A Warning for Frontier AI Model Governance | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Frontier artificial intelligence (AI) model governance has arrived on Capitol Hill. Reps. Ted Lieu (D-Calif.) and Nathaniel Moran’s (R-Texas) AI Kill Switch Act would empower the secretary of the Department of Homeland Security to slow or halt frontier models. Sen. John Kennedy (R-La.) introduced a different “kill switch” bill, placing such power in the hands of private actors. Reps. Jay Obernolte (R-Calif.) and Lori Trahan’s (D-Mass.) FRONTIER Act would vest regulatory authority in the Department of Commerce and independent auditors, arguing that AI governance should not be “buried inside the national security apparatus.”

We applaud the governance momentum that is gathering. This problem deserves an all-hands response, one that considers cybersecurity and national security risks as well as the future of labor and access to knowledge. But Congress and other actors face a temptation with AI regulation, one that has often arisen in technologically complex, national security-adjacent situations: cybersecuritization.

Cybersecurity Mission Creep

In a new article in the University of Illinois Law Review, “Cybersecurity Mission Creep,” one of the authors, Mailyn Fidler, lays out what cybersecuritization is and how it works. When cybersecuritization happens, policymakers flatten complex issues into only two of their dimensions: technical complexity and danger to a public interest. Instead of accessing the full range of policymaking tools to address these complicated issues, policymakers resort first to blunt, emergency procedures that focus on the “tech-threat” dimensions of the issue.

This oversimplification of the debate often removes the issue from ordinary democratic deliberation into the realm of the expert and the emergent. Policymakers and other government actors alike can portray a tech threat as too technical for non-experts and too urgent for normal politics. For comparison, a conventional cyber threat, such as a piece of malware or an exploit, endangers computer systems themselves and is then addressed by technical fixes like patches or liability regimes. Conventional cybersecurity threats are catalogued and patched. But a tech threat is framed differently: Policymakers diagnose an issue’s technological features as dangerous to a nontechnical, societal target in ways that fundamentally change who should decide how to fix the issue. A normal fix won’t do. The decision moves from the standard cybersecurity realm into the realm of actors who claim that they can move to address the societal as well as technical threat. For example, imagine a vulnerability in one of the protocols that secures the internet. A conventional response to this kind of threat is to log the vulnerability and push a patch. Now, imagine, instead, that officials argued that this vulnerability could destabilize social and economic activity that the internet facilitates. A normal response no longer seems adequate; regulating who may contribute to the project or placing the project under government oversight might seem like a suitable response. The decision moves from the realm of technical contributors to the agencies that claim they can address both the technical and societal dimensions of the threat. 

Framing an issue as a tech threat also increases secrecy of governance mechanisms, in two ways. First, functionally: Technical issues are opaque. Technical issues implicate expertise. When policymakers frame an issue as technical, those without expertise may be discouraged from engaging. Second, legally: A technical issue that is also a threat can easily slot into existing, condoned secrecy regimes. For example, national security is a policy area where we allow secrecy to override transparency. When policymakers position an issue as one of national security, they imply that secrecy is appropriate. Positioning an issue as a tech threat becomes a trump card that lets officials skip past concerns about legal authority, evidentiary standards, procedural protections, distributional consequences, and competing public interests. 

Beyond secrecy, the flattening of the original problem into trump card form also incentivizes opponents to deploy trump cards in response. Both sides of the debate collapse into rigid positions, and important considerations that fall outside the scope of these argumentative trump cards have less of a chance of shaping the response. Consider the recent battle over TikTok. Congress cast the app as a grave national security threat, and TikTok and its users raised their own trump card in response: the First Amendment. But neither trump card adequately answered a broader question of why American users’ data is so easy to gather and sell in the first place. 

These issues typically do involve real technical and security threats, and those threats deserve a response. But those threats are rarely the only issues in play—the framing of them is itself a concern. When policymakers treat a multifaceted problem as purely, or even primarily, a tech-threat problem, they can justify a response without confronting more difficult questions about legal authority, evidentiary standards, procedural protections, distributional consequences, and competing public interests. The threat becomes a reason to skip those questions.

Online Misinformation Undergoes Cybersecurity Mission Creep

Cybersecuritization has cropped up in a range of tech-adjacent issues, including over online misinformation, children’s social media use, antitrust enforcement, and sex trafficking laws. Take the online misinformation case as an example. Online misinformation is a substantial problem: It shapes public discourse, including election results; alters popular culture; changes the digital economy; and may complicate widespread understandings of First Amendment protections. Yet, from 2020 to 2022, both the Trump and Biden administrations reframed online misinformation as primarily a tech threat, describing it as a threat to critical cybersecurity infrastructure. (The first Trump administration eventually changed its tune, firing the director of the Cybersecurity and Infrastructure Security Agency (CISA); the second Trump administration has been hostile to CISA, detailed below.) Online misinformation—a complex societal issue—became reduced to its technical and threat dimensions, crowding out other actors and considerations that deserve a place in the response. Online misinformation became a technical problem that could be solved in the same mode as other online threats, not a multifaceted social issue. The government positioned cybersecurity experts, chiefly at CISA, as the best responders. One of these experts even argued that cybersecurity “saved U.S. democracy,” a claim that shows how much a many-sided problem had been collapsed into a single frame.

