[House Hearing, 118 Congress]
[From the U.S. Government Publishing Office]


                        BALANCING KNOWLEDGE AND
                        GOVERNANCE: FOUNDATIONS
                     FOR EFFECTIVE RISK MANAGEMENT
                       OF ARTIFICIAL INTELLIGENCE
=======================================================================                                   

                                HEARING

                               BEFORE THE

                     SUBCOMMITTEE ON INVESTIGATIONS
                             AND OVERSIGHT
                SUBCOMMITTEE ON RESEARCH AND TECHNOLOGY

                                 OF THE

                      COMMITTEE ON SCIENCE, SPACE,
                             AND TECHNOLOGY

                                 OF THE

                        HOUSE OF REPRESENTATIVES

                    ONE HUNDRED EIGHTEENTH CONGRESS

                             FIRST SESSION

                               __________

                            OCTOBER 18, 2023

                               __________

                           Serial No. 118-27

                               __________

 Printed for the use of the Committee on Science, Space, and Technology
 
 [GRAPHIC NOT AVAILABLE IN TIFF FORMAT]

                                __________

                   U.S. GOVERNMENT PUBLISHING OFFICE                    
53-782PDF                  WASHINGTON : 2025                  
          
-----------------------------------------------------------------------------------     

       Available via the World Wide Web: http://science.house.gov

              COMMITTEE ON SCIENCE, SPACE, AND TECHNOLOGY

                  HON. FRANK LUCAS, Oklahoma, Chairman
BILL POSEY, Florida                  ZOE LOFGREN, California, Ranking 
RANDY WEBER, Texas                       Member
BRIAN BABIN, Texas                   SUZANNE BONAMICI, Oregon
JIM BAIRD, Indiana                   HALEY STEVENS, Michigan
DANIEL WEBSTER, Florida              JAMAAL BOWMAN, New York
MIKE GARCIA, California              DEBORAH ROSS, North Carolina
STEPHANIE BICE, Oklahoma             ERIC SORENSEN, Illinois
JAY OBERNOLTE, California            ANDREA SALINAS, Oregon
CHUCK FLEISCHMANN, Tennessee         VALERIE FOUSHEE, North Carolina
DARRELL ISSA, California             KEVIN MULLIN, California
RICK CRAWFORD, Arkansas              JEFF JACKSON, North Carolina
CLAUDIA TENNEY, New York             EMILIA SYKES, Ohio
RYAN ZINKE, Montana                  MAXWELL FROST, Florida
SCOTT FRANKLIN, Florida              YADIRA CARAVEO, Colorado
DALE STRONG, Alabama                 SUMMER LEE, Pennsylvania
MAX MILLER, Ohio                     JENNIFER McCLELLAN, Virginia
RICH McCORMICK, Georgia              TED LIEU, California
MIKE COLLINS, Georgia                SEAN CASTEN, Illinois,
BRANDON WILLIAMS, New York             Vice Ranking Member
TOM KEAN, New Jersey                 PAUL TONKO, New York
VACANCY
                                 ------                                

              Subcommittee on Investigations and Oversight

                HON. JAY OBERNOLTE, California, Chairman
BRIAN BABIN, Texas                   VALERIE FOUSHEE, North Carolina, 
MAX MILLER, Ohio                         Ranking Member
RICH McCORMICK, Georgia              KEVIN MULLIN, California
VACANCY                              JEFF JACKSON, North Carolina
                                 ------                                

                Subcommittee on Research and Technology

                  HON. MIKE COLLINS, Georgia, Chairman
JIM BAIRD, Indiana                   HALEY STEVENS, Michigan, 
DARRELL ISSA, California                 Ranking Member
RICK CRAWFORD, Arkansas              ANDREA SALINAS, Oregon
SCOTT FRANKLIN, Florida              KEVIN MULLIN, California
BRANDON WILLIAMS, New York           EMILIA SYKES, Ohio
TOM KEAN, New Jersey                 SUZANNE BONAMICI, Oregon
                        
                        
                        C  O  N  T  E  N  T  S

                            October 18, 2023

                                                                   Page

Hearing Charter..................................................     2

                           Opening Statements

Statement by Representative Jay Obernolte, Chairman, Subcommittee 
  on Investigations and Oversight, Committee on Science, Space, 
  and Technology, U.S. House of Representatives..................    11
    Written Statement............................................    13

Statement by Representative Valerie Foushee, Ranking Member, 
  Subcommittee on Investigations and Oversight, Committee on 
  Science, Space, and Technology, U.S. House of Representatives..    14
    Written Statement............................................    15

Statement by Representative Mike Collins, Chairman, Subcommittee 
  on Research and Technology, Committee on Science, Space, and 
  Technology, U.S. House of Representatives......................    16
    Written Statement............................................    17

Statement by Representative Haley Stevens, Ranking Member, 
  Subcommittee on Research and Technology, Committee on Science, 
  Space, and Technology, U.S. House of Representatives...........    17
    Written Statement............................................    18

Written statement by Representative Frank Lucas, Chairman, 
  Committee on Science, Space, and Technology, U.S. House of 
  Representatives................................................    19

Written statement by Representative Zoe Lofgren, Ranking Member, 
  Committee on Science, Space, and Technology, U.S. House of 
  Representatives................................................    68

                               Witnesses:

Ms. Elham Tabassi, Associate Director for Emerging Technologies, 
  Information Technology Laboratory, National Institute of 
  Standards and Technology
    Oral Statement...............................................    20
    Written Statement............................................    22

Mr. Michael Kratsios, Managing Director, Scale AI 4th Chief 
  Technology Officer of the United States
    Oral Statement...............................................    33
    Written Statement............................................    36

Dr. Emily M. Bender, Professor of Linguistics, University of 
  Washington
    Oral Statement...............................................    42
    Written Statement............................................    44

Mr. Caleb Watney, Co-CEO, Institute for Progress
    Oral Statement...............................................    50
    Written Statement............................................    52

Discussion.......................................................    60

             Appendix I: Answers to Post-Hearing Questions

Ms. Elham Tabassi, Associate Director for Emerging Technologies, 
  Information Technology Laboratory, National Institute of 
  Standards and Technology.......................................    86

Mr. Michael Kratsios, Managing Director, Scale AI 4th Chief 
  Technology Officer of the United States........................    95

Dr. Emily M. Bender, Professor of Linguistics, University of 
  Washington.....................................................    98

Mr. Caleb Watney, Co-CEO, Institute for Progress.................   102

            Appendix II: Additional Material for the Record

Statement submitted by Representative Valerie Foushee, Ranking 
  Member, Subcommittee on Investigations and Oversight, Committee 
  on Science, Space, and Technology, U.S. House of 
  Representatives
    Statement for the Record of Rep. Anna G. Eshoo...............   106

Letter submitted by Representative Haley Stevens, Ranking Member, 
  Subcommittee on Research and Technology, Committee on Science, 
  Space, and Technology, U.S. House of Representatives
    Merve Hickok, President, et al., Center for AI and Digital 
      Policy.....................................................   107

Article submitted by Representative Suzanne Bonamici, Committee 
  on Science, Space, and Technology, U.S. House of 
  Representatives
    ``How Flawed Data Aggravates Inequality in Credit,'' Edmund 
      L. Andrews, HAI, Stanford University.......................   116

 
                        BALANCING KNOWLEDGE AND
                        GOVERNANCE: FOUNDATIONS
                     FOR EFFECTIVE RISK MANAGEMENT
                       OF ARTIFICIAL INTELLIGENCE

