
The US-China AI competition has quietly become a …
Loading summary
A
Why the US China AI race is turning into a cybersecurity race. We'll dive into it on this episode of Safe Mode. Welcome to Safe Mode. I'm Greg Otto, editor in chief at cyberscoop. Every week we break down the most pressing security issues in technology, providing you the knowledge and the tools to stay ahead of the latest threats, while also taking you behind the scenes of the biggest stories in cybersecurity.
B
An attack is coming. It's about keeping us safe. He's just a disgruntled hacker.
C
She's a super hacker.
B
Stay alert.
A
Stay safe.
D
Stay safe.
B
This is safe mod.
A
Welcome to this week's episode of Safe Mode. I am your host, Greg Otto. In our interview segment this week, we're going to be talking with Booz Allen's Brad Madeiri about, like I said at the top, the US China AI race. Brad has some really interesting feedback on some testing that Booz Allen has done, particularly around the open weight models and the juxtaposition with the frontier models that are being developed by US companies. A really fraught time right now around this. We've seen a lot of petitions in the industry talking about open weight models and there's been talk inside the government about possibly curtailing the use of Chinese open weight models. So very prescient conversation that I have with Brad. But first talking with Tim Starks, senior reporter for cyberscoop. Tim did some yeoman's work for us in terms of looking through some public comments tied to the Circe town halls. DHS has been on a roadshow talking about the regulations that are going to be tied to Circe. And you read through some of the comments, I should say more than some, pretty much all of them. Tell us what you found here.
C
Yeah, I read all of them and then I also talked to some people independently, I think, you know, CERCIA is an acronym that sounds kind of boring. And you know, some of the discussion around it has been a little dry at times, but it is a very important law on the need for critical infrastructure companies to notify the government when they suffer a big incident. And there's been a lot of hand wringing in industry over the years about this. What I was struck by, by the comments and there were, I think there were four town halls and the transcripts were in some cases more than 100 pages long, was the bluntness of industry that at times past they've said, we wish you'd tweak this definition thus and such. But in some cases, if you read the quotes, they were people Just saying, we don't think this should apply to our companies. It was much more, this is what we think should happen for us. Sometimes when industry comments on regulations, it's no surprise at all that they don't want to be regulated as much. But they will couch it in a lot of terms about how this is bad for the country as a whole. It's not just bad for us, the companies, but in some cases they were just outright saying, we just don't think this regulation should apply to our industry sector.
A
So there are a lot of critical infrastructure sectors, 16 and then there are a lot of companies that fall under those sectors. So this, the comments, you know, when we talk about the companies themselves could come from a wide array of companies. Talk about some of the, the actual trade associations and groups that commented on the record to say, no, our companies
B
don't want to do this.
C
Basically, yeah. I think if you look at the way Circe is predicted and how many entities it's projected to affect, and this is. We're talking about a rule that was created in 2024, this different administration, they said this could apply to 300,000 industries or so. And one of the organizations I commented was, we had all the big ones. We had the Chamber of Commerce saying, we think that's too many, that's just too many companies for it to be affecting. Some of the companies were like, if you're defining it, who meets the standard by size or by importance essentially, well, you're going to get so many things because people were saying suppliers to us might be defined as having to. This will apply to them because they contribute to critical infrastructure in some way, shape or form. Then you saw more specific smaller groups talking about chopping it up even further. There were two insurance industry groups not representing the entire insurance industry groups, but I think one of them dealt was like realtors or something. I can't remember the. But a couple different subsectors of the insurance industry saying, this isn't us. You had the Nuclear Energy Institute saying, you've got to cut down on how many of our companies might be affected by this. Let's just use anybody that's already covered under these existing rules. So it was lobbying broadly in some cases, but in some cases very specifically saying, not us, someone else.
A
What was DHS's reaction to this?
