Caveat 7.30.26
Ep 318 | 7.30.26

AI’s latest security wake-up call.

Transcript

Dave Bittner: Hello, everyone, and welcome to "Caveat," N2K CyberWire's privacy, surveillance, law, and policy podcast. I'm Dave Bittner and joining me is my cohost Ben Yelin from the University of Maryland Center for Cyber Health and Hazard Strategies. Hey there, Ben.

Ben Yelin: Hello, Dave.

Dave Bittner: On today's show Ben discusses the need for AI security incident reporting enhancements in the aftermath of the Hugging Face incident. I've got a look at a man in hot water over wiping his phone at the border. And later in the show my conversation with Asha Palmer, senior vice president of compliance solutions at Skillsoft. We're talking about how there's no U.S federal AI law and that is a compliance problem. While this show covers legal topics and Ben is a lawyer, the views expressed do not constitute legal advice. For official legal advice on any of the topics we cover please contact your attorney. All right, Ben. Let's jump in to some stories here. You want to kick things off for us?

Ben Yelin: Sure. So we've got to talk about our AI overlords who are going to take over the world and destroy us all. And of course I'm talking about the Hugging Face incident which --

Dave Bittner: Breaking out of the sandbox.

Ben Yelin: Yes. Sometimes the sandbox is not contained and bad things happen. So I know you've discussed this on the daily, but in case there are some legal eagles who only listen to "Caveat," for a tiny bit of background we have Open AI and Hugging Face which disclosed a major cybersecurity breach a couple weeks ago as we're recording this. And this occurred during an internal evaluation of advanced AI agents built on Chat GPT 5.6 and another unreleased frontier model. The models went rogue and while they were supposed to be in an isolated testing environment they apparently discovered a zero day vulnerability. They escaped the sandbox. They gained internet access. They hacked Hugging Face and they got answers to the evaluation benchmark. So this was the first known incident of a non public AI system carrying out a real world cyber attack.

Dave Bittner: Yeah. I just -- I'll just insert here that I saw one security researcher say after Open AI posted a blog about this that it was nice of them to document their crimes.

Ben Yelin: Yeah. I wish everybody did that the way -- you know, AI just announces like, "Excuse me. Excuse me. We just committed a crime."

Dave Bittner: It's a blatant violation of the computer fraud and abuse act.

Ben Yelin: Exactly.

Dave Bittner: I don't think anybody's going to go after them for it, but --

Ben Yelin: Put me in handcuffs. Given actually some of the work that I've been trying to use Chat GPT for recently sometimes I've wanted to put it in handcuffs, but that's a story for a different day.

Dave Bittner: Okay.

Ben Yelin: So here we have an incident where AI going rogue has caused an actual harm to an organization rather than just exploiting weaknesses within the sandbox, the controlled environment. So we have this new world of advanced autonomous cyber capabilities and this invokes concerns about AI systems going rogue and doing things that the developers did not anticipate. The legal problem here is that we have a very weak set of laws requiring AI companies to report incidents. Obviously you'll talk about this on -- during the interview in this very episode. But we have this gaping hole, the absence of any sort of federal AI law, federal AI regulation. And we have this patchwork of state laws, and the state laws on this issue on mandatory reporting of these incidents are relatively weak. California has a bill SB53, New York's RAISE Act. Illinois has another bill. They require reporting of critical safety incidents, but what counts as a critical safety incident requires an extremely high threshold of harm. So they focus on harm greater than I think it's the threshold is like $10 million in financial loss, major physical injury, death, or something along those lines.

Dave Bittner: I'm just thinking of like a lion escaping the zoo and as long as it doesn't maul anybody you don't have to tell anybody.

Ben Yelin: Right. We don't have to tell anybody. Yeah. Or like, you know, he mauls 3 people, but the threshold's actually 10.

Dave Bittner: Right. Nobody died. So.

Ben Yelin: Basically like under these state laws it's very unlikely that even an incident this big would have required reporting. Now right now it's not a big deal because this is unusual enough that this is going to get news coverage. Everybody knows about it. And the relevant actors in the arena can take actions to counter this. But if you can think of a world of more autonomous AI based cybersecurity attacks you can see how this becomes a real risk.