                              ----------                              


                      WEDNESDAY, OCTOBER 18, 2023

        House of Representatives, Subcommittee on 
            Investigations and Oversight joint with the 
            Subcommittee on Research and Technology, 
            Committee on Science, Space, and Technology,
                                                   Washington, D.C.
    The Subcommittees met, pursuant to notice, at 2:33 p.m., in 
room 2318 of the Rayburn House Office Building, Hon. Jay 
Obernolte [Chairman of the Subcommittee on Investigations and 
Oversight] presiding.
[GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]

    Chairman Obernolte. The joint hearing will come to order. 
Without objection, the Chair is authorized to declare a recess 
of the hearing at any time.
    I'd like to welcome everyone today to today's hearing 
entitled ``Balancing Knowledge and Governance: Foundations for 
Effective Risk Management of Artificial Intelligence (AI).'' I 
now recognize myself for five minutes for an opening statement.
    I'd like to welcome everyone to what I am hopeful will be a 
very fruitful discussion on foundational questions that 
Congress needs to answer to ensure that we strike a careful 
balance between protecting consumers and protecting innovation 
as we create a regulatory framework for artificial 
intelligence.
    Earlier this summer, the Science Committee held a hearing 
to explore how Congress can ensure that AI technology advances 
our national interest. One of the unifying takeaways from that 
hearing was that there remains a number of unsolved technical 
challenges, which, if we address them, would advance innovation 
while making AI systems safer, more transparent, and more 
easily--easier to implement guardrails around.
    Today's hearing will buildupon that theme by exploring how 
the Science Committee can support research, testing, and the 
development of methods and tools for managing AI risks. These 
tools and methods will be critical to the good governance of 
these systems as Congress examines how we should regulate 
artificial intelligence.
    I believe that foundational research on AI is a necessary 
precondition for safer systems. While regulations can make 
undesirable actions unlawful, technological advances in 
coordination with other countries and monitoring who has access 
to the compute necessary to train frontier AI models and how 
it's being put to use will be critical tools in supporting and 
enforcing these regulations.
    One example of this is the use of confidential computing to 
make the theft of AI models more difficult. It is currently 
relatively straightforward to steal an AI model because the 
data needed to operate the model, known technically as the 
model weights, is stored in raw data files. Stealing these 
files would allow criminals to use the model without spending 
the millions of dollars on compute and data necessary to train 
and develop the model. Stricter cybersecurity laws can only go 
so far in preventing this from occurring. However, recent 
research into confidential computing could potentially enable 
the model to be operated without allowing access to the model 
weights, rendering cyber theft of the model impossible and 
addressing the root causes of this problem.
    Another challenge that advances in research can help 
resolve is identifying whether AI has been used to generate 
content. It's clear that instances of identity fraud, 
plagiarism, and a host of other issues will become more and 
more common as the power of AI tools increase. Watermarking is 
a technique where digital content is encrypted with a unique, 
often hidden identifier that provides information about its 
origin. Watermarking has the potential to identify the origin 
of any content, regardless of how it was created or digitally 
altered. Although current discussions of watermarking center on 
desire that all AI-generated content be watermarked, 
watermarking can also use to prove the provenance of authentic 
content. In fact, I believe it's entirely possible that in the 
future, people might automatically assume that any content is 
AI generated unless its watermark proves its authenticity. 
Solving this technical problem would enable a new set of good 
governance tools concerning generative AI that were previously 
infeasible.
    These examples illustrate the fact that research and policy 
are not mutually exclusive but, in fact, are mutually 
dependent. Research advances unlock previously unpractical 
approaches to regulation, and smart policy accelerates 
research.
    I believe we must also standardize technical definitions 
for methodologies, risks, and technological concepts across all 
of our agencies of government. The NIST (National Institute of 
Standards and Technology) AI Risk Management Framework (AI RMF) 
lays out a foundation that other agencies can buildupon. As 
these agencies consider passing rules or using procurement 
authorities to incentivize good behavior, they should also 
ensure a consistent methodology for assessing risk levels and 
tailor their policies accordingly.
    Another technical area in which Congress has a crucial role 
to play is promoting and establishing best practices. This 
includes everything from technical standards and evaluation 
benchmarks to testing the trustworthiness and risks of AI 
systems. And let us not forget that Congress should certainly 
not rush to overregulate, but we should also not be complacent. 
The United States must avoid falling behind other major world 
powers who are finalizing their AI standards and regulations. 
Without proactive American leadership, supremacy in AI could be 
seized by the EU or China, both of whom are taking far more 
draconian approaches to AI regulation. Because the United 
States currently leads the rest of the world in AI research and 
development (R&D), it makes no sense for us to stand by while 
American companies are forced to either make educated guesses 
or to play by others' rules.
    We must also ensure that our academic institutions continue 
to play an active role in research and development of AI and 
that the transparent system of publication and peer review that 
has enabled its success thus far is not replaced with an opaque 
system where cutting-edge research is only performed by 
corporations. This is why I believe it's critical that we 
establish a National Artificial Resource--Research Resource--
NAIRR, we call it--as a shared national research infrastructure 
to ensure researchers have access to the tools needed to test, 
develop, and create new AI-backed technologies.
    This idea was proposed earlier this Congress when I joined 
my fellow AI caucus chairs in introducing H.R. 5077, the 
Creating Resources for Every American to Experiment with 
Artificial Intelligence Act, or the CREATE Act we call it. See 
what we did there. Establishing a shared computing and data 
infrastructure resource such as that detailed in the act would 
democratize access to AI by providing researchers and students 
across scientific fields and disciplines with access to compute 
resources and high-quality data, along with the appropriate 
educational tools and user support.
    I would like to thank all of our witnesses for taking the 
time this afternoon to join us for this important discussion. 
I'm looking forward to hearing your recommendations to how this 
Committee can strengthen our Nation's leadership in artificial 
intelligence and set clear rules for the safe, responsible, and 
human-centered development of this exciting new technology.
    [The prepared statement of Chairman Obernolte follows:]

