question? Mister Cable?
I I I would say that yes. I I as I mentioned before, right, I believe the best way to counter this is to have open weight models originating from the United States that are the best in the world. We already have closed weight frontier models that are the best. So so I believe it's a matter of putting proper resources into making sure that we can have uh similarly competitive open weight models.
Thank you. Uh, I th I think it's important to for all of us to understand that the future is here. The threat is here is is is not an academic conversation. So for for America to tread water means you fall behind. And I think that's why it's important that that we have hearings like this. So with that, I yield back.
The gentleman yields back. I recognize the gentleman from Rhode Island, Mister Magaziner, for five minutes.
Thank you. You know, on the topic of needing to stay ahead of China in the AI race, uh inevitably we keep coming back to the topic of why are we allowing the sale of advanced ai chips to china to help power their ai which can be used to attack us and so for over a year now every cyber security panel that's come before this subcommittee i've asked does anyone here think it is a good idea for the administration the trump administration to be allowing the sale of these advanced chips to china And if so, why? Every single expert panel we've had in front of us, no one has said yes, they think it's a good idea. Not one person. And I know that, I, and not only has no panelist said that it's a good idea, but no member on either side of the aisle, in fact, I know that I think every member, if not most members, think that this is incredibly dangerous. And we are not powerless in this. there is legislation, Republican-led legislation, to stop the sale of these chips. That has already passed out of committee, but has languished and hasn't made it to the House floor. We should take matters into our own hands, we should discharge it, we should do something, because nobody thinks this is a good idea from a cyber security point of view. Going back to um uh the issue of having a federal government role in vetting frontier AI m products before they are released to the market whether you believe that it should be voluntary participation or mandatory participation one question i think we need to answer is where would this function sit so my understanding is that under the executive order treasury is the primary nexus of this vetting function with input from other agencies i think there's legislation draft legislation that's been floating around congress i've heard that would place it at commerce Chairman McCall yesterday, when we had Secretary Mullen in, I think reminded everybody that when CISA was first created, this was the type of role in a less advanced context that CISA was envisioned to play. So, I I'd welcome feedback from everybody, because we gotta get this right. Whether it's voluntary or mandatory for AI developers to to participate in this sort of a vetting process before a product is released, where should that function sit, and who should be involved in making sure that it's successful. Um, I'll open that up to anybody. Please.
Um, I think one thing that I would say is, um, one of the things that we really, uh, encourage and have encouraged even, uh, a year ago in response to, uh, an RFI about, um, uh, the development of the AI action plan that the administration put together, um, was that there would need to be, uh, sophisticated expertise on uh evaluation and testing within government um and we were pleased to see um last year uh that the center for ai standards and innovations uh was kind of empowered to do a lot of that testing um uh and i i think um uh to the extent that there needs to be greater kind of public private partnerships uh in the development of this uh you know technology and an assessment of the safety and security of these systems um i think the thing that i would underscore is that it is hard to do that without relevant expertise um and uh i i think we've really welcomed the uh expertise that the kac has developed over the uh uh since it was created
mmm alright thank you um again just sort of thinking in terms of next steps building off of the executive order are there any other ideas or insights for things that we ought to do in order to make this successful so that as these products come to market there's consumer safety and an ability for defenders to defend themselves before the attackers are are able to exploit their vulnerabilities.
Sorry.
Thank you, Congressman. I would say that where where I I would like to see more is to move beyond just this element of you know identifying and one-off fixes of vulnerabilities. That's you know what ha has often been the predominant strategy is very necessary to do so right but at the scale we are operating you mentioned anthropic reporting fifteen hundred vulnerabilities via mythos, only six percent of those being fixed. I would argue that's not enough and I think we have to be thinking bigger right about how we can enable these large scale remediation campaigns refactoring software systems right will will it will take time and money but it al- is also the sort of thing that AI systems can help us with. So I think those are the sort of actions as well as preventing vulnerabilities at scale, as new software is being built with AI coding tools that are ultimately necessary and will allow us to upscale the the security of our systems.