Opponents of this cybersecuritized approach to online misinformation responded with a different trump card: lawsuits claiming that the government’s approach violated the First Amendment. The debate over online misinformation then hardened into two camps: those who took the threat seriously versus those who prioritized free speech. That framing leaves little room for a middle ground, or for the many other implications of online misinformation that neither argument captures. Cybersecuritization has since come at a cost to security itself. Months after Trump’s second inauguration, the administration proposed slashing CISA’s budget, and roughly a third of its workforce left. These developments may threaten CISA’s ability to help defend traditional targets like power grids, voting infrastructure, and water utilities. By cybersecuritizing the issue of online misinformation, CISA helped create a backlash that weakened support for its broader cybersecurity work.

Cybersecuritization and Frontier AI Model Governance

Frontier AI model governance is especially susceptible to cybersecuritization. AI models involve real cybersecurity and national security risks. AI also has the makings of a societally disruptive technology. Frontier AI models implicate the future of work, access to knowledge, economic orders, political decision-making, geopolitical competition, and more. Still, the deeply technical nature of frontier AI models, along with their genuine national security and cybersecurity implications, makes it tempting to treat them primarily as a tech threat and to respond on those terms.

This already played out in this summer’s Anthropic export control saga, when the Department of Commerce imposed export controls on two of the company’s models, requiring government permission before they could be made available to any foreign national, even those inside the United States. What began as a debate over a contested cybersecurity risk escalated into the use of the government’s full national security powers. Still, the details of that risk remain murky: The U.S. claimed, without explaining, that foreign nationals’ access to the product posed a substantial risk, while Anthropic argued the problem was a narrowly scoped jailbreak. The result was a rapid, sweeping export control directive. Because Anthropic had no way to verify users’ nationalities, it pulled the two models, effectively shutting them down for everyone until the directive was lifted less than three weeks later.

The Trump administration moved quickly from asking Anthropic to pull its models voluntarily, without sharing sufficient information, to imposing full-scale export controls. It also acted without consulting a broad range of decision-makers. Congress itself complained in a June letter that it had been shut out, learning of the administration’s actions from “publicly available accounts and discussions with relevant experts.” A small group of individuals, working largely in secret, used legally questionable powers to resolve what was nominally a cybersecurity risk. The response reflects a stark shift from treating the models as a standard cybersecurity concern to treating them as a “tech threat.”

After the administration played its tech-threat trump card, opponents answered with one of their own: economic growth. Anthropic warned that applying the government’s standards across the industry could “essentially halt all new model deployments for all frontier model providers.” The episode further entrenched a security-versus-prosperity framing of frontier AI regulation, crowding out more nuanced views. Cybersecuritization collapsed a multifaceted debate about a real issue into two entrenched sides.

Cybersecuritizing frontier AI models also risks dulling public appetite for addressing the risks these models actually pose. An export control regime that is imposed quickly and then lifted just as swiftly could lead the public to doubt future government claims of risk. International partners, for instance, have expressed skepticism about U.S. intentions, with French President Emanuel Macron calling the Anthropic episode “strictly nationalist.” Because cybersecuritization can be perceived as a pretext for other motives, it can weaken buy-in for future attempts to deal with similar threats. Cybersecuritization risks crying cybersecurity “wolf.”

Even if readers disagree with our characterization of the administration’s response to Fable and Mythos as cybersecuritization, frontier AI governance remains prone to it. The question now being debated in Congress heightens that susceptibility: Is a kill-switch approach to these technologies appropriate? If so, who should hold the switch? These are exactly the questions the tech-threat framing risks answering in overly simplistic ways. 

Combating Cybersecurity Mission Creep

Cybersecuritization can be short-circuited. Legislators, judges, researchers, journalists, and the public can insist that decision-makers open up the black box around cybersecuritized issues. When policymakers use cybersecurity risks to flatten complex questions, officials and citizens alike can insist that other interests at stake, from scientific collaboration to procedural fairness, be part of the debate. Asking “but what about X?” pushes policymakers to address the cybersecurity concern without overlooking other key issues and without letting the tech-threat framing dictate the entire response.

Congress has the chance to do just that. The aforementioned bills under debate offer an opportunity to revisit AI model governance more thoughtfully than this summer’s events allowed. Even Anthropic has accepted that the government should be able to block some unsafe deployments of frontier models, provided it does so through a transparent, clear, fair process that is set by statute and grounded in technical evidence. We agree, and we would go further. Any such authority should be created through democratic deliberation, and it should not rest solely with the national security apparatus. It should also require the government to try the narrowest effective remedy first, disclose the evidence behind a decision to developers and Congress, and allow independent review in the mode of an inspector general or oversight board.

With frontier AI models, those in power have used the word “cybersecurity” not as a reason to act but as a substitute for reasoning about how to act. That is the temptation of cybersecuritization: It turns hard political choices into quasi-technical inevitabilities. Resisting it means returning those choices, and the responsibility for them, to the many rather than the few.

——————————————————-


Click Here For The Original Source.