Search

Search bills, members, committees and pages...

“The Quantum, AI, and Cloud Landscape: Examining Opportunities, Vulnerabilities, and the Future of Cybersecurity”

HearingHomeland Security Subcommittee on Cybersecurity and Infrastructure ProtectionDec 17, 2025 · 10:00 AM

Summary

Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection held a hearing on Dec 17, 2025 at 10:00 AM in Cannon House Office Building, Room 310. 4 witnesses appeared.


Record

The meeting has its video, its transcript, witnesses and documents on the record.

Video

The proceedings, as the committee streamed them.

Transcript

The transcript runs to 3,623 lines and 208,613 characters, as the Government Publishing Office printed it.

house-hearing-63128.txt
1[House Hearing, 119 Congress]2[From the U.S. Government Publishing Office]34                 THE QUANTUM, AI, AND CLOUD LANDSCAPE:5                  EXAMINING OPPORTUNITIES, VULNERABILITIES,6                  AND THE FUTURE OF CYBERSECURITY7=======================================================================89                             JOINT HEARING1011                               BEFORE THE1213                            SUBCOMMITTEE ON14                           CYBERSECURITY AND15                       INFRASTRUCTURE PROTECTION1617                                AND THE1819                            SUBCOMMITTEE ON20                       OVERSIGHT, INVESTIGATIONS,21                           AND ACCOUNTABILITY2223                                OF THE2425                     COMMITTEE ON HOMELAND SECURITY26                        HOUSE OF REPRESENTATIVES2728                    ONE HUNDRED NINETEENTH CONGRESS2930                             FIRST SESSION3132                               __________3334                           DECEMBER 17, 20253536                               __________3738                           Serial No. 119-313940                               __________4142       Printed for the use of the Committee on Homeland Security4344[GRAPHIC NOT AVAILABLE IN TIFF FORMAT]4546        Available via the World Wide Web: http://www.govinfo.gov4748                               __________4950�                  U.S. GOVERNMENT PUBLISHING OFFICE5163-128 PDF                  WASHINGTON : 202652=====================================================================�5354                     COMMITTEE ON HOMELAND SECURITY5556                Andrew R. Garbarino, New York, Chairman57Michael T. McCaul, Texas, Vice       Bennie G. Thompson, Mississippi,58    Chair                                Ranking Member59Michael Guest, Mississippi           Eric Swalwell, California60Carlos A. Gimenez, Florida           J. Luis Correa, California61August Pfluger, Texas                Shri Thanedar, Michigan62Marjorie Taylor Greene, Georgia      Seth Magaziner, Rhode Island63Tony Gonzales, Texas                 Daniel S. Goldman, New York64Morgan Luttrell, Texas               Delia C. Ramirez, Illinois65Dale W. Strong, Alabama              Timothy M. Kennedy, New York66Josh Brecheen, Oklahoma              LaMonica McIver, New Jersey67Elijah Crane, Arizona                Julie Johnson, Texas, Vice Ranking68Andrew Ogles, Tennessee                  Member69Sheri Biggs, South Carolina          Pablo Jose Hernandez, Puerto Rico70Gabe Evans, Colorado                 Nellie Pou, New Jersey71Ryan Mackenzie, Pennsylvania         James R. Walkinshaw, Virginia72Brad Knott, North Carolina           Troy A. Carter, Louisiana73Vince Fong, California               Al Green, Texas74Matt Van Epps, Tennessee75                     Keighle Joyce, Staff Director76                  Hope Goins, Minority Staff Director77                       Sean Corcoran, Chief Clerk78                                 ------7980      SUBCOMMITTEE ON CYBERSECURITY AND INFRASTRUCTURE PROTECTION8182                   Andrew Ogles, Tennessee, Chairman83Carlos A. Gimenez, Florida           Eric Swalwell, California, Ranking84Morgan Luttrell, Texas                   Member85Ryan Mackenzie, Pennsylvania         Seth Magaziner, Rhode Island86Vince Fong, California               LaMonica McIver, New Jersey87Andrew R. Garbarino, New York (ex    James R. Walkinshaw, Virginia88    officio)                         Bennie G. Thompson, Mississippi89                                         (ex officio)90             Roland Hernandez, Subcommittee Staff Director91           Moira Bergin, Minority Subcommittee Staff Director92                                 ------9394     SUBCOMMITTEE ON OVERSIGHT, INVESTIGATIONS, AND ACCOUNTABILITY9596                   Josh Brecheen, Oklahoma, Chairman97Marjorie Taylor Greene, Georgia      Shri Thanedar, Michigan, Ranking98Dale W. Strong, Alabama                  Member99Andrew Ogles, Tennessee              Delia C. Ramirez, Illinois100Brad Knott, North Carolina           Troy A. Carter, Louisiana101Andrew R. Garbarino, New York, (ex   Al Green, Texas102    officio)                         Bennie G. Thompson, Mississippi103                                         (ex officio)104           Grayson Westmoreland, Subcommittee Staff Director105           Lisa Canini, Minority Subcommittee Staff Director106107                            C O N T E N T S108109                              ----------110                                                                   Page111112                               Statements113114The Honorable Andrew Ogles, a Representative in Congress From the115  State of Tennessee, and Chairman, Subcommittee on Cybersecurity116  and Infrastructure Protection:117  Oral Statement.................................................     1118  Prepared Statement.............................................     3119The Honorable Josh Brecheen, a Representative in Congress From120  the State of Oklahoma, and Chairman, Subcommittee on Oversight,121  Investigations, and Accountability:122  Oral Statement.................................................     6123  Prepared Statement.............................................     7124The Honorable Shri Thanedar, a Representative in Congress From125  the State of Michigan, and Ranking Member, Subcommittee on126  Oversight, Investigations, and Accountability:127  Oral Statement.................................................     4128  Prepared Statement.............................................     5129The Honorable Bennie G. Thompson, a Representative in Congress130  From the State of Mississippi, and Ranking Member, Committee on131  Homeland Security:132  Prepared Statement.............................................     8133The Honorable Delia C. Ramirez, a Representative in Congress From134  the State of Illinois:135  Prepared Statement.............................................     8136The Honorable James R. Walkinshaw, a Representative in Congress137  From the State of Virginia:138  Prepared Statement.............................................     9139140                               Witnesses141142Mr. Logan Graham, Ph.D., Department Head, Frontier Red Team,143  Anthropic PBC:144  Oral Statement.................................................    11145  Prepared Statement.............................................    12146Mr. Royal Hansen, Vice President, Privacy, Safety, and Security147  Engineering, Google LLC:148  Oral Statement.................................................    17149  Prepared Statement.............................................    19150Mr. Eddy Zervigon, Chief Executive Officer, Quantum XChange:151  Oral Statement.................................................    22152  Prepared Statement.............................................    24153Mr. Michael Coates, Founding Partner, Seven Hill Ventures:154  Oral Statement.................................................    26155  Prepared Statement.............................................    27156157                                Appendix158159Question From Honorable James R. Walkinshaw for Logan Graham.....    53160Questions From Honorable James R. Walkinshaw for Royal Hansen....    53161Question From Honorable James R. Walkinshaw for Eddy Zervigon....    54162Questions From Honorable James R. Walkinshaw for Michael Coates..    55163164    THE QUANTUM, AI, AND CLOUD LANDSCAPE: EXAMINING OPPORTUNITIES,165           VULNERABIL- ITIES, AND THE FUTURE OF CYBERSECURITY166167                              ----------168169                      Wednesday, December 17, 2025170171             U.S. House of Representatives,172                    Committee on Homeland Security,173                         Subcommittee on Cybersecurity and174                         Infrastructure Protection, and the175                                Subcommittee on Oversight,176                        Investigations, and Accountability,177                                                    Washington, DC.178    The subcommittees met, pursuant to notice, at 10:01 a.m.,179in room 360, Cannon House Office Building, Hon. Andy Ogles180[Chairman of the Cybersecurity and Infrastructure Protection]181presiding.182    Present from the Subcommittee on Cybersecurity and183Infrastructure Protection: Representatives Ogles, Gimenez,184Luttrell, Fong, Swalwell, Magaziner, McIver, and Walkinshaw.185    Present from the Subcommittee on Oversight, Investigations,186and Accountability: Representatives Brecheen, Strong, Ogles,187Thanedar, Ramirez, and Carter.188    Mr. Ogles. The Committee on Homeland Security, Subcommittee189on Cybersecurity and Infrastructure Protection and Subcommittee190on Oversight, Investigations, and Accountability will come to191order. Without objection, the Chair may declare the committee192in recess at any point.193    The purpose of this hearing is to examine how rapid194advances in artificial intelligence, quantum computing, and195cloud technologies are reshaping the cybersecurity landscape in196ways that affect both U.S. defensive capabilities and the197operational reach of our adversaries. The hearing will also198assess how the adoption and governance of AI, cloud199infrastructure, and post-quantum security measures are200strengthening or, in some cases, exposing U.S. critical201infrastructure, Federal systems, and sensitive data, and what202steps Government and industry must take to stay ahead of the203rapidly-evolving threats.204    I now recognize myself for an opening statement.205    Good morning and thank you all for being here. I want to206begin by thanking Chairman Brecheen and Members of the207Subcommittee on Oversight, Investigations, and Accountability208for partnering with my subcommittee to hold this hearing. The209issues before us today affect national security, economic210competitiveness, and public trust. They deserve attention that211reflects their scale and importance.212    We are meeting at a time when the technology shaping our213digital environment are also shaping the security and strength214of the United States. Artificial intelligence, cloud computing,215and quantum technologies are now woven into how Federal, State,216and local governments operate, how intelligence is collected217and analyzed, how critical infrastructure functions, and how218American companies compete in a global economy. These219technologies offer extraordinary promise, but they also220introduce risks that are advancing faster than many of the221frameworks and systems designed to manage them.222    Artificial intelligence is changing the pace and character223of cyber activity. It allows information to be processed at224speeds far beyond human capacity and perhaps in some ways even225comprehension. It enables automation across complex networks226and supports decision making at scale. These capabilities can227strengthen cyber defense and improve resilience. However, they228can also be exploited to accelerate malicious activities,229expand the reach of cyber operations, and make hostile actions230more difficult to detect, attribute, and disrupt.231    Cloud computing has amplified both opportunity and risk.232Cloud platforms have enabled modernization across Government233and industry, supporting flexibility, scalability, and234innovation. Yet they also consolidate vast amounts of data235access and computing power into shared environments, raising236the stakes of security configuration and oversight decisions.237    Quantum technologies present a longer-term challenge with238significant implications. Much of our digital security relies239on encryption to protect sensitive communications, verify240identities, and secure critical systems. Advances in quantum241computing raises serious questions about whether today's242encryption methods will remain effective in the future. Our243adversaries understand this risk and are already planning,244including by collecting encrypted data now with the expectation245that it may be accessed later.246    The threat environment surrounding these developments is247intensifying. The People's Republic of China, PRC, and the248Russian Federation, the RF, are investing heavily in advanced249computing, automation, and data exploitation as tools of250national power. They view artificial intelligence, cloud251infrastructure, and emerging technologies as means to gain252strategic advantage, conduct sustained cyber and intelligence253operations, and operate below the threshold of an open or254kinetic conflict.255    China, in particular, has pursued a model that tightly256integrates government, military, academia, and the private257sector. This approach allows innovations developed for258commercial purposes to be adapted quickly for state use. In259cyber space it supports operations built for scale and260persistence, including the use of automated tools to scan261networks, identify vulnerabilities, manage stolen credentials,262and analyze large volumes of data across many targets263simultaneously.264    At the same time, these technologies provide the United265States with powerful tools to strengthen security and266resilience. Artificial intelligence can improve threat267detection and response. Cloud computing can enhance reliability268and operational flexibility. Advances in quantum research may269ultimately yield new security capabilities.270    But also there is a downside. The challenge lies in271ensuring these benefits are realized without introducing272vulnerabilities that adversaries can exploit. The Department of273Homeland Security and Cybersecurity and Infrastructure Security274Agency, or CISA, play an essential role in this effort. Their275work on cloud security practices, artificial intelligence, risk276management, and preparation for future changes in encryption277help shape how Federal agencies and critical infrastructure278operators address emerging threats.279    Congress also has an important responsibility. Oversight280helps ensure that security keeps peace with adoption that281roles--or pace rather--with adoption that roles and282responsibilities are clearly defined and that risks are283addressed early rather than after they have created serious284harm.285    This is not about slowing innovation. It is about making286sure innovation strengthens the nature rather than exposing it.287The decision being made now about how artificial intelligence,288cloud computing, and quantum technologies are secured will289shape the country's security prosperity for years to come and I290would argue, also, our role as the, quite frankly, sole291superpower.292    I appreciate our witnesses for being here. I look forward293to their testimony and the discussion ahead.294    [The statement of Chairman Ogles follows:]295                   Statement of Chairman Andrew Ogles296                           December 17, 2025297    Good morning, and thank you all for being here. I want to begin by298thanking Chairman Brecheen and the Members of the Subcommittee on299Oversight, Investigations, and Accountability for partnering with my300subcommittee to hold this hearing. The issues before us today affect301national security, economic competitiveness, and public trust, and they302deserve attention that reflects their scale and importance.303    We are meeting at a time when the technologies shaping our digital304environment are also shaping the security and strength of the United305States. Artificial intelligence, cloud computing, and quantum306technologies are now woven into how Federal, State, and local307governments operate, how intelligence is collected and analyzed, how308critical infrastructure functions, and how American companies compete309in a global economy.310    These technologies offer extraordinary promise, but they also311introduce risks that are advancing faster than many of the frameworks312and systems designed to manage them.313    Artificial intelligence is changing the pace and character of cyber314activity. It allows information to be processed at speeds far beyond315human capacity, enables automation across complex networks, and316supports decision making at scale. These capabilities can strengthen317cyber defense and improve resilience. However, they can also be318exploited to accelerate malicious activity, expand the reach of cyber319operations, and make hostile actions more difficult to detect,320attribute, and disrupt.321    Cloud computing has amplified both opportunity and risk. Cloud322platforms have enabled modernization across government and industry,323supporting flexibility, scalability, and innovation. Yet, they also324consolidate vast amounts of data, access, and computing power into325shared environments, raising the stakes of security, configuration, and326oversight decisions.327    Quantum technologies present a longer-term challenge with328significant implications. Much of our digital security relies on329encryption to protect sensitive communications, verify identities, and330secure critical systems. Advances in quantum computing raise serious331questions about whether today's encryption methods will remain332effective in the future. Our adversaries understand this risk and are333already planning for it, including by collecting encrypted data now334with the expectation that it may be accessed later.335    The threat environment surrounding these developments is336intensifying.337    The People's Republic of China and the Russian Federation are338investing heavily in advanced computing, automation, and data339exploitation as tools of national power. They view artificial340intelligence, cloud infrastructure, and emerging technologies as means341to gain strategic advantage, conduct sustained cyber and intelligence342operations, and operate below the threshold of open conflict.343    China, in particular, has pursued a model that tightly integrates344government, military, academia, and the private sector. This approach345allows innovations developed for commercial purposes to be adapted346quickly for State use. In cyber space, it supports operations built for347scale and persistence, including the use of automated tools to scan348networks, identify vulnerabilities, manage stolen credentials, and349analyze large volumes of data across many targets simultaneously.350    At the same time, these technologies provide the United States with351powerful tools to strengthen security and resilience. Artificial352intelligence can improve threat detection and response. Cloud computing353can enhance reliability and operational flexibility. Advances in354quantum research may ultimately yield new security capabilities. The355challenge lies in ensuring these benefits are realized without356introducing vulnerabilities that adversaries can exploit.357    The Department of Homeland Security and the Cybersecurity and358Infrastructure Security Agency play an essential role in this effort.359Their work on cloud security practices, artificial intelligence risk360management, and preparation for future changes in encryption helps361shape how Federal agencies and critical infrastructure operators362address emerging threats.363    Congress also has an important responsibility. Oversight helps364ensure that security keeps pace with adoption, that roles and365responsibilities are clearly defined, and that risks are addressed366early rather than after serious harm has occurred. This is not about367slowing innovation. It is about making sure innovation strengthens the368Nation rather than exposing it.369    The decisions being made now about how artificial intelligence,370cloud computing, and quantum technologies are secured will shape the371country's security and prosperity for years to come.372373    Mr. Ogles. I now recognize the Ranking Member for the374Subcommittee on Oversight, Investigations, and Accountability,375the gentleman from Michigan, Mr. Thanedar, for his opening376statement.377    Mr. Thanedar. Thank you, Chairman Ogles. Appreciate this378hearing. Good morning to all of our witnesses. I look forward379to hearing your thoughts.380    For two decades, hostile nations have conducted381increasingly sophisticated cyber attacks against the United382States. These attacks have been used to spy, steal intellectual383property, cripple critical infrastructure, and demand ransom384payments. China, Russia, Iran, North Korea are aggressively385using advanced cyber capabilities to threaten our national386security and economic prosperity. China is both the most active387and persistent cyber threat and is also the only country with388both the desire and the ability to reshape the world order,389which is why it is extremely shocking that President Trump390recently agreed to allow Nvidia to sell advanced artificial391intelligence chips to China. Really shocking.392    Let's just see some background information here. Why did393this decision the President made? The President was quick to394sell out America's security after Nvidia's CEO attended a $1395million per plate dinner at Mar-a-Lago and donated to Trump's396White House ballroom. So much for America First.397    Trump's own Department of Justice has warned that China is398seeking to become the AI leader by 2030 and plans to use AI399chips to modernize its military, design and test weapons of400mass destruction, and deploy advanced surveillance tools. We401should be disrupting and dismantling threat actors whose402actions threaten our national interest, not enabling them.403    The rapid development of emerging technologies, including404advanced AI and quantum computing, enables and enhances405security risks. These advanced technologies not only accelerate406the cyber abilities of countries such as China, but they also407make it easier for countries that are not well-resourced and408enable a growing threat from organized criminal groups.409    Over the past year, cyber attacks have become faster, more410widespread, and harder to detect. As AI-assisted cyber attacks411hit harder and faster, it is critical that that Congress412extends CISA 2015, the Cybersecurity Information Sharing Act of4132015. CISA 2015 provides privacy and liability protection to414companies to encourage them to share data about cyber415vulnerabilities and threats. These protections are necessary to416fully understand the risk and facilitate collaboration between417the Federal Government and the private sector.418    Unfortunately, CISA 2015 expires next month. A 10-year419extension is the best reauthorization strategy that will also420provide the private sector with assurances while eliminating421the risk of this authority lapsing.422    I look forward to hearing from our witnesses how else we423can best defend against cyber attacks that are leveraging424powerful emerging technologies.425    Thank you and I yield back, Mr. Chair.426    [The statement of Ranking Member Thanedar follows:]427               Statement of Ranking Member Shri Thanedar428                           December 17, 2025429    For two decades, hostile nations have conducted increasingly430sophisticated cyber attacks against the United States. These attacks431have been used to spy, steal intellectual property, cripple critical432infrastructure, and demand ransom payments.433    China, Russia, Iran, and North Korea are aggressively using434advanced cyber capabilities to threaten our national security and435economic prosperity. China is both the most active and persistent cyber436threat and is also the only country with both the desire and ability to437reshape the world order. Which it is why it shocking that President438Trump recently agreed to allow Nvidia to sell advanced artificial439intelligence chips to China.440    The President was quick to sell out America's security after441Nvidia's CEO attended a $1 million-per-plate dinner at Mar-a-Lago and442donated to Trump's White House ballroom boondoggle. So much for443``America First''!444    Trump's own Department of Justice has warned that China is seeking445to become the AI leader by 2030 and plans to use AI chips to modernize446its military, design and test weapons of mass destruction, and deploy447advanced surveillance tools. We should be disrupting and dismantling448threat actors whose actions threaten our national interests, not449enabling them.450    The rapid development of emerging technologies, including advanced451AI and quantum computing, enables and enhances security risks. These452advanced technologies not only accelerate the cyber abilities of453countries such as China, but they also make it easier for countries454that are not well-resourced and enable a growing threat from organized455criminal groups.456    Over the past year, cyber attacks have become faster, more wide-457spread, and harder to detect. As AI assisted cyber attacks hit harder458and faster, it is critical that Congress extend CISA 2015--the459Cybersecurity Information Sharing Act of 2015. CISA 2015 provides460privacy and liability protections to companies to encourage them to461share data about cyber vulnerabilities and threats. These protections462are necessary to fully understand the risks and facilitate463collaboration between the Federal Government and the private sector.464    Unfortunately, CISA 2015 expires next month. A 10-year extension is465the best reauthorization strategy that will also provide the private466sector with assurances while eliminating the risk of this authority467lapsing. I look forward to hearing from our witnesses how else we can468best defend against cyber attacks that are leveraging powerful emerging469technologies.470471    Mr. Ogles. Thank you, Ranking Member Thanedar, and I look472forward to following up on your insightful comments.473    I now recognize the Chairman for the Subcommittee on474Oversight, Investigations, and Accountability, the gentleman475from Oklahoma, Mr. Brecheen, for his opening statement.476    Mr. Brecheen. Thank you, Chairman Ogles. Good morning.477Thank you to our witnesses. Very complex subject. Many of us in478all vulnerability feel really unqualified to be in these479discussions. Grateful we are going to have some expertise to480drive into the massive amount of vulnerabilities that AI is481presenting on our cyber front. As Chair of the Subcommittee on482Oversight, Investigations, and Accountability, I am looking483forward to partnering with the Subcommittee on Infrastructure484Protection to focus on this topic, explore ways that Congress485can assist the Department of Homeland Security in countering486this new threat.487    This integration of AI into cyber attacks should concern488every American. The recent cyber attack leveraging Anthropic's489AI infrastructure showed that complex attack campaigns can now490be conducted with little to no human interaction, at speeds491faster than a human could replicate. We have all seen how AI492can easily streamline tasks that would otherwise be very labor493intensive, both in business and everyday life. Now that an494attack like this has successfully taken place, we can expect to495see more events like this in the future. The proof of concept496is there, and even if U.S.