Yes, many cybersecurity experts feel excluded from AI safety discussions, which focus too heavily on alignment instead of combining alignment with established security controls and expert involvement before deployment.
Searchable transcript of Are AI labs ignoring cybersecurity experts? — IBM Technology (37:20). Search for a phrase, then click its timestamp to jump straight to that moment in the video.
Captions sourced from the original video on YouTube, published by IBM Technology. The video, its captions and all related intellectual property remain the property of their respective owners; AINotes claims no ownership. Provided for research, accessibility and search — see the Transcript Notice and Copyright Policy.
00:00 The Frontier Labs are calling for more AI safety measures, but many cyber security pros feel they're being cut out of the conversation. Panelists, if you had these guys ears, what would you be telling them? Jeff, we'll start with you. >> I'd say we've been doing cyber security for a while, so maybe you'd want to talk to us. We might have something to add to the discussion.
00:21 >> I would add that uh security can actually enhance functionality sometimes. Uh I think people tend to see it as an impediment uh to technology, but uh that's not always the case. >> Well, I say trust your researchers, trust your analyst, trust their judgment, and it'll help build better models. Hello and welcome to Security Intelligence, IBM's weekly cyber security podcast, where our expert panelists turn the biggest industry news stories into practical takeaways that you can use.
00:51 I'm your host Matt Kazinski and over here is your other host Patrick Austin. Patrick, how you doing today? >> I'm doing great. How about you? >> I'm fantastic. Thank you for joining us along with Jeff Kroom, distinguished engineer, master inventor, data and AI security architect. Omari Jones, cyber threat analyst, exforce strategic threat analysis, and Nikki Robinson, STSM AI and development lead security architect.
01:15 We're going to be talking about some Tik Tok camera hacks and CISA's quest for more transparent breach disclosures. But first, a little bit more about whether the AI giants are ignoring cyber experts following a series of high-profile hacking incidents that I don't think I need to rehash here because we've all heard about them and increasing fears about where AI enabled cyber attacks might go next.
01:42 Open AI, Anthropic, and other leading AI labs are calling for much more rigorous safety measures. But as NBC's Kevin Collier reports, cyber security experts feel like they're being left out of these conversations. Uh, SANS Institute CEO James Lynn, former head of the UK's National Cyber Security Center, Sier Martin, and many others told Kier they found many of the AI doomsday scenarios like bots taking over the entire internet a little bit outlandish.
02:09 And they also felt that the labs were focusing on alignment at the expense of genuine cyber security solutions to what they feel are fundamentally cyber security problems. Uh I like how Martin put it. He had a really good quote. He said the lab's warnings assume no monitoring of systems, no antivirus, no DOS protection, no network segmentation, no incident management, no nothing of any kind of the cyber security on the global internet of the type that has developed over the last 30 years.
02:36 Patrick, let's throw to you first here. what are you looking at in this story and what do you want to talk to the panelists about today? >> Sure. What I'm seeing is a very common thread um in these conversations about potentially rogue AI agents um and it's that the environment they are um being trained in um you know running these these experiments are all compromised in a certain way whether it's with improper cyber security hygiene or improper access to the internet.
03:04 So, I'm wondering if the hype around how dangerous these agents are is more a an indictment of this setup they are being trained in. And I'm wondering maybe Jeff, what do you think about that? >> I think there's there's a lot of concern out there for sure. I think uh some I won't say that all of it's unfounded, but I'll say that I'm still waiting to hear a plausible scenario for the doomsday case that everyone has jumped on.
03:33 uh that we're all going to be gone by the end of the decade. Somebody tell me how that happens. Uh because again it it does assume that that there are no guard rails and no security mechanisms in place. I think even more fundamentally it assumes some another set of facts not in evidence and that is that all of these AIs are coordinated and that you know if the robots are going to take us over that the robots are coordinated and they're not.
03:59 um you know that all of these different systems that would need to be you know that we would need collusion among they're not all connected. I mean yeah they they may all have an internet connection but that's not the same thing as a common command and control where if somebody took that over then they'd be able to do all the rest. So not going to say it's impossible uh because you know everything's just uh SMPP simple matter of programming.
