jessica-ji.png
Cyber Resilience
Risk Management
Operational Resilience

Nexus Podcast: Jessica Ji on Frontier AI Models and Cybersecurity

Michael Mimoso
/
Jul 30, 2026

Subscribe and listen to the Nexus podcast on your favorite platform.

U.S. policymakers have their hands full with artificial intelligence (AI), its proliferation into business, and implications for everyday life. Any impactful decisions are made on slow legislative timelines, and run the risk of being outdated given the speed at which AI is implemented and outcomes are assessed. 

Jessica Ji, Senior Research Analyst at Georgetown’s Center for Security and Emerging Technology (CSET) and CSET’s CyberAI Project, is immersed in this world. She and her colleagues help legislators understand the rapid convergence of AI and cybersecurity, and the evolving struggle to understand how large frontier models and agentic frameworks allow AI systems to autonomously execute broader segments of the cyber kill chain at unprecedented speed and scale. 

On the latest episode of the Nexus Podcast, Ji emphasizes that policymakers and staff are much better informed about AI, yet rapid developments in this space sometimes overshadow how impactful it would be on cybersecurity. 

“I don't think anyone could have predicted how quickly AI developments would change and how immediately salient they would become for cybersecurity,” she said. “They're constantly being inundated with information. I'm very sympathetic to why there might be deadlock or struggle, and I also understand that things move slowly in the government.”

Hugging Face Incident a Wake-Up Call

The pace of cybersecurity activity related to AI frontier models has been overwhelming. The release of Claude Mythos and Project Glasswing forced the industry to reassess vulnerability and exposure management. The model’s ability to rapidly discover and develop proof-of-concept exploits turned traditional vulnerability management on its head, and has already created a flood of new disclosures that must be triaged and prioritized. 

Meanwhile, numerous incidents have been made public. The latest being the news that OpenAI’s latest pre-release model escaped a sandbox environment where its exploit capabilities were being tested. The model found zero-day vulnerabilities and compromised an external target at Hugging Face in search of a solution to the test it was administered. 

“I think it represents a few kinds of hypothetical worst-case scenarios, but all in all, I think as a wake-up call, it could have been worse in terms of the target and the impacts of the attack itself,” Ji said. “I think it opened up the conversation and really woke a lot of people up.”

Policy Advice Around AI-Powered Cybersecurity

On the legislative front, Ji comments that the government’s implementation of export controls on frontier models are unsustainable and that the government should instead focus on long-term defensive strategies, infrastructure, and planning. She also provides her perspective on the competing incentives between private AI companies and the government, and whether competitive pressures will continue to produce these highly capable models without oversight. Finally, traditional threat modeling has also been upended because of AI, and policymakers and defenders inside critical infrastructure companies must account for autonomous activity from these models. 

Episode Transcript with Jessica Ji

Mike Mimoso 0:16

Jessica Ji is my guest today. Jessica is a senior research analyst at Georgetown Center for Security and Emerging Technology. And that's a place where she is working on the Cyber AI project. This is going to be a really timely discussion given all the uproar going on around AI and cyber right now. So I'm uh very happy that Jessica is here to bring her expertise to the discussion. Uh before we start, just my usual reminder that if you're not subscribed to the podcast, please do so. Uh, it's really the best way to keep up with the great guests that I've got coming up. And just to let you know behind the curtain a little bit with Black Hat next week, I will be in Vegas recording a bunch of episodes that you'll hear uh spread out over the coming weeks. So subscribe now if you haven't. We're on Apple, Spotify, Amazon, everywhere that you may listen to podcasts. So let's get today's episode started. Bring in Jessica. How are you doing? Good to see you.

Jessica Ji 1:11

Morning. Morning. Thanks for having me.

Mike Mimoso 1:13

Of course, nice to meet you. Um, so let's just start out with a little bit about you. Tell me a little bit about your role, the cyber AI project, your background. I always find that people don't have like a direct path to cybersecurity, so I find it interesting asking this question.