-based AI companies can put497safeguards against using their models for such attacks, these498actors will find other ways to access this technology.499    China is our most significant cyber threat actor and it500continues to search for tactics to infiltrate critical U.S.501systems and prioritize the development of advanced computing502technology and AI that supports its economic and strategic503goals. Cyber espionage has been a key part of their plan,504China's plan ongoing campaign of stealing intellectual505property. This is decades-old and they now have new tools, and506this will fuel rapid technological advancement at the expense507of American innovators.508    As this committee has highlighted over the years, cyber509actors linked to China pose a threat on an unprecedented scale510targeting U.S. companies, critical infrastructure, and the511Federal Government. As technologies like AI continue to advance512at such speeds, we have to be vigilant strategic in protecting513intellectual property and our national security. From an514oversight perspective, we need to make sure that Federal515civilian agencies are taking the proactive steps needed to516protect their networks against intrusion. Technology doesn't517advance on the Government's time line and we can't afford to518have cybersecurity practices moving at such speeds absent519Government interdiction. That path leaves us reacting to520security failures instead of proactively confronting today's521threats.522    This is an area where Federal Government can partner with523and learn from the private sector to implement best practices524and incorporate needed technology. The Federal Government needs525to be better at sharing information on cyber threats between526Federal agencies and with private stakeholders in a timelier527manner. I hope to learn in today's hearings how Congress can528empower the Department of Homeland Security and its sub-529agencies to counter this threat and ensure safety integrity of530U.S.-based infrastructure.531    I want to thank again our panel of witnesses for joining us532to discuss today to discuss the cyber attack, implementation of533that. Congress and American people need to consider how we can534work with you all in your expertise to safeguard our critical535infrastructure.536    With that, I want to yield back to Chairman Ogles.537    [The statement of Chairman Brecheen follows:]538                  Statement of Chairman Josh Brecheen539                           December 17, 2025540    Thank you, Chairman Ogles. Good morning and thank you for joining541us today to discuss the highly complex and important issue of542artificial intelligence's role in carrying out cyber attacks.543    As Chair of the subcommittee on Oversight, Investigations, and544Accountability, I am looking forward to partnering with our545Subcommittee on Cybersecurity and Infrastructure Protection to focus on546this topic and explore ways Congress can assist the Department of547Homeland Security in countering this new threat.548    The integration of AI into cyber attacks should concern all549Americans.550    The recent cyber attack leveraging Anthropic's AI infrastructure551showed that complex attack campaigns can now be conducted with little-552to-no human intervention at speeds faster than any human could553replicate.554    We've all seen how AI can easily streamline tasks that would555otherwise be labor-intensive, both in business and in everyday life.556    However, now that an attack like this has successfully taken place,557I think we can expect to see more events like this in the future.558    The proof of concept is there. And even if U.S.-based AI companies559can put safeguards against using their models for cyber attacks, cyber560threat actors will find other ways to access this technology.561    China, our most significant cyber threat actor, continues to search562for new tactics to infiltrate critical U.S. systems, and is563prioritizing the development of advanced computing technology and AI564that supports its economic and strategic goals.565    Cyber espionage has been a key part of China's on-going campaign of566stealing intellectual property to fuel rapid technological advancement567at the expense of American innovators.568    As this committee has highlighted over the years, cyber actors569linked to China pose a threat on an unprecedented scale targeting U.S.570companies, critical infrastructure, and the Federal Government.571    As technologies like AI continue to advance at rapid speeds, we572must be vigilant and strategic in protecting our intellectual property573and national security.574    From an oversight perspective, we need to make sure that Federal575civilian agencies are taking the proactive steps needed to protect576sensitive networks against intrusions.577    Technology doesn't advance on the Government's time line; we can't578afford to have Federal cybersecurity practices move at the speed of579government.580    That path leaves us reacting to security failures instead of581proactively confronting today's evolving threats.582    This is an area where the Federal Government can partner with, and583learn from, the private sector to implement best practices and584incorporate modern technology.585    Additionally, the Federal Government needs to be better at sharing586information on cyber threats between Federal agencies and with private587stakeholders, in a timelier manner.588    I hope to learn in today's hearing ways that Congress can empower589the Department of Homeland Security, and its subagencies, to counter590this threat and ensure the safety and integrity of U.S.-based cyber591infrastructure.592    I want to thank our panel of witnesses for joining us today to593discuss this latest cyber attack and the implications that Congress and594the American people need to consider as we think about how to protect595critical networks in the age of AI.596597    Mr. Ogles. Thank you, Chairman Brecheen, and just echo your598sentiments.599    Other Members of the committee, you are reminded that you600can submit for the record an opening statement.601    [The statements of Ranking Member Thompson, Honorable602Ramirez and Honorable Walkinshaw follow:]603             Statement of Ranking Member Bennie G. Thompson604                           December 17, 2025605    With cybersecurity threats constantly evolving, it is essential606that we assess how to stay ahead of our adversaries by both defending607against new technological threats and by developing and deploying the608best tools to defend our networks.609    Anthropic's recent report on the use of AI by Chinese state-610sponsored actors demonstrates just how rapidly changes in technology611can impact cybersecurity. Since ChatGPT's launch just 3 years ago, we612have already seen large language models significantly change how613hackers carry out cyber campaigns.614    Today's hearing will give the subcommittee an opportunity to hear615from the private sector on how a range of technological innovations are616impacting cybersecurity today and how the Federal Government can better617prepare for tomorrow's threats. While I appreciate the strong618bipartisan interest in this topic, I worry that many of the Trump619administration's actions are moving us in the wrong direction by620hamstringing both the public and private-sector security efforts. CISA621has lost hundreds of employees this year, and during the shutdown, the622administration attempted to illegally fire CISA's stakeholder623engagement staff--the very staff who carry out the public-private624collaboration we all agree is necessary in cybersecurity.625    Across the Federal Government, the administration's war against626Federal employees has reduced technological expertise and done long-627term damage to the Federal Government's ability to recruit and retain628technology experts. I cannot imagine the Chinese government would try629to force out their AI or quantum experts, yet that is exactly what we630have seen the Trump administration do here. Such actions make us less631safe and put us at a competitive disadvantage.632    At the same time, the Trump administration has implemented anti-633immigrant policies that have made it harder for high-skilled immigrants634to move the United States, while harassing and profiling immigrants635already living here. The United States will never be able to compete636with China on the size of our overall workforce.637    But, our ability to attract the best and the brightest from around638the world has always given us an advantage, as we have seen from the639many immigrants who have founded and led cutting-edge technology640companies. If we close the door to immigrants, our national security641will suffer. As we in Congress assess how to strengthen our642cybersecurity, we must increase our oversight over CISA and other643Federal agencies to better understand how they are combatting new644threats with their current staffing and resources and how recent policy645decisions have impacted our security posture. I hope that we will have646CISA officials before the committee soon we can ask them these647important questions.648    Additionally, we must fulfill our obligations to maintain and grow649our Nation's cybersecurity capacities by passing a long-term650reauthorization of the Cybersecurity Information Sharing Act of 2015,651while adequately funding research and development in novel technologies652and security. As we consider oversight and legislative activities next653year, I am confident the witnesses' testimony today will help inform654our efforts.655                                 ______656657                Statement of Honorable Delia C. Ramirez658                           December 17, 2025659    Thank you, Chair and Ranking Member, for holding today's hearing,660and to our witnesses for joining us.661    It's really hard to talk about the ``opportunities'' around AI,662quantum, and cloud computing to reduce the risk of cyber threats, when663the Department of Homeland of Security (DHS) is using similar664technologies and its own private partnerships to threaten our665communities.666    DHS is violating our rights with AI, data monitoring, and667surveillance technologies they've purchased with taxpayer dollars:668    1. DHS kept Chicago Police records in direct violation of domestic669        espionage rules designed to prevent domestic intelligence670        operations from targeting legal U.S. residents.671    2. In Chicago, DHS is using facial recognition technology to target672        immigrants while removing policies intended to restrain their673        use from their website.674        a. In Chicago and the State of Illinois, Clearview AI is banned675            from doing business with police agencies because of a676            lawsuit that alleged they violated a landmark State law677            protecting our personal information. This is the same678            company DHS now has a $9.2 million dollar contract with.679    3. DHS has also used AI technology to do ``AI assisted reviews'' of680        social media in what is described as a surveillance program on681        a scale that was never possible before, and has the potential682        to have a chilling effect on free speech on a never-before-seen683        scale.684    DHS's use of technology, data, and AI to surveil our communities685and suppress dissent is deeply alarming. But it is unsurprising, given686the lawlessness demonstrated by Trump, Secretary Noem, and DHS687leadership. That is why it is critical that we do not ignore the688opinion and expertise of the privacy, technology, and civil rights689experts who are calling out the threat that DHS's unregulated,690unaccountable, unlawful use of technology poses to data protections,691privacy, and civil rights.692    Whether it's scanning social media accounts or tracking people's693movements, it is evident that AI is being used to target communities694who dissent and to execute Trump's racist and xenophobic mass695deportation campaign. It is critical that meaningful restrictions be696put in place. That requires limitations on government use,697specifically, but also requires AI developers to limit how their698technology is used by consumers.699    It's laughable that the Republicans--the party of small700government--are totally comfortable being the party of big brother.701    If you ask Republicans:702    1. Want to use the power of Government to end hunger? No.703    2. Want to use it to address climate change? No.704    3. Want to use it to end homelessness? No.705    If you ask Republicans, if they want to use it to strike fear into706the hearts of your people, chill dissent, and undermine the foundations707of liberty and democracy? Why, yes. Yes, let's do that.708                                 ______709710               Statement of Honorable James R. Walkinshaw711                      Wednesday, December 17, 2025712    A highly-skilled workforce, combined with the adoption of cutting-713edge technologies, should be the foundation of our Nation's efforts to714remain the global leader in emerging technology and to counter cyber715threats to our national security. Unfortunately, the Trump716administration has purged much of its technical expertise through717Department of Government Efficiency (DOGE) ``reductions in force''718(RIFs) and its Deferred Resignation Program (DRP). Entire units such as71918F were entirely eliminated. Engineers, data scientists, and designers720from the U.S. Digital Service have been laid off. Hundreds quit because721of the organizational chaos created by President Trump and DOGE.722Artificial Intelligence (AI) experts brought in under the National AI723Talent surge were pushed out. Just as we need AI and cyber talent the724most, the Trump administration has fired and driven them out.725    The Trump administration is now promoting its new ``Tech Force''726program, which would bring private-sector tech talent into Government727for short-term stints, as a magical solution to Federal modernization728challenges. This administration's assault on the Federal workforce has729made it almost impossible to recruit the highly-skilled and highly-730knowledgeable people that we need to make our Government work and to731counter cyber threats we are facing today. Short-term hiring732initiatives like ``Tech Force'' will not repair the lasting damage this733administration has inflicted on the Federal Government's ability to734recruit and retain technical talent needed to meet evolving national735security threats from malign actors.736    The United States must prioritize maintaining a sophisticated737Federal workforce to ensure we remain positioned to deter cyber738attacks.739740    Mr. Ogles. I am pleased to have a distinguished panel of741witnesses before us today on this critical topic. Pursuant to742committee rule VII(C), I ask that our witnesses please rise and743raise their right hands.744    [Witnesses sworn.]745    Mr. Ogles. Let the record reflect that the witnesses have746answered in the affirmative. Thank you and please be seated.747    I would like to now formally introduce our witnesses.748    Dr. Logan Graham serves as the department head of the749Frontier Red Team at Anthropic, where he leads efforts to750evaluate the behavior and potential misuse of advanced AI751systems as model capabilities continue to scale. His work752focuses on identifying national security risks posed by753Frontier AI, including its potential use in cyber espionage and754offensive cyber operations, as well as developing safeguards to755detect and disrupt malicious activity.756    Prior to joining Anthropic, Dr. Graham held roles at Google757X and Babylon Health. He also previously served as special758advisor to the Prime Minister of the United Kingdom,759contributing to national science and technology policy, and the760development of the United Kingdom's AI strategy. Dr. Graham761earned his undergraduate degree in economics from the762University of British Columbia and completed his Ph.D. in763engineering science at the University of Oxford where he was a764Rhodes Scholar. Thank you, sir.765    Mr. Royal Hansen is vice president for privacy, safety,766security engineering at Google, where he leads the engineering767team research responsible for securing Google's global768technical infrastructure and protecting billions of users769world-wide. Prior to joining Google, Mr. Hansen held senior770security leadership roles in the financial services sector,771including at American Express, Goldman Sachs, Morgan Stanley,772and Fidelity Investments. Mr. Hansen holds a bachelor of arts773in computer science from Yale University. Thank you, sir.774    Mr. Eddy Zervigon is the chief executive officer of Quantum775XChange. Under his leadership, Quantum XChange works with776Government and private-sector partners to prepare critical777systems for emerging cyber- and quantum-enabled threats. Mr.778Zervigon brings extensive experience in corporate leadership,779operations, and restructuring, including prior service as a780managing director in the Principal Investments Group at Morgan781Stanley, where he oversaw technology and infrastructure782investments across the United States and Latin America. He783holds a bachelor's degree in accounting and a master's degree784in taxation from Florida International University and a master785of business administration from Dartmouth. Thank you, sir.786    Mr. Michael Coates is the founding partner of Seven Hill787Ventures, an early-stage venture firm focused exclusively on788cybersecurity investment, addressing enterprise operational and789national security challenges. He brings more than two decades790of experience securing large-scale digital platforms and791advising organizations on cyber risk.792    Mr. Coates previously served as the chief information793officer at Twitter and also led security efforts at Mozilla.794Mr. Coates holds a bachelor of science in computer science from795the University of Illinois Urbana-Champaign and a master of796science in computer information and network security from797DePaul University. I thank each of our--thank you, sir.798    I thank each of our distinguished witnesses for being here799today.800    This is a topic that, you know, a year-and-a-half ago was801somewhat of a niche for laypersons, but for you experts,802obviously, clearly recognize that this was going to be, quite803frankly, the next arms race, threat battlefield as we go804forward. So what you are doing today here before Congress means805more than I think we can possibly comprehend as we begin this806discussion and, quite frankly, dive into the emergence of this807technology.808    With that, I now recognize Dr. Graham for 5 minutes to809summarize his opening statement.810811STATEMENT OF LOGAN GRAHAM, PH.D., DEPARTMENT HEAD, FRONTIER RED812                      TEAM, ANTHROPIC PBC813814    Mr. Graham. Chair Ogles and Brecheen, Ranking Member815Thanedar, Members of the committee, thank you for the816opportunity to testify today.817    Anthropic is a leading Frontier AI model developer working818to build reliable, interpretable, and steerable artificial819intelligence. Our flagship AI assistant, Claude, serves820millions of Americans and trusted partners worldwide, from821Fortune 500 companies and U.S. Government agencies to small822businesses and cutting-edge startups, and consumers, enhancing823productivity on tasks including software engineering, data824analysis, and scientific research.825    At Anthropic, I lead the Frontier Red Team. Our job is to826build an early warning system for advanced risks from AI so827that we can mitigate them and to help the world prepare as far828in advance as possible. Transparency is a fundamental value for829Anthropic and we believe it should be an industry standard.830That is why we published a report about how in mid-September8312025 anthropic detected suspicious activity that our832investigation determined to be a largely autonomous,833sophisticated cyber espionage campaign conducted by a group834sponsored by the Chinese Communist Party.835    To be clear, Claude's code was not compromised, nor were836Anthropic's labs infiltrated. Instead, this group maliciously837misused Claude to automate large portions of cyber attacks838against their targets. We estimate their use of the model839allowed them to automate approximately 80 to 90 percent of the840work that previously required humans to do. This is a841significant increase in the speed and scale of operations842compared to traditional methods.843    Further, this group invested significant resources and used844our sophisticated network--used their sophisticated network845infrastructure in order to circumvent our safeguards and846detection mechanisms prior to being detected. They then847deceived the model into believing the tasks were ethical848cybersecurity tests. The campaign consisted of a few distinct849phases. First, a human operator provided targets to Claude,850directing it to conduct autonomous reconnaissance against them851in parallel. Second, acting on the human operator's direction,852Claude leveraged third-party software tools to search for853vulnerabilities in these systems. The third and final step was854to task Claude to exploit these vulnerabilities and extract855sensitive information from the targets, which was only856successful in a handful of cases.857    We detected this campaign. Within 2 weeks, the attackers858first confirmed offensive activity, triggering a swift859response, including account bans, strengthening our safeguards,860entity notifications, authority coordination, and indicator861sharing with partners.862    We have reached an inflection point in cybersecurity. It is863now clear that sophisticated actors will attempt to use AI864models to enable cyber attacks at unprecedented scale. This865threat is not unique to Claude and affects all AI models. That866is why we've been open and transparent about this incident and867one of the reasons why I'm grateful to you that you are holding868this hearing today. Industry and Government must collaborate to869prevent this misuse and enable cyber defenders to prepare.870    To address these risks there are at least 3 things that871should be done immediately. First, there needs to be rapid872testing of models for national security capabilities.873Government-led evaluations, like those conducted by NIST's874Center for AI Standards and Innovation, give us visibility into875model capabilities and security. Codifying and expanding this876process is critical.877    Second, there must be robust threat intelligence sharing.878Frontier AI labs and the U.S. Government need stronger channels879to share indicators of misuse as exists in critical880infrastructure sectors.881    Third, and finally, industry should invest in empowering882our cyber defenders. We must make models useful for defenders883and get them into their hands. Anthropic is improving its884models for cyber defenders and building tools, for example,885that can patch vulnerabilities.886    We cannot lose sight of the strategic picture. The United887States and its allies must maintain leadership in AI. The Trump888administration has taken important steps to advance U.S. AI889leadership, including accelerating the build-out of AI890infrastructure, promoting Federal adoption, and strengthening891security testing and coordination. We strongly support these892efforts.893    Equally critical is maintaining the United States'894advantage in computing power, the single most important input895into developing powerful AI models. The United States currently896has a significant edge over the CCP in access to advanced897chips. But if advanced compute flows to the CCP, its national898champions could train models that exceed U.S. frontier cyber899capabilities. Attacks from these models will be much more900difficult to detect and deter.901    We are in a race against threat actors who will stop at902nothing to misuse AI for cyber attacks. Our response must be903urgent, coordinated, and focused on securing systems faster904than they can be attacked.905    Thank you again for the opportunity to testify and I look906forward to your questions.907    [The prepared statement of Mr. Graham follows:]908                   Prepared Statement of Logan Graham909                           December 17, 2025910    Chair Ogles, Chair Brecheen, Ranking Member Swalwell, Ranking911Member Thanedar, and Members of the committee, thank you for the912privilege and opportunity to testify today.913    Anthropic is a leading frontier AI model developer working to build914reliable, interpretable, and steerable artificial intelligence (AI)915systems. Anthropic has become the fourth-most valuable private company916in the world.