▶ 0:27:04The subcommittee will come to order. Without objection, the chair is authorized to declare a recess at any time. We welcome today our guests for a hearing on trade secrets and global in the global AI arms race. I now recognize myself for a short opening statement.
▶ 0:27:22Today's hearing addresses the core tension in the age of artificial intelligence, the push for disclosure balanced with the need to protect innovation that drive us leadership.
▶ 0:27:36And we'll there's a non-disclosure on the The proprietary algorithms that in fact train data sets are likely to be now and in the future the secret sauce. Not patented, not available to the public, but of such value that other nefarious actors will do anything to get them.
▶ 0:28:04Without strong protections, we risk sacrificing the very breakthroughs we aim to encourage. Some have called the sweeping AI disclosure mandates in the name of transparency. This committee has strongly believed and will continue to believe in transparency. But like anything else, a order is just a promise. And a promise that is historically not kept in fact has no value.
▶ 0:28:35We cannot require disclosure of trade secrets or proprietary data sets under the guise of transparency. Such disclosures would not only have a chilling effect on innovation but hand strategic advantage to foreign adversaries who do not play by the same rules. Consider this. The United States investment in AI is approaching a trillion dollars.
▶ 0:29:01China has invested not more than onethird as as much and is already neck-to- neck with the United States. Deepseek and other Chinese models are rapidly catching up to American companies. But let's look deeper. Deepseek contains models that clearly were taken from open AI and other sets.
▶ 0:29:24We know China's speed is not merely because they invest in It is also the result of IP theft, reverse engineering, efforts to circumvent US export controls and more. China has also weaponized our legal system by financing lawsuits that target American firms in expensive litigation and with the intent in many cases to mine that proprietary information.
▶ 0:29:55All the while, China continues to refuse meaningful protections on USIP in its own courts. I personally have been part of that recognition that they will not defend trademarks, patents, even when you go to the expense of getting them in China. Even if you make your product in China, you will not be protected. Lastly, American companies have a a reverse situation.
▶ 0:30:24One in which we are working constantly and this committee has worked tirelessly on a bipartisan basis to promote rocket dockets to in fact get the speed of decision to the lowest cost and the quickest time. Well, in China, you can be assured if you're an American company asserting your rights, you will go into the never never land of your case will come up someday.
▶ 0:30:51Efforts uh continue to include the need to prevent US engineers with access to specific sensitive AI systems from sideststepping non-competes and NDAs by working for Chinese firms. ensure the disclosure of regimes do not inadvertently reveal protection by mirroring EU style regulations.
▶ 0:31:15And I might say here a little off the record, EU as we speak is second-guessing their very disclosures. It is not it has not escaped us that the AI act of Europe in fact was a great step forward and as we speak many are pushing to take at least a small step backwards and with that I'm delighted to introduce my ranking member for his opening statement. Thank you Mr.
▶ 0:31:45117 days ago, Chinese company Deep Seek launched its flagship model Deep 6 RO1. In the following days and weeks, American experts rung their hands and shook their heads, many considering for the first time the possibility that we may be losing the so-called AI arms Deep Seek claims RO1 was developed faster and cheaper
▶ 0:32:15than comparable US models. Others argue Deep Seek at a minimum violated OpenAI's terms of service to obtain proprietary training data. Where everyone seems to agree is that AI startups should be innovating faster. I've heard colleagues suggest we should forget regulations, ignore IP laws, and just focus on clearing the way for AI companies.
▶ 0:32:45I agree everyone wins when we foster American AI startups. But I think it's a false choice to say we can succeed only if we do so you excuse me, if you walk around the Capitol today, you can see plants sprouting out of the soil, beginning to grow.
▶ 0:33:08What you'll notice if you look closely is some of those shoots growing in the shade look like they're growing faster than the others. as they race for just a little bit of sunlight. Yes, they grow quickly, but ultimately they grow less hearty, more brittle, and prone to disease. AI innovation works the same way.
▶ 0:33:33As we seek ways to promote American AI startups, we should also work to ensure that businesses meet minimum standards for system cyber security. We should ask what types of transparency are necessary to protect other IP rights and consider how to set standards while still protecting trade secrets.
▶ 0:33:54By encouraging companies to meet best practices and respect intellectual property rights, we will foster hearty competition that protects US innovation from those who seek to undermine our success. The government of China has made no secret of its intent to steal American intellectual property and there is bipartisan agreement that the United States should protect its innovations from those who seek to benefit from ingenuity.
▶ 0:34:25There is al also a right way and a wrong way to compete with our While we don't always agree on this committee, we have had meaningful discussions on the right to protect American IP from the government of China, cyber security, cyber security standards to keep our people and our safe and the threat landscape to AI
▶ 0:35:00Donald Trump, on the other hand, has acted in ways that hurt American businesses. His ideologically inconsistent and unpredictable tariffs have hurt American consumers, American businesses, and our allies. Innovation in America suffers when the path forward uncertain. For generations, American companies have benefited from attracting the best and the brightest from other nations.
▶ 0:35:28Yet, seemingly without reason, Trump again and again hurts American businesses by attempting to revoke already granted student visas and threatening and threatening the H1B visa program for highly skilled immigrants. The dilletterious impact of these policies on AI innovation should not be ignored.
▶ 0:35:53According to a recent study, immigrants founded or co-founded 28 of the top 43 AI companies in the United States and 70% of full-time graduate students in fields related to artificial intelligence are international students. So instead of focusing on policies that stand to derail American innovation, we should focus on upholding our treaties and respecting our allies.
▶ 0:36:22We should encourage our research institutions to engage with universities around the world. The breakneck speed of innovation has made it easier than ever to reach out to people around the world. Now is not a time for isolationism because history has shown us that true innovation thrives on openness. After all, groundbreaking inventions rarely emerge when knowledge is walled off.
▶ 0:36:50I thank the witnesses for being here today and I yield back. Gentleman yields back. We now recognize the ranking member of the full committee for his opening statement. Thank you very much, Mr. Chairman. Uh and thanks to the witnesses for joining us. I'm happy to participate uh in a rare hearing on the important bipartisan work of this committee. We don't agree on a lot these days, but the importance of the US intellectual property regime to American innovation is indeed a value that we all share.
▶ 0:37:20Um, but even with this agreement in Congress, the executive branch has injected terrible uh into our intellectual property regime. Innovation depends on stable and predictable rules that people can rely on to secure their inventions and property rights, manufacture their products, and attract investors and consumers to their businesses.
▶ 0:37:43But instead of fostering a stable atmosphere which allows people to innovate, the Trump administration has hampered creativity. Since he was inaugurated, Trump has revoked federal research grants to universities where scientists make significant new discoveries every year. He's tried to take over some universities. He's tried to cancel student visas.
▶ 0:38:04Uh last time he was president, of course, he increased the denial rate for highly skilled immigrants who work in engineering, computer programming, and at research labs in highly technical fields. Already in the first quarter of this year, uh, Donald Trump's trade war against the world, except for Russia, has reduced the US gross domestic product. It's raised prices on consumers, and it's encouraged businesses to hoard goods.
▶ 0:38:29Chaotic tariffs that change from day to day make it difficult for businesses to plan ahead and result in them taking fewer risks. Companies are then less likely to invest in ideas and innovators are in turn less likely to strike out on their own. We may never know what inventions, life-saving cures, worldchanging businesses are being sacrificed at the altar of Donald Trump's helter skelter and lawless tariff agenda. We should also remember that inventors and creators aren't just big businesses.
▶ 0:38:57The heart of our IP system are parents tinkering with an invention at the kitchen table after putting the kids to sleep, aspiring songwriters waiting tables to pay the bills while chasing their dreams, and engineering students researching the next big idea. Yet now all of these people are having a tough time in Trump's America, a place where hope of that next big break feels further and further away. Investing in an idea is a risky proposition, but it's even riskier for the individual who has to go it alone.
▶ 0:39:27Finally, in most cases, intellectual property ownership is only as good as the ability to enforce that right in court. Every rights holder should be worried as we watch the all-out assault on the judicial branch unfold. A judicial system that doesn't work for everyone eventually won't work for anyone and that includes IP owners. Despite these threats, the US IP system is still lauded around the world for its ability to spur innovation and creativity.
▶ 0:39:52That is in part because our founders chose to promote innovation by protecting the rights of individual creators. Federalist 43, Madison wrote that the utility of the intellectual property clause will scarcely be questioned and in the case of patents and copyrights, the public good fully coincides with the claims of individuals, rewarding individual discoveries and creations has allowed innovation to flourish.
▶ 0:40:17According to a recent study, the US is home to over half of the more than 10,000 AI startups across the 10 countries leading in AI. We should be proud of our AI leadership, but we must also take steps to protect American trade secrets from competing nations that seek seek to steal our technology. Some have referred to the push to develop the most advanced AI model as the AI arms race.
▶ 0:40:41Now there's nothing wrong with uh competition in this sense but when other countries threaten US cyber security, steal our inventions and conduct economic espionage against US companies as the government of China has done, that is cause for serious scrutiny. Just because we all agree AI systems should be secure from foreign threats does not obiate the responsibility of course for AI that AI platforms have to other rights holders and to consumers.
▶ 0:41:09Jack Dorsey and Elon Musk both recently made the claim that we should delete all IP law. Uh I think that we can all emphatically reject that notion. America's intellectual property system has not just made us a global leader in AI. Its very foundation created the careers of those two men. Intellectual property is the engine that powers our economy, drives innovation, jobs, and growth at every turn for all inventors big and small, including Dorsene Musk.
