AI cyber risks and China rivalry dominate US Congressional hearing

Share:
Audio Loading voice…
AI cyber risks and China rivalry dominate US Congressional hearing

Synopsis

A US Congressional hearing on 7 June exposed a stark reality: AI is already being used by criminals to develop zero-day exploits, and China's low-cost AI models could quietly colonise Western critical infrastructure if Washington falls behind. The double-edged nature of frontier AI — defender's shield and attacker's weapon simultaneously — is now a legislative emergency, not a hypothetical.

Key Takeaways

The House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection convened an AI cyber risk hearing on 7 June 2025 .
Google Threat Intelligence VP Sandra Joyce testified that AI has already been used to develop a zero-day exploit by cyber criminals — a first-of-its-kind confirmed instance.
Frontier Model Forum's Chris Meserole warned that 'adversarial distillation' could allow foreign actors to replicate advanced AI capabilities while removing safety protections.
China was repeatedly cited as the primary strategic rival, with witnesses warning that low-cost Chinese AI could dominate cloud computing and critical infrastructure globally.
President Trump signed an executive order ahead of the hearing directing agencies to build a framework for evaluating AI cyber capabilities.
The Electronic Frontier Foundation cautioned that AI-powered surveillance tools require stronger legal safeguards to protect civil liberties.

Artificial intelligence is fundamentally reshaping the cybersecurity landscape — simultaneously arming defenders and handing adversaries powerful new attack tools — technology experts and lawmakers warned during a US Congressional hearing on 7 June 2025. The session, convened by the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection, underscored mounting anxiety in Washington over AI-enabled threats to critical infrastructure and the intensifying technology rivalry with China.

The Hearing's Central Warning

The hearing followed President Donald Trump signing an executive order directing federal agencies to develop a framework for evaluating advanced AI cyber capabilities and expanding frontier AI model access for government and critical infrastructure operators. Subcommittee Chairman Andy Ogles set the tone early. 'These models are already reshaping the threat landscape, and the federal government cannot be the last to understand what they can do,' he said.

AI Already Weaponised by Criminals

Sandra Joyce, Vice President of Google Threat Intelligence Group, told the subcommittee that AI has moved beyond theoretical threat status. 'Those concerns were validated recently when we discovered evidence for the first time that AI was used to develop a zero-day exploit by cyber criminals,' she testified. Joyce warned that attackers are now leveraging AI to identify vulnerabilities and traverse networks at speeds that outpace conventional security response. 'Threat actors are able to move rapidly before and after gaining access to a network using AI. They can take advantage of vulnerabilities faster than we can patch, and they can move rapidly through networks using autonomous agents,' she said.

Jack Cable, Chief Executive Officer of Corridor Security and a former adviser at the Cybersecurity and Infrastructure Security Agency (CISA), reinforced that assessment. 'The central challenge is not that AI creates new categories of vulnerabilities. It's that AI dramatically increases the speed and scale at which vulnerabilities can be introduced, found, and exploited,' he said. Cable argued that the focus must shift to preventing vulnerabilities before software is deployed, rather than relying solely on post-discovery remediation.

The Double-Edged Nature of Frontier AI

Chris Meserole, Executive Director of the Frontier Model Forum, highlighted the dual-use dilemma at the heart of advanced AI systems. 'An agent that finds zero-day vulnerabilities can protect us in the hands of a defender but expose us in the hands of an attacker,' he said. Meserole raised particular concern over a technique called 'adversarial distillation,' through which foreign actors could replicate the capabilities of cutting-edge AI models while stripping away their safety guardrails. 'Foreign actors can use distillation to accelerate their own AI development and leverage the capabilities they gain against US critical infrastructure,' he warned.

China as the Defining Rival

China emerged as a recurring flashpoint throughout the hearing. Witnesses cautioned that low-cost Chinese AI systems could achieve widespread adoption across software development, cloud computing, and critical infrastructure if the United States fails to maintain its competitive edge. Joyce was blunt: 'I don't think there's a prize for second place in the AI race, nor is there one in the quantum race.' She noted that Chinese cyber groups have already demonstrated the ability to infiltrate critical infrastructure networks, framing AI leadership as a direct national security imperative. This comes amid broader US-China technology tensions, including export controls on advanced semiconductors and restrictions on Chinese software platforms.

Privacy and Civil Liberties Concerns

Democratic lawmakers raised a parallel set of concerns around domestic surveillance. Matthew Guariglia, a senior policy analyst at the Electronic Frontier Foundation, cautioned that AI-powered tools could dramatically expand government surveillance capabilities unless accompanied by stronger legal safeguards and transparency requirements. The warning reflects a growing tension in Washington between national security imperatives and civil liberties protections — a debate that is likely to intensify as AI capabilities advance. With the Trump administration's executive order now in motion, the hearing signals that Congress is moving toward a more structured legislative response to AI-driven cyber risk.

Point of View

While adversaries are already operational. The adversarial distillation warning is also underreported: it means that US safety investments in frontier models may be systematically neutralised by foreign replication, rendering export controls on hardware insufficient on their own. The civil liberties thread, raised by Democrats, risks being drowned out — but it is the domestic counterweight that will define whether AI security tools become a surveillance apparatus or a genuine public good.
NationPress
23 Jul 2026

Frequently Asked Questions

What was the US Congressional AI cybersecurity hearing about?
The hearing, held on 7 June 2025 by the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection, examined how artificial intelligence is transforming cyber threats to US critical infrastructure. Experts testified on AI-enabled attacks, China's growing AI capabilities, and the dual-use risks of frontier AI models.
Has AI actually been used in a real cyber attack?
Yes, according to testimony from Google Threat Intelligence VP Sandra Joyce. She told the subcommittee that her team discovered evidence — for the first time — that AI was used to develop a zero-day exploit by cyber criminals, confirming that AI-assisted attacks have moved from theory to practice.
What is adversarial distillation and why does it matter?
Adversarial distillation is a technique by which foreign actors can replicate the capabilities of advanced AI systems while stripping away their safety protections, according to Frontier Model Forum Executive Director Chris Meserole. It matters because it could allow rivals like China to accelerate AI development and weaponise those capabilities against US critical infrastructure, even if access to the original models is restricted.
Why is China a concern in the context of AI cybersecurity?
Witnesses warned that low-cost Chinese AI systems could become dominant across software development, cloud computing, and critical infrastructure globally if the US loses its competitive edge. Google's Sandra Joyce also noted that Chinese cyber groups have already demonstrated the ability to infiltrate critical infrastructure networks, making AI leadership a national security issue.
What has the Trump administration done in response to AI cyber risks?
President Donald Trump signed an executive order directing federal agencies to develop a framework for evaluating advanced AI cyber capabilities and expanding access to frontier AI models for government and critical infrastructure operators. The Congressional hearing followed shortly after, signalling legislative momentum toward a more structured policy response.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 18 hours ago
  2. 2 weeks ago
  3. 3 weeks ago
  4. 3 weeks ago
  5. 1 month ago
  6. 1 month ago
  7. 1 month ago
  8. 6 months ago
Google Prefer NP
On Google