C
So DHS's reaction to me was not very helpful, I'm afraid. CISA provided a quote which you always appreciate saying, this is the future. Because I went to them and said, are you going to incorporate this feedback and what's the next step? Because the conversations I had with industry folk separate from this was that we're not getting a lot of guidance from CISA right now. And cisa's comment was pretty broad in saying, this is the website you can go to find out more. And we had these town halls because we wanted to hear from these people, but it didn't directly comment on what they wanted. If you looked at the comments from CISA officials at the town halls, they kind of gave a broad brush of what they wanted it to be. I think that this being a Republican administration and a Republican administration somewhat leaning against regulation on industry as a default stance, I think that there's been a little bit of a sense that they're going to be providing some relief from the things that industry is concerned about here. Nick Anderson said, we don't want this to be a check the box exercise. We want this to be valuable information. So I think that there was one industry source I talked to who said the sense he's getting from CISA is that this is something that CISO will be looking to scale back and kind of have the most basic building blocks here. And then if we need to go back to it and we can add to it later. The concern about this law has not been entirely industry. For what it's worth, I'm talking a lot about what industry said, because that was who was at the town hall. But we have seen some concern from the Hill on both sides of the aisle saying this is just written a little too broadly. It's folding in too much information. Things like concerns about having to, when you report an incident, report a bunch of details about what kind of information security programs you have in place. So I think we can see some of those things probably be scaled back based on the way industry is talking about what they want, the way this administration seems sympathetic, and some of the comments from Nick Anderson and some of the other top officials at CISA about what they were hoping to accomplish with this.
A
And a little part of that, too, based on the overly broad criticisms, is the timeframe, too. This is one of those where it's like, oh, this needs to happen 72 hours or 96 hours after an incident, which I feel like I can understand the pushback there, because sometimes these incidents take, you know, a week or two weeks to really resolve. And think about it in the case of a ransomware attack, like, you may have systems up and running again, but there's still negotiations that might take place or, you know, something to that degree where it's not. This isn't a bank robbery. A direct comparison to a bank robbery.
C
I hear that. You know, one of the things I think is interesting about that is when this law was first being written and popped up on the Hill and became a big deal right after the solar winds breach. The sentiment, I think Mark Warner's bill, the Virginia senator, Democrat, I think his bill said 24 hours for all of it. So 72 hours was the compromise that Congress ended up with. But even that is something that a lot in industry were worried about. That while, yes, I think the case can be made on the side of QUIC that if CISA is going to be able to help people. That's the whole idea of this. Right. It wasn't just to report it. It was. CISA gets the information about a breach fast and then gets it out fast too. But even within that standpoint, there's all these other things that are really fascinating. If you're the kind of person I am who likes reading regulations and finding out what it really does. Where you talk about, well, what constitutes a major incident? Do you report from the moment of discovery? When does this reporting clock start? Does it start when it actually happened? And how do you find that out? And then there was a good amount of the feedback that we've heard over the years. And we heard again with East Town halls, which is 72 hours. We barely have our heads screwed on about this. We don't know what's happening really. We're going to have limited resources. We don't want to be spending that putting together a report to an agency. We want to be spinning it, responding to the attack. So that was there.
A
So then what next? Because I feel like everybody's just kind of hemming and hawing about this. And yet we're just going to keep going down the road until we see something. Something's going to come of this.
C
I think eventually, yeah. I mean, this law was passed in 2022, I believe, and the deadline was for them to have the first rule, like the interim rule in 2024 and then to have it finished in 2025.
A
And it's 2026.
C
And it's 2026. And the latest estimate from the administration in their official regulatory agenda is September 2026. I didn't find anybody who thought that was likely to be the timeframe. And I understand the skepticism. I mean, certainly there have been delays in this that have not been SIS's fault. They have had multiple government shutdowns that have affected DHS specifically, some of it is, you can't say it's CISA's fault, but this administration cut back a lot of personnel. And when the idea of how are we going to implement Socia first came around, Congress was talking about applying a lot of money to this and hiring a bunch of personnel to be able to make the regulation even happen and then to have the people who can receive the reports and do anything with them. So this has been going on for a long time. I think it's probably going to be going on for a longer time. Whoever's fault it is or not, I do think that they want to finish it. That's the impression I get. They do want to make this rule become a thing. But there were people who were proposing in these documents, like, let's just start over completely. Well, if we start over completely, I don't know, we might be looking at another four to five years of this. So I think if they can just make some tweaks, maybe we will see this sometime in the relatively near future. But if they go back to the drawing board pretty completely, we might be talking more years, multiple.