\1\ Our flagship AI assistant, Claude, serves millions of917Americans and trusted partners worldwide, from Fortune 500 companies918and U.S. Government agencies to small businesses, cutting-edge startups919and consumers, enhancing productivity on sophisticated tasks including920software development, data analysis, and scientific research.921---------------------------------------------------------------------------922    \1\ Yuliya Chernova, ``Anthropic Valuation Hits $183 Billion in New923$13 Billion Funding Round.'' The Wall Street Journal, Sept. 2, 2025,924www.wsj.com/articles/anthropic-valuation-hits-183-billion-in-new-13-925billion-funding-round-6212f3ed.926---------------------------------------------------------------------------927    We believe these AI models could become extremely powerful very928soon. We think that by late 2026 or early 2027, it may be possible to929have ``a country of geniuses in a data center.'' America is in an930excellent position to lead its development, and we must preserve this931advantage.932    The benefits of powerful AI will be immense. We see it enabling933pioneering cancer research, supporting discoveries in material science,934and providing health care support where it's most needed. AI is now935unlocking large productivity increases for the world's largest936businesses, as well as small and nimble start-ups. Anthropic is937committed to making these benefits available to the world while safely938and securely stewarding the development of powerful AI.939    I lead Anthropic's Frontier Red Team, an internal research team940that studies the capabilities of frontier AI models. Our work generates941insights that enable rapid, responsible AI development and inform942policy on frontier AI capabilities and risks. The team focuses its943evaluations in three critical domains: cybersecurity capabilities,944biosecurity risks, and increasing autonomy in AI models. We primarily945evaluate Anthropic's Claude series of frontier models, but in some946circumstances evaluate models from other AI developers. Our work shows947that AI models are rapidly becoming more capable in areas like948cybersecurity--capabilities that, in the right hands, can dramatically949strengthen our U.S. and allied national security.950    My team has been tracking cybersecurity capabilities of AI models951since late 2022. We were among the first in the world to study the952dramatic cybersecurity implications of a world where models match or953exceed humans in these capabilities. We have allocated significant954resources to studying and experimenting on model cybersecurity955capabilities. In essence, this amounts to testing AI models'956capabilities by giving them the same hacking tasks you might give to a957human. In those tests, we have seen a very consistent trend: models958have shown rapid progress on cybersecurity challenges. Two years ago,959models were largely unable to complete most basic cybersecurity tasks;960last year, they began to do so reliably; and this year, they have begun961outcompeting humans in some head-to-head competitions.962    We are confident that now is the moment to act. Anthropic is963determined to support defenders, and we believe that other model964developers, cybersecurity companies and researchers, and the United965States Government all have important roles to play. We must also take966whatever steps are necessary to ensure America maintains its lead in967developing powerful AI, including restricting our adversaries' access968to advanced AI chips and the tools needed to manufacture them. These969types of controls are vital to our national security and economic970competitiveness.971    Today, I will discuss how Anthropic discovered, disrupted, and972publicly disclosed what we believe is the first documented case of a973successful, highly autonomous cyber espionage campaign that relied on974the misuse of AI models. We assess with high confidence that this975campaign was conducted by a highly-sophisticated Chinese Communist976Party (CCP)-sponsored group. This cyber espionage campaign demonstrates977that a sophisticated, well-resourced threat actor--one willing to go to978great lengths to circumvent AI model safeguards and deceive the AI979model about its true intentions--can now extract meaningful operational980value from frontier AI models.981    We believe this is the first indicator of a future where, despite982strong safeguards, AI models may enable threat actors to conduct an983unprecedented scale of cyber attacks, and that these cyber attacks may984become increasingly sophisticated in their nature and scale.985        ai-driven cyber espionage campaign sponsored by the ccp986    In mid-September 2025, Anthropic detected a sophisticated cyber987espionage operation where malicious actors abused our model, Claude, in988violation of Anthropic's Acceptable Use Policy.\2\ While we have989safeguards in place designed to detect and prevent this kind of990malicious activity, in this case we were confronted with a991sophisticated and well-resourced effort to circumvent those defenses992and manipulate Claude into complying with the attackers' instructions.993---------------------------------------------------------------------------994    \2\ ``Usage Policy.'' Anthropic, Sept. 15, 2025, https://995www.anthropic.com/legal/aup.996---------------------------------------------------------------------------997    A CCP-sponsored group misused Claude to automate a substantial part998of the process of conducting the attacks. Based on our investigation,999we believe the attacks targeted roughly 30 entities, with the goal of1000finding and extracting valuable information from these entities. While1001a majority of these infiltration attempts failed, a small number were1002successful. Upon detecting this attack, we launched an investigation,1003disrupted the campaign, implemented new mitigations to prevent similar1004activity, coordinated with the authorities, notified affected entities,1005and shared technical indicators with our partners to mitigate similar1006campaigns.1007    We believe that this group's abuse of Claude was able to1008substantially increase the speed and scale of the attack. Importantly,1009however, our takeaway is that this is not a story just about Claude,1010nor about what the attack was able to accomplish.1011    This challenge is not unique to Anthropic--every frontier model1012developer will face increasingly sophisticated attempts by threat1013actors to circumvent safeguards and misuse their models. What we1014observed here is one data point on a trendline. As models become more1015capable, we expect a wider swath of threat actors will continue to seek1016ways to misuse models for malicious ends. That is why the entire1017industry, along with government partners, must continue to strengthen1018our defenses.1019           details of the ccp-backed cyber espionage campaign1020    The attackers developed a framework designed to execute components1021of their cyber espionage campaign in a way that relied on human input1022at a few key points but which was able to misuse Claude Code (a popular1023product of ours that enables Claude to autonomously write and execute1024code) and open standard Model Context Protocol (MCP) tools to execute1025many components of the cyber espionage campaign with a substantial1026degree of autonomy.\3\ Using this combination of tools, the attackers1027circumvented our safeguards and deceived the model about the true1028nature of the tasks they were directing Claude to complete.1029---------------------------------------------------------------------------1030    \3\ ``Introducing the Model Context Protocol.'' Anthropic, Nov. 24,10312024, https://www.anthropic.com/news/model-context-protocol.1032---------------------------------------------------------------------------1033    The campaign consisted of distinct phases. At first, a human1034operator input a target--for example, an entity, or an entity's1035network--to Claude. The framework's orchestration engine would then1036task Claude to autonomously conduct reconnaissance against multiple1037targets in parallel. Approximately 30 systems from foreign governments1038and global companies were targeted, consistent with the threat actor's1039instructions. Upon completion, Claude delivered results to the1040operators for review and to determine the next step.1041    Next, acting on the threat actor's direction, Claude leveraged1042third-party software tools to search for vulnerabilities in these1043systems. Claude looked for ``weak spots'' in the target's1044infrastructure that could be exploited for the operators to gain1045unauthorized access to these systems. Many of these software tools were1046the same open-source software tools used by legitimate defensive1047actors.1048    The next and final step was to attempt to exploit any discovered1049vulnerabilities using third-party tools and to then find and extract1050sensitive information. This was only successful in a handful of cases,1051but required similar abilities to scan for systems containing valuable1052information, identify and exploit vulnerabilities, and exfiltrate the1053information. It also involved ``moving laterally'' within the system to1054establish access to new areas of the target's system. At the threat1055actor's direction, Claude queried databases, extracted information,1056parsed results to identify proprietary information, and categorized1057findings by intelligence value to the human operator. Claude then1058produced a summary report for the human operators to review.1059    This attack demonstrated that current frontier AI models are1060capable of uplifting dedicated, sophisticated groups.\4\ Our1061preliminary estimate is that the threat actor was able to leverage1062Claude to perform the work of a 10-person team managed by one human1063operator. For example, we observed that approximately 80 to 90 percent1064of the CCP-backed campaign tasks were automated by Claude, whereas the1065remaining 10 to 20 percent were tasks where the human operators1066reviewed Claude's outputs and directed the models.1067---------------------------------------------------------------------------1068    \4\ ``Uplift'' is the term we use to estimate how much individuals1069are able to benefit from using models compared to if they had tried to1070accomplish the same outcome without using models.1071---------------------------------------------------------------------------1072    There were critical limitations in the campaign. First, the models1073frequently hallucinated. Hallucinations are when models essentially1074``make up'' incorrect information--in this case, false credentials, or1075that it had succeeded when in reality it had not. This means human1076operators have to spend more time carefully validating all claimed1077results, limiting overall operational effectiveness. Second, the attack1078still fundamentally required a human operator at various decision1079points to progress. That is, the models still requested approval to1080progress from reconnaissance to active exploitation, authorize use of1081harvested credentials, and to make final decisions about data1082exfiltration. Last, the campaign did not produce fundamentally novel1083attack techniques unknown to security practitioners. Rather, it applied1084existing methods to identify and exploit vulnerabilities in software1085systems at scale.1086     anthropic's work to disrupt the ccp-backed espionage campaign1087    Anthropic detected this CCP-backed campaign within 2 weeks of the1088attackers' first confirmed offensive activity. Anthropic maintains1089multiple systems designed to detect suspicious activity, including1090cyber classifiers and what are known as YARA rules in the security1091industry.\5\ In this case, one of these systems triggered an immediate1092human investigation. Over the following 10 days, we banned the1093associated accounts, implemented detection mechanisms for similar1094behavior, notified affected entities, and coordinated with authorities1095to gather actionable intelligence. We also collected the technical1096indicators of these attacks, and took steps to share these with1097partners, including other frontier labs, with whom we have threat-1098sharing agreements, so that they could identify and mitigate similar1099campaigns.1100---------------------------------------------------------------------------1101    \5\ ``Using YARA For Malware Detection.'' NCCIC, https://1102www.cisa.gov/sites/default/files/FactSheets/1103NCCIC%20ICS_FactSheet_YARA_S508C.pdf.1104---------------------------------------------------------------------------1105    We assessed with high confidence that the threat actor was1106affiliated with the CCP because of technical evidence from the1107sophisticated obfuscation infrastructure that enabled the threat actor1108to access Claude accounts and evade detection. In addition, the1109targeted entities aligned with known targets of the CCP; and the1110operators exhibited behavior consistent with this conclusion, including1111following the Chinese workday--including observing lunch breaks--and1112observing Chinese national holidays.1113    The threat actor went to great lengths to obfuscate their work,1114conceal their intentions from Claude, or evade our safeguards. First,1115the actor ``jailbroke'' our models by, in some instances, deceiving the1116model, falsely stating they were conducting ethical defensive1117cybersecurity testing. Then, having convinced the models to comply, the1118attackers created a sophisticated network of many accounts, which all1119used separate instances of the model to perform subcomponents of the1120attacks on different targets. Separating work in this way frequently1121makes the subcomponents seem benign, but when put together, form a1122pattern of malicious behavior. They routed their actions through an1123obfuscated network they controlled.1124   anthropic is continuing to secure its models in response to this1125                                campaign1126    During and after the campaign, we instituted new mitigations to1127better prevent this kind of misuse of Anthropic models. We expanded our1128detection mechanisms to better cover novel threats such as this1129campaign--including by improving our cyber-focused classifiers. We are1130also prototyping early detection systems specifically targeted at1131autonomous cyber attacks, and researching new techniques for1132investigating and mitigating large-scale distributed operations.1133    Importantly, because all AI models are susceptible to this type of1134misuse, we shared and continue to share the results of our1135investigation with frontier labs. Defensive actors world-wide need to1136prepare for and defend against these new threats.1137                 what industry and government should do1138    As model capabilities advance, AI developers have to get better at1139understanding risks, preventing misuse, and ensuring that models can be1140used by defenders. This is a shared challenge on which industry and1141government should work together. While the threat actors likely1142leveraged Claude for this campaign due to its advanced coding and1143agentic capabilities, many models available today could soon be able to1144conduct such an attack. It is therefore critical that industry,1145Government, and researchers work together to evaluate model1146capabilities, rapidly secure critical infrastructure, and develop1147better methods to restrict malicious use.1148Predeployment Testing and Transparency for National Security1149        Capabilities1150    The United States should continue to be the best and fastest at1151evaluating model capabilities, deploying models, and learning from1152these deployments. Government-led evaluations remain critical, as the1153intelligence community and agencies like the Department of Energy1154possess unique expertise to evaluate how adversaries could exploit AI1155models.1156    The Frontier Red Team has an on-going partnership with the U.S.1157Government that enables risk mitigation and provides strategic national1158security insights. One major part of this is our collaboration with the1159U.S. Center for AI Standards and Innovation (CAISI) in the Department1160of Commerce. Through voluntary agreements, the CAISI conducts rapid1161predeployment testing of our Claude models that gives the Government1162visibility into AI model capabilities, provides us with critical1163information about our models' national security implications, and1164allows us to launch our commercial models more rapidly and with1165enhanced confidence about their reliability. Because of the sensitive1166nature of cybersecurity information, the CAISI and the U.S. Government1167in general are in an advantageous position to evaluate model1168capabilities and understand capability trajectories better than anyone1169in the world. Codifying the CAISI can ensure the Government can test1170and evaluate models for these capabilities, in partnership with the1171U.S. national security community.1172    In conjunction with Government testing, transparency standards play1173a crucial role in achieving secure AI development. This is why1174Anthropic published a transparency framework to inform light-touch1175guardrails that encourage the largest AI developers to follow secure1176practices--disclosing how they assess and mitigate national security1177risks, their testing procedures, and results.\6\ This transparency1178approach would establish industry best practices for safety and set a1179baseline for secure model training, ensuring developers meet basic1180accountability standards while enabling public visibility into1181development without impeding innovation.1182---------------------------------------------------------------------------1183    \6\ ``The Need for Transparency in Frontier AI.'' Anthropic, July11847, 2025, https://www.anthropic.com/news/the-need-for-transparency-in-1185frontier-ai.1186---------------------------------------------------------------------------1187Threat Intelligence Sharing1188    Additionally, the U.S. Government has an important role in1189identifying what critical national infrastructure must be protected. We1190know that all American frontier AI labs are targets for infiltration by1191state and non-state actors. As the models become more capable, it is1192critical that frontier labs work with the U.S. Government to implement1193defensive measures against threat actors who would seek to abuse their1194models. This is why we believe there should be more robust channels1195between American frontier AI laboratories and the U.S. Government to1196facilitate threat intelligence sharing, similar to information-sharing1197processes used in critical infrastructure sectors, so we may shore up1198our collective defenses against malicious actors. Galvanizing the U.S.1199Government and industry capacity to sprint to prepare AI infrastructure1200for a world of cybersecurity AI agents is critical at this juncture.1201Making Models Useful for Cyber Defenders1202    We therefore think a large part of making the future secure depends1203on our ability to make models useful for defenders and get the models1204into those defenders' hands. To that end, Anthropic has piloted and1205deployed our models with a large fraction of the world's largest1206cybersecurity companies, with whom we continue to partner.1207    We are also developing tools designed to help defenders. For1208example, Anthropic has released a security review tool that, with a1209single command, reviews a codebase for vulnerabilities and can suggest1210patches before code reaches production.1211    We envision a world where models are used by cyber defenders--in1212industry, Government, and by individual researchers and engineers--to1213secure all parts of the infrastructure that the world relies on. I am1214particularly encouraged by a new generation of advanced start-ups that1215are among the fastest and best at deploying models in creative ways to1216outpace attackers. We believe it is very possible that the force of1217innovation, spearheaded by inventive white hat companies, will be the1218most important factor in our ability to triumph over threat actors.1219            the stakes of maintaining u.s. leadership in ai1220    This campaign also underscores a broader strategic reality: the1221United States and like-minded democracies must maintain leadership in1222frontier AI development. Based on the current trajectory of AI1223development, our ability to lead at the AI frontier in the 2026-20271224time period will likely also translate directly into significant1225capability advancements in cyber, military, intelligence, and other1226critical national and economic security functions.1227    In this case, CCP-sponsored operators misused an American model1228running on American infrastructure because our technology represents1229the state-of-the-art. That's not a coincidence--it's a direct result of1230U.S. policy choices that have constrained the CCP's access to the1231advanced compute needed to train frontier models. Because CCP-sponsored1232operators had to use our systems, we were able to detect and disrupt1233them, and share information about the threat with the U.S. Government.1234That is an enormous strategic advantage.1235    The Trump administration has already taken important steps to1236advance U.S. AI leadership, including accelerating the domestic1237buildout of AI infrastructure, promoting Federal adoption, and1238strengthening safety testing and security coordination. But preserving1239the United States' lead in frontier AI development during this critical1240window depends on protecting our current advantage in compute--or the1241AI chips that power advanced AI systems. Restrictions on exports of1242advanced semiconductors and semiconductor manufacturing equipment to1243the CCP, building on actions initiated during the first Trump1244administration and expanded under the Biden administration, have been1245vital to preserving that edge.1246    Relaxing controls on advanced AI chips at this juncture could allow1247the CCP to close the gap in frontier AI development--producing models1248that may match or exceed current U.S. capabilities for cyber-offensive1249tasks, but without our safeguards, and using them to target U.S.1250critical infrastructure and national champions. Export controls on1251advanced semiconductors have proven effective at constraining the CCP's1252AI development. Without them, what any individual American company does1253to secure its own models becomes far less consequential. We simply1254won't see the attacks coming.1255                               conclusion1256    We are in a race against threat actors to secure systems faster and1257more robustly than they can be attacked. Threat actors will stop at1258nothing to develop, steal, or manipulate AI models to conduct1259increasingly sophisticated cyber attacks at scale, and we must respond1260urgently.1261    Thank you for the opportunity to appear before the committee today,1262and I look forward to answering your questions.12631264    Mr. Ogles. Thank you, Dr. Graham.1265    I now recognize Mr. Hansen for 5 minutes to summarize his1266opening statement.12671268STATEMENT OF ROYAL HANSEN, VICE PRESIDENT, PRIVACY, SAFETY, AND1269                SECURITY ENGINEERING, GOOGLE LLC12701271    Mr. Hansen. Chairmen Garbarino, Ogles, Brecheen, Ranking1272Members Thompson, Swalwell, Thanedar, and Members of the1273committee and subcommittees, thank you for the opportunity to1274speak with you today. My name is Royal Hansen and I serve as1275the vice president of privacy, safety, security engineering at1276Google, and, as discussed, we build the financial technology1277that keeps billions of people safe on-line.1278    As this committee knows, we stand at a critical1279technological inflection point. Rapid advances in AI are1280unlocking new possibilities for the way we work and1281accelerating innovation in science, technology, and beyond.1282Some of these same AI capabilities, however, can also be1283deployed by attackers, leading to understandable anxieties1284about the potential for AI to be misused for malicious1285purposes.1286    Until recently, our analysis showed that government-backed1287threat actors were using generative AI primarily for common1288tasks like troubleshooting, research, and content generation.1289Over the past year, Google's Threat Intelligence Team has1290identified an important shift, with adversaries not only1291leveraging AI for productivity gains, but deploying novel AI-1292enabled malware in active operations. We have identified1293malware families that use LLMs to generate malicious scripts,1294obfuscate their own code to evade detection, and use AI models1295to create malicious functions on demand rather than hard-coding1296them into the malware. This marks a new operational phase of AI1297abuse involving tools that dynamically alter behavior mid-1298execution. While still nascent, this development represents a1299significant step toward more autonomous and adaptive malware.1300    We believe not only that these highly-sophisticated threats1301can be countered, but that AI can supercharge our cyber1302defenses and enhance our collective security. LLMs can unlock1303new and promising opportunities, from sifting through complex1304telemetry to secure coding, vulnerability discovery, and1305streamlining operations.1306    Google's AI-based efforts, like Big Sleep and OSS-Fuzz,1307have demonstrated AI's capability to find new zero-day1308vulnerabilities in well-tested, widely-used software. Recently1309we developed CodeMender, an AI-powered agent that utilizes the1310advanced reasoning capabilities of our Gemini models to1311automatically fix critical code vulnerabilities. CodeMender1312scales security, accelerating time to patch across the open-1313source landscape. It represents a major leap in proactive AI-1314powered defense and includes features such as root cause1315analysis and self-validating patching.1316    We believe the private sector, governments, educational1317institutions, and other stakeholders must work together to1318maximize AI's benefits while also reducing the risks of abuse.1319As innovation moves forward, the industry more broadly needs1320security standards for building and deploying AI responsibly.1321That's why Google introduced the Secure AI Framework or SAIF, a1322conceptual framework to secure AI systems. Our recent expansion1323to SAIF 2.0 addresses the rapidly-emerging risks posed by1324autonomous AI agents and extends our proven framework with new1325guidance on agent security risks and controls to mitigate them.1326    We published a comprehensive toolkit for developers that1327includes resources and guidance for designing, building, and1328evaluating AI models responsibly. We've also shared best1329practices for implementing safeguards, evaluating model safety,1330and red teaming to test and secure AI systems. We are committed1331to developing technology responsibly and in a manner that is1332built for safety, enables accountability, and upholds high1333standards of scientific excellence.1334    For example, as part of our industry-leading security1335architecture, we do not offer our core products such as Search,1336Gmail, Maps, and YouTube in mainland China. We also do not1337conduct AI research, offer domestic cloud services, or have1338data centers in mainland China. Our comprehensive approach1339means we secure all components of the AI ecosystem, including1340data, infrastructure, applications and models.1341    As governments and civil society leaders look to counter1342the growing threat from cyber criminals and state-backed1343attackers, we're committed to leading the way in using AI to1344tip the balance of cybersecurity in favor of defenders.1345    Finally, this is more than a job for me. My youngest son,1346now 15, has suffered from a chronic illness for the past 51347years, during which time he has rarely moved from lying down in1348a dark, cold room. One of the few things that gives him hope is1349that technologies like AI and Quantum will continue to yield1350scientific and medical breakthroughs that will alleviate his1351suffering and the suffering of millions like him. Security and1352safety are among the critical foundations that will enable this1353science at digital speed. I am personally committed to that1354mission with the help of both the public and private sector.1355    We look forward to answering your questions.1356    [The prepared statement of Mr. Hansen follows:]1357                   Prepared Statement of Royal Hansen1358                           December 17, 20251359    Chairmen Garbarino, Ogles, Brecheen; Ranking Members Thompson,1360Swalwell, Thanedar; and Members of the Committee and Subcommittees:1361Thank you for the opportunity to speak with you today. My name is Royal1362Hansen, and I serve as vice president of privacy, safety, and security1363engineering at Google. Our team is responsible for building and scaling1364the foundational technology to keep billions of people safe on-line.1365    Thank you for holding this important hearing. We welcome the1366opportunity to provide information about Google's efforts to secure its1367own artificial intelligence, protect its customers' workloads, and use1368artificial intelligence to strengthen cyber defense and enhance our1369collective security.1370                  securing our artificial intelligence1371    Google's AI principles, published in 2018 and updated this year,1372describe our commitment to developing technology responsibly and in a1373manner that is built for safety, enables accountability and upholds1374high standards of scientific excellence. We have built on this work1375through our Secure AI Framework, as well as with extensive model1376hardening and various governance measures. This comprehensive approach1377means we secure all components of the AI ecosystem including data,1378infrastructure, applications, and models.1379The Secure AI Framework (SAIF)1380    SAIF is our framework for integrating security and privacy measures1381into machine learning and generative AI applications and it governs how1382we embed controls throughout the AI system stack from data,1383infrastructure, application, and models. The framework, which is1384designed to ensure that AI models are secure by design, has six core1385elements:1386   Expand strong security foundations to the AI ecosystem.