▶ 0:16:01Committee on Homeland Security subcommittee on cyber security infrastructure protection will come to order. Without objection, the chair may declare the committee in recess at any point. Purpose of this hearing is to examine the nexus between artificial intelligence or AI and cyber security. We'll examine how AI systems can be secured, the risk to our cyber security posed by adversaries who use AI tools, and the promise AI holds for our cyber defense. And I recognize myself for an opening statement.
▶ 0:16:28In late 2022, generative a artificial intelligence entered the public sphere and became a viral sensation. Today, Generative AI has evolved into a useful tool for cyber criminals, nation state cyber actors, and cyber defense teams across the globe. In just a few short years, AI has evolved so quickly that we are now discussing a new t type of AI, agendic AI. The use of agents raises important questions about how much decision-making control AI should have and how these tools can be secured.
▶ 0:16:59Innovative American cyber security companies have developed cutting edge tools to integrate AI into cyber defense across the public and private sectors. AI is upscaling cyber security teams abilities to make to manage vulnerabilities, detect and analyze threats, track regulatory compliance and automate responses to security These new capabilities can help reduce cyber security teams workload and produce better cyber security outcomes. This is especially crucial considering our nation's significant shortage of skilled cyber security professionals.
▶ 0:17:31However, we must be cleareyed. While AI bolsters our product productivity and security, our adversaries also hope to use technology for their own gain. Our nation's adversaries increasingly weaponize AI to scale and more quickly develop attacks against American citizens, businesses, and government entities. Additionally, fishing attacks have increased nearly 1,200% since the rise of generative AI in late 2022.
▶ 0:17:57Beyond cyber attacks, malicious actors exploit AI models for nefarious purposes such as conducting AI assisted social engineering attacks, developing ransomware, and creating autonomous attack bots. The adversarial use of AI is most evident in deep fakes, where attackers can impersonate a trusted individual with AI generated audio and video seeking financial gain or access to secure networks. Threat actors also directly target the integrity of AI models, underscoring why security is an imperative.
▶ 0:18:28Through manipulation, attackers attempt to destabilize AI models, deteriorating their accuracy and performance by targeting training data, input data, and other structural components. As our enemies continue their endeavors to compromise and weaponize AI systems, we must ensure that security remains at the forefront of innovation in an art in artificial intelligence. Emerging AI technology must be constructed with the appropriate security measures to be resilient against malicious actors.
▶ 0:18:55While adversaries leverage AI to improve their ability to target the United States, we must use it to sec. Also before I close, I have heard recently in the last couple months of some of our best cyber security experts being directly approached by foreign leaders in being offered visas and funding for their research.
▶ 0:19:21We are at risk of the greatest brain drain our country has seen if we don't find a way through the federal programs we have to keep these individuals working for the US government. It's also true in the health and sciences fields where NIH scientists and cancer researchers are also being approached. There's been an exodus of talent from CISA, NIST, NSF and every procurement and CIO shop across the federal government.
▶ 0:19:49We will not be able to harness the full potential of AI if we don't have a workforce who understands how to procure it and secure it. With that, chairman, again, I'm so glad we're having this hearing. Look forward to hearing from each of our witnesses. And I yield back. Gentlemen yields back. Other members of the committee reminded that opening statements may be submitted for the record. I'm pleased to have a distinguished panel of witnesses before us today. I ask that our witnesses stand and please uh raise their right hand.
▶ 0:20:19You solemnly swear that the testimony you will give before the committee on homeland security of the United States House of Representatives will be the truth, the whole truth, and nothing but the truth. So help you God. Let the record reflect that the witnesses have answered in the affirmative. Thank you. Please be I would now like to formally introduce our witnesses. Mr. Kiran Jin Shinagangan Nagari, sorry about that, is co-founder and chief product of technology officer at Securin.
▶ 0:20:47He oversees the development of software as a service-based cyber security products to leverage AI and machine learning to increase vulnerable intelligence, attack surface management, and threat prioritization. He previously served as chief technology officer and assistant director for the state of Steve Fail serves as the US government leader for Microsoft where he is responsible for driving cyber security collaboration with federal government agencies to accelerate security modernization and increase national He has
▶ 0:21:17over 20 years of cyber security experience and roles across the public So Gareth Mccclaclin is the chief product officer for Trellix where he is responsible for product development, innovation and intelligence. Prior to his role at Trellix, he was responsible for product management and go-to market for Mand Mandant management defense consulting and threat intelligence.
▶ 0:21:44Sir Jonathan Damrott is the chief executive officer of Cranium AI where he leads the company's work to provide AI governance software that enables drive security, compliance, and trust across AI and generative AI systems. Prior to creating AI, he served as a partner at KPMG leading thirdparty security globally. I I thank the witnesses for being here today and I now recognize Mr. China Nagari for five minutes to summarize his opening statement.
▶ 0:22:13Chairman Garberino and distinguished members of the subcommittee, thank you for the opportunity to testify on this very important topic today. My name is Kiran representing securin a CISA JCDC member with deep roots in collaboration with DARPA department defense Arizona State University New Mexico and Mississippi State universities. Securin is not just any other cyber security startup.
▶ 0:22:36We have taken research from the lab to the marketplace building patented technology that uses AI for early warning and predictive defense empowering organizations to stay ahead of attackers. One of our notable project is cactus. It stands for computational analysis of cyber terrorism against the United States. I have the privilege of serving in various government roles and my perspective today is shaped particularly by my seven-year tenure as the CTO for state of Arizona.
▶ 0:23:04The experience has provided me with a profound understanding of the technological challenges faced at both the state and federal levels. Let me start and end with one core message. Securing AI models is not just about protecting algorithms. It's foundational to the United Na United States national and economic security with national resilience against adversaries ranging from threat actors nation states to individual detractors.
▶ 0:23:31Recent a campaigns such as those attributed to W typhoon have exploited toxic combinations of vulnerabilities chaining together weaknesses and vulnerabilities in both legacy and AI powered systems to achieve persistent and stealthy access. Our research also reveals that as AI models become more capable, their attack surface grows.
▶ 0:23:52Models with high reasoning capability are paradoxically more exploitable, making robust model security and adverse testing is essential as we advance these AI capabilities. As AI becomes the backbone of our economy, healthcare and critical infrastructure, its vulnerabilities become the vulnerabilities of our entire Why does this matter? One for offensive AI.
▶ 0:24:17Both attackers and defenders are leveraging AI to simulate sophisticated cyber attacks from nation state to ransomware schemes exposing vulnerabilities in real time. This offensive strategy is not just valuable. It's indispensable for organizations using AI in cyber security to outpace adversaries. Number two, weaponization is at happening at speed.
▶ 0:24:39Attackers were already using AI to automate fishing attacks, generate deep fakes, discover vulnerabilities, and create polymorphic malware that evades traditional defenses. Three, global competition. We start we see a star contracts between Chinese and Western AI models. Chinese models often outperform in raw speed and scale, whereas western models tend to prioritize security and transparency. This trade-off is critical consideration for US policy and competitiveness.