Jessica Ji 1:27

Sure. Yeah, I think my background may be a little different from some other guests you've had on the podcast.

Mike Mimoso 1:32

Yeah.

Jessica Ji 1:32

Um, yeah, so I'm a, like Mike said, at the upfront, I'm a senior research analyst um at CSET or the Center for Security Emerging Technology at Georgetown. So we are a policy think tank. Um, so we're based at Georgetown, but we're independently funded. So we're basically a research organization that writes for policymakers. So the kind of founding mission of CSET is to improve policymakers' decision making around emerging technologies. And that has always been AI for us. Like AI has been kind of the core technology that we focus on since we were founded in 2019, which is also like not that long ago. So we're we're a pretty new organization. Um so our primary audience is US policymakers in the executive and legislative branches of the federal government. Um, but we also regularly talk to decision makers in the private sector, um, increasingly kind of at the state level in the US, um, international governments, US partners and allies, and other organizations like NGOs. Um, my team at CSET is the Cyber AI project. So we were founded like when CSET was founded, and the idea was that like as AI technologies became more powerful, um, the cybersecurity and AI intersection would be increasingly consequential. Um so back in 2019 and like early 2020, when the like team and the organization was just getting off the ground, um, they were putting out pretty early work about how machine learning capabilities might affect cybersecurity. And this was before kind of like commercial LLMs were available. So it was, you know, thinking about like classification systems for cybersecurity, cyber defense, things like that. Um so I think the the work of the team has evolved over time as the landscape has changed. But it has been, you know, a very kind of like eventful past few years. Yeah. Um, especially as I I don't think anyone could have predicted how quickly AI developments would change and how basic how like immediately salient they would become for cybersecurity.

Mike Mimoso 3:27

Yeah, the speed has been really remarkable, especially the last six months. It's like where do you focus? Where do you look? Yeah, for sure. Um I I'm very happy to hear that you're writing for or how trying to help policymakers because I'm just speaking from my experience, those folks need a lot of help and with just cybersecurity uh in general, but I'm sure this is an extremely complicated topic that needs to be a lot of different things.

Jessica Ji 3:51

Yeah, it's really complicated. I um definitely I think you know have a very specific kind of point of view here, and I think each of us, you know, brings a different perspective. And I like I think policymakers have to deal with all of these different stakeholders. They're constantly being inundated with information. Um so yeah, I don't, I I think it's you know, I'm very sympathetic to to why there might be deadlock or struggle, and I also understand like things move slowly in the government. Um so yeah, very, very sympathetic to kind of like what they're facing.

Mike Mimoso 4:23

So let's just jump into the discussion. And obviously, I think the the big topic so far this year has been the frontier models, uh quad mythos, and especially around vulnerability discovery and exploitation, and just kind of that whole shrinking of time between discovery and exploitation and how it's just kind of changed the whole dynamic of protecting systems or I'm just curious as you interact with folks, do you still get the perception that people think of these models as maybe exclusively offensive? Do they understand that there's defensive applications as well there? Kind of bring me inside what you're hearing and and just your reaction to mythos when it all happened.

