Nick Marinos, the managing director of IT and cybersecurity issues at GAO, said leveraging existing avenues for cybersecurity information sharing can expedite getting AI safety policies into law. #
As Congress continues to wade through legislation focused on the various aspects of artificial intelligence, an official at the congressional watchdog — the Government Accountability Office — said lawmakers are going about AI safety the wrong way.
Nick Marinos, GAO’s managing director of IT and cybersecurity issues, said the legislative approach to addressing newfound cybersecurity and other risks presented by advancing AI models is too reactive.
Speaking during a GovCIO AI event on Thursday, Marinos said lawmakers need to go beyond thinking about cybersecurity risk mitigation policies and focus on eradicating them altogether.
While he acknowledged that positive strides have been made in catching up with new technologies at the government level — such as the creation of the Cybersecurity and Infrastructure Security Agency and the Office of the National Cyber Director — Marinos said the government remains “behind the eight ball” in regulating AI-related threats. “If you look at a lot of the AI safety bills, think about the need for us to update key legislation,” Marinos said. “It's really more about stepping away from thinking that we're going to address all the vulnerabilities, but more so thinking about ‘how can we close the door as much as possible,’ and then ‘how can we be very quick to respond and react when there is an incident’ as well.”
Some of the key legislation Marinos referred to included the Cybersecurity Information Sharing Act of 2015. The law created a voluntary attack sharing mechanism between the government and private sector, provisions that are set to expire this coming September.
The Senate approved a short-term funding measure on Aug. 8 that would extend the Cybersecurity Information Sharing Act until Dec. 11. The law temporarily expired during the 43-day government shutdown late last year, although Congress passed a funding package in February that extended the statute through Sept. 30.
The original text of the Cybersecurity Information Sharing Act does not address AI. Marinos said that one starting point to more proactive AI safety legislation could look like an extension to the existing law that includes information sharing AI-specific attack data.
“If it's a given that a vulnerability is going to be found, how are we monitoring activity to prevent the most catastrophic consequence to it?” he said. “It's going to take a full collaboration.”
GAO initially considered information security a “high-risk” area about 30 years ago, Marinos said, noting that even at the time the pace of technological innovation was moving at an exponentially faster rate than government guidance and action.
“We've seen too often that if one part of critical infrastructure is being affected by something, it probably is being affected in other places,” he said. “If they're not talking, or if the government isn't trying to facilitate that communication, then as a nation, we're not going to be well prepared to protect.”
Industry experts agree with Marinos’s point. Cyber Threat Alliance CEO Michael Daniel said that AI-related cyber threats could be mitigated with updates to statues in a landmark bill like CISA 2015.
“While one could make an argument that existing CISA 2015 protections cover that type of information, Congress should update the definitions in the Act to clearly cover information about threats to AI systems,” Daniel told Nextgov/FCW. “A single piece of legislation does not have to address every cybersecurity problem related to AI to be useful.”