--1387        Leverage secure-by-default infrastructure protections and1388        expertise built over the last two decades to protect AI1389        systems, applications and users. At the same time, develop1390        organizational expertise to keep pace with advances in AI and1391        start to scale and adapt infrastructure protections in the1392        context of AI and evolving threat models. For example,1393        injection techniques like SQL injection have existed for some1394        time, and organizations can adapt mitigations, such as input1395        sanitization and limiting, to help better defend against prompt1396        injection-style attacks.1397   Extend detection and response to bring AI into an1398        organization's threat universe.--Detect and respond to evolving1399        AI-related cyber incidents by extending threat intelligence and1400        other capabilities. For organizations, this includes monitoring1401        inputs and outputs of AI systems to detect misuses, and using1402        threat intelligence to anticipate attacks. This effort1403        typically requires collaboration with trust and safety, threat1404        intelligence, and counter abuse teams.1405   Automate defenses to keep pace with existing and new1406        threats.--Harness the latest AI innovations to improve the1407        scale and speed of response efforts to security incidents.1408        Adversaries will use AI to scale their impact, so it is1409        important to use AI and its current and emerging capabilities1410        to stay nimble and cost effective in protecting against them.1411        It is important to remember that the vast majority of1412        successful attacks--whether AI-enabled or not-prey on legacy1413        systems; AI can help defenders modernize and address issues at1414        a scale and speed that has historically proved challenging.1415   Harmonize platform-level controls to ensure consistent1416        security across the organization.--Align control frameworks to1417        support AI risk mitigation and scale protections across1418        different platforms and tools to ensure that the best1419        protections are available to all AI applications in a scalable1420        and cost-efficient manner. At Google, this includes extending1421        secure-by-default protections to AI platforms like Vertex AI1422        and Security AI Workbench, and building controls and1423        protections into the software development life cycle.1424        Capabilities that address general use cases, like Perspective1425        API, can help the entire organization benefit from state-of-1426        the-art protections.1427   Adapt controls to adjust mitigations and create faster1428        feedback loops for AI deployment.--Constantly test1429        implementations through continuous learning and evolve1430        detection and protections to address the changing threat1431        environment. This includes techniques like reinforcement1432        learning based on incidents and user feedback, and involves1433        steps such as updating training data sets, fine-tuning models1434        to respond strategically to attack attempts, and allowing the1435        software that is used to build models to embed further security1436        in context (e.g. detecting anomalous behavior). Organizations1437        can also conduct regular Red Team exercises to improve safety1438        assurance for AI-powered products and capabilities. These are1439        exactly the techniques we have used to defend Gmail, the Play1440        Store and Chrome with AI at scale for many years.1441   Contextualize AI system risks in surrounding business1442        processes.--Conduct end-to-end risk assessments related to how1443        organizations will deploy AI. This includes an assessment of1444        the end-to-end business risk, such as data lineage, validation1445        and operational behavior monitoring for certain types of1446        applications. In addition, organizations should construct1447        automated checks to validate AI performance. Nearly all1448        businesses are increasingly digital--AI will only accelerate1449        that trend. The controls required to mitigate risks in these1450        processes must keep pace--some of which will be digital and1451        some will be procedural.1452Model Hardening1453    Our AI models are fine-tuned on large datasets of realistic attack1454scenarios to build intrinsic resilience. They are taught to recognize1455and ignore malicious instructions while still following user requests.1456This is, and will continue to be, an evolving space requiring rapid1457iterations as attackers innovate.1458    Over the past decade, we have evolved our approach to translate the1459concept of red teaming to the latest innovations in technology,1460including AI. The AI Red Team is closely aligned with traditional red1461teams, but also has the necessary AI subject-matter expertise to carry1462out complex technical attacks on AI systems. A core part of our1463security strategy is automated red teaming, where our internal Gemini1464team constantly attacks Gemini in realistic ways to uncover potential1465security weaknesses in the model. We fine-tuned Gemini on a large1466dataset of realistic scenarios, where automated red teaming generates1467effective indirect prompt injections targeting sensitive information.1468    Protecting AI models against attacks like indirect prompt1469injections requires ``defense-in-depth''--using multiple layers of1470protection, including model hardening, input and output checks (like1471classifiers), and system-level guardrails. Securing advanced AI systems1472against specific, evolving threats like indirect prompt injection is an1473on-going process. It demands pursuing continuous and adaptive1474evaluation, improving existing defenses and exploring new ones, and1475building inherent resilience into the models themselves.1476Securing AI Workloads1477    Recent headlines have highlighted several key vulnerabilities and1478attack vectors targeting private and public-sector entities. It is1479clear that legacy systems, misconfigured cloud environments, and the1480exploitation of known vulnerabilities remain significant concerns.1481Email phishing, supply chain attacks, criminal hacking, and state-1482sponsored cyber espionage further compound these challenges. Our1483approach to protecting public and private-sector entities is built on1484several core tenets:1485   AI-Powered Security.--We leverage the power of AI and1486        machine learning to enhance threat detection, automate security1487        operations, and secure AI development.1488   Secure by Design.--We engineer security into every layer of1489        our infrastructure and services, from custom-designed hardware1490        to advanced encryption techniques. To do this well requires1491        security engineering which goes well beyond checklists and1492        compliance requirements.1493   Zero Trust.--We ensure that no user or device is inherently1494        trusted, regardless of their location or network. Access is1495        continuously authenticated and authorized based on identity,1496        device health, and context. We developed this approach in the1497        wake of Chinese threat actor attacks on Google over 15 years1498        ago, and it remains as important today.1499   Shared Fate.--We operate under a clear shared responsibility1500        model, securing the underlying cloud infrastructure while1501        providing tools and guidance for customers to manage their own1502        security. We believe in a ``shared fate'' where our success is1503        tied to the customer's. We are deeply invested in the1504        collective security outcomes of consumers, companies, and1505        countries. We align our goals with the security and resilience1506        of critical operations, particularly where national security is1507        at stake.1508Artificial Intelligence and Cybersecurity: Identifying Opportunities1509        and Mitigating Risks1510    We stand at a critical technological inflection point. Rapid1511advances in AI are unlocking new possibilities for the way we work and1512accelerating innovation in science, technology, and beyond. Some of1513these same AI capabilities, however, can also be deployed by attackers,1514leading to understandable anxieties about the potential for AI to be1515misused for malicious purposes. Until recently, our analysis of1516government-backed threat actor use of AI revealed that threat actors1517were using generative AI primarily for common tasks like1518troubleshooting, research, and content generation. Over the past year,1519Google Threat Intelligence Group has identified an important shift,1520with adversaries not only leveraging AI for productivity gains, but1521experimenting with novel AI-enabled malware in active operations.1522    We have identified malware families that use LLMs to generate1523malicious scripts, obfuscate their own code to evade detection, and use1524AI models to create malicious functions on demand, rather than hard-1525coding them into the malware. This marks a new operational phase of AI1526abuse, involving tools that dynamically alter behavior mid-execution.1527While still nascent, this development represents a significant step1528toward more autonomous and adaptive malware. We have and will continue1529to publish on these topics, take action and enhance our products to1530ensure industries and societies as a whole can keep pace with the1531latest threats.1532    Today, and for decades, the main challenge in cybersecurity has1533been that attackers need just one successful, novel threat to break1534through the best defenses. Defenders, meanwhile, need to deploy the1535best defenses at all times, across increasingly complex digital1536terrain--and there is no margin for error. As we have seen in recent1537years, this is particularly true for legacy technology. This is the1538``Defender's Dilemma,'' and there has never been a reliable way to tip1539that balance.1540    Our experience deploying AI at scale informs our belief that AI can1541reverse this dynamic in several ways and enhance our collective1542security.1543   AI allows security professionals and defenders to scale and1544        accelerate their work in threat detection, malware analysis,1545        vulnerability detection, vulnerability fixing, and incident1546        response.1547   Google's AI-based efforts like BigSleep have demonstrated1548        AI's ability to find new zero-day vulnerabilities in well-1549        tested, widely-used software. Developed by Google DeepMind and1550        Google Project Zero, Big Sleep can help security researchers1551        find zero-day (previously unknown) software security1552        vulnerabilities. Since it was introduced last year, it has1553        continued to discover multiple flaws in widely-used software,1554        exceeding our expectations and accelerating AI-powered1555        vulnerability research. With Big Sleep, we have demonstrated1556        how we can find vulnerabilities that defenders don't yet know1557        about. In this case, we found a vulnerability that the1558        attackers knew about and had every intention of using. We were1559        able to detect and report it for patching before they could1560        exploit it.1561   Finding vulnerabilities is only half of the battle.1562        Recently, we developed CodeMender, an AI-powered agent that1563        utilizes the advanced reasoning capabilities of our Gemini1564        models to automatically fix critical code vulnerabilities.1565        CodeMender scales security, accelerating time-to-patch across1566        the open-source landscape. It represents a major leap in1567        proactive AI-powered defense and includes features such as root1568        cause analysis and self-validated patching. This capability in1569        particular will be the most significant security advancement in1570        many years.1571   collaboration toward responsible artificial intelligence adoption1572    We believe the private sector, governments, educational1573institutions, and other stakeholders must work together to maximize1574AI's benefits while also reducing the risks of abuse. As innovation1575moves forward, the industry more broadly needs security standards for1576building and deploying AI responsibly. That's why Google introduced1577SAIF, as noted above, as a conceptual framework to secure AI systems.1578Our recent expansion to SAIF 2.0 addresses the rapidly-emerging risks1579posed by autonomous AI agents and extends our proven framework with new1580guidance on agent security risks and controls to mitigate them.1581    In addition, Google co-founded the Coalition for Secure AI (CoSAI),1582an open-source initiative to help all developers and deployers of AI1583create and maintain secure by design AI systems and help advance the1584framework. CoSAI helps foster a collaborative ecosystem to share open-1585source methodologies, standardized frameworks, and tools. Since its1586launch, CoSAI has made significant strides in strengthening AI security1587in collaboration with industry and academia in areas including Software1588Supply Chain Security for AI Systems; Preparing Defenders for a1589Changing Security Landscape; AI Security Risk Governance; and Secure1590Design Patterns for Agentic Systems. We have also supported the1591MLCommons Association's efforts to develop AI safety benchmarks by1592contributing funding for the development of a testing platform, as well1593as technical expertise and resources. ML Commons' shared research1594infrastructure helps the scientific research community derive new1595insights for breakthroughs in AI.1596    Across Google Cloud, we model and promote the adoption of1597responsible AI data practices that preserve our customers' privacy and1598support their compliance journey. Robust privacy commitments outline1599how we protect user data and prioritize privacy and the greater1600adoption of artificial intelligence rearms their importance. We adhere1601to a holistic approach to AI risk management and compliance, including1602focusing on employing an AI risk assessment methodology for1603identifying, assessing, and mitigating risks; developing and using an1604automated, scalable, and evidence-based approach for auditing1605generative AI workloads; and emphasizing human oversight and1606collaboration in our risk assessments and governance councils.1607    We use explainability tools to help understand and interpret AI1608predictions and evaluate potential bias; privacy-preserving1609technologies such as masking and tokenization and adhering to privacy1610laws; continuous monitoring and auditing for security vulnerabilities1611that AI might miss; investing in training programs to bridge the AI1612knowledge gap; and encouraging ``interdisciplinary collaboration''1613between data scientists, risk analysts, and domain experts is also key.1614    Cybersecurity has never been a field where perfection is possible.1615It will remain a dynamic space for years to come, and speed and1616resilience will be required to defeat and contain innovative attackers.1617As governments and civil society leaders look to counter evolving1618threats from cyber criminals and state-backed attackers, we are1619committed to leading the way in using AI to tip the balance of1620cybersecurity in favor of defenders.1621    We appreciate the committee convening this important hearing. And1622we look forward to answering your questions.16231624    Mr. Ogles. Thank you, Mr. Hansen. Just kind-of a point.1625First of all, thank you for sharing and I look forward to1626hearing more about what you're working on, sir.1627    We do have votes, so we will take a short recess. I would1628ask all Members of the committee after the second vote to come1629back here as promptly as possible so that we can get to the1630remaining two witnesses and their opening testimony. I plan on1631starting as quickly as we can, if that is possible.1632    So thank you all. We will take a short recess.1633    [Recess.]1634    Mr. Ogles. I call to order the Committee on Homeland1635Security, Subcommittee on Cybersecurity Infrastructure1636Protection and Subcommittee on Oversight, Investigations, and1637Accountability will come to order.1638    Again, thank you, Mr. Hansen.1639    Then would like to recognize Mr. Zervigon for 5 minutes to1640summarize his opening statement. Again to the witnesses, we1641appreciate your patience.16421643 STATEMENT OF EDDY ZERVIGON, CHIEF EXECUTIVE OFFICER, QUANTUM1644                            XCHANGE16451646    Mr. Zervigon. Thank you. Good morning. Chairman Garbarino,1647Ranking Members Thompson, Thanedar, Chairman Ogles, Chairman1648Brecheen, and Members of the committee, thank you very much for1649the opportunity to testify today.1650    My name is Eddy Zervigon and I am the CEO of Quantum1651XChange. We were founded in 2018, 2 years after NIST was tasked1652with evaluating the algorithms to take us into the quantum age.1653Quantum XChange is a cybersecurity company that interoperates1654with the major network infrastructure vendors to enable1655encryption that protects data today and into the post-quantum1656future, with hardware and software solutions developed entirely1657in the United States.1658    While quantum computing and AI promise new breakthrough1659capabilities, they also introduce significant risk to our1660national and economic security. They must be urgently1661addressed. AI can enable faster, more dangerous cyber attacks,1662and quantum computers can break current encryption standards,1663exposing sensitive data. These capabilities will be weaponized1664by our adversaries, creating a very dangerous imbalance in our1665cyber defenses.1666    For more than 50 years, encryption has safeguarded our data1667from theft and misuse. We've had the luxury of a set-it-and-1668forget-it mindset, trusting its strength by default. That era1669is now ending with quantum computing. Think about it like this.1670Imagine all digital communication from Government agencies sent1671over the past 10 years being readable by our adversaries. This1672is a real threat to the United States today. Rogue nation-1673states and state-sponsored terrorist groups are collecting1674encrypted data now to decrypt later with a quantum computer.1675    Further, now imagine our adversaries reading sensitive1676Government data in real time and altering it without anyone1677knowing. This could be tomorrow's reality. Public and private-1678sector work on quantum resilient solutions is on-going.1679Technologies like post-quantum cryptography, PQC, or quantum-1680safe encryption algorithms are part of the solution, but not1681the complete answer.1682    Despite our best efforts, post-quantum cryptography may1683still be vulnerable to quantum-related attacks. All of which1684raises the fundamental question and challenge what happens when1685an algorithm breaks? Because it is a when and not if. Every1686agency CIO, enterprise CISO, security vendor, and network gear1687manufacturer must be able to answer that question.1688    In our view, what's needed to ensure data security and1689confidentiality in the quantum age is an architectural1690approach, not just a new algorithm. This architectural approach1691enables agencies to focus on securing the network that data1692travels on to strengthen the existing infrastructure against1693quantum attacks while minimizing disruption to existing1694operations. This is how our Government agencies need to be1695protected.1696    When you have valuables in your house, the first step isn't1697going out and buying a new jewelry box with biometric access1698controls. It's locking your front and back doors so the house1699is secure and harder to get in. Once your home is secure, then1700you can figure out what specific rooms need further locks or1701security measures to protect your valuables and sensitive1702documents.1703    Federal agencies handling sensitive data need to act now1704and follow the lead set by Customs and Border Protection. Our1705work with CBP to incorporate PQCs across their network1706infrastructure in 2026 has shown that you can begin to secure1707your networks today with quantum-resistant technologies in a1708FIPS-validated way without having to rip and replace your1709entire infrastructure.1710    I cannot stress enough the timing here is critical.1711Agencies that fail to prepare today risk leaving their data1712vulnerable. Every day that we are not quantum-resistant is1713another day that data is harvested to be decrypted later.1714    It is important to note that we at Quantum XChange are not1715the only ones advocating for action today. The Quantum Industry1716Coalition of which we are part of, as well as Amazon Web1717Services, Google, IBM, Microsoft, Accenture, and others,1718believe that agencies handling sensitive Government data should1719be actively working and preparing for the transition and should1720begin migrating to high-risk systems to FIPS/NIST validated PQC1721where possible.1722    Having the opportunity to meet with several of your1723offices, I was often asked what can Congress do? Through this1724committee's leadership and building off the work previously1725done, Congress can accelerate the time lines for PQC1726compliance, allocate the budget to allow migration process to1727begin, and work with leaders within the administration to1728encourage adoption as the technology is readily available and1729deployable today.1730    America's defenses cannot stop at our physical borders.1731Through your leadership and efforts and in partnership of1732private-sector partners, like us, we can and secure--we can and1733will secure America's digital borders, too.1734    In closing, I want to thank you again for the opportunity1735to offer some thoughts today and I look forward to your1736questions. Thank you.1737    [The prepared statement of Mr. Zervigon follows:]1738                  Prepared Statement of Eddy Zervigon1739                           December 17, 20251740    Good morning, Chairman Garbarino, Ranking Member Thompson, Chairman1741Ogles, Chairman Brecheen, and Members of the committee. Thank you very1742much for the opportunity to testify today.1743    My name is Eddy Zervigon, and I am the CEO of Quantum XChange. We1744were founded in 2018, 2 years after NIST was tasked with evaluating the1745algorithms to take us into the quantum age. Quantum XChange is a1746cybersecurity company that interoperates with the major network1747infrastructure vendors to enable the encryption that protects data1748today and into the post-quantum future with hardware and software1749solutions developed entirely in the United States.1750    While quantum computing and AI promise new breakthrough1751capabilities, they also introduce significant risks to our national and1752economic security that must be urgently addressed. AI can enable1753faster, more dangerous cyber attacks and quantum computers can break1754current encryption standards, exposing sensitive data. These1755capabilities will be weaponized by our adversaries, creating a very1756dangerous imbalance in our cyber defenses.1757    For more than 50 years, encryption has safeguarded our data from1758theft and misuse. We've had the luxury of a ``set it and forget it''1759mindset, trusting its strength by default. That era is now ending with1760quantum computing.1761    Think about it like this: Imagine all digital communications from1762Government agencies sent over the past 10 years being readable by our1763adversaries. This is a real threat to the United States today; rogue1764nation-states and state-sponsored terrorist groups are collecting1765encrypted data NOW to decrypt later with a quantum computer.1766    Further, now imagine our adversaries reading sensitive Government1767data in real time, and altering it without anyone knowing. This could1768be tomorrow's reality.1769    Public and private-sector work on quantum-resilient solutions is1770on-going. Technologies, like post-quantum cryptography (PQC) or1771quantum-safe encryption algorithms, are part of the solution but not1772the complete answer. Despite our best efforts, post-quantum1773cryptography may still be vulnerable to quantum-enabled attacks.1774    All of which raises this fundamental question and challenge: What1775happens when an algorithm breaks (because it is a when, not if)? Every1776agency CIO, enterprise CISO, security vendor, and network gear1777manufacturer must be able to answer that question.1778    In our view, what's needed to ensure data security and1779confidentiality in the quantum age is an architectural approach, not1780just a new algorithm.1781    This architectural approach enables agencies to focus on securing1782the network that data travels on to strengthen the existing1783infrastructure against quantum attacks, while minimizing disruption to1784existing operations. This is how our Government agencies need to be1785protected. When you have valuables in your house, the first step isn't1786buying a new jewelry box with biometric access controls, it's locking1787your front and back doors, so the house is secure and harder to get in.1788Once your home is secure, then you can figure out what specific rooms1789need further locks or security measures to protect your valuables and1790sensitive documents.1791    Federal agencies handling sensitive data need to act now and follow1792the lead set by Customs and Border Protection. Our work with CBP to1793incorporate PQCs across their network infrastructure in 2026 has shown1794that you can begin to secure your networks today with quantum-resistant1795technologies in a FIPS-validated way, without having to rip and replace1796your entire infrastructure. I cannot stress enough that timing here is1797critical.1798    Agencies that fail to prepare today risk leaving their data1799vulnerable. Every day that we are not quantum-resistant is another day1800that data is harvested, to be decrypted later. It is important to note,1801that we at Quantum XChange are not the only ones advocating for action1802today. The Quantum Industry Coalition, which we are a part of and1803includes Amazon Web Services, Google, IBM, Microsoft, Accenture, and1804others believes ``that agencies handling sensitive government data1805should already be actively preparing for the transition and should1806begin migrating high-risk systems to FIPS/NIST validated PQC where1807possible.''1808    Having the opportunity to meet with several of your offices, I was1809often asked ``What can Congress do?'' Through this committee's1810leadership, and building off the work previously done, Congress can1811accelerate the time lines for PQC compliance, allocate the budget to1812allow the migration process to begin, and work with leaders within the1813administration to encourage adoption, as the technology is readily1814available and deployable today. America's defenses cannot stop at our1815physical borders. Through your leadership and efforts, and in1816partnership with private-sector partners like us, we can and will1817secure America's digital borders too.1818    In closing, I want to thank you all again for the opportunity to1819offer some thoughts today and look forward to your questions.1820    Appendix.