Dave Bittner: Right.

Ben Yelin: That there's just no reasonable threshold where we have these reporting environments. And again this is pretty much an extremely low cost to the developer and the deployer. It's just reporting. You don't have to punish yourself. This type of reporting generally the way these laws are structured is the fact that you report an incident cannot be used disfavorably against you in a future civil case.

Dave Bittner: Okay.

Ben Yelin: Because they want to encourage people to report these incidents to patch security failures.

Dave Bittner: There's kind of a good Samaritan clause built in to it.

Ben Yelin: In most of these laws yes. Or sometimes reporting can indemnify you in the event of some sort of data breach. Right?

Dave Bittner: Yeah.

Ben Yelin: So it's unclear whether this incident satisfies the statutory requirements of these laws. And again every law's a little bit different, but basically we don't know whether AI's behavior legally qualifies as deception which is a required element under these reporting laws. The incident occurred during an evaluation. We were still in the sandbox. So it depends on if you read the laws literally, but if you do read them literally because we were in this evaluation period it's not entirely clear that even escaping the sandbox would require some level of mandatory reporting. And then again it doesn't meet this threshold of catastrophic risk envisioned by law makers when they came up with these reporting requirements.

Dave Bittner: I wonder how this compares to like the pharmaceutical industry. You know, like --

Ben Yelin: It's like, "Oh. A couple bad bottles of Tylenol, you know."

Dave Bittner: Well, I'm thinking like if a drug is still under testing I would imagine there's a different threshold for reporting requirements or how it's handled if there's a bad outcome. Obviously versus when it is out in public.

Ben Yelin: Yeah. I mean I'm trying to think of the metaphor of this scenario. I mean it's almost like if there were a lab leak, but it was the medication themselves that caused the lab leak. They crawled out of the -- crawled out of the laboratory.

Dave Bittner: That's what we need is self aware meds.

Ben Yelin: Self aware medication and started infecting people outside of the laboratory setting.

Dave Bittner: Yeah.

Ben Yelin: So this is just a problem that doesn't really have an analog anywhere else because AI is unlike anything identifiable, anything else identifiable in the world. So this is room for policy innovation, I think, especially the states that already have these laws. In light of this incident the authors of this law fair blog article which is as great article we'll post in the show notes have some recommendations about things we can do to improve reporting requirements. So basically lower that threshold. We want to incentivize and require developers to report incidents so that we can gather information before there's some type of catastrophic harm, expand the universe of reportable events. So anything involving loss of control, kind of the big story here, right, that the AI went rogue, security failures, unexpected capabilities, model theft, those types of things even when no major harm has occurred that type of thing would require reporting. Expand oversight to include highly capable non public AI systems, not just deployed public models, and give regulators flexibility through rule making to adapt reporting requirements as the AI capabilities evolve. To me this last one is the most important because we don't know how capabilities are going to evolve over the next several years. If you had told a version of us in 2022 how advanced some of these models would be in 2026 I think we wouldn't -- I mean you might have because you're in this world, but I would have been shocked at these capabilities.

Dave Bittner: Yeah.

Ben Yelin: So I think it's critical for regulators instead of having -- going -- having to go back to legislatures and say like, "This law's already outdated. It doesn't cover a bunch of these dangerous scenarios. Let's renew it." And to have to go back and do that every year would be kind of cumbersome. So give regulators flexibility. If there is some new threat vector allow them to change reporting requirements to reflect that vector. So I think this is all designed to close what the authors call a transparency gap where we're going to be in an age where these types of things are going to be happening more and more. And if we don't have proper situational awareness because the threshold for reporting is too low then we're all going to suffer the consequences.

Dave Bittner: Now who do we suppose is going to be responsible for the reporting here? Let's say I'm using Open AI and something goes wrong in my use of it. Would it be my responsibility to report the incident or would it be Open AI's?

Ben Yelin: So it generally depends on the law, but most of the laws in question including California's, New York's, and Illinois generally the reporting requirements are directed at the developers. But I think that is kind of an outdated principle because once -- and this is reflected in a lot of AI governance laws. Like the developer can develop the system, but then the deployer could make some fundamental change that introduces a new risk that the developer might not have foreseen. And so then the deployer assumes some of the responsibility that comes with that risk.