▶ 0:25:11We do have a urgency for legislation and AI guardrails. The threat landscape is evolving rapidly. Nation states and ransomware groups are not waiting for legislation. They're exploiting every gap and inconsistency. AI powered attacks are already undermining authentication, public trust, and critical infrastructure.
▶ 0:25:29This rapid prolification of AI has not only magnet magnified old vulnerabilities but also new introduced new ones from supply chain risk to adversial manipulation of What is the path forward? A federal baseline with state partnership, a one-sizefits-all federal law could overlook local needs, but leaving it to states alone would risk fragmentation and weak spots.
▶ 0:25:55What's needed is a federal baseline much similar or much like PCI or HIPPA developed in partnership with states setting minimum standards while allowing for regional adaptation. Our assessment shows that no state excels in every area. So combining best practices is essential. Let me close where I began. Securing AI is not just about algorithms. It's about protecting the United States future. It's foundational to national security.
▶ 0:26:23Offensive security anticipating how AI can be weaponized must guide both technology and policy. Enforcable guardrails are needed now and it's urgent. Attackers are moving faster than regulators, so we must act swiftly and precisely. And lastly, a coordinated federal and statewide approach that is informed by real world offensive security insights and clear frameworks is the only way to move forward. Thank you for the opportunity to testify here.
▶ 0:26:52Please feel free to call me as Casey instead of my full last name. I look forward to your questions and working together on this critical mission. Thank you again. Thank you, Casey. That's what you said, Casey. All right. I appreciate that. And now now recognize Mr. Fail for five minutes to summarize his opening statement. Chairman Garberino, ranking member Swallwell, and members of the committee, thank you for the opportunity to testify before you today.
▶ 0:27:20I'm Steve Fail, Microsoft's US government security leader. Microsoft is on the front lines of cyber defense, protecting our customers from more than 600 million cyber attacks per day. Our threat intelligence now also tracks more than 600 nation state actors, and that count has doubled year onear. The rapidly increasing quantity of attacks and number of threat actors together is an indicative of the resolve of our adversaries and the need for achieving decisive advantage in the cyber domain.
▶ 0:27:49I would say that at Microsoft we have a front row seat to this, but we don't. We're actually in the game and on the field night and day with 15,000 cyber professionals giving it their all. We've prioritized security above all else, fielding an additional equivalent of 34,000 full-time engineers to engage on continuous security improvements and hardening of our products and services. Bringing forward this talent to stem the digital tide of conflict is necessary, responsible, and in my opinion, heroic.
▶ 0:28:18But we're at an inflection point and adding more human attention is just not scalable. There is no way to tackle this urgent national security issue without organizations including the federal government immediately embracing AI. There are three primary ways at Microsoft that we think about security and AI together. One of them is security with AI, then security of AI, and finally security from AI.
▶ 0:28:43Security with AI is grounded in using large language models that provide the opportunity to supplement human effort and attention with computational power. We track the implications of fielding this technology closely as we support customers with our security co-pilot product. As a result, we've seen a 34% decrease in mistakes, a 17% decrease in breaches, and a 30% faster time to incident resolution using this technology, which is a huge leap forward in capability. And we're still only in the early innings of generative AI.
▶ 0:29:13We're also leaning into the next horizon of cyber AI and our support of the US government with AIEL investigations, taking the most time-consuming aspects of security response and delegating them to AI agents with human analyst review and oversight. Our findings are encouraging and the potential implications are astounding. Here's a recent example of an investigation that was humanled where the total investigation cost was $640,000.
▶ 0:29:37But with generative AI, we were able to achieve the same result in an AIE investigation for only $80. An 8,000 time increase in throughput. Government domain spoofing detection is another example of success of security with AI. Detecting spoof domains is a difficult problem to solve with current approaches only going so far. This results in end users needing to report spoof domains, delaying response, leading to more victims, and amounts to a multi-million dollar a day whack-a-ole.
▶ 0:30:07With generative AI, we can achieve greater than 99% accuracy dep detecting these domains immediately and for only a few dollars a day. This represents a paradigm shift which enables organizations to be proactive in addressing the threat landscape at the necessary scale. While there's an incredible opportunity for security with AI, we're also cleareyed on the risks leading us to the security of AI. Starting with secure by design, we ensure models are hosted in our Azure AI foundry are isolated so your data is only accessible to you.
▶ 0:30:35We add on to that scanning, monitoring, red teaming, source code, and version controls, and rigorous testing to ensure that our AI systems are operating as designed. Government agencies and private sector organizations can use these with confidence that their data is not being used to train existing or future commercial models. The future cyber battlefield itself will be reshaped by AI, applying intelligence to data to gain understanding to and take action.
▶ 0:30:59However, few agencies are capturing the necessary data due to limited adoption of OMM2131, which is currently unfunded. Most agencies are also hesitant about the use of AI while our adversaries appear to feel no such compunction. Which brings us to security from AI. So far, we've not seen threat actors use of AI to create novel threats at scale. They're leveraging AI to increase productivity, automating the creation of fishing emails, generating deep fake content, and conducting large-scale social engineering campaigns.
▶ 0:31:28However, it's only a matter of time until this changes. And if we maintain our current course in speed, we run the risk of being vulnerable and illequipped on the cyber battlefield. Some of the tactical norms of strategic cyber defense will also evolve in the in the age of AI. The value of data itself has actually increased due to AI being applied at scale. Protecting email data may now be as important as protecting a weapon system. And shame on us if an adversary understands our data better than we do.
▶ 0:31:57As I referenced in my written testimony, Congress should consider policy recommendations such as facilitating workforce readiness, developing cyber deterrent strategies, and reforming traditional IT acquisition models to meet this AI moment. In conclusion, cyber security stands as one of the most impactful and lowest risk applications of artificial intelligence. In the face of increasingly sophisticated and large-scale threats, the only certainty is that inaction will lead to failure. Thank you, and I look forward to your questions. Thank you, Mr. fail.
▶ 0:32:27I now recognize Mr. Mccclaclin for five minutes to summarize his opening Chairman Gavino, recommend Swallwell, distinguished members, thank you for the invitation to testify. To put my testimony in my context, my my comments into context. TRUX is one of the largest cyber security providers globally, supporting over 50,000 organizations.
▶ 0:32:47More than half of our revenue comes from working with governments, critical infrastructure providers, and regulated And Trex has been using generative AI for more than two years, machine learning for more than 10, but we do not build our own models. We use commercial models and we've built our own frameworks to make sure we use those securely and safely. There are really three points that I want to emphasize from my written testimony this morning. Firstly, is the use of generative AI by the dark side by attackers.
▶ 0:33:18It is true that they are experimenting at the moment. We're not yet seeing these being used in production at scale. But the heart of it, Genai is really just driving a change in economics in any business and criminal proceedings, nation state attacks are a business. Things that we thought to be true. The scarcity of resources, number of people, the skills that are needed, the experience to go run attacks have changed.
