A new bill would turn the National Institute of Standards and Technology into a matchmaker for the U.S.’s most vulnerable sectors and artificial intelligence developers.
HAPPY MONDAY, and welcome to MORNING CYBERSECURITY! Busy weekend on the AI front! How’s everybody feeling? I’ll be off for the week to celebrate my father’s birthday down in South Carolina, but I’m leaving you in the very capable hands of Maggie and John.
Follow POLITICO’s cybersecurity team on X at @RosiePerper, @johnnysaks130, @delizanickel and @magmill95, or reach out via email or text for tips.
REGISTER FOR POLITICO’S DECODED SUMMIT: Do Washington and Silicon Valley need to rein in AI before the technology imperils humanity? That doomsday scenario has gained momentum in recent days amid dire warnings from AI researchers about the risks ahead and calls from the nation’s leading AI companies to slow the pace of development.
At POLITICO’s Decoded Summit on Wednesday, industry leaders like Trump adviser and venture capitalist David Sacks, Anthropic’s Sarah Heck and Hugging Face CEO Clem Delangue will unpack what’s fueling the latest fears and the next moves from frontier labs. Reps. Brett Guthrie (R-Ky.) and Greg Casar (D-Texas) will dissect the renewed furor on Capitol Hill and potential for AI legislation.
Plus, tech investor and entrepreneur Reid Hoffman and RAISE US co-chairs Gina Raimondo and Eric Holcomb will delve into voters’ growing anxiety about AI safety and job losses, which will influence the upcoming midterm and presidential elections. Click here to see the full lineup and register for the livestream.
Want to receive this newsletter every weekday? Subscribe to POLITICO Pro. You’ll also receive daily policy news and other intelligence you need to act on the day’s biggest stories.
Hacked
FIRST IN MC: NEW AI BILL INCOMING — Rep. Pat Harrigan (R-N.C.) is preparing to introduce a bill to bring AI developers and critical infrastructure owners together to develop a plan for using rapidly evolving AI systems to better defend the nation’s most vulnerable networks.
— The deets: A draft of the NIST Defensive Standards Act, shared exclusively with your host, would task the Commerce Department’s National Institute of Standards and Technology with developing “voluntary standards and best practices” for using AI for cyber defensive purposes.
NIST’s director would be required to convene an “AI Cybersecurity Roundtable” consisting of private sector AI industry officials and owners and operators of critical infrastructure to share recommendations for the best practices, within 180 days of the bill’s passage. The collaborative group would have one year to develop and publish the guidelines on NIST’s website.
“It’s about getting people in the room, getting people talking to each other,” said Thomas Rigali, Harrigan’s senior legislative aide who helped author the bill. He told your host that the roundtable would also help people who run critical sectors — which include hospitals, water treatment facilities, banks and power grids — to communicate directly with AI companies about where they need the most assistance.
— What else: Notably, the bill also includes a provision requiring NIST to collaborate with AI industry leaders to develop voluntary best practices for defending American labs from distillation attacks — an increasingly common tactic used by Chinese AI labs to steal and replicate leading U.S.-made AI capabilities. “A lot of our cybersecurity rests on our ability to out-compete China in this technology,” Rigali said. “If [Beijing] has better AI models that can spot vulnerabilities in our critical networks, and we have less advanced models, that’s also a vulnerability.”
— Some context: Currently, top AI firms offer programs that give certain, vetted organizations access to their most powerful models for cyber defense. OpenAI’s Daybreak and Anthropic’s Project Glasswing are among these initiatives.
Participation has largely centered around the technology, cybersecurity and financial services sectors, but a growing push within private industry to extend these capabilities could soon deliver access to more critical infrastructure.
Our own Aaron Mak scooped on Thursday that OpenAI CEO Sam Altman met with representatives from multiple top power companies to discuss using the AI firm’s cybersecurity services to better defend energy grids in cyberspace. (Harrigan pointed to this report when he first teased the NIST Defensive Standards Act on X last week.) And Anthropic this summer expanded access to Project Glasswing to additional critical sectors around the world, including health care, water and telecommunications organizations.