    Good afternoon. Welcome to what I am hopeful will be a very 
fruitful discussion on foundational questions Congress needs to 
answer to ensure that we strike a careful balance between 
protecting consumers and protecting innovation as we create a 
regulatory framework for artificial intelligence.
    Earlier this summer the Science Committee held a hearing to 
explore how Congress can ensure that AI technology advances our 
national interest.
    One of the unifying takeaways was that there remains a 
number of unsolved technical challenges which, if addressed, 
would advance innovation while making AI systems safer, more 
transparent, and easier to implement guardrails around.
    Today's hearing will build upon that theme by exploring how 
the Science Committee can support research, testing, and the 
deployment of methods and tools for managing AI risks. These 
tools and methods will be critical to the good governance of 
these systems as Congress examines how it should regulate AI.
    I believe that fundamental research on AI is a necessary 
precondition for safer systems. While regulations can make 
undesirable actions unlawful, technological advances and 
coordination with other countries in monitoring who has access 
to the compute necessary to train frontier AI models and how it 
is being put to use will be critical tools in supporting and 
enforcing regulations.
    One example is the use of confidential computing to make 
the theft of AI models more difficult. It is currently 
relatively straightforward to steal an AI model because the 
data needed to operate the model-known as the model weights-is 
stored in raw files. Stealing these files would allow criminals 
to use the model without spending the millions of dollars on 
compute and data necessary to train the model. Stricter 
cybersecurity laws can only go so far to prevent this from 
occurring. However, recent research into confidential computing 
could potentially enable the model to be operated without 
allowing access to the model weights, rendering cyber-theft 
impossible and addressing the root cause of the problem.
    Another challenge that advances in research can help 
resolve is identifying whether AI has been used to generate 
content. It is clear that instances of identity fraud, 
plagiarism, and a host of other issues will become more common 
as the power of AI tools increases. Watermarking is a technique 
whereby digital content is encrypted with unique, often hidden, 
identifiers that provide information about its origin. 
Watermarking has the potential to identify the origin of any 
content regardless of how it was created or digitally altered. 
Although current discussions of watermarking center on a desire 
that AI-generated content be watermarked, watermarking can also 
be used to prove the provenance of authentic content. In fact, 
it is entirely possible that in the future, people may 
automatically assume that all content is AI-generated unless 
its watermark proves its authenticity.
    Solving this technical problem would enable a new set of 
good governance tools concerning generative AI that were 
previously infeasible.
    These examples illustrate the fact that research and policy 
are not mutually exclusive, but in fact mutually dependent. 
Research advances unlock previously unpractical approaches to 
regulation, and smart policy accelerates research.
    I believe that we must also standardize technical 
definitions for methodologies, risks, and technological 
concepts across the government. The NIST AI Risk Management 
Framework lays out a foundation that other agencies can build 
upon. As these agencies consider passing rules or using 
procurement authorities to incentivize good behavior, they 
should ensure a consistent methodology for assessing risk 
levels and tailor their policies accordingly.
    Another technical area in which Congress has a crucial role 
to play is promoting and establishing best practices. This 
includes everything from technical standards to evaluation 
benchmarks for testing the trustworthiness and risks of AI 
systems.
    Let us not forget that while Congress should certainly not 
rush to overregulate, we should also not be complacent. The 
U.S. must avoid falling behind other major world powers who are 
finalizing their AI standards and regulations.
    Without proactive American leadership, supremacy in AI 
could be seized by the EU or China, both of which are taking 
far more draconian approaches to AI regulation.
    Because the U.S. currently leads the rest of the world in 
AI research and development, it makes no sense for us to stand 
by while American companies are forced to either make educated 
guesses or play by others' rules.
    We must also ensure that our academic institutions continue 
to play an active role in research and development of AI, and 
that the transparent system of publication and peer review that 
has enabled its success thus far is not replaced with an opaque 
system where cutting-edge research is only performed by 
corporations. This is why I believe is it critically important 
that we establish a National Artificial Intelligence Research 
Resource (NAIRR) as a shared national research infrastructure 
to ensure researchers have access to the tools needed to test, 
develop, and create new AI-backed technologies. This idea was 
proposed earlier this Congress when I joined my fellow AI 
Caucus Chairs in introducing H.R. 5077, the Creating Resources 
for Every American To Experiment with Artificial Intelligence 
Act (CREATE AI Act). Establishing a shared computing and data 
infrastructure resource, such as that detailed in the Act, 
would democratize access to AI by providing researchers and 
students across scientific fields and disciplines with access 
to compute resources and high-quality data, along with 
appropriate educational tools and user support.
    I want to thank all our witnesses for taking the time to 
join us today for this important discussion.
    I look forward to hearing your recommendations for how this 
committee can strengthen our nation's leadership in artificial 
intelligence and set clear rules for the safe, responsible, and 
human-centered development of this exciting new technology.

    Chairman Obernolte. I'd now like to recognize the Ranking 
Member of the Investigations and Oversight Subcommittee, the 
gentlewoman from North Carolina, for her opening statement.
    Mrs. Foushee. Chairman Obernolte and Chairman Collins, 
thank you for holding today's hearing on this important and 
timely subject, and certainly, thank you to our witnesses.
    Artificial intelligence is an emerging technology that 
holds the potential to transform many aspects of human society, 
and I am incredibly impressed with the quality of scientific 
research currently being conducted in the realm of AI. In my 
district, North Carolina's 4th, Duke University is leading the 
Athena Institute, which is an NSF (National Science 
Foundation)-funded multidisciplinary research institute focused 
on AI research for edge computing related to communications 
networks. And UNC (University of North Carolina) Chapel Hill is 
participating in the Artificial Intelligence Institute for 
Engaged Learning, another NSF-funded research institute working 
on the development of AI tools to enhance educational learning 
opportunities. I have met with these researchers. Their work is 
exciting, and their brilliance, ingenuity, and commitment to 
developing AI applications that serve the public good are 
second to none.
    At the same time, there is no escaping the reality that 
certain kinds of AI systems and their applications could pose 
grave risks in the absence of clear, rigorous oversight rooted 
in practical and ethical considerations. AI risk management is 
a complex subject that defies easy answers, but there are some 
guiding principles that should be at the front of our minds as 
we think about these issues.
    First, there is a pressing need to develop effective 
scientific tools and test methods that can support researchers 
and policymakers in evaluating the benefits and risks of 
different AI systems. This is an area where Federal agencies 
such as NIST can play a leading role.
    Second, it is crucial for the Federal Government to 
prioritize research into the benefits and risks of different AI 
systems and applications and then fund that research 
accordingly. AI risk management must be a Federal research 
priority because it is essential for understanding AI's broader 
impact on society.
    And finally, as we race to keep up with the breakneck pace 
of AI research and the accompanying risk, our discussion must 
be centered around the real-world risks and safety concerns 
that arise from AI systems. The debate over AI risk management 
has an unfortunate tendency to become fixated on dramatic 
existential risks like the end of human civilization, which are 
based in speculation. Those risks are legitimate subjects for 
research inquiry, but they should not be elevated over 
concrete, tangible concerns in areas such as equity, bias, 
privacy, cybersecurity, and disinformation. These are the 
existing fact-based risks to real people in the real world, not 
distractions pulled from the world of science fiction, and they 
deserve to be prioritized in the AI Risk Management Framework 
to come.
    The Science Committee is the right place for this kind of 
discussion. We pride ourselves on our responsible and 
bipartisan approach to complex questions like this one with 
deliberations grounded in scientific fact and informed by a 
broad range of perspectives. I'm confident that today's hearing 
will continue in that tradition.
    As a Member of the New Democrat Coalition's Artificial 
Intelligence Working Group, I believe this is exactly the kind 
of issue that deserves more of our attention in Congress. 
Chairman Obernolte, I have great respect for your leadership on 
AI issues, and I am eager to use today's hearing to explore 
areas where we may be able to work together on AI-related 
oversight in the future.
    And I yield back.
    [The prepared statement of Mrs. Foushee follows:]

    Chairman Obernolte and Chairman Collins, thank you for 
holding today's hearing on this important and timely subject. 
Artificial Intelligence is an emerging technology that holds 
the potential to transform many aspects of human society. And I 
am incredibly impressed with the quality of scientific research 
currently being conducted in the realm of AI.
    In my district, North Carolina's Fourth, Duke University is 
leading the Athena Institute, an NSF- funded multidisciplinary 
research institute focused on AI research for edge computing 
related to communications networks. And UNC Chapel Hill is 
participating in the Artificial Intelligence Institute for 
Engaged Learning, another NSF-funded research institute working 
on the development of AI tools to enhance educational learning 
opportunities. I have met with these researchers. Their work is 
exciting, and their brilliance, ingenuity, and commitment to 
developing AI applications that serve the public good are 
second-to-none.
    At the same time, there is no escaping the reality that 
certain kinds of AI systems and their application could pose 
grave risks in the absence of clear, rigorous oversight rooted 
in practical and ethical considerations. AI risk management is 
a complex subject that defies easy answers. But there are some 
guiding principles that should be at the front of our minds as 
we think about these issues.
    First, there is a pressing need to develop effective 
scientific tools and test methods that can support researchers 
and policymakers in evaluating the benefits and risks of 
different AI systems. This is an area where federal agencies 
such as NIST can play a leading role. Second, it is crucial for 
the federal government to prioritize research into the benefits 
and risks of different AI systems and applications, and then 
fund that research accordingly. AI risk management must be a 
federal research priority because it is essential for 
understanding AI's broader impact on society. Finally, as we 
race to keep up with the breakneck pace of AI research and the 
accompanying risks, our discussion must be centered around the 
real-world risks and safety concerns that arise from AI 
systems.
    The debate over AI risk management has an unfortunate 
tendency to become fixated on dramatic existential risks, like 
the end of human civilization, which are based in speculation. 
Those risks are legitimate subjects for research inquiry. But 
they should not be elevated over concrete, tangible concerns in 
areas such as equity, bias, privacy, cybersecurity, and 
disinformation. These are the existing, fact-based risks to 
real people in the real world, not distractions pulled from the 
world of science fiction. And they deserve to be prioritized in 
the AI risk management framework to come.
    The Science Committee is the right place for this kind of 
discussion. We pride ourselves on our responsible and 
bipartisan approach to complex questions like this one, with 
deliberations grounded in scientific fact and informed by a 
broad range of perspectives. I'm confident thattoday's hearing 
will continue in that tradition.
    As a member of the New Democrat Coalition's Artificial 
Intelligence Working Group, I believe this is exactly the kind 
of issue that deserves more of our attention in Congress. 
Chairman Obernolte, I have great respect for your leadership on 
AI issues, and I'm eager to use today's hearing to explore 
areas where we may be able to work together on AI-related 
oversight in the future.
    I want to thank our expert witnesses for appearing before 
the committee today and for your thoughtful testimony on this 
topic. I look forward to a vigorous and engaging discussion.
    Thank you, and I yield back.