▶ 0:41:36Without a strong IP system, we risk losing the very spark that has made us such a leader in global innovation and opportunity. I look forward to hearing from our witnesses today and I thank you, Mr. Chairman, and yield back. Without objection, all other opening statements will be included included in the record. It's now my pleasure to introduce our panel of witnesses. Mr. Nicholas Anderson. Mr.
▶ 0:41:59Anderson is president and chief operating officer of Invidus International Consulting Company uh which provides technical services for national security systems. He previously served as chief information officer for public sector at uh Lumen Technologies and served at the department of energy office of management and budget and the department of navy coast guard and served on active duty as United States Marine which I presume means that he has been
▶ 0:42:29to Camp Pendleton in my district. It is a right of passage. Dr. Benjamin Jensen. Dr. Jensen is a director of future labs and a senior fellow at the defense and security department at the center for strategic and international studies. He is also the Frank E. Peterson chair for emerging technologies and a professor of strategic studies at the Marine Corps University. I knew I knew you'll laugh for a reason. Advanced warfare. Dr.
▶ 0:42:59Jensen previously served as a senior research director uh of the US Cyber Salarium Commission and is a reserve officer in the United States Army. Double dipping. Mr. Christopher Moore. Mr. Moore is president of the software information industry association uh and uh say a collection of entertainment consumer and business software companies.
▶ 0:43:28He previously served as senior vice president for intellectual property and general counsel at that organization and continues to serve as the chief legal officer for the association. Miss Helen Toner. Miss Toner is director of strategies and foundation research grants at Georgetown Center for Security and Emergency Technology.
▶ 0:43:51She previously served as senior research analyst at open philanthropy where she advised policy makers and grant makers on AI policy and strategy. Dr.
▶ 0:44:08John Velo sior fair not great uh is professor of electrical engineering law public policy and management at the fac and and the facility co-director at the institute for technology law and policy at UCLA. professor works and is work is focused on technology and law related to artificial intelligence, digital communication, computing, network and cyber security and privacy.
▶ 0:44:39We welcome our witnesses here today and pursuant to the committee's rules, I would ask that you all rise to take the oath and the right hand is always good to use. Do you do you solemnly swear or affirm under penalty of perjury that the testimony you will give will be true and correct to the best of your knowledge information? Please be seated.
▶ 0:45:04Let the record reflect that all witnesses answered in the affirmative. Now, the part you've all seen on C-SPAN, we'd like you to stay as close as we can you can to five minutes. the lights on in front of you uh will will count you down and indicate when you're close to and then finally when you've hit five minutes.
▶ 0:45:26Rest assured that not only will all your opening statements in their entirety be included in the record, but additional information that you provide or that later you provide uh pursuant to questions or things which stim are stimulated from our discussion. So you really get hours and hours. You just get five minutes up front. Dr. All right. Thank you, Chairman, Ranking Member Johnson, members of the subcommittee. I mean, before I start, I view my job here today to really help frame a larger conversation.
▶ 0:45:57And that conversation really is about the defining competition of the 21st century. And that is the race to shape what we're starting to call agentic AI. So, when I say agentic AI, I'm not just talking about everybody playing with an LLM here or there or narrow imagery recognition. I'm talking about the next level where all of these applications start to work together and they start to generate actual knowledge, influence our decisions and even help us manage complex tasks at scale.
▶ 0:46:28U frankly, whoever leads this agentic AI race is going to shape the rules of the future international order. And I'm not being hyperbolic. I sincerely mean that. If you talk about the efficiencies, the economic growth, the changing questions of governance, we are literally at a historical inflection point which made it so good to hear you bring in the federalist papers because we almost have to really think at that level about these tasks. The stakes could not be clearer.
▶ 0:46:54Um, this is not just about AI as a tool of human flourishing or who makes more money or who makes a better poem with an app. This is really about whether or not this is going to be a mechanism for authoritarian control or a way to really embody and propagate the best traditions and values upon which our republic was founded. Um, and I really mean that about the stakes.
▶ 0:47:16And frankly, while America has been the leader of this, the pioneer, you can go back to the invention of the term artificial intelligence at Dartmouth, all of the early engineering from from Cornell to other universities, as you point out, this kind of basic research plus the beauty of capitalism working together. But frankly, that's under assault. The People's Republic of China is exploiting our economy and our innovation ecosystem.
▶ 0:47:40Beijing is basically conducting a coordinated strategy that siphons off intellectual property, circumvents export controls, and exploits legal gaps with state directed theft and replication. Chairman, what you accurately characterized as weaponizing our legal system against us. And I think for at least today, I want to talk about three ways this strategy unfolds. Um, some technical, some more general. So first, through knowledge distillation and what's called unbounded consumption attacks.
▶ 0:48:10Chinese firms replicated US foundation models. So think um OpenAI's chat GPT at a fraction a fraction of the cost. Not talking a billion dollars to develop a model. We're talking millions of dollars. So a significant economic difference. And essentially what they did is they harvested the outputs of American models definitely without permission and used them to build their own versions like Deepseek. Bluntly this is not innovation. This is intellectual looting.
▶ 0:48:38Um, second, through state sponsored cyber espionage, Chinese AP, advanced persistent threat groups like Silk, Typhoon, and others target everything from our cloud infrastructure to semiconductors. And increasingly, this isn't just random smash and grab hacking. It's a calculated campaign to steal what free societies and free people create. And third, despite export controls, China continues to access critical chips and software.
▶ 0:49:02export controls have utterly been feudal up to this point and really make us have to rethink like what what is our defensive playbook and what is our offensive playbook. Um through loopholes, third party countries and subsidies, they keep advancing while American firms face regulatory burdens and shrinking market access. In short, the current approach is not enough. Export controls and AI diffusion policy do more economic harm than good.
▶ 0:49:28And as you pointed out, Representative Johnson, we really have to protect those smaller innovators. So how are we going to balance that? So if the Chinese Communist Party and its network of little giants and firms with parties to state control are using this playbook of steal, copy, accelerate, what do we do? Well, first, America is never powerless. Uh we it's time that we act decisively and we preserve our AI leadership. And I think there's three things that we can discuss along those lines. Uh first, we modernize intellectual property laws.
▶ 0:49:56And I think that we have amazing experts to talk to you about that. We need to address techniques like knowledge distillation and API ads. Um, and we need to basically coordinate globally. So it's not just in US courts, it's other free society courts where we can bring this to bear. And we even start to imagine, I love that you brought up again Federalist 43. What would that look like written in 2025? And what would that look like if a legal scholar using an LLM wrote it as a basis for us to start this conversation about what are property laws?
▶ 0:50:26Second, we may need to start treating AI companies like critical infrastructure. Their products support national security, economic competitiveness, and global influence. And those designations means that you can work cross jurisdiction with other subcommittees and other committees to start to think about tax credits and other incentives that get you what you were talking about. How do you defend their IP? And I'll close with saying we go on the offense. Um, lawsuits alone will not deter coordinated statebacked BIP campaigns.
▶ 0:50:54So we have to prioritize the type of intelligence collection that can be declassified and turned into legally admissible information that can be used to hold China accountable in multiple courts and frankly even consider the type of offensive cyber actions that makes them think twice about stealing from America. So in closing, this is way more than about company profits. It's about free societies and not authoritarian regimes assuming leadership of the coming AI century.
▶ 0:51:22And so I thank you for your time and I welcome your questions in the comment period. Thank you Dr. Vle Sor chairman Isa ranking member Johnson now the little button in front when it turns red it's a good sign chairman isa ranking member Johnson ranking member Rascin members of the subcommittee thank you very much for the opportunity to testify here today I should mention at the outset that I'm testifying in my own individual capacity and I'm not representing any organization America
▶ 0:51:52is the clear global leader in AI a technology that is foundational to our continued economic prosperity and national security. The competitive differentiation that is so instrumental to the success of the US AI industry is vulnerable in several ways. First, precisely because American AI companies are so innovative and market leading, they are ripe targets for trade secret theft. Secondly, policy discussions regarding AI regulation here in the United States often give insufficient consideration to the potential collateral damage to trade secret rights.
▶ 0:52:23Given the enormous attention to generative AI products such as chat GPT, it's important to keep in mind that AI is much more than generative AI. The recent advances in other areas of AI are equally impressive. For instance, AI is revolution revolutionizing drug discovery. AI is also at the core of algorithms that enable autonomous vehicles to navigate complex city streets. Collaborations between humans and AI is promising to bring improvements to medical image interpretation.
▶ 0:52:48AI can extend the human capacity to create new inventions and will revolutionize logistics, weather forecasting, and many other fields. And AI is critical to ensuring strong national defense. Overly expansive transparency rules would undermine AI leadership. Uh, exhibit A for that would be, for example, the now revoked executive order issued in October 2023, which would have required some AI companies to file with the government information about the physical and cyber security measures used to protect their model weights.
▶ 0:53:18Clearly, if the government were to maintain databases like that, those databases would become essentially a target list uh for cyber espionage armed with the information hacked from those databases and those databases would get hacked. then uh state sponsored actors could more easily enter uh the systems of uh leading AI companies. There are novel trade secret issues arising from the adaptive nature and complexity of AI systems.
