▶ 0:06:46Committee on Homeland Security, Subcommittee on Cyber Security and Infrastructure Protection and Subcommittee on Oversight, Investigations, and Accountability will come to order. Without objection, the chair may declare the committee in recess at any point. The purpose of this hearing is to examine how rapid advances in artificial intelligence, quantum computing, and cloud technologies are reshaping the cyber security landscape in ways that affect both US defensive capabilities and the operational reach of our adversaries.
▶ 0:07:16The hearing will also assess how the adoption and governance of AI cloud infrastructure and postquantum security measures are strengthening or in some cases exposing US critical infrastructure, federal systems and sensitive data at and what steps government and industry must take to stay ahead of the rapidly evolving threats. I now recognize myself for an opening statement.
▶ 0:07:43Good morning and thank you for thank you all for being here. I want to begin by thanking Chairman Been and members of the subcommittee on oversight, investigations, and accountability for partnering with my subcommittee to hold this hearing. The issues before us today affect national security, economic competitiveness, and public trust, and they deserve attention that reflects their scale and importance. We are meeting at a time when the technology shaping our digital environment are also shaping the security and strength of the United States.
▶ 0:08:13Artificial intelligence, cloud computing and quan quantum technologies are now woven into how federal, state and local governments operate, how intelligence is collected and analyzed, how critical infrastructure functions, and how American companies compete in a global economy. These technologies offer extraordinary promise, but they also introduce risks that are advancing faster than many of the frameworks and systems designed to manage them.
▶ 0:08:42Artificial intelligence is changing the pace and character of cyber activity. It allows information to be processed at speeds far beyond human capacity and perhaps in some ways even comprehension. It enables automation across complex networks and supports decision making at scale. These capabilities can strengthen cyber defense and improve resilience.
▶ 0:09:03However, they can also be exploited to accelerate malicious activities, expand the reach of cyber operations, and make hostile actions more difficult to detect, attribute, and disrupt. Cloud computing has amplified both opportunity and risk. Cloud platforms have en enabled modernization across government and industry supporting flexibility, scalability, and innovation.
▶ 0:09:29Yet, they also consolidate vast amounts of data, access, and computing power into shared environments, raising the stakes of security, configuration, and oversight decisions. Quantum technologies present a longerterm challenge with significant implications. Much of our digital security relies on encryption to protect sensitive communications, verify identities, and secure critical systems.
▶ 0:09:55Advances in quantum computing raises serious questions about whether today's encryption methods will remain effective [clears throat] in the future. Our adversaries understand this risk and are already planning, including by collecting encrypted data now with the expectation that it may be accessed later. The threat environment surrounding these developments is intensifying.
▶ 0:10:17The People's Republic of China, PRC, and the Russian Federation, the the RF are investing heavily in advanced computing, automation, and data exploitation as tools of national power. They they view artificial intelligence, cloud infrastructure and emerging technologies as means to gain strategic advantage, conduct sustained cyber and intelligence operations and operate below the threshold of an open or kinetic conflict.
▶ 0:10:46China in particular has pursued a model that tightly integrates government, military, academia and the private sector. This approach allows innovations developed for commercial purposes to be adapted quickly for state use in cyerspace. It supports operations built for scale and persistence, including the use of automated tools to scan networks, identify vulnerabilities, manage stolen credentials, and analyze large volumes of data across many targets simultaneously.
▶ 0:11:15[snorts] At the same time, these technologies provide the United States with powerful tools to strengthen security and resilience. Artificial intelligence can improve threat detection and response. Cloud computing can enhance reliability and operational flexibility. Advances in quantum research may ultimately yield new security capabilities, but also there's a downside. The challenge lies in ensuring these benefits are realized without introducing vulnerabilities that adversaries can exploit.
▶ 0:11:44The Department of Homeland Security and the Cyber Security and Infrastructure Security Agency or CISA play an essential role in this effort. Their work on cloud security practices, artificial intelligence, risk management, and preparation for future changes in encryption helps shape how federal agencies and critical infrastructure operators address emerging threats. Congress also has an important responsibility.
▶ 0:12:07Oversight helps ensure that security keeps peace with adoption that roles or pace rather with adoption that that roles and responsibilities are clearly defined and that risks are addressed early rather than after they've condu created serious harm. This is not how not about slowing innovation. It is about making sure innovation strengthens the nature rather than exposing it.
▶ 0:12:30The decision being made now about how artificial intelligence, cloud computing, and quantum technologies are secured will shape the country's security prosperity for years to come. And I would argue also our role as the quite frankly sole superpower. I appreciate our witnesses for being here. I look forward to their testimony and the discussion ahead.
▶ 0:12:54I now recognize the ranking member for the subcommittee on oversight, investigations, and accountability, the gentleman from Michigan, Mr. Thanodar, for his opening statement.
▶ 0:13:04Thank you, Chairman Ugles. Appreciate u this hearing and good morning to all of our witnesses. Uh look forward to hearing your thoughts. For two decades, hostile nations have increasingly sophisticated cyber attacks against the United States.
▶ 0:13:32These attacks have been used to spy, steal intellectual property, critical infrastructure, and demand ransom payments. China, Russia, Iran, North Korea are aggressively using advanced cyber capabilities to threaten our national security and economic prosperity.
▶ 0:14:02China is both the most active and persistent cyber threat and is also the only country with both the desire and the ability to reshape the world order.
▶ 0:14:16Which is why it is extremely shocking that President Trump recently agreed to allow Nvidia to sell advanced artificial intelligence chips to China. Really shocking. And let's just see some background information here. Why did this decision the president made?
▶ 0:14:46The president was quick to sell out America's security after Nvidia's CEO attended a $1 million per play dinner at Mara Lago and and donated to Trump's White House So much so much for
▶ 0:15:16[snorts] Trump's own Department of Justice has warned that China is seeking to become the AI leader by 2030 and plans to use AI chips to modernize its design and test weapons of mass destruction, and deploy advanced surveillance tools.
▶ 0:15:39We should be and dismantling threat actors whose actions threaten our national interest, not enabling them. The rapid development of emerging technologies, including advanced AI and quantum computing, enables and enhances security risk.
▶ 0:16:03These advanced technologies not only accelerate the cyber abilities of countries such as China, but they also make it easier for countries that are not wellresourced and enable a growing threat from organized criminal groups. Over the past year, cyber attacks have become faster, more widespread, and harder to detect.
▶ 0:16:30As AI assisted cyber attacks hit harder and faster, it is critical that Congress extends CESA 2015, the Cyber Security Information Sharing Act of 2015. CISA 2015 provides privacy and liability protection to companies to encourage them to share data about cyber vulnerabilities and threats.
▶ 0:17:00These protections are necessary to fully understand the risk and facilitate collaboration between the federal government and the private sector. CISA 2015 expires next month.
▶ 0:17:18A 10-year extension is the best reauthorization strategy [snorts] that will also provide the private sector with asurances while eliminating the risk of this authority lapsing. I look forward to hearing from our witnesses how else we can best defend against cyber attacks that are leveraging powerful emerging Thank you and I yield back, Mr.
▶ 0:17:48Chair.
▶ 0:17:48Thank you, Ranking Member Thanadar. And I look forward to uh following up on your your insightful comments. I now recognize the chairman for the subcommittee on oversight, Investigations, and Accountability, the gentleman from Oklahoma, Mr. key for his opening statement.
▶ 0:18:02Thank you, Chairman Ogles. Good morning. Thank you to our witnesses. Um very complex subject. Um many of us in all vulnerability feel really unqualified to be in these discussions. Grateful we're going to have some expertise to to drive into the the massive amount of vulnerabilities that AI is presenting on on our cyber front.
▶ 0:18:22As chair of the subcommittee on oversight, investigations, accountability, I'm looking forward to partnering with the subcommittee on infrastructure protection to focus on this topic, explore ways that Congress can assist the Department of Homeland Security in countering this new threat. Um, this integration of AI into cyber attacks should concern every American. The recent cyber attack leveraging anthropics AI infrastructure showed that complex attack campaigns can now be conducted with little to no human interaction at speeds faster than a human could replicate.
▶ 0:18:51We've all seen how AI can easily streamline tasks that would otherwise be very labor intensive both in business and everyday life. Now that an attack like this has successfully taken place, we can expect to see more events like this in the future. The proof of concept is there and even if US-based AI companies can put safeguards against using their models for such attacks, these actors will find other ways to access uh this technology.
▶ 0:19:15China is our most significant cyber threat actor and it continues to search for tactics to critical US systems and prioritize the development of advanced computing technology and AI that supports its economic and strategic goals. Cyber espionage has been a key part of their plan. China's plan ongoing campaign of stealing intellectual property is decades old. They now have new tools and this will fuel uh rapid technological advancement at the expense of American innovators.
▶ 0:19:42As this committee has highlighted over the years, cyber actors linked to China pose a threat on an unprecedented scale targeting US companies, critical infrastructure, and the federal government. As technologies like AI continue to advance at such speeds, we have to be vigilant, strategic, and protecting intellectual property and our national security. From an oversight perspective, we need to make sure that federal civilian agencies are taking the proactive steps needed to protect their networks against intrusion.
▶ 0:20:07technology doesn't advance on the government's timeline and we can't afford to have cyber security practices moving at such speeds absent government interdiction. That path leaves us reacting to security failures instead of proactively confronting today's threats. This is an area where federal government can partner with and learn from the private sector to implement best practices and incorporate needed technology.
▶ 0:20:31Federal government needs to be better at sharing information on cyber threats between federal agencies and with private stakeholders in a timelier manner. I hope to learn in today's hearings how Congress can empower the Department of Homeland Security and its sub agencies to counter this threat and ensure safety integrity of US-based infrastructure.
▶ 0:20:47And I want to thank again our panel of witnesses for joining us to dis today to discuss the the cyber attack imple implementation of that and Congress and American people need to consider how how we can work with you all and your expertise to safeguard our critical infrastructure. With that, I want to yield [clears throat] back to Chairman
▶ 0:21:06Thank you, Chairman Been, and just echo uh your sentiments. Uh other members of the committee, uh you're reminded that you uh can submit for the record an opening statement. I'm pleased to have a distinguished panel of witnesses before us today on this critical topic. Pursuant to committee rule 8C, I ask that our witnesses please rise and raise their right hands.