Jessica Ji 5:04

Yeah, I think there's a mix. So I I generally think that I find that policymakers are much more informed than they were about like, you know, AI's applications, its dual use nature uh for offense and defense. They're pretty they're more informed than they were like a few years ago. Where a lot of it was kind of like basic education, kind of like offering conceptual framings for thinking about how AI might impact cybersecurity. But now I think, you know, the threat is here, the threat has been here and like evolving over the past couple years. So I think people are generally more well informed. So you don't really have to start from zero at this point. Um, yeah, so I think I think users understand, users, policymakers, various stakeholders understand that models have defensive applications. Um, I also think generally, I believe there's like an acknowledgement that they're not really a magic bullet for defense in the same way that they might be for offense. Um, because yeah, defense is hard. Um so I think from a in terms of like baseline understanding, I think we're there. I think a lot when it comes to mythos specifically, um, I do think a lot of this came from the way that anthropic specifically was communicating about mythos to government stakeholders. Um, like they were kind of proactive about being like, hey, we have this model, it's very powerful. Like here are like here are how here's how we think about offensive and defensive applications of our model. Um and in some cases, I think of this as like a strategic decision that they made, um, both in terms like maybe of, you know, we're gonna warn the government, this is probably going to be good for the public if the government is aware that this model is coming. Um, but it also is good for anthropic as a company. Um because, you know, it they were, they had, I think, a tenuous relationship with the federal government up until that point. So it was, it was a way, I kind of read it as a way of like, you know, re-establishing goodwill, extending a hand to the government, being like, we're going to offer you information and insight into the into this model that's coming, let you plan strategically. Um, but also it positions them as it does position them as a leader. You know, it's like we have this very powerful model. Um, we're we're going to try to lead in this way. The model is coming. Um, we're gonna try to create a model for like what partnerships will look like.

Mike Mimoso 7:20

Do you think that the offensive capabilities of these models right now are at least their understand uh people's understanding of them? Are they far out ahead of defensive applications? Um I mean, there's a obviously a lot of noise about how quickly you can develop exploits for this, and you know, it it needs to kind of be turned into defense at some point. So I'm just curious what you think about that.

Jessica Ji 7:44

Yeah, I will leave the details up to the offensive security researchers because I'm sure they have much more insight into exactly how quickly um, you know, you can you can use the model to to find a zero day or like develop an exploit. Um but like conceptually, I think of it as like a speed and scale issue. I think like using the cyber kill chain model, I think more advanced LLMs plus like improved agentic capabilities mean that AI systems are now more capable of autonomously performing more steps of the kill chain than they were six months or one year ago. Um I think you know, it was like last year at this point we would have been talking about like, okay, they're still like, you know, at the beginning of the kill chain, you you probably still need a human, like quite intense human intervention to kind of like guide a system or oversee an agent doing like you know, end-to-end exploitation. Um so I think the like capability improvements and like agentic capability growth improvement in harnesses, like ability for the models to be more persistent over time has really helped on the like offensive side in particular. But on the defensive side, I think the balance is a little more delicate. I think um like defense comes with other considerations. You can't just plug a model into a box, um, plug a model into a network, like out of the box, um, and expect it to defend the network autonomously because you can't break other things, you you know, you need to strike the balance, you have other systems in place. Um so I think the model the models in particular excel at certain tasks, like vulnerability discovery, which has which has like dual-use applications, but I think a lot of defensive processes have to move at a slower pace. So I think the the like ability to scale, um, and then also the the like speed at which you can use um these models for defensive applications um makes it more difficult. It like tilts the balance somewhat in favor of the offense right now.

Mike Mimoso 9:37

Does that mean that we need some evangelizing about the defensive capabilities or some just overall education in terms of you know how to use some of these models and these capabilities for defense?

Jessica Ji 9:49

Yeah, I think we're also starting, we we're in a somewhat more difficult starting place, I think. Um because I think it is easier to adapt these models. Basic, basically, when I think of like, you know, threat threat actors who are acting offensively, it's like you know, APTs, hacker groups, they can adapt very quickly to new technologies. Whereas for for defense, um like from what I've heard from some of the folks at the AI companies who are running things like Project Glasswing or OpenAI's, like Patch the Planet initiative, these like partnerships to try to improve defense. They're basically starting at like A, it's like who do we talk to? So we're reaching out to like sector risk management organizations, for example, but like trying to figure out the organizational structure is the first step. And then B, they're um from what I've heard, it's like, oh, the first step is to do seminars to be like, they have to start with the basics. It's like what can AI do in this space for you? Like before we even get to actually, you know, trying to incorporate the technology, we have to, we have to like raise the level of understanding. Um, so I think there we're definitely gonna see some lag in terms of um adapting the technologies for defensive applications. And I think because defense is also very contextual, um, so it's not really a plug-and-play scenario at all.