A
Let's hope that's not the case.
C
Yeah, I think even industry doesn't want that. They kind of are like, let's get something done on this. We've been talking about this for so long, there's a lot of impatience. Like, let's go.
A
Tim, great reporting as always. Thanks for talking to us.
C
Thanks.
A
Now to our interview with Booz Allen's Brad Madeiri talking about the AI China AI race. And look, this is a hot topic right now in D.C. lots of talk about open weight models, particularly the ones coming out of China. Kimi K3 Quen Zhu Pei AI Some really interesting conversations around how this all affects cybersecurity, particularly around the fact that the AI companies and big deal cybersecurity companies have been signing petitions to make sure that everybody understands that they welcome open weight models, but they definitely want the US Government to be helping out to push US innovation. Really interesting conversation that looks at how cybersecurity focuses into all of this, particularly around mythos and OpenAI's daybreak and how the Chinese open weight models are really pushing the US Models in a competition. Check out our conversation.
C
All right.
B
Joining us on this week's interview segment for Safe Mode is Brad Mederi, the president of National Cyber for Boost, Alan Hamilton. Brad, sitting with us at a very breakneck time. I feel like at the intersection of AI cybersecurity, national security policy, it's been a whirlwind week, particularly talking about US models versus Chinese models. And I can't think of a better expert who talk about the issue. So thank you for joining us.
D
Hey, thanks for having me today. Excited to be here. This week has been pretty sporty, right?
B
Yeah. So let's talk about the US China race, because I feel like that has really been the focus in Washington this week. And I know that you have said in the past that the US China AI race effectively has become a cyber security race. I'm wondering, to start off, when did that shift really happen for you and what happened to made it click that this is really a cybersecurity space race almost?
D
Yeah. I mean, there's a couple, like for us, key milestones. And it started about a year ago where in cyberspace we, we started looking at the application of AI for offensive cyber operations and how our adversaries were not only investing, but testing AI in cyberspace. Last summer we saw, you know, AI assisted operations. Back in the fall, we saw an open source framework called Villager come out of out of China. And that open source framework was a red teaming tool, but could be used to run agentic operations. That was very interesting in the sense that it did embed key loggers and some other things that, you know, there wasn't pure intent in terms of security research with the tool. Um, we saw the jailbreak of a frontier model last December, and around that time, you know, we said, look, this is really hyper accelerating and you know, the adversary gets a vote in cyberspace. And we're at a, we're at an inflection point where we think the scale is starting to tip from favoring the defender to favoring the attacker.
B
So with those Chinese models, specifically this week or over the past week, we've seen Congress start to say that they're going to launch investigations that look at these models. We saw OSCP leader Michael Kratzios point the finger at K3 moonshot, saying that they distilled their latest model off of anthropics Fable 5. When it comes to these Chinese models like Deep Sea Wen Kimmy and the concerns with distillation, do you find this to be political theater or is there a there there? Because with it being open weight, that, that really throws a wrench into what we're talking about when it comes to a race.
D
I mean, I think distillation attacks are real. And I think, you know, the US Our frontier models are clearly leading the pack in terms of models, and China wants to catch up the easiest and fastest way to Catch up is through distillation. The other interesting, you know, one other Chinese model that I think is really up and coming is Z AI. Right. That's one that we're tracking really closely. But the other piece, so, you know, as we were looking, you know, over the last year in terms of, you know, AI being used in cyberspace, AI used for offensive cyber operations. But we've also taken a hard look and we produced a report back in June that really assessed the Chinese models, many of the ones that you mentioned. And we ask a few strategic questions. One was, know, do these models introduce bias and inferencing? And the second is given context. The context, whether it's a US government, someone from the defense industrial base, a US Federal mission, will those models in writing source code generate more insecure code? And so we ran a comprehensive test, we produced a report, and the answer to those, both of those questions was yes. Chinese models trained on Chinese policy and doctrine do slant towards bias, you know, Chinese bias in inferencing. And when writing code in the context of, you know, a US Federal government, the defense industrial base, those models will produce code with more vulnerabilities than when prompted with, you know, someone not under that context.