▶ 0:21:33Do you solemnly swear that the testimony you will give before the committee on homeland security of the United States House of Representatives will be the truth, the whole truth, and nothing but the truth. So help help you God. Let the record reflect that the witnesses have answered in the affirmative. Thank you and please be seated. I would like to now formally introduce our witnesses. Dr.
▶ 0:21:56Logan Graham serves as the department head uh head for of the frontier red team at Anthropic where he leads efforts to evaluate the behavior and potential misuse of advanced AI systems as model capabilities continue to scale. His work focuses on identifying national security risk posed by frontier AI, including its potential use in cyber espionage and offensive cyber operations as well as developing safeguards to detect and disrupt malicious activity.
▶ 0:22:26Prior to joining anthropic, Dr. Graham held roles at Google X and Babylon Health. He also also previously served as special adviser to the prime minister of the United Kingdom, contributing to national science and technology policy and the development of the UK's AI strategy. Dr. Graham earned his undergraduate degree degree in economics from the University of British Columbia and completed his PhD in engineering science at the University of Oxford where he was a roads scholar. Thank you, sir. Mr.
▶ 0:22:55Royal Hansen is vice president for privacy, safety, security engineering at Google, where he leads the engineering team responsible for securing Google's global technical infrastructure and protecting billions of users worldwide. Prior to joining Google, Mr. Hansen held SEC senior security leadership roles in the financial services sector, including at American Express, Goldman Sachs, Morgan Stanley, and Fidelity Investments. Mr. Mr.
▶ 0:23:22Hampton holds a bachelor of arts in computer science from Yale University. Thank you, sir. Mr. Eddie Zurvigon is the chief executive off officer of Quantum Exchange. Under his leadership, Quantum Exchange works with government and private sector partners to prepare critical systems for emerging cyber and quantum enabled threats. Mr.
▶ 0:23:44Reserve Gone brings extensive experience in corporate leadership, operations, and restructuring, including prior service as a managing director in the principal investments group at Morgan Stanley, where he oversaw technology and infrastructure investments across the United States and Latin America. Elij holds a bachelor's degree in accounting and a master's degree in taxation from Florida International University and a master of business administration from Dartmouth. Thank you, sir. Mr. Mr.
▶ 0:24:12Michael Coats is the founding partner of Seven Hill Ventures, an early stage venture firm focused exclusively on cyber cyber security investments addressing enterprise operational and national security challenges. It brings more than two decades of experience securing large-scale digital platforms and advising organizations on cyber risk. Mr. Coats previously served as the chief information officer at Twitter and also led security efforts at Mozilla. Mr.
▶ 0:24:39Coats holds a bachelor of science in computer science from the University of Illinois Urbana Champagne and a master of science in computer information and network security from Depal University. I think each of our Thank you, sir. I thank each of our distinguished witnesses for being here today.
▶ 0:24:56Um this is a topic that you know a year and a half ago was somewhat of a niche for lay persons but for you experts obviously uh clearly recognized that um this was going to be quite frankly the the next uh arms race uh threat battlefield uh as we go forward.
▶ 0:25:17And so what you're doing today here before Congress means more than I think we can possibly comprehend as we begin this discussion and quite frankly dive into the emergence of this technology. And with that I now recognize Dr. Graham for five minutes to summarize his opening statement.
▶ 0:25:36Chair Ogul and and Bin Ranking Member Thanodar members of the committee thank you for the opportunity to testify today. Anthropic is a leading frontier AI model developer working to build reliable, interpretable, and steerable artificial intelligence.
▶ 0:25:53Our flagship AI assistant, Claude, serves millions of Americans and trusted partners worldwide, from Fortune 500 companies and US government agencies to small businesses and cutting edge startups and consumers, enhancing productivity on tasks including software engineering, data analysis, and scientific research. At Enthropic, I lead the frontier red team. Our job is to build an early warning system for advanced risks from AI so that we can mitigate them and to help the world prepare as far in advance as possible.
▶ 0:26:24Transparency is a fundamental value for Anthropic and we believe it should be an industry standard. That is why we published a report about how in midepptember 2025, Anthropic detected suspicious activity that our investigation determined to be a largely autonomous sophisticated cyber espionage campaign conducted by a group sponsored by the Chinese Communist Party. To be clear, Claude's code was not compromised, nor were Anthropics Labs infiltrated.
▶ 0:26:51Instead, this group maliciously misused Claude to automate large portions of cyber attacks against their targets. We estimate their use of the model allowed them to automate approximately 80 to 90% of the work that previously required humans to do. This is a significant increase in the speed and scale of operations compared tra to traditional methods.
▶ 0:27:13Further, this group invest invested significant resources and used our sophisticated network used their sophisticated network infrastructure in order to circumvent our safeguards and detection mechanisms prior to being detected. They then deceived the model into believing the tasks were ethical cyber security tests. The campaign consisted of a few distinct phases. First, a human operator provided targets to Claude, directing it to conduct autonomous reconnaissance against them in parallel.
▶ 0:27:40Second, acting on the human operator's direction, Claude leveraged third party software tools to search for vulnerabilities in these systems. The third and final step was to task Claude to exploit these vulnerabilities and extract sensitive information from the targets which was only successful in a handful of cases.
▶ 0:27:57We detected this campaign within two weeks the attackers first confirmed offensive activity triggering a swift response including account bans strengthening our safeguards entity notifications authority coordination and indicator sharing with partners. We have reached an inflection point in cyber security. It is now clear that sophisticated actors will attempt to use AI models to enable cyber attacks at unprecedented scale.
▶ 0:28:24This threat is not unique to Claude and affects all AI models. That is why we've been open and transparent about this incident and one of the reasons why I'm grateful to you that you are holding this hearing today. Industry and government must collaborate to prevent this misuse and enable cyber defenders to prepare to address these risks. There are at least three things that should be done immediately. First, there needs to be rapid testing of models for national security capabilities.
▶ 0:28:52Government evaluations like those conducted by NIST's Center for AI standards and innovation give us visibility into model capabilities and secure security. Codifying and expanding this process is critical. Second, there must be robust threat intelligence sharing. Frontier AI labs and the US government need stronger channels to share indicators of misuse as exists in critical infrastructure Third and finally, industry should invest in empowering our cyber defenders.
▶ 0:29:21We must make models useful for defenders and get them into their hands. Anthropic is improving its models for cyber defenders and building tools, for example, that can patch We cannot lose sight of the strategic picture. The United States and its allies must maintain leadership in AI.
▶ 0:29:41The Trump administration has taken important steps to advance US AI leadership, including accelerating the buildout of AI infrastructure, promoting federal adoption, and strengthening security testing and coordination. We strongly support these efforts. Equally critical is maintaining the United States advantage in computing power, the single most important input into developing powerful AI models. The United States currently has a significant edge over the CCP in access to advanced chips.
▶ 0:30:12But if advanced compute flows to the CCP, its national champions could train models that exceed US frontier cyber capabilities. Attacks from these models will be much more difficult to detect and deter. We are in a race against threat actors who will stop at nothing to misuse AI for cyber attacks. Our response must be urgent, coordinated, and focused on securing systems faster than they can be attacked. Thank you again for the opportunity to testify, and I look forward to your questions.
▶ 0:30:46Thank you, Dr. Graham. And I recognize Mr. Hansen for five minutes to summarize his opening statement. Chairman Garbrino, Ogals, Brooken, ranking members, Thompson's, Mwell, Thaner, and members of the committee and SP committees. Thank you for the opportunity to speak with you today. My name is Royal Hansen and I serve as the vice president of privacy, safety, security, engineering at Google. And as discussed, uh uh we build the financial technology that keeps billions of people safe online.
▶ 0:31:15As this committee knows, we stand at a critical technological inflection point. Rapid advances in AI are unlocking new possibilities for the way we work and accelerating innovation in science, technology, and beyond. Some of these same AI capabilities, however, can also be deployed by attackers, leading to understandable anxieties about the potential for AI to be misused for malicious purposes.
▶ 0:31:40Until recently, our analysis showed that governmentbacked threat actors were using generative AI primarily for common tasks like troubleshooting, research, and content generation. Over the past year, Google's threat intelligence team has identified an important shift with adversaries not only leveraging AI for productivity gains, but deploying novel AI enabled malware in active operations.
▶ 0:32:04We have identified malware families that use LLMs to generate malicious scripts, obuscate their own code to evade detection, and use AI models to create malicious functions on demand rather than hard coding them into the malware. This marks a new operational phase of AI abuse involving tools that dynamically alter behavior midexecution. While still nent, this development represents a significant step toward more autonomous and adaptive malware.
▶ 0:32:35We believe not only that these highly sophisticated threats can be countered, but that AI can supercharge our cyber defenses and enhance our collective security. LLMs can unlock new and promising opportunities from sifting through complex telemetry to secure coding, vulnerability discovery, and streamlining operations.
▶ 0:32:55Google's AI based efforts like Big Sleep and OSS Fuzz have demonstrated AI's capability to find new zeroday vulnerabilities in well- tested, widely used software. And recently we developed code mender, an AI powered agent that utilizes the advanced reasoning capabilities of our Gemini models to automatically fix critical code Code mender scales security, accelerating time to patch across the open-source landscape.
▶ 0:33:26It represents a major leap in proactive AI powered defense and includes features such as root cause analysis and self- validating We believe the private sector, governments, educational institutions, and other stakeholders must work together to maximize AI's benefits while also reducing the risks of abuse. As innovation moves forward, the industry more broadly needs security standards for building and deploying AI responsibly.
▶ 0:33:55That's why Google introduced the secure AI framework or safe, a conceptual framework to secure AI systems. Our recent expansion to safe 2.0 know addresses the rapidly emerging risks posed by autonomous AI agents and extends our proven framework with new guidance on agent security risks and controls to mitigate them. We published a comprehensive toolkit for developers that includes resources and guidance for designing, building, and evaluating AI models responsibly.
▶ 0:34:26We've also shared best practices for implementing safeguards, evaluating model safety, and red teaming to test and secure AI systems. We are committed to developing technology responsibly and in a manner that is built for safety, enables accountability, and upholds high standards of scientific excellence. For example, as part of our industry-leading security architecture, we do not offer our core products such as search, Gmail, maps, and YouTube in mainland China.
