The Hacking Policy Council (HPC) submits the following comments in response to the Request for Information (RFI) related to National Institute of Standards and Technology (NIST)’s responsibilities under Sections 4.1, 4.5, and 11 of the recent Artificial Intelligence (AI) Executive Order (EO) 14110. We thank NIST for the opportunity to provide input towards this important proposal.

The HPC is a group of industry experts dedicated to creating a more favorable legal, policy, and business environment for vulnerability management and disclosure, good faith security research, penetration testing, bug bounty programs, and independent repair for security. Many of our members are deeply involved in AI system deployment, testing, and red teaming.

HPC’s comments focus on AI testing and red teaming. As AI systems become increasingly common in a variety of environments, including critical and public applications, ensuring the security, safety, and trustworthiness of AI is a major priority. Testing AI for alignment with evaluation metrics is a key safeguard against poor security, discrimination, bias, inaccuracy, and other harmful or undesirable outputs. However, we also emphasize that testing should be only one component of a security and trustworthiness program that includes risk assessment, vulnerability management, incident response plans, and other safeguards.

Read Next

European Commission 2028-2034 Budget Proposal Includes Substantial Increase for Cyber, Digital Programmes

The European Commission presented its initial proposal for the European Union’s 2028-2034 financial framework that, if approved, could authorise nearly EUR 2 trillion in spending over seven years for cyber and other digital efforts.

Congress’ Proposed Chip Security Act Threatens to Create New Cyber Vulnerabilities in U.S. Semiconductors

As the U.S. races toward global AI dominance, a new bill aimed at preventing diversion of innovative U.S. semiconductors to China could inadvertently make those very same chips less secure.

Japanese Regulator Balances Cybersecurity, Competition Concerns In MSCA Implementation Guidelines

Promoting robust competition in the digital space while ensuring cybersecurity protections is challenging. The Japan Fair Trade Commission strikes a crucial balance between these priorities in its May 2025 guidelines.