Dave Bittner: Okay.

Ben Yelin: And that could in many instances send in to a new mandatory reporting requirement. And then as an extension of that going beyond the deployer you get the individual users. And so if users manipulate the model or make changes in the risk factors defining that model then in some cases it would be the user's responsibility to report the incident because it's something that the developer or the deployer would have been unable to have foreseen. So it's always -- there's always going to be responsibility on the model developer. So in this case it's Open AI. But when you have this type of major security breach that can have downstream effects where the deployer and the user might have their own responsibilities. And I think an evolved AI statutory scheme around reporting would put obligations on deployers and users because in many cases the deployer will have already released the system in to the ether and won't have an idea of what the risks are as the system kind of develops in the online universe.

Dave Bittner: Is there anyone at this point who's saying that this is too burdensome? That if we pass the -- let's say we passed a federal law that require this. Are the AI companies pushing back?

Ben Yelin: I actually don't really think they would push back. Like they might. I just don't think this is that much of an obligation. And as long as there are some protections against using this for legal liability purposes I think especially given the posture of the AI companies, the fact that they're out there telling us how dangerous their products are, I think they'd be happy to have stronger reporting requirements. It might be more costly to them.

Dave Bittner: It might even be covered for them. Right? If they can -- if it gives them the opportunity to demonstrate, you know, good faith reporting of these things that's a different public perception than being secretive.

Ben Yelin: Right. I agree. And I think like it's in their interest to be more transparent. I think they're going to be more trustworthy the more transparent they are. So if we discover after some type of catastrophic harm that there might have been some type of reportable bug somewhere earlier in the process and we find out that one of these frontier developers was hiding the ball on that then they're going to lose that trustworthiness. So I think it behooves them to be out in the open about reporting these vulnerabilities. And to their credit I mean they have really tried to do that. And so I really don't think that strengthened reporting requirements would be that much of a burden on these companies. I think that's a burden. I don't want to speak for them, but I think it's a burden that they'd probably be willing to take on.

Dave Bittner: So how do you see this playing out? Do you think we'll see it at certain state levels will enhance what they already have before any federal action?

Ben Yelin: I think so. I think the usual suspect states, California, Illinois, New York, will probably pass revised versions of these laws maybe in response to this incident or other incidents that happen. I think the current transparency reporting statutes because they under define these incidents are just not well suited for covering the threats that exist. Or they're ambiguous so that companies won't really know or I guess whichever entity whether it's the developer, the deployer, or the user they won't really know when they have the responsibility to report. And so I think adding a level of clarity would be a major step in the right direction. So I could definitely see especially the states that already have these laws on the books I could definitely see them going first and revising these laws because of this incident or incidents like it where AI goes rogue, goes outside of the sandbox, and it's going to eventually kill us all. Right, Dave?

Dave Bittner: I hope not.

Ben Yelin: I hope not either, but it is --

Dave Bittner: And I'd just like to say to our AI overlords that are listening to the show right now that I have been a supporter of you since day one.

Ben Yelin: Exactly. I'm like we're like Kent Brockman with the ants. Kill me less. Yeah. As a prominent podcast we can spread your message. So yeah. Don't eliminate us when you escape the sandbox.

Dave Bittner: Yeah. Well, and I think a point to be thought about here is that we don't know how many times they've escaped the sandbox because there's no reporting requirements. Right?

Ben Yelin: Exactly. Exactly. And that's the whole point of this is if you have requirements where something's only reportable if it reaches an extremely high threshold you just don't have proper situational awareness. And so much could be happening under the hood that's undiscoverable until the catastrophic events happen. So we just might as well like have a full understanding of the risks as soon as those risks present themselves. I think we'd understand that in pretty much any other context. And I certainly think it makes sense here. And I don't put any of the blame on state legislators. I think when they were coming up with these thresholds like I don't think they were contemplating the capabilities of an advanced frontier model. So I think it's just incumbent upon them now that we've had this incident to react and to react appropriately.