▶ 0:34:55We also do not conduct AI research, offer domestic cloud services, or have data centers in mainland China. Our comprehensive approach means we secure all components of the AI ecosystem, including data, infrastructure, applications, and As governments and civil society leaders look to counter the growing threat from cyber criminals and state-backed attackers, we're committed to leading the way in using AI to tip the balance of cyber security in favor of defenders.
▶ 0:35:26Finally, this is more than a job for me. My youngest son uh now 15 has suffered from a chronic illness for the past five years during which time he has rarely moved from lying down in a dark cold room. One of the few things that gives him hope is that technologies like AI and quantum will continue to yield scientific and medical breakthroughs that will alleviate his suffering and the suffering of millions like him.
▶ 0:35:52Security and safety are among the critical foundations that will enable this science at digital speed. I am personally committed to that mission with the help of both the public and private sector. We look forward to answering your questions.
▶ 0:36:07Well, thank you Mr. Hansen. Um just kind of point of first of all uh thank you for sharing and I look forward to hearing more about uh what you're working on sir. Uh we do have votes. Um so we will take a short recess. I would ask all members of the committee after the second vote to come back here as promptly as possible so that we can get to the remaining two witnesses and their opening testimony. Uh I plan on starting as quickly as we can if that's possible. So thank you all.
▶ 0:36:35We will take a short Call
▶ 1:22:14to order. The Committee on Homeland Security, Subcommittee on Cyber Security, Infrastructure Protection, and Subcommittee on Oversight, Investigations, and Accountability will come to order. Uh, again, thank you, Mr. Hansen. And then would like to recognize Mr. Zervigon for five minutes to summarize his opening statement. And again to the witnesses, we appreciate your patience.
▶ 1:22:37Thank you. Good morning, Chairman Garberino, ranking members Thompson, Thanodar, Chairman Ogles, Chairman Bkin, and members of the committee. Thank you very much for the opportunity to testify today. My name is Eddie Zervagan and I'm the CEO of Quantum Exchange. We were founded in 2018, two years after NIST was tasked with evaluating the algorithms to take us into the quantum age.
▶ 1:23:01Quantum Exchange is a cyber security company that interoperates with the major network infrastructure vendors to enable encryption that protects data today and into the postquantum future with head with hardware and software solutions developed entirely in the United States. While quantum computing and AI promise new breakthrough capabilities, they also introduce significant risk to our national and economic security. They must be urgently addressed.
▶ 1:23:28AI can enable faster, more dangerous cyber attacks, and quantum computers can break current encryption standards, exposing sensitive data. These capabilities will be weaponized by our adversaries, creating a very dangerous imbalance in our cyber defenses. For more than 50 years, encryption has safeguarded our data from theft and misuse. We've had the luxury of a set it and forget it mindset, trusting its strength by default. That era is now ending with quantum computing. Think about it like this.
▶ 1:23:57Imagine all digital communication form uh from government agencies sent over the past 10 years being readable by our adversaries. This is a real threat to the US today. Rogue nation states and state sponsored terrorist groups are collecting encrypted data now to decrypt later with a quantum computer. Further, now imagine our adversaries reading sensitive government data in real time and altering it without anyone knowing. This could be tomorrow's reality.
▶ 1:24:25Public and private sector work on a quantum resilient solutions is ongoing. Technologies like postquantum cryptography PQC or quantum safe encryption algorithms are part of the solution but not the complete answer. Despite our best efforts, postquantum cryptography may still be vulnerable to quantum related attacks. All of which reach all of which with raises the fundamental question and challenge what happens when an algorithm breaks because it is a when and not if.
▶ 1:24:54Every agency CIO, enterprise SISO, security vendor and network gear manufacturer must be able to answer that question. In our view, what's needed to ensure data security and confidentiality in the quantum age is an architectural approach, not just a new algorithm. This architectural approach enables agencies to focus on securing the network that data travels on to strengthen the existing infrastructure against quantum attacks while minimizing disruption to existing operations.
▶ 1:25:24This is how our government agencies need to be protected. When you have valuables in your house, the first step isn't going out and buying a new jewelry box with biometric access controls. It's locking your front and back doors so the house is secure and harder to get in. Once your home is secure, then you can figure out what specific rooms need further locks or security measures to protect your valuables and sensitive Federal agencies handling sensitive data need to act now and follow the leads set by Customs and Border Protection.
▶ 1:25:53Our work with CBP to incorporate PQC's across their network infrastructure in 2026 has shown that you can begin to secure your networks today with quantum resistant technologies in a FIPS validated way without having to rip and replace your entire infrastructure. I cannot stress enough the timing here is critical. Agencies that fail to prepare today risk leaving their data vulnerable.
▶ 1:26:18Every day that we are not quantum resistant is another day that data is harvested to be decrypted later. It is important to note that we at Quantum Exchange are not the only ones advocating for action today. The quantum industry coalition of which we are part of as well as Amazon Web Services, Google, IBM, Microsoft, Accenture and others believe that a agencies handling sensitive government data should be actively working and preparing for the transition and should begin migrating to high-risisk systems to FIPS/NIST
▶ 1:26:49validated PQC where possible. Having the opportunity to meet with several of your offices, I was often asked, "What can Congress do?" Through this committee's leadership and building off the work previously done, Congress can accelerate the timelines for PQC compliance, allocate the budget to allow migration process to begin, and work with leaders within the administration to encourage adoption as the technology is readily available and deployable. Today, America's defenses cannot stop at our physical borders.
▶ 1:27:20through your leadership and efforts and in partnership with private sector partners like us, we can and secure we can and will secure America's digital borders too. In closing, I want to thank you again for the opportunity to offer some thoughts today and I look forward to your questions. Thank you.
▶ 1:27:37Thank you, Mr. uh Mr. Zeriggon. I now recognize Mr. Coats for five minutes to summarize his opening statement. Chairman Ogles, Ranking Member Suaveell, Chairman Bkin, and Ranking Member Tanidor. Thank you for the opportunity to testify. I'm honored to be here to discuss the changing cyber security landscape and the impacts of artificial intelligence and quantum computing.
▶ 1:27:59My perspective is grounded in over 20 years of experience in cyber security, including serving service as a chief information security officer, leadership in global software security organizations, founding a technology startup, and investing in cyber security Today we sit at the precipice of significant change. While much attention is paid to AI and future breakthroughs like AGI, the most immediate impact on cyber security is not the creation of entirely new threats.
▶ 1:28:25Instead, AI and quantum technologies are collapsing the time, cost, and skill required to conduct cyber operations. These changes are outpacing existing technical, regulatory, and operational defenses, fundamentally reshaping the threat landscape. Historically, different attackers, nation states, cyber criminal organizations, and loan activists were constrained by skill, resources, and scale.
▶ 1:28:50The most sophisticated attacks were largely limited to nation states, while criminals focused on repeatable, monetizable techniques. That constraint is rapidly changing. Recent real world examples such as the report issued by Anthropic show AI systems being used as a central orchestration layer for complete cyber operations, coordinating reconnaissance, exploitation, and execution with limited human involvement.
▶ 1:29:14While the techniques themselves may not be novel, the orchestration and automation represent a meaningful shift in adversary Agentic AI further removes human constraints. Autonomous systems are not limited by time, fatigue, or attention. And research recently released from Stanford, Carnegie Melon, and Grace Swan AI already show AIdriven penetration testing performing at or above the level of highly skilled professionals at a fraction of the cost.
▶ 1:29:41At the same time, AI is accelerating vulnerability discovery and exploitation. AI powered software analysis is capable of identifying previously unknown zero-day vulnerabilities faster than ever. Yet for many organizations, the long-standing challenge has not been awareness that a vulnerability exists, but rather the inability to patch and remediate quickly. As attack timelines compress, this operational inertia becomes more dangerous. The practical result is a dramatic reduction in the time available for defenders.
▶ 1:30:12Comprehensive attacks are easier to launch. The pool of capable adversaries expands and smaller organizations such as hospitals, schools, and small businesses are increasingly exposed to the same level of adversarial capability once reserved for critical national infrastructure. This compression of time changes the n nature of cyber risk itself. Defenders are often no longer responding to early indicators, but to attacks that are already in progress.
▶ 1:30:37Intelligent automation allows attacks to become continuous rather than episodic, eroding assumptions that organizations can recover between incidents or rely on periodic assessments. The widening gap between machine speed attacks and human speed defenses means cyber security outcomes are increasingly determined by whether defenses can operate at comparable speeds. These shifts have clear implications for defense policy and coordination.
▶ 1:31:03First, secure by design principles must become a baseline expectation, particularly as AI increasingly writes and modifies software. Second, regulatory clarity is critical. Fragmented or ambitious regulations can slow defensive responses in environment where speed matters. Third, public private coordination remains essential, ensuring that defensive learning keeps pace with adversarial innovation.
▶ 1:31:28Fourth, defensive capabilities must increasingly rely on automation and autonomy as purely human-driven defenses will struggle to keep up. And fifth, finally, uh quantum prepar preparedness is necessary. While postquantum cryptographic standards exist, the challenge lies in the time and coordination required to migrate existing systems before an adversary achieves cryptographically relevant quantum capability. Finally, trust and transparency in AI systems are crucial.
▶ 1:31:57AI reflects the data incentives and governance under which it is trained. In a security related context, understanding potential model bias and model origin is as important as performance. Artificial intelligence and quantum computing are accelerating forces that dramatically reshape cyber security. Our success will depend on whether our technical, operational, institutional responses can adapt at a comparable pace. Thank you, and I look forward to your questions.
▶ 1:32:25Thank you, Mr. Coats [clears throat] members will be recognized by order of seniority for their five minutes of questioning and I recognize myself for five minutes. Dr. Graham Anthropic's investigation into the recent PRC affiliated cyber incident involving Claude suggests we may be approaching a turning point in how cyber operations are conducted where AI systems once asked uh tasked by human operators can execute and refine large portions of a cyber attack at machine
▶ 1:32:56speed rather than human speed. And obviously you touched on this in your opening statement, but uh should this incident be understood as an early warning of the future of AI systems, how they're autonomously, you know, writing and adapting uh to systems and quite frankly from a defensive perspective, uh you know, what capability gaps do we have? Where do we need to be anticipating?