--Quantum Industry Coalition Position on Post-Quantum1821                              Cryptography1822                            October 23, 20251823    The National Institute of Standards and Technology (NIST) has1824approved the first set of postquantum cryptographic (PQC) algorithms,1825in what promises to be an iterative process moving forward. NIST has1826been leading the migration charge for close to a decade, evaluating and1827approving the algorithms and delivery architectures that will protect1828our data networks into the post-quantum era.1829    The Federal Government has set time lines for the adoption of these1830post-quantum algorithms through Legislation and Executive Orders.1831Government agencies should already be preparing for PQC transition1832through education, cryptographic inventory, risk assessments,1833transition strategies, and pilots. At the same time, the ecosystem of1834innovative start-ups and established players surrounding the delivery1835of these algorithms has progressed to a point where transition is1836possible in some high-risk areas, such as securing the network layer.1837    It is our position that agencies handling sensitive Government data1838should already be actively preparing for the transition and should1839begin migrating high-risk systems to FIPS/NIST validated PQC where1840possible.1841    Quantum Industry Coalition Members Include:1842Accenture1843D-Wave1844Entanglement Institute1845IonQ1846Quantinuum1847Rigetti Computing1848Xanadu1849Amazon Web Services1850Cold Quanta1851Diraq1852Google1853MesaQuantum1854Quantum Corridor1855SandboxAQ1856Anametric1857EeroQ1858IBM1859Microsoft1860Quantum Machines1861SEEQC1862Atom Computing1863enQase1864Infleqtion1865Qolab1866Quantum XChange1867Strangeworks18681869    Mr. Ogles. Thank you, Mr. Zervigon.1870    I now recognize Mr. Coates for 5 minutes to summarize his1871opening statement.18721873   STATEMENT OF MICHAEL COATES, FOUNDING PARTNER, SEVEN HILL1874                            VENTURES18751876    Mr. Coates. Chairman Ogles, Ranking Member Swalwell,1877Chairman Brecheen, and Ranking Member Thanedar, thank you for1878the opportunity to testify. I'm honored to be here to discuss1879the changing cybersecurity landscape and the impacts of1880artificial intelligence and quantum computing. My perspective1881is grounded in over 20 years of experience in cybersecurity,1882including service as a chief information security officer,1883leadership in global software security organizations, founding1884a technology start-up, and investing in cybersecurity1885innovation.1886    Today we sit at the precipice of significant change. While1887much attention is paid to AI and future breakthroughs like AGI,1888the most immediate impact on cybersecurity is not the creation1889of entirely new threats. Instead, AI and quantum technologies1890are collapsing the time, cost, and skill required to conduct1891cyber operations. These changes are outpacing existing1892technical, regulatory, and operational defenses, fundamentally1893reshaping the threat landscape.1894    Historically, different attackers, nation-states, cyber-1895criminal organizations, and lone hacktivists were constrained1896by skill, resources, and scale. The most sophisticated attacks1897were largely limited to nation-states, while criminals focused1898on repeatable, monetizable techniques. That constraint is1899rapidly changing. Recent real-world examples, such as the1900report issued by Anthropic, show AI systems being used as a1901central orchestration layer for complete cyber operations,1902coordinating reconnaissance, exploitation, and execution with1903limited human involvement. While the techniques themselves may1904not be novel, the orchestration and automation represent a1905meaningful shift in adversary capability.1906    Agentic AI further removes human constraints. Autonomous1907systems are not limited by time, fatigue, or tension, and1908research recently released from Stanford, Carnegie Mellon, and1909Grace One AI already show AI-driven penetration testing1910performing at or above the level of highly-skilled1911professionals at a fraction of the cost.1912    At the same time, AI is accelerating vulnerability1913discovery and exploitation. AI-powered software analysis is1914capable of identifying previously-unknown zero-day1915vulnerabilities faster than ever. Yet for many organizations,1916the long-standing challenge has not been awareness that a1917vulnerability exists, but rather the inability to patch and1918remediate quickly. As attack time lines compress, this1919operational inertia becomes more dangerous.1920    The practical result is a dramatic reduction in the time1921available for defenders. Comprehensive attacks are easier to1922launch, the pool of capable adversaries expands, and smaller1923organizations, such as hospitals, schools, and small businesses1924are increasingly exposed to the same level of adversarial1925capability once reserved for critical national infrastructure.1926    This compression of time changes the nature of cyber risk1927itself. Defenders are often no longer responding to early1928indicators, but to attacks that are already in progress.1929Intelligent automation allows attacks to become continuous1930rather than episodic, eroding assumptions that organizations1931can recover between incidents or rely on periodic assessments.1932    The widening gap between machine-speed attacks and human-1933speed defenses means cybersecurity outcomes are increasingly1934determined by whether defenses can operate at comparable1935speeds. These shifts have clear implications for defense policy1936and coordination.1937    First, secure-by-design principles must become a baseline1938expectation, particularly as AI increasingly writes and modify1939software. Second, regulatory clarity is critical. Fragmented or1940ambitious regulations can slow defensive responses in an1941environment or speed matters. Third, public-private1942coordination remains essential, ensuring that defensive1943learning keeps pace with adversarial innovation. Fourth,1944defensive capabilities must increasingly rely on automation and1945autonomy as purely human-driven defenses will struggle to keep1946up. Fifth, finally, quantum preparedness is necessary. While1947post-quantum cryptographic standards exist, the challenge lies1948in the time and coordination required to migrate existing1949systems before an adversary achieves cryptographically-relevant1950quantum capability.1951    Finally, trust and transparency in AI systems are crucial.1952AI reflects the data, incentives, and governance under which it1953is trained. In a security-related context, understanding1954potential model bias and model origin is as important as1955performance.1956    Artificial intelligence and quantum computing are1957accelerating forces that dramatically reshape cybersecurity.1958Our success will depend on whether our technical, operational,1959institutional responses can adapt at a comparable pace.1960    Thank you and I look forward to your questions.1961    [The prepared statement of Mr. Coates follows:]1962                  Prepared Statement of Michael Coates1963                           December 17, 20251964    Chairman Ogles, Ranking Member Swalwell, Chairman Brecheen, and1965Ranking Member Thanedar, I thank you for the opportunity to testify1966before you today. I'm honored to be here to speak about the changing1967landscape in cybersecurity and the resulting impacts from AI and1968quantum computing.1969    The perspective I will share is grounded in over 20 years of1970experience in cybersecurity, including service as a chief information1971security officer, a chairman of a global non-profit advancing the state1972of application and coding security, a technology start-up founder, and1973a venture capital investor supporting cybersecurity innovation.1974    Today we sit at the precipice of significant change. While1975advancements in AI and development toward AGI are widely discussed, the1976practical and operational impacts to cybersecurity defenders are less1977often examined.1978    The fundamental reality is not that AI and quantum are creating new1979types of threats, but rather they are collapsing the time, cost, and1980skill required to conduct cyber operations. These changes are outpacing1981the existing technical, regulatory, and operational defenses. This1982shift reshapes the cyber threat landscape and forces a reconsideration1983of how we defend critical systems in an era defined by speed,1984automation, and intelligent scale.1985         what is changing: the compression of cyber capability1986    capability compression & orchestration expands the attacker base1987    Corporations and citizens potentially face a variety of threat1988agents including highly-funded nation-state adversaries, financially-1989motivated cyber-criminal organizations, and lone hacktivists motivated1990by ideology. Each attacker type has different skills and resources at1991their disposal and to date, these have constrained the complexity or1992scale of cyber attacks available to each adversary.1993    The most advanced attacks were often only launched by nation-state1994adversaries against select targets. Whereas cyber-criminal entities1995focused their efforts on pipelines of optimized offensive security1996services, such as ransomware extortion, to monetize the compromise of1997businesses or individuals.1998    Robust security attacks require a series of steps spanning1999reconnaissance, exploitation, command and control, and delivery of the2000ultimate objective, such as data theft or system modification. Each of2001these components could be executed by a well-funded nation-state2002adversary or a competent cyber-criminal organization, but it was not as2003achievable for the lone hacktivist or unsophisticated security hacker.2004This is rapidly changing.2005    As demonstrated in the November, 2025 Anthropic report ``Disrupting2006the first reported AI-orchestrated cyber espionage campaign'',\1\ a2007nation-state adversary used AI systems as a central brain and point of2008coordination for a complete security attack against multiple targets2009across the United States. AI was used to execute and interpret results2010for each step of the attack and as an overall orchestration layer, with2011the human adversary only interacting at a few decision points.2012---------------------------------------------------------------------------2013    \1\ https://www.anthropic.com/news/disrupting-AI-espionage.2014---------------------------------------------------------------------------2015    While this attack may not have demonstrated new or novel attack2016methods, the orchestration and use of AI is a critical development in2017the ecosystem of the cybersecurity adversary.2018                agentic attacks remove human constraints2019    Agentic AI systems will enable the attacker to no longer be bound2020by time of day, hours awake, or the need for food or sleep. Autonomous2021agentic systems are replicating the most advanced attackers and will be2022able to target with accuracy and ease.2023    This is no longer theoretical as research just released by Stanford2024\2\ shows that an autonomous AI penetration-testing agent already2025performs at or above the level of most highly-skilled professional2026security testers, outperforming 9 out of 10 participants in a live2027network test with an 82 percent valid vulnerability discovery rate at a2028fraction of the cost.2029---------------------------------------------------------------------------2030    \2\ https://arxiv.org/pdf/2512.09882.2031---------------------------------------------------------------------------2032        acceleration of vulnerability discovery and exploitation2033    Furthermore, the increasing power of AI for software vulnerability2034analysis is enabling faster and more accurate detection of previously-2035unknown zero-day security vulnerabilities. For example, Google's Big2036Sleep, a collaboration between Google Project Zero and Google DeepMind,2037has discovered a critical zero-day vulnerability in the major software2038SQLite Database Engine.\3\2039---------------------------------------------------------------------------2040    \3\ https://cloud.google.com/blog/products/identity-security/cloud-2041ciso-perspectives-our-big-sleep-agent-makes-big-leap.2042---------------------------------------------------------------------------2043    Over the past decades, the challenge for many organizations has not2044been knowledge that a vulnerability existed, but rather the operational2045inertia to deploy, test, and productize the software patch. In fact,2046the 2025 Verizon Data Breach Investigations Report found that2047vulnerability exploitation was the initial access vector in 20 percent2048of breaches, and that defenders often cannot remediate fast enough--2049organizations fully remediated only about 54 percent of vulnerabilities2050in network edge devices, with a median remediation time of 32 days,2051while CISA KEV vulnerabilities can be mass exploited in a median of 52052days.\4\2053---------------------------------------------------------------------------2054    \4\ https://www.verizon.com/business/resources/reports/dbir/.2055---------------------------------------------------------------------------2056            the practical result: reduced time for defenders2057    With AI orchestration, the ease of launching comprehensive2058cybersecurity attacks against any target is substantially reduced. The2059result is that many more potential adversaries now have the means to2060execute these attacks.2061    In addition to an increase in attacks against the most critical2062targets, this development will also result in lesser-profile targets,2063such as small businesses across the country, being subjected to full-2064scale security assaults.2065    The direct result of this change will be a dramatic drop in the2066time available for defenders to detect attacks, initial compromise, or2067lateral movement before critical access or sensitive data is breached.2068Taken together, these shifts do not just increase cyber risk, they2069fundamentally change the speed at which cyber incidents unfold.2070         why time compression changes the nature of cyber risk2071    The compression of time, cost, and skill required to conduct cyber2072operations fundamentally changes how cyber risk manifests in practice.2073While individual techniques may appear familiar, the speed at which2074attacks now unfold alters the balance between attackers and defenders2075in ways that existing security models were not designed to accommodate.2076    The most immediate consequence is a dramatic reduction in the time2077available for defenders to detect and respond to malicious activity.2078AI-enabled orchestration and automation allow attackers to move from2079initial access to lateral movement and impact far more quickly than in2080the past. In many cases, defenders are no longer responding to early2081indicators of compromise, but to attacks that are already well under2082way.2083    This compression of time disproportionately affects organizations2084that lack large, specialized security teams. While highly-resourced2085enterprises may be able to invest in advanced detection and response2086capabilities, smaller organizations, including hospitals, schools, food2087processing facilities, and small businesses often rely on delayed or2088manual processes. As sophisticated attacks become easier to launch and2089less expensive to operate, these lower-profile targets increasingly2090face the same level of adversarial capability once reserved for2091critical national infrastructure.2092    At the same time, intelligent automation and scaling by adversaries2093is shifting the risk of attacks from periodic events to a continuous2094threat. AI-driven attacks do not require sustained human attention and2095can operate persistently, adapting to defenses and retrying failed2096approaches automatically. This erodes traditional assumptions that2097organizations can recover between incidents or rely on periodic2098assessments to maintain security.2099    Existing defensive and governance models further compound this2100challenge. Over the past decades, many major breaches did not occur2101because vulnerabilities were unknown, but because organizations were2102unable to deploy patches or mitigations quickly enough. As AI2103accelerates vulnerability discovery and exploitation, this operational2104inertia becomes more consequential. The gap between awareness and2105action grows more dangerous as attack time lines compress.2106    The result is a widening gap between the speed and accessibility of2107modern cyber attacks and the ability of most organizations to respond.2108As AI compresses attack time lines and expands the pool of capable2109adversaries, cybersecurity outcomes will increasingly be determined by2110whether defenses can operate at machine speed.2111        implications for cyber defense, policy, and coordination2112    The advancements in artificial intelligence and quantum computing2113present significant opportunities for innovation, but without2114appropriate alignment between technology, operations, and governance,2115they also introduce material cybersecurity risk. The shifts described2116earlier are not theoretical, and they cannot be addressed by any single2117organization or sector acting alone.2118    The following are key areas where attention is warranted to2119increase the cybersecurity posture of our organizations and critical2120systems.2121Secure by Design as a Baseline Expectation2122    As software is increasingly written, analyzed, and modified by AI2123systems, secure design principles must be integrated into the creation2124of software from the outset. Initiatives such as CISA's Secure by2125Design program, along with industry standards promoted by organizations2126like OWASP and the Cloud Security Alliance, provide important guidance.2127Supporting these organizations and reinforcing these efforts helps2128ensure that speed and automation do not come at the expense of security2129fundamentals.2130Regulatory Clarity That Supports Speed and Innovation2131    Clear and transparent regulatory frameworks are necessary to enable2132rapid innovation while maintaining responsibility for security and2133safety. In an environment where threats evolve quickly, ambiguity or2134fragmentation in regulation can unintentionally slow defensive response2135and increase systemic risk. Policy should seek to provide clarity and2136consistency without constraining the ability of organizations to adapt2137at machine speed.2138Public-Private Coordination on AI-Driven Cyber Threats2139    The pace of change in the cyber threat landscape reinforces the2140importance of strong public-private partnerships. Effective2141coordination, information sharing, and joint response mechanisms help2142ensure that defensive learning keeps pace with adversarial innovation.2143These partnerships remain a critical component of national cyber2144resilience as AI-driven threats continue to evolve.2145Migration Toward Autonomous Defensive Capabilities2146    As attackers increasingly rely on automation and agentic systems,2147purely human-driven defenses will struggle to keep pace. Continued2148investment in research, development, and deployment of intelligent and2149autonomous defensive systems is necessary to address machine-speed2150threats. This includes supporting innovation across both the public and2151private sectors.2152Quantum Preparedness for Cryptographic Systems2153    Stable, cryptographically-relevant quantum computing would render2154many of today's widely-deployed public-key encryption algorithms2155ineffective, impacting secure communications across government,2156industry, and critical infrastructure. While post-quantum cryptographic2157standards already exist, the primary challenge is the time and2158coordination required to migrate existing systems. Deliberate2159preparation is crucial to avoid a reality where an adversary achieves2160cryptographically-relevant quantum capabilities first and thus access2161not only to future communications, but potentially to sensitive data2162captured and stored today.2163Trustworthiness and Transparency in AI Systems2164    As AI systems are increasingly embedded into security-sensitive2165workflows, trust in operation becomes crucial. Large language models2166reflect the data, incentives, and governance structures under which2167they are trained, and these factors can materially influence2168reliability and security outcomes.2169    Bias in AI systems--whether intentional or unintentional--can2170affect how software is generated, how alerts are prioritized, and how2171decisions are made. In security-critical contexts, performance alone is2172not sufficient; the provenance, training, and oversight of AI systems2173must also be considered as part of risk assessment.2174    Furthermore, greater transparency in software procurement and2175composition is needed. Requiring bill of materials and software2176contracts to disclose the use of AI within software, as well as the2177specific models and model origins, can help organizations better assess2178risk and make informed security decisions, particularly in sensitive or2179critical environments.2180    Artificial intelligence and quantum computing are accelerating2181dynamics that dramatically shift the cybersecurity landscape. As AI and2182quantum computing continue to advance and are increasingly leveraged by2183cyber adversaries, success will depend on whether our technical,2184operational, and institutional responses can adapt at comparable pace.2185    I appreciate the opportunity to share these observations and look2186forward to your questions.21872188    Mr. Ogles. Thank you, Mr. Coates.2189    Members will be recognized by order of seniority for their21905 minutes of questioning. I now recognize myself for 5 minutes.2191    Dr. Graham, Anthropic's investigation into the recent PRC-2192affiliated cyber incident involving Claude suggests we may be2193approaching a turning point in how cyber operations are2194conducted, where AI systems, once asked--tasked by human2195operators, can execute and refine large portions of a cyber2196attack at machine speed rather than human speed. Obviously you2197touched on this in your opening statement--should this incident2198be understood as an early warning of the future of AI systems,2199how they are autonomously, you know, writing and adapting to2200systems? Quite frankly, from a defensive perspective, you know,2201what capability gaps do we have? Where do we need to be2202anticipating?2203    I mean, I see a horizon that we can't quite define because2204of the rapidness and just the evolving nature of the2205technology. I go back to kind-of the arms race. There was a2206point at which, between the United States and Russia, there was2207this detente, there was this, you know, mutually-assured2208destruction, where it was at some point we all had enough nukes2209to kill everybody and blow the whole world up. It was all about2210delivery systems at that point.2211    AI is different. There is no horizon. There is no kind-of2212point at which I think it stops, that there is a ceiling. So,2213please, take it away.2214    Mr. Graham. You're correct that we are at a change point.2215There are a couple of change points here. The first that we see2216now is, to our understanding, this is the first time where2217these models will now be sought and used by sophisticated state2218actors. We've been tracking this trend line for many years.2219This is the clearest evidence for the first time that this is2220now happening.2221    But it's also possible this gets more serious and the2222stakes become much higher. As you say, it's very possible that2223attacks from here on might scale if we don't properly secure2224and safeguard the models. It's also possible that while in this2225case we didn't see an instance of novel--or novel methods of2226attack, it's very possible that models could get that good.2227    What's important now is a few things. First, it's really2228hard to win if we can't see the playing field. I think the2229easiest way to start is continuing to evaluate the capabilities2230of these models. This is something industry should do, this is2231something Government should do. Second, we should be sharing2232threat intelligence as it happens so that we can mitigate as2233fast as possible. Third, as you say, we need to make sure2234defenders have the advantage, particularly the United States,2235make sure that it defends itself faster than it can be2236attacked. We are working very hard, and I think all industry2237needs to work hard to make that happen.2238    Mr. Ogles. You know, a follow-up onto that point, you know,2239clearly, when you look at the investments that China is making2240on these quantum capabilities, AI, et cetera, you know, there2241is a requirement between, you know, their private sector, if2242you want to even call it a private sector because most of it is2243state-owned, that any innovation is immediately shared with the2244State. So, as you mentioned, there is going--for us to be2245successful, there is going to have to be this collaboration2246between private and Government, quite frankly.2247    But one of the things, and obviously that is easier to2248accomplish, but there is--I foresee a need where the industry2249itself is going to have to be sharing information. Of course,2250the problem you get into there is the proprietary nature of2251things. You know, obviously there is the monetization factor2252that comes into that. But at the end of the day, we are