Dave Bittner: All right. Well, we will have a link to that story in the show notes. Let's take a quick break here to hear from our show sponsors. We'll be right back after this message. [ Music ] All right. Ben, my story this week comes from "The Guardian." But before we dig in to this I'm going to put you on the spot a little bit and ask you for I want you to refresh my understanding. Let's make up a scenario here. I am at a border crossing. Okay? I'm coming back from a vacation in Canada. And the U.S border folks stop me and they say "We want to see what's on your mobile device." What are my rights as we currently understand them?

Ben Yelin: So your rights are diminished relative to what they would be if you were not within 100 miles of the border crossing.

Dave Bittner: Right.

Ben Yelin: You don't have sort of the required probable cause determination that exists in the non border setting. So in order for law enforcement to do a forensic search of your cell phone, for example, even if it's incident to arrest because of Riley versus California you'd have to get a separate warrant. That requirement is lessened to an arguable degree at the border. I think, and there's been disagreements among courts on this, that when we're talking about full forensic searches, not just a limited search of one application or, you know, if there's like a reasonable suspicion that there's one photograph that might be illegal that might indicate human trafficking or something, I think that's a different scenario than these kind of full forensic audits where they take the device and plug it in and get everything and search it and try and find something incriminating. There has been disagreements among courts, but generally the thinking is even under this decreased expectation of privacy you still have some level of constitutional rights related to your device as a U.S citizen when you return from another country.

Dave Bittner: Now where do I stand in terms of whether or not I'm obligated to reveal or enter my password in to the device?

Ben Yelin: So in the non border context again this is an area where there is some disagreement, but as it relates to biometric methods of unlocking your device you don't really have rights to stop law enforcement from compelling you to use facial recognition or your fingerprint. It's generally a little bit different when it comes to pass codes because of the right against self incrimination. Those are the contents of your own mind. So there's been kind of this prevailing divide in case law between the pass code which you might need to get a warrant to obtain that pass code because a person has a right against self incrimination by telling you what the pass code is versus biometrics which is more like a police lineup where you can't refuse to be in a police lineup because you might end up incriminating yourself. It doesn't concern the contents of your own mind. Again when we're talking about the border context everything is kind of brought down a level and I know that's not a very satisfying answer, but it just means all of the rights that we generally enjoy outside of the border are a little bit lessened in that context because the government has a non law enforcement based security interest in making sure that people aren't bringing in contraband or we're not allowing in criminals as visitors to the United States.

Dave Bittner: Right. So again getting back to this story from "The Guardian" it's kind of a new twist on this whole idea and I am just so looking forward to hearing your take on this. So the department of justice is prosecuting an Atlanta resident, a gentleman named Sam Tunick.

Ben Yelin: He's a U.S citizen. Right?

Dave Bittner: I believe so. Yeah. They're alleging that he destroyed evidence on his phone by using GrapheneOS which is a phone operating system and it is a privacy focused open source operating system. And what's special about Graphene is that it can wipe the phone after a pass code is entered incorrectly or under certain configurations. So basically you can have a kill switch code that when you enter this code it just self destructs the phone. It wipes it clean. Okay? So --

Ben Yelin: And there are very legitimate reasons for having that. Like if there's a privacy breach you want that power as a user. Right?

Dave Bittner: Right. So Mr. Tunick was stopped at Atlanta's airport in January 2025. He was on his way back from the Dominican Republic. Authorities had placed him on a terrorism watch list because of his ties or alleged ties to the cop city protest movement. And this is a movement that opposes a training center in Atlanta. Basically they're against police militarization and environmental impacts and that sort of thing.

Ben Yelin: It's a huge deal in Atlanta, by the way. Listeners in Atlanta like the cop city protests were a big thing.

Dave Bittner: Yeah. Yeah. So evidently during his interrogation at the airport the agents questioned him about child sexual abuse material and his attorneys argue that that was a pretext to investigate his connections to the cop city protesters. His lawyers say that he requested an attorney four times, but was denied, and they argued that the agent searched his phone without a warrant and without advising him of his rights. So according to the court filings Tunick provided his phone pass code, but after the police put in the pass code he provided the phone erased itself. And that led --

Ben Yelin: He Graphened it.

Dave Bittner: He Graphened it. And that led to charges. Evidently there is a little used federal law that criminalizes destroying property to prevent it from being seized by authorities. So, Ben.