▶ 0:53:44Because AI systems learn from their environment, they can operate in ways that can be elusive even to their designers. This creates some really important and interesting questions. First, can creators of AI systems have trade secret rights and algorithms they do not understand? I believe that the answer to this question is yes. Suppose that a company builds an I AI system that through adaptation has evolved to the point where an algorithm it is executing is quite different from the one initially envisioned and programmed by its employees.
▶ 0:54:13After the adaptation process, the company employees no longer know how the algorithm works, but they do know that it works extremely well for its intended purpose. Does this algorithm qualify as a trade secret owned by the company, even though no human knows what it is? In my view, it does. Second, how can plaintiffs assert misappropriation of trade secrets they don't know? Well, the answer is that asserting trade secret rights in an algorithm will require describing it, which requires plaintiffs to learn it.
▶ 0:54:37It will not be sufficient for plaintiffs to state in effect, we're not sure how our AI works, but whatever it is doing, it's our trade secret, and the defendant has misappropriated it. Rather, plaintiffs will need to provide enough detail for a court and a defendant to know what specific trade secret is at issue. I would also like to briefly mention the global context. The preeminence of American AI companies creates an asymmetry. Policymakers outside the US may have less concern than their US counterparts about the collateral damage to trade secrets resulting from AI regulations.
▶ 0:55:06They will have little incentive to regulate in a manner that preserves the competitive advantage of US AI companies. Finally, I would like to briefly comment on AI regulation more generally. In the past several years, there's been a steady drum beat of calls to aggressively regulate AI. Sometimes this is motivated by the premise, which I disagree with, that AI is an existential threat to humanity.
▶ 0:55:26Sometimes it is motivated by the view, which I also disagree with, that the best way for government to respond to AI is by subjecting it to an extensive new regulatory regime aimed at slowing AI down so that it can progress only as fast as policymakers allow. If adopted in the US, this approach would directly undermine American AI leadership as there are other countries including geopolitical rivals that will certainly avoid adopting policies centered on the goal of impeding AI development.
▶ 0:55:52It is also important to keep in mind that there is already a thicket of nonAI specific law and regulation that will apply to AI. For example, the use of a discriminatory AI system to make home loan decision decisions would already be unlawful under the Fair Housing Act. In closing, I would like to thank the members of the subcommittee for the opportunity part to participate in today's hearing and I look forward to your questions. Thank you, Mr. Moore. Mr. Chairman, Ranking Member Johnson, Ranking Member Raskin, and members of the committee.
▶ 0:56:22Uh, on behalf of SIA and its members, thank you for this opportunity to share our views. SIA represents over 350 companies in the business of information. Our members range from startups to some of the largest and most recognizable corporations in the world. For over 40 years, we've advocated for the health of the information life cycle, advancing favorable conditions for its creation, dissemination, and productive use.
▶ 0:56:47Our members create educational software, search engines, e-commerce platforms, legal research, and financial databases, and a variety of other products that people depend on in their day-to-day lives. We're the place where information and technology meet and occasionally collide. SIA was founded on the premise of respect for intellectual property rights, especially around software. For decades, we helped our members enforce their copyrights against infringers, something we still do.
▶ 0:57:15Today, our members are building AI into many of their products and services. They actively use it in their media operations, in the classroom, in fraud detection, in market data, in moneyaundering investigations, and in locating missing children. They've invested billions in its development, acquisition, and use. They also have intellectual property rights undergirling that investment, including patent, copyright, and trade secret rights.
▶ 0:57:40As both software and information become increasingly sold as services, the threat from IP theft has evolved. The most valuable part of technology may not be in simply copying and using it, although that's certainly a threat, but in figuring out how it works. Our members welcome competition within the bounds of legal rules. The problem is that not everybody follows them.
▶ 0:58:04From the very first days of the adoption of the trips agreement in 1994, our members have had problems with state sanctioned IP theft by the PRC. Now, the PRC has stated that it wishes to lead the world in AI by 2030 and reduce reliance on foreign technology. It intends to leverage the communist system and achieve that leadership in key areas including smart devices and speech recognition, image and video recognition and financial services to name just a few.
▶ 0:58:33Unfortunately for us, and to mix metaphors a bit, the dragon has not changed its stripes. It is actively involved in the theft of trade secrets in several ways. From the use of insider threats to cyber attacks to forced technology transfer to investment in US startups to conditioning market access on the divulging of proprietary information. Legal rights are not the problem.
▶ 0:58:57Congress has adopted substantive rights governing trade secrets in the United States and a global framework to respect those rights. What is lacking is a means to sufficiently incentivize the Chinese government to abide by those protections or to provide means to enforce those protections. While there is no perfect solution, Congress has tools that it can and should develop to further protect American AI development from foreign theft and possibly sabotage. We would suggest four areas for congressional attention.
▶ 0:59:28The first is cyber security. Building and updating infrastructure to keep up with emerging and evolving threats is a constant project. Large companies have cutting edge systems that they can use to protect their products and users. Smaller businesses lack such resources. The government should continue to explore ways to help them.
▶ 0:59:46Second, Congress should ensure that the Committee for Foreign Investment or CPHAS continues to serve as an effective way to address trade secret risk by making sure that its scope of review remains adequate to address those risks. Third, Congress should assist the administration in working with our allies and partners to build AI in infrastructure on trusted providers. Adoption of Huawei and other PRC located providers creates an unreasonable potential for trade secret theft.
▶ 1:00:16Finally, while the legal framework for protecting trade secrets is welldeveloped, an emerging area of concern involves the exploitation of the US legal system to gain unauthorized access to trade secret information through third party litigation funding of patent disputes by sovereign wealth entities. The landscape around AI and intellectual property is constantly evolving and as a technology continues to advance, new threats will emerge.
▶ 1:00:42That pattern is unlikely to stop anytime soon and we commend the subcommittee for continuing to monitor these issues and engage industry. Thank you for your consideration of our views and I'm happy to answer any questions. Thank you, Miss Toner. Chair is ranking member Johnson, Ranking Member Rasin, and members of the subcommittee. Thank you for the opportunity to testify.
▶ 1:01:02My name is Helen Toner and I'm part of the founding team at CEST, the Center for Security and Emerging Technology at Georgetown, where for the past six years I've focused on AI and national security, US China competition over AI and AI safety and security issues more broadly. It's a cliche that AI is hard to govern because the technology is moving so fast. But there's one important thing about AI that is actually quite predictable. It's only getting more capable, more powerful, and more strategically critical.
▶ 1:01:29This is especially true of what gets called frontier AI systems which are the focus of my testimony. Frontier AI is a term for the most cutting edge general purpose AI systems like Google's Gemini 2.5, OpenAI's 03 or Anthropics Cloud 3.7. The companies at the AI frontier are actively working to build so-called artificial general intelligence or AGI which roughly means AI that is as smart as a human or even to build super intelligence which is AI far more capable than a human.
▶ 1:01:56The CEOs of these companies claim that they'll get this far within the next two to five years. And this is not just marketing hype. Many top researchers agree. Even if two to five years is overly optimistic, the possibility that major tech companies could build human level AI anytime in the foreseeable future should galvanize us to take action now. What action? If we agree that AI's strategic importance is already high and will only grow from here, I want to note two vital national security interests that follow from that.
▶ 1:02:26First, for the topic of this hearing, the US government has a critical national security interest in protecting the trade secrets and IP of leading US AI companies. Second, there's also a critical national security interest in understanding and monitoring the development of Frontier AI as it moves towards AGI and even super intelligence. The most important point I want to make today is that these two critical priorities, security and transparency, do not need to be in tension with one another. We can pursue both in parallel.
▶ 1:02:55My written testimony lays out the kinds of trade secrets that are most important to protect, primarily AI models themselves as well as the algorithmic secrets used to create them and data sets and hardware related IP as well. I also lay out the areas where we most need transparency. These are things like testing for capabilities and risks of new systems, the goals that AI models are trained to pursue, safety and security risk management practices within the frontier companies, data on their internal use of AI, and whistleblower protections for their employees.
▶ 1:03:25Notice that there's not much overlap between the things we most need to keep secure and the things that we most need to bring into the sunlight. Where overlap does exist, we have options. information can be shared with governments via secure channels or it could also be shared only with thirdparty independent auditors who work under NDA inside company's own facilities. I would make the following five recommendations to this subcommittee and to Congress. First, fund and expand security collaborations between the US government and frontier AI companies.
▶ 1:03:56There are several small-cale voluntary programs that have recently been started, including threat intelligence sharing with the intelligence community and voluntary testing for capabilities that are relevant to national security. These initiatives are highly valuable and should be strengthened and expanded. Second, on transparency, you can use existing authorities or create new ones to increase visibility into the most advanced AI systems being built by frontier companies.
▶ 1:04:21Many of these companies have already made voluntary commitments to share safety and security information so Congress can ask them about how those commitments are going and make sure they're fulfilling them reliably. There are also existing authorities that the government can use to compel disclosure if necessary. New legislation could enshrine transparency requirements targeted for AI or create whistleblower protections for AI company employees. Third, invest in the technologies and infrastructure that we need to ensure that strategically critical AI systems of the future stay secure.
▶ 1:04:52This could include R&D funding, public private partnerships, or demonstration projects that push forward things like secure by design hardware or highly secure data centers. Fourth, consider giving companies permission to prioritize security in ways that are currently legally fraught. One example here is creating safe harbor from antitrust concerns specifically for collaboration on safety and security issues.