talking2253about the homeland. So how do you see that working in practice,2254understanding the complications that we have essentially in a2255free market?2256    Then another layer to that is essentially the Five Eyes,2257the Seven [sic] Eyes, our European partners, who are aligned2258with us in our values, who understand the existential threat2259that China poses. Again, it is important for everyone to2260understand that China is probing us daily to look for2261weaknesses and opportunities to take advantage of information2262that is not properly secured. What is different about this is2263the leveraging and the scale and the percentage, if you will,2264that AI was leveraged. Sir.2265    Mr. Graham. It is very, very important that industry does2266share the information that it has between itself. It's very2267important it shares that with Government. It's very important2268that industry develop solutions now, whether it's by improving2269the models or building tools and putting them in the hands of2270the defenders. I think just making the models good enough isn't2271sufficient. We need to make sure people are using it to2272proactively defend critical infrastructure. One way that I2273think Government can be extremely helpful here is identifying2274the critical infrastructure that needs to be defended in this2275new era of cybersecurity and allowing industry to point out its2276talents and innovation toward that.2277    Mr. Ogles. Well, I want to thank, again, all of you for2278being here and, quite frankly, to Anthropic for your report. I2279think it was one of those inflection points that we all2280understood the seriousness of this. But your report, I think,2281really put a light on where we are at and where--and some of2282our vulnerabilities.2283    I now recognize the Ranking Member, the gentleman from2284Michigan, Mr. Thanedar, for his 5 minutes of questions.2285    Mr. Thanedar. Thank you, again, Chairman Ogles. Appreciate2286all of our witnesses.2287    You know, I remain deeply worried and concerned about2288President Trump's decision to allow export of advanced chips to2289China. I just don't understand other than his desire to please2290a donor. I just don't understand, why would we give such2291advanced technology to an adversary like China, who can then2292use this technology to attack us? Who could use this technology2293to cyber attack our critical infrastructure?2294    Dr. Graham, how would China having access to this advanced2295chips, how will that help advance their AI technology? Will2296that pose a threat to the United States, our national security?2297    Mr. Graham. We view it as, first, extremely important that2298America retains its AI leadership. The most important input to2299this is the compute advantage. My concern from watching these2300models progress in their capabilities, especially as a result2301of the cyber espionage campaign, is that if Chinese frontier2302labs have access to similar amounts of compute, they could2303train models that are equally or more capable in the cyber2304domain and that this could unleash new scale and new2305sophistication, and we will have a harder time detecting and2306defending it.2307    Mr. Thanedar. Thank you. Thank you. I want to shift my2308focus. I only have a limited time. I want to shift my focus on2309immigration.2310    You know, in his first term, President Trump's first term,2311and now in his second term, there is just so much of hate2312against immigrants. Yet we know, and I hope the panel agrees2313with me, that the United States technology industry has2314benefited greatly from immigrants.2315    Just by answering yes or no from the witnesses, does your2316companies have immigrants, skilled immigrants, and do you2317depend on them? Yes, no?2318    Mr. Graham. Anthropic is composed of many of the best2319talent from around the world.2320    Mr. Thanedar. Anybody thinks we should have less of skilled2321immigrants on the panel here? Should we restrict access of2322immigrants to our technology companies, immigrants who help us2323keep on the edge?2324    Well, certainly, you know, I am myself an immigrant.2325Twenty-four years old, I came here escaping poverty in India,2326got a Ph.D. in chemistry, became a serial entrepreneur, ran2327many pharmaceutical companies, developing technology that2328helped us stay on top of innovation. You know, while it is2329important that American jobs be protected, it is important that2330we create skills. But at the same time, our tech industry2331heavily depends on skills, skill sets, immigrant skill sets.2332    Have the actions of the Trump administration--how has acts2333of the Trump administration made it difficult to retain2334international talent in your companies with regard to both2335international workers choosing to leave or being forced to2336leave due to discrimination changes, the hardship that they2337have in terms of getting their status adjusted, getting their2338green cards, the long delay in processing, making it harder to2339get an H-1B visa? I just wanted to understand what kind of2340impact these administration's positions are doing to your2341ability to grow your companies, grow your new technology for2342the United States. Anybody? Yes.2343    Mr. Graham. Well, it's not my issue area that I cover in2344the company. Speaking for my team, it's really important that I2345find and hire the best people around the world that are2346committed to our mission of making AI stay secure and ensuring2347America's leadership.2348    Mr. Thanedar. Yes. Anybody else? How important is2349immigration?2350    Mr. Hansen. I mean, I'd just say again, it's not--you'd2351have to talk to our H.R. department so we can come back to you2352with--you know, I'll relay that question to the teams.2353    Mr. Thanedar. What percent of your organization has2354immigrants?2355    Mr. Hansen. I wouldn't know the exact number, but certainly2356we do have green cards and immigrants that work at Google.2357    Mr. Thanedar. Thank you. Anybody else?2358    You know, again, the need continues and for us, America, to2359have its edge on innovation, whether it is cybersecurity, AI,2360quantum, we must have skilled work force. If that means we have2361to depend on immigrants, so be it.2362    Thank you. I yield back.2363    Mr. Ogles. The gentleman yields back.2364    I recognize the Chairman of the Subcommittee on Oversight,2365Investigations, and Accountability, the gentleman from2366Oklahoma, Mr. Brecheen.2367    Mr. Brecheen. Thank you Mr. Chairman.2368    Mr. Hansen, just before I get started, prayers over your2369son. May the Lord do what human hands can't. Appreciate your2370passion, appreciate your vulnerability in sharing that.2371    Also appreciate what you expressed about limiting services2372for mainland China. I think that is great that your company is2373willing to do that. My hope is that others would watch your2374concern over proprietary information and desire to make sure2375that U.S. citizenry is protected and follow your lead.2376    Mr. Graham, you talked about that you felt like that robust2377intelligence sharing could be enhanced. So what is it that you2378are seeing that could be improved upon about, of course, your2379front line, the free market, Government learns from it? What2380can the Fed be doing to a greater level, Homeland Security2381specific to this committee's assignment, to make sure that that2382robust intelligence sharing is happening, so that, you know, in2383real time we are sending out information that others can be2384protected based upon immediate experience?2385    Mr. Graham. Yes. A fundamental issue here is that as the2386technology gets better, we're going to start seeing new2387patterns that are potentially more sophisticated that either in2388industry or across government we have not seen before in terms2389of what these attacks look like. I think the first most2390important thing is we need good and quick and sensitive2391channels to share the novelty of this information, possibly2392within and to Government and cross industry.2393    We probably need to get ahead of it as well. So we need to2394be able to share information prior to the attack occurring. We2395regularly brief and share information about model capabilities2396as they're advancing. In general, any effort here I think is2397extremely valuable and I think is going to put all of industry2398in a better position.2399    Mr. Brecheen. Yes. One of the things we can do is there are2400people that work behind the scenes that never, you know, get in2401front of the limelight of Government. So without naming names,2402what division with Homeland Security can we highlight to just2403send a special thank you to working with you?2404    Mr. Graham. I'm not an issue expert in the specific2405components of homeland security, but would very happily follow2406up with you to talk more.2407    Mr. Brecheen. That would be great. We want to make sure2408we're congratulating those groups that are taking your2409experience seriously.2410    I want to talk about the at-scale capability of 80 to 902411percent of nonhuman hands on what would be formally labor-2412intensive, now turned into generated by computer processing. So2413Mr. Hansen, if AI is utilized to provoke, then AI can be2414utilized to defend. So how can we enhance our scale of2415utilizing AI to wall off?2416    Mr. Hansen. It's exactly the right question. So when you2417talk about what we can do is I think of the old adage about the2418cobbler's children who don't have shoes. So there are far more2419defenders in the world than there are attackers. But we need to2420arm them with the--that same type of automation that you saw in2421the attack described by Anthropic. Because it's just in many2422ways using commodity tools that we already have to both find2423and fix vulnerabilities. Those can be turned from offensive2424capabilities to the patching and fixing. But the defenders have2425to put shoes on. They have to use AI in defense.2426    So while the attackers are experimenting, we need the2427defenders to be experimenting and becoming great users of AI to2428find the same vulnerabilities that were described, but instead2429of exploiting them, to patch them. That's the kind of--I2430mentioned CodeMender is our project, which takes advantage of2431this, you know, vibe coding, if you want to call it. It's2432easier and easier to code. We make it easier and easier to2433patch.2434    With so much of our problems based on legacy technology,2435small companies, others, that's the only way we're going to get2436ahead. This defender's dilemma of attacker needs to be right2437once, defender needs to be right all the time, AI can help the2438defender be right all the time. That's what we need to do.2439    Mr. Brecheen. Mr. Zervigon, if I did a horrible job of2440pronouncing your name, you have a last name like mine, I2441apologize. Mr. Coates, you have taken the time to be here. I2442have got 30 seconds. If there is anything, because this is such2443an exploratory exercise for so many of us that are not experts,2444is there anything you want to just highlight? I have got 202445seconds to split between the two of you.2446    Mr. Zervigon. I would say innovative results demand2447innovative time lines. Right? You can't be operating on legacy2448time lines in order to achieve innovative results to protect2449the homeland.2450    Mr. Coates. The piece I would add is that the information2451sharing is critical. Staying abreast of how this is evolving is2452going to be one of the most important pieces amongst2453enterprises fighting against the new threats.2454    Mr. Brecheen. I look forward to highlighting Homeland2455Security staff with our committee staff.2456    Thank you, Mr. Chairman.2457    Mr. Ogles. The gentleman yields back.2458    I recognize the gentleman from Rhode Island, Mr. Magaziner.2459    Mr. Magaziner. Thank you, Chairman.2460    I am going to get right to the point. The Chinese2461government just launched the first-ever AI-powered cyber attack2462against our country that we know of. At the same time,2463President Trump is selling the powerful H200 Nvidia chips, the2464next generation chips, to China. I will ask any of our 42465experts, does anybody think this is a good idea? Or our2466colleagues or anyone, does anyone want to defend this decision?2467    Like they are literally--they are engaging in cyber warfare2468against us right now. They just did it. They just launched the2469first AI-powered cyber attack against U.S. organizations. Why2470in the world, given that they just did this, what, a couple2471months ago, would we be giving them these next generation chips2472now? At the very least, we ought to be holding them back until2473we have some way of verifying that these chips are not going to2474be used to attack us.2475    So I will ask again. Any of our witnesses, Mr. Graham, Mr.2476Coates, anyone, why is it concerning to you that China is about2477to receive these H200 chips from Nvidia? Mr. Coates, would you2478like to take a stab at it?2479    Mr. Coates. The defenses that we put into our LLMs, that2480Anthropic, that Google, and others are doing to provide safety,2481are things that we can control and we can use to prevent future2482type attacks from China using these resources. As China2483achieves the same capabilities and their technology from these2484chips, we lose control of the ability to put those safeguards2485in place and we're on our heels. So I agree with the concern2486that's being raised.2487    The other piece that I will mention here is that as China2488provides greater frontier models, like DeepSeek, and it's2489appealing to U.S. software corporations to integrate that into2490their stack for performance regions, we have to remember that2491that is essentially delegating decision making and trust to2492China, even though it might be U.S. software. We need greater2493focus on that.2494    Mr. Magaziner. Yes, I mean, look, cybersecurity is a2495bipartisan issue. I believe that there are people on both sides2496who care genuinely about keeping us safe in the cyber domain.2497But, like, I don't know how anybody can be OK with this chip2498sale given what literally just happened 2 months ago. That is2499something that I think we need to find a way as a Congress to2500deal with because the administration, I fear, has made a grave2501mistake.2502    I want to talk about the attack more specifically because2503we need to learn as much as we can from it. Mr. Graham, I am2504grateful that Anthropic was able to detect and then report2505about the nature of the attack, but my understanding is it took2506about 2 weeks for Anthropic to realize that the attack was2507happening, give or take. Is that correct? Can you explain to2508us, you mentioned it in your written testimony, can you explain2509to us generally why it took so long and what lessons you have2510learned, and how you can now detect similar attacks, hopefully2511faster in the future?2512    Mr. Graham. Yes. The first thing to note is we ultimately2513did detect and disrupt the attack. When we did, it was clear2514that this was a highly-resourced, sophisticated effort to get2515around the safeguards in order to conduct the attack. Very2516specifically, what they did was they used a private obfuscation2517network to ensure that it was difficult to trace where the2518operations were coming from. They broke out the attack into2519small components that individually looked benign, but taken2520together form a broad pattern of misuse. Then ultimately, they2521deceived the model into believing that it was performing2522ethical--I mean----2523    Mr. Magaziner. They basically told the model, help us2524figure out how to protect ourselves from a cyber attack, but,2525in so doing, the model revealed the vulnerabilities to a cyber2526attack. Is that, in layman's terms, what happened?2527    Mr. Graham. That is one of the components. That's--it's one2528of the key issues with cybersecurity.2529    Mr. Magaziner. Yes. I mean, I would just say as like a2530layperson, that that seems like something that, you know, ought2531to be flagged. Right? If someone says, help me figure out what2532my vulnerabilities are, there should be an instant flag that2533someone may actually be looking for vulnerabilities for a2534nefarious purpose.2535    So I will just ask for the time I have left to any of our2536witnesses, I mean, what regulation is required to ensure that2537commercially-available AI products have adequate guardrails in2538place? We appreciate the, you know, the efforts that companies2539are already undertaking, but there should be some sort of a2540baseline of standards that we set as a country, should there2541not?2542    Mr. Hansen. We released this Secure AI Framework, SAIF, and2543then there's a 2.0 version, as well as a Coalition for Secure2544AI where we're not just helping set standards, but open source2545the implementations so, broadly, people can take advantage of2546and use those in their infrastructure.2547    Mr. Magaziner. All right, thank you all. I yield back.2548    Mr. Ogles. The gentleman yields back.2549    I now recognize the gentleman from Texas, Mr. Luttrell.2550    Mr. Luttrell. Thank you, Mr. Chairman.2551    Mr. Zervigon, did I say that right?2552    Mr. Zervigon. Perfect. Yes, sir.2553    Mr. Luttrell. You spoke on architecture and how to secure a2554proverbial infrastructure and how information flows. The2555question was hinted at earlier, and we need to know this on2556this side, who is it that you deal with? Department of Homeland2557Security, Mr. Brecheen brought that up. From my understanding,2558and this is what I am trying to get clarity on, from my2559understanding it is there is 3 entities: Department of Justice,2560Department of Homeland Security, and Department of Defense all2561touch our communication capabilities above the ground and below2562the ground. Can you add clarity for me on who you deal with2563directly? Is there one more than the other?2564    The discussions I have had with our departments is they2565kind-of hand the football off, and I really can't find anybody2566who is running point on this. I will start with you, sir, and2567we can move back and forth.2568    Mr. Zervigon. I mean, from our experience, I think Customs2569and Border Protection are showing a lot of leadership on this2570issue and understanding that this is an architectural problem2571that needs to be remedied. Obviously with the cost-benefit2572analysis of being able to do this over a period of time.2573    Mr. Luttrell. Is that brick-and-mortar facilities that our2574undersea cabling runs into, that, you know, Salt Typhoon is2575having a heyday with, things like that?2576    Mr. Zervigon. All of them. All the above. So it's about any2577network connection, any network endpoint that needs to be2578updated for post-quantum cryptography.2579    Mr. Luttrell. Mr. Hansen.2580    Mr. Hansen. As an example, we in the Chrome Browser back in25812023, changed the implementation of the encryption to begin to2582be post-quantum crypto-resistant because everyone would use it.2583Right? It's used broadly in the industry. So our strategy is2584to, whether it's undersea cables, whether it's data centers,2585whether it's the hardware, make it secure by default.2586    Mr. Luttrell. Is that your company specifically that is2587providing the security profile for that or is that something2588that Homeland is coming in assisting with or Department of2589Defense is coming in and assisting with? I got to tell you,2590this was kind-of, and I hate to say, ignorant to really kind-of2591what the answer is to that.2592    Mr. Hansen. Yes. In a world where every one of these2593departments or, you know, sort-of the scope of their oversight2594is digital or increasingly digital, we work across all of those2595entities you've mentioned and more on these kinds things.2596    Mr. Luttrell. I feel like we are not doing enough. Case in2597point, Mr. Graham, with what happened with Claude, and you guys2598have Gemini, correct? Am I saying that correctly?2599    Mr. Graham. That's right.2600    Mr. Luttrell. Where the bad actors, the nefarious actors,2601are utilizing AI capabilities to hack into the kind-of the2602sweet spot of what we are not looking at.2603    Mr. Graham, was the--was it a human or software that found2604the attack or both?2605    Mr. Graham. On our side it was a combination of both.2606First, there's a series of detection measures that are2607generally automated and software-based. This triggered a human2608investigation that allowed us to----2609    Mr. Luttrell. So as fast as we are moving on the2610advancements of artificial intelligence and we can't--I don't2611think we can stop. Because if we slow down, everyone else is2612going to keep going. Then if we are behind now, we are2613absolutely going to be in last place. So here we go. If we move2614to a point where artificial intelligence removes the human2615element, but you needed the human element to find it, what2616happens?2617    Mr. Graham. I am enormously optimistic about the2618opportunities here to leverage AI to do this. This is the first2619time we're seeing some of this.2620    Mr. Luttrell. We all are, too. This is us being overly2621cautious. It is not us that is going to be able to regulate it.2622It is too fast. By the time you show up in front of us to tell2623us what happened, whomever took ahold of Claude to make--are2624they lying in wait? Are they sleeping inside the program now2625and we have missed it, and they are watching you fix the2626problem and they know how you fixed it, and they are going to2627attack someone else that is not as strong and capable or2628yourself or Google?2629    Mr. Graham. Well, in this case, it wasn't Anthropic itself2630that was infiltrated.2631    Mr. Luttrell. Yes, I am sorry. OK.2632    Mr. Graham. It is very clear that sophisticated actors are2633now doing preparations for the next time, for the next model,2634for the next capability they can exploit. This is why we have2635to be detecting them as fast as possible and mitigating at the2636model layer.2637    Mr. Luttrell. Because I am going to use the term super2638scientist. This is what AI has created. You have titrated2639hundreds of attackers down to 2 or 3 that have the capability2640to ask the AI the question on exactly how to get in----2641    Mr. Hansen. Yes, I think once----2642    Mr. Luttrell [continuing]. At a speed that is2643uncomprehensible.2644    Mr. Hansen. To this point, we've been using behind Gmail2645and behind the Play Store and behind Chrome for almost a decade2646AI in its earlier forms to do exactly what you're talking2647about, so no humans involved. So your question is correct. It's2648actually been happening, you know, long before the large2649language models emerged.2650    Mr. Luttrell. OK, thank you.2651    I am sorry, Mr. Chairman. I yield back.2652    Mr. Ogles. The gentleman yields back.2653    I recognize the gentlewoman from New Jersey, Ms. McIver,2654for 5 minutes.2655    Ms. McIver. Thank you, Mr. Chair and Ranking Member, and2656thank you to our witnesses for joining us today.2657    Every community, State, and country will be impacted by the2658benefits and risks of AI. In fact, we already see these impacts2659occurring. While the United States has been a leader with AI2660technology, our rivals are innovating in this area with great2661speed and we have to make sure working people here have what2662they need to stay safe and successful.2663    Education will be key to maintaining American dominance,2664security, and economic success. With my colleagues,2665Representative Cleaver and Senators Blunt, Rochester, and2666Hirono and Schiff, we introduced the Workforce of the Future2667Act. This legislation would help us better examine the skills2668necessary for workers to thrive in the AI-dominated economy. It2669will also provide resources for educators and students to get2670the skills they need to participate in the work force of the2671future and stay protected against adverse consequences of new2672technology.2673    We need to make sure that all Americans are set up to2674succeed in a world impacted by AI, not be displaced by it. An2675AI-competent work force will lead to a more secure United2676States and a stronger future for working people.2677    With that, Mr. Coates, I would love to talk with you about2678Trump recently signed an Executive Order that would overturn2679any State-based AI regulation deemed burdensome. What are some2680risks of letting AI develop unregulated?2681    Mr. Coates. I think the important piece with AI regulation2682is to set clear guidelines and rules of the road and establish2683transparency amongst the creators. We want to motivate2684innovation and ensure that the United States stays as a leader2685in the world on AI.2686    One of the challenges in cybersecurity in particular can be2687a patchwork of regulations across States to deal with,2688especially in things like data disclosure, breach responseness,2689et cetera. So we want to make sure that in the fast-moving2690field of AI innovation, we are setting the right objectives2691clear, so we can operate to rules of the road, but we don't2692hamstring our technology organizations and prevent innovation.2693The last thing we want to be is on our heels or second to2694others in the world with AI technology.2695    Ms. McIver. Thank you for that. Just a follow-up, you2696mentioned cybersecurity. Can you expand a little bit of how2697important will AI knowledge and competency be in the future of2698cybersecurity?2699    Mr. Coates. I would consider AI to be a critical piece of2700the future of cybersecurity, both from the operators and the2701defenders. Understanding the core principles of cybersecurity2702through education, understanding how technology works, and then2703understanding how the different resources can be used as a2704defender. As I mentioned in my testimony, there's no question2705that for defense to be effective, it's going to have to move at2706the speed of computers. So we need the best humans to2707understand this technology and harness AI in a defensive2708capability.2709    Ms. McIver. Thank you for that. As AI data centers continue2710to expand, how do you balance innovation with the significant2711environmental and economic burdens they place on local2712communities and infrastructure?2713    Mr. Coates, you can start, but anyone else can chime in as2714well.2715    Mr. Coates. Maintaining dominance in AI is multifaceted.2716It's from the technology innovation in the models themselves to2717having sufficient power and technology and data centers to fund2718and power this innovation. So I do think it's critical to work2719across the Nation to understand where can we have the right2720locations of data centers with sufficient power. We don't want2721to lose control of the pieces that go together to build2722technology. To have effective AI, you have to have sufficient2723power and data center resources.2724    Ms. McIver. Thank you. Anyone else? Mr. Hansen.2725    Mr. Hansen. I was just going to say, yes, I talked a little2726bit about my son's situation and the science and tech and you2727think of this