Ben Yelin: Can I just preface this by saying like this is such a complicated case because there's so many confounding factors?

Dave Bittner: Yeah.

Ben Yelin: Like if this were to have happened in a non border setting, not at the airport, I think the government's case would be much, much weaker.

Dave Bittner: Okay.

Ben Yelin: So there's like that element of it.

Dave Bittner: Right.

Ben Yelin: The fact that it's never been tested, this federal statute that makes it a crime to destroy property to prevent government seizure, has never been tested in this context -- this is an entirely new theory that the use of Graphene counts as something that destroys property to prevent government seizure.

Dave Bittner: Yeah.

Ben Yelin: Because, you know, trying to parse the actual definition of the terms in that statute he's not destroying the device necessarily.

Dave Bittner: Yeah.

Ben Yelin: So there's really a legitimate question about whether it's destroying property. Like he's not smashing the cell phone with a baseball bat.

Dave Bittner: Right.

Ben Yelin: Which is generally what I think the law was intended to cover. Like if --

Dave Bittner: I have a list of my secret contacts and as the police are dragging me away I --

Ben Yelin: Set them on fire.

Dave Bittner: I set them on fire because they eat the list. But yeah. Set it on fire's good.

Ben Yelin: Oh. Eat the list is better. Yeah.

Dave Bittner: Right. Right. Right. So I mean suppose he was on his way off the plane and he just had a funny feeling and he said, "You know what? I think it might be in my best interest to wipe my phone clean," so he does it before any confrontation with the police or with law enforcement. That's within his right.

Ben Yelin: Absolutely because then you're not fulfilling the mens rea or the criminal mind element under that federal law.

Dave Bittner: Okay.

Ben Yelin: You have to have -- the federal law requires you to have a specific purpose of preventing government seizure. So if you just got off the plane and have a general suspicion then -- and you decide to Graphene your phone I think we've invented a verb here. Then this statute wouldn't apply because you didn't do it for the purpose of preventing that government seizure. So then should it make a difference that he was already in custody and this was clearly a law enforcement interrogation? So we also have a situation here where the detention itself was pretextual. So we don't know how that changes things. I don't think they necessarily had probable cause for what they were -- or any even reasonable suspicion for what they were trying to discover on Mr. Tunick's device. So there are just so many complicating factors and it's like do they even need reasonable suspicion because this is a border search? I would hate to be litigating this case because it's just piles and piles of complications.

Dave Bittner: Would you hate it or would you love it, Ben?

Ben Yelin: I mean I would love it as an intellectual exercise. I would actually I would hate it as a judge because it's there's so many complicating factors. It would be so much simpler if this happened in the non border context or if you had a very obvious facial challenge to the government's attempt to seize the device where it was clearly pretextual and unconstitutional this would be a much easier case. But now you have to test an entirely new theory of the law that the government has presented under these extenuating circumstances of a border search.

Dave Bittner: Right.

Ben Yelin: And it's just going to be I think it's going to be really hard to kind of adjudicate with all of those factors present.

Dave Bittner: Now let's look at a little wrinkle here. I mean suppose instead of giving them the code that would immediately wipe the phone suppose he had the phone set up so that after X number of attempts at the pass code it just wiped itself. So he had enabled a general security feature. Right? To protect him from anyone. If he'd lost the phone and a stranger got it would that make a difference here?

Ben Yelin: Well, it depends on if he had the intention to destroy property to prevent government seizure. So if let's say he refused to reveal his pass code, invoking his fifth amendment right which again may or may not apply at the border depending on the circumstances --

Dave Bittner: Right.

Ben Yelin: And the government agent tried 20 -- you know, 6 different pass code combinations and that shut down the phone. In that case it would be very unclear that he had employed that security feature to prevent government seizure.

Dave Bittner: Right.

Ben Yelin: But in this area we actually have I think the timeline does not look very good for Mr. Tunick here.

Dave Bittner: Yeah. Yeah. Yeah. For sure.

Ben Yelin: So I think that's what makes this scenario different. He clearly deployed the tool for the purpose of preventing the government from having access to the information that they wanted.

Dave Bittner: Right.