    Chairman Obernolte. Thank you, Mrs. Foushee.
    I now recognize the Chairman of the Research and Technology 
Subcommittee, the gentleman from Georgia, for his opening 
statement.
    Mr. Collins. Thank you, Mr. Chairman. Good afternoon, and 
thank you again to our panel of witnesses for sharing their 
experience with us here today. I look forward to hearing your 
recommendations on where the Federal Government should focus 
investments to promote the development and deployment of 
effective artificial intelligence systems.
    The purpose of this hearing is to explore an important 
question: What tools and resources still need to be developed 
in order to create guardrails on AI? I also hope we can use 
this hearing as an opportunity to learn where gaps exist and 
where further investment is needed to achieve this goal. 
Federal science agencies, academia, and industry are carrying 
out critical research to develop and test methods for the 
responsible methods and tools for managing risk from AI.
    In fact, my home State of Georgia is leading the way. 
Earlier this month, Georgia State University received a $10 
million grant from the Department of Defense (DOD) to establish 
the Center of Excellence in Advanced Computing and Software. 
The Center of Excellence will help researchers address critical 
problems in AI and robotics. In addition, three Georgia 
institutions have received investments totaling $60 million to 
lead three National Science Foundation AI research institutes, 
and they will play a critical role in facilitating public-
private partnerships to advance research and translate into 
practical applications.
    As AI systems continue to be developed at scale, we must 
continue to address existing knowledge gaps and build off the 
progress we have thus made so far. This will be critical for 
the United States to lead in AI and to enable American 
innovation, enhance economic and national security, and 
maintain our global competitive edge.
    I'm proud that this Committee and this chamber have led the 
way in holding public hearings to discuss these critical 
issues. As Congress grapples with how to regulate AI, it is 
critical that it is done in an open and transparent manner, 
unlike our colleagues in the Senate.
    I once again want to thank our witnesses for their 
participation here today, and I yield back, Mr. Chairman.
    [The prepared statement of Mr. Collins follows:]

    Good afternoon. Thank you to our panel of witnesses for 
sharing their expertise with us here today.
    I look forward to hearing your recommendations on where the 
federal government should focus investments to promote the 
development and deployment of effective artificial intelligence 
systems.
    The purpose of this hearing is to explore an important 
question-what tools and resources still need to be developed in 
order to create guardrails on AI?
    I also hope we can use this hearing as an opportunity to 
learn where gaps exist and where further investment is needed 
to achieve that goal.
    Federal science agencies, academia, and industry are 
carrying out critical research to develop and test methods for 
the responsible methods and tools for managing risks from AI.
    In fact, my home state of Georgia is leading the way.
    Earlier this month, Georgia State University, received a 
$10 million grant from the Department of Defense to establish 
the Center of Excellence in Advanced Computing and Software. 
The Center of Excellence will help researchers address critical 
problems in AI and robotics.
    In addition, three Georgia Institutions have received 
investments totaling $60 million to lead three National Science 
Foundation AI Research Institutes, which will play a key role 
in facilitating public-private partnerships to advance research 
and translate it into practical applications.
    As AI systems continue to be deployed at scale, we must 
continue to address existing knowledge gaps and build off the 
progress we have made thus far. This will be critical for the 
U.S. to lead in AI and to enable American innovation, enhance 
economic and national security, and maintain our global 
competitive edge.
    I am proud that this Committee and this Chamber have led 
the way in holding PUBLIC hearings to discuss these critical 
issues. As Congress grapples with how to regulate AI, it is 
critical that it is done in an open and transparent manner, 
unlike our colleagues in the Senate.
    I once again would like to thank our witnesses for their 
participation here today.

    Chairman Obernolte. Thank you, Mr. Collins.
    I'll now recognize the Ranking Member of the Research and 
Technology Subcommittee, the gentlewoman from Michigan, for her 
opening statement.
    Ms. Stevens. Thank you, Mr. Chair.
    The Science Committee meets. The work continues. It is a 
real delight to be with you, Chairman Obernolte and obviously 
Ranking Member Foushee, our colleagues from the Oversight and 
Investigations Committee and, of course, the Chairman of the 
Research and Technology Subcommittee, Mr. Collins. And we 
welcome our very distinguished panel of witnesses. You have 
very informative testimony, and we're quite grateful.
    So in the grand tradition of this Committee, we have worked 
together to promote trustworthy AI. And I have helped pass 
legislation on this very Committee targeting deepfakes and have 
worked to include trustworthy AI provisions in the CHIPS and 
Science Act that passed Congress last year, and we're thrilled 
to see that working its way through NIST. Mr. Kean and I have a 
bipartisan bill, the Privacy Enhancing Technology Research Act, 
which just passed through this Committee a few months ago, and 
as soon as the Congress is back open, we hope to see it hit the 
floor, and will support--you know, this bill supports privacy-
enhanced data sets and tools for AI training systems. And 
anyone in this AI conversation knows we need to do PETs 
(privacy-enhancing technologies).
    So today's hearing is also a very nice follow up from a 
hearing that we held last year that I chaired on the Research 
and Technology Subcommittee to discuss AI risks broadly, AI 
risks and biases. We had a very informative hearing, 
particularly on the bias risks, and throughout the--you know, 
some of the racial disparities that come up. And so it's 
certainly quite remarkable how rapidly AI technology has 
advanced just in the last year since we had that hearing. Its 
potential benefits are obviously boundless. We could go on and 
on on that front, but so, too, are the risks, and not just the 
hypothetical, but the very much here and now.
    And, fortunately, we have seen a swift response and good 
leadership from President Biden and our Federal agencies to 
assess these risks and threats. And the Biden Administration 
released its framework for an AI Bill of Rights just last year 
and multiple, multiple Executive orders (EOs) to address AI 
risks. And I was especially pleased to see the National 
Institute of Standards and Technology released the AI Risk 
Management Framework in January, bravo, the mighty agency that 
could and will. And that's just a very important step in AI 
safety that was developed in the 2020 National AI Initiative 
Act, another product of this very Committee. And so this 
document is already helping organizations understand and 
mitigate the risks associated with these technologies. And I'm 
excited to see more major AI companies adopt this baseline for 
AI risk management.
    We're going to continue to work rigorously to develop 
meaningful and robust governance frameworks for trustworthy AI. 
That is absolutely our charge. We've got several TIME100 AI 
leaders as witnesses today, no pressure. You know, we're going 
to look back in history on your leadership and the work that 
you're doing. Financial AI systems will have different risks 
than generative AI chatbots. We're going to need to develop 
technical standards to mitigate risks across sectors and use 
cases. Testing and evaluation (T&E) of AI systems will also be 
critical to enable AI governance. After all, it's very hard to 
regulate what you cannot measure, as our friends at NIST know.
    I think in conclusion here, it's fair to say that we're in 
a big competition globally on the technology front. I sit on 
the Select Committee on Strategic U.S. Competitiveness with the 
Chinese Communist Party (CCP). We want to have the risk 
framework, we want to have the mitigation, we want to have 
ownership of the technology here. You know, we've heard from 
other NIST witnesses, according to international indicators, 
indicators that we don't even measure as a nation, that China 
is leading in 27 out of 34 critical sectors. So AI is a place 
that the United States wants to continue to lead on. We want to 
set the standards for the world. And we're so excited to get 
exploring and discovering and deepening our knowledge here 
today.
    Thank you so much, Mr. Chair, and I yield back.
    [The prepared statement of Ms. Stevens follows:]