▶ 1:05:17Another possibility would be to enact legislation that makes it easier for AI companies to engage in intensive personnel vetting and monitoring to reduce insider threats. Fifth, in your interactions with AI companies, press them on what their cyber security practices look like and how they're working to improve. Use your bully pulpit to impress upon them that this is a critical question of US security and competitiveness. The United States cannot lead if adversaries have easy access to our best technology. Thank you and I look forward to your questions.
▶ 1:05:47Thank you, Mr. Anderson. Mr. Chairman, Ranky Miner Johnson, Ranky Mener Raskin, members of the subcommittee. Thank you for the opportunity to testify today. My name is Nick Anderson. I served in senior cyber security leadership roles in the previous Trump administration including as the principal deputy assistant secretary and performing the duties of the assistant secretary for cyber security energy security and emergency response at the department of energy.
▶ 1:06:11I've also served in white house uh as a white house cyber official as state chief information security officer and a chief information officer in the intelligence community. All of that is to say uh that I'm not before you today as someone who can provide intensive IP legal analysis, but as a national security and cyber security professional who spent nearly two decades defending this country, often against the adversaries who are now racing to dominate the future of AI. Chief among them is the Chinese Communist Party.
▶ 1:06:40Almost as a mirror image as we sit here just last week, Xihinping presided over a pullet bureau study session on AI. Let me be clear. The People's Republic of China does not simply seek to compete with us. It seeks to overtake us. And in doing so, uh, it's not going to be through fair market competition. It's going to be doing so through theft, deception, and the systematic targeting of America's innovation base.
▶ 1:07:05The tactics used by Chinese intelligence services and statebacked actors include cyber intrusions, insider recruitment, deceptive investment strategies, and the use of academic partnerships as cover for espionage. This is not speculative. It is confirmed through multiple indictments by the department of justice and ongoing intelligence assessments from the office of the director of national intelligence. The AI community, particularly companies building dual use technologies, have become a top target. And yet, our national defenses remain inconsistent.
▶ 1:07:35We do not require minimum security baselines for companies building next generation models. We do not vet outbound investments that may expose sensitive technology. We do not hold venture capital or private equity firms accountable for facilitating access to strategic industries by foreign adversaries. This must change. I support efforts to codify these outbound investment screenings, strengthen cyber requirements for federally funded tech firms, and require public disclosures when there's foreign ownership or influence in American AI companies. This is not about isolationism.
▶ 1:08:05It's about discipline, strategic clarity, and the courage to act before it's too late. During our previous years and last administration, we took bold steps to harden our infrastructure and disrupt adversary operations. This results driven approach, including with offensive cyber operations, must return. I believe we have two to five years to close the most dangerous gaps. Beyond that, we risk losing our technological and strategic edge, possibly for good. AI is not just an economic issue, it's a national security issue, and we must treat it accordingly. Thank you for the opportunity to speak today, and I look forward to your questions.
▶ 1:08:36Thank you. We'll now go back and forth between the majority and minority beginning with the gentleman from Wisconsin. um Mr. Anderson, AI infrastructure is is not currently treated or identified as critical infrastructure for cyber security purposes.
▶ 1:08:57Um should we rethink whether AI is actually critical infrastructure and if so, what would that mean for uh from a cyber security Thank you for your question. Uh the the short answer is is yes. Uh the longer answer is we have lots of technologies that when we previously considered critical infrastructure designations, things like cloud computing and uh artificial intelligence companies that were previously not considered to be critical infrastructure.
▶ 1:09:23Doing so today would give us an opportunity to examine minimum cyber security requirements would bring them into the fold for larger strategic planning and lash them up with communities like uh DHS's the cyber security and information and excuse me the cyber security and uh infrastructure security agency uh to be able to engage in information sharing operations uh these types of things I think would help to underpin greater security in these critical infrastructure industries. Very good. Thank you Mr. Moore.
▶ 1:09:52stakeholders have raised concerns about difficulties in protecting trade secrets during litigation. Uh what is the standard process for protecting trade secrets in court cases specifically? Well, t typically what happens is that there is a protective order and uh the in other words when the uh when the def the defense the accused party has has a right to defend themselves
▶ 1:10:22and they have a right to know okay what are they being accused of stealing and so if it is a trade secret and it leaks out for example on a court docket then the secrecy is gone and it's no longer valuable. So the what the judge will do is balance uh a number of factors and typically write an order that restricts access to the trade secret and makes um makes sure that uh the the information doesn't leak out into the public domain. Right?
▶ 1:10:53So if the risk of trade secret leakage increases as the use of third party litigation funding continues, especially like a patent case or other technology, um what would be kind of the scope of the requirements in and around that? How do you protect yourself? Well, the the scope is is really is really left to the discretion of the trial judge.
▶ 1:11:17But from our point of view, the more information the the more information the trial judge has, the better an order that the judge is going to be able to write. So for example, suppose you knew that one of the parties, let's take this, it's a third party litigation funded lawsuit. It w it is a um a party that is funded by the Chinese government.
▶ 1:11:40Uh, and if you have if you're the judge and you're crafting a protective order in that case, you would write a pretty you probably write a much more severe one than if you thought it was just a a couple of local dry cleaners fighting over a formula. It might that that protective order might look very very different. You might have, for example, personal liability for the attorneys, uh, which has a way of focusing the mind, uh, if any of the if any of the information were to leak out.
▶ 1:12:09And there's a number of things the judge can put protocols into how in terms of how the information is used, how it's stored, under what circumstances, and who can see it and how that access is logged among other things. Very good. Thank you, Dr. Villisar. Why is trade secret protection important to AI development compared to just any other type of IP protection?
▶ 1:12:33uh I guess specifically like many of us have heard testimony this morning between the US and China as well. Why why is that? Why is it important? Well, trade secrets are important across the spectrum of of industries, but they are absolutely critical to AI because uh even in the case of you might have heard these systems that are described as open systems, the open AI systems, they are still enormous amounts of trade secrets that go into that.
▶ 1:12:58In other words, if somebody releases the model weights, for example, as open, they wouldn't necessarily release how they train those model weights and what the training data was used. And so, and and they're not going to often release the source code. And so, there's an enormous amount of of trade secrets in AI, just like there is in other areas as well. But with AI, it's particularly complex just because the sheer size and magnitude of these systems is so large that there's just more opportunity to build, you know, an incredible amount of trade secrets.
▶ 1:13:24So I think that's without trade secrets, we do not have the ability to maintain our AI leadership. That's that's that's what the investment is going into and that's what the companies are being valued for. And I'm guessing because China is so secretive in that the way they've the way they view this that it makes it even more difficult when it when it comes to specifically seeing exactly what they're up to. Is that correct? Well, I I think the the open system that we have here where companies make their own choices about what to reveal and what to keep secret is incredibly powerful and the and the the proof is in the pudding.
▶ 1:13:54We are unquestionably the country with the leading AI ecosystem and I don't think that's an accident. Thank you, chair. I yield back. Thank the gentleman. We now recognize the ranking member of the subcommittee, the gentleman from Georgia for his his questioning. Thank you, Mr. Chairman. Uh, Miss Toner, the prospect of seeding American technological leadership to China is often used as an argument against implementing regulations of any kind on AI. Do you agree with uh that approach?
▶ 1:14:26No, I I do not believe that we should say that the need to beat China necessarily means that we cannot regulate AI ourselves for several reasons. The first and most important reason is that regulation does not actually need to slow down our industry whatsoever. Um well-designed regulation can actually even support industry. So AI is an industry where there are huge problems with consumer trust. Right now there's been some data showing that um products that list that they involve AI will actually be trusted less by consumers.
▶ 1:14:54Consumers are used to um experiencing these hallucinations and reliability issues that we have with AI. So I think there are ways in which if you can use regulation to build consumer trust by making them know that they're going to be interacting with high quality products um and likewise know that they're going to have recourse if something goes wrong um know that they are not just out there on their own. Um that actually can be can be very industry boosting. So that would be the primary reason that I think this is not a good argument.
▶ 1:15:18I think um people making this argument uh this argument that we can't regulate because we might then lose to China also tend to neglect the uh pretty hefty regulations that China is enacting on its own AI ecosystem um and also uh I think sometimes overestimate the uh the quality of the Chinese AI ecosystem which is certainly competitive with the US but I think not poised to you know overtake and run far away from us anytime soon.
▶ 1:15:42Uh so no I think I think it's really important um to protect our citizens to uphold our democratic uh institutions and and way of life um and also to support the industry itself that we put in place um smart guardrails. Mhm.
▶ 1:15:56What um what makes you so confident that um China is not poised to overtake the US in AI development and what are uh some of the ways that regulations can hurt uh the pace of innovation in America, AI innovation in America? Sure. I'll take the questions in reverse order. So I think AI is a rapidly developing technology.
▶ 1:16:20I think if we were to go ahead and try and create, you know, regulations that were sort of a checklist of if you're building AI, you have to do these 12 steps that a government committee came up with um and then they don't get changed. You know, they don't get adapted. Um they're not responsive to specific cases. I think regulations that really are very prescriptive and and limit uh what companies can do or force them to use procedures that would not be competitive, that would not be productive. So, we should not be not be going that route. Um but there are many other kinds of approaches.
▶ 1:16:47So for example uh looking at transparency and disclosure that doesn't need to force you to build your systems any particular way simply to share information about what you're doing. To your first question about uh Chinese competitiveness this may be an area where I I differ a little from some of the other witnesses present today. I think honestly the biggest advantage that the US has right now is our access to compute.