▶ 1:33:21I mean I see I see her a horizon that we can't quite define uh because of the rapidness uh and just the evolving nature of the technology. I go back to kind of the arms race. There was a point at which between the US and Russia there there was this day there was this you know mutually assured destruction where it was at some point we all had enough nukes to kill everybody and blow the whole whole world up. It came it was all about delivery systems at that point. AI is different. There is no horizon.
▶ 1:33:49there is no kind of point at which I think it stops or there's a ceiling. So please uh take it
▶ 1:33:58You're you're correct that we are at a change point and there are a couple change points here. The first that we see now is to our understanding this is the first time where these models will now be sought and used by sophisticated state actors. We've been tracking this trend line for many years. This is the clearest evidence for the first time that this is now happening. But it's also possible this gets more serious and the stakes become much higher.
▶ 1:34:24As you say, uh it's very possible that attacks from here on might scale if we don't properly secure and safeguard the models. Uh and it's also possible that while in this case we didn't see an instance of novel uh or novel methods of attack, it's very possible that models could get that good. Um what's important now is a few things. First, it's it's really hard to win if we can't see the playing field. And I think the easiest way to start is continuing to evaluate the capabilities of these models.
▶ 1:34:54This is something industry should do. This is something government should do. Uh second, we should be sharing uh threat intelligence as it happens so that we can mitigate as fast as possible. Uh and third uh as you say we need to make sure defenders have the advantage particularly uh the United States make sure that it defends uh itself faster than it can be attacked uh and we are working very hard and I think all the industry needs to work hard to make that happen. Yeah, I follow up onto that point.
▶ 1:35:21You know, clearly when you look at the investments that China is making on these quantum capabilities, AI, etc. Um, you know, there is a um a requirement uh between, you know, their private sector, if you want to even call it a private sector because most of it is stateowned, that any innovation is immediately shared with the state.
▶ 1:35:41And so as you mentioned there's going for us to be successful there's going to have to be this collaboration between private and uh and government quite frankly but one of the things and obviously there that's easier to accomplish but there's I I I foresee a need um where the industry itself is going to have to be sharing information. Of course the problem you get into there is the pri proprietary nature of things. the uh you know obviously there's the monetization factor that comes into that but at the end of the day we're talking about the homeland.
▶ 1:36:12So how do you see that working in practice? Understanding the complications that we have essentially in a free market. Then another layer to that is essentially the five eyes, the seven eyes, our European partners who are aligned with us in our values, who understand the existential threat that China poses. And again, it's it's it's important for everyone to understand that China is probing us daily to look for weaknesses and opportunities to take advantage of information that's not properly secured.
▶ 1:36:40What's different about this is the the leveraging and the scale uh and the percentage if you will that AI was leveraged sir
▶ 1:36:48it is very very important that industry does share the information that it has uh between uh itself um it's very important it shares that with with government uh it's very important that industry develop solutions now whether it's by improving the models or building tools and putting them in the hands of the defenders uh I think just making the models good enough isn't sufficient we need to make sure people are using it to proactively defend critical infrastructure.
▶ 1:37:12One way that I think government can be extremely helpful here is identifying the critical infrastructure that needs to be defended in this new era of cyber security and allowing industry to point its its talents and innovation towards that.
▶ 1:37:25Well, I want to thank again all of you for being here and quite frankly to Anthropic for your report. I think it was one of those inflection points that we all understood the seriousness of this, but your report I think really put a light on where we're at and where and some of our vulnerabilities. Um, and now recognize [clears throat] the ranking member, the gentleman from Michigan, Mr. Thanodar, for his five minutes of
▶ 1:37:49Thank you again, Chairman Ogles. Appreciate all of our witnesses. Um, you know, I remain deeply worried and concerned about President Trump's decision to export allow export of advanced chips to China. I just don't understand uh other than his desire to please a donor.
▶ 1:38:13I just don't understand why would we give uh such advanced technology to an adversary like China who can then use this technology to attack us who could use this technology to cyber attack our critical infrastructure uh Dr. How would China having access to this advanced chips, how will that help advance their AI technology is that will that pose a threat to the United States, our national security?
▶ 1:38:45We view it as first extremely important that America retains its AI leadership. [snorts] The most important input to this is the compute advantage. My concern from watching these models progress in their capabilities, especially as a result of the cyber espionage campaign, is that if Chinese frontier labs have access to similar amounts of compute, they could train models that [snorts] are equally or more capable in the cyber domain and that this could uh unleash new scale and new sophistication
▶ 1:39:16and we will have a harder time detecting and defending it.
▶ 1:39:18Thank you. Thank you. I want to shift my focus. I only have a little limited time. I want to shift my focus on immigration. Uh you know in his first term, President Trump's first term and now in his second term, there is just so much of hate against immigrants and yet we know and I hope the panel agrees with me that the United States technology industry has benefited greatly from uh immigrants.
▶ 1:39:45Uh just by answer yes or no from the witnesses does your companies uh have immigrants skilled immigrants and do you depend on them?
▶ 1:39:56Yes. No.
▶ 1:39:57Anthropic is composed of many of the best talent from around the world.
▶ 1:40:03Anybody thinks uh we should have less of skilled immigrants on the panel here? Should we restrict access of immigrants to our technology companies? Immigrants who help us keep on the edge? Well, certainly, you know, I'm myself an immigrant.
▶ 1:40:2124 years old, I came here escaping poverty in India, got a PhD in chemistry, uh became a serial entrepreneurial many pharmaceutical companies, uh developing technology that helped us stay on top of innovation.
▶ 1:40:38uh you know this while it is important that American uh jobs be protected it's important that we create skills but at the same time our tech industry heavily depends on uh skills skill sets uh immigrant skill sets um have uh the actions of the Trump administration how how has acts of the Trump administration made it difficult to retain international talent in your companies with regard to both international
▶ 1:41:08workers choosing to leave or being forced to leave due to discrimination charge changes, the hardship that they have in terms of getting their status adjusted, getting their green cards, the long delayed in processing, uh making it harder to get an H-1B visa.
▶ 1:41:26Just wanted to uh understand what kind of uh impact uh these administrations positions are uh doing to your ability to grow your companies, go your grow your uh techn new technology for the United States.
▶ 1:41:44Anybody? Yeah.
▶ 1:41:46Uh well, it's not not my issue area that I cover in in the company. uh speaking for my team, it's really important that I uh find and hire the best people around the world that are committed to to our mission of making uh AI stay secure and ensuring America's
▶ 1:42:01Yep. Uh anybody else? Uh how important is immigration?
▶ 1:42:08I just again it's not we you'd have to talk to our HR department so we can come back to you with you. I'll relay that question to the teams. What percent of your organization has immigrants?
▶ 1:42:20Uh I wouldn't know the exact number but certainly we do have green cards and and immigrants that work at Google.
▶ 1:42:27Thank you. Thank you. Anybody else? You know again uh the need continues and for us America to have its edge on innovation uh whether it's cyber security AI quantum uh we must have skilled workforce and if that means we have to depend on uh immigrants so be it. Thank you. I yield back.
▶ 1:42:52The gentleman yields back. I recognize the chairman of the subcommittee on oversight investigations and accountability. the gentleman from Oklahoma, Mr. Been.
▶ 1:43:02Thank you, Mr. Chairman. Mr. Hansen, just before I get started, uh prayers over your son. May the Lord do what human hands can't. Um appreciate your passion. Appreciate your vulnerability in sharing that. Also [clears throat] appreciate what you expressed about limiting uh services for mainland China. I think that's great that your company's willing to do that.
▶ 1:43:22Um, my hope is is that others would watch your concern proprietary information and uh the desire to make sure that US citizenry is protected and follow your lead. Um, Mr. Graham, you talked about that you felt like that robust intelligence sharing could be enhanced.
▶ 1:43:48So in what is it that you are seeing that could be improved upon about of course your front line free market government learns from it. What can the Fed be doing to a greater level homeland security specific to this committee's assignment uh to make sure that that robust intelligence sharing is happening so that uh you know in real time we're sending out information that others can be protected based upon immediate A uh fundamental
▶ 1:44:19um issue here is that as the technology gets better, we're going to start seeing new patterns that are potentially more sophisticated that either in industry or cross government we've not seen before. In terms of what these attacks look like, I think the first most important thing is we need good and quick and sensitive channels to share the novelty of this information possibly within and to government and across industry. We probably need to get ahead of it as well. So we need to be able to share information prior to the attack occurring.
▶ 1:44:48Uh we regularly brief and share information about model capabilities as they're advancing. Um in general any effort here I think is extremely valuable and I think is going to put all of industry in a in a better position. You
▶ 1:44:59know one of the things we can do is there are people that work behind the scenes that never you know get in front of a the limelight of government. So with without naming names what division with homeland security can we highlight to just spend send a special thank you working with you? I'm I'm not an issue expert in in the the specific components of homeland security, but would very happily follow up with you to talk more.
▶ 1:45:20Be great. We want to make sure we're congratulating those groups that are taking your experience seriously. Um I want to talk about the at scale capability of 80 to 90% of nonhuman what would be formerly labor intensive now turned into generated by computer processing. So Mr. Hansen um if we if AI is utilized to provoke um then AI can be utilized to defend.
▶ 1:45:48So how can we enhance our scale of utilizing AI to um to wall off?
▶ 1:45:55It's exactly the right question and and so when you talk about what we can do is I think of the old adage about the cobbler's children who don't have shoes. And so it there are what far more defenders in the world than there are attackers, but we need to arm them with the that same type of automation that you saw in the attack described by anthropic because it's it's just a in many ways using commodity tools that we already have to both
▶ 1:46:25find and fix Those can be turned from offensive capabilities to the patching and fixing. But the defenders have to put shoes on. They have to uh use AI in defense.
▶ 1:46:39So while the attackers are experimenting, we need the defenders to be experimenting and becoming great users of AI to find the same vulnerabilities that were described but instead of to exploiting them to patch them and that's the kind I mentioned code mener is our project which takes advantage of this you know vibe coding if you want to call it it's easier and easier to code we we make it easier and easier to patch and with so much of our problems based on legacy
▶ 1:47:09technology, small companies, others. That's the only way we're going to get ahead. This defender's dilemma of uh attacker needs to be right once, defender needs to be right all the time. AI can help the defender be right all the time. That's what we need to do.
▶ 1:47:24Mr. Zerviggon, if I did a horrible job of pronouncing your name, you have a last name like mine. I apologize. And Mr. Coach, you've taken the time to be here. I've got 30 seconds. if there's anything because this is such an exploratory exercise for so many of us that are not experts. Is there anything you want to just highlight? I've got 20 seconds to split between the two of you.
