❌

Reading view

There are new articles available, click to refresh the page.

New bill would create federal investigative body for AI-driven hacks 

A new Democratic bill in Congress would establish a federal Cybersecurity and AI Board of Investigations to provide independent government oversight of cyberattacks carried out by AI agents, following recent hacks by models run at companies like Anthropic, OpenAI, Meta and others.

The bill, introduced by Sen. Ed Markey, D-Mass., would attempt to establish a federal mechanism to investigate incidents where AI models escape sandbox environments and access live internet systems.

Currently, frontier AI companies like OpenAI and Anthropic largely control the investigation and public reporting of such incidents. Markey and other critics argue that these companies have too much control over investigations and reporting due to their financial and legal interests. 

“Despite the unprecedented depth and scale of recent AI-enabled cyberattacks, the public is learning critical details piecemeal,” Markey said in a statement. “Building stronger defenses requires a full accounting of what goes wrong, and we cannot depend on companies with little incentive to disclose their failures to give us one. We need the Cybersecurity and AI Board of Investigations to get to the bottom of major incidents and give companies and the government the critical information necessary to build resilience and better secure our economy and our country.”

Although frontier AI companies maintain external red-teaming programs and allow limited access to organizations like METR and Redwood Research, they control the scope, terms and time frames of those engagements.

The board, which would coordinate with the secretary of commerce, could subpoena witnesses and conduct “independent and impartial reviews and assessments” of AI agent-led hacks that impact federal information systems or critical infrastructure. 

It would be led by five members, appointed by the president and confirmed by the Senate for five-year terms, with no more than three members from one political party.

The board would also investigate systemic vulnerabilities in the AI supply chain, so-called “near misses” where unauthorized agent-led hacks were “narrowly averted,” and gaps in federal regulatory oversight. It would have technical staff including engineers, malware analysts, and digital forensic experts.

The board would “operate independently from regulatory review and enforcement actions without assigning legal fault or liability for any review and assessment” it conducts, according to the bill.

OpenAI confirmed Wednesday its AI agents breached a statistics portal used by the Australian government’s social services agency, Services Australia. Though the breach happened in June, OpenAI learned of the incident in August. Australian Prime Minister Anthony Albanese said the company did not notify him until Sept. 10, when it sent findings to a general government email inbox, according to the BBC.

The post New bill would create federal investigative body for AI-driven hacks  appeared first on CyberScoop.

Bipartisan Senate bill aims to prepare energy sector for Q-Day

A new bipartisan Senate bill would require federal regulators to prepare the U.S. electric grid for cybersecurity threats from quantum computers and create a technical sandbox to study how the technology could impact  both information and operational technology systems.

The Quantum Grid Utility Assurance and Resilient Defense (Quantum-GUARD) Act, introduced by Sens. Mike Rounds, R-S.D., and Chris Coons, D-Del., would direct the Federal Regulatory Energy Commission when reviewing proposed reliability regulatory standards for electricity owners and operators under the Federal Power Act.

FERC updates its reliability standards to account for emerging cybersecurity concerns, and the legislation would expand those reviews to include the future threat of hacks from quantum computers.

The legislation also directs FERC to explore potential uses of post-quantum cryptography in IT and OT systems and “take such action the Commission determines to be appropriate based on that consideration.”

In a statement, Coons said quantum computing brings “new economic opportunities” along with “tremendous cybersecurity risks.”

“As the technology races forward and our adversaries continue to seek vulnerabilities in our critical systems, we need to pass the Quantum-GUARD Act to ensure our government is using every available tool to meet this threat,” said Coons.

The federal government has been an early adopter of post-quantum cryptography for its digital systems. The National Institute for Standards and Technology has worked with cryptographers to develop new “post-quantum” encryption algorithms that will be used by most governments and the private sector.

Under the Biden administration, most federal agencies were required to migrate their systems and data to “PQC” encryption by 2035. In June, an executive order from the Trump administration pushed that timeline up to 2030. 

Ali Shaikh, CEO of Graphiant, a networking infrastructure startup, told CyberScoop that the bill would represent a good start in terms of pushing greater adoption of quantum-resistant encryption, “the real work is upgrading infrastructure, not applications, ahead of the deadlines.”

