ai-cybersecuritytrade-pressNewsThe Broadside1 min read

Senate panel urged to mandate AI pre-deployment testing

The proposal would require critical infrastructure operators to test leading AI models before deployment, layering a compliance obligation across both telecom carriers and AI developers.


TL;DR

A Senate Commerce telecom subcommittee hearing July 30 surfaced a concrete policy proposal: Vanderbilt Policy Accelerator's Asad Ramzanali urged Congress to mandate pre-deployment testing of leading AI models for all critical infrastructure operators. Ramzanali anchored the ask in the Salt Typhoon breach (accomplished without AI, he noted) arguing that AI-enabled attackers now compound an already vulnerable baseline. Separately, USTelecom CEO Jonathan Spalter pressed for reauthorizing the Cybersecurity Information Sharing Act of 2015. Cisco's Bob Everson offered the practitioner's checklist: patch relentlessly, retire unpatchable tech debt, enforce MFA, deploy zero trust.

The hearing, chaired by Sen. Deb Fischer (R-NE), was framed around AI's dual role in telecom: it demands low-latency, high-bandwidth networks, but it can also make those networks more efficient and more secure. The testimony, however, quickly turned to security obligations that don't yet exist.

Ramzanali's central recommendation was a pre-deployment testing mandate for leading AI models, covering both closed and open-weight systems. The testing requirement would apply to critical infrastructure operators, not just AI developers, meaning telecom carriers, pipeline operators, and others would need to evaluate AI models for cyber risk before integrating them. "You have to harden the infrastructure that critical infrastructure operators have, and you have to require pre-deployment testing so that the government and critical infrastructure providers know the scope of the threat and can mitigate risks," Ramzanali told Sen. Amy Klobuchar (D-MN). "Those two parts both have to happen."

The Salt Typhoon reference was deliberate. Ramzanali characterized that breach, which compromised at least eight U.S. telecom providers and intercepted communications from presidential candidates, as "low tech, pre-AI," citing an investigation that called U.S. systems "a house full of open windows." The policy logic: if pre-AI intrusions were that damaging, AI-enabled ones demand structural intervention.

Spalter's CISA 2015 reauthorization pitch, directed at Sen. Jacky Rosen (D-NV), was the industry-familiar ask: preserve the liability protections and information-sharing channels that let carriers and government exchange threat data. Everson's advice was blunter and more immediately actionable, patch everything, identify and replace unpatchable gear, enforce multifactor authentication, and adopt zero-trust architecture that doesn't rely on perimeter defenses alone. The gap between Everson's list and Ramzanali's mandate is, in its own way, the story: one describes what operators can do today; the other describes what they might soon be required to do.


Published ·Deep Fathom