B
So you hit on a bunch of stuff that I wanted to dive into. Let's start with Zai or Chupai or I'm not sure what we call it goes back and forth, but glm, we had Armadin founder David Slater on last week and he talked about some of the measurements that he was doing with that and he found it to be very impressive. And I know that there are other experts that say that GLM is on par with what can be done with anthropics models. So given that and given all the noise around trying to ban or do something about Chinese open weight models, is banning the right policy response? Is there a policy response to be had? Because I think about any open source software, once it's out there and free on the Internet, it's kind of tough to put the toothpaste back in the tube.
D
I think it's a really hard problem. I think in general in cybersecurity, what we've seen is tech adoption outpaces cybersecurity controls and policy. And so I think the easy our opinion, should Chinese models be used in US critical infrastructure or national security systems? No.
B
Yeah, probably a no there. Right, right.
D
But the question is, you know, going back to what we tested, right. Will Chinese models produce more vulnerable code? Well, that's as far left, you know, in, in the supply chain as you can almost get at the point of code generation. And it's really difficult to be able to, you know, govern, govern that. And, and so I think that we're at a point where this is a really hard problem. What we counsel our clients on is really, it starts with knowing what models are in your environment. We were talking to someone and, you know, an entity, and they said, oh, we don't use Chinese bottles, we use Kimmy. And we're like, okay. So, you know, I think a lot of this is just education. And one of the reasons that we produced the report that we did was just to create the conversation and the awareness around that. I think once we were aware, once we understand, then we can actually better, you know, start to put in the right mitigations and controls in place.
B
Let's talk to that and talk about that entity that you were talking about there, because it hits upon something that I wanted to talk about. What are those conversations like with enterprise level CISOs, Fortune 500 government CISOs, when, like, no, we don't want to use Chinese models. We're using just this open source. And you're like, oh, hi, I got, I got some news for you. I guess where that came from. Like, what, what are you hearing from CISOs when they realize that it's not just, oh, just go to the Internet and find the code that we need and carry on?
D
I mean, I think that the CISOs understand the issue, are starting to understand the issues. I think what they are struggling with is governance and control. And so shadow AI, it's, it's the new shadow. It's okay. And so, you know, tech is moving fast. The world is moving fast. You know, think about your, your, an enterprise in a competitive environment where you need to modernize your business processes and you need to rapidly adopt AI, you know, to deliver new capabilities to streamline operations, et cetera. You're really focused on the rapid pace of adoption. And I think, you know, it's, it's, it is a race. And I think the CISOs are just, you know, trying to kind of put the right controls and bounds in place to be able to mitigate the risk.
B
So with your report, and I know there's been other reports too, particularly there was one from NIST that looked at Deep seq, which was Deep Seq's most quote, unquote secure model, right. And it said that it was 12 times more likely to follow malicious instructions. So there's the malicious instruction part, there's prompt injection, and there is the vulnerable Code that they might produce too. But is that something that you're just seeing in testing or do you see that starting to trickle out and you're hearing sizzos go, this thing, we put our trust in this thing. And then all of a sudden it turned around. Like, I know there was an instance with Amazon. Amazon AWS had some cloud outages and it turned out that it was because junior engineers were just shipping code and they were like, let's, let's not do that. Let's put some checks in place. So there's a real world example, but I don't know if you're hearing anything else.
D
Right. I mean, I think for, for us, we've seen it mostly in the lab. You know, I think in terms of like software development. I have college kids and, you know, some of them are doing data science, computer science. And, you know, we have a lot of conversations around, okay, these AI tools are great at generating code, but there needs to be sort of a whole set of processes in place to validate the design, to validate the integrity of the code, to test the scalability, etc. And so I think, you know, everyone is, you know, struggling with the pace of adoption. And, and so we have a long way to go.
B
So let's talk about what is actually possibly happening if attackers are leveraging this AI. A lot of it, from what I've seen and what we've written about, doesn't look like there's any really new trade craft. It's just the quote, unquote, traditional tradecraft.
A
Just faster, I think.
B
Is that. Yeah, no, you want to press back on that, that's fine.
D
This is. No, I agree. I mean, this is all about speed and scale. And so, you know, I mentioned last year, right, we saw a series of escalating events in cyberspace. And so we took a strategic step back and we, to understand it, we built a red teaming tool using agentic technologies that automated the kill chain. And we ran that in a lab environment and it was pretty astounding at the sense that the speed and scale, which it could actually do reconnaissance across a network, which it could pinpoint an unpatched vulnerability, which it could throw an exploit, gain initial access and move within an environment. And the challenge is, you know, you only need a small crack in your security, security controls for a moment in time, and AI at the speed and scale can be able to compromise it. So I do believe, and we saw this just recently with hugging face and OpenAI. And so I think we're in a point in Time where to some extent AI is starting to democratize hacking and it lowers the barrier to entry for novices, for criminal organizations. And nation states are going to use it in a very sophisticated way to be able to deliver impacts and effects at speed and scale that I don't think that we've seen before.
B
So with that speed and scale, do the traditional defenses like detection signatures or threat intelligence, do they work or do they just need to run faster? Does AI attacker behaviors need to be measured in a way that doesn't currently exist?
D
I think that, you know, we spend a lot of time talking about like, you know, to start, you know, the strategic question is how do you defend against an agentic attack? And it does come down to you do need the basics in place, right? You need that foundational zero trust controls, you need to have detection and response, you need to have, you know, complete visibility across your network. But I think what, what fundamentally breaks down in many cases is in an enterprise is the fact that we have spent 20 plus years building a cyber defense operating model. And that model looks something like this. You instrument your network and across your network you collect lots of data, you pipeline that into a data lake or a pane of glass and you run analytics against that. You pop alerts, you have analysts that triage those alerts based upon a threshold. You do incident response. And while that process is fine, that process is, tends to be slow and in many cases manual. And so I think that, you know, as an industry, we're coming to grips of what this new attack vector looks like at speed and scale and then how we need to modernize cyber defense to think about it in a different way.
B
So what is that different way of thinking about it?
D
Yeah, so I think, I think a couple of things. One is, I think that we're going to need to push much more processing and actual action remediation out to the edge. Okay. Because you know, what we've seen in our environment when we run our agentic red teaming tool against a medium sized infrastructure, we can compromise an environment with foundational and standard security tools in six minutes. And so think about six minutes when we run that against how a SOC would operate, you know, in, in the real world, you know, at about minute 48 it comes into the analyst at the pane of glass, right? So the attack has already happened. And so I think that we're going to need to get comfortable pushing more detection and actual remediation to the edge. And, and that's hard, right? Because that's a fundamental cultural shift. You Know, today folks are very hesitant to let machines take automated actions around patching and remediation without a human in the loop.
B
Right. I was going to ask, how do you talk to a risk averse, whether it's a government CISO or an enterprise CISO to let software make containment decisions autonomously?
D
I think, I think we're going to, we're learning as we go. You know, I think back to, you know, some of the, you know, I've done some large scale incident responses and the Fortune 100 over the past 15 years and I can think of cases where there was a compromise and shortly after there's a decision, do we patch or do we move forward? And we moved forward. And you know, that customer decided to move forward because the risk to their, their, their enterprise business was, was too large. I think that we're at a point now where that calculus is going to start to change as we start to better understand the threat. I think that's going, and the capability, I think that's going to push the conversation so we get much more comfortable with that.
B
So talking a little bit more about the technology itself is, you know, you've argued that AI and cybersecurity are basically merging into the same discipline at this point. What does that convergence actually look like inside an organization? Even beyond what we were just talking about here saying that push it to the edge, let it be a little bit more autonomous. What else is going to happen as this continues to sort of blend together?
D
Yeah, it's funny, rsa. Someone described the RSA Cybersecurity conference this year as an AI conference.
B
It was, I was there definitely was.
D
And so, you know, there were, there were 9,000 products, 4,500 of them were cyber AI products and the other 4,500 were zero trust products. So I think that we are, we are, we are norming around a set of buzzwords in this industry. And so to answer your question, in terms of what, what I think this looks like in the future, I think there's a couple of things. One, and I think we maybe take them in bite sized chunks.
B
Okay.
D
The first is what's the impact of Mythos on an enterprise? And that's a really interesting question. And so Mythos came out and Mythos is really good at discovering complex vulnerabilities and be able to chain those together into exploits. And so there's really kind of two implications there. One is as part of project Glasswing, you know, companies like Microsoft, Palo Cisco are all now using capabilities like this. Whether it's Mythos or another frontier model to discover vulnerabilities in their code. And so now what we're seeing is an unprecedented number of patches. Think about, you know, June, just a month ago in June Patch Tuesday, Microsoft released 200 new patch vulnerabilities, right?
B
And the July one I think was
A
their biggest one ever.
B
And they attributed a big part of
D
that to AI 600, 622. And by the way, July is usually the slow month because of, because, because of PTO. So think about an enterprise, you're sitting in a CISO or a CIO seat. You, you have and that's just micro 622 is just Microsoft. Think about how many product vendors that you have in your enterprise that you need to patch and remediate, right?
B
I get emails all the time now about security updates on, you know, enterprise IT level things and they say in the emails like we found this, right, because we were running Mythos or Daybreak
D
or some other type of model, right? So when you're in the seat you're going to get, you know, from all of your vendors a tremendous amount of patches that you know, you're going to need armies, swarms to be able to go out and address. Then you're going to run Mythos against your internal systems and that's going to be a whole new set of vulnerabilities. And so I think the question is, you know, you're going to have this big mound of stuff, you're going to have a finite set of resources and so what does vulnerability management look like in the future? And I think that we have been, you know, in a, in a mode of, you know, looking at vulnerabilities based upon criticality. But I think that that calculus is going to change. We're going to have to apply more of a business risk, business and mission risk lens to that. But I think that, you know, everyone is going to struggle in the near term with patches and vulnerabilities. I think, I think the second piece is as this agentic AI enabled hacking comes into play and it's moving extremely fast. You know, two examples I use, one is there was a couple weeks ago, I think it was an Ethiopian using Claude and Codex compromised 14 US and US companies and was able to actually use the models to be able to find important data on the, on the enterprise, prioritize it. And you know, that was a pretty novice hacker. We know that because they were caught because they also used the model to write their resume and they exposed all their personal information. But the real and, and then we saw, you know, the OpenAI hugging face just, just this week which was publicly announced where the OpenAI model escaped out of the boundary and compromised hugging face and the gentic, you know, autonomous way. So you know, the first piece is vulnerability. The second piece, with this agentic kill chain coming online, I think that enterprises are going to be really forced to modernize their security operations. And from a security operations perspective they're going to need to be more automated, they're going to need to do, you know, implement agents in their enterprise to be able to backstop and augment the humans, to be able to move at a much more rapid pace. And so I think we're going to see a lot of focus around SOC modernization there. And then I think that where we have to go and we probably need to go there faster than what we think we need to now, it's just then moving into more automated patching and remediation. So I think we're on this journey. You know, it's going to start with really getting our arms around what this next gen vulnerability management is. Then we're going to need to think about how do we automate and identify, if that's a word, how do we AI enable at our security operations. And then we're really going to need to get comfortable with more, more automated remediation because the only way that we're going a defender is going to be able to kind of tip the advantage is to be able to actually do response at machine speed, likely without human in the loop.
A
So those are all interesting points and
B
when I hear you say that, I think back to something CISA Academy director Nick Anderson said at a conference that I was at and you talked about next gen vulnerability management. But I almost wonder if it's like a next gen risk management thing where because what Director Anderson said he was like, basically the idea was we're going to find all of these, but you really have to have deep hard conversations about what the risk is to your enterprise because you're just not going to be able to patch everything that comes out. Like you need to really think about what could affect your enterprise more than anything else. Otherwise you're going to be drowning in CVEs for, for all of eternity. So I'm wondering whether you think that that may be where the conversation is headed. Because like just going back to patch Tuesday, I can only imagine the multiplying effects of Microsoft releasing 600 vulnerabilities and that across Microsoft's gargantuan customer base, nobody's ever going to be able to patch all of those just off of that report. So is it more so that the vulnerability management needs to transform into a different conversation about risk?
D
I think so. I mean, we've been, you know, as a cyber security professional, you know, we've been talking about this for 20 years. Right. And, you know, back in, you know, back in the early 2000s in DoD, there was a something called netops. And netops was all about understanding and overlaying mission risk around cybersecurity. We've kind of been on that journey for a long time. I think this is going to accelerate and really focus that conversation because we can't operate the way we have in the past. It doesn't scale, it's too costly, and it's not fast.
B
So do you think that there are any other policy levers to throw here? Because I think about the Kev list and again, what Acting Director Anderson said, and I think he's starting to think about it differently. But in your opinion, are there any other levers that Washington could throw that could help ease this tidal wave of vulnerabilities being found?
D
I mean, I think that we're in a really interesting time. I think some of the executive orders that we've seen come out talking about the application of AI for cyber defense. I think that is going to be important. And so I think that everyone is trying to do the right thing. We're learning as we go. The tech world is evolving, I think, you know, faster than I've seen since really the dot com era back in the late 90s. And it's a wild ride. You know, I mean, we started off, wow, a lot's happened this week. Well, a lot happened last week, and a lot happened the week before. A lot's going to happen next week.
B
Right.
D
And so I think it's really hard to write policy that keeps up with the pace of this technology change.
B
So back to what we were talking about at the beginning of this conversation with this AI race between us and China, what do you think happens in terms of winning or is winning the wrong way to frame it? Do we just out innovate or is there sort of a detente or a diplomatic approach where US and Chinese models all work together in harmony?
D
Yeah, it's a great question. Keep in mind, you're asking a techie, and so the techie answer is always out innovate. And so I bet on us on the United States to, you know, really move faster. We're leading in hardware, we're leading in the frontier models. And I think that we need to keep keep accelerating. I think there's going to be a lot of interesting conversations within the US around regulation. I think regulation is important, but I also think that China and other entities don't look at it the same way. And so what is a world where we have regulation and guardrails and China doesn't? And so, you know, I think there's going to be a lot of conversations that need to be had around that.
B
Interesting. Brad, really appreciate you hopping aboard to discuss all of this. Like you said, it's moving so fast and I can only imagine where the next couple months are going to take us. So appreciate it.
D
Yeah, great conversation. Thank you.
A
Thanks for listening to Safe Mode, a weekly podcast on cyber security and digital privacy, brought to you by cyberscoop. If you enjoyed this episode, please leave a rating and a review and share it with your friends, your co workers, your sizzos, your sysadmins, your mom, your dad. Anybody that wants to know more about cyber security. To find out more information or to contact me, please look for all of our social media handles or visit cyberscoop.com thanks for listening. Check us out next week.
Episode Title: Why Cybersecurity is at the Heart of the US-China AI Race
Date: July 30, 2026
Host: Greg Otto (Editor-in-chief, Cyberscoop)
Guests:
This episode delves deep into the growing overlap between the US–China competition in AI and the vital role cybersecurity now plays within that race. The show first covers the regulatory tensions around critical cyber incident reporting (CIRCIA) in the US, then pivots to an in-depth discussion with cybersecurity leader Brad Madeiri on how AI models—particularly those developed and released by Chinese companies—have shifted the strategic cybersecurity landscape. The episode explores offensive and defensive uses of AI, the implications of open-weight models, operational realities for CISOs, and the evolving policy outlook.
Timestamps: 00:35–11:11
Industry Comments on CIRCIA:
Tim Starks discusses wide-ranging and often blunt feedback from industry about the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA)—noting a fundamental concern that the regulation is too broad and affects too many companies, including suppliers and subsectors.
DHS/CISA Response:
The Department of Homeland Security’s responses are described as vague with an emphasis on intention rather than detail. CISA officials have suggested a willingness to scale back requirements, citing both industry and some Congressional concerns.
Timelines and Delays:
The regulation is far behind schedule (law passed in 2022, first interim rule supposed to finish by 2025, now delayed well into late 2026 or beyond, with skepticism about timely delivery).
Timestamps: 12:12–36:21
Distillation and Copying Risks:
Distillation—training domestic models to mimic proprietary western models—is real, and “open-weight” models from China are rapidly improving.
Security Concerns:
Booz Allen’s testing shows that, given a US enterprise or government context, these Chinese models produce code with more vulnerabilities and introduce Chinese policy bias.
Banning Open-Weight Models?
The panel assesses that banning is infeasible—open-source code is hard to restrict, and awareness/education is currently the most practical strategy.
Shadow AI in Enterprises:
Many organizations may unwittingly import risky models. New governance challenges emerge ("shadow AI" is the new "shadow IT").
Traditional Tactics, Exponential Speed:
Attacks are not novel but their speed and automation are. Booz Allen’s AI red team tool compromised standard security-protected environment in minutes.
Democratization of Hacking:
AI lowers the barrier to entry and increases sophistication—both nation states and individual actors use agentic tools.
Current Cyber Operations Too Slow:
The classic “collect + alert + manual response” operation model is incompatible with the speed of modern AI attacks.
Push Remediation to the Edge:
Organizations must enable more autonomous detection/remediation—this is a cultural shift, especially in highly risk-averse environments.
Modernization Path:
AI Finds More Flaws:
With tools like Mythos, vendors are discovering and patching an unprecedented number of vulnerabilities.
CISO Overwhelm:
Patching cannot keep up; organizations must apply business/mission risk assessment to triage.
Autonomous Attacks:
Regulation: US vs. China Approaches
“The scale is starting to tip from favoring the defender to favoring the attacker.”
(13:18, Brad Madeiri)
“Distillation attacks are real...China wants to catch up. The easiest and fastest way...is through distillation.”
(15:04, Brad Madeiri)
“Should Chinese models be used in US critical infrastructure or national security systems? No.”
(17:48, Brad Madeiri)
“Shadow AI, it's the new shadow [IT].”
(19:17, Brad Madeiri)
“AI is starting to democratize hacking and...nation states are going to use it in a very sophisticated way to deliver impacts and effects at speed and scale that I don't think that we've seen before.”
(22:50, Brad Madeiri)
“We can compromise an environment...in six minutes...at about minute 48, it comes into the analyst at the pane of glass, right? So the attack has already happened.”
(24:58, Brad Madeiri)
“I think we're going to see a lot of focus around SOC modernization...to move at a much more rapid pace.”
(30:28, Brad Madeiri)
“You're just not going to be able to patch everything that comes out...Otherwise you're going to be drowning in CVEs for, for all of eternity.”
(32:11, Greg Otto)
“It's a wild ride...the tech world is evolving, I think, faster than I've seen since really the dot com era back in the late 90s.”
(34:16, Brad Madeiri)
This episode underscores how the rapid evolution of AI—especially the proliferation of open-weight models from China—has fundamentally transformed the cybersecurity landscape, shifting the balance of power towards attackers and demanding faster, more automated, risk-focused defenses. The regulatory environment remains tangled, and US organizations must adapt quickly if they are to retain their advantage in a complex, fast-moving US–China AI/cybersecurity contest.
Whether you are an executive, CISO, policymaker, or just a cybersecurity enthusiast, this episode distills the most urgent debates and operational transformations facing organizations in 2026 as AI and cybersecurity become inseparable facets of the new technological arms race.