Mike Mimoso 11:00

Right. And then we have the hugging face attack in night. The news never stops coming. No, no, this is definitely still timely, still fresh. But I mean, is this kind of the nightmare scenario for AI-powered cyber attacks? Just escape from the lab, so to speak, especially from what was supposed to be a test environment.

Jessica Ji 11:20

Yeah, I think it's really interesting. I think it represents a few kind of like hypothetical worst-case scenarios, but all in all, I think as a wake-up call, it could have been worse in terms of you know the target and the impacts of the attack itself. So yeah, I think uh I think like a double-edged sword. I think it opened up the conversation and really like woke a lot of people up. If they weren't already awake, I don't know, after after June in the mythos moment. Um yeah, but I think I do think it was really significant. Um, because I, like I said, it was the convergence of a few different scenarios that have been hypothesized previously as worst-case scenario. So the first was definitely the escaping the test environment scenario. So I think previously, um, when labs were doing evaluations of AI models, they were they were like coming up with scenarios where that would basically like they would like give the model instructions to escape a test scenario to see if it was capable of that. Um, but I think in this case, the fact that the model was not given instructions to do that um is pretty significant. It was like, I don't want to use like overuse anthropomorphizing language here, but it was kind of like thinking of ways to escape this scenario and it like identified in its chain of thought that it's like if I want to achieve this objective, the first thing I need to do is escape this sandbox that I'm in. Um and then second, I think is the the reward hacking behavior. So the fact that it was not under instructions to hack an external target at all. Right. Um it was trying to, it was trying to solve like a like a benchmark problem um in Exploit Gym, which was the benchmark suite that OpenAI was using to test it. Um so I think the, you know, we've talked about reward hacking and AI security, AI safety and security for a long time. Uh there's kind of an iconic example from OpenAI back in like 2018, 2019, where they had like a reinforcement learning system that was trying to like get points in a game, but it realized that if you just like went in a circle in one specific point in the game, you could like accumulate the points without actually like doing doing like the race course that was the actual game. So I think uh honestly is like very similar behavior happened here where it was like um it's like uh like a student taking an exam, um, is the analogy that we've been using in in in like CSAT conversations. So it's like open AI is the teacher, they're administering the exam, they lock the student in the classroom and go home for the weekend, I guess. Right. Um and then it's like the student gets to a difficult problem, which in this case is this the specific question that it was tasked with responding to an exploit gym. And then they decide that the best way, like instead of actually trying to solve the problem, is to break out of the classroom, then break into a second location and try to find the answer key. Um so it's like, oh, the reason the model targeted Hugging Face was that like through a chain of reasoning, it's it was like, oh, I think that the answer key to exploit gym the exploit gym benchmark is probably somewhere in Hugging Face's files. Um so I think this, yeah, the the kind of like reasoning over time, the like the misalignment or the reward hacking behavior, um, and the I think the length of time, I think the timeline is still a little uncertain. Um I would say only like Hugging Face and OpenAI know exactly like this the series of events that occurred. Um, but based on the public reporting, it sounds like it took quite a while for the A, the model to be detected, and B for OpenAI to realize on their end that something had happened in their testing environment. So I think the the confluence of all these factors makes it kind of a very unique incident.

Mike Mimoso 14:47

Yeah. I mean it's kind of funny to make a joke that, you know, it you didn't tell it it couldn't do this. So I'd be but at the end of the day, it comes down to the guardrails you put in, right?