▶ 1:17:07So computational power advanced AI chips and I think the export controls while they have been um uh imperfectly applied and imperfectly enforced I think they have been a huge success uh or at least have the signs of being a huge success um if if we carry out if we continue to um to enforce them and and keep them in place. Uh one example of a signal for this is that the CEO of deepseek has made very clear that access to compute is the biggest limitation for him.
▶ 1:17:33So I think um the way that they were able to train the the system that made such a splash um was using a large number of chips that they imported in the gap between an October 2022 set of export controls um and then they bought a bunch of chips throughout 2023 and then in 2023 those chips were also restricted and so they were now no longer able to buy the kind of chips that they used to train that system.
▶ 1:17:56So the way that the export controls will work is not just a matter of um uh you know do a few of them get slipped through. It's really a question of um the volumes that we are able to produce outside of China. Um we need to also be looking at the semiconductor manufacturing equipment. That's a huge piece that often gets neglected. So this is not just preventing export of the chips themselves but preventing the machines the exquisite very expensive machines that are produced only by a very small number of countries that are US allies.
▶ 1:18:23um preventing those and actually enforcing the the protections on those would also help protect um the US advantage. So um happy to have a longer conversation about the export controls, but I think that is a huge advantage right now. Thank you. Uh Dr. uh Villisor, um would you agree that not all AI transparency obligations implicate trade secrets? Uh yes, that's that's true. There will be some that would not, but many would, but some some that don't.
▶ 1:18:49Is there a way to craft policies such that the disclosure requirements necessary transparency can avoid touching on trade secrets? I I think in general it is possible but it probably depends on the sector. AI spans all these sectors and so the answer can be different depending on the specific se sector. Thank you. I'm out of time. I yield back. Gentleman yields back. We now go to the gentleman from Kentucky for his questioning. Thank you Mr. Chairman.
▶ 1:19:16Which of the witnesses is proposing that the government should take some kind of action? Raise your hand. Okay, Miss Toner, what is uh what is the action that you think the government needs to take? So, uh I have several suggestions. Um perhaps a top priority would be to expand the current voluntary collaborations that are being undertaken between national security parts of the US government and the US's leading AI companies.
▶ 1:19:45So there are some early efforts right now. Um they include um threat intelligence sharing with the intelligence community. So they are working handinhand in similar ways to how they do with critical infrastructure providers or our defense industrial base to ensure that when there are incoming threats when we do have statebased actors trying to infiltrate our US companies. They're trying to find unclassified ways to ensure that the companies are aware and can prevent those threats and defend against them. There's also very valuable uh collaborative testing going on. Um, which which direction is most important?
▶ 1:20:15The government sharing information with the companies or the companies sharing information with the government? Uh, I think they're both very important. Um, perhaps if I had to pick one, I'd say the government sharing information with the companies, but I think there has also been um valuable threat reporting from the companies as well. There's also been within the Department of Commerce um a dedicated institute, the AI safety institute that has been again on a voluntary basis working with some of these leading companies to um to test their new most advanced systems.
▶ 1:20:41So these are systems where the companies themselves say we think they might soon be able to aid in the creation of bioweapons. They might soon be able to help not very sophisticated hackers hack into US critical infrastructure. Um they might pose other threats. Um uh and there are ways in which having access to classified information, classified expertise allows the government to actually um help those companies do tests that they want to be doing anyway. Do you think the collaboration should be compulsory? Uh no, most likely not.
▶ 1:21:10Um, but it should certainly be resourced and and authorized and uh expanded. Uh, Dr. I guess you were seeing in my eyes I'm more the small government guy. Um, I think you're seeing broad agreement on a number of things, but you did raise your hand. I did a little tipsy tipsy. Uh, we do have which concerns me. Just kidding. We'll settle it over. I'm interested in your answer. Yeah. So, I would say this. You have broad agreement about the need to provide cyber security.
▶ 1:21:38Now whether that's an incentive from the government and then there's some minimum viable standard that industry is held to or whether there's more of a government can reach in and monitor everything from the employees to the company to you know push someone what becomes like voluntary sharing becomes volunttoled sharing um and so I would tend to think we agree on quite a bit here but let's talk about that split difference because showing our differences is important for you all as a committee and I would say I tend to think that
▶ 1:22:08smaller less government is what's important because that's what's actually allowed these companies to grow, these companies to thrive. Now, we have to balance that against that you have a large predatory communist state that is directly targeting them.
▶ 1:22:22So there's a question of what is the federal government's national security obligation to protect US persons and companies versus not overreaching with regulation to have them spending the marginal dollar to hire attorneys or to invest in some system that they're not spending in the lab trying to develop a new edge to the frontier model or some new component. So that is a really hard balance to strike. So, I don't envy your job, but I'm glad you're all going to do it because it means the basic protections that even the federalist papers were talking about.
▶ 1:22:52It means thinking about what does it look like to declassify sensitive intelligence information where we document this so that it's admissible in our courts or in courts and other free societies. So, I think what you're seeing is we broadly agree on the need to help companies help themselves with cyber security. We broadly agree that the federal government has a role. We might disagree on the extent of that role. Um and then we also agree that these companies really are going to define our economic growth and prosperity into the coming century.
▶ 1:23:21I have another question and probably Dr. Villis, you might be the one to answer this. Um are AI companies um looking to use trade secrets because patents aren't necessarily um conducive to protecting their intellectual property. It's a great it's a great question. There's a subset of of innovations that could be protected either as trade secrets or patents. But trade secrets have a far broader scope.
▶ 1:23:50They can protect far more. There are plenty of things that are protectable by trade secrets. For example, you know, long lists of files of source code. You can't just get a patent on a million lines of source code, but that source code is certainly a trade secret. And so there's an enormous amount of intellectual property that is not protectable as a patent, but that is nonetheless vital to the value and value proposition and differentiation of the company. Is isn't the biggest u trade secret risk here is somebody just comes in and hires the employees.
▶ 1:24:20Uh well, I would hope that employees would would you know respect their confidentiality obligations. It is certainly the case that we have had problem there have been problems like that, but I think that's one risk. There's hacking. Um there's many risks to trade secrets. Thank you, Mr. Chairman. I yield back. Thank you. We now go to the uh ranking member of the full committee, Mr. Rascam, for his questions. Thanks, Mr. Chairman. Uh continuing with you, Dr. Villisor.
▶ 1:24:45Um many of the AI models incorporate open-source code, coding that's publicly available into their models. How does this affect their ability to assert uh a trade secret claim? Well, it's it's a really good question.
▶ 1:25:00I I think it depends in part on how they've incorporated these open- source uh sources for example, but it is certainly possible to have a system that had some component that was based on open source, but that also has a lot of intellectual property that's created independent of that and there would be trade secret value in that and for example on how they in integrate that with open source information. So I wouldn't conclude or I wouldn't believe that the presence or the use of open source would eviscerate trade secret rights for the companies that use it.
▶ 1:25:30All right, Dr. Jensen, do you agree with that that you can still maintain uh some kind of uh trade see some actionable trade secret claim even if you've been using open- source code as part of your programming? It's hard. And this is why again I want to stress that idea of going on the offense. Um, and this is where it definitely gets outside the jurisdiction of this committee and gets really in more into what's the rights of the executive.
▶ 1:25:54I think you are going to have to find ways to potentially sabotage the most malicious offenders that you identify as linked to a foreign government going after you because you can protect it. He's right with the larger trade secret, but then it becomes only a matter of time before they put the pieces together. And if you have someone engaged in industrial size like generation defining theft, you can't trust that person.
▶ 1:26:16So where is the balance there of how you actually take other measures that are again outside this jurisdiction to start to hold those companies countries accountable and then undermine it? That's the only way I think it's going to work. Okay. Meron, you've advocated for transparency requirements for developers of uh high stakes AI systems including transparency for training data, capability testing, safety testing, risk management, safety cases and so on.
▶ 1:26:43um what does transparency mean in this context and what is its purpose in these different areas? It's a great question. I would just clarify I would not necessarily advocate for transparency over training data, but the rest of the items that you listed certainly um I think there's different purposes and different forms it can take. So the simplest form of transparency is transparency to the public. I think this has a very broad range of benefits. It um means that it's already transparent to governments because governments can access anything that is public.
▶ 1:27:09But it also lets a broader set of academics, experts, um employees of of companies who might be affected. It just it just really empowers the public to understand the stakes of this technology and how the technology is changing over time. Um which I think is important given that it is going to affect all of our lives very profoundly and perhaps in in sudden and unexpected ways. A different form of transparency is transparency to government. Um so there's some kinds of information that maybe are not suited to be public. Maybe we want to keep them protected.
▶ 1:27:35um and uh that could particularly be relevant for national security relevant information. So for example, I think a big area of concern right now is the potential cyber security capabilities of the most advanced models, whether they're going to um make critical infrastructure systems more vulnerable than they have been in the past. Maybe that's not something that we want disclosed publicly immediately, but it is an area where partnership with government makes sense.
▶ 1:27:58a third form of transparency which is maybe transparency is not quite the right word but I think it's important to also think about the ability to bring in independent third parties into these companies and provide independent oversight or independent verification of some highstakes claims they're making. So if they're saying that they're running certain kinds of tests that they're performing certain kinds of safety protocols. Can you bring in a third party under NDA to work inside the company's own facilities? That might allow you to get a little bit of additional independent verification so you're not just taking the company's word for everything for these high stakes claims they're making. Great. Thank you, Dr.