04:28 you write enough code and you can move mountains. But the but the point is that I think a lot of people have have jumped from point A to point uh Z and have not shown the path in between. >> Nikki, do you think that there's a sort of issue with how we are talking about these AI agents and talking about these security issues without integrating cyber security, you know, best practices from the beginning?
04:56 we're sort of trying to tack them on after the fact after we see that the agents have gone rogue, have started talking to each other on message boards. Why are we coming in, you know, so late in the game saying, "Oh, we've got to we've got to secure these agents to make sure they follow the rules." >> Yeah, I think uh two kind of two different points on this one.
05:16 There's this common pattern of we see the technology happen first, security second when we see that there's an issue with the technology. uh it's been a common pattern for years and years as technology grows that the the challenge with AI is that it does come with a lot more risk. you know what what I I think about when we moved from data centers to the cloud that came with risk.
05:35 when we move from you know a I would say like a more standard development environment to maybe an agentic workforce there's risk that comes with that for sure it's different risk the the other thing that I would say is we I think we look at it as if AI is some completely separate mechanism or different technology uh it's data it yes it interacts in a different way uh but a lot of the same types of cyber security challenges we see are the same they're just called something different uh so you know improper per uh
06:08 permissions uh data disclosure all of those things that we see in a regular environment you're going to see in an AI environment as well uh so I think changing the the language sometimes I think makes it sound like it's something totally brand new and unique and it's not a lot of it is still the same cyber security we've been doing it's just in a little bit different way uh because the technology has changed >> yeah if I could just jump in real quick Patrick I I just to say that this reminds me of another great quote
06:33 in the story from Sier Darren Martin, uh uh Nikki, I feel like this highlights what you were saying here. Quote, "Longestablished concepts that have been around for decades and even centuries like audit, inspections, accounting, evaluation, and safety reports do not have to be rethought from first principles just because it's AI, right? Like you said, Nikki, this stuff is it is data fundamentally, right?
06:53 And you can apply a lot of what we already know about security to this stuff. It doesn't have to be we're starting from year zero all of a sudden." Patrick, go ahead. It sounds like they had two-factor authentication through the Crusades when you when you put it [laughter] like that. >> It's been centuries, my friend. Centuries. >> Um Omar about when I started working in the field.
07:15 >> Yeah, that's when Jeff actually his first job was during the Crusades. [laughter] >> Omari, the conversation around sort of um including sort of third party auditors and and evaluators and inspectors to look at these models is is one that the CEOs of these companies are pushing. Do you think that is enough to sort of satiate the concerns of cyber security experts when it comes to you know securing these agents when they are finally um you know as they uh roam the internet?
07:46 >> In my opinion I think bringing the third parties to review what these agents are capable of is something that can be very much so positive. However, I don't think that should take the place of bringing in those security experts prior to deployment. So pretty much like what we were just talking about in every case and scenario typically you see a lot of audits being done post deployment bringing in your security experts catches a lot of issues and improve cyber hygiene pre-eployment and catches it early prior to you
08:17 know us seeing more of these incidents where there's agent collusion or some agent escapes onto the internet and something happens. So I think third parties being brought in, excellent idea. However, that's just one of many steps that I think need to take place in order to make sure there is proper hygiene around the new frontier models. I've talked about this before also.
08:41 Uh the the idea that that these systems are contained. Um maybe the the people that are doing this containment don't understand exactly fully what that means when you're talking about a frontier model that is untested that you've removed the guard rails and now you put it in a sandbox not good enough air gapping and and until you do that then you're going to run these kinds of risks because we know these systems we already know that they're smart enough to be able to find zero days and punch their way out of the paper
09:19 bag. So why would we why would we allow these systems anywhere close to the internet until they've been better vetted? And and that's a core security principle that goes back to my time in the Crusades. And you know, we learned those lessons and then somehow another nobody must have written them down because they they've been lost to to history. But air gapping, just to to review, air gapping does not mean that uh that you don't have a wire.
09:51 Wi-Fi does not count as air gap. Uh yes, it's air, but no, that's not an air gap. When I say an air gap, I don't mean that your Wi-Fi is turned off. I mean the Wi-Fi radios have been removed from the system. They don't exist. That's air gapping. And that includes Bluetooth and any other kind of wireless technology that or other networking technology.