    Thank you to Chairman Obernolte and Ranking Member Foushee 
for holding this hearing jointly with Chairman Collins and 
myself, and welcome to our distinguished panel of witnesses.
    I have long worked with my colleagues on both sides of the 
aisle to promote trustworthy AI. I have helped pass legislation 
targeting deepfakes and worked to include trustworthy AI 
provisions in the CHIPS and Science Act. My Privacy Enhancing 
Technology Research Act, which passed through this Committee 
just a few months ago, will support privacy-enhanced datasets 
and tools for training AI systems.
    Today's hearing will follow up on a hearing we held in the 
Research and Technology Subcommittee last September to discuss 
AI risks broadly. It is remarkable how rapidly AI technology 
has advanced just in the last year. Its potential benefits are 
boundless. Unfortunately, so too are its risks--not just the 
hypothetical but very much the here and now.
    Fortunately, we have seen a swift response by President 
Biden and our federal agencies to these risks and threats. The 
Biden Administration released its Framework for an AI Bill of 
Rights last year and multiple Executive Orders to address AI 
risks. I was especially pleased to see the National Institute 
of Standards and Technology released the AI risk management 
Framework in January, an important step in AI safety that was 
developed by the 2020 National AI Initiative Act, a Science 
Committee product. This document is already helping 
organizations understand and mitigate the risks associated with 
these technologies, and I am excited to see more major AI 
companies adopt this as a baseline for AI risk management.
    However, we are still in the early days of developing a 
meaningful governance framework for trustworthy AI. There is a 
lot of hard work ahead of us to be able to adequately define 
and measure the risks associated with AI systems. As we learned 
during our hearing last year, context is critical in AI risk 
management. Financial AI systems will have different risks than 
generative AI chatbots. We will need to develop technical 
standards to mitigate risks across sectors and use cases. 
Testing and evaluation of AI systems will also be critical to 
enable governance. After all, it's very hard to regulate what 
you can't measure.
    I look forward to an update on NIST's work to develop 
technical standards and AI risk profiles for different sectors 
and use cases. I am particularly interested in understanding 
NIST's plans for promoting the adoption of the risk management 
framework across the public and private sectors.
    Another major challenge I hope that we address in this 
hearing is that of the AI risk management workforce. Federal 
agencies and regulators who are seeking to address AI-related 
challenges lack a workforce capable of understanding and 
responding to AI risks. Most private sector organizations 
deploying AI systems also lack such expertise. As we focus on 
development of the AI workforce broadly, we must not ignore 
this critical segment of the workforce and the particular 
skills they will require.
    I'm looking forward to discussing today what more Congress 
can do to ensure the United States leads the world in 
trustworthy artificial intelligence.
    Thank you and I yield back.

    Chairman Obernolte. Thank you, Ms. Stevens.
    [The prepared statement of Chairman Lucas follows:]

    Thank you, Chairman Obernolte and Chairman Collins, for 
holding this hearing today. Artificial intelligence is 
transformational technology, and it deserves thoughtful, 
informative discussions about any potential government action 
in this area.
    As we discussed during our last hearing on AI, rushing to 
regulate this technology could have detrimental effects on our 
ability to innovate and maintain American leadership. We want 
to be sure that we allow this technology to grow and advance, 
and to be sure that we develop it in a safe and trustworthy 
manner that maintains American values of fairness and 
transparency.
    That requires a measured approach, one which I'm proud to 
say our Committee has long embraced. From the time we passed 
the National AI Initiative Act, we've focused on the strategic 
development of AI and risk management standards.
    A crucial part of that legislation was directing the 
National Institute of Standards and Technology (NIST) to 
develop an AI Risk Management Framework that could serve as a 
tool for the trustworthy design, development, use, and 
evaluation of AI.
    I'm very pleased with the work NIST put into this product, 
which was developed with years of input from stakeholders, 
government, industry, and academia.
    This represents the kind of approach we need to ensure AI 
remains safe, trustworthy, and fair.
    Other international entities are moving forward with 
regulations as we speak. The European Union is taking a 
particularly prescriptive approach to managing the risks of AI.
    While we cannot afford to fall too far behind other 
nations, I urge caution to anyone who would move forward too 
quickly with strict regulations here in the U.S.
    We need to find a balance between allowing the technology 
the freedom to grow and developing and a framework that helps 
us manage potential risks from AI.
    That's why today's hearing is so important. We can't rush 
to regulate before knowing the tools and resources we need in 
place in order to successfully approach this governance 
challenge.
    AI is grabbing big headlines right now and I understand the 
impulse to make rushed decisions about how to manage it. But 
that leads us down unproductive paths. Our friends in the 
Senate, for instance, are choosing to make an end run around 
the normal committee process and hold confidential meetings 
with big tech companies instead. The White House, instead of 
steadily building on the smart risk management framework put 
out by NIST, is issuing reports, bills of rights, and executive 
orders somewhat haphazardly.
    I'm not arguing that we shouldn't regulate the development 
of AI at all, just that we should approach any new requirements 
methodically and openly so we can ensure the best possible 
outcome for Americans and American businesses.
    I believe that if we approach this correctly, we will get 
this right and ensure the safe, trustworthy, and fair 
development of AI.
    Thank you to our witnesses for joining us today, and I look 
forward to a productive discussion.

    Chairman Obernolte. We'll move now to our witness panel. 
Our first witness today is Ms. Elham Tabassi, the Director for 
Emerging Technologies of the Information Technology Laboratory 
at the National Institute of Standards and Technology. She also 
leads NIST's Trustworthy & Responsible AI Program and the 
development of the National AI Risk Management Framework that 
seeks to cultivate trust in the design, development, and use of 
AI technologies. Ms. Tabassi, you are recognized for five 
minutes.