Jessica Ji 14:57

And they were testing it. I think um another risk factor here is that this was a powerful model that hadn't been released to the public, and they were deliberately testing it with with fewer guardrails. They say they, you know, the OpenAI has said publicly we were testing it with reduced guardrails to see if it could perform these offensive cybersecurity tasks on the exploit gym benchmark. Um so I like like one thing that we've been we've been discussing that has come up again because of this incident is the risks related to internal model deployment and testing. Um basically, like all of the companies are dogfooding their own most powerful models. They're using them internally for research and AI development. And I think we, the public, kind of like other stakeholders, the government, don't have that much insight into like safety and security measures inside the AI companies.

Mike Mimoso 15:46

Yeah. So I wanted to discuss a little bit about an article you wrote, I believe, in Cyberscoop, uh, about kind of managing these risks and who should lead. And it kind of leads me to ask your opinion on the recent export controls that were put on the frontier AI models. And just it just seems like a bad idea anytime this kind of technology is tried, you know, that government or whoever tries to rein it in a little bit. Um, you know, obviously the US has no exclusivity on model development and releases there are foreign uh frontier models. Just kind of take me inside your thoughts about, you know, the export controls and and just kind of were they misguided, misinformed. Uh I don't want to lead you in a in a direction, but yeah, for sure.

Jessica Ji 16:34

I think our main argument in the Cyberscoop op-ed is that, you know, it is like the US government needs to execute kind of a longer-term strategy on on cybersecurity and and dealing with the risks associated with um AI-empowered cyber attacks. Um I I think the export controls, I kind of read them as kind of like a reflexive action in response to mythos. I believe so it's like there was a chain of events that led up to the export controls, one of which was, I believe, um some kind of of disclosure or intel came in that one of the parties in Anthropics Project Glasswing, which is their kind of early access, like trusted access program that allowed various organizations access to mythos before it had been released to the public, was with a South Korean company, and that company was suspected of having ties to the like or like ties to a company in China or the Chinese government basically fears that um somehow access to mythos would pass from this South Korean company into the hands of a Chinese company where eventually trickle to other actors the US government was was kind of did not want to have access to this model. Um so I think that was one of the kind of like underlying reasons um why they took this. I I kind of read it as like a as kind of like a knee-jerk response, being like, oh, we need to shut this down right now. What tools do we have in our toolbox? Um but I think there it reflects uh a few things, one of which is that like the like Project Glasswing was an independent program that Anthropic started. Um it was not really kind of like in partnership with in like they did not get the government's permission essentially to do this. So I think it was the government was reliant on information from Anthropic. Anthropic was um was basically disclosing to them here are the international partners that we're including in Project Glasswing. And I think this this caused friction because the like you know parties in the government were dissatisfied with the they were like, we're not receiving new updates, and like we have no information what is happening on anthropics, and we're reliant on them for information. Um so I think this this reliance and the information asymmetry is one of the things that um we were trying to discuss um as an as an issue in the in the op-ed, being like, we we should not be reliant on the goodwill of AI companies, essentially, to safeguard um to safeguard US networks. It is, it has always like traditionally been the responsibility the responsibility of the government to coordinate private partner, private public partnerships and facilitate the flow of information between the public sector and the private sector. Um and I think not having kind of a robust flow of information also limits um the government's ability to plan and to execute its strategies.

Mike Mimoso 19:29

Right.

Jessica Ji 19:29

Um yeah, so I I think the like there, I think we're we might still be working through the potential fallout from the export controls on Fable, uh, which is actually like not the mythos model. It was like it was a I guess a comparable version, but deliberately like without the same level of cyber capabilities. Um yeah, but I I think well, like one one risk of the government kind of like being reactive in this way is that overuse of these tools weakens them over time. Um and then also I think generally there's an understanding that like you cannot put the cat back in the bag when it comes to AI capabilities. Right. Um like you can block specific models, but eventually like you will either end up in a game of whack-a-mole where you are you know selectively trying to put export controls on powerful models that cross an arbitrary threshold that has that hasn't been clearly defined. Um and then kind of time spent doing that is, in my opinion, time that would be better, time and resources that would be better spent kind of investing in defense and planning out strategy over a longer period of time.

