Artificial intelligence (AI) creates two sets of cybersecurity risks: cyber risks in the AI systems themselves, and cyber risks from AI tools used to exploit non-AI systems. The U.S. government has primarily focused on the former, but it should urgently be preparing for the latter. Securing AI systems has been a priority for the past two administrations. Under President Biden, the National Institute of Standards and Technology (NIST) created the U.S. AI Safety Institute to support the development of safe and secure AI. Later, under President Trump, NIST reformed the organization as the Center for AI Standards and Innovation (CAISI) and refocused its priorities to concentrate on securing commercial systems. Late last year, the Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) issued a report for securely integrating AI in government operations, which included principles such as secure‑by‑design integration, continuous monitoring, anomaly detection, human‑in‑the‑loop oversight, and rigorous testing and red‑teaming of AI systems. But the federal government has taken relatively few steps to address risks in existing systems that cyber threat actors may discover and exploit using artificial intelligence (AI) tools, despite policymakers being aware of the issue. For example, nearly two years ago, the Bipartisan Senate AI Working Group called on lawmakers “to develop legislation bolstering the use of AI in U.S. cyber capabilities.” Similarly, the Bipartisan House Task Force on AI stated that “security teams must use AI defensively to improve cybersecurity resiliency.” However, the issue has now reached a new level of urgency. Earlier this month, Anthropic announced Claude Mythos Preview, a new frontier AI model—meaning a cutting-edge model that pushes the boundaries of what AI can accomplish —that is “capable of identifying and then exploiting zero-day vulnerabilities in every major operating system and every major web browser.” For example, the model uncovered
Federal Government Should Partner With Frontier AI Labs on <b>Cybersecurity</b> Defense
Read the original article
datainnovation.org →