▶ 1:28:28Jensen. Um, the Washington Post reported that tech companies uh or some tech tech companies are telling their employees on visas not to leave the United States out of concern that they won't be readmitted to the country or they could be stopped at the border. Visa holders are obviously running a lot of tech tech companies. They're uh working at startups. They're key in the field. 70% of graduate students in AI related fields are believed to be international students.
▶ 1:28:57So, if the Trump administration begins to deny H-1B visas um as he did in the first term, what will the consequences be on American AI innovation and on these business? Well, I'll start with this combat veteran. It'll cut my lab in half. Um, literally of the three people I employ, I would it cut it at four people counting me total, I would lose two of them. Um, and I think I'm a microcosm compared to the size and scale of how this could ripple through the American ecosystem.
▶ 1:29:26That doesn't mean that we don't have the right and the executive doesn't have the right to determine how best we, you know, seal our borders and determine, you know, very complex immigration questions, but I think we have to have a really hard conversation as a nation about what really is the major competition of the 21st century.
▶ 1:29:42If it truly is AI and AI becomes the focal point of grand strategy, then these immigration discussions have to be taken as part of that and we're going to have to find some areas of bipartisan agreement or compromise or we're going to have to really double down in investment in STEM education which is going to even take longer and we have to figure out how it works. Now I just say one note quick about transparency to double down. There's a really interesting point of transparency.
▶ 1:30:06So my lab we do benchmarking um and you're going to need almost a toquevillian civil society function where whether it's just naturally happens or it's incentivized by the people's house independent groups not government not business come together and hold company models accountable. So in our case, we actually do the hard work to say when a deepseek or a Gemini responds with escalatory responses on a data set trained on standard international relations and foreign policy decision-making.
▶ 1:30:36That's just one example. So it's not just transparency in the ways we've discussed. It's also let's get creative and think about all of American society and what are the ways civil society can be incentivized to organize organically from below and provide checks on us because I don't think benchmarking can just be the government that'll lead to overreach and it can't just be companies because that'll lead to kind of skirting claims and there's there's perverse incentives for either the government or just firms.
▶ 1:31:02So transparency needs to also include civil society and us thinking about what does that benchmarking look like conducted through voluntary American associations. I appreciate that. I yield back. Mr. Chairman, that was a great round of questioning. I appreciate it and I appreciate your answer on broadening transparency. With that, we go to the gentleman from South Carolina, Mr. Fry. Thank you, uh, Mr. Chairman. Dr.
▶ 1:31:25Jensen, uh, to continue with you, you would agree that AI is uh one of our most critical tools in strengthening national defense. 100%. And in in that same vein, um, would that translate if if we were a leader in that, would that translate to superiority for our defense capabilities and our war fighters on the battlefield? Uh, great question.
▶ 1:31:47And I can tell you honestly, so as a chair at Marine Corps University, for really the last two and a half years, we've been experimenting with how could you use AI to help Marines plan better. So no more eaten crayons. Uh time to actually get down with the code. And frankly, we found tremendous strides. But this is actually why it's a complex answer to this. It's not just a function of the engineering. It's how you actually change professional military education and training to make officers and enlisted personnel understand that technology and know how to ask the right question.
▶ 1:32:17What makes us the best fighting force is that we care about our people. We invest in them. We challenge them. We pull them from all ranks of our society. So in an era of AI, that also means ensuring they have the requisite technical education and we've given them the ability to work with algorithms to augment military decision-making. So, it won't just be enough to be an AI superpower to, you know, give a trillion dollars to one company to give us widgets.
▶ 1:32:41It's going to be the harder investments we make in our people, how we change our training pipelines, and how we simulate future battles. To to what extent do you think that Chinese espionage is undermining our national defense capabilities in in the space of AI? Yeah, daily, if not every second.
▶ 1:32:58Remember they have proven that you can mass steal your way into the 21st century through intellectual property theft both with hackers but also we heard about it today these third party purchases of firms through insider recruitment they've got a deep wellestablished playbook so number one that changes our cost to innovate every secret they steal changes the marginal cost for the next innovation it's cheaper for them more expensive for us number two it also gives them sensitive data on how best to defeat our systems.
▶ 1:33:28So this is why we have to probably come up with entirely new concepts of how we secure data and how we secure training data because the worst thing we would want is they actually steal every experiment we've done with AI in a military training setting and actually statistically analyze our patterns. Most people when they're fighting have tells boxers know this, but it's true at larger order combat formations. We all have patterns and if you can see the enemy's pattern, you can conduct a spoiling attack or some maneuver to offset it.
▶ 1:33:58And so we have to make sure they can't use our patterns through seeing us in that technology to exploit in the battlefield. Well, how do we do that? I mean, in in dealing with espionage and trade secrets. Yeah. Um, what kind of protections do you think would be most important to ward that kind of incursion by the CCP? You know, um, this is where the lawyers don't get mad if I say this. I'm going to put more of my war fighting hat on. I think number one, we probably have to get really creative with almost creating entire digital terracotta armies.
▶ 1:34:26Why shouldn't it be that every US military personnel isn't in three to four paces simultaneously, only one of which is real? So, your adversary, even if they can see you in a transparent global competition, doesn't know what's real. It means we're probably also going to have to get pretty aggressive with data poisoning, knowing full well that there's real risk of that blowing back on us given how these models are trained. Um, but these are really the core counter intelligence and operational security questions of the 21st century.
▶ 1:34:54And that's doubles back to if you don't train your intelligence community and your war fighter how to answer these questions, we're never going to develop in the military the policies. And then we're going to have generals testifying before you who don't know what they're talking about. Now, I think we can do better than that. I think our military will do better than that, but it requires that technical training, that pipeline, that space to experiment. Thank you for that, Miss Toner. Um can you uh briefly explain China's thousand talent program and uh does it specifically target US scientists and AI professionals?
▶ 1:35:25So the thousand talents plan is only one of many a very large number of uh talent plans that China uses to try and recruit um recruit talent in in critical industries. They certainly target AI both the thousand talents plan and and other plans. Um and they're certainly making the most of the current administration's um effects on US immigrant and immigrants in the United States. So there's a lot of I think interest among people who are currently here on visas in whether their future in the US is secure.
▶ 1:35:52And you can bet that China is making the most of that both with plans like Thousand Talents and also offering you know lots of resources for research um uh you know great cushy jobs. Um they're they're certainly stepping in there. Do you think that th those recruitment efforts have led to the leakage if you will of trade secrets uh or sensitive technologies from the US and other western countries? Certainly in in the AI industry broadly I think as has already been mentioned one of the biggest sources of trade secrets being leaked is simply employees moving from one company to another.
▶ 1:36:21This happens inside Silicon Valley between you know Google and and OpenAI and other similar companies. Um but certainly if you're able to hire employees from those companies and get them to come over to China that's going to have the same effect. What can we do to close that security gap? Just briefly, I know my time's expired, but I wanted to get to that. I think uh you know, one piece here would be for people who are doing it intentionally and are doing it maliciously. Um that is where some of my recommendations around personnel vetting could come in.
▶ 1:36:49It's very important that that not become a broader anti-immigrant sentiment though because as um as Dr. Jensen has already laid out, um the contributions of foreign nationals to USI competitiveness are are immense. Thank you for that, Mr. Chairman. I yield back. I thank the gentleman. We now go to the gentle lady from North Carolina, Miss Ross. Um, thank you, Mr. Chairman, and ranking member for holding this hearing. I apologize for being a little late, but we had a hearing on quantum computing um that raised many of these same issues. The best part is you arrived just in the lick of time.
▶ 1:37:19Yeah, there you go. Um, so anyway, Dr. Jensen, um, Deep Deep Seek's rapid AI advancements have sparked debate. Um, and I wanted to know whether you think they are driven by local innovation or replication or theft of American research. Where do you think they come from? Uh, it's straight up stealing.
▶ 1:37:44Um, and we can give different verbs to describe theft, but it's how they did it that's important for us to provide the right type of protection. So again, the idea is if I'm going to basically basically do these attacks where I exploit your ability to pull data and ask a question to one model to shorten the amount of time and the amount of computational cost to train my model. It's a minimum a legal gray area, but I really do think it's that and I defer to the legal experts on that.
▶ 1:38:12I think what's more important about deepseek to take stock of is I think stealing your way into the 21st century as awful as it is is still subject to diminishing returns and why we can still win and will continue to. And I say that because our benchmarking study we tested deepseek was actually prone towards escalatory responses in a foreign policy scenario. So 66,000 unique question and answer pairs in 400 scenarios. And even worse, it was horribly biased against the US and the UK.
▶ 1:38:40Now you might say that's a mirror into Chinese Communist Party leadership, but any mirror like that that has a bias is actually a weakness we can exploit over time. So that's why benchmarking becomes so important because you want to understand the tendencies in these models and then an open society with an open market there will be commercial incentives to update those models whereas a closed society excels only at lying to itself and that's actually going to put them a strategic deficit. Can I comment on that as well? Oh absolutely. Yeah, I apologize.
▶ 1:39:10But just to to respectfully disagree with the assessment of of what DeepS did here, I think it's really important. There has been plenty of overstating of the sophistication of what they did and how advanced their AI system is. But it doesn't help us to understate it either. And I think it's important to describe what it is believed that they did in terms of distillation, which is the technique they used. Um, this is a very common technique that a lot of US AI developers will use as well. Essentially, it's using a more advanced AI model to get some answers and to use that as part of your training data. and I don't have any inside information.