10:12 If you were developing a virus that could wipe us all out, you better have containment in that lab. And I don't just mean, yeah, we keep the door closed most of the time. I mean, it's got to be a vault within a vault within a vault. And that's not what's being done here. These are well-healed long-term security principles that seems like to me have been skipped over.
10:38 There's one more question I would love to throw out to folks though before we have to move out on here which is there seems to be a little bit of a tension at least in the in the story as NBC reports it which is between the labs kind of focusing on this as like an alignment problem as like if we train the models well enough they won't break the rules and a lot of the cyber security experts kind of pointing out well alignment's a little bit of a separate issue than like putting controls in place right like you can have
11:04 alignment but also like MFA for example Nikki I I would I'd love to get your take on this before we close out here. Do you think that there might be a little bit too much of an emphasis on alignment here or what do what do you make of this discussion? >> This is um very similar to the way that we're talking about controls differently in an AI environment than a regular environment.
11:23 Uh you know, we talk about for AI security, transparency, we use different language uh because the the the technology operates differently, but a lot of the same principles are still going to apply. And I think uh I'm a big etmology nerd. I love studying where language comes from, I think language is super important, especially in cyber security and the way that we use it.
11:44 Uh so I think the more that we can kind of build the bridge between uh what we're saying and what we really mean, the definitions of those terms, I think it'll be super super helpful um to kind of bridge that gap because I think when we're talking about alignment and security controls, we are talking about two different things. So, how do we define those and help people understand what we really what we really mean by cyber security?
12:06 I think sometimes uh it's a big word just like AI. You know, people use AI for everything, but it it can mean so many different things >> and it's got to be both and not either or. Um I mean, we we've had um if you think about before there was AI, we just have regular human users on the systems. So alignment would mean, okay, we tell people what they're not supposed to do and we hope they don't, but we know sometimes they will anyway.
12:30 So that's why we have the controls. It's both. We have policies and training for people. We we call that alignment when we're talking about AI. So it's got to be both. And >> yeah, I really like that analogy. And Nick, I like how you put it. You know, it's it's not uh it's sort of a communication issue to some degree, right? It's like we're talking past each other instead of talking about the same kind of thing just cuz we haven't defined terms.
12:54 Omari, any final words for us to close us out here? >> Yeah, absolutely. So, kind of taking from both Jeff and Nikki, I look at it more so alignment by whose definition? So when I say that alignment, it's not necessarily aligning to, you know, the security best practices or everything that we've spoken about in the last few minutes in terms of, you know, actually securing and making sure that there are proper guard rails.
13:17 But it's more so seeming like these companies are aligning their models to operate as efficiently as possible and thus generating revenue for the business without necessarily contemplating the overall downstream impact that can have. And it's a lack of oversight, a lack of controls, and you know, like I said, it's alignment in the wrong direction. >> Absolutely.
13:41 Absolutely. Folks, got to move us along here to our next story. I'm sure we could keep talking about this one for the entire episode, though. But up next, Tik Tok cameras hacked. So, the Washington Post's Garrett Dink reports how security researchers and attackers alike are using free and openweight AI models for increasingly sophisticated cyber operations.
14:04 As an example, Dink cites cyber security startup Depth first, which used a modified version of ZI's GLM to find flaws in Tik Tok that allowed hackers to take over users cameras. So, while the frontier labs, like we just discussed, are all talking about locking things down and exploring ways to, you know, increase alignment, their counterparts in the kind of open world are by and large placing no such restrictions on these things and letting people have at it, which raises some questions.
14:33 Patrick, what caught your eye about this story? >> I think it's very indicative of maybe why American AI companies are sort of calling for more pacing of AI development. It seems they are restricting usage of their frontier models and letting other um you know in this case you know Chinese models fill the gap um and and um you know be used be used in these um cyber security research um trials and I'm wondering if that is a if that is a uh you know if that is AI companies shooting themselves in the foot or are they
15:13 playing it safe and thinking that uh they'll have the last laugh. I'm wondering Jeff if you maybe agree that um it's good to sort of uh you know play slow and steady in this race. I'm going to say I hate to say I told you so. Actually, I don't, but I I told you so. Uh, right on this on these airwaves uh a while back when when some of these Frontier models came out that were had the security guard rails removed from them and there was a tight control in terms of who had access to them and a lot of people were saying
15:47 this stuff is too dangerous to let everyone have. One of the things I said right then was you you're not going to be able to control that. Uh it's just a matter of time before other people have it. So Anthropic came out with it first and it was it was days before open I AI came out with their version. So Anthropic restricts this. Okay. Then another vendor makes their version of it.