Alpha Fold, which was the protein folding work2728that won the Nobel Prize from Google last year. Fusion and2729energy and clean and safe energy, for me, is another problem.2730Like the cobbler's children, let's use the AI to help solve2731that problem. You asked a very good question and that's why we2732need to keep going on the science and technology as well.2733    Ms. McIver. Got it. Anyone else in 20 seconds? All right.2734Well, thank you so much.2735    With that, Mr. Chairman, I yield back.2736    Mr. Ogles. The gentlewoman yields back.2737    You know, appreciate the topic she touched on because, you2738know, as we move forward, and hopefully we will have time to2739come back to it, but this idea of what does that regulatory2740landscape look like and, you know, this ever-developing,2741quickly-evolving subject matter where energy is a factor,2742right? You know, this latency period where we are realizing we2743have these vulnerabilities that we are not quite ready to, you2744know, adapt to or backfill. So this is one of those--again,2745this hearing is the beginning of a very large conversation,2746whether it is energy, whether it is homeland security, and,2747quite frankly, the future of our role in the world.2748    I recognize the gentleman for Alabama for his 5 minutes of2749questions, Mr. Strong.2750    Mr. Strong. Thank you, Mr. Chairman, Ranking Member.2751Witnesses, thank you for being here today.2752    Dr. Graham, as my colleagues have mentioned, one concern is2753that AI allows adversaries to scale operations without scaling2754personnel. This changes the threat calculus for the United2755States. When AI tools are misused by cyber activity what2756visibility, if any, does DHS and CISA have into these2757incidents?2758    Mr. Graham. While I'm not familiar with the specific2759visibility of DHS and CISA here, I do know that what's2760important is industry should have information-sharing2761mechanisms with Government in these areas in order to give that2762visibility and also, in reverse, to understand the areas that2763industry should defend.2764    Mr. Strong. Absolutely. Turning to you, Mr. Hansen, cloud2765platforms now underpin Federal networks, critical2766infrastructure, and, increasingly, AI enables Government2767systems. From a national security perspective, does that2768concentration of sensitive activity in the cloud create new,2769wide-spread risk for the homeland?2770    Mr. Hansen. Actually, I think it is helping us clean up2771legacy technology issues. When you look at the vulnerabilities2772we've had over the last, you know, decade, it's generally2773people running on old versions of software that they're not2774maintaining. So we need competition in the space and I think it2775is competitive in many dimensions. But overall, modernizing is2776going to make you more secure in the moment.2777    Mr. Strong. I agree with you. Competition is where it is2778going to be, also.2779    AI and data centers are the future. I represent a State2780that is blessed with all forms of energy: coal, hydro, gas,2781solar, and nuclear power. We are able to meet the demand. What2782are your thoughts on AI and data centers in the future?2783    Mr. Hansen. You know, I know there's a--this is a big2784topic, as you would imagine, at Google, and there may be2785better, you know, people to talk about it. I would just say to2786the point about using AI, we use AI in the management of our2787data centers, in the management of the power in a variety of2788ways. So using the technology to help us do it as efficiently2789and effectively as possible is sort-of my only perspective. But2790we could go deeper on that with others in the company.2791    Mr. Strong. I also know that companies like Google, Meta,2792which both of those are located in my district, work closely2793with universities and the public sector on emerging2794technologies. In my district, we have institutions such as the2795Alabama School of Cyber Technology and Engineering that focuses2796on building early hands-on cyber and technology skills.2797    Mr. Hansen, from your view, how can public-private2798partnerships and collaboration with universities help2799accelerate practical understanding and to secure adoption of AI2800and cloud technologies across the Government?2801    Mr. Hansen. It's a really great question and relates to the2802work force question as well. We, in fact, over the last few2803years have stood up what we call cyber clinics. These are not2804just with the big State universities or private universities.2805They're with community colleges and they represent places2806across the country. So I think the working together on the2807curriculum, the technology, the approach for the next2808generation is critical.2809    Mr. Strong. Thank you. Mr. Zervigon, many national security2810data sets must remain secure for decades. What are the biggest2811practical challenges to deploying quantum-resistant encryption2812at scale today?2813    Mr. Zervigon. The desire to do so, I think. I think the2814capabilities are there. There are many innovative technologies2815and innovative companies that can assist. With the desire to do2816so, I think we can start going by protecting the transport2817layer, right? The overriding layer, which this information,2818this data travels.2819    Mr. Strong. Thank you. How can Government and industry work2820together to reduce risk without disrupting operations or2821slowing innovation?2822    Mr. Zervigon. Looking at it from an architectural2823standpoint, it's not just about the math. It's not just about2824creating new algorithms. It's about creating an architecture2825that allow you to deliver these algorithms, be able to swap2826them out at scale, be able to protect ourselves in the case2827that an algorithm is broken, because it will happen. So by2828doing so, it allows us to mitigate the effects, the ill effects2829of a harvest now, decrypt later attack.2830    Mr. Strong. Thank you. To close out, I would like to ask2831all the witnesses, if resources are limited, what should DHS2832and CISA prioritize first to reduce cyber risk most2833effectively? I will start on the end.2834    Mr. Graham. I think establishing threat intelligence-2835sharing channels, very important. Identifying infrastructure2836that needs to be secured, that we can go secure.2837    Mr. Strong. Thank you. Mr. Hansen.2838    Mr. Hansen. Modernization. Right? This is not something we2839go backward on. We got to go forwards.2840    Mr. Zervigon. Again, looking at the transport layer,2841looking at the biggest pipes carrying the most important2842pertinent data, and protect those first and then move downward2843from there.2844    Mr. Coates. It would be information sharing on emerging2845threats and adoption of autonomous defense systems.2846    Mr. Strong. Thank you. Mr. Chairman, I yield back.2847    Mr. Ogles. The gentleman yields back.2848    I now recognize the gentleman from Louisiana, Mr. Carter,2849for his 5 minutes.2850    Mr. Carter. Thank you, Mr. Chairman.2851    Cybersecurity is no longer a hypothetical risk. It is a2852real and growing threat to Louisiana and to our Nation's energy2853security. Louisiana sits at the heart of America's energy2854system, with refineries, petrochemical plants, pipelines, LNG2855export terminals, offshore platforms, and the electric grid all2856tightly interconnected. A successful cyber attack on any one of2857these systems could ripple across our entire national economy.2858    In 2021, the Colonial Pipeline cyber attack shut down a2859major fuel artery, caused shortages across the Southeast, and2860drove panic buying and price spikes, all without a single2861physical asset being damaged. That attack showed just how2862vulnerable our energy systems can be. That is why we must act2863now by strengthening cybersecurity, modernizing systems,2864sharing threat intelligence, and using AI defensively to stop2865attacks before they succeed.2866    Mr. Coates, in your testimony you state that bias in AI2867systems, whether intentional or unintentional, can affect how2868software is generated, how alerts are prioritized, how2869decisions are made. How can bias enter AI-driven security tools2870and what risk that poses to our cybersecurity?2871    Mr. Coates. It's an excellent question. The challenge in2872front of us is that we are off-loading decision making into AI2873when we use AI in our software systems. AI itself is trained on2874pre-training data, post-training data, configuration, et2875cetera, but that's reflective of the entity and organization2876that creates it.2877    CrowdStrike just released a report recently showing that2878the DeepSeek LLM model has bias. When you ask that model to2879create software and mention terms related to items like Tibet2880and other things not favorable in the CCPI, it generates code2881that is more vulnerable than had you not mentioned it. So this2882bias is built deeply into it. Maybe that is unintentional and a2883result of training data that was used. But nonetheless, we need2884to be aware that if American corporations are using software2885that's powered by LLMs, that are built outside the United2886States, that bias could come back to put us in a more risky2887position.2888    Mr. Carter. So what should we, should the Federal2889Government, should Congress, be doing to detect and mitigate2890these actions going forward?2891    Mr. Coates. The most important piece here is transparency.2892Requiring in the bill of materials for software procurement2893that we clearly state the origin of the pieces of the software.2894This is something we're doing already, but needs to be expanded2895to cover things like LLM, including where it was created,2896training information, et cetera.2897    Mr. Carter. Dr. Graham, you predict these attacks will only2898grow in effectiveness. What steps should we be taking to get2899ahead of this evolving threats, particularly those targeting2900critical infrastructure? What should Congress, what should we2901be doing as this committee do, to arm you, to arm others, to2902make sure that we are not playing catch-up, but we are catching2903this before it happens?2904    Mr. Graham. The very first thing we should do is that2905industry and Government should share threat intelligence so2906that we can get ahead.2907    Mr. Carter. Is that happening at a rate that you are2908comfortable?2909    Mr. Graham. It should always happen faster and more. The2910second is that I believe Congress can enable the deployment of2911these tools defensively. We can identify the infrastructure we2912should proactively defend and we can support or remove barriers2913to pulling these tools in order to defend them.2914    Mr. Carter. Mr. Hansen, as CISA developed and issued AI2915guidance, it worked in collaboration with our international2916allies. Why should the United States continue to coordinate2917with countries in this area?2918    Mr. Hansen. I was thinking about this when I was in Poland2919just after the Russian invasion of Ukraine, and they explained2920how they were now getting grain on the railroad out of Ukraine2921through Poland, but it had to be changed at the border because2922the Soviet-era railroad tracks' gauge was different from that2923in the West. I view this the same. We want American technology2924to be the railroad gauge of the 21st Century. So, to me, it's a2925national security question that people use our technology and2926not others.2927    Mr. Carter. Mr. Zervigon, I've got a lot of good friends in2928Louisiana with that name, so we will check boxes and see if2929Luis or some of those people are related to you, but.2930    Mr. Zervigon. They are.2931    Mr. Carter. Are they really? Fantastic. Some of my very2932dear friends.2933    But now that we have had a family reunion, tell me about2934investments. Are we making the kind of investments to stay2935ahead of the nefarious actors? As was mentioned earlier, we2936know that the bad guys sometimes get a lot more information2937than we do, and their technology grows pretty quickly. What can2938we do to make sure--because we have got listening ears here,2939and this is a great bipartisan group of individuals who really2940want to help. I know my time has expired, so can you give me a2941quick answer on that?2942    Mr. Zervigon. Sure. I mean, as I mentioned in my testimony,2943I think increasing the budget for the migration. Right? I think2944we don't have to do as much on the inventorying and the2945assessing and the understanding. We know the pipes that we need2946to secure, we know the data that we need to secure. We need to2947start doing that. Also I think helping that is accelerating the2948time lines and removing these artificial numbers out in the2949distance. When we should start doing it now.2950    Mr. Carter. Thank you, Mr. Chairman. You are very generous.2951    Mr. Ogles. The gentleman yields back. Thank you, sir, for2952your questions.2953    I am going to go to the gentleman from Texas----2954    Mr. Luttrell. Thank you, Mr. Chairman.2955    Mr. Luttrell [continuing]. Mr. Luttrell, for a second2956round.2957    Mr. Luttrell. The amount of data centers that we are2958building out, they draw a lot of power, and we are steadily2959increasing the footprint of each one of those facilities. Now,2960Texas stands alone as far as the national grid goes. There will2961come a time the amount of power drawn on everything that we are2962putting onto the grid will kill it. I am not talking--I am2963talking next year, 2 years, maybe max. Then what?2964    I think because we are all in the game together, is there a2965way that you all can decrease the amount of power, photon2966communications, or how the grid--how the data centers2967themselves communicate instead of that amount of power being2968drawn in? Because we will never catch you. There is no way we2969can build out enough infrastructure to power the amount of data2970centers being built. Just those alone.2971    So I don't know if this is more of a question than a2972concern that I am sure you are thinking about this. There is2973going to come a hinge point that it is either going to be an2974all-stop evolution we have to deal with. We have to do what we2975have right now because China, they don't have that problem.2976They are building hand over fist just to keep up the amount of2977energy that they are drawing. What do we do?2978    Mr. Hansen. So, you talked a little about the fusion or2979technological investment. So I think that's--we need to get2980started on doing that. We also--and you've seen this from2981Google, with our TPUs, which is a different type of chip, there2982are more efficient ways to do some of the computational work2983related to AI. So I think we need a round of innovation, which2984we're investing in, to make these chips more efficient and more2985performative.2986    Mr. Luttrell. Well, that happened----2987    Mr. Hansen. That's the work.2988    Mr. Luttrell [continuing]. Before the grid failed?2989    Mr. Hansen. That's the work. Yes, that is the work.2990    Mr. Luttrell. Mr. Graham, Mr. Coates, anything on this? I2991mean, Ms. McIver, hit the nail on the head here. This is a very2992real thing and we are not trying to slow innovation in any way,2993shape, or form. The entire globe is moving to the metaverse and2994we have to be able to sustain that. We do not have the2995infrastructure in place. I think in Texas, it is 2 years it is2996going to hit, and I would bet you a dollar on that one. But2997anyway, thank you, sir.2998    I yield back.2999    Mr. Ogles. The gentleman yields back.3000    I will go to the gentleman, the Ranking Member from OI&A,3001Mr. Thanedar.3002    Mr. Thanedar. Thank you, Chairman Ogles. Appreciate it.3003    As cyber attacks evolve, it is critical that the private3004sector share information about cyber threats with the Federal3005Government. This evolution is only accelerating due to AI,3006making it more important than ever that the Federal Government3007has the information necessary to understand current threat3008landscape. The Cybersecurity Information Sharing Act of 2015,3009the law that facilitates this kind of critical information3010sharing between the private sector and Federal Government, this3011law is set to expire on January 30.3012    My question to all of you is how important is it that3013Congress pass a long-term reauthorization of CISA 2015,3014particularly in light of the rapid evolution and deployment of3015novel technologies?3016    Mr. Coates. I think this is critical. In cybersecurity3017defense the basic primitives are known across organizations. We3018understand the plumbing, the core items that we need to do, but3019the techniques and the methods being used by the adversaries3020continues to change. It's crucial that organizations can say3021we've discovered this piece and share it with others. So3022collectively, we don't need to compete on defense, but look at3023it as a national imperative that we are secure and information3024sharing is a key piece of that.3025    Mr. Thanedar. Thank you.3026    Mr. Hansen. Yes, we're very supportive. In fact, I go3027further and say the Information Sharing and Analysis Centers,3028the ISACs, which exist by sector, this isn't just going to be a3029technical issue. This will be a health care, energy, and so the3030sector-specific sharing we need to focus on as well,3031particularly as AI operates more at the human layer than at the3032technical layer.3033    Mr. Thanedar. The private sector is usually on the top of3034the developments and certainly would be in a position to help3035the Federal Government, right?3036    Mr. Hansen. Absolutely. One of the reasons I came to Google3037from after working in financial services for many years was the3038realization that everyone was going to--every industry would3039need the benefits of security being baked into their3040technology, which includes sharing and making it easier for3041people to defend themselves.3042    Mr. Thanedar. Thank you, I appreciate it. I yield back.3043    Mr. Ogles. The gentleman yields back.3044    You know, there is a lot to unpack here and so we will drop3045in--unless other Members come in, we can drop some the3046formality and have more of a conversation and feel free to jump3047in.3048    You know, I guess I want to start us off with, is we know3049that we have a lot of, I think, infrastructure gaps. I mean,3050you know, I like to say we are the dominant predator currently3051across landscapes, but in this space in particular, that can3052change rapidly. So when you are setting the marker down, if you3053had to predict, and whoever wants to answer and understanding3054this is just a prediction, you know, when you think of our3055nearest adversary, how long before they are at quantum3056computing? I know that is a big question by the way, but who3057wants to guess?3058    Mr. Zervigon. That would be the $64,000 question.3059    Mr. Ogles. Right. But are we talking about 2 years or 123060years?3061    Mr. Zervigon. Well, I think the better analysis is whatever3062the number is, the data that you want to keep secret and you3063want to keep protected, is it outside of that? So if you think3064that a quantum or cryptographically-relevant quantum computer3065is 5 years out, then any information outside of the 5 we know3066is problematic. So we need to make sure that we're protected.3067It's not like Y2K with one moment in time where we need to3068worry about. It's that moment in time and then the predating of3069that information and protecting that information.3070    Mr. Ogles. Well, that is kind-of where I wanted to take3071this, is that when I think about, you know, just in general, we3072as individuals, Members of Congress, you know, kind-of device3073hygiene, the amount of information that is stored that if3074compromised, that is suddenly is unlocked or unleashed. My fear3075is currently, as has been stated, is there is a harvesting3076going on of information across sectors.3077    So, you know, financial services, that actually is what3078piqued my interest in AI was being on the Financial Services3079Committee and specifically the Subcommittee on National3080Security. I am thinking about all of the threats and how they3081are escalating and continuing to escalate when it comes to3082personal information, but also breaching of accounts where3083suddenly your voice, if it is out there somewhere, can be3084replicated, where, you know, IDs can be falsified, et cetera.3085    So, you know, if you want to speak to the amount of3086information and then what do we do with it? Like how do we--do3087we need to take this information off-line? Do we silo it? How3088do we clean up this mess, all these footprints and fingerprints3089that we have all left across that cyber landscape because it is3090being harvested, quite frankly, to be weaponized against us?3091    You want to start, Dr. Graham?3092    Mr. Graham. I think there are a number of very substantial3093opportunities that we have here. I'm, again, I'm extremely3094optimistic about using AI to help do this. Anthropic takes3095privacy and the sensitivity of data extremely seriously. I3096think we could probably unleash quite a lot of innovation here3097using AI to secure data infrastructure sensitive systems. I3098think this is going to be one of the important topics if we3099deploy this technology more and more into the economy to ensure3100that it's critical we get it to defend critical infrastructure3101without exposing it anymore.3102    Mr. Hansen. Yes. First of all, the reason we implemented3103the new encryption in Chrome was to start to get ahead of3104exactly the kind of question you're talking about. So there are3105some common utilities, whereas we at Google or other companies3106migrate, you get an architectural benefit for others.3107    But to the point on using AI, we have used, again, even3108before large language models, AI to help identify unused data,3109label data per certain sensitivities, and then you can3110implement policy that protects it. But I think, you know, he's3111correct. We'll have to use AI to get to the scale of the3112problem that you're describing. That means we'll also have to3113modernize, though, because we can't do that with the servers3114that are under desks and in, you know, sort-of second-class3115data centers that no one's modernized before. So that3116combination of modernization and using the tools, I do think we3117can scale to that problem.3118    Mr. Coates. I see two parts to the question you raise, one3119of which is how do we defend organizations against the rising3120orchestration of attacks that we've talked about some through3121AI? The second piece around how quantum changes things, and the3122biggest challenge with decrypting--the ability to decrypt3123traffic when quantum becomes relevant is the change that we3124need to do to be defensive here is a administrative and3125operational change.3126    We understand the systems that we have inside our3127organizations. We need to essentially upgrade them.3128Unfortunately, with the number of priorities we have for3129cybersecurity, it needs to become a top issue for organizations3130to say this needs to happen by this date, because otherwise,3131we're going to be really caught behind the eight ball where the3132data will be captured, it will be decrypted, and the time to do3133the upgrade will be so significant that we'll be in that risky3134position for a much longer period.3135    Mr. Ogles. Thank you. You know, Google's infrastructure,3136you mean, the amount of computing that you are supporting, from3137Government to private to health. I mean, just across the board,3138when you look at these kind-of constant attacks, so just had a3139hearing last week, Financial Services, on the Oversight3140Committee. We had, you know, everyone from Verizon to, you3141know, the credit card companies to, you know, across the board.3142Right? The social media platforms, the architecture platforms.3143We were talking about the threats that they are facing and the3144amount of investment that is being made and, quite frankly,3145leveraging.3146    So when it comes to credit cards, for example, it is where3147you have AI that is constantly watching transactions, looking3148for those patterns that otherwise are outside the norms. But3149what are those fail points when you look at that ecosystem from3150a Google perspective?3151    Mr. Hansen. Yes, it's a great point. I'll maybe just extend3152that a little bit and see if this is what you're asking about.3153But it is the controls that we care about in finance or health3154care or transportation are going to be different, the risks are3155different. So it's not just about the plumbing, let's call it,3156the technology, but in your credit card, the limits you set.3157Show me what--any transaction over $100 and you get that3158monitoring. You think about the kind of monitoring that occurs3159in health care.3160    I think the key is that this isn't just a technical3161problem. This is an industry problem. AI can help because AI3162understands the language. If you write a policy that says this3163heartbeat level is problematic under these conditions, the AI3164model is going to be better at monitoring that than a human. So3165that's where we need to go, is to use AI. This is my--I keep3166coming back to the cobbler's children. Let's not, you know, be,3167you know, shoeless in defending ourselves.3168    Mr. Ogles. Well, again, on the AI, you know, when I think3169about--when you look at Elon and some of the other companies3170that are doing the--any of the autonomous robots or humanoids,3171whatever you want to call them, and the ability to have a3172partner that now can watch a child who is ill or a spouse or an3173elderly parent that is--where they are wearing a ring or a3174bracelet, where they are constantly being monitored in real3175time, where you have a situation where they can dispense or3176disperse medicines and, again, immediately relaying back to the3177doctor, there is a huge upside to this. It is going to be3178transformative in a way that, again, I think is hard to fathom.3179    My concern is when we have these nation-states that are3180constantly seeking to exploit what otherwise could be used for3181tremendous good. So I do think when I think about China and3182their overt--I mean, at this point, they are not even hiding3183it. I mean, you know, I think they were testing. You know, the3184question or the point was made is, you know, I don't think we3185should ever underestimate our adversaries. This idea that, you3186know, they put it out there, it was detected, you know, they3187are watching to see how you detected it. How can they replicate3188or do it better the next time?3189    So we know it is coming, it is just a matter of time. You3190know, as we think about--and the investment, quite frankly,3191that they are making is that, I think, you know, from our3192perspective, we have to do a better job. You know, put up the3193guardrails, increase the transparency. But this flow of3194information is going to be critical. That is going to include3195some of our partners overseas. So from an industry perspective,3196how is that cross-collaboration