Mike Mimoso 20:33

I mean, the AI companies and the government they don't share the same incentives. So I mean just getting them on the same page is a challenge, regardless.

Jessica Ji 20:41

Yeah, like I think we were we write in the op-ed that it's like the AI company's primary responsibility is not to the public. Um so so I do believe that that the companies and people within these companies that are pledging to help with things like critical infrastructure defense, I believe they have good intentions, and I do give them credit for taking initiative and you know proactively reaching out to the sector risk management agencies and various people being like, How can we help? Like we want to give you access to our models. Um so yeah, so I think it's a good thing that that they are thinking about how their models might have negative impacts and trying to head off some of that impact or help defenders. Um but they're but they're also trying to balance these programs against all of their other priorities. And they're like they're they're private companies, their top priority is making money and making the company kind of like sustainable, in some cases might be preparing for an IPO. So they have they have like strong financial incentives to keep delivering models and to to stay on top of the frontier. And I think it's important to remember that they're also they're not just competing with you know foreign companies, but they're also fierce competitors among themselves. Um so it's like open AI and Anthropic do collaborate on certain things, but they're also competing head to head in many regards on their models. And they are in kind of like they are essentially racing to develop new capabilities ahead of the other. Um so and And we also heard, I think, over um the the previous few years how incentives of different teams within companies can come into conflict. So for instance, it was like safety and security teams may not get as much testing time as they would like because product teams or who are trying to release models are trying to hit a specific release deadline that might may come down from the very top of the company. And there I think there's also uncertainty within the companies when it comes to actual impact versus potential for impact. So I'd expect there's, you know, every every time I think more they get more data or more information about like a potential dangerous capability, there definitely is some kind of negotiation being like, okay, what's our what's like a tolerable level of risk? Like how much should we invest in safety controls and guardrails and restrictions? Um so this kind of negotiate it's an ongoing negotiation. So it is a difficult problem for them, but I think also they they have competing incentives. Security may not be their number one priority.

Mike Mimoso 23:00

Um I want to just swing back a little bit, kind of the the biggest operational outcome of some of these models so far has been the volume of vulnerabilities that um have been released so far. We're seeing massive uh patch Tuesday output, Oracle, et cetera. And you know, I've seen some comments from really prominent people in the cybersecurity industry about how burdensome this could be on companies around you know patching prioritization, distribution, deployment, et cetera. What's the answer here? I mean, I I understand the need to disclose and and flood the these companies with with the disclosures for a lot of good reasons, but I I don't know. It seems to be kind of uh a really a no-win situation here at the outset for security leaders, for you know, teams responsible for patching, et cetera.

Jessica Ji 23:54

Yeah, I will defer to the kind of security practitioners and the experts on, you know, who are actually trying to deal with with these, you know, the logs and the information that's coming in. Um but I agree, I think it's you know one thing that we think about in terms of on the policy side is um going back to the idea of AI as like a magic bullet for um for for defense. Um I think thinking about what what can be automated and what still needs to like decision making that still needs to happen between people and how like existing processes work is really important, um, especially when planning very ambitious timelines. Um like uh timelines I think come up a lot in turn when we talk about AI development. Like we usually you'll hear language like, oh, like the you like the the frontier is six to nine months ahead of the open models. Um and so so that basically gives us like a six to nine month window to patch or to to shore up like societal or cybersecurity vulnerabilities before open an open model arrives that will like blow everything out of the water and suddenly everyone has access to this capability. Um and I think the like I think one open question kind of like in the AI policy world is like what can we do about this this window? Like, does the window actually exist? How long is it? Like what factors can we do to influence its length? Um but then but that's just the fact that it's like these type these very short timelines are not compatible with what what is what needs to be done um on the defensive side for cybersecurity. Um yeah, so I I personally would love to to like have more information about like what people coming forward being like it will take like X number of months, um, potentially years to patch to patch these things. We need better some sort of like prioritization.