▶ 1:47:46I would say um innovative results demand innovative timelines, right? You can't be operating on legacy timelines in order to achieve innovative results to to protect the homeland. Uh the piece I would add is that the information sharing is critical and staying a breast of how this is evolving is going to be one of the most important pieces amongst enterprises fighting against the the new threats.
▶ 1:48:09I look forward to highlighting Homeland Security staff with our committee staff. Thank you, Mr. Chairman.
▶ 1:48:13The gentleman yields back. I recognize the gentleman from Rhode Island, Mr.
▶ 1:48:19Thank you, Chairman. Um I'm going to get right to the point. Um, [clears throat] the Chinese government just launched the first ever AI powered cyber attack against our country that we know of.
▶ 1:48:33And at the same time, President Trump is selling uh the powerful H200 Nvidia chips, the next generation chips to I will ask any of our four experts, does anybody think this is a good idea? or or our colleagues or anyone. Does anyone want to defend this decision? Like they are literally they they are engaging in cyber warfare against us right now. They just did it.
▶ 1:49:03They just launched the first AI powered cyber attack against US organizations. Why in the world, given that they just did this what, a couple months ago, would we be giving them these next generation chips now, at the very least, we ought to be holding them back until we have some way of verifying that these chips are not going to be used to attack So, I'll ask again any of our witnesses, Mr. Graham, Mr. call anyone.
▶ 1:49:33Why is it concerning to you that China is about to receive these H200 chips from Nvidia?
▶ 1:49:43Mr. Cos, would you like to take a stab at it?
▶ 1:49:46The the defenses that we put into our LLMs, that enthropic that Google and others are doing to provide safety are things that we can control and we can use to prevent future type attacks from China using these resources. as China achieves the same capabilities and their technology from these chips, we lose control of the ability to put those safeguards in place and we're on our heels.
▶ 1:50:10Um so I agree with the concern that's being raised and the other piece that I will uh mention here is that as China provides greater uh frontier models like deepseek and it's appealing to US software corporations to integrate that into their stack for performance reasons. We have to remember that that is essentially delegating decision-m and trust to China even though it might be US software and we need greater focus on
▶ 1:50:36Yeah. I I mean, look, cyber security is a bipartisan issue and I believe that there are people on both sides who care genuinely about keeping us safe in the cyber domain, but like I don't know how anybody can be okay with this chip sale given what literally just happened two months ago. And uh that is something that I think we need to find a way as a Congress to deal with. Um because the administration I fear I fear has made a grave mistake.
▶ 1:51:02Um, I want to talk about the attack more specifically because we need to learn as much as we can from it. Um, Mr. Graham, I'm grateful that Anthropic was able to detect and and then report uh about the nature of the attack, but my understanding is it took about two weeks for Anthropic to to realize that the attack was happening give or take. Is that correct? C can you explain to us you you mentioned it in your w in your written testimony.
▶ 1:51:28Could you explain to us generally why why it took so long and what lessons you have learned and how you can now detect similar attacks hopefully faster in the
▶ 1:51:39Yeah. The first thing to to note is we ultimately did detect and disrupt the attack and when we did it was clear that this was a highly resourced sophisticated effort to get around the safeguards in order to conduct the attack. Very specifically what they did was they used a private obfiscation network to ensure that it was difficult to trace where the operations were coming from. They broke out the attack into small components that individually looked benign but taken together form a broad pattern of misuse.
▶ 1:52:08Uh and then ultimately they deceived the model uh in uh to believing that it was performing ethical. I mean they basically told the help us figure out how to protect ourselves from a cyber attack but in so doing the model revealed the vulnerabilities to a cyber attack. Is that in layman's terms what happened?
▶ 1:52:28That is uh that is one of the components and that's that is highlights one of the key issues with cyber security.
▶ 1:52:33Yeah. I mean, I would just say as like a lay person that that seems like something that, you know, ought to be flagged, right? If someone says, "Help me figure out what my vulnerabilities are," there should be an instant flag that someone may actually be looking for vulnerabilities for for a nefarious purpose. So, I'll just ask for the time I have left to any of our witnesses, I mean, what regulation is required to ensure that commercially available AI products have adequate guardrails in place?
▶ 1:52:58We appreciate the um you know the efforts that companies are already undertaking but there should be some sort of a a baseline of standards that that we set as a as a country should there not. We released this uh secure AI framework safe and and and then there's a 2.0 version as well as a coalition for secure AI where we're not just helping set standards but open source the implementations so broadly people can take advantage of and use those in their
▶ 1:53:26All right. Thank you all. I yield back.
▶ 1:53:28The gentleman yields back. I now recognize the gentleman from Texas, Mr.
▶ 1:53:32Thank you, Mr. Chairman.
▶ 1:53:33Mr. Zerviggon. Is that how I say it?
▶ 1:53:36Yes, sir.
▶ 1:53:38You spoke on architecture and how to secure our our proverbial infrastructure and how information flows. And the question was was hinted at earlier and we need to know this on this side. Who is it that you deal with? You Department of Homeland Security. Uh Mr. Um, brought that up. From my understanding, and this is what I'm trying to get clarity on.
▶ 1:54:01From my understanding is part there's three entities, Department of Justice, Department of Homeland Security, and Department of Defense all touch our communication capabilities above the ground and below the ground. Is there can you add clarity for me on who you deal with directly and is there one more than the other?
▶ 1:54:20the discussions I've had with our departments is they kind of hand the football off and I I really can't find anybody who's run a point on this and I'll start with you sir and can move back and forth. I mean from our experience I think uh customs border protection are are showing a lot of leadership on this issue and understanding that this is an architectural uh problem that needs to be remedied and obviously with with the costbenefit analysis of being able to do this over over
▶ 1:54:50is that brick and mortar facilities that our our undersea cabling runs into that you know salt typhoon's having a heyday with things like that
▶ 1:54:59all of them all the above so it's about any network connection, any network endpoint that needs to be updated for postquantum cryptography.
▶ 1:55:08Mr. Hansen.
▶ 1:55:09Yeah. As an example, um we in the Chrome browser back in 2023 changed the implementation of uh the encryption to to begin to be uh postquantum crypto resistant because everyone would use it, right? It's used broadly in the industry. So our strategy is to whether it's undersea cables, whether it's data centers, whether it's the hardware, make it secure by default.
▶ 1:55:33Is that the your company specifically that's providing security profile for that or is that something that the Homeland is coming in assisting with or Department of Defense is coming in and assisting with? What I cannot tell you this we're kind of and I hate to say ignorant to really come to what the answer is to that.
▶ 1:55:52Yeah. In a world where every one of these departments or you know sort of the the scope of their uh oversight is digital or increasingly digital we work across all of those entities you've mentioned and more on these kinds of
▶ 1:56:06I feel like we're not doing enough case in point Mr. ground with with what what happened with Claude and you guys have Gemini. Correct. I'm saying that
▶ 1:56:12That's right.
▶ 1:56:13Where are where the bad actors and nefarious actors are utilizing AI capabilities to hack into the the the kind of the sweet spot of what we're not looking at. Mr. Graham, was the did was it a human or or a software that that that found the attack or both?
▶ 1:56:32On our side, it was a combination of both. First, there's a series of detection measures that are generally automated and softwarebased. And this triggered a human investigation that allowed us to to
▶ 1:56:41So, as fast as we're moving on the advancements of artificial intelligence and we we can't I don't think we can stop because if we slow down, everyone else is going to keep going and then we're if we're behind now, we're absolutely going to be in last place. So, here we go.
▶ 1:56:59If we move to a point where artificial intelligence are are removes the human element, but you needed the human element to find What happens?
▶ 1:57:16I am enormously optimistic about the opportunities here to leverage AI to do this. This is the first time we're seeing some of this.
▶ 1:57:24We all are, too. This is us being overly
▶ 1:57:30It's not us that's going to be able to regulate it. It's too fast. And by the time you show up in front of us to tell us what happened, whomever took a hold of Claude to make, are they lying in wait? Are they sleeping inside the program now? And we've missed it and they're watching you fix the problem and they know how you fix it and they're going to attack someone else that's not as strong and capable of yourself or
▶ 1:57:54Well, well, in this case, it wasn't anthropic itself that was infiltrated.
▶ 1:57:58I'm sorry. It is very clear
▶ 1:58:00that uh sophisticated actors are now doing preparations for the next time for the next model for the next capability they can exploit. This is why we have to be detecting them as fast as possible and mitigating at the model layer. As I believe you use the term super scientists this is what AI has created.
▶ 1:58:17You've you've you've titrated hundreds of attack attackers down to two or three that have have the capability to ask the AI the question on exactly how to get Yeah, I think one just at
▶ 1:58:32a at a speed that's uncomprehensible.
▶ 1:58:35to this point, we've been using behind Gmail and behind the Play Store and behind Chrome for almost a decade AI in its earlier forms to do exactly what you're talking about. So, no humans involved. So, your question is correct and it's actually been happening long, you know, long before the large language models emerged.
▶ 1:58:55Okay. Thank you. I'm sorry, Mr. Chairman. I yield back.
▶ 1:58:58The gentleman yields back. I recognize the gentleoman from New Jersey, Miss
▶ 1:59:02Thank you, uh, Mr. Chair and ranking member, and thank you to our witnesses for joining us today. Every community, state, and country will be impacted by the benefits and risks of AI. In fact, we already see these impacts occurring. While the United States has been a leader with AI technology, our rivals are innovating in this area with great speed and we have to make sure working people here have what they need to stay safe and success and successful.
▶ 1:59:31Education will be key to maintaining American dominance, security, and economic success. With my colleagues, Representative Clever and Senators Blunt, Rochester, and Hyino, and Schiff, we introduced the Workforce of the Future Act. This legislation would help us better examine the skills necessary for workers to thrive in a AI dominated economy.
▶ 1:59:55It will also provide resources for educators and students to get the skills they need to participate in the workforce of the future and stay protected against adverse consequences of new technology. We need to make sure that all Americans are set up to succeed in a world impacted by AI, not be displaced by it. An AI competent workforce will lead to a more secure United States and a stronger future for working people. With that, Mr.