▶ 0:33:43And attackers are using this to be able to personalize email campaigns, set up infrastructure far faster than before, even starting to explore new zero days. That changes what we have to go and deal with as defenders. So that moves me really to the the positives. We're already using generative AI within our security operations platforms.
▶ 0:34:06We have demonstrated with our customers that doing so scales up the the defenses that an organization may have far faster and far more effectively. In fact, if we do not use Genai to actually secure environments, we will be lost against the attackers themselves. And the reason being is security operations has been based upon hire a few experts, get them to find the most important things and go look at them in detail.
▶ 0:34:35doesn't work when Gen AI allows the bad guys to hide within the shadows, do things at scale, personalize every single attack so you can't spot for patterns. But adding Genai to the security operation side works. Genai is never going to get bored. It's never going to get distracted. It doesn't care about looking at the same things over and over again every time it gets a little bit more information. And so I move really to the way in which we are using it within Trell.
▶ 0:35:04As I said, we do not build our own models. We do not train our models. We use commercial models that are available. But we focus on making sure that when we do it, we know how to validate those different models. We make sure those models are not being used. Our data and our customers data is not being used to train those models. And we always use and recommend organizations think about it just like an email. any prompt, any instruction going into a gen AI model and any output from it, don't trust it.
▶ 0:35:34It could be malicious code, it could be leaking information. Now, in order to take the benefits of Gen AI, we do it in two ways. We make sure that we have a very rigid guidance framework. We don't allow it to make its own decisions. We give it a a thousand different things it can choose from to make sure we get rid of the risk of We require it to use the evidence of the data we provide it to justify its decisions.
▶ 0:36:00We use Aentic AI to make it debate amongst itselves and take different perspectives in order to come to a good conclusion. And we always use humans in the loop either to verify the models or to make decisions and act decide when to act on the outputs from it. And like many companies, we also use it to actually improve the security of our own products. The secure by design approach becomes that much more efficient when you start to throw Gen AI into the mix. Again, we use commercial tools to do this.
▶ 0:36:31It allows us to make sure that the tests that we run are exhaustive. It allows us to make sure that the code that's written is produced at scale and produced faster, but we always distrust it until proven otherwise. And we use Genai to actually red team our own products. So for us at Trellix, there is no alternative but to actually embed generative AI technologies within the security operations frameworks and the platforms that our customers both government and enterprise use.
▶ 0:37:00It enables defenders to be far more effective. It reduces the risk for an organization of relying on a few individuals and their own internal skills, biases and experience and puts us in a situation where today we are actually ahead of the attackers which is a rare and valuable thing to me. Thank Thank you Mr. McLaclin. I now recognize Mr. Damraat for five minutes to summarize his opening statement.
▶ 0:37:30Chairman Garberino, ranking member Swallwell, and distinguished members of the subcommittee. Thank you for the opportunity to testify today on the crucial matter of securing artificial intelligence to strengthen our nation's cyber security. My name is Jonathan Danro and I serve as CEO and co-founder of Cranium, an AI security and governance platform built to enable safe, resilient, and innovative AI adoption across enterprise and critical infrastructure.
▶ 0:37:53At Cranium, we believe that the future of secure AI begins not just with risk awareness, but with a f a foundational shift to transparency, accountability, and continuous security throughout the life cycle of every AI system. As the US competes to lead in global AI development and deployment, we must advance innovation handinand with strong governance to ensure that AI progress reinforces our national security and democratic values. AI is transforming every industry, promising significant benefits.
▶ 0:38:22But it also introduced new risks. As an enterprise focused on AI security, Cranium's perspective is that we must secure AI systems both before they're deployed and throughout their operational life cycle. This means building security into AI by design from the outset and maintaining robust defenses and oversight by default after deployment. We believe this approach can foster innovation while safeguarding AI systems. Artificial intelligence is now deeply embedded into our digital digital infrastructure.
▶ 0:38:49From foundational models and generative systems to embedded AI and thirdparty software and services, the pace and scale of adoption has accelerated beyond what many expected. This proliferation has introduced new risks. Complex supply chains, unmonitored shadow AI deployments, and misaligned thirdparty integrations that are difficult to address without robust AI native security strategies. To mitigate AI risk early, we must change the development culture and tooling.
▶ 0:39:15Security should be treated as a first class concern and in model design and training just as performance or accuracy is. The goal is that by the time the AI system goes live, it has been harded against foreseeable attacks or failures. Embracing secure by design for AI also means empowering those building AI with better knowledge and incentives. We must ensure education is prioritizing security and by disseminating secure AI development guidelines across the entire supply chain including trusted third parties.
▶ 0:39:45Further, Congress and this subcommittee can play a pivotal role in promoting secure by design principles for AI. We urge policymakers to encourage evidence-driven security and verification in AI development. Beyond pre-eployment security, we emphasize the need for continuous protection and monitoring throughout the operational life cycle of AI systems across the supply chain. AI systems and models evolve, inputs shift, and adversaries adapt, requiring a governance framework that is not static, but dynamic.
▶ 0:40:14As we evaluate how best to secure the nation's AI infrastructure, we must also confront the growing threat posed by autonomous AI agents. These agentic systems and non-human identities introduce a new and complex class of security risks. A compromised or maliciously directed AI agent could autonomously conduct cyber operations at m machine speed. To counter this risk, security must be embedded throughout the life cycle of AI agents from the moment they're conceived uh and built to the moment they're deployed and run.
▶ 0:40:44Relying on AI to stop AI is not a viable defense strategy. The threat of AI enabled attacks necessitates layered, in-depth, and proactive defenses. Our best response is to double down on what this hearing is all about. Securing AI to strengthen cyber security. We need to be proactive and forward-looking, anticipating these threats and preparing defenses and norms accordingly. Chairman, ranking member and members of this subcommittee. Securing artificial intelligence is stren is to strengthen cyber security is one of the defining challenges and opportunities of our time.
▶ 0:41:14AI will undoubtedly shape the future of our economy and national security. Whether that future is more secure or more dangerous depends on the actions we take today to embed security, accountability, and resilience into our AI ecosystem. Companies like Cranium exist precisely to ensure that security advances in tandem with AI advancement. We believe the United States can lead the world in both AI innovation and AI security. If we do, our cyber security will be stronger, our values will be upheld, and our citiz citizens will reap AI's benefit without unnecessary fear.
▶ 0:41:43Thank you for the opportunity to testify and for your leadership on this issue. I look forward to answering any questions you may have. Thank you, Mr. Dan Rod. We like the ranking members said, thank you for uh skipping your family vacation for a little bit to be with us. This is a very important hearing. Members will be recognized by order of seniority for their five minutes of questioning. Additional round of questioning will be called after members have been recognized. I now recognize the gentleman from Louisiana, Mr. Higgins, for five minutes of questions. Thank you, Mr. Chairman, and I thank you for the indulgence.