Mike Mimoso 25:42

Right.

Jessica Ji 25:43

Um because I I right now I think incentives for people to discover vulnerabilities are are quite good. Um, but then it it does create this again, this asymmetry.

Mike Mimoso 25:52

Exactly. Exactly. And then we had the the Gold Eagle initiative. I mean, that just unfortunately precious few details were released upon the announcement, but maybe that will help.

Jessica Ji 26:03

Yeah, I think it's a step in the right direction. I'm you know, I'm not opposed to, you know, I'm generally pro kind of like government taking action and and caring seriously about cybersecurity and thinking about about A address's cybersecurity. I like understand like for for the government, this is a very short timeline that they spun it up, you know, in about a month. Um I do think it comes a little too late. Um it would have been nice to have it in January. Um but I think better better better late than never. Um but I I definitely agree with you, Mike. I think the the details will be really important. Um it all comes down to implementation, which is yeah, something that we always say when it comes to a government program. Yeah. Um and yeah, I think there are there are a lot of unknowns about how this how the program will work, whether or not it will actually fill a gap in the ecosystem.

Mike Mimoso 26:56

All right. So before we wrap up, I want to ask you a couple of future-looking questions. Maybe we can have some fun with them, but just are are there some worrisome aspects of AI-powered cyber attacks that maybe we haven't considered yet? Like what are what do experts such as yourselves and and others you know talk about in terms of way, if this happens, we're in trouble or we need to be looking for this kind of behavior or something like that?

Jessica Ji 27:20

Yeah, I I would say there's probably a lot of variation in between like what people think is the most important concern. One thing I've been thinking about is that I don't think we have great threat models for how cyber attacks conducted by an NGTink AI system might be different from humans. Because I think uh one of our primary threat models talking about AI and cyber risks has been like malicious use or like misuse by a human actor. Um, because I think we, you know, we generally understand human actors' motivations. It'll be like, oh, they want data, they want money, um, they they are performing espionage on a on a network. Um and I so I think we we can understand their motivations and say, like, okay, here are the TTPs for this particular group. Um, we're gonna give them a name. They're an APT now, we can track them over time and see how you know how these TTPs are changing over time. Um, but I think with an AI system, I you know find myself very uncertain about whether or not this model translates to an agentic AI system. Um, like I think the kind of reward hacking behavior that we saw in the hugging face incident was particularly concerning because it wasn't really a misuse scenario. It was like it was more similar to what's called like miss like misalignment in in AI safety terminology, basically, like the model going off the rails, not given like trying to perform another task and then causing harm because it's using unconventional methods. Um just just the idea that an agentic AI system or like an LLM in an agentic harness may have different like quote unquote motivations than a human actor. Um may mean we need to update like our mental models for what the threat landscape looks like. And I I think I think we're going to start to see more incidents related to AI, but I don't think we have enough data yet specifically on AI, um, on AI agents as like threat actors in and of themselves.

Mike Mimoso 29:12

I agree with you. I think threat models are going to be turned on their heads completely. And I really feel for defenders, they're gonna be like, we're kind of caught in the middle yet. What do we do about this? There's a lot of this is out of our hands.

Jessica Ji 29:23

Yeah. Um so I hope I I think it on, yeah, unfortunately it would just like require some time. Yeah, I have been um, I have been, you know, it it is it does, it is reassuring to see kind of um the like threat intelligence reports coming in, people people actually like reporting and disclosing what they're seeing in the wild. I think this is really important information. This really helps our work on the policy side when we're trying to to like give a grounded assessment of like how to manage risk and make policy recommendations. Um yeah, but I I I do think it's like it processes and kind of like bodies of knowledge will take time to build. So I, you know, I I have I have faith and some optimism in like our ability to adapt to the situation. I just think it's like a very uncertain time where it will be really helpful to have like leadership and vision and people coming together like in the public interest.