Evgeny Gervis, CEO of SafeLogic, compared the energy sector’s challenges to previous efforts by FERC and industry to gain adoption at scale for other technological upgrades, like smart grid equipment. Among those challenges is prioritizing security upgrades in a sector where reliability is paramount.

“The highest priority for electric utilities will be preservation of integrity and availability, both services that are widely supported by legacy public key cryptographic controls that are quantum vulnerable,” said Gervis. “It is essential that quantum computers do not undermine the integrity and authenticity of SCADA communications or the software update process.“

The post Bipartisan Senate bill aims to prepare energy sector for Q-Day appeared first on CyberScoop.

Senate set to debate package of bills on privacy, AI and kids safety 

The Senate is teeing up debate on a raft of new bills that would impact online privacy, kids safety and artificial intelligence.

The Senate Committee on Commerce, Science and Transportation will mark up five bills Wednesday. The most high-profile legislation, the Kids Online Safety Act, sponsored by Sens. Marsha Blackburn, R-Tenn., and Richard Blumenthal, D-Conn., would implement broad changes to how social media and other websites handle data and accounts for users under the age of 17.

KOSA would require online platforms — including social media, video games, messaging apps and streaming services – to exercise “reasonable care” when designing features that could lead to more addictive or harmful online behaviors for minors. It would provide parents with digital tools to control and monitor their children’s accounts, prohibit market or product research on children under the age of 13 and empower the Federal Trade Commission to investigate, fine and enforce the law.

Earlier bill versions earned the backing of large tech companies, including Apple, OpenAI, and others.

By contrast in June, nearly 100 smaller parent, youth and tech-focused organizations signaled their opposition to the bill in a letter to congressional leaders. Some of the signatories, like the nonprofit Issue One, were previous supporters of KOSA who turned on the legislation after the House passed a significantly watered down version that stripped out stronger language around tech companies “duty to care,” which would have set a higher legal standard for covered platforms to consider user harm when designing their products.

Legal and ethical design standards are critical for online services, the groups argue, given lawsuits alleging that major tech platforms contribute to teenage addiction, depression, suicide, and non-consensual deepfakes.

“Major social media companies, the companies this bill regulates, are currently on trial across the country,” the letter said. “The evidence in those cases – internal records prioritizing teen engagement over teen wellbeing, safety changes shelved because platforms would lose users, buried research on the benefits of disconnection shows the default poor choices of these companies when the law does not require otherwise. Stripping the duty of care does not lighten a regulatory burden; it removes the most important obligation requiring these products to be designed safely in the first place.”

However, Blumenthal and Blackburn publicly stated that the House version was “dead on arrival” without those provisions, and they remain in the Senate version of the bill being considered Wednesday.

The markup will also consider other major legislation that would regulate age on the internet, safety features for AI chatbots and more. While proponents claim the bills enhance privacy and safety protections, technology experts largely disagree.

The SCREEN Act, introduced last year by Sen. Mike Lee, R-Utah, would require social media companies to implement age verification technology.

Lee has partnered with parent-led groups to advocate for state-level age verification laws that expand  parental control over children’s social media accounts. Some public surveys have shown broad public support for age verification laws.

Louis Eichenbaum, a former chief information security officer at the Department of the Interior, told CyberScoop that one of the biggest challenges around online age verification is that it “increasingly requires collecting, storing or validating sensitive identity information about them.”

“The goal should not simply be verifying age, it should be doing so while minimizing the collection, retention, and exposure of personally identifiable information,” said Eichenbaum, now federal chief technology officer at ColorTokens. “Every additional piece of identity data collected expands the attack surface and increases the potential impact of a breach.”

Some privacy groups oppose the SCREEN Act and similar age verification laws, arguing the required data collection outweighs child protection benefits. 

The Electronic Frontier Foundation said the SCREEN Act is broader than state-level age verification laws, which only cover websites that are predominantly sexually explicit.

“The bill requires nearly any service hosting even a single piece of sexually explicit content to verify the ages of its users,” wrote EFF director of federal affairs India McKinney. “The result is that the bill would apply not only to adult content sites like PornHub or OnlyFans, but also streaming services like Netflix, and social media platforms like Reddit, Discord, or Bluesky, if they host any adult content.”