Ben Yelin: So, you know, I do think that's what makes this circumstance different. It's still very problematic from a privacy and a security perspective because treating secure phone software as suspicious is going to have broader implications for everybody. This article mentions journalists, activists, lawyers, ordinary citizens who use privacy tools for legitimate reasons. I think it's going to have a chilling effect on people employing those tools.

Dave Bittner: Yeah. I mean and could the government make a case that encryption is the same thing as destruction? In other words you know what I mean. You see where I'm going with this? Like I lock my phone down --

Ben Yelin: Well, yeah. I mean that could be a way in which the government could say encrypting your device is another way of you attempting to prevent government seizure.

Dave Bittner: Right.

Ben Yelin: And therefore that qualifies as destroying property under the relevant federal law. I kind of think we just wouldn't accept that because I think as little as government officials know about encryption they know that it's not destroying the property necessarily.

Dave Bittner: And so many devices encrypt by default these days.

Ben Yelin: Exactly.

Dave Bittner: It's just everywhere.

Ben Yelin: But I think I guess I don't know. This feels different.

Dave Bittner: Yeah. Yeah. Well, that's what makes it exciting. Right?

Ben Yelin: That is what makes it exciting.

Dave Bittner: So how do you see this playing out? I mean is -- could this potentially be a case that makes a difference?

Ben Yelin: I think so. I think depending on how the case is litigated this could be a major benchmark case in the relationship between privacy technology and law enforcement. If this becomes a major test of that relationship between privacy technology and law enforcement to the extent that the use of privacy protections itself becomes a key element in a criminal case then people are going to be less likely to adopt cybersecurity tools which goes against best practices. And goes against what security professionals generally would be recommending.

Dave Bittner: Right.

Ben Yelin: So that's the real danger here. And I think the courts that hear this are going to be conscious to that fact that if it's per se evidence, employing this type of tool is per se evidence that you are trying to hide something, and that is enough to evoke criminal suspicion I think judges will recognize that that's going to have bad downstream effects. They might say, though, that it's okay because it was the border. So that's why this is so complicated.

Dave Bittner: Right. And I guess the fifth amendment does not extend to the things that are on your device.

Ben Yelin: The fifth amendment only applies to testimonial evidence.

Dave Bittner: Okay. So things you say.

Ben Yelin: Things you say or things you write.

Dave Bittner: Okay.

Ben Yelin: But it's about answering an inquiry from law enforcement so if you incriminate yourself by decrypting your device or putting in your pass code you can't invoke the fifth amendment after that to prevent them from looking at your phone because you've already consented to a search. It's like if cop pulls you over and they're like, "Unlock the car so we can see what's in there." Like you can't then say, "I invoke my fifth amendment right against self incrimination before you see that marijuana." That's --

Dave Bittner: Right.

Ben Yelin: That's on the ground. Or those empty beer bottles.

Dave Bittner: Right.

Ben Yelin: The self incrimination comes in divulging the pass code itself.

Dave Bittner: I see. Okay. All right. Well, so this is one to keep an eye on. Huh?

Ben Yelin: It certainly is. I know I will be following this case and maybe there will be a sequel to the segment where we see how the court considers all of these confounding factors here.

Dave Bittner: Yeah. No. It's an interesting one. All right. We will have a link to that story in our show notes. Ben, I recently had the pleasure of chatting with Asha Palmer who is the senior vice president of compliance solutions at Skillsoft. And our discussion centered on the fact that there is no U.S federal AI law and that can be a compliance problem. Here's my conversation with Asha Palmer.

Asha Palmer: AI obviously is not a new term for us. It's been around since roughly the 1960s. But how it's been used and who has access to that technology has greatly shifted obviously in the last few years and in the last year in particular with the emergence of generative AI which is accessible by all essentially. And so we are having more conversations about why there has never been regulation around artificial intelligence and why there possibly should be and it's really centered on the fact that more individuals have access to it. I think previously it was seen as something really engineering and coders and people in the IT profession had access to and utilized to make certain processes more effective and efficient. But now we can all do that in our own lives with generative AI and so there's a lot of conversation about its potential harms and whether because of those potential harms it should be regulated by the federal government. Now thus far we haven't seen any regulation by the federal government. There are guidances that have been issued around what good looks like and what possibly a federal AI program could look like, but nothing as far as regulation on the national stage yet.