▶ 2:00:25Coats, I would love to talk with you about Trump recently signed an executive order that would overturn any state-based AI regulation deemed burdensome. What are some risks of letting AI develop unregulated?
▶ 2:00:43I think the important piece with uh AI regulation is to set clear guidelines and rules of the road uh and establish transparency amongst the creators. uh we want to motivate innovation and ensure that the US stays as a leader in the world on AI. Um one of the challenges in cyber security in particular can be a patchwork of regulations across states to deal with especially in things like data disclosure, breach responsiveness, etc.
▶ 2:01:13And so we want to make sure that in the fastmoving field of AI innovation, we are setting the right um objectives clear so we can operate to rules of the road, but we don't hamstring our technology organizations and prevent innovation. The last thing we want to be is on our heels or uh second to others in the world with AI technology.
▶ 2:01:33Thank you for that. Just to follow up, you mentioned cyber security. Can you expand a little bit of how important will AI knowledge and competency be in the future of cyber security?
▶ 2:01:44I I would consider AI to be a critical piece of the future of cyber security both from the operators and the defenders. Um understanding the core principles of cyber security through education, understanding how technology works and then understanding how the different resources can be used as a defender. Um, as I mentioned in my testimony, there's no question that for defense to be effective, it's going to have to move at the speed of computers.
▶ 2:02:11So, we need the best humans to understand this technology and harness AI in a defensive capability.
▶ 2:02:17Thank you for that. As AI data centers continue to expand, how do you balance innovation with the significant environmental and economic burdens they place on local communities and infrastructure? Mr. coach you can start but anyone else can uh chime in as well.
▶ 2:02:34Maintaining dominance in AI is multiaceted. It's from the technology innovation in the models themselves to having sufficient power in technology and data centers to fund and power this uh innovation. So I do think it's critical to work across the nation to understand where can we have the right locations of data centers with sufficient power. We don't want to lose control of the pieces that go together to build technology and to have effective AI you have to have sufficient power and data.
▶ 2:03:04So center resources.
▶ 2:03:06Thank you. Anyone else? Mr. Hansen,
▶ 2:03:08I was just going to say, you know, I talked a little bit about my son's situation and the science and tech and you think of this alpha fold which was the protein folding work that won the Nobel Prize from Google last year. Fusion and energy and clean and safe energy is for me is another problem. like the cobbler's children. Let's use the AI to help solve that problem. You ask a very good question and that's that that's why we need to to keep going on the science and technology as well.
▶ 2:03:34Got it. Anyone else in 20 seconds? All right. Well, thank you so much with that. Mr. Chairman, I yield back. gentleoman yields back and you know um appreciate the topic she touched on because you know as we as we move forward and hopefully we'll have time to come back to it but this idea of what is that regulatory landscape look like and and you know this ever developing quickly evolving subject matter where energy is a factor right you know this latency period where we're realizing we have these vulnerabilities that we're not quite ready to
▶ 2:04:04you know adapt to or or back fill so it's a this is one of those uh again this hearing is the beginning of a very large conversation whether it's energy whether it's homeland security and quite frankly the future of our role in the in the world I recognize the gentleman for Alabama for his five minutes of questions Mr. Strong
▶ 2:04:24thank you Mr. Chairman ranking member um witnesses thank you for being here today Dr. Graham, as my colleagues have mentioned, one concern is that AI allows adversaries to scale operations without scaling personnel. Uh this changes the threat uh calculus for the United States. When AI tools are misused by cyber activity, what visibility uh if any does DHS and CISA have into these
▶ 2:04:53Well, I'm not familiar with the specific visibility of DHS and and SISA here. do know that what's important is industry should have information sharing mechanisms with government in these areas in order to give that visibility and also for uh in reverse to understand the areas that industry should defend.
▶ 2:05:10Absolutely. Turning to you Mr. Hansen. Uh cloud platforms now underpin federal um networks critical infrastructure and increasingly AI enables uh government systems. uh from a national security perspective does that uh concentration of sensitivity act uh sensitive activity in the cloud create new widespread risk for the homeland?
▶ 2:05:33Uh actually I think it it is helping us clean up legacy technology issues. When you look at the vulnerabilities we've had over the last you know decade it's generally people running on old versions of software that they're not maintaining. And so it we need competition in the space and and I think it is competitive in in many dimensions but overall modernizing is going to make you more secure in the moment.
▶ 2:06:00I agree with you competition is where it's going to be. Also AI and data centers are the future. Uh I represent uh a state uh that is blessed with all forms of energy, coal, hydro, gas, solar and nuclear power. uh we're able to meet the demand. What are your thoughts on AI and data centers in the future?
▶ 2:06:25You know, I know there's a this is a big topic as you would imagine at Google and there may be better, you know, people to talk about it. I would just say to the point about um using AI, we use AI in the management of our data centers, in the management of the power in a variety of ways. So using the technology to help us do it as efficiently as effectively as possible is sort of my only perspective but we could go deeper on that with with others in the company.
▶ 2:06:51I also know that companies like Google, Meta um which both of those are located in my district um work closely with universities in the public sector on emerging technologies. In my district, we have institutions such as the Alabama School of Cyber Technology and Engineering that focuses on building early hands uh hands-on cyber and technology skills. Mr.
▶ 2:07:14Hansen, from your view, how can public private partnerships and collaboration with universities help accelerate practical understanding and to secure adoption of AI and cloud technologies across the
▶ 2:07:27It's a really great question and relates to the workforce question as well. We in fact over the last few years have stood up what we call cyber clinics and these are not just with the big um uh state universities or private universities. They're with community colleges and they represent places across the country. So I think the working together on the curriculum, the technology, the approach for the next generation is critical.
▶ 2:07:52Thank you Mr. Zervagon. Many national security um uh data sets must remain secure for decades. What are the biggest practical challenges to deploying uh quantum resistant encryption at scale
▶ 2:08:10The desire to do so. I think um I I think the capabilities are there. uh there are many innovative technologies and innovative companies that can assist and with the desire to do so I think we can start going by protecting the transport layer right the the overriding layer that which this information this data travels.
▶ 2:08:31Thank you. Uh how can government and industry work together to reduce risk without disrupting operations or slowing uh innovation?
▶ 2:08:40Looking at it from an architectural standpoint, it's not just about the math. It's not just about creating new algorithms. It's about creating an architecture that allow you to deliver these algorithms, be able to swap them out at scale, be able to uh protect ourselves in the case that an algorithm is broken because it will happen. And so by doing so, uh it allows us to mitigate the uh the effects, the yield effects of a harvest now decrypt attack. Thank you.
▶ 2:09:04To close out, I'd like to ask all the witnesses, if resources are limited, what should DHS and CISA prioritize first to reduce cyber risk most
▶ 2:09:16I'll start on the on the end.
▶ 2:09:18I think establishing threat intelligence sharing channels very important identifying infrastructure that needs to be secured that we can go secure.
▶ 2:09:25Thank you, Mr. Hansen.
▶ 2:09:27Modernization, right? This is not something we go backwards on. We got to go forwards. again looking at the transport layer looking at the biggest pipes carrying the most important pertinent data and protect those first and then move downward from there.
▶ 2:09:40Uh it would be uh information sharing on emerging threats and adoption of autonomous defense systems.
▶ 2:09:47Thank you Mr. Chairman. I yield back.
▶ 2:09:48The gentleman yields back and now recognize the gentleman from Louisiana, Mr. Carter, for his five minutes.
▶ 2:09:53Thank you, Mr. Chairman. Cyber security is no longer a hypothetical risk. It is a real and growing threat to Louisiana and to our nation's energy security. Louisiana sits at the heart of America's energy system with refineries, prochemical plants, pipelines, LG export terminals, offshore platforms, and the electric grid all tightly A successful cyber attack on any one of these systems could ripple across our entire
▶ 2:10:24national economy. In 2021, the Colonial Pipeline cyber attacks shut down a major fuel artery, car shortages across the Southeast and drove panic buying and price spikes, all without a single physical asset being damaged. That attack showed just how vulnerable our energy systems can be.
▶ 2:10:44That's why we must act now by strengthening cyber security, modernizing systems, sharing threat intelligence, and using AI to stop attacks before they succeed. Mr.
▶ 2:10:58Coats, in your testimony, you state that bias in AI systems, whether intentional or unintentional, can affect how software is generated, how alerts are prioritized, how many decisions, how decisions are made, how can bias enter AIdriven security tools, and what risk that poses to our cyber
▶ 2:11:22Uh, it's an excellent question. the the challenge in front of us is that we are offloading decision making into AI when we use AI in our software systems and AI itself is trained on pre-training data, post-training data, configuration, etc. But that's reflective of the entity and organization that's creates it. Uh, Crowdstrike just released a report recently showing that the DeepSk LLM model has bias.
▶ 2:11:49And when you ask that model to create software and mention terms related to um items like Tibet and other things not favorable in the CCPI, it generates code that is more vulnerable than had you not mentioned it. So this bias is built deeply into it and maybe that is unintentional and a result of training data that was used.
▶ 2:12:11But nonetheless, we need to be aware that if American corporations are using software that's powered by LLMs that are built outside the US, that bias could come back to put us in a more risky
▶ 2:12:24So what should we should the federal government should Congress be doing to detect and mitigate uh these actions going forward? The most important piece here is transparency, requiring in the bill of materials for software procurement that we clearly state the origin of the pieces of the software. This is something we're doing already, but needs to be expanded to cover things like LLM, um, including where it was created, uh, training information, etc.
▶ 2:12:51Dr. Graham, you predict these attacks will only grow in effectiveness. What steps u should we be taking to get ahead of this evolving threats particularly those targeting critical infrastructure? What should Congress what should we be doing as this committee do to arm you to arm others to make sure that we are not playing catchup but we're catching this before it happens?
▶ 2:13:13The very first thing we should do is that industry and government should share threat intelligence so that we can get ahead.
▶ 2:13:19Is that happening at a rate that you're
▶ 2:13:21Uh it should always happen faster and more. Um the the second is that uh I believe Congress can enable the deployment of these tools defensively. Uh we can identify the infrastructure we should proactively defend uh and we can support or remove barriers to pulling these tools in order to defend them.