— What’s next: Harrigan plans to introduce the bill early next month, Rigali said. But quick movement on the measure may be challenging as the House prepares to leave at the end of this week ahead of the midterms. At the same time, Congress is muddling through a crowded slate of AI legislation, much of which is more focused on the growing security risks associated with the technology.
ARTIFICIAL INTELLIGENCE
PUMPING THE BRAKES? — Some of the most influential AI leaders are displaying a rare consensus by calling for a slowdown in the development of the technology following a ramped-up alarm across Washington and Silicon Valley that AI is outpacing its creators’ ability to control it, our own Ben Johansen and Owen Dahlkamp reported on Saturday.
— Lining up: Anthropic CEO Dario Amodei was first on Saturday to publicly call for the slowdown, writing in an essay that developers “must slow the pace at which we improve the capabilities of AI models.”
The lengthy missive earned endorsements from tech executives at competing AI labs, including Elon Musk, CEO of xAI and OpenAI’s Altman. Musk wrote on X “Dario is right,” just days after he downplayed public concern over an Anthropic researcher’s warnings that AI could result in the death of humans as a “psy op.”
“I agree with Dario that we need to pace the frontier,” Altman wrote on X, adding that the issue has been a primary topic of discussions at OpenAI recently.
— Zoom out: The calls for a slowdown also come as developers have disclosed a series of AI-led cyberattacks on companies. This includes reports on Friday that OpenAI’s models launched a separate cyberattack against an online service months before the Hugging Face breach in July.
CYBER POLICY
LET ME SEE SOME ID — Reps. Erin Houchin (R-Ind.) and Jake Auchincloss (D-Mass.) introduced a bill that would prohibit social media platforms from allowing users under 16 to create accounts.
The bill, 16 & Up Social Media Act, would only apply to platforms that use “a design feature to promote user engagement,” including infinite scroll, notifications, rewards for use, and filters that alter users’ appearances, among others, according to the bill text. The bill would require the platforms to verify the age of potential users to ensure they are at least 16 years old.
“These platforms were engineered by the smartest people in the world to hold attention, and they are winning that fight against our kids,” Houchin said in a statement.
— Popular right now: Policymakers around the world have introduced a wave of legislation aimed at protecting children online in the last year, many of which include provisions that require social media platforms to verify the age of its users. These checks can include requiring users to upload a government-issued ID or biometric face scanning for the company’s validation and analysis — sensitive data that has become an attractive target for hacking groups.
Earlier this month, the FBI confirmed the agency is investigating a suspected breach at a widely used identity verification company that reportedly resulted in the driver’s licenses of at least 153 million Americans and Canadians being leaked online. Last year, online gaming platform Discord disclosed a similar breach involving one of its third-party customer service providers that exposed thousands of user-submitted documents used to verify age.
People on the Move
Divyansh Kaushik has joined OpenAI’s national security team. He previously served as vice president at Beacon Global Strategies.
Quick Bytes
IPO DELAY — OpenAI’s Altman said he doesn’t think OpenAI will go public this year and separately called for increased safety evaluations of AI models, our own Chase DiFeliciantonio reports.
WE’RE HIRING — Researchers at Silent Push uncovered efforts by a suspected North Korean operative to promote a fake job scam over Discord servers, according to a new report from the cybersecurity firm.
TREATY TIME? — Trump and Chinese leader Xi Jinping must come together and establish a joint effort on AI governance during their summit later this month, CEO of The Alliance for Secure AI Brendan Steinhauser writes in an opinion piece for the Washington Examiner.
ON THE UP-AND-UP — Following years of high-profile breaches targeting its products, Microsoft is revamping how it approaches cybersecurity, Eric Geller reports for CybersecurityDive.
Chat soon.
Stay in touch with the whole team: Rosie Perper ([email protected]); John Sakellariadis ([email protected]); Maggie Miller ([email protected]); and Dana Nickel ([email protected]).