The AI Security Landscape: How Frontier Models, Agentic AI, and AI Coding Tools Are Reshaping Cybersecurity and Critical Infrastructure Resilience

US-China Technology CompetitionHomeland Security Subcommittee on Cybersecurity and Infrastructure Protection · 2026-06-04 · 119th Congress
The House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection held this hearing to examine how frontier AI models, agentic AI, and AI coding tools are reshaping cybersecurity and the resilience of critical infrastructure, including national security risks from China's open-weight AI strategy and adversarial distillation. Begins at 0:18:58
Transcript
Highlights

Title

AI's growing role in cyber offense, defense, and critical infrastructure risk

Purpose

The House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection held this hearing to examine how frontier AI models, agentic AI, and AI coding tools are reshaping cybersecurity and the resilience of critical infrastructure, including national security risks from China's open-weight AI strategy and adversarial distillation. The hearing followed a presidential executive order directing CISA and other agencies to develop a benchmarking and early-access framework for advanced AI cyber capabilities, and members probed witnesses on whether that framework should be voluntary or mandatory. Witnesses from Google, the Frontier Model Forum, Corridor Security, and the Electronic Frontier Foundation testified on both the defensive potential and civil-liberties risks of AI-driven cybersecurity. Begins at0:18:58

Who spoke

Chairman Ogles (R-TN)0:19:48: Opened by describing frontier models that can find and exploit unknown software flaws at machine speed, noting the most advanced model was deemed too dangerous to release publicly and was instead shared with roughly 50 companies0:21:37; warned that Chinese open-weight models are becoming the default global option due to cost and could embed censorship and stripped safeguards0:23:050:23:36.

Ranking Member Ramirez (D-IL)0:48:41: Criticized the administration's executive order for being silent on privacy protections despite AI's surveillance risks, citing DHS use of AI facial recognition in her district0:50:040:50:27; touted Illinois' SB 315 requiring third-party audits of frontier AI developers0:51:21 and called for enforceable federal rules rather than voluntary pledges0:52:10.

Sandra Joyce, Google Threat Intelligence0:27:40: Testified Google recently found the first evidence of AI used to develop a zero-day exploit by cybercriminals0:28:34; described Google's four-step "always on" defensive framework (prepare, scan/prioritize, remediate, monitor)0:30:26 and later cited a January disruption of an IP proxy network used by 500+ threat actors for malicious distillation1:36:56.

Dr. Chris Meserole, Frontier Model Forum0:33:07: Explained adversarial distillation lets foreign actors strip safeguards from copied US models and use them against critical infrastructure0:35:49; said antitrust guidance currently limits industry from even discussing how to counter distillation1:37:59.

Jack Cable, Corridor Security0:38:30: Said only 6% of the 1,500 vulnerabilities Anthropic disclosed via Mythos have been fixed0:40:28; reported giving coding agents proper security context at the planning stage cuts vulnerabilities by 60%0:42:10, and recommended Congress fund a multibillion-dollar open-source security refactoring initiative and pass the Securing Open Source Software Act0:42:59.

Dr. Matthew Guariglia, Electronic Frontier Foundation0:44:00: Warned AI-enabled surveillance can infer sensitive details about Americans' politics, religion, and location without individualized suspicion0:44:52; raised the practice of government "zero-day hoarding," citing NSA's EternalBlue vulnerability being exploited by adversaries0:47:00, and later said he did not know who would be legally responsible if an autonomous AI system wrongly shut down a city's water infrastructure1:02:33.

Rep. Fong (R-CA)1:03:42: Asked how smaller critical infrastructure operators can keep pace with machine-speed attacks when only well-resourced firms can rapidly patch AI-found vulnerabilities1:04:32; later asked what leverage China would gain if PRC-origin models became embedded in global software and infrastructure1:22:39.

Rep. Magaziner (D-RI)1:08:38: Argued the executive order's vetting framework for frontier models is only voluntary and that the world was "fortunate" Anthropic alerted the government before releasing Mythos1:09:361:10:12; said financial institutions found thousands of previously unknown vulnerabilities using Mythos1:12:57, and repeated his standing objection to allowing advanced AI chip sales to China1:27:34.

Key moments

Joyce disclosed that Google recently confirmed, for the first time, that AI was used by cybercriminals to develop a zero-day exploit0:28:34.

Meserole said Anthropic's Mythos model and GPT-5.5 mark the third "no surprise" AI capability jump in three to four years, after the original GPT moment and the DeepSeek moment1:41:44.

Cable stated GitHub reports 14 times more code committed in 2026 than 2025 and Google says 75% of its new code is AI-generated, while academic benchmarks show even the best AI models introduce vulnerabilities roughly a third of the time0:41:180:41:43.

Cable disclosed that of 1,500 vulnerabilities Anthropic has disclosed via Mythos, only 6% have been fixed0:40:28.

Ramirez pressed Guariglia on accountability for an autonomous AI system that wrongly shuts down city water infrastructure; he answered "I don't know who's responsible under current law" and "I'm not sure" what recourse harmed communities would have1:02:331:03:29.

Magaziner noted financial institutions told him Mythos uncovered thousands of previously unknown vulnerabilities, arguing the damage could have been severe had Anthropic not shared it with defenders first1:12:57.

Joyce said Chinese state actors including "Volt Typhoon" have already demonstrated capability and intent to preposition in US critical infrastructure, confirmed by the government to be for potential future kinetic action rather than mere reconnaissance1:23:531:24:09.

Cable said there are currently no frontier open-weight AI models originating from the United States, urging federal support to close that gap1:16:571:17:08.

Guariglia said Congress and courts have yet to meaningfully address AI-enabled mass surveillance, criticizing the "Anthropic deal" with the Pentagon as privacy being decided by corporate contract rather than statute1:00:231:00:48.

Meserole acknowledged current antitrust guidance leaves a "lack of clarity" preventing industry from even discussing how to counter adversarial distillation of US models1:37:59.

Metadata

CommitteeHomeland Security Subcommittee on Cybersecurity and Infrastructure Protection
Chamber / CongressHouse · 119th Congress
Date2026-06-04
TypeHearing
Witnesses
Ms. Sandra Joyce — Vice President, Google Threat Intelligence, Google LLC
Dr. Chris Meserole — Executive Director, Frontier Model Forum
Mr. Jack Cable — Chief Executive Officer and Co-Founder, Corridor Security Inc.
Dr. Matthew Guariglia — Senior Policy Analyst, Electronic Frontier Foundation
Videoyoutube
Transcript235 caption blocks · 13,821 words · 1:43:26 runtime
EventCongress.gov 119258