The Hacking Policy Council (HPC) submits the following comments in response to the Request for Information (RFI) related to National Institute of Standards and Technology (NIST)’s responsibilities under Sections 4.1, 4.5, and 11 of the recent Artificial Intelligence (AI) Executive Order (EO) 14110. We thank NIST for the opportunity to provide input towards this important proposal.
The HPC is a group of industry experts dedicated to creating a more favorable legal, policy, and business environment for vulnerability management and disclosure, good faith security research, penetration testing, bug bounty programs, and independent repair for security. Many of our members are deeply involved in AI system deployment, testing, and red teaming.
HPC’s comments focus on AI testing and red teaming. As AI systems become increasingly common in a variety of environments, including critical and public applications, ensuring the security, safety, and trustworthiness of AI is a major priority. Testing AI for alignment with evaluation metrics is a key safeguard against poor security, discrimination, bias, inaccuracy, and other harmful or undesirable outputs. However, we also emphasize that testing should be only one component of a security and trustworthiness program that includes risk assessment, vulnerability management, incident response plans, and other safeguards.
Read Next
New Cybersecurity Executive Order, Same Mission: Protecting America's Digital Infrastructure
Since taking office speculation has swirled on what President Trump would do on cybersecurity. A new EO upholds previous messaging and underscores that cybersecurity isn't a partisan battle; it demands nonpartisan solutions to protect the nation.
Dual Drone EOs: A Boost to the Domestic Drone and Counter-Drone Industries
President Trump signed two executive orders with the stated purpose of supporting the domestic drone industry, while also protecting against the threats posed by the misuse and malicious use of drones.
Japan's new Active Cyber Defense Law: A Strategic Evolution in National Cybersecurity
Japan's National Parliament passed the landmark Active Cyber Defense Law, marking a pivotal shift in the country's cybersecurity strategy, encompassing a range of provisions aimed at modernizing Japan's institutions and enhancing cybersecurity.