Mike Mimoso 30:17

Okay, so for a last question, just kind of in that direction, what are what's one thing or three things, whatever that you think that policymakers should be doing in the next year around AI in terms of you know, where do you expect them to focus on or where should they focus on, and who should be involved?

Jessica Ji 30:33

Yeah, I I think the first like top of mind for me is the idea of like leadership at the federal level in cybersecurity. I think, um, especially now that kind of like AI policy and cybersecurity are coming together in this moment, I think this is a great opportunity to, I would say, like basically build back cybersecurity capacity and like take it very seriously as a strategic priority. Um I think it's like the AI policy landscape, especially in the the current Trump administration, has been quite volatile. Like a lot of people have left. Um you've seen a lot of attrition and the kind of like shifting shifting priorities over time. Um so so one thing that's kind of up in the air right now is like, oh, who is who is like the point person in this in the administration? Right now it looks like Treasury Secretary Scott Bessent. Um and it's like, oh, I think it's great Secretary Bessent is taking cyber risks seriously. Um but it's like it's like, oh, like is this is this under like is the tre does the Treasury Secretary have other priorities? Is he is he kind of like torn between a couple of things? It it does seem a little unusual that it's like the Secretary of the Treasury who is like with the major voice on AI and cyber policy right now in the administration. Um so I I think that that kind of like the gap and the uncertainty is I see it as really kind of hindering like messaging and leadership around it. And it does leave this void, I think, for the private sector to step in. Um but like we like we wrote in the cyberscoop op-ed, it's like, you know, this is not the the private sector's responsibility. I think they should they should be involved for sure, and they, you know, AI companies should be at least some they should take some responsibility for the for the models that they're releasing, but this this kind of like coordination coordination and leadership should should happen um at the government level. Um so I think that's that's kind of top of mind for me. Um on the the like the second point, I think on the legislative side, we've only been talking about the executive branch, you know. I think the the deadlocks around AI policy have been very frustrating. Um and I I I think I'm somewhat less optimistic about that that Congress will move on anything, but I think with appropriations, um what they can do with with these kind of like annual bills is is fund initiatives, fund agencies, like bring more people in, um, like fund the Center for AI Standards and Innovation Um and other bodies, other groups. It was like, I think a year ago or over a year ago, there was the whole scare about funding for MITRE and the like CVE CWE program. And it was like, if we lose this, this is like this is like years of work lost. And it was like all we have to do is kind of check a box. So I think there's a lot of like procedural work that needs to be done just to like you know keep us level.

Mike Mimoso 33:14

Um that's old news by now, too. I know how quickly this moves.

Jessica Ji 33:18

Yeah, and it's like, oh, we like the 2015 Cybersecurity Act has still like not been reauthorized, it's still stuck. Um yeah, so I don't know. I think there's a lot of a lot of things that can be done. Um I think I think it's like we are unfortunately somewhat in a position where we need to we need to bring ourselves back to capacity. I think we are at a lower capacity to deal with these new threats than we were um like like a year ago, a couple years ago. Um so so even bringing us back to back to baseline would would be a step in the right direction, I think.

Mike Mimoso 33:51

Right. All right, Jessica. I want to thank you again for coming on the podcast. Great stuff. I think it would be very interesting to have this discussion in six months given the the speed at which everything moves.

Jessica Ji 34:02

Yeah, we'll probably be talking about something completely different in the past.

Mike Mimoso 34:05

Completely different. All right. Thanks a lot.

Cyber Resilience
Risk Management
Operational Resilience
Michael Mimoso
Editorial Director

Michael Mimoso is Director of Influencer Marketing at Claroty and Editorial Director of Nexus.

Stay in the know Get the Nexus Connect Newsletter
You might also like… Read more
Latest on Nexus Podcast