▶ 2:13:41Mr. Hansen, uh as CISSA developed and issued AI guidance, it worked in collaboration with our international allies. Why should the US continue to coordinate with countries uh in this area? Yeah, I was thinking about this um when I was in Poland just after the Russian invasion of Ukraine and they explained how they were now getting uh grain on the railroad out of Ukraine through Poland, but it had to be changed at the border because the Soviet era railroad
▶ 2:14:11tracks gauge was different from that in the west. I view this the same. We want American technology to be the railroad gauge of the 21st century. And so to me, it's a national security question that people use our technology and not others. Mrs. Zervagon, I've got a lot of good friends in Louisiana with that name. So, we'll check boxes and see if uh Louise or some of those people are related to you. But uh are they really fantastic?
▶ 2:14:41Some of my very dear friends. Um, but now that we've had our family reunion, um, tell me about investments. Are we making the kind of investments to stay ahead of the nefarious actors? As was mentioned earlier, we know that the bad guys sometimes get a lot more information than we do and their technology grows pretty quickly. What can we do to make sure because we got listening ears here and this is a great bipartisan group of of individuals who really want to help. And I know my time's expired, so can you give me a quick answer on that?
▶ 2:15:10Sure. I mean, as I mentioned in my testimony, I think um uh increasing the budget for the migration, right? I I think we don't have to do as much on the inventorying and the assessing and the understand. We know the pipes that we need to secure. We know the data that we need to secure. We need to start doing that. And also, I think helping that is accelerating the timelines and removing these artificial numbers out in the distance when we should start doing it
▶ 2:15:33Thank you, Mr. Chairman. You
▶ 2:15:35uh the gentleman yields back and thank you, sir, for your questions. I'm going to go to the gentleman from Texas.
▶ 2:15:40Thank you, Mr. Mr. Latrell for a second
▶ 2:15:43The amount of data centers that we are are are building out, they draw a lot of power and we are steadily increasing the footprint of each one of those facilities. Now, Texas stands alone as far as the national grid There will come a time the amount of power drawn on everything that we're putting onto the grid will kill it.
▶ 2:16:12And I'm not talking I'm talking next year, two years maybe max then what I think because we're all in the we're all in the game together. Is there a way that the that you all can decrease the amount of power photon communications or how the grid how the data centers themselves communicate instead of that amount of power being drawn in because we'll never catch you.
▶ 2:16:41There's no way we can build out enough infrastructure to power as power the amount of data centers being built. just those alone. What? So I I don't know if this is more of a question than a concern that I'm sure you're thinking about this. There's going to come a a hinge point that it's either going to be an alltop evolution. We have to deal with we have to do what we have right now because China, they don't have that problem.
▶ 2:17:09They're they're building handover fists just to keep up the amount of energy that they're drawn. What what do we do?
▶ 2:17:15So you know, you talked a little bit about the fusion or or technological investment. So I think that's we need to get started on doing that. We also and you've seen this from Google with our TPUs which is a different type of chip. Uh there are more efficient ways to do some of the computational work related to AI. And so I think we need a round of innovation which we're investing in to make these chips more efficient uh and and more performant at the same
▶ 2:17:43will that happen be before the before the grid.
▶ 2:17:48That is the work. Yeah, that is the
▶ 2:17:53Mr. Graham, Mr. Coats, anything on this? I mean, Miss McCyver hit nail on the head here. We This is This is a very real thing and we're not trying to slow innovation in any way, way, shape, or form.
▶ 2:18:06and the entire globe is moving to a to the metaverse and we have to be able to sustain that and we do not have the infrastructure in and I think in Texas in two years it's going to hit I'mma bet and I'd bet you a dollar on that one but um anyway thanks sir yield back
▶ 2:18:27gentleman yields back I'll go to the gentleman the ranking member from OIA Thank you, Chairman Ogles. Appreciate. As cyber attacks evolve, it is critical that the private sector share information about cyber threats with the federal government.
▶ 2:18:49This evolution is only accelerating due to AI making it more important than ever that the federal government has the information necessary to understand current threat landscape. The Cyber Security Information Sharing Act of 2015, the law that facilitates this kind of critical information between the private sector and federal government.
▶ 2:19:19This law is set to expire on January 30th. My question to all of you is how important is it that Congress pass a long-term reauthorization of CISA 2015 particularly in light of the rapid evolution and deployment of novel
▶ 2:19:47Uh I think this is critical. Um in in cyber security defense the basic primitives are known across organizations. We understand the plumbing the cork items that we need to do but the techniques and the methods being used by the adversaries continues to change. It's crucial that organizations can say we've discovered this piece and share it with others. So collectively we don't need to compete on defense but look at it as a national imperative that we are secure and information sharing is a key piece of that.
▶ 2:20:18Thank you.
▶ 2:20:21Yeah, I we're very supportive. In fact, I'd go further and say the information sharing and analysis centers, the ISACs which exist by sector, this isn't just going to be a technical issue. This will be a healthc care, energy uh and so the the sector specific sharing we need to focus on as well particularly as AI operates more at the human layer than at the technical layer.
▶ 2:20:45and the private sector is usually on the top of uh the developments and uh certainly um would be in a position to help the federal government. Right. AB:
▶ 2:20:57Absolutely. One of the reasons I came to Google from after working in financial services for many years was the realization that everyone was going to every industry would need the benefits of security being baked into their technology which include sharing and making it easier for people to defend
▶ 2:21:14Thank you. I appreciate
▶ 2:21:16and you're back.
▶ 2:21:18Gentleman yields back. You know, there's um there's a lot to unpack here and so uh we'll we'll drop unless other members come in, we can drop some of the formality and have more of a conversation and feel free to jump in. Um you know, I guess I want to start us off with um is we we know that we have a lot of I think infrastructure gaps. I mean, we, you know, I like to say we're the dominant pro predator currently across landscapes, but in this space in particular, that can change rapidly.
▶ 2:21:47Um, so when you're setting the marker down, if you had to predict and and whoever wants to answer and understanding this is just a prediction, uh, you know, when you when you think of our nearest adversary, how how long before they are at quantum computing? And I I know that's a big question, by the way. So, but who wants to guess?
▶ 2:22:09That would be the $64,000 question,
▶ 2:22:11right? Right. But are we talking about two years or 12 years?
▶ 2:22:14I I think the better analysis is whatever the number is, the data that you want to keep secret and you want to keep protected, is it outside of that? So if you think that a quantum a quantum cryptographically relevant quantum computer is five years out then any information outside of the five we know is problematic. So we need to make sure that we're protected. It's not it's not it's not like uh Y2K where it's one moment in time where we need to worry about.
▶ 2:22:43It's that moment in time and then the predating of that information and protecting that information. Well, that's kind of where I wanted to take this is that when I think about u you know just in general we as individuals members of Congress you know kind of device hygiene the amount of information that's stored that uh if compromised that is suddenly is unlocked or unleashed and my fear is currently has been stated there's a harvesting going on of information across sectors so you know financial services that actually what what
▶ 2:23:13piqued my interest in AI was being on the financial services committee and specifically the subcommittee on national security. And I'm thinking about all of the threats and how they're they're escalating and continuing to escalate when it comes to personal information, but also breaching of accounts where where suddenly your voice if it's out there somewhere uh can be replicated where uh you know IDs can be falsified etc.
▶ 2:23:36And so you know if you want to speak to the amount of information and then what do we do with it like how do we do we need to take this information offline? Do we silo it? Uh how do we clean up this mess, all these footprints and fingerprints that we have all left across that cyber landscape because it's being harvested quite frankly to be weaponized against us. You want to start Dr. Grime?
▶ 2:23:59I I think there are a number of very substantial opportunities that we have here. I'm again I'm extremely optimistic about using AI to help do this. Anthropic takes privacy and sensitivity of data extremely seriously. Um I think we could probably unleash quite a lot of innovation here using AI uh to secure data infrastructure sensitive systems.
▶ 2:24:21I think this is going to be one of the important topics if we deploy this technology more and more into the economy to ensure that it's critical we get it to defend critical infrastructure without exposing it anymore.
▶ 2:24:33You know this first of all the the reason we implemented the new encryption in Chrome was to start to get ahead of exactly the kind of question you're talking about. So there are some common utilities whereas we in a at Google or other companies migrate you get an architectural benefit for others.
▶ 2:24:51But to the point on using AI we have we have used again even before large language models AI to help identify unused data label data per certain sensitivities and then you can implement [clears throat] policy that protects it. But I think he he's correct. We'll have to use AI to get to the scale of the problem that you're describing.
▶ 2:25:13That means we'll also have to modernize though because we can't do that with the the servers that are under desks and in you know sort of secondass data centers that no one's modernized before. So that combination of modernization and using the tools I do think we can scale to that problem. I see two parts to the question you raise.
▶ 2:25:38one of which is how do we defend organizations against the rising um orchestration of attacks that we've talked about some through AI and the second piece around uh how quantum changes things and the the biggest challenge with decrypting um the ability to decrypt traffic uh when quantum becomes relevant is the the change that we need to do to be defensive here is a administrative and operational change. We understand the systems that we have inside our organizations.
▶ 2:26:09We need to essentially upgrade them. And unfortunately with the number of priorities we have for cyber security, it needs to become a top issue for organizations to say this needs to happen by this date. Um because otherwise we're going to be really caught behind the eightball where the data will be captured, it will be decrypted and the time to do the upgrade will be so significant that we'll be in that risky position for a much longer Thank you.
▶ 2:26:39Um, you know, Google's infrastructure, you you mean the amount of uh computing that you're supporting from government to private to uh health, I mean just across the board. uh when when you look at uh these kind of constant attacks.
▶ 2:27:03So, uh, just had a hearing last week, financial services on the oversight committee and, uh, we had, you know, everyone from Verizon to, you know, the credit card companies to across the board, right? The social media platforms, the architecture platforms, and we were talking about the the threats that they're facing and the amount of investment that is being made and quite frankly leveraging.
▶ 2:27:27So when it comes to credit cards for examples where you have AI that that is constantly watching transactions looking for those patterns that that otherwise are outside the norms but what are those fail points when you look at that ecosystem from a Google perspective? Yeah, I it's a great point and I'll maybe just extend that a little bit and see if this is what you're you're asking about, but is that the controls that we care about in finance or health care or transportation are going to be different that the risks are different.
▶ 2:27:58And so it's not just the plumbing, let's call it the technology, but in your credit card, the limits you set, show me what any transaction over $100 and you get that monitoring. Think about the kind of monitoring that occurs in health care. I think the key is that this isn't just a technical problem. This is a industry problem. And AI can help because a un AI understands the language.