                TESTIMONY OF MS. ELHAM TABASSI,

         ASSOCIATE DIRECTOR FOR EMERGING TECHNOLOGIES,

               INFORMATION TECHNOLOGY LABORATORY,

         NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY

    Ms. Tabassi. [inaudible] and Members of the Subcommittee, 
thank you for the opportunity to testify today on NIST's 
efforts to advance trustworthy and responsible AI. My name is 
Elham Tabassi. I'm Associate Director for Emerging Technologies 
at the Information Technology Laboratory in the Department of 
Commerce's National Institute of Standards and Technology, or 
NIST. I also lead the NIST Trustworthy & Responsible AI 
program.
    AI technologies provide enormous opportunities for positive 
impact. They can also cause cascading negative consequences if 
proper safeguards are not in place. NIST works to advance 
research, standards, measurements, and tools to manage AI risks 
and realize the full promise of this technology for all people. 
NIST works with the AI community to develop and improve its 
resources. We pride ourselves in our engagements and 
collaborations, and the trust we have built with the private 
sector, government agencies, civil society, and academia.
    Among its many AI-related activities, NIST released the AI 
Risk Management Framework, or AI RMF, in January 2023 after 
considerable collaborations with stakeholders. Directed by 
congressional mandate, the AI RMF is a voluntary framework that 
provides a flexible, structured, and measurable process to 
address the AI risks purposefully and continually throughout 
the AI lifecycle. The AI RMF offers a resource to the 
organization's designing, developing, deploying, or using AI 
systems to help manage the many risks of AI and promote 
trustworthy and responsible development and use of AI systems. 
The framework was developed through an open, transparent, and 
collaborative process that allowed for a broad range of 
stakeholder input. NIST also released a companion NIST AI RMF 
playbook and a roadmap. The playbook provides additional 
guidelines to organizations on the action they can take to meet 
the outcomes included in the framework. The roadmap identifies 
key activities for advancing the AI RMF that could be carried 
out by NIST in collaboration with public or private 
organizations or by those organizations independently.
    To support the operationalization of the AI RMF, NIST 
established the online Trustworthy & Responsible AI Resource 
Center (AIRC) in March 2023. It serves as a one- stop shop for 
foundational content, technical documents, and AI toolkits. In 
June 2023, NIST launched a generative AI public working group 
to help NIST develop a profile of AI RMF to address the risks 
of generative AI technologies.
    The AI technologies are advancing at an extraordinary pace. 
For that reason, the AI RMF and its related documents will 
evolve over time to reflect new knowledge and practices. NIST 
continues its robust engagement with stakeholders to keep the 
framework up to date with AI trends and reflect experience 
based on the use of AI RMF.
    To build on NIST's work on the AI RMF and provide 
additional guidelines to organizations to advance trustworthy 
and responsible AI, NIST conducts fundamental research on many 
of the AI trustworthiness characteristics and prioritizes its 
work based on its insights and the community's stated needs.
    New NIST efforts in AI evaluation will focus on 
sociotechnical aspects of system functionality and performance 
in addition to accuracy. In particular, the evaluations have 
the goal of identifying risks and harms of AI systems before 
they are deployed and to establish metrics and evaluation 
infrastructure that will allow AI developers and deployers to 
detect the extent to which AI systems exhibit negative impacts 
or harms.
    NIST engages with partners around the world to advance 
shared goals in trustworthy AI. NIST also coordinates with 
other Federal agencies and leads several policymaking and 
interagency efforts, including administering the National 
Artificial Intelligence Advisory Committee, or NAIAC, which 
advises the President and the National AI Initiative Office.
    Advancing AI research, evaluation, and standards that 
contribute to a secure, private, interoperable, innovative, and 
world-leading digital economy is a top priority for NIST. Thank 
you for the opportunity to present on NIST's activities to 
improve AI trustworthiness. I look forward to your questions.
    [The prepared statement of Ms. Tabassi follows:]
    [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]
    
    Chairman Obernolte. Thank you, Ms. Tabassi.
    Our next witness is Michael Kratsios. Mr. Kratsios is the 
current Managing Director at Scale AI. Prior to joining Scale, 
Mr. Kratsios served as the fourth Chief Technology Officer 
(CTO) of the United States where he oriented national 
technology policy around ensuring American leadership in 
emerging technologies, including overseeing the implementation 
of the National AI Initiative. He also served as the Acting 
Undersecretary of Defense for Research and Engineering, and 
currently serves as a Distinguished Fellow at the Council on 
Competitiveness.
    Mr. Kratsios, you are recognized for five minutes.

               TESTIMONY OF MR. MICHAEL KRATSIOS,

                  MANAGING DIRECTOR, SCALE AI

       4TH CHIEF TECHNOLOGY OFFICER OF THE UNITED STATES

    Mr. Kratsios. Chairmen Obernolte and Collins, Ranking 
Members Foushee and Stevens, and Members of the Investigations 
and Oversight and Research and Technology Subcommittees, thank 
you for the opportunity to testify here today. My name is 
Michael Kratsios. I'm the Managing Director of Scale AI. 
Previously, I served as the CTO of the United States and also 
as Acting Undersecretary of Defense for Research and 
Engineering.
    I'd like to use my statement today to make two points. 
First, large language models (LLMs) mark a milestone in AI, but 
they're not our first brush with the promise and the risks of 
this technology. Policymakers have grappled with AI oversight 
for years. Since 2016, successive Administrations and Congress 
have laid a robust foundation for AI policy and regulation. 
This includes a report on the future of AI under President 
Obama and the Nation's first AI strategy and multiple Executive 
orders under President Trump. When Trump Administration made AI 
a national technology priority, he committed to doubling 
Federal AI research spending, created first-of-a-kind national 
AI research institutes, developed the world's first guidance 
for the regulation of AI in the private sector, and 
collaborated with allies to develop the world's first 
intergovernmental AI policy guidelines at the OECD 
(Organization for Economic Cooperation and Development). 
Congress codified many of these efforts in the bipartisan 2020 
National AI initiative and AI in Government acts. The Biden 
Administration continued work on AI, releasing a blueprint for 
an AI Bill of Rights, securing a voluntary--securing voluntary 
commitments from tech companies, and publishing an AI Risk 
Management Framework.
    Unfortunately, implementation of existing legislation and 
Executive orders has fallen short. A study by Stanford found 
that less than 40 percent of the legal requirements associated 
with the AI in Government Act and the two Executive orders have 
been implemented. While considering additional legislation or 
pursuing new administrative actions on AI, policymakers should 
first ensure that Federal agencies fully implement existing 
laws and follow through with requirements from AI Executive 
orders.
    When contemplating new AI regulation, lawmakers should 
pursue a use case and sector-specific risk-based approach 
rooted in high-quality testing and evaluation. This approach 
tailors the rigor of the evaluation to the level of risk posed 
by each use case. For example, AI-powered medical diagnostics 
should undergo more stringent testing and evaluation compared 
to lower risk applications like a movie recommendation 
algorithm.
    And we're not starting from scratch here. The current OMB 
(Office of Management and Budget) guidance to agencies on 
regulating AI in the private sector already takes this 
approach. I believe this guidance remains fair and appropriate. 
The Biden Administration has recognized the value of testing 
and evaluation through their support of the DEF CON AI red 
teaming event in August. The event gathered over 2,000 
participants to red team eight leading LLMs on a test 
evaluation platform built by Scale.
    In short, there's been a tremendous amount of work on AI 
oversight to date across the Federal Government. The prudent 
path forward is to build on existing efforts and adopt new use 
cases--and adopt use-case, sector-specific, risk-based 
guidelines for responsible AI deployment.
    Second, to ensure the deployment and development of safe, 
secure, and responsible AI, we must harness the full strength 
of America's unique innovation ecosystem of government, 
industry, and academia. Historically, the Federal Government 
has focused on funding fundamental R&D, and industry has 
commercialized those discoveries. However, rapid advancements 
in the state-of-the-art of AI are being propelled today 
primarily by private companies. This landscape requires 
ecosystem collaboration to ensure we develop safe and secure 
AI.
    Industry is participating in a number of consensus-building 
forums to address gaps in and conduct research on AI standards. 
Scale recently published its own technical methodology for LLM 
testing and evaluation, which combines automated assessment 
with human evaluation of AI systems.
    Within the Federal Government, the Department of Energy's 
national labs represent a unique strategic asset both for 
fundamental AI research and for addressing potential risks. DOE 
is leading--world-leading supercomputing capabilities, 
multidisciplinary expertise, and university partnerships make 
it a natural home for the U.S. Government's work on addressing 
frontier risk. Additionally, Congress could take a major step 
forward by formally establishing and funding the NAIRR. This 
would create a critical shared research infrastructure, 
expanding access to computational capabilities, high-quality 
datasets, and educational resources.
    Beyond research and development, we should convene 
stakeholders, provide direction, and assert American leadership 
at international standards organizations. The United States 
should continue to engage with our partners and allies across 
international fora to ensure American values continue to 
underpin AI's development. We must not see this ground to 
authoritarian governments who do not share our values. And our 
Nation's universities must continue to tackle complex research 
problems and lend their expertise to collaborative working 
groups.
    I truly believe that the United States can and must 
maintain and expand our global leadership in artificial 
intelligence. American leadership in AI is crucial for 
maintaining the economic and national security of the United 
States.
    Thank you again for this opportunity, and I look forward to 
your questions.
    [The prepared statement of Mr. Kratsios follows:]
    [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]
    
    Chairman Obernolte. Thank you, Mr. Kratsios.
    Our third witness is Dr. Emily Bender. Dr. Bender is a 
research professor and scientist with the School of Computer 
Science and Engineering at the University of Washington. Her 
work has illuminated how natural language processing systems 
and large language models work, seeking to promote fairness and 
healthy engagement between humans and AI systems.
    Dr. Bender, you are recognized for five minutes.

