Episode 193: AI Security and Responsibility in EO 14409
In episode 193 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager sit down with Rob T. Lee, Chief of Research & Chief AI Officer at the SANS Institute, and Brian Calkin, Chief Technology and Innovation Officer at the Center for Internet Security® (CIS®). Together, they discuss AI security and the responsibility of the U.S. government in creating confidence around it, as represented in Executive Order (EO) 14409, "Promoting Advanced Artificial Intelligence Innovation and Security."
Here are some highlights from our episode:
- 00:50. Introductions to Rob and Brian
- 02:32. How to conceptualize confidence around something as complex as AI security
- 04:32. The U.S. government's responsibility to set AI security guardrails as clear expectations
- 08:12. The use of "voluntary" participation to create confidence in the context of EO 14409
- 14:38. How Mythos AI and similar developments affect assessment of frontier AI models
- 17:11. Airport security as an analogy for understanding AI security and privacy concerns
- 18:41. Why cybersecurity is a hard sell until an incident occurs
- 20:50. How AI is quickly becoming critical infrastructure
- 22:53. Furbies as reference for a flexible, iterative benchmarking process for AI security
- 25:50. The need for technical folks to translate AI risks into something understandable
- 28:21. Balancing encouragement of AI innovation with mindfulness of risk
- 31:24. The basics as a foundation for building shared responsibility around AI security
Resources
- Promoting Advanced Artificial Intelligence Innovation and Security
- The Myth of Mythos: What It Means For Information Security
- Episode 190: Separating Mythos AI Fact from Fiction
- The “AI Vulnerability Storm”: Building a “Mythos-ready” Security Program
- Anthropic says it has taken its latest AI models offline to comply with new export controls
- Establishing Essential Cyber Hygiene
- Episode 187: The Role of a CISO as a Strategic Storyteller
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].
As of June 23, 2025, the MS-ISAC has introduced a fee-based membership. Any potential reference to no-cost MS-ISAC services no longer applies.