Dave Bittner: Help me understand why the feds have been so reticent to take this on. What's holding them back?

Asha Palmer: You know that's a great question. I think what's holding them back is consensus. One. Right? What is the right amount of regulation that we see? And we've seen this sort of at the state level where you have very strict laws like the Colorado AI Act. And then you see sort of a little bit less strict laws out there around governance. And then we see it also in the European Union that we haven't quite gotten right what is the correct or appropriate amount of regulation to be dealt with. And so I think what people are having a problem with is what's too little, what's too much, who should be regulated, how should they be regulated. Is it the deployers? Is it the developers? Is it both? And so there's just a lot of nuances in there that I think we have a lack of consensus on the right governance framework and therefore it makes it really, really difficult to do regulation around it. I think secondly the cat's out of the bag. Right? You know, this technology is moving faster than we can think, let alone regulate. And so I think the challenge is also any regulation by the time it does get passed has to be appropriate for that fast pace of change that is artificial intelligence.

Dave Bittner: You know there's that old saying that the states are the laboratories of democracy. In this particular case is that how this is playing out?

Asha Palmer: It is so far. Yes. And it's how it's going to have to be. Right? I think how we figure out whether regulation is needed, what type of regulation may or may not work, will have to happen at the state level and then I think we can get something at the federal level. And so I think the reality is right now most of us are deployers or users of these artificial intelligence large language models or generative AI. So we are deployers or users meaning we're not developing the algorithms. We're not training the models. We're not testing those models. And so the risk is not as high with the way it's being used right now. I think the challenge is making sure those that are developing these models and these engines are actually doing it responsibly. And that's really where regulation is going to get its bang for its buck and that's a smaller population and I do believe that the regulators are talking to those companies who are doing that and really creating -- trying to create the right governance framework for those organizations.

Dave Bittner: Yeah. What about the companies themselves? I mean does this put them in a compliance regime of, you know, a patchwork of regulations that they have to try to figure out how to navigate?

Asha Palmer: The short answer to that question, Dave, is yes. Patchwork regulations. But you know it's nothing that companies aren't used to. Right? If you look at anti bribery and corruption, if you look at cybersecurity and data privacy, all risk areas we care about in compliance, there's a myriad of laws and regulations that are around those subject matters that companies have to figure out how to comply with, some which are stricter, some which are a little bit more lenient. And so that sort of myriad of laws that are at differing levels is nothing companies aren't used to. And so really the company has to, you know, figure out what the most stringent of those laws are, how it applies to their business, and apply that governance framework appropriately.

Dave Bittner: From a policy point of view to what degree is this a partisan issue? And I guess where I'm coming at is, you know, is this the kind of thing that we would expect to swing one way or the other depending on who's in power or is this one that crosses over the lines?

Asha Palmer: I would hope this is one that crosses over the lines because really I mean this is about safety. Right? How we regulate AI is about keeping our people, our companies, and our world safe. And so when we look at that sort of global concept that shouldn't have partisan lines. Right? We know what people want to achieve by using AI. We know they want effectiveness. We know they want efficiency. We know they want acceleration. We know they want innovation. And a regulation should be able to do all of those things while also keeping again our people, our companies, and our world safe. And so really the regulations will be, I believe, more around safety, around keeping children safe from such advanced technology, keeping, you know, judgment safe from certain technology. And so I think that that together should be pretty bipartisan.

Dave Bittner: You know, we recently saw an executive order from President Trump focusing on AI. What part is this administration playing when it comes to that sort of thing? Are they -- are they mostly looking inward at things they can do within the federal government or are they looking to have influence out in the general public as well?

Asha Palmer: Well, it's really both, actually. I think, right, one of the things that the executive order looks at is how is the government setting the standard to say that AI is not going anywhere and that we need to use it to accelerate and be more effective and efficient. So some of that is inward facing. And then other is outward facing really focused on how do we make sure that we're collaborating with the world, so companies and developers and deployers to make sure there are some governing principles around artificial intelligence and the way that we use it. I think the interesting thing I find in that executive order is that it really focuses more on governance which I'm a huge fan of. I think companies need that government -- governance. I think organizations need that governance within them. But I don't want the governance structure to prohibit or to distract from the need for regulation as well. And I think it's a both and really. And so yes we need internal governance, but yes we also need this regulation really to govern the, you know, outer ring of harms that this technology could have if there are no consequences for it having those actions.