               TESTIMONY OF DR. EMILY M. BENDER,

       PROFESSOR OF LINGUISTICS, UNIVERSITY OF WASHINGTON

    Dr. Bender. Thank you. Good afternoon, Chairmen Obernolte 
and Collins and Ranking Members Foushee and Stevens. Good 
afternoon, distinguished Members of the Committee. Thank you 
for this opportunity to speak with you today about the risks 
associated with technologies being marketed as, in quotes, 
``artificial intelligence.'' My name is Emily M. Bender, and 
I'm professor of linguistics at the University of Washington, 
also affiliated with computer science and the Information 
School.
    This technological sector that we're talking about is 
presently the site of enormous influxes of capital and enormous 
concentrations of power. In order to channel the innovation 
taking place toward the benefit of society, we need thoughtful 
regulation that shores up our rights. I'm very heartened to see 
your Committee engaging with these important discussions.
    A key step toward clear discussions of these topics is 
clear terminology. I find that the phrase artificial 
intelligence is best understood as a marketing term and one 
which tends to muddy the waters. It is clearer in my opinion to 
talk about automation, and then we can focus on who is 
automating what and why.
    Types of automation that are sometimes called in quotes AI 
include the following, among others: automated decision systems 
and automated decision support systems; automated 
classification like facial recognition systems; automated 
recommender systems like algorithmic feeds in social media; 
systems which provide an interface layer for access to human 
labor like Uber and Lyft; automated translation of information 
between formats like automatic transcription, machine 
translation, and image style transfer; and synthetic media 
machines like ChatGPT, DALL-E, and others.
    I'd like to say a few more words about ChatGPT because it 
is important to understand how it produces the illusion of 
understanding and therefore the illusion of intelligence. 
ChatGPT is fundamentally what we call a language model. That 
means that its only task is to repeatedly produce a likely next 
word. And it's doing that given some input word sequence or 
prompt and its training text. Because it is trained with 
enormous amounts of text, it can produce plausible seeming 
output on nearly any topic. But that output comes without any 
commitment to its contents. At present, no one is actually 
accountable for the synthetic media being spilled into our 
information ecosystem.
    At the same time, as people, we can't help but make sense 
of language that we encounter. We do it instinctually by 
imagining the point of view of the person that we're imagining 
has spoken or written that thing in order to infer what it is 
that we think they want us to understand by having said that. 
Prior to the advent of ChatGPT, if we encountered some 
coherent-seeming text, it was safe to assume that it came from 
some person who was using it to communicate something. So it's 
only natural that when we see the output of ChatGPT, we imagine 
that the computer behind it is doing the same thing when 
emphatically it is not. If we don't account for our own 
sensemaking ability when we try to evaluate these technologies, 
we can end up concerned with fantasy scenarios instead of real-
world risks and harms.
    Sometimes in conversations about the risks of so-called AI, 
you'll hear a strong focus on something called existential risk 
or the idea that the, quote, ``AI'' might become sentient and 
turn on us. It is important to know that discussions of 
fantastical malevolent autonomous thinking machines are a 
deflection and a distraction. They are a deflection because 
they locate the potential for harm in the technology itself 
rather than in the choices of human actors. They are a 
distraction because they point your attention toward imaginary 
scenarios and away from the actually occurring harms and real-
world risks.
    Those real harms and risks includes things like the 
pollution of the information ecosystem with synthetic media; 
the exploitation of workers and data theft underlying the 
creation of the systems; substantial environmental impact both 
in carbon footprint and water usage; the oppressive 
surveillance of people as citizens, as migrants, as workers, 
and as the formerly and currently incarcerated; the fraying of 
social services when automated allocation systems are being 
used to reduce the amount of support offered, or when the 
replacement of quality healthcare, education, and other social 
benefits with synthetic text is suggested. And finally, there's 
the use of automation to replace skilled jobs with deskilled, 
precarious gig work.
    These harms are real and present, but we are not powerless. 
I believe that an effective regulatory remedy would include the 
following elements: First, requirements of transparency about 
the fact of automation, including the fact of synthetic media; 
requirements of transparency about the data systems are trained 
on and their resulting performance; clear accountability for 
system outputs; recourse for people who are adversely affected 
by automated systems; and national funding for humanities and 
social science research into the impact of technology on 
society.
    Thank you again for your attention and for the opportunity 
to speak with you today about these important matters.
    [The prepared statement of Dr. Bender follows:]
   [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]
    
    Chairman Obernolte. Thank you, Dr. Bender.
    Our final witness this afternoon is Mr. Caleb Watney. He is 
co-CEO (Chief Executive Officer) of Institute for Progress 
(IFP), a nonpartisan research organization that promotes 
innovation policy and scientific advancement. His research 
focuses on policy methods of achieving state capacity and a 
posture of innovation. He's written commentary published in The 
Washington Post, The Atlantic, Lawfare, Politico, among others. 
Mr. Watney, you are recognized for five minutes.