▶ 0:42:12uh have committee across campus I need to get to is super important. Um gentlemen, thank you for for being here. I've been involved in a in a bit of an investigative effort uh regarding a a particular um that's happening across the country like Mr. Fail and Mr.
▶ 0:42:39China to address please the the purchase of by the the purchase of of infrastructure businesses and businesses related to key infrastructure in our country.
▶ 0:42:57We're talking about the energy sector, financial sector, transportation sector, agricultural sector, supply chain sector, the tech sector, the defense sector, the medical sector, the the research and development sector, the thousands of of companies across the country that are many are small businesses with with a handful of employees or under 100 employees.
▶ 0:43:21the kind of the kind of company that can go under the radar uh if it's bought or sold. These companies are being bought by equity firms across the country and I'm advised that one of the the first actions this restructuring by these equity firms that purchase these these key businesses. Of course, they're buying them legally. You understand? It's not a big deal.
▶ 0:43:51Maybe a small story in local news, but one of their first actions I'm being told is to eliminate the cyber security contracts of those companies. Then they own these companies for a period of time as an equity firm. They're not interested in that trucking company or that energy sector company or or that financial sector company.
▶ 0:44:19They're interested in building equity in that company and then what? Reselling it. Right? So over the course of weeks or months or maybe a year or two, they'll own this company as an investment. They have shut down cyber security. Then they resell it. And the guys that buy it say, "Wow, this company has no cyber security. We have to establish that cyber security.
▶ 0:44:50This is of great concern to me because what the hell happens if we had many of these equity firms have have Chinese investors or connections with with with Chinese So, you know, we're living in a world of of of intense cyber threat and with the introduction of AI and its emergence, how it plugs into cyber security, it's of great concern to me.
▶ 0:45:19So, I'm happy to have a panel of experts in front of me. Mr. fail. Um what what would be this my question to both you gentlemen. What would be the irreversible impact of key businesses connected to our crucial infrastructure across this country going without cyber security protection for weeks or months sort of under the radar? What kind of what would happen in that time frame?
▶ 0:45:50So thank you for the question. Representative Higgins, uh, I think I I would start by suggesting that cyber adversaries at the moment appear to, uh, be very little deterred by cyber defenses that have been employed by small businesses and critical infrastructure. And that's actually why the advance Hold on, let me let me stop you there. Let's not judge the quality of the cyber security with a broad brush brush.
▶ 0:46:18it this we're talking about the elimination of cyber security from a company that gets bought by by an equity firm. You think that's no problem? AB it is a problem. I think it's indicative of a broader problem of inattention to cyber security in general. Um and adversaries have been often uh not deterred by efforts we all need to do more doing less. Okay. So the gentleman agrees that that generally that it's it's it's it's a problem.
▶ 0:46:49Mr. Chininda Gang Anna Gary, I do agree with that and there's a huge security risk by having these type of protections taken away from small businesses when they're either acquired or merged with other companies and that if that small company is actually doing business with a critical sector especially with government that gives them a attack vector for a hacker to get into it. Thank you. So it has to be protected. Mr. Chairman, thank you for this hearing. Thank you for your indulgence.
▶ 0:47:19My time is well expired. Mr. Ranking member. Thank you. I yield. Gentleman yields back. I now recognize Miss Macyver from the gentle lady from New Jersey, Miss McCyver, for five minutes of questions. Thank you, uh, Mr. Chairman, and thank you to our ranking member, and thank you to each of our witnesses for being here today with us. Um, especially you for missing your family vacation to be here. I hope you get back there soon. um to join them. Uh artificial intelligence is transforming the world we live in.
▶ 0:47:49We know every day we're learning new ways to harness this power. When used with caution, it can be a crucial tool in countering the cyber attacks that have become all too common on our critical infrastructure. I know how important this task is. I represent New Jerseys 10th Congressional District and we have seen how fragile our critical infrastructure systems are. Under this administration, North Liberty Airport has experienced significant flight cancellations and general dysfunction.
▶ 0:48:19A cyber attack on top of this would be devastating. We must work to ensure that the American people can rely on critical infrastructure systems under any circumstance. AI could be part of that answer. So with that, I have a couple of questions for you, Mr. Fel. How can US critical infrastructure owners and operators take advantage of AI to help them defend against relentless cyber attacks? Thank you for the question.
▶ 0:48:49Uh critical infrastructure is is an area that uh often has many challenges and of course receives a lot of attention from cyber threat actors. One of the things that is difficult for critical infrastructure providers is to understand the specific threats that they face as a result of uh a particular uh niche that they may have.
▶ 0:49:09And so while we broadly distribute as an industry a lot of general threat intelligence, understanding the context of what a specific actor and what specific threat intelligence means for you in your critical infrastructure industry is incredibly important to prioritize defense. This is one of the areas where we see generative AI closing the gap and surfacing and prioritizing the right security investment areas and the right security steps to take that are custom to a particular organization and not just applied with a broad brush. Thank you for that.
▶ 0:49:39My second question question is can you explain how AI products can help close the cyber skills gap and does Microsoft have any solutions currently available to help address the issue? We believe it it absolutely can and we have seen it firsthand um as we as we look at diffusing more cyber knowledge throughout the community. Generative AI is a great tool because it's an always on teacher. Um and we're not waiting for bottlenecks of when is the subject matter expert available to teach the rest of us.
▶ 0:50:09And so by having some expertise available in the model itself, you can go to it on demand and receive assistance for the task at hand just in time, just enough. And you can even ask it to explain itself three or four times and it won't get frustrated with you. So we find it's a great tool for learning. Uh my kids use it for learning about cyber education all the time. Our employees use it. I assigned a task to an architect not too long ago. She came back to me a couple of uh days later and said, you know, I couldn't complete the task because I didn't have the requisite skills. I didn't know how to do XYZ.
▶ 0:50:39I can't write code. And I said, well, we'll find someone to coach you on that. She said, no, no, I finished the project. Uh not a problem. I just used AI to assist. So we are seeing this firsthand bolstering our own cyber security education and workforce development. We see this with our customers and with security co-pilot we've fielded a capability that anyone can tap into for that technical expertise at a moment's notice. Thank you for that. And you talked a little bit about this in the next question I'm going to ask, but if you can, you know, explore a little bit more with it.
▶ 0:51:07what testing goes into your AI tools to ensure that they are secure and do not introduce more vulnerabilities into the ecosystem that you know can be Thank you for the question. U we test at many different layers and many different using many different methods. So uh there is the focus on the model itself. Uh obviously we test the model, we examine the model, we scan the model, ensure that there's no malware in it, those types of things.
▶ 0:51:34Uh but as we uh move up the stack, we also scan the system because AI is more than just the model. It's the system that you build around it. And the guardrails that were mentioned in in earlier oral testimony are an important part of that process as well. So we do static scans of a variety of of of kinds, do dynamic scans as well, rigorous testing, but then also testing against baselines and seeing when those baselines change with version control.