Mm. Well thank you. You know I'll just close by saying that um I'm glad that Mythos has scared at least some people in the administration enough to take the issue of AI safety seriously. I think the hands-off approach from the last year was a mistake, and now in a thoughtful, collaborative way with industry, it's time for us as a federal government to take our job seriously when it comes close to, when it comes to, uh, protecting the American people. So, I yield back.
The gentleman yields back. I kind of want to piggyback on, uh, where you were going with this. Uh, when, when I think about, uh, China and the threat that China poses, when you think of a tool like Mythos, um, you know, in the event, whether it's to, you know, impact an election, to, uh, have adverse effect, on our economy, uh perhaps China's looking to do something in the Pacific, how real is the threat to our critical infrastructure, like energy, like water, that they could start flipping switch switches to create that internal chaos so that they can, whatever their goal or uh desired outcome might be. Anyone?
I think the threat is something that we have seen already present. for many years. We know that the threat is there. Uh, with AI models in particular, we've also seen that type of innovation, not just from uh threat actors in the, you know, China, North Korea, Iran, and and and others, but we're also seeing it in with cyber criminals as well. So often the threat from nation-states is more on uh reconnaissance, although in the case of old typhoon there's something a lot more uh concerning there. But what cybercriminals bring to the table is a lot more of uh sloppiness, a lot more recklessness in order to do things that are financially motivated. For example, we have seen them um extort, do ransomware, and with the latest report that we put out, we have seen them taking steps to even create their own harnesses and create an exploit using AI. So we know that they're making a lot of progress and we know that nation-states are posing these threats today. It's something that we see every single day.
Anyone else wanna chime in?
I I would just agree with that, in that we we've already seen adversaries exploiting these systems through campaigns like Volt Typhoon, Salt Typhoon, before AI, and we know that adversaries are leveraging AI to accelerate every step of these attacks. So to me that is all the more reason to double down on defense, right? I think the best approach here is for defenders to deploy AI systems and shore up some of the foundational, oftentimes relatively basic vulnerabilities that our adversaries are exploiting.
Going back to the profit motive, um, obviously you talk about the sophistication of the models themselves, and it doesn't have to be the latest and greatest to be effective. So what's the the threat environment for the jailbroken uh versions of ai that are out there and you know i think anyone of us with a little technical know-how can download and put on a laptop in a matter of seven ten minutes.
well what we have observed in the underground or the what some people call the dark web, is that a whole market place of advertising for so-called jailbreak you know bots of different kinds. uh something as low as ninety nine dollars a month you can go and and uh get that. Now some of those are not true, some of those are just criminals, you know, not being uh honest, as which is not a surprise to anybody. Um but what we're also seeing is a lot more uh advancement with cyber criminals. They're doing things that, you know, uh creating zero days, they're taking advantage of uh supply chain risks, crypto currency, so we're seeing a real vast marketplace um of of uh criminal enterprises both with scams and with other other elements. So much so that in my group we have started a disruption unit. And what we have been doing is operationalizing the intelligence that we have in order to take down and create coordinated disruption of a lot of these different infrastructure. So for example in January, uh Google's disruption unit took down something called the IP uh IP idea residential proxy network. And in doing so,
And the idea of disruption,
Mm-hmm.
uh, Doctor Mesereau, I think you mentioned antitrust uh regulation, is that a concern uh for any of you when you look at this marketplace of crossing and violating some sort of antitrust um you know current law? Are there reforms that need to be made in order that we can be more uh aggressive in protecting our country, quite frankly?
Uh I'd already alluded to this briefly, but I'd Under current uh antitrust guidance there's a li there I would say there's a lack of clarity about what actually can be done, um uh to the point again that we have not had conversations about how to counter um what what is happening um uh I think, having a a much clearer sense of what the um what can and can't be done would be useful.