▶ 1:39:39So, you know, we'd have to look at the internal investigation OpenAI is running. But the what's available externally suggests that they have just done a pretty regular standard of pra standard practice um procedure as one small part of their overall um process for building this model. And I think it's important that we not underestimate um the the level of engineering sophistication and research that they did bring. They were genuinely innovating here in addition to making some use of OpenAI's models. I believe according to evidence we have um again in a way that I think is a legal gray area is is correct.
▶ 1:40:08A legal gray area and and very commonly done by by many USI developers as well. Thank you for that addition. Um back to you Dr. Jensen. Drawing from your analysis of technology diffusion, what indicators uh patent citations, talent flows from US labs, or codebased similarities would signal reliance on external knowledge versus organic R&D in China.
▶ 1:40:34So, I love this question because you're getting at the heart of what does it mean to be an AI superpower and how would you measure it and then how could you as elected officials look at those measures and determine the right mix of legislation or even the right type of of budget allocations to go forward with and I think a few stand out even before whether it's externally or internally driven one triadic patents absolutely um are always going to be a key one second even though it we can't necessarily always draw a direct link even if it's there's a correlation I do
▶ 1:41:04think STEM education is critical as well as basic research um investments. There are certain categories of research frankly that it's just not commercially viable for companies to invest in. Um, in fact, most of our more interesting technological developments really in the kind of postworld war II vanavir bush moment come from our willingness to take risk in basic research on universities and then finding the right type of whether it's through defecting protecting it with patents but then also commercial incentives for those researchers and then entrepreneurs
▶ 1:41:34to roll those out. So what are the real measures will be those things in my opinion and then you'll know if it's really coming up because there's only so much of that you can steal. So, we um just came I just came from the science committee and we are actually seeing NSF grants being cancelled if they have a quote DEI connection, which to me is a way of cancelling investment in talent in underserved communities because we have talent everywhere
▶ 1:42:05in the United States. Could you comment on that? Sure. Briefly, if you would please. Yeah, I'll be very quick. For me, first it starts with basic research. And true DEI in this case means we just really want good researchers. And you're right, they come from everywhere. So the debate here would be whether trying to preface certain communities inadvertently undermines the commitment to treating everybody by the content of their character, not by the color of their skin.
▶ 1:42:28So how we first my first priority would be increasing that basic research investment and then figuring out how we make sure we have research ecosystems that are distributed across America so we can find all that talent where it is. Thank you and I yield back. Thank you. I thank the gentle lady. No problem. We now go to the gentleman from Virginia for five minutes. Thank you Mr. Chairman. Uh Mr. Anderson, trade secrets are often described as one of the most important tools for fostering innovation.
▶ 1:42:53In your view, how critical is the protection of trade secrets for the continued advancement of AI technologies, particularly in the context of US companies trying to stay competitive with foreign players like China? I I believe it's exceedingly critical. Uh, you know, being able to safeguard, you know, the secret sauce, if you will, of of how we're how we're going about our business is exceedingly important.
▶ 1:43:14Uh, and I'm as uh as I probably can be, but you know, when I left when I left home and deployed to Iraq and left the wire uh to go out on patrol, I didn't look at having to put on a flat jacket and kevlar and be conditioned one with my rifle as an over overly burdensome regulation. I looked at it as a recognition of the operating environment that I was in. And I think engaging in both good cyber security practices and being able to protect protect trade secrets is exceedingly important to maintaining our edge.
▶ 1:43:45Given China's rapid advancement in IIA in AI, what steps should the US take to protect its AI innovations from theft or exploitation by foreign adversaries especially considering the open AI ecosystem that may facilitate such So I think uh first and foremost it's engaging in good good cyber security hygiene. Uh you know I brought this up up very briefly uh with regard to the earlier question about critical infrastructure.
▶ 1:44:11You know our technology companies whether it's an AI company or cloud computing companies or some of the more generic developers in the market are critical infrastructure and moreover the the information that they're producing today is critical to both our economic success and our national security. So good basic cyber security hygiene whether it's looking at CMMC and what we're doing with the defense industrial base or how it would apply within this industry segment personnel screening and vetting and again outbound investment screening.
▶ 1:44:39Make sure we're not unwittingly or wittingly investing in a way that's going to harm US national security interests is critically important. As Congress considers AI transparency legislation, how do we strike the right balance between disclosing enough to ensure AI systems are safe and understandable without undermining the incentives for American companies to keep innovating?
▶ 1:45:03Um, so I think that's a that's exceedingly tough to do to balance uh balance the you know the require for disclosure versus uh versus again keeping keeping sort of your secrets in house. uh in my mind uh you have to develop sort of red line thresholds of what information is important and what information needs to be disclosed. Uh in particular focused on uh those critical technology security areas that we've identified as high risk.
▶ 1:45:29So in my mind it's about bounding things in that appropriate way not necessarily asking for full disclosure and full openness in a way that would degrade competitiveness within the environment. Are there lessons that you've learned from your experience in cyber security risk management that could inform disclosure frameworks that uh would be created for AI systems without compromising proprietary data?
▶ 1:45:52Well, I think you uh if you look at u you know legislation that's existed for the past uh decade, things like CISA 2015 which has allowed for uh private industry to be able to share more openly with the government and participate in threat intelligence information sharing. I think that's a good model. Now that's up for renewal this year. Would you make any adjustments or changes or I think there's always opportunities for improvement, but I would certainly uh support its re its reauthorization.
▶ 1:46:18Uh just just to be completely honest, just because I don't want to have one more opportunity for a company's general counsel to whine to me about uh about liability protection issues, uh it's anything we can do to continue to encourage the private sector to share information, I think is is fantastic. Any other panelists want to comment on uh the reauthorization of CISA 20 CISA 15 that's coming up this year? Okay. All right. Uh Mr.
▶ 1:46:47Moore, uh from the software industry's perspective, what trade secret protections are most critical to ensuring that American AI companies can continue to innovate without fearing intellectual property theft, especially by state backed Thank you for the question. The it it there are several areas where the trade secret doctrine uh can apply. uh it can apply to the algorithm itself.
▶ 1:47:16uh professor Villisenor raised a very interesting a really interesting point for example about how if for example one of these algorithms were found not to be covered by the trade secret docu doctrine because nobody understand it understands it. It's basically a a black box but it's something that was kept secret and kept for commercial advantage. That would be a legislative gap. That would be a problem.
▶ 1:47:40um the but the it can apply to the algorithm, it can apply to the training data, it can apply to you know perhaps a specific configuration of the chips used any number of um pieces of the of the Thank you. I yield back. Thank you, gentlemen. Mr. Anderson, if I can briefly just ask one question. You noted you're going over the wire, through the wire, uh, and wearing your your armor.
▶ 1:48:09Isn't it true that not everyone wears the same amount of armor and that in some cases if you wear every piece that they manufacture, you won't be able to move sufficiently fast to accomplish the mission? Yes, sir. I think that's that's absolutely true. You know, we I couldn't say just because I'm going into a potential armed engagements, you know, in Fallujah that somebody who's a police officer here in DC should be walking around with the same amount of body armor.
▶ 1:48:33There's still potential for threat engagement there, but the operating environments are different and the, you know, the requirements need to be tailored to what specifically is going to be useful both for the operating conditions and the risk. I thank the gentleman, gentle lady from California is recognized for five minutes. Thank you, Mr. Chair, and I want to thank the ranking member. Um this has been a really interesting discussion.
▶ 1:48:53Um but for me it remains uh abstract if we're also not talking about the available human capital uh and the talent investment that is needed. I have a young person getting ready to go to college. I've been talking to college students. Um, I've actually been talking to a lot of engineers in this space who are worried about their prospects for employment and also their ability to stay here and to contribute to building our edge in AI. Um, Mr.
▶ 1:49:23Chair, I would like to submit for the record a January 14, 2025 White House AI talent report. Without objection, so ordered. It warns that international researchers may increasingly choose to work in countries like Canada or the UK due to visa uncertainty. And we know that nearly 50% of non-citizen AIPDs face immigration challenges and many are unsure if they will even remain here. So, Mrs.
▶ 1:49:49Toner, if we continue to make it harder for top talent to stay, what are the strategic risks to US innovation and our ability to protect those innovations through trade secrets? The biggest thing I would say is that talent is a huge asymmetric advantage for the United States. We're in systemic competition with China and in different elements, we have different levels of advantage. The ability to attract the world's best and brightest is one of our very biggest and most asymmetric advantages over China.
▶ 1:50:18they are graduating more and more PhD students, master students, bachelor students, they are vastly outstripping our ability to train domestic talent because their population is larger. So if we're just using domestic talent, even if we we should obviously be improving our K through2 education system, our higher education system, but we can do that all we want. If we only use domestic talent, we cannot match them. So but we're very fortunate the number of people, the number of really brilliant researchers and engineers who want to come to the United States if we will only let them.
▶ 1:50:46So I would say you know and we look at the way that that affects the US AI uh ecosystem. Um twothirds of the top AI startups had an immigrant founder. More than half of the AI talent at the PhD level in the United States is foreignb born. This is a big part of our ecosystem. We should treasure it. We should value it. We should let those people come and let them stay. Thank you so much. Um, you know, unrelated, I was having discussions with folks in my district about breast cancer uh research and finding cures.