▶ 0:52:00And finally, uh you you can't do better than having AI red teams, the humans that come in and question your assumptions that pound on the infrastructure and uh use novel techniques uh to try and expose weaknesses. This is an area where we see ne it's necessary to continue to innovate. Uh but the results so far have been fantastic. Thank you so much for that, Mr. Fel. With that, I yield back. Gentle lady yields back. I now recognize myself for five minutes of questions.
▶ 0:52:28Two years ago, SISA launched the secure by design movement to encourage software developers to consider security from the beginning of the product development. Given how AI has evolved rapidly in just a few years from machine learning to generate AI to nowic AI, it appears we have an opportunity to adopt similar a similar philosophy and deploy secure AI tools. Casey, how can we adopt secure by design principles for AI? Thank you for the question, chairman.
▶ 0:52:56I would say that software um secure by design um policies or framework is not new. It was introduced back in 2005 by Nest and unfortunately those secure by design standards have not been adopted or not been practiced and with AI it's actually exaborating that problem that we are seeing with Wbe coding lot of students lot of kids lot of folks that do not have any software experience are writing code and it's introducing more and more software vulnerabilities and
▶ 0:53:26weaknesses we actually did a research analysis and we saw most of the models that are out there can be jailbroken if you have the patience and will to get to it. And we also have analyzed about 15,000 MCP servers that are out there. One of the thing that we noticed is that CW20 which is input validation which is very old vulnerability and weakness it's been exploited even today any AI model or MCP server that you see we seeing that as a big issue.
▶ 0:53:55So there needs to be a big push from from the Congress and legislation to mandate secure by design in in the products and and offerings that these vendors are providing out there. And I saw the EO on Friday that actually pushes that um that uh that software by design policies forward. Do we need different principles depending on the type of AI security design principles?
▶ 0:54:22I would say that the AI vulnerabilities are slightly different but the traditional software vulnerabilities still apply. where AI would differ is things like data where you're thinking about you know how do you attack you know the model to give you nefarious answers you know those are the things that I think AI is slightly different but if you go back to it these same issues happen you know the data and the analysis and security so I don't think we need a new framework or anything you just need to make sure that existing
▶ 0:54:52ones are used effectively and that goes from uh even that that even includes on aentic AI the new the newest frontier. I would agree to that. 100%. Mr. Danrod, your company fa focuses on securing AI. However, many startups have scarce resources, meaning they may not prioritize investing their money in security.
▶ 0:55:12How can we ensure startups think about AI security as a worthwhile return on investment for their organization and for the broader AI Thank you for that question. I you know I think when we look at small businesses I think AI becomes a great equalizer in many ways right it offers a power that many of them have never had at their fingertips to introduce into their products and services and really fundamentally change the way that they can compete in the market.
▶ 0:55:38Um but I think you're right we definitely see organizations that don't necessarily focus on security by design and AI security by design. integration strategies that my colleagues here talk about. You know, we see technologies that surround these models that may also introduce vulnerabilities. So, we really need to look at the entirety of the AI system. Small businesses have an obligation. I think um they need to be educated on those risks. Often times, these are not well understood. I think we have to focus on education.
▶ 0:56:07I think we need to make sure that the tooling that's available to small businesses as they're starting to integrate and develop these technologies into their products is e more easily accessible, easily understood and the foundational model providers have an obligation to continue their hard work to make sure that they're using the most secure models in the uh process of that integration. So I think there are opportunities here to improve.
▶ 0:56:30Uh when we look at the small businesses that we actually identify through our customers uh and the that are third parties introducing AI services, many of them have never done any AI red teaming. They haven't gone through that process. In fact, I think when we look at our our vendors uh about 95% of them haven't done that, some of which are small business. So we really have to focus on that. make sure that they is there a is there a role for the US government to support here or not? Are you just No, not really. What do you think? Absolutely.
▶ 0:57:00Yeah, I think that there's an opportunity by basically putting better guidelines in place to make sure that as people are playing with agentic systems that we understand that there are things that have to be done uh in order to put those into production and that monitoring and and making sure that that is uh not just a manual process and raising your hand that's a not a checklist process but a technical process is one of the things that we need to start to push on. Right. Wonderful. My time is now up, but I'm definitely we're coming back for a second round of questions.
▶ 0:57:27So, I'm going to yield and I recognize the gentleman uh from California, the ranking member, Mr. Swallwell, for five minutes. Thank you. Uh Mr. Tambbrat, can you elaborate on how AI red teaming improves AI security? I think you have a a platform. Is is it Arena? Is that the red teaming platform?
▶ 0:57:46How can the federal government better support AI red teaming ensure and ensure it is used to test AI on federal networks and what are legal protections that are necessary to make sure researchers can engage in red teaming without fear of legal repercussions? Thank you for that question. Yeah, so you know when we think about red teaming generally we want to make sure that we understand how that system is being used from its outset. We want to understand the intended purpose of that.
▶ 0:58:13We want to understand how the technologies are being introduced, the models as well as the toolkits and data sets that are being introduced as people are organizing their AI system. Um that red teaming process includes being able to then identify what kinds of vulnerabilities can be identified.
▶ 0:58:29What we've done at Cranium is we've set it up so that we can not fundamentally change the way developers work but enable them to use the tool we call it the arena to basically understand that system pull it into a place where we can simulate that system attack it provide vulnerability mitigation support and then make sure that that system whether it's pre-production or post-production is being monitored and that those vulnerabilities are being reduced right so I think that there are opportunities again to enable innovation at pace at scale without necessarily fundamentally having to
▶ 0:58:59overwhelm a business or a capability um so that we can make sure that people get the best products and services with fewer vulnerabilities. Great. And and Mr. Fail, what are the obstacles that you see to federal deployment of AI cyber security services and and how do you envision SISA better incorporating AI cyber uh defense?
▶ 0:59:19And if you have time on the clock, could you also talk about quantum computing and how you all are approaching quantum computing and the risk that that poses to decryptting uh any data that our adversaries may have already captured but cannot yet unlock. Absolutely. Thank you for the question, Ranking Member Swallwell.
▶ 0:59:44As we look at what can be done and and what is standing in the way of adoption from a federal perspective, there is a workforce readiness angle of there is more education that is needed so that agencies can adopt AI especially for security purposes with confidence. Um in addition to that looking at new IT acquisition models uh perhaps that are centralized.
▶ 1:00:05One of the challenges with adopting cyber AI is that uh there are times at which you actually need to ramp up capacity in order to meet a need during a crisis. It's not an it's not an even uh evenly used capability. There are some days on a rainy day you're going to use it more um than on a sunny day. And so as a result it's very difficult for agencies to budget to understand what those requirements are.
▶ 1:00:28Uh so if we look at umbrella capabilities uh such as what's been created with CISA with the CDM program to help offer buffer for agencies to where they can uh plan to use capability without having to have complete certainty around the cost. I think we all agree that surging to meet the need in cyber defense is worth the cost. Uh but the question of who will pay that cost and and how do we plan for it is incredibly complicated for agencies and is definitely hindering adoption.