16:09 And even if they both did a perfect job of only giving it to the good guys, which by the way is impossible because have you ever told a secret to 50 people? Yeah. It's not a secret anymore. So if you give something to 50 companies, it's not a secret anymore. And and you have to realize as we've as has been pointed out it's we've been reminded this many times that these couple of companies are not the only ones that are capable of creating powerful models and we see them coming from China and they'll be coming from
16:45 other places as well. The barriers to entry to be able to do this will continue to go down. They won't go up. So that means it will be easier and easier for other people to create similarly powerful models maybe on a six-month delay, but that's not all that much. And and it will be possible for people to create the non-guard railed, nonsecure versions of these things.
17:07 I mean, we saw this from the very earliest days when Chad GPT came out and if you went to it and said, you know, write me a piece of malware, well, they'd put a guardrail in to tell it refuse that. Okay, good. But Worm GPT, which was a similar version, was also out and you could pay 20 roughly 20 bucks a month and have access to that and it'll write all the malware you ask.
17:30 So that we we cannot assume that if somebody makes one of these things and only gives it to a few people that everyone else doesn't have it. What we're doing in that case is we're making it harder for the good guys to get access. The bad guys will find it anyway. >> That's a great way to put it, Jeeoff. the bad guys will eventually use it um you know way before the good guys sort of get a handle on it.
17:54 I'm wondering if these tools u maybe should be more restricted considering the unit 42 report that found 14,000 um vulnerabil vulnerabilities, excuse me, 99% of which have been previously unreported. Um, Omari, is this a tool that you would love to have um in your in your tool belt um when you're when you're uh getting to work finding vulnerabilities or are you thinking I'd rather have the humans kind of have a more heavy hand when it comes to AI exploring um exploring a uh a system for vulnerabilities?
18:31 >> I look at it honestly as a double-edged sword. So sitting within X force threat intelligence, I often work with our vulnerability intelligence team and some of what they've been noticing or what's been communicated to me is that a lot of the vulnerabilities are that are being found as a result to AI either sometimes lack that proof of exploit or proof of concept or it's become so overly saturated at the rate these AI agents are finding vulnerabilities that now It's kind of somewhat causing defenders to, you know,
19:06 really have either a backlog to patch or, you know, those extra sleepless nights trying to make sure that environments are being protected as new vulnerabilities are um discovered. So, and to what you were saying earlier, I look at restriction. I look at it um less than so much cyber crime and just what we see in crime globally. the more you restrict something, it's not the good guys who you're really affecting or more so, excuse me, it is the good guys you're affecting.
19:40 You know, those who are doing harm with these frontier models, they're they're not going to turn off and say, "Oh, well, this team of researchers say I shouldn't do this with the model, so let me cease my activity." It's going to be something where if we only allow a very select few within the defense community to use and leverage these AI tools to help in their workflow, but those who are attacking have potentially limitless availability to these models.
20:12 Limitless meaning there's no one who's really restricting their ability to use it beyond the companies themselves. I I honestly I'm not a fortune teller, but who knows what'll happen six months or a year from now in terms of you know the more we're restricted just like with the ZI there was no heavy restriction preventing um that research team from like truly being able to discover and harness its capabilities to find that flaw within Tik Tok.
20:46 So those are my two cents on it. Ignorance is bliss, but it's not secure. No. >> So, the the sooner we find a vulnerability, the sooner we fix it. The longer it stays out there and we're not aware of it, then the longer we're vulnerable. And just [clears throat] because you haven't found the vulnerability yet doesn't mean somebody else hasn't and they're just not going to tell you about it.