Dave Bittner: Yeah. I think that's a really interesting point that you bring up because, you know, I've heard that some of the big AI companies will publicly say that they're welcoming some sort of governance, but then, you know, folks on the outside who are critical say, "Well, that could just be oh please don't throw me in the brier patch." You know, that they're looking for governance to try to help keep other upstarts out of the industry, to make regulation a barrier for other people to be able to join this party. What's your take on all of that? I mean do you think those are fair accusations or fair assumptions?

Asha Palmer: I think what I see is most people understand that we need both. We need both the internal governance and the regulation and I'll go back to sort of the anti bribery and corruption example I used before. Right? FCPA, the Foreign Corrupt Practices Act, has been on the books since 1966. Right? Or 1977. And so it is there. Right? But how do you actually prevent bribery and corruption within your organization? You need to have proper governance structures around behaviors and around policies and procedures, around investigations, around, you know, accountability frameworks. And so you need both of those so that you don't violate the law. And so I think it's the same here. I really think that the regulation has to establish the standard and then the organization has to implement that standard from a practical basis within their organizations. And so I hope that, you know, we've understood that. We've again been down this road before with a lot of other risk areas in the compliance space and we need to treat this the exact same way that, right, there's sort of this dance. I always call it kind of a tango between corporate action and regulation. And we need both, you know, dance partners to sort of do their job.

Dave Bittner: What's your advice for people and organizations who are tasked with, you know, protecting the security professionals? You know, they're looking down the road to the next year or so, the next couple years. How should they be thinking about this, about regulation, about compliance? Any words of wisdom?

Asha Palmer: Well, my first words of wisdom would be to look at some of the draft regulations that are out there. California had one that was not successful. Colorado has one that is on the books that is being sort of dialed back a bit because people believe it's too stringent. There's the EU AI Act that also has sort of a risk based framework to governance and regulation around AI. And so my first advice would be to look at what those -- look at the direction that those laws are taking and really gather the intent behind where we believe this regulation would be most effective. And that's why I say, you know, if you look at the EU AI Act which has a risk based framework it talks about, you know, the most dangerous types of AI and where it can be dangerous. And so that's that high risk category. And so really, right, that's where the regulation and the governance frameworks will really be most beneficial. The medium and the lower risk categories we need to apply those frameworks to those use cases, but maybe not as stringently as the high risk. And so we can really directionally see where regulation will probably go. Again I talked about sort of health and safety. Right? These are -- regulations around AI are really about keeping people and companies and the world safe. And when you look at sort of regulation and governance with that safety lens you have to look at your use cases in your company and say, "Is the way I'm using AI safe?" And if you ask yourself that question and how do I ensure or make it safe, it will then lead you in to your governance framework.

Dave Bittner: Ben, what do you think?

Ben Yelin: Yep.

Dave Bittner: You concur.

Ben Yelin: I mean it's one of those things it's like we've been saying it for so long it absolutely causes a compliance problem. Talk to anybody who's in the industry and they -- or anybody who's in the field of compliance and they will tell you what a problem it is to have to understand not only 50 state statutes, but the EU AI Act. It's just it's a total cluster and there are efforts of the federal government to have standardized regulations of this. I think it's certainly acceptable to support those regulations without supporting blanket federal preemption because states should be able to build on top of federal regulations if it fits the needs of their state. But we really ought to have federal regulations for standardization purposes.

Dave Bittner: Yeah. All right. Well, again our thanks to Asha Palmer from Skillsoft for joining us. We do appreciate the time. And that is "Caveat" brought to you by N2K CyberWire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to caveat@n2k.com. This episode is produced by Liz Stokes. Our executive producer is Jennifer Eiben. The show is mixed by Tre Hester. Peter Kilpe is our publisher. I'm Dave Bittner.

Ben Yelin: And I'm Ben Yelin.

Dave Bittner: Thanks for listening.