▶ 1:00:54As we look at uh quantum specifically, uh Microsoft is a leader in quantum innovation as it relates to creating more scalable quantum computing. We've had some milestones and breakthroughs there. Uh still a long way to go in uh in development, but uh the results are encouraging and and I think very supportive of US leadership in the field. Um as we look at the defensive side of that for postquantum cryptography, uh you mentioned the store now decrypt later tactics that adversaries could be using on data.
▶ 1:01:22That means we need to move faster uh as it relates to uh crypto agility and moving to uh more modern quantum resistant uh methods of encryption. This is an area that Microsoft has thought about deeply and uh we have researchers working on that topic. We also have already included some capabilities within the platforms that are already uh being used today such as Windows. So these are areas where uh we are we are working hard.
▶ 1:01:46there's still a long way to go, but as we uh look at adoption across the entire federal ecosystem and private sector as well. I think this is an area where tech companies can lean in to do more to make work less work for everyone. Um and so that is absolutely the approach that we're taking. Uh every syso should not have to figure out how to tackle postquantum cryptography. We need a a a safety net of the underlying systems that power technology and collaboration uh to make that transition for them wherever possible.
▶ 1:02:16Great. Thank you. Yield back. Gentleman yields back. We're going to start our second round of questions because some other members might come. All right. I now recognize myself for my second round of uh five minutes. Last Friday, the Trump administration released its first executive order on cyber security.
▶ 1:02:40It addressed problematic elements from previous EOS, including the approach to AI security proposed in in the final Biden administration cyber EO. Trump administr administration's EO focuses on vulnerability identification and management, including making data sets publicly available for cyber defense research. question for all of you and we can start with Casey and then move over uh to the right.
▶ 1:03:04How would you access how would access to data sets for cyber cyber defense improved your products Thank you for the question chairman. Right now as we are using these models we just like any other organization that's using these models it's a black box. We do not know what these models were trained on and we do not know how the data is biased.
▶ 1:03:29So that actually poses a significant question whenever we use this models for any purposes in any sector or any use cases. So having access to that type of data at least will help us understand what the model was trained on and if there is any bias that is introduced. In fact, we do propose a ju just like FDA. When you go to the store, when you buy food or when you buy a drug, there is label and ingredients on it. You know exactly what you're consuming. So, you know what the impact of it is.
▶ 1:03:58We need a similar one for AI understanding the entire model build of materials including the data that is a missing piece in my opinion and there's something that you know security has been working very happy and glad to provide that uh information to you chairman. Honorable Mr. Fail the avail the availability of data I think is especially important when it comes to benchmarking and assessment.
▶ 1:04:23So having common data available to agencies such that they can test AI solutions on that common data set uh to analyze for results. Uh many agencies would like to do assessment of AI solutions but are hesitant to make their own data available to do so. And so as a result, you can actually have broader testing, have AB comparisons, benchmarks, common benchmarks. We've seen that with data that NIST has provided where it fuels innovation because you can now start to benchmark and compare uh solutions.
▶ 1:04:54And any solution that uh involves AI is going to involve a lot of testing and validation. And so therefore providing data in that capacity is extremely I would concur with my panelists. The availability of data is always going to help both on the benchmarking, the validation, understanding what's in it. Um, however, one of the other elements that we would benefit from from the sharing of threat data is it actually allows us to start to drive towards more efficient, more effective models.
▶ 1:05:23One of the challenges with using LLMs today is not only that it knows a bit about security, it's also got 32,000 recipes for apple pie in its memory. So, getting down to something which is more specific does help us verify the outcomes from it. Thank you. Thank you Dan Brown. Thank you. Um so look I think the uh access to data question is important. I you know in regards to security information I think that is highly relevant uh as mentioned for benchmarking.
▶ 1:05:52I think when it in regards to understanding the implications for AI testing I think we can actually look at opportunities to take that data and make synthetic opport uh data sets so that we can do that testing against synthetic data. So for us when we look at those production AI systems that are look you know we want to test we don't always necessarily use that training data we will take that data we will make it synthetic we will then use that synthetic data to test against a pipeline that we create and then test that using AI red teams as well as
▶ 1:06:22uh AI agents that are uh you know trained in how to do that effectively. Um you know for us we want to protect the data of our uh clients and agencies and I think what we want to really come back with is how can we give a high confidence that the vulnerabilities we identify through the use of that process is going to solve the problem. So I think yes data is extraordinarily important when it comes to security.
▶ 1:06:45Uh however I think we can also use different techniques to make sure that we are not you know disclosing sensitive healthcare or other type of information. Mlaughlin Trellix uh signed CIS secure by design pledge uh which focused on bolstering transparency and vulnerability disclosure. How should companies think about vulnerability disclosure for AI systems? Thank you for the question.
▶ 1:07:13So the secure by design process the the self addestation was introduced by CISO was really quite significant for our organization for many organizations. You know, it encouraged us in to look at things in two ways. You know, it encouraged to go back and look at our own processes, make sure that not only our policies were fit for purpose, they've been implemented correctly, but it also changed some of the economic arguments.
▶ 1:07:35You know, now when I go talk to my board about why I want to do certain things, I can use the process that was put in place by CISA as an argument for certain investments. I think the same holds true for being able to bring those through to AI. Um I mentioned before we do not build or train our own model.
▶ 1:07:52deliberately decided not to do that because there is a risk of introducing bias by trying to do that and we focus really on being able to put the frameworks around it and use AI in a secure and responsible way for us knowing that not only that the AI models themselves the developers of those have applied secure by design principles have attested to those whether that's you know even though that might be just for government use to begin with it benefits us as a user of those it benefits any enterprise with being able to look to those
▶ 1:08:22particular models. But it then also allows any organization such as Trellix who takes one of those models, includes it in their own software and products to bring to the US government to be able to show that we've done the um the evaluation, the consideration of the AI that we use and the way that we're using it. Thank you very much, Mr. Fail. Microsoft's co-pilot studios studio enables individuals to build their own AI agents.
▶ 1:08:52How does Microsoft ensure agents are both secure by design, including protecting privilege access and tailored to the needs of individual Thank you for the question. In the case of copilot studio where individual end users are building agents that is done within a framework and a system uh that builds on the secure by design uh from the ground up from the model all the way up through the uh the system itself for Azure AI foundry.
▶ 1:09:21Um, as we use the co-pilot studio, it actually encourages users to adopt the defaults that are the correct secure by default such as the users authentication is used to retrieve data as opposed to the systems authentication itself. That's the single biggest mistake that organizations make when they try to build AI systems is they grant data access to the system instead of to the user and that is the easiest way to unintentionally leak data.
▶ 1:09:49So by building these constraints so that they just work and it's a paved path for end users to do the right thing. Uh we believe that using tools like copilot studio will help create a more secure by design output as there will be an explosion of software utilizing AI. It's important that that is done the right way. Having the guard rails there in place for them in a tool is one way to enforce that. Thank you. Mr. McGlaughlin, what are the most promising use cases for Agentic AI that you've seen?