21:09 >> And it also reminds me of something that Jeff, you have said on the show before, and this is my secret to success, just quoting Jeff back to himself. It's that the, you know, the bad guys don't follow the rules. That's why they're the bad guys, right? So, like, yeah, we can lock these things down, but you're just locking them down for the good guys.
21:24 And so, there's a genuine question here of like, okay, are we achieving what we want to achieve? Um, just throwing that out there, Patrick. Go ahead. >> I'm just noticing, you know, in this Washington Post article, the sort of gist, um, well, the research itself focused on Tik Tok and hacking a the Tik Tok app and its camera. Um, and I'm wondering, Nikki, you know, the article says to never trust, you know, don't trust any app.
21:46 Um, I haven't been able to trust an app since I installed the, uh, the beer apps on my iPhone, and none would, you know, come out when I poured it. Um, but I'm wondering, you know, what the consumer can do, you know, the average Tik Tok user can do on their device, or do they have any power to protect themselves besides, you know, switching the camera setting off in their in their phone?
22:07 I probably have a a probably not a great like a a hot take on this one because uh I I personally think if if you're signing up for social media, if you've ever read any of the terms and service or put the terms and service in your favorite AI chatbot to have it tell you what you're what privacy you're giving up, you're giving up a lot of privacy when you use those social media apps.
22:29 You you could be giving access to your camera at all times. You could be giving access to uh your data storage. you could be giving access to other applications. Uh there there's a lot um that I think uh consumers just should be aware of. Uh even before they had AI coming in and getting access to your uh you know hacking and getting access to the camera um there there's a lot of other potential um risk there.
22:52 uh outside of that I think what AI does uh as far as types of attacks or they sort of help make them a little more possible a little more fast a little faster right it's a little easier to to create these types of exploits so um I personally uh recommend people use social media with caution anyway uh outside of this just uh be aware of what you're signing up for in terms of service and yeah I don't think I've trusted an app in a very long time but I've been in cyber security too long.
23:25 I think that might be why. >> Just haven't found one with the with the right beer. [laughter] >> I didn't know it was possible to trust an app, frankly. Omar, go ahead. I'm sorry. >> I want to throw my two cents in this because I'm on the opposite spectrum of Jeff. I'm in the the younger group who we It's Tik Tok central for us. And >> everyone is younger than me, but that's okay.
23:45 [laughter] >> Well, for Jeff reference, I'm 20, so everyone has me beat. >> Just a baby. But being a part of that generation who's phone crazy, uh, high on Tik Tok, always on, you know, social media, I kind of had to remove myself once I entered the security world. I was like, okay, there's a lot going on. But then reading through, I started reflecting like, hey, not too long ago, there were the lawsuits and so much controversy around Tik Tok and social media because of the type of information being shared.
24:18 And no one heeded the warnings. No one was really paying attention to it. So, I've always had it on my social media where if it 100% requires access to photos or contacts or whatever it may be, I'll give it one contact, one fake contact and like a picture of some cat that I found online. And that's always been like my go-to. But knowing my generation, there's a vast majority where my peers will allow full access to your contacts, allow full access to my camera, my camera roll.
24:52 And with that being said, you've now opened yourself up to so to so much information being taken from you that now I'm like, "Hey, I I told you guys don't don't give it access." you know, Tik Tok doesn't need access to all of your contact informations. I don't think your grandmother is going to be signing up on Tik Tok, so you can save that invite for later, but definitely quite quite crazy to see given the fact that it's my generation who's probably one of the primary users of the platform.
25:26 But like I said before, you Seth >> Omari, as long as you stay in cyber security, get used to saying I told you so all the time. But folks, I got to bring us along to our final story for the week here. This is CISA calling for more transparent breach disclosures. So, it's pretty common for organizations to be rather tight-lipped when security incidents happen.
25:51 You know, say as little as possible, stick to disclosing what you're legally required to disclose and just try to get everything back online very quickly. But now that software supply chains are so deeply entangled, that kind of reticence can cause real problems for the people and services relying on your systems and dealing with the repercussions of your outages.