                 TESTIMONY OF MR. CALEB WATNEY,

                 CO-CEO, INSTITUTE FOR PROGRESS

    Mr. Watney. Thank you, Chairman Obernolte and Chairman 
Collins, Ranking Member Foushee and Ranking Member Stevens, 
Members of the Committee. Good afternoon, and thank you for the 
opportunity to testify today.
    I'm the co-founder and co-CEO of the Institute for 
Progress, IFP. We're a nonpartisan thinktank that's focused on 
innovation policy. In particular, we spend a lot of time 
thinking about the American research and development enterprise 
and how we can get the most bang for our buck on a per-dollar 
basis. As one example of this, we recently signed a partnership 
with the National Science Foundation to help them think through 
more creative ways of doing scientific grantmaking and overall 
kind of monitoring the efficacy of the R&D enterprise in the 
United States.
    What I'd like to talk about today are four key research 
priorities within the field of AI that I think represent a 
tremendous opportunity for the Federal Government to be 
proactive about shaping the technology. Effectively, these four 
areas have served as market failures where private companies 
have been unwilling or unable to invest the sufficient level of 
capital. And this provides a really important key moment for 
the public sector to make sure that the development of AI stays 
within the public interest.
    First, we need a better way to understand how models are 
making decisions. This field of research is broadly called 
interpretability, and it tries to understand how these black 
box models are actually making decisions. It seems difficult to 
imagine how we would begin to integrate these models in 
healthcare, in finance, in transportation, in national security 
information loops unless we actually understand how they're 
making decisions and we can rely on them to be trustworthy.
    There is some investment happening in both the private 
sector and within the public sector on this, but it's orders of 
magnitude too little compared to the social importance of this 
research topic. While it's not a perfect analogy, I think 
something on the scale and the level of ambition of the Human 
Genome Project would be a remarkable downpayment to really 
understand the inner workings of these black box models and 
make sure that we can begin to build trustworthy and reliable 
systems.
    Two, defensive cybersecurity. The CEO of Anthropic Dario 
Amodei recently acknowledged in an interview that if a state 
actor were determined to steal the model weights, that is the 
inner workings of how their models work, they would be unable 
to stop them. This is tremendously concerning, especially given 
the large policy investment that the national security 
community has been making to prevent the Chinese Communist 
Party and other nation-states from being able to achieve state-
of-the-art models. What we need are a new set of technologies 
to tilt the playing field back to the defensive side of 
cybersecurity. As--Chairman Obernolte, as you mentioned 
earlier, confidential computing is one set of techniques that 
could accomplish this. By encrypting model weights throughout 
the training and the deployment process, it'd be substantially 
harder for adversaries to be able to steal frontier models and 
effectively turn what is currently a cybersecurity challenge 
into a physical security challenge.
    Third, we need a better set of real-world benchmarks. I 
think it's remarkable the extent to which we have disagreements 
not only about the future path of AI, but also about its 
current and present capabilities. I think a large part of this 
is due to the immaturity and the shallowness of current 
benchmarks. There's lots of good work being done, but 
oftentimes, these work as multiple-choice tests that are being 
rapidly aced or which don't actually make apples-to-apples 
comparisons across leading models.
    Furthermore, it's possible for leading AI companies to pick 
and choose the benchmarks that they think make their models 
look best, and there's been a splintering effect across the 
ecosystem. We also don't really have that many models that are 
trying to test for real-world capabilities in open-ended 
environments or when can--humans can be a key part of the 
decisionmaking loop. This is a key area for Federal research 
and investment, and I think a better understanding of model 
capabilities today could actually inform better policy 
discussions tomorrow.
    Fourth, we need a better set of techniques around privacy-
preserving machine learning. Ms. Stevens, as you mentioned, I 
think there's a lot of really good work that is already 
beginning to happen on this between federated learning and 
differential privacy and model auditing and assurance, there's 
lots of ways that we can make the very real perception of 
tradeoffs between AI progress and AI privacy less concerning, 
but this is going to be an important role for the Federal 
Government to actually invest real funding and coordination on.
    And in conclusion, through targeted Federal funding and 
creative partnerships, we can target these core market 
failures, and we can advance research that not only pushes the 
boundaries of what we think AI can do for society, but also 
ensures that it's being developed and deployed in a manner that 
is ethical, secure, and beneficial for all of the United States 
and the world.
    Thank you for the opportunity to testify, and I look 
forward to answering any questions.
    [The prepared statement of Mr. Watney follows:]
    [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]
    
    Chairman Obernolte. Thank you, Mr. Watney. Thank you very 
much to all of our panelists. It was an excellent introduction 
to this very complicated but important topic.
    I now recognize myself for five minutes of questions.
    Mr. Kratsios, I'd like to start with you. And I want to 
talk about Federal preemption because this is something that 
we're going to have to decide very soon whether or not the 
regulation of AI is something that is going to be federally 
preempted or whether or not we're going to allow the States to 
be the laboratories of democracy and to innovate on this. Even 
if the Federal Government sets a floor for regulation, do we 
allow individual States to set a ceiling?
    So on the one hand, that would certainly be a more anti-
Federalist way to go about it. On the other hand, I fear that 
it might create a very complex legal and regulatory landscape 
that would make it difficult for smaller firms who don't have a 
building full of lawyers to rely on to be able to comply with. 
And I think it might be very destructive to entrepreneurialism. 
So from your industry standpoint, what do you think? Should--we 
have three things we can do. We can fully federally preempt, we 
can partially preempt, and we can allow the States to set their 
own ceilings or we cannot act and allow the States to take the 
lead on this. What do you think of those three options?
    Mr. Kratsios. My general view on this issue is Federal 
preemption areas of emerging technology tend to be--like 
artificial intelligence can be extraordinarily beneficial to 
ensuring that the sort of larger marketplace of entrepreneurs 
is able to tackle the very important issues of building 
companies around this new tech. We've seen when patchworks do 
exist, ultimately, you're not able to see the quick 
proliferation of technologies kind of across the country. I 
think the most--the best example of this or a really good one 
is the struggle that Europe has had for many years in their 
long attempt to create a single digital market for a lot of 
their technology companies. And the failure to have one for 
decades kind of was a big hindrance to their ability to 
innovate.
    So my general sense is that I think we should begin by 
thinking about what type of Federal preemption can ultimately 
be done. The other thing that I would worry a little bit about 
and why I think there's some urgency to this is there continues 
to be, as many of you I'm sure know, this almost sort of 
regulatory pipeline between Brussels and Sacramento. And 
California tends to be a State that likes to very quickly 
address some of these technology-related regulatory issues, and 
they see Brussels as kind of the place where they can sort of 
learn from.
    So my general sense is we probably should be wary of 
individual States like California running ahead, and I think 
there's a big opportunity for Committees like this one to make 
it a much more clear regulatory environment for so many of our 
entrepreneurs.
    Chairman Obernolte. I think, at the very least, we in 
Congress have to recognize the Federal responsibility to 
regulate interstate commerce and the fact that that is a 
Federal obligation and not something we can allow the States to 
preempt, so I think that's a strong argument for the Federal 
Government to take a leading role in this. But, you know, the 
point is this is a decision that has to be made soon because 
the mistake that was made with digital data privacy is Federal 
inaction, which allowed--now we have 23 different State 
frameworks, probably more to come in the months and years 
ahead, that create this patchwork of regulation that's very 
difficult for small companies to deal with. And now there's a 
creative ownership amongst the States that makes it more 
difficult for us to preempt at the Federal level. So I think if 
we're going to do it, it has to be done now.
    Ms. Tabassi, I would like to ask you a question about the 
path that we take in crafting a Federal regulatory framework 
for AI. And NIST, I think, has done some of the furthest-
reaching work on looking at risk management and looking at what 
a framework might look like. In my thinking, we really have two 
paths. We can follow the European model where we spin up a 
brand new bureaucracy and empower them with the ability to 
issue licenses and preempt that authority from--away from the 
existing sectoral regulators. Or we could empower our existing 
sectoral regulators to regulate within their sectoral spaces 
and give them the tools and the resources that they need, which 
would include support from organizations like NIST in 
developing testing and evaluation standards and the frameworks 
that you've already been working on to be able to do those 
jobs. Which of those two approaches do you think would be best? 
I mean, is it like if you consider the fact that the FDA (Food 
and Drug Administration) has already processed over 500 
applications for the use of AI in medical devices? You know, 
the question is, is it easier to teach a new organization 
everything the FDA knows about ensuring patient safety, or is 
it easier to teach the FDA what it doesn't already know with 
the help of organizations like NIST about artificial 
intelligence?
    Ms. Tabassi. Thank you for that question. As we all know, 
NIST is a non-regulatory agency, so we don't take----
    Chairman Obernolte. That's why I asked you.
    Ms. Tabassi [continuing]. Regulation agnostic.
    Chairman Obernolte. You don't have a dog in the fight.
    Ms. Tabassi. Thank you. Thank you. The approach we took 
for--in development of the AI RMF is actually a hybrid approach 
that the AI RMF provide the horizontal, the interoperable 
lexicon to talk about risk. So because we don't want to make--
we want to make sure that the risk of bias or interpretability 
has the same meaning, and hopefully, similar measurement 
techniques and methods across all of the different sectors and 
think about development of the profiles, which are verticals, 
that give more specificity for that domain.
    One other thing that I also want to mention, a lot of 
really good and important noting that importance of 
availability of metrics, methodologies, test environment, and 
measurement science for evaluations of AI systems, limits, 
capabilities, functionality, and trustworthiness. So regardless 
of the regