The Hacking Policy Council (HPC) submits the following comments in response to the Request for Information (RFI) related to National Institute of Standards and Technology (NIST)’s responsibilities under Sections 4.1, 4.5, and 11 of the recent Artificial Intelligence (AI) Executive Order (EO) 14110. We thank NIST for the opportunity to provide input towards this important proposal.

The HPC is a group of industry experts dedicated to creating a more favorable legal, policy, and business environment for vulnerability management and disclosure, good faith security research, penetration testing, bug bounty programs, and independent repair for security. Many of our members are deeply involved in AI system deployment, testing, and red teaming.

HPC’s comments focus on AI testing and red teaming. As AI systems become increasingly common in a variety of environments, including critical and public applications, ensuring the security, safety, and trustworthiness of AI is a major priority. Testing AI for alignment with evaluation metrics is a key safeguard against poor security, discrimination, bias, inaccuracy, and other harmful or undesirable outputs. However, we also emphasize that testing should be only one component of a security and trustworthiness program that includes risk assessment, vulnerability management, incident response plans, and other safeguards.

Read Next

EU’s Cyber Resilience Act Enters Into Force

New product cybersecurity requirements are coming to the EU single market after years of intense debate and negotiation in Brussels, as the European Union’s Cyber Resilience Act officially enters into force.

Through the Looking Glass: An Updated Vision for the Office of the National Cyber Director

The ONCD was established to advise the President on cybersecurity and has matured into a key component of cybersecurity policymaking. However, changes are needed to ensure the efficacy of the office, especially as it relates to other agencies.

The U.S. Data Security EO with Lee Licata and Grant Dasher (Part 2)

For the first time in the Distilling Cyber Policy podcast, Alex and Jen are re-joined by guests from earlier this season: Lee Licata, from the Department of Justice, and Grant Dasher, from CISA.