▶ 1:10:20So for us, there already two main use cases. One is actually in security operations itself. As I mentioned before, the starting point for Genai was always just it's a helper. You can ask a question. It will give you some answers. That presupposes that the analyst is an expert and knows what to ask.
▶ 1:10:38for us by actually using Aentic AI to go and do the work beforehand before the analyst even turns up in the morning go find the evidence run a series of investigative steps built from our own knowledge of what are those typical things to do in a certain case and be able to present to that analyst here's the set of what's happened here's the evidence here's the reason I've made to and particularly using those agents to take different perspectives and argue amongst each other or having another agent sitting as chairman to actually make a consensus
▶ 1:11:08comes from that that helps move Alice forward. We've got to the stage we see with our customers that the application of Magenta Gay effectively is a 10-fold increase in the security operations capability that they have. It means they don't actually have to worry about who's on shift on a Sunday night and how good that person is and whether they're paying attention. The agentic AI is able to do most of that work for them and in many cases brings up the experience and the expertise of individual users.
▶ 1:11:38They may not have seen something before. Agentic AI can fill in those gaps. Thank you. And then we use it for software development as well. Wonderful. Thank you. And lastly, um Casey, you mentioned that security may differ at the data uh layer. Recent PaloAlto Networks report on generative AI notes that 14% of all data security incidents are caused by generative AI. How can model developers help protect their customers against data security Thank you for the question chairman.
▶ 1:12:08Um I think there are a couple of ways to do that. One is I would say um like Microsoft was talking about my panelist here poor access controls is one giving access to a system account rather than a user account. I think that's the first and foremost one that we need to really work on and making sure that the models only have access to the right data sets. Second one is adversial testing.
▶ 1:12:29I think we need to do a lot of testing around this agentic models or agentic applications whether it is red teaming on pentesting looking at also the model drifts and biases that they are going to be introducing. So I would say that you know those are the couple of ways we could do that. Thank you very much. I thank the ranking member for indulging me. Uh I now I yield back and I recognize the ranking member, the gentleman from California, Mr. Swallwell for 5 minutes. Thank you. Uh Mr.
▶ 1:12:57Damro, going back to the conversation about a brain drain and direct competition with China. Can you speak to why it's so important that we continue to invest in research and development and that universities that we invest in research and development in universities and that we keep US companies competitive in AI development and how does federal support of research and development support companies like yours?
▶ 1:13:28Thanks for that question. So I think it is apparent that we need the best talent in the world in order to build AI systems at scale. Um we need the the not only the brightest talent, we need people who are you know motivated to ensure that they are building systems that are going to solve our biggest problems.
▶ 1:13:49Um, we are a leader in both of those things in building incentives that enable people to come here and make sure that they are, you know, we're getting the best and brightest and our universities are the best in the world at attracting that talent. So, I can tell you when we look at attracting talent at Cranium, uh, we need the best AI talent. We need the best AI security talent. Um, we need people and frankly we don't we don't want to stop ourselves from bringing that talent in from anywhere, right?
▶ 1:14:17So I think we want to make sure that that um continues um through continued investment in uh both AI training um in the universities by enabling them to have freedom of uh you know people that are coming from wherever they are as long as they are talented and uh invested and motivated to make this a better uh place to study and build AI systems and we need to train and upskill those people that are here who want to use AI in building systems so
▶ 1:14:47that they can you know solve incredible problems whether those are small businesses or large businesses I think universities can play a role in that as well. So you know I just know when I think about my own teams and uh the people that you know are generally looking to even hire them um there's just a huge gap in the talent today we don't have enough AI engineers or AI security professionals to even go after the challenges that we see today. So we need to continue to make that investment. Mr. McLaughlin, do you agree with that answer or anything you wanted to add?
▶ 1:15:18I think as a as a global company, you know, we're always looking and building talent wherever we can. We have operations across the globe. Um, my mind, the AI industry is very much like the cyber security industry. There's just not enough people with the knowledge and skills and expertise yet. And so, wherever we can find them, wherever we can bring them is important to us. And Mr. Casey, what do you what do you think? I would agree to that.
▶ 1:15:40um generative a AI is rather new I would say and so there's not a lot of education that has been um done by universities I think universities are now just starting to understand where AI is heading and trying to incorporate that into the curriculums but I would agree that you know we should be encouraging any type of talent anywhere because there is a big talent gap in cyber security as is 500,000 jobs now you add AI on top of it and um pair AI with cyber
▶ 1:16:10security the gap is even more and based on each of your own training expertise when do you believe our schools should introduce AI into the classroom like at what level should a child or even a parent start to introduce a child to AI so that they're not left behind what would you say Casey I think they are already using it whether they're using Siri or Alexa or some
▶ 1:16:40other systems without knowing they're using AI behind the scenes. I think it's about teaching these kids, you know, the right way of using AI. So not using it for you know solving their homework problems or math problems but being able to do a critical thinking and that's what universities and schools have to start you know incorporating into the courses classwork and curriculum about how to leverage AI the right way and then use critical thinking and problem solving not use it just to solve your problems at hand
▶ 1:17:11like your homework right the input matters right the input matters the input absolutely right Mr. fails. I I believe that the uh the number one answer is whenever they're interested and so I I don't know that we need to u I don't know that we need to push it on anyone but there will be a time in which they are interested and the great thing about generative AI is that it is inherently usable as a human based on its understanding of language.
▶ 1:17:39It is one of the more usable pieces of technology. So, uh, as children or, uh, children in school are are learning, uh, to better communicate with humans, sometimes communicating with a generative AI, um, system can actually help improve their human communication as well. And, uh, so it can be a great tool from that perspective. I think the important thing is how to frame it so that children understand it is a map of human knowledge. Uh, it is not your conscience. Uh, there are a lot of things that it's not.
▶ 1:18:08Um but something that it is is uh a great map of human knowledge that you can interact with and I think just being present and being a part of that as a parent or as a school teacher to guide that experience will help them to frame and take the best advantage of AI in the future and and Mr. McLaclin and Mr. Danro if you wanted to add to this I'd welcome your wisdom on it. I'm not sure I'll give you wisdom for me when I was at school we learned how to go and use an encyclopedia. you look something up, then we moved on to using the internet.
▶ 1:18:38It's a tool like anything else. So, it's there to actually help people move forward, but knowing how to use an encyclopedia doesn't mean that you're suddenly a biochemist and can go and do the research. So, it's a great way to get them started. And what we'll see is a few of those to my my colleagues comments will either find it an easier way of learning, which is all to be good, or it will spark enough of their interest to go and pursue maybe what they would have done anyway, but start to build and be comfortable with the use of AI technologies. Great. Thank you, Mr. to Denver.