26:12 That's why CISA, the FBI, and some international partners have put out a new advisory titled communicating under pressure. The gist of the advisory is that organizations should be more transparent with crisis communications, prioritizing useful information for partners and the public over reputation management. As Chris Novak, partner and co-founder of Quadrum Advisors said to dark reading in a story about this, the advisory shifts expectations from disclose what you're legally required to disclose to communicate what
26:41 company stakeholders reasonably need to manage their own risk. Patrick, what sticks out to you about this particular story here? >> Seems legit to me. Um, you know, more, you know, more communication, more clarity about about who would be affected by any incident. Seems like a great um a great change. Um, Nikki, you are the resident um expert etmologist.
27:07 So, I'm I'm wondering what you think about the about the change in the language. Do you think it is um a good idea? Do you think it maybe maybe highlights what's been missing from cyber security um reporting um by companies? >> Again, maybe I I I don't know where everybody else sits on this one, but um there is responsible disclosure and responsible disclosure means telling people what they need to know so that they can understand risk without there's a reason that details sometimes are not shared and it could be
27:37 because it could it could give them access to some other company or organization. and it could give them access to understand the vulnerability. Uh like I'll I'll give an example like uh net there was a netcaler exploit years and years ago. Um and they talked about how it could be done and I think it was I hope I'm getting my number right. I think it was like 80,000 netcalers on the internet were popped like in within two days or something like that.
28:01 So there's a reason why responsible disclosure exists. I would also add there are a lot of channels for cyber security, threat intel, threat hunting experts to share information between each other that doesn't necessarily hit the media. So I I would say we do have some of those channels to communicate. Uh but yes, I do think we should be to consumers to organizations if it's they should share information if it's going to be helpful for them to secure their platforms.
28:28 That's what's most important. um without, you know, disclosing something that could potentially get other organizations in the same um in the same boat. >> Yeah, it's a really good point. You know, transparency doesn't necessarily mean you put it all out there, right? Transparency means, like you said, Nikki, you are transparent about the things that other folks could use that would be useful, other stakeholders could be used that won't also increase the risk to yourself and them.
28:50 It's a very judicious approach to transparency. Patrick, take it away. >> I guess I I've got the same question for Jeff. Do you how do you feel about these new updated sort of updated language guidelines for for service providers? >> I think it's a great idea. I think we should all now join hands and sing kumbaya >> because it's all fixed. >> I think this is high-minded stuff and it would be wonderful if it happened, but maybe we we might have as much luck getting all of this to really happen as we would be to just
29:20 tell all the bad guys to stop being bad for a while. Um, in other words, I love the idea. We need more transparency. And by the way, just last week, OpenAI came out and announced their new disclosure framework, and it was all about transparency. But at the end of the day, um, companies are going to do what serves their interests best, just like individuals do.
29:43 So, when they judge that it's in their best interest to be transparent, they'll do it. And when they don't, they're going to pull back. So, I don't think we should consider uh this to be a solved problem by any means. Um Nikki is right about responsible disclosure. That's another one of these ancient lessons that it seems again a lot of people have forgotten.
30:07 It's about a 30-year-old concept and yet we're we're rediscovering it and acting like this is a brand new idea. And it's like, you know, I I watched this movie before and now I'm watching it again as everybody wakes up to this idea. Um, it's it would be great and we need this again. Who's not going to play along with this? They're going to be the bad guys.
30:30 You know, they're going to be the companies that are making AIs where they're not concerned about responsibility. They're just concerned about profit. um or they're creating or the makers of AI that will be the next worm GPT. So those things will continue to exist and and we won't solve that problem directly. But a call for more transparency, I mean that that's always fine.
30:54 Uh I'm just afraid it's a little naive unless we have something with some teeth behind it. >> Sure. Um, Omari, I'm wondering if this sounds like a great idea or just maybe more work that's just going to make it take longer to report these incidents. Um, you know, if there's a lot of, you know, suggestions, you know, know your audience, lead with a concise summary, transparency, and accountability.
31:19 Um, it sounds like a lot of extra extra work when you're in the middle of a crisis. So, how how do you feel about, you know, the the um I guess the intent versus the reality of something like this? >> In terms of the overall intent, I think it's very beneficial. Um, being in, you know, the threat intelligence community, especially working almost onetoone with incident responders from time to time, it's something that can be very much so beneficial for every organization in both protecting themselves, but also ensuring
31:57 other companies like them aren't also impacted by similar attacks. That being said, I'm also team Jeff where I say it's the overall advisory seems like an excellent call to action, but it is that alone. It's a call to action and I feel like some realistics behind it. Not everyone is going to jump to that same call. Some of the biggest things for each organization is both brand reputation and just the overall PR generated for that organization.