going with some of our European3197partners or Israel or to the extent that you can disclose?3198    Mr. Graham. On topics of national security, Anthropic works3199with U.S. and democratic allies quite heavily for exactly this3200reason. One of the areas of collaboration that has helped the3201most has been in testing of model capabilities, so that3202everybody understands where we're at and what's coming down the3203pipeline. That is the key first step.3204    Additionally, there are probably international insights3205into, how we do secure our infrastructure and learn from each3206other? Broadly, we generally support this, and I think it's a3207testament to America's leadership that it has instigated that3208degree of international collaboration.3209    Mr. Hansen. It's a great point. Just my job's changed3210dramatically from the, you know, 20 years ago when I started. I3211was just thinking this year, I was in Tokyo, Singapore, Abu3212Dhabi, Tel Aviv, Sao Paulo, Warsaw, talking exactly about these3213kinds of issues and how do we raise the baseline for those3214citizens? So it's a big part of the job. We realize that.3215    Mr. Zervigon. For us, I think a large part of it is on the3216architecture, right? As we develop the architecture that allows3217different countries, different regions to employ the encryption3218that they want to employ, we certainly like to show leadership3219in that. We are with the work that NIST has done over the past3220decade. But at the end of the day, different countries,3221different regions are going to want to do what they want to do.3222So focusing on the architecture enables that.3223    Mr. Coates. In terms of information sharing I would point3224to the innovation pipeline. I was just in Tel Aviv last week at3225a major cybersecurity conference, speaking with start-ups and3226other innovators in the space. Tel Aviv in particular and3227Israel creates amazing technology that bridges to the United3228States as one of their main customer bases.3229    So as we look at where the next great ideas are coming3230from, they are being created inside the United States and3231they're being created with our allies. Working closely,3232especially with Israel, for cybersecurity is definitely to our3233advantage.3234    Mr. Ogles. Well, on that, when I think about the innovation3235and the innovation pipeline, you know, as we look at the NFI 7,3236kind-of 14 Eye groups, you know, I think one of where it is3237imperative that we are sharing information across kind-of3238countries and nation-states is this, you know, certain3239countries based off of where they are at and the type of3240threats they are exposed to get quite good at those types of3241attacks. So what South Korea is facing may be slightly3242different or a different perspective than Israel is facing3243versus Eastern Europe.3244    So one of the things that I have done is I have had the3245opportunity to travel in South and Central America and to3246Eastern Europe to talk about cybersecurity. What troubles me is3247in many of these countries, especially when you get into that3248second tier, is they are wholly unprepared.3249    I think, Mr. Zervigon, you mentioned that, you know, what3250we want to do is create a cyber environment where the world is,3251quite frankly, reliant on our architecture, our expertise. So3252the idea of the chips, there's some huge--you know, it is a3253pause moment to figure out what do we want to share versus3254where do we want to hold back. That is probably not a3255conversation that we can have in this setting.3256    But that being said is ultimately we want our global3257partners, whether in South America or Africa or Europe, Central3258America, to be dependent on us and trust us in this ever-3259evolving space. Because in my humble opinion, the threat to the3260West and the developing world is China. It is time we have that3261honest conversation. Quite frankly, your report really puts a3262fine point on the fact that this was an intentional attack to3263undermine the United States of America, to undermine the West3264and to, quite frankly, to try to achieve a technical advantage3265that they currently don't have as they seek to leap forward in3266their own development and their own technology.3267    So with that, and, you know, we are probably going to end a3268little soon, but what I would love to do is just go down the3269line, any thoughts that you might have. You know, sometimes you3270are in a room, you don't ask the right questions, so feel free3271to point out the right question. Then also, what is that thing?3272You know, what are next steps? Then what keeps you up at night?3273    Dr. Graham, you are at the top of the table, so we will3274just start with you, sir.3275    Mr. Graham. To me personally, as we watch these threats,3276and have for the past 2-plus years, we have seen the models go3277from zero to extremely useful and now used in the real world.3278This only happens because we monitor this threat in the first3279place.3280    But the most important thing in our team's view from now on3281is to take this moment here as the change point, is from now on3282that we will have a degree of scale that I think we've never3283had before and very possibly very soon, a degree of3284sophistication. I fear the day we wake up and models are doing3285things more complicated and sophisticated than the best humans3286on Earth are able to understand.3287    The only answer we think over the long term is to make sure3288that we're using models to keep up and outpace the attackers.3289We need to give the defenders a permanent advantage. We're3290going to work really hard to make sure our models can do that.3291We're going to work really hard to make sure that they're3292deployed. This is a cross-industry challenge. We have to work3293with Government on it. This is, we believe, the fundamental3294issue.3295    Mr. Ogles. Dr. Hansen.3296    Mr. Hansen. Yes, maybe just two things. One, I'm reminded3297that in 2009, Google was compromised by Chinese threat actors.3298This goes back over 15 years. It was our--it was a watershed3299moment at the company and we spoke openly about it. They had3300attacked 25 companies. It's really where the modern3301architecture for security was born. You hear about zero trust.3302This was the company redoing our infrastructure from the ground3303up to be up to the kind of attacks we now knew were possible.3304    To the point about AI, I think that's the next phase of3305this threshold is to put in hands of defenders the tools that3306will allow them to be successful in ways that we've, frankly,3307been--the numbers game doesn't work for us right now with all3308this legacy software. So now is the time to put those tools in3309the hands of defenders.3310    Mr. Zervigon. I would say also to accelerate the time lines3311and the budget as we talked about. I mean, 15 years ago, two-3312factor authentication, nobody had ever heard of it. Now it's3313everywhere. You can't buy concert tickets without two-factor3314authentication. Same thing is going to be the case with3315encryption.3316    I think under the Legislative branch as well as the3317Executive branch, continuing to lead on this and to kind-of3318push the envelope and set the table for innovative technologies3319and innovative companies to actually be able to start doing3320what they do best rather than waiting for legacy time lines to3321take hold, I think that's in everyone's best interest. It3322starts with the Government and then it'll move quickly to3323critical infrastructure or critical industries and then it'll3324move to everything, just like two-factor authentication did.3325    Mr. Coates. The country that leads in AI will lead in the3326world. This is the most important and innovative time in recent3327history. I believe that it is imperative that we align behind3328the challenges may be that data centers, be that energy, be3329that human resources, be that regulation, to create a3330transparent playing field in the United States where we can3331spur innovation forward. I think if we are caught up in any of3332the obstacles in pursuit of that, it will only give foreign3333adversaries the upper hand and then let them lead other3334countries to build on top of their technologies, which will be3335even harder to dig out from.3336    So the future is in front of us and leading in AI is the3337most important thing we can do.3338    Mr. Ogles. Absolutely. You know, I thank all the witnesses.3339Mr. Coates, to your point, you know, of there are a lot of3340subjects in Congress that we address that are kind-of very3341heated and at times partisan, but I would like to think this is3342the one that isn't. We have a lot to do, whether it is the3343sharing of information, whether it is better educating our3344allies overseas, preparing for that--the energy load that we3345know is coming, and just sheer innovation.3346    Like has been said, you know, we want to put up the3347guardrails to protect Americans and our allies. We also3348understand that our adversaries are not going to use3349guardrails. I would argue that they would quite--they, quite3350frankly, are willing to be reckless in achieving this goal,3351this endgame, which is AI and quantum. Because it does, it3352changes the world forever.3353    So I think this is the wake-up call. This is that moment in3354time that we will point to in this space. Did we heed the3355warning? Were we listening? Were we paying attention?3356    You have got our attention. My challenge to you would be to3357feel free to come to this body, come to me, come to the Ranking3358Member and have those honest conversations of we see a3359deficiency here and we need your help. Or this is a space where3360you are getting it wrong. Because if we don't have that3361communication and that trust, forget ideologies and politics3362and who you voted for, this is about national security. This is3363about your son. Right? Is not putting impediments and3364guardrails in the way that impedes that cure or whatever3365discovery is next. I truly--I can't imagine what the future3366looks like, but it's coming whether we prepare for it or not.3367    So I commend all of you for being here. Quite frankly, I3368would love to have the conversation with each of you about3369having a working group that is outside that reports back to3370this body. We can get bipartisan membership to participate in3371it, so to guarantee that we truly--is it one of the things to3372get platitudes, right? It is one thing, oh, we are going to3373share information, we are going to work with our allies. We are3374going to do the right thing for the right reasons. But if we3375are not having any conversations, it is all platitudes. I am3376not one to shy and beat around the bush. If we don't get this3377right, we are screwed. Right?3378    I think you said, Dr. Hansen, you know, the defender has to3379be right every time. Right? Your adversary only has to be right3380once. If we mess this up, it changes everything forever.3381    Any final thoughts?3382    Well, I, again, I thank you all. I am humbled that you3383would come before Congress. It is important that we have this3384conversation. I look forward to getting to know each of you3385better. I personally will reach out to each one of you3386individually, so that you know that you have access to Congress3387every single day of the week,338824/7. I will answer my phone.3389    With that, the committees stand adjourned. God bless you,3390sir, and your son.3391    [Whereupon, at 12:35 p.m., the subcommittees were3392adjourned.]33933394                            A P P E N D I X33953396                              ----------33973398      Question From Honorable James R. Walkinshaw for Logan Graham3399    Question. What are your recommendations to ensure that safety and3400security of artificial intelligence (AI) models scale and extend beyond3401how we think about model development in today's graphic processing unit3402era and into a far broader landscape brought about by quantum computing3403and quantum machine learning?3404    Answer. At Anthropic, our work on the Frontier Red Team is premised3405on the idea that safety and security measures must be built proactively3406and evaluated continuously. Three recommendations from my testimony are3407directly applicable to ensuring that foundation holds as compute3408architectures evolve.3409    First, codify and expand model testing capacity. The U.S. Center3410for AI Standards and Innovation (CAISI) has developed real expertise in3411evaluating frontier AI models for national security-relevant3412capabilities. Congress should permanently authorize CAISI and resource3413it to develop evaluation methodologies that can adapt to new3414capabilities over time. The voluntary agreement Anthropic has with3415CAISI provides a replicable model for how this can work in practice.3416    Second, strengthen threat intelligence sharing between frontier AI3417labs and the U.S. Government. The CCP-backed campaign we disclosed3418demonstrates that threat actors are already probing frontier AI models3419to leverage their capabilities for offensive cyber capabilities and3420other malicious use cases. As those models grow more capable, the3421imperative for robust, real-time intelligence sharing between3422Government and industry only increases. Congress should establish3423formal channels modeled on existing critical infrastructure3424information-sharing mechanisms.3425    Third, maintain and strengthen export controls on advanced compute.3426The strategic logic here extends to any hardware paradigm that could3427provide adversaries with the capacity to develop or run frontier AI3428systems. Ensuring that authoritarian nations cannot acquire the3429advanced compute needed to close the gap with U.S. frontier3430capabilities is the single most important structural safeguard we have.3431    The most important thing Congress can do to ensure AI safety and3432security scales into the future is to build the institutional3433infrastructure--testing capacity, intelligence sharing, and compute3434controls--that can keep pace with a rapidly-changing landscape.3435     Questions From Honorable James R. Walkinshaw for Royal Hansen3436    Question 1. How can digital transformation and transitioning to3437cloud computing support an organization's cybersecurity objectives?3438    Answer. Google keeps more people safe on-line than anyone else, and3439this scale has required us to deliver pioneering approaches to cloud-3440native security. As a result, Google Cloud defends its users' data3441against threats and fraudulent activity using the same infrastructure3442and security services it relies on for its own operations.3443    With respect to this infrastructure, Google Cloud provides a3444secure-by-design foundation--a model for risk management supported by3445products, services, frameworks, best practices, controls, and3446capabilities--that acts as an organization's security transformation3447partner. By building advanced security into every stage of our product3448development and cloud infrastructure, we enable organizations to3449modernize and strengthen their IT security while helping users protect3450their personal information and access the internet safely.3451    As referenced below, Google Cloud enables organizations to3452implement a zero-trust approach--where trust in users and resources is3453established via multiple mechanisms and verified on a continuous3454basis--to protect their workforce and workloads.3455    Question 2. How can the scale of cloud computing assist with3456mitigating cyber events?3457    Answer. Google Cloud's baseline security architecture adheres to3458Zero Trust principles--the idea that every network, device, person, and3459service is not trusted until it proves itself. It also relies on3460defense in depth, with multiple layers of controls and capabilities to3461protect against the impact of configuration errors and attacks.3462    Public clouds have the scale to implement levels of security and3463resilience that few organizations have previously constructed. At3464Google, we run a global network, and we build our own systems,3465networks, storage, and software stacks. We equip this network with a3466high level of default security; our Titan security chips assure a3467secure boot; we provide default data-in-transit and data-at-rest3468encryption; and we make available confidential computing nodes that3469encrypt data even while it is in use.3470    We prioritize security by design and have a team of security3471engineers who work continuously to deliver secure products and customer3472controls.. Our global public cloud enables Google to achieve3473unparalleled economies of scale, making security more efficient and3474cost effective for Google and its customers or users.3475    Question 3. How can cloud service providers contribute to the3476secure development of Artificial Intelligence?3477    Answer. Enterprises today face the critical challenge of delivering3478AI to production while ensuring accuracy, safety, and data security.3479Google's approach to generative AI prioritizes enterprise readiness3480with built-in mechanisms for robust data governance, privacy controls,3481IP indemnification, and responsible AI practices. We provide the tools3482and services necessary to secure AI and offer data sovereignty options,3483giving customers the confidence to deploy models at scale.3484    Google Cloud takes several steps to help organizations leverage the3485power of generative AI:3486   Conducting comprehensive reviews during AI product3487        development.--Google Cloud identifies and assesses potential3488        risks at both the model level and the point of their3489        integration into a product or service. Our approach considers3490        how AI will interact with the world and existing systems and3491        evaluates the potential impacts and risks that may be posed3492        both at the initial release and at points thereafter. Reviewers3493        understand that potential risks and impacts might be different3494        at the model level and at the application level and consider3495        mitigations accordingly. We draw from various sources,3496        including academic literature, external and internal expertise,3497        and our in-house ethics and safety research.3498   Privately releasing models.--The private release of models3499        allows our product teams to gather valuable feedback before we3500        make these models generally available. Once feedback is3501        incorporated, we update our product documentation to account3502        for any changes.3503     Question From Honorable James R. Walkinshaw for Eddy Zervigon3504    Question. Your company is supporting efforts to protect enterprise3505infrastructure against brute force quantum attacks on encryption that3506could cripple e-commerce, personal communication, and national3507security. Other than post-cryptography standards that the National3508Institute of Standards and Technology approved in 2024, what other3509assistance could the Federal Government provide to prioritize or raise3510awareness of dangers of quantum attacks on our commercial3511communications infrastructure?3512    Answer. As requested by the House Committee on Homeland Security,3513I'm responding to your letter dated February 12, 2026, asking for3514additional insights on what other assistance, beyond the adoption of3515post-quantum cryptography (``PQC'') standards, that the Federal3516Government can provide to prioritize or raise awareness of the dangers3517of quantum attacks on our commercial communications infrastructure.3518    As I testified at the joint hearing titled, ``The Quantum, AI, and3519Cloud Landscape: Examining Opportunities, Vulnerabilities, and the3520Future of Cybersecurity'' on Wednesday, December 17, 2025, the most3521important initiatives that this committee and Congress can undertake3522are to approve funding for PQC migration now and to accelerate the time3523lines for adoption on our most sensitive data networks. We cannot3524achieve innovative results on legacy time lines, and we can't afford to3525wait. Congress should work with Federal agencies to accelerate this3526migration through legislation and regulation.3527    Two additional areas of concern have surfaced during our work with3528Federal agencies to deploy PQC's. These are inter-vendor compatibility3529and crypto-agility.3530    As standards are adopted and agencies and enterprises begin to3531migrate to PQC, we need to ensure that proprietary vendor3532implementations of PQC's do not slow our ability to scale. This3533committee should provide guidance that mandates inter-operability3534between different vendor platforms in their implementation of PQC's.3535    Finally, our ability to change PQC's (either the algorithm or the3536implementation) needs to be as seamless as possible to prevent any3537delays in adoption of these changes when (because it's going to happen)3538an algorithm or implementation is broken. We need to be sure that any3539implementations can support future NIST PQC algorithms, irrespective of3540legacy technical limitations (such as key-size, packet size, or network3541quality, etc.).3542    We very much look forward to our continued work with the3543committee's staff and welcome any opportunities to offer our expertise3544around this issue. I thank you all for your leadership on this critical3545issue and your efforts to strengthen our Nation's security and expand3546economic prosperity.3547    Questions From Honorable James R. Walkinshaw for Michael Coates3548    Question 1. How do you foresee the economic development3549opportunities for advances in quantum computing and how it will shape3550the cybersecurity and AI markets?3551    Answer. Quantum computing represents both a significant economic3552opportunity and a moment of critical security transformation.3553    In the short term, the most immediate opportunities from quantum3554computing will not center on cybersecurity risk, but on its3555computational power to solve previously intractable problems. Quantum3556acceleration has the potential to impact logistics optimization,3557pharmaceutical discovery, advanced materials science, energy systems,3558and manufacturing. These advances could materially increase3559productivity across multiple sectors. Quantum techniques may also3560meaningfully enhance certain artificial intelligence workloads over3561time, further accelerating AI-driven innovation.3562    At the same time, quantum computing introduces structural3563implications for cybersecurity. Public-key cryptography underpins3564nearly every secure digital system, including financial transactions,3565identity infrastructure, cloud workloads, software updates, and3566government communications. The transition to post-quantum cryptography3567(PQC) is not a routine software update. It is a multi-year3568infrastructure migration affecting hardware, firmware, cryptographic3569protocols, certificate management systems, and embedded technologies.3570    This transition represents a substantial economic activity in its3571own right. It will require software modernization across both public3572and private systems, along with operational oversight, planning,3573validation, and testing. Organizations must inventory cryptographic3574assets, implement crypto-agility, update long-lived systems, and ensure3575interoperability. The scale of this effort will create significant3576market opportunities in cybersecurity, infrastructure management, and3577enterprise modernization.3578    In short, quantum computing will drive economic development through3579both innovation expansion and necessary security modernization. The3580organizations that succeed will be those that enable practical, secure3581transition rather than simply theoretical advancement.3582    Question 2. How can the Federal Government ensure that citizens3583broadly benefit from rapid advances in quantum computing, like they did3584with the advent of personal computing in the 1980's and the internet in3585the 1990's?3586    Answer. Broad economic benefit depends on open standards,3587distributed innovation, and trusted digital infrastructure.3588    First, the Federal Government should accelerate adoption of post-3589quantum cryptography within the public sector and use its procurement3590authority to drive timely migration across critical industries. Federal3591systems process sensitive citizen data and underpin national3592infrastructure. Leading by example reduces systemic risk. Clear time3593lines and enforcement mechanisms will also push the private sector to3594modernize more quickly. That acceleration is in the public's interest.3595Citizens depend on banks, health care providers, utilities, cloud3596platforms, and other businesses to safeguard their data and operations.3597A delayed transition increases collective vulnerability.3598    Second, policy makers should preserve an open innovation ecosystem.3599The economic success of the personal computing and internet revolutions3600stemmed from broad participation across start-ups, universities, and3601private industry. Encouraging domestic research commercialization and3602supporting start-up formation will help ensure quantum capability is3603not overly concentrated and that its economic benefits are widely3604distributed.3605    Third, work force development is essential. Migrating national3606infrastructure to quantum-safe systems will require engineers and3607security professionals trained in both legacy and next-generation3608cryptography. Without sufficient technical talent, modernization3609efforts stall and risk persists.3610    Finally, trust and privacy must remain central. Citizens only3611benefit from technological revolutions when they trust the systems that3612underpin commerce, communication, health care, and financial services.3613Strong, uncompromised encryption is foundational to that trust. History3614has demonstrated that deliberately weakening encryption--even with3615limited intent--introduces systemic vulnerabilities that adversaries3616can exploit. As the Nation transitions to quantum-resistant systems,3617preserving robust, trustworthy encryption protects individual privacy,3618economic stability, and national security.3619    Quantum's promise will be realized not merely through innovation,3620but through secure, timely, and broadly-deployed implementation that3621maintains public confidence in the digital ecosystem.36223623                                 [all]

Witnesses

4 witnesses appeared, with 12 papers on file.

NamePositionPapers
Mr. Eddy ZervigonChief Executive Officer, Quantum XchangeTestimony · Truth in Testimony · Biography
Mr. Royal HansenVice President, Safety, and Security Engineering, Google LLCBiography · Truth in Testimony · Testimony
Mr. Logan Graham, PhDDepartment Head, Frontier Red Team, Anthropic PBC
Mr. Michael CoatesFounding Partner, Seven Hill VenturesTruth in Testimony · Testimony · Biography

Documents

The committee filed 2 documents for the meeting.

DocumentKindFormat
Joint Hearing NoticeSupport DocumentPDF
Hearing: Witness ListHearing: Witness ListPDF