▶ 1:19:05I might be showing my age, but when I was uh younger, I I couldn't take standardized tests without I like they wouldn't let me use a calculator, right? So, you may or may not remember that. I think we're living in an age where using AI is considered cheating. Um I think we need to have guidelines for uh our educators to better inform how to use these tools, how to make sure that they're get, you know, students can get better use out of them. Uh just like any other level of abstraction, right? We used to not be able to use computers, we can now. Now AI is that next level of abstraction we need to integrate.
▶ 1:19:36I agree and I was in a classroom recently and I asked a robotics team how they used a AI and the teacher interrupted me and she said no no that would be cheating and I think what she was revealing was that that they was she was just not equipped and taught how to teach them it because the inputs would matter and if we understood what inputs they were using it's not cheating it's just where we're going. Mr.
▶ 1:20:00Phil, do you want to maybe amplify some of the examples that you gave earlier uh as far as uh what you're doing with AI and how we can build that out to scale? You in your opening testimony, you gave us some examples, but wanted to see if you wanted more time to talk about those.
▶ 1:20:18Certainly I think while this is still an emerging area of AIled investigations uh we are essentially able to create check sums of of human-led investigations u oftentimes solving a problem in cyber security as my colleagues on the panel know is about looking at the data through a different lens and as AI provides at least one additional lens for the humans that are working tirelessly on this project um of of securing our digital estate uh it is very valuable to bring AI to that as well but You can also use
▶ 1:20:48AI to bring it from several perspectives as was also discussed earlier in testimony. And so that ability to have a multiplicity of perspectives uh without tying up a large human team in the process is incredibly valuable. Uh we see various uh a variety of uh benefits when it relates to uh different types of investigations. Uh not every investigation can be solved by an AI agent today.
▶ 1:21:14uh but they're a number that is repeatably predictably good at and uh to see numbers like 8,000 times uh better return on investment. Uh also other scenarios where we've tested and seen that not only has it uh created a 3,000 times better return on investment, but it was twice as effective. And so sometimes we're able to do, you know, something at par with a human team, sometimes we're able to do something a little bit better. Uh but in the end, the humans are it's still at the direction of a human.
▶ 1:21:42the humans are uh are there to review, the humans are there to assess and the judgment calls and response options are are by humans as well for AIEled investigations. And can you speak to the difference between machine learning tools that have been around for a while and the AI tools for cyber defense that you're currently deploying? I think the the biggest change uh that really has occurred um is something that uh is is lost in many conversations on AI.
▶ 1:22:09And so when people hear AI, they think of everything they've been taught about traditional machine learning and they immediately assume that the model is learning. Uh and with large language model systems, uh the models are actually static. And so it when we're trying to defend systems and uh create more secure AI systems, it's actually important to know the behavior of that system we're trying to defend. If it's static, we defend it very differently than if it's dynamic and it's learning. Uh so I think that's really the biggest change.
▶ 1:22:39uh they are technologies that solve problems different ways in different areas and sometimes you need a model that's going to learn and continue to accept incremental training data and sometimes you need something that is uh pre-trained uh to a very large extent that you can use repeatably. Great. And and the chairman has has asked and I think it's a good idea uh that each witness uh provide just kind of a one minute summary of anything that you wanted to add to the record that you did not add uh in Mr.
▶ 1:23:07Uh Dan Bro, uh you went last to start with testimony, so I'll let you go first uh to close. So, one thing that I I I would love to add and I think there was some commentary around the surface area of AI systems. Um what we've noticed as we've gone and worked with organizations building uh and integrating uh generative uh AI as well as machine learning is that there's really not a great understanding if you're just asking people what is in their AI system.
▶ 1:23:36um we have a capability called code sensor and when we use that historically we see 15 to 20 times the amount of surface area in an AI system then if you just ask the developer what is it what's there uh one example we used uh was for an agentic system where the developers thought they had used four models we identified 126 using code sensor and the surface area uh had an an additional 300 technologies that were surrounding it so you think about that and now the you know connective tissue between egentic systems and existing tools tools to make decisions
▶ 1:24:06and then internal AI systems versus those at third parties that are now getting connected. This is a problem that we need an AI native solution for and I think that surface area challenge that I think was identified by one of the other panelists is one that really needs to be explored more more heavily. Thank you. Thank you Mr. Mccclaclin. I think two points I'd like to maybe reinforce.
▶ 1:24:28Um first of all it will be great when we actually have considerations which help us as adopters of an AI model understand what went into it how it was trained the biases and many of the commercial providers some of whom sitting on this panel already do that it helps us make the decision which to use and how to benchmark but I think we will always go into the use of those with the view that the AI model itself is inherently insecure and we have to then build controls around it for me it's very Much like
▶ 1:24:58email servers, yeah, you might know that how the email server was built. You might have it certified, but you then also got to check the emails going in and out of it. The same would be true of the prompts going into the I model, the responses that are coming back through. Great. Thank you, Mr. Fail. One area that I would like to add to the record is just how well equipped we are to deal with the AI revolution. Um, AI is often looked at as something that's inherently other.
▶ 1:25:25uh but it is actually a squarely human endeavor built on human knowledge and fielded by humans. Um as we we look at all of the experience that we have in parallel domains managing intelligence with human resources with government itself uh we have a lot of experience in uh in handling the good, the bad and the ugly as it relates to human intelligence. Uh we are going to be able to apply those lessons uh to also guide this journey of artificial intelligence.
▶ 1:25:53And so in many cases uh where uh where organizations may not know the next right thing to do with AI, they can look back to their experience of how have we delivered this more broadly as an organization. How have we delivered solutions here as a government uh through rigorous conversation, debate uh and collaboration uh we will solve these together and we will uh ensure that we continue to uh grow US leadership in AI and effectively cyber defense as well. Great. Thanks Mr.
▶ 1:26:23Casey, thank you for the question. Ranking Mangus Falwell, um, what I would say is that AI models are changing so rapidly that in some way AI is not replacing humans. Maybe humans are replacing models every day. There's new models every single day and we are changing these models. The question is like which model should we use like how do we know this model is trustworthy? This can be explainable AI or trustworthy AI.
▶ 1:26:51And I would like to see on the record you know if I can you know a baseline of AI models how these models have been tested what is the build of materials for these models you know maybe not provide the secret sauce but you know have this been tested against so and so criteria like you know what are the red teaming exercises what are the inputs that went into it and how are the software by or secure by design you know principles applied to this model so that a consumer of the model understand that hey when I use this model or
▶ 1:27:21compare this model versus the second model or maybe the same model iteration or revision one with revision two. I know what change went in, what are the consistent um what are the discrepancies, what are the changes and what are the gaps. Thank you. Great. Thank you and chairman. Before we close, I ask unanimous consent to submit into the record a report titled the AI tech stack a primer for tech and cyber policy. I yield back. Without objection. So ordered. Gentleman yields back. I thank the witnesses for their valuable testimony and the members for their questions.
▶ 1:27:52Members of the committee may have some additional questions for the witnesses and we would ask that the witnesses respond to these in writing. Pursuant to the committee rule 7E, the hearing record will will be held open for 10 days. Without objection, this committee stands adjourned.