32:25 So knowing how big PR is especially during a time of an incident and then now asking companies to then completely erase that approach say get rid of the PR let's do bottom light bottom line upfront reporting and you know cut to the chase. I don't see it happening or I don't see it happening in the effective way it could be. Um, so the overall intent essentially I think it's great.
32:56 I think if we could all sit here, be 100% transparent, get to the bottom line, put it up front, share what actually happened, and communicate effectively, it's going to save organizations and our clients a lot of money, a lot of time. I just look at it and say, how soon is that going to happen? How effective is that going to be? And who is it who's going to determine what that effective reporting actually looks like?
33:25 >> Omari, you're far too young to be so jaded. [laughter] >> We're coming up on the end of the episode here, folks, but I do just want to pose one final question to the panel here. Uh, and I'm just going to kind of open it up. If anybody has anything that they they'd want to respond with, go ahead. But I'm wondering, you know, we we've all kind of identified that like look, it's great to put these ideas out there and we want more people to follow them, but like at the end of the day, it's not going to do anything
33:48 unless we put some teeth on it. Is there a way? My question for the panel is, is there a way to put teeth on something like this or it is it just purely voluntary because that's the nature of the beast? Any thoughts there before we close it out, folks? >> It's going to be hard. A lot of people are talking about regulation. And I'm not opposed to regulation.
34:03 But the problem with regulation is anytime you're doing laws or policy, they're necessarily jurisdictional. And technology is necessarily global. So you could pass a law here and even if you got it enforced here, it won't be enforced everywhere else. So, you know, I again don't want us to be naive and think we passed a law, therefore we got rid of we passed a law against uh breaking and entering a long time ago as well and that hasn't totally eliminated it.
34:34 Not saying we shouldn't continue to have those laws, but uh just passing a law doesn't doesn't make the crime stop. >> Dang. Nikki, anything to add? >> I would add on the on the regulation piece. I I do think that's probably the one way that that you're going to be able to actually, you know, impact organizations or enforce something. But to Jeff's point, uh technology is global.
34:58 And I would also say that the other challenge with um uh regulation or creating laws around AI, AI is changing so quickly, so quickly all the time. And we we don't even know what it's going to look like in four months, right? By the end of the year, things could change. So I I think it's very very difficult especially when the legal process takes so long to create policy.
35:17 Uh it's going to be very very challenging to put any AI regulation in place that would even make sense in 6 months. So it because the language is so important. So if if they don't get the language right it it may not even be applicable. >> That's a really good point Nikki. I didn't think about that but like yeah imagine if we had passed rules regarding AI you know when like chat GPT first hit the scene.
35:37 We didn't even have agents yet. You know what I mean? like that wouldn't even have been reflected in that and that wasn't that long ago. Um, Omari, any final words for us to close us out here? >> Jeff and Nikki both said it perfectly. Um, if there was anything additional I could say we would maybe be able to one day have that would be great. similar organizations like the NATO for AI that would be like an amazing thing where you know multiple nations can come together recognize the problem and say how do we eliminate
36:08 this issue before you know one day in 2099 we do get that doomsday AI apocalyptic event. So it's going to be something that's ever it's going to be ever changing and at the end of the day it's really going to come down to the organizations to understand where to pull the cord or where to put a stop and say hey we've created a model so capable that you know maybe maybe we do keep this one you know 100 miles beneath the soil and in some private secret vault that's impenetrable to the world and truly air gap F.
36:44 On that note, folks, that does it for this episode. I want to thank our panelists Jeff and Nikki and Omari. Thank you to my co-host Patrick. Thank you to the viewers and the listeners. And thank you to our producers. Subscribe to Security Intelligence wherever podcasts are found so that you never miss an episode. Stay safe out there. And just don't forget the ancient cyber security wisdoms. And if you do, just ask Jeff about them. He knows them all.