You know, something to i if any of you have ideas uh to report back and and give to committee uh you can send them to me I would love to when we look at the regulatory form or lack thereof or the clarity, lack thereof, there's things that we need to be doing in anticipation of what the marketplace is going to need, uh, we are all ears. That's the purpose of this this hearing today is to figure out what have we gotten wrong and what do we need to do better going forward so any of you that have that type of input please forward it to me uh as soon as you can get it ready. Uh, with that, I recognize the ranking member, Miss Ramirez, for five minutes.
Actually don't have any other questions at this moment, but I really do appreciate the follow-ups that you just asked for. Thank you.
Yes, ma'am. Uh, well with that, um, we are nearing the end, I guess we'll just go down the line. We'll start on this end, since we've been picking on Miss Joyce the entire hearing, and just kind of closer remarks, uh, anything that we missed that you wanna, you know, kind of double down on, Mister Wrigley?
I I think just the one thing that hasn't come up yet, um that i mentioned in my opening remarks is the us government's own finding and exploitation of of zero days um and uh thinking about uh the integrity of american critical infrastructure uh as being undermined by the government's also their desire to collect as much data as possible and to keep those vulnerabilities open for the purposes of exploiting it for feature surveillance Um, and so thinking about uh how the NSA and the intelligence agencies' own desires to spy on Americans uh often undermines our own critical infrastructure.
And if you have any thoughts that you'd like to forward on those types of concerns, seven O two, again, thinking forward, uh, you know, last thing we wanna do is create Skynet or uh, you know, an observation tool that, you know, suddenly uh gets away from us but i do appreciate your input sir.
Absolutely.
Mister Cable.
Thank you Chairman and Ranking Member for the opportunity to testify today. As I mentioned I believe that we need to get ahead of these um issues so that each model release doesn't create an emergency right and I believe that we can do that by putting in place these foundational defenses across our critical infrastructure or s across the software products that we rely on, across open source software, and the foundational ecosystem that that is. And I believe we can use AI for these missions to prevent vulnerabilities in new code going forward by putting in place guardrails and to refactor existing code bases, to root out entire classes of vulnerabilities. So I would encourage the committee to focus on how we can get ahead of these issues, and I'm happy to work with you um to do so.
Doctor Mesrell.
Um, I think one thing I would underscore, uh, which I also alluded to in my opening testimony was just that the trend line here is pretty unmistakable. Um, and one of the things that, um, uh, I think one of the reasons why I think we need to strengthen our public-private partnerships and information sharing mechanisms, um, is so that when new capabilities come online, it is not coming as a surprise to the policy community. This is probably the the current moment, I would say, is the third time this has happened in the last three or four years where the first one being the kind of the GPT moment, um uh the second being the deep-seek moment a a year or so ago, and then now with mythos and GPT five point five. Um what concerns me is that to the expert community that is working on these issues, none of those things came as a surprise. Um and so um I think we need to develop, you know, again much closer uh and more tightly knit um information sharing mechanisms and and public-private partnerships to ensure that the policy community and others are getting the information they need and and understanding it ahead of the moment, uh uh as opposed to uh in response to it.
Well, and you know, to that point, you know, AI is advancing so quickly and let's let's be honest, Congress tends to move quite slowly, so I wou I would agree with you wholeheartedly that we've got to, you know, increase this the speed at which we're communicating so that we can react and it doesn't become an emergency every time we have a new release. Miss Joyce, final word.
I think we have said that this technology and AI is too important to not regulate, and it's too important to not regulate well. So Google stands by to be uh a useful and dependable partner in this space, as we support American leadership in these critical technologies.
I wanna thank all the witnesses for their testimony and members for their questions. Members of the civic committee may have some additional questions for the witnesses, and would ask and I would ask that the the witnesses respond to these in writing, pursuant to committee rule seven E. The hearing record will be open for ten days. Without objection, this subcommittee stands adjourned.
Morning digest
Start every morning briefed on yesterday’s hearings
A free weekday email covering yesterday’s hearings and transcripts newly unlocked in the archive.