▶ 2:28:26If you write a policy that says this heartbeat level is problematic under these conditions, the AI model is going to be better at monitoring that than a human. So that's where we need to go is to use AI. This is my I keep coming back to the cobbler's children.
▶ 2:28:42Let's not, you know, be, you know, uh, shoeless in defending Well, [clears throat] again on the AI um you know, when I think about um when when you look at Elon and and some of the other companies that are doing the the autonomous robots or humanoids, whatever you want to call them, and the ability to have a partner that now can watch a child who is ill or a spouse or an elderly parent that is where they're wearing a ring or a bracelet
▶ 2:29:12where they're con constantly being monitored in real time where you have a situation where they can dispense or disperse medicines and again immediately relaying back to the doctor. There's a huge upside to this. Uh and it's going to be transformative in a way that again I think is hard to fathom. My concern is when we have these nation states that are constantly seeking to exploit what otherwise could be used for tremendous good.
▶ 2:29:36And so I do think when I when I think about China and their overt I mean at this point they're not even hiding it. I mean, you know, the uh I think they were testing um you know, the the the qu the question or the point was made is, you know, uh I don't think we should ever underestimate our adversaries. Uh the this idea that, you know, they they they put it out there, it was detected, you know, they're watching to see how you detected it. How can they replicate or do it better the next time? So, we know it's coming.
▶ 2:30:06It's just a matter of time. is, you know, as we think about uh in the m the investment quite frankly that they're making is that I think you know from our perspective and we have to do a better job um you know put up the guard rails increase the transparency but this flow of information is going to be critical that's going to include some of our partners overseas so from an industry perspective how is that cross collaboration going with some of our European partners or Israel or to the extent that you can disclose
▶ 2:30:38on uh on on topics of national security, Anthropic works with US and democratic allies uh quite heavily for exactly uh this reason. One of the areas of collaboration that has helped the most has been in testing of model capabilities so that everybody understands where we're at and what's coming down the pipeline. That is the key first step. Additionally, there are probably international uh insights into how we do secure our infrastructure and learn from each other.
▶ 2:31:06uh broadly we we generally support this and I think it's a testament to America's leadership that it has instigated that degree of international collaboration. And it's a great point and just my jobs changed dramatically from the you know 20 years ago when I started.
▶ 2:31:21I was just thinking this year I was in Tokyo, Singapore, Abu Dhabi, Tel Aviv, Sao Paulo, Warsaw um talking exactly about these kinds of issues and how do we raise the ba uh the baseline for those citizens. So it's a big part of the job. We realize that
▶ 2:31:42for us I think it uh a large part of it uh is is on the architecture right as we develop the architecture that allows different countries different regions to employ the encryption that they want to employ uh we certainly like to show leadership in that and and and we are and with the work that NIST has done over the past decade but at the end of the day different countries different regions are going to want to do what they want to do so focusing on the architecture enables that
▶ 2:32:08in terms of information sharing. Um I would point to the innovation pipeline. I was just in Tel Aviv last week at a major cyber uh security conference speaking with startups and other innovators in the space and Tel Aviv in particular in Israel creates uh amazing technology that bridges to the United States uh as one of their main customer bases.
▶ 2:32:29So as we look at where the next great ideas are coming from, they are being created inside the United States and they're be created with our allies and working closely especially with Israel for cyber security is definitely to our advantage. Well, on that the um when I think about uh this the innovation and that innovation pipeline, you know, as we look at the again the five, seven kind of 14 eye groups, you know, I think one of where it's imperative that we're sharing information across kind of uh countries and
▶ 2:32:59nation states is this, you know, certain certain countries based off of where they're at and the type of threats they're exposed to get quite good at those types of attacks. And so what South Korea is facing may be slightly different or a different perspective than Israel is facing versus Eastern Europe. And so one of the things that I've done is I've had the opportunity to be to travel in South and Central America into Eastern Europe to talk about cyber security.
▶ 2:33:25And what troubles me is uh in many of these countries especially when you get into that that second tier is they're wholly unprepared. And I think Mr. Zeragon, you mentioned that uh that you know what we want to do is create a cyber environment where where the world is quite frankly reliant on our e architecture, our expertise.
▶ 2:33:45And so the the idea of the chips uh there's some huge uh you know it's a pause moment to figure out what do we want to share versus where do we where do we want to hold back. Um and that's probably not a conversation that we can have in this setting.
▶ 2:33:59That being said is ultimately we want the the our global partners whether in South America or Africa or Europe, Central America to be dependent on us and trust us in this ever evolving space because because in my humble opinion the threat to the west uh and the developing world is China and we it's time we have that honest conversation and quite frankly your report uh really puts a fine point on the fact that this was this was an intentional attack to undermine the United States of America
▶ 2:34:30to undermine the west and to quite frankly to try to achieve a technical advantage uh that that they currently don't have and as they they seek to leap forward uh in their own development in their own technology. So, with that, and you know, we're um probably going to end a little soon, but what I would love to do is just go down the line. Um any thoughts that you might have, you know, sometimes you're in a room, you don't ask the right questions. So, feel free to point out the right question.
▶ 2:34:58Then also, what is that thing uh you know, what are next steps and then what keeps you up at night? And well, Dr. Graham, you're at the top of the table. So, we'll just start with you, sir. To to me personally as as we watch these threats and have for the past two plus years, we have seen the models go from zero to extremely useful and now used in the real world. This only happens because we monitor this threat in the first place.
▶ 2:35:27But the most important thing in our team's view from now on is to take this moment here as the change point is from now on that we will have a degree of scale that I think we've never had before and very possibly very soon a degree of sophistication. I fear the day we wake up and models are doing things more complicated and sophisticated than the best humans on earth are able to understand.
▶ 2:35:54The only answer we think over the long term is to make sure that we're using models to keep up and outpace the attackers. We need to give the defenders a permanent advantage. We're going to work really hard to make sure our models can do that. We're going to work really hard to make sure that they're deployed. This is a cross-industry challenge. We have to work with government on it. This is we believe the fundamental issue.
▶ 2:36:19Yeah, maybe just two things. one um I'm reminded that in 2009 um Google was compromised by Chinese threat actors. This goes back over 15 years and it was our it was a watershed moment at the company and we spoke openly about it. Uh they had attacked 25 companies. It's really the where the modern architecture for security was born. You hear about zero trust.
▶ 2:36:44This was the company redoing our infrastructure from the ground up to be up to the kind of attacks we now knew were possible. And to the point about AI, I think that's the next phase of this threshold is to put in hands of defenders the tools that will allow them to be successful in ways that we've frankly been uh uh the numbers game doesn't work for us right now with all this legacy software.
▶ 2:37:12So now is the time to put those tools in the hands of
▶ 2:37:19Uh I would say also to accelerate the timelines um and the budget u as we talked about. I mean 15 years ago two-factor authentication nobody had ever heard of it. Now it's everywhere. You can't buy concert tickets without two-factor authentication. Same thing is going to be the case with encryption.
▶ 2:37:34And I think under um uh the legislative branch as well as the executive branch continuing to lead on this and to kind of push the envelope and and and set the table for innovative technologies and innovative companies to actually be able to um uh start doing what they do best rather than waiting for for legacy timelines to take hold. I think that's in everyone's best interest. It starts with the government and then it'll move quickly to critical infrastructure or critical industries and then it'll move to everything just like two-factor authentication did.
▶ 2:38:06the the country that leads in AI will lead in the world. This is the most important and innovative time uh in recent history. Uh I believe that it is imperative that we align behind the challenges may be that data centers, be that energy, be that human resources, be that regulation to create a transparent playing field in the United States where we can spur innovation forward.
▶ 2:38:32Um I think if we are caught up in any of the obstacles in pursuit of that it will only give uh foreign adversaries the upper hand and then let them lead other countries to build on top of their technologies which will be even harder to dig out from. So the future is in front of us and leading in AI is the most important thing we can do.
▶ 2:38:53Absolutely. And you know I thank all the witnesses Mr. coach, to your point, you know, of uh there are a lot of subjects Congress that we address that are kind of very heated and and at times partisan, but I I would like to think this is the one that isn't.
▶ 2:39:12And we have a lot to do whether it's the sharing of information, whether it's better educating our uh allies overseas, preparing for that that the energy load that we know is coming and just sheer innovation and and like has been said, you know, we want to put up the guard rails to protect Americans and our allies. We also understand that our adversaries are not going to use guardrails.
▶ 2:39:40I would argue that they would quite they quite frankly are willing to be reckless in achieving this goal, this endgame which is AI and quantum because it does it changes it changes the world forever. And and so I think this is this is the wakeup call. This is that moment in time that we'll point to in this space. Did we heed the Were we listening? Were we paying you've got our attention.
▶ 2:40:12Um, and my my challenge to you would be to feel free to come to this body, come to me, come to the ranking member and have those honest conversations of we see a deficiency here and we need your help or this is a space where you're getting it wrong. Because if we don't have that conf that that communication and that trust, forget ideologies and politics and who you voted for. This is about national security. This is about your son, right?
▶ 2:40:41It's not putting impediments and guardrails in the way that that that impedes that cure or whatever discovery is next. And and I truly I can't imagine what the future looks like, but it's coming whether we prepare for it or not. And so I commend all of you for being here. And quite frankly, I would love to have the conversation with each of you about having a working group uh that is outside that reports back to this body. we can get uh bipartisan membership to participate on in it.
▶ 2:41:10So to guarantee that we truly it's one of the thing to get platitudes, right? It's one thing. Oh, we're going to share information. We're we're going to work with our allies. We're going to do the right thing for the right reasons, but if we're not having the conversations, it's all platitudes. And and I'm not one to uh shy and beat around the bush. If we don't get this right, we're screwed, right? I think you said uh Dr. Hansen. You know, the defender has to be right every time, right? Your adversary only has to be right once.
▶ 2:41:38And if we mess this up, it changes changes everything forever. Any final thoughts? Well, I again, I thank you all. I'm humbled that you would come before Congress. Uh it is important that we have this conversation. I look forward to getting to know each of you better.
▶ 2:41:54uh and I personally will reach out to each of one each one of you individually so that you know that you have access to Congress every single day of the week 24/7 I will answer my phone with that the committee stands adjourned and God bless you sir and your