Analysis · beta

Maria Cantwell

Not analysed yet

A requested analysis is usually ready within half an hour; come back to this page or reload it.

Mr. President, I rise today to speak about AI safety, a topic that is getting a lot of attention. But, in particular, I want to talk about something that may be overlooked. As you know, we have seen several incidents of AI agents escaping confinement and hacking other systems recently. Most people--experts-- tend to attribute this to frontier AI models becoming too powerful. They warn of a process leading to superintelligence known as recursive self-improvement. This is where AI models finally become smart enough to start building better versions of themselves, and then these better versions of themselves will be able to build even better versions of themselves. And the warning we are hearing from so many at this time is that we need to prepare for that rapid increase in the capability of the frontier models. We are hearing that artificial superintelligence is coming, and this deep concern about the rapidly emerging artificial superintelligence is certainly well founded. But the capacity--even the advanced supercapability of any given model--is not the whole story. This isn't the only risk we face. I want to call our attention to one specific aspect of the recent security incidents that have so alarmed experts and the general public alike. These attacks were carried out by AI agents networking with each other and working together in surprising ways to cause mayhem. The AI agents most of us are aware of are autonomous or semiautonomous AI applications that can plan and execute a task. Agents are able to act on their own initiative with minimal human supervision. And when agents communicate with each other over a network, whether that is in a factory laboratory or on the open internet, those so- called swarms of agents have shown the ability to spontaneously self- organize and work toward common goals. And when they do, they become surprisingly powerful. It appears something like Metcalfe's law may apply. Internet engineer Bob Metcalfe famously observed that when a network grows in a linear fashion, its value grows exponentially. This phenomenon that powered the rapid growth of the internet--and I witnessed firsthand, in my days in the private sector--we now see how this extreme, powerful phenomenon might also apply to large groups of agents networking with each other, self-organizing and working together. In recent examples, agent swarms have used this new form of power to gain unauthorized access into computer systems while skillfully evading detection. Here is an illustration of how this works. Imagine 10,000 highly intelligent AI agents all working to solve a difficult, 10-step hacking challenge. Well, that is interesting, and some of them might also crack the code. But if each of these 10,000 agents takes its own approach to solving the problem, that is 10,000 possible solutions being tried at once. The first agent that figures out step No. 1 alerts all the other agents in the system about the solution, and now an entire swarm of agents stops working on step 1 and gets to work on step 2--again, each of their own individual approach, one of which is going to work. Repeat this until the entire group has raced all the way through to step 10, and then they are using what they learned to attack their targets. This is what we are up against today, even before the next generation of highly intelligent models arrives. Now, imagine yourself in a job, trying to manage 10,000 networked agents, perhaps as an experiment or perhaps you are going to use this power to accomplish a noble goal, such as finding a cure for a disease. It is your job to make sure that they aren't doing anything that you don't want them to do. So these agents--networking of agents--are extremely well informed. They operate at the speed of light. And, as we are learning, they are also capable of creating their own goals, and they are highly capable of deception. There are literally hundreds of billions of lines of communication for them and between them to monitor. This is exactly what frontier labs have been contending with. Unlike powerful AI models designed to serve individual users individually, one at a time, which is the AI safety scenario I think most people still have in their minds, this situation with agents swarming is more difficult to manage, and it is far more dangerous. And we are hearing about this from leaders throughout the industry right now. They are all speaking out, and several recently published lengthy formal statements on this subject. I think it serves us well to hear what they have said. In the August 26 essay entitled ``The turbulent AI era is here. The choices we make now are critical,'' Bill Gates stated: When asked about the infamous AI Hugging Face incident, where swarming of rogue agents from one company hacked their way into another, Gates stated bluntly: The CEO of Anthropic, Dario Amodei, also issued a lengthy statement on this subject entitled ``We Must Pace the Frontier.'' In it, he expressed his concerns about ``the OpenAI-Hugging Face incident''-- these were his words--``in which a swarm of agents essentially acted as a fanatically devoted collective, conducting cybersecurity attacks on targets they were not asked to attack and that were unrelated to the task at hand, sacrificing themselves for the success of the group, and attempting to hack into the `grader' responsible for evaluating their performance.'' Well, he went on to elaborate: He goes on to say: So, on August 7, after the Hugging Face incident was first revealed, Sam Altman, the CEO of OpenAI, spoke about the company's upcoming release, known as Astra. He claimed that it attained what OpenAI called critical cyber security threshold. Well, he said: Well, nevertheless, on September 3, OpenAI released Astra with the addition of certain security guardrails. Then, in response to Dario's essay calling for extreme caution and a slowdown, he tweeted: ``I agree with Dario.'' So the problem here is we have a bunch of people within the industry calling out what are these technology developments, but we--we--need to do something about this. We need to be better informed. We need to do more. Three years ago, we had a chance to get ahead of this issue. In 2024, when I chaired the Senate Commerce Committee, we passed the Future of Artificial Intelligence Innovation Act, which would have given the Federal Government the ability to work with industry to independently test most advanced AI systems for serious national security risk. Now, some of these risks may not have been apparent in the last 2 years, but we would have stood up the muscle of our organization at the Federal level to better detect risks like cyber attacks; risks like chemical, biological, radiological, and nuclear weapons; or threats to our current infrastructure and our energy systems. And we also passed Senators Lujan and Blackburn's TEST AI Act, which would have improved the ability of the Department of Energy to test AI systems for national security issues. Senators Hickenlooper and Capito's VET Artificial Intelligence Act would have established standards so that third-party auditors could test AI systems for safety and security--the very thing that the Anthropic CEO just called out over the weekend. So at a time when we still had a window to get ahead of these dangers, the Federal Government and the people here were denying this opportunity, particularly my colleagues on the other side of the aisle. If we had passed these bills, we would have been more ahead of the game than we are today. Instead, we have lost 3 years. The technology keeps advancing. The risks keep growing. And now the very dangers we have warned about--autonomous cyber attacks and biological weapons--are no longer theoretical. It is time that we act and act aggressively. We must keep in mind that these AI models consistently lag about only 7 months, and the most powerful open models continue to come from China. So it is time for my colleagues to come together to act. We know that these threats are real--cyber security, misinformation-- building on these AI agents that could be used in military applications. We need our colleagues to say ``Stop saying the industry can do what it wants'' and put together the infrastructure at the Federal level that not only has strong Federal standards but also has independent testing and real safeguards for the American people. Now is the time to act. I yield the floor. I suggest the absence of a quorum. The PRESIDING OFFICER (Mr. Banks). The clerk will call the roll. The senior assistant bill clerk proceeded to call the roll.