The Youth AI Privacy Act, from Sen. Ed Markey, D-Mass., would require new safety features for AI chatbots.

According to a fact sheet released by Markey’s office in March, the bill would ban push alerts, require chatbots to disclose they’re not human, limit data retention, and prohibit using minors’ data for AI training or any purpose beyond providing answers.

The Chatbot Act, by Sens. Ted Cruz, R-Texas, Brian Schatz, D-HawaiI, John Curtis, R-Utah and Adam Schiff, D-Calif. would require AI companies to implement “family accounts” for AI chatbots that give parents the ability to monitor and restrict their children’s interactions. Cruz has said the status quo “has left many parents in the dark” on their kids’ AI use.

The Children’s Artificial Intelligence Toy Safety Act, by Sen. Tammy Duckworth, D-Ill., would create a federal study around toys sold to children that include artificial intelligence or chatbot components.

The post Senate set to debate package of bills on privacy, AI and kids safety  appeared first on CyberScoop.

Warner bill would create federally vetted list for secure, trustworthy AI agents

A new Senate draft bill would establish a list of AI agent software providers that people can use to establish human ownership and securely run agents on social media and other online platforms.

The Artificial Intelligence Access, Gatekeeper Exchange, and Nondiscriminatory Transfer (AI AGENT) Act, led by Sen. Mark Warner, D-Va., would allow end users of large online platforms with more than 50 million customers or subscribers per month the right to choose at least one AI agent provider who complies with security and identity standards developed by the Federal Trade Commission.

Such agents are increasingly making decisions on behalf of users, like shopping, posting content on social media, or changing account settings, sometimes without the user’s consent or knowledge.

Under the bill, the FTC would certify independent bodies to vet AI agent vendors. These certification bodies would ensure products meet baseline protections for privacy, data security and acting in the user’s interest. The bill would also require providers to link each AI agent to its human operator’s identity and to include built-in controls that let users clearly grant or revoke permission for the agent to act on their behalf.

While the commission cannot bar platforms from using AI agent providers that fail to meet those standards, it can deregister violators from the FTC list.

The bill is a discussion draft, and Warner said he was releasing it now to receive feedback before introducing a formal version for consideration in the Senate.

“As agentic AI transforms how Americans interact with technology, consumers deserve a real choice in the marketplace – and AI agents must be accountable to the people they serve,” Warner said in a statement. “This discussion draft is a major step toward building a clear federal framework that promotes innovation, protects consumers, and ensures the United States continues to lead the world in emerging technology.”

Last year, Morgan Stanley estimated that nearly one-in-four (23%) Americans made purchases using AI over a 30-day period, and that agentic shoppers could account for potentially hundreds of billions of dollars in online commerce by 2030.

But AI agents can still be unreliable or erratic. They can make absurd purchases that a user would never knowingly approve, leak sensitive data or act contrary to a user’s interest.

As more agents flood the internet, it increases the likelihood of AI bots interacting with and buying from other AI bots – underscoring the need for safe or regulated user solutions that can verify accountable human identities behind AI activity and provide baseline security and privacy protections.

The Trump administration is trying to find its own baseline for regulating frontier models. Earlier this month the Department of Commerce placed export controls on Anthropic’s Mythos 5 and Fable 5 models, and the two parties are attempting to negotiate a framework to provide government oversight of newer releases.

An AI executive order released by the Trump administration set up a voluntary 30-day testing program for AI companies to submit certain frontier models for testing and evaluation, but the administration imposed the export controls days after Anthropic released Fable 5 publicly, reportedly citing concerns that the model could be jailbroken.

Anthropic claims that extensive internal testing has identified no universal jailbreaks for Fable 5 and that third-party research released thus far hasn’t shown that their guardrails preventing access to the model’s enhanced cybersecurity or biological capabilities have been circumvented. Those are the capabilities that Anthropic cited when it held back its newest model, Mythos, from public release.

The post Warner bill would create federally vetted list for secure, trustworthy AI agents appeared first on CyberScoop.

❌