▶ 1:51:14And the folks that are actually at the center are immigrants. And um I I just kept thinking to myself, okay, and now we're demonizing this group of people that's actually working to try to figure out ways to save lives. Even Dr. Jensen just said that good researchers come from everywhere. They may come from everywhere. We want them to come here and by golly, we want them to stay here because we want to have the edge.
▶ 1:51:35uh we cannot protect our edge in AI and cyber security actually without investing in the people in the institutions that are building the edge and I'm talking about colleges and universities that are feeling like they are under attack the faculty the curriculum the prospective students and the students that are there right now given that between 40 and 60% of AI related master's degrees and nearly 60% of AI PhDs have gone to non US citizens in recent years.
▶ 1:52:06I'm going to say to you, Professor Villisor, what are the long-term risks to us innovation if we keep pushing out the very talent that is being used to build this field? I think the risks are enormous.
▶ 1:52:21Uh I think uh we are leaders in AI in large part because of our human capital and as has been said by multiple people here our human capital is people who are uh at least half and probably a lot more from overseas and we need to make sure to create a climate where they feel that they can stay here and start their businesses here because the businesses they start are going to be the ones that employ 100 a thousand 10,000 people in the future and they're going to start those businesses somewhere and we want it to be here. Thank you for that.
▶ 1:52:50Um, as I mentioned, I was I know we're talking about cyber security and cyber threats. I'm also thinking about all of the other ways where AI can play a positive and constructive um part in how we are coming up with solutions, how we are protecting our people, how we are enhancing our national security.
▶ 1:53:10And what I think should be most important is who is what folks are bringing to the table rather than what they look like or where they were born. Because I don't think a solution cares too much about the person who came up with it. We're interested in how we can build our competitive edge, how we can protect the folks in our country, how we can create more jobs, and how we can create an ecosystem that is both safe and sustainable, right?
▶ 1:53:39economically, politically, from a national security standpoint. And I'm just saying this because I'm talking to all of the young people who are graduating who want to play a role in how we are finding solutions for all of these issues. And they are scared. And we don't want folks to be scared. We want folks to feel hopeful and engaged and like they're able to work with their country on addressing some of these solutions. And with that, Mr. Chair, I yield back.
▶ 1:54:05I thank the gentle lady and I I would only uh opine that you may be making a case for uh to for us to bring back up the H-1B reform so that we are in fact recruiting and retaining the best and the brightest as you you noted. And with that we will not go to that gentlemen. I guess it it boils down to me now. I'll recognize myself for a series of questions.
▶ 1:54:31Um, one of the questions I have is I'll follow up on the recruit retain. It was opined by people on both sides of the deis that uh we may be losing good people under current policy for all of you isn't one of the loopholes in our system that the massive amount of people who are training on AI getting their degrees in AI they go back to China.
▶ 1:54:59Isn't that effectively uh Miss Dona people at your university you include Chinese uh exchange students who will train on AI will be uh advanced by looking at what we're doing and then they will whether they want to remain or not be forced to return to China. Isn't that a practical reality today?
▶ 1:55:19So in fact this is a a great question an important question and it's one that colleagues of mine at at CES at Georgetown have done great work on and actually if you look at the numbers specifically in AI and specifically for Chinese immigrants and you look at how what percentage of those researchers are staying over 5 years over 10 years the numbers are north of 85%. So there's actually a very very large fraction who do stay in the country. Yeah.
▶ 1:55:41But under the current under the current law, yes, they're circumventing their original uh presence in order to do it. They're marrying an American. They're applying for this visa or that visa. Yes. Many people who come here who are the best and the brightest remain, but they don't come under a status that guarantees the remain. They take undergraduate degree and then a graduate degree and then a work program, then another graduate degree.
▶ 1:56:10We all know that there are ways to stay here for a long period of time and eight years is a blink in the back and forth in university. The question though is how many people come here and have a reasonable expectation that they can remain here permanently and thus make the plans that might lead to loyalty. It'd be a different question. I have two service members here. Uh are you both current reservist? You're not. You are. Were you an officer, Mr.
▶ 1:56:39Anderson, you're enlisted. So, I'm going to make one assumption. Dr. Jensen, you currently hold at least a secret secret security clearance, don't you? That's true, Chairman. Okay. How many other people here hold security clearances today? Okay. For your security clearances, was there a background Yes. And now we're also subject to what's called continuous monitoring evaluation.
▶ 1:57:03And as a result, one of the questions in that background is, are you susceptible to in fact being leveraged by a foreign power? And isn't one of the greatest foreign power leverages the the having family in a foreign nation and particularly a hostile one?
▶ 1:57:22So isn't one of the questions that has not the genie that we have to let out of the bottle is one of our challenges by definition is whether you said you had two out of the four but if they are from China and their family is in China they are subject to potentially being leveraged through their family and if they're from China and for the 6 8 10 12 years every day of their lives they potentially susceptible to being taken back
▶ 1:57:52to China, they are they are less likely to be reliable from a standpoint of keeping secrets secret. Miss Tona, wouldn't you even agree with that? I think that is true and a concern for I would say a small fraction of the people in question here. We only need one to give away the secrets and the next bomb will not be stopped on its way in.
▶ 1:58:12So one of the questions that I have here today is there's been a lot of discussion about uh basically foreign policy, immigration and so on but from a standpoint of keeping our edge tariffs will not keep our edge in AI. Is that correct? And I think that's correct Miss Toner. One of the areas that you opined on positively was that uh our export controls have helped us keep that edge.
▶ 1:58:43Yes sir. And when we talked about cooperation, the very chips that we have export controls on trying to keep from leaving every company that we want to have work in a collaborative way with our government to help keep secret secret to help uh have the level of cyber security. Every one of them pretty much uses those chips, right? Yes, sir. So maybe we can have a sense of consensus here for a moment.
▶ 1:59:11Isn't it fair to say that although we want it to be cooperatively, we want it to be voluntary, access to those very powerful chips that we will not let our enemies have, in fact creates a bargain in which you really must work with the government to make sure that you're safeguarding the fruit of those very powerful chips. Is that fair to say?
▶ 1:59:36Okay, seeing no disagreement, I'll say we've gotten that. And I'm going to, you know, this is one of those times when which I don't want to abuse the opportunity. The ranking member is going to let me have an extra minute or two, but I just want to close with a with a question that hopefully sets it up. This this hearing was primarily about our current edge, where it is, and what we should do.
▶ 2:00:01And there'll be a lot of questions both from members who couldn't be here myself I couldn't be at the science committee so I'm going to be asking them a lot of questions on quantum but isn't one of the most important things we should be doing and I want to bring together both sides and their questions.
▶ 2:00:19We should be figuring out how to recruit and retain from the entire world the best and the brightest and create an environment in which they are safe and secure from being moved out of the United States so that we have the first step in developing the best technology and then continue in every way possible to make sure that those who are our enemies will not in fact use
▶ 2:00:49the fruit of that to their benefit i.e. China is that all a consensus the last one is Dr. Jensen, you touched on one thing and I just want to make sure I understood it. It's sort of a technical question. This whole question of We all understand that today uh AI various AI models are being offered in some cases free as a service.
▶ 2:01:17What you alluded to that is part of DeepSeek and and Miss Toner, I'm sure you saw it too. If we allow models to be used as a service and if they can be a service to people outside the country nefariously trying to to get ahead of us then don't we in fact provide the very lead that we're trying to deny uh when we hold back chips either one of you.
▶ 2:01:46Yeah, I'll just start uh chairman by saying yes, but this is where it gets precarious, right? So the thing again I was talking about was the unbounded consumption attack. So how they manipulate the API um beyond just the knowledge distillation and even if that is just a legal gray area and US people exploit it, it doesn't make it right. And so now the question becomes is how do you make sure that that technology proliferates because as everyone's talked about whether it's breast cancer whether the really interesting next innovations are second order.
▶ 2:02:15It's how people begin to employ these models to solve other problems and you don't want to limit that. At the same time you don't want to limit its abuse. This is why I think you need to really go on the offense. And what I want to be brutally clear when I say that that means finding way for sensitive intelligence to be declassified to then differentiate between what's natural business competition and what's actually nefarious and then begin to make it admissible in not just the US but also in multiple other free societies.
▶ 2:02:40So it starts to create a compounding effect and even in the more extreme case that's when you turn it over to a presidential finding and you actually talk about what you might sabotage digitally overseas. Miss Stony, you had a closing statement. Yes. To to build on that, I think a really important element here that often gets um not discussed as much as it should is how these companies are monitoring the use of their systems.
▶ 2:03:03So, it's not just a question of testing them in advance or um or the cyber securities at the companies themselves, which are very important, but if they're going to make their products available to users, which is important for their business models, it's important for us to to benefit from them. Um how are they detecting when they are being used improperly? And uh I think different leading AI companies have different uh practices around monitoring of different quality. Um and I would certainly encourage um you and your oversight role to discuss with with the leading AI companies. How are they monitoring? How their systems are being used?
▶ 2:03:32You know, I I believe that OpenAI is currently investigating whether Deepseek used their their uh systems inappropriately and if so, how? Um how do they detect that? What are they logging? What systems automated and human-based do they have in place to tell when those improper uses are occurring? Thank you. And uh having no further uh questions from the deis currently I would bring this to a close by saying that for the next five legislative days u we'll allow members to uh ask additional questions.
▶ 2:04:02Would you all agree to respond uh to those in writing and then just to make sure I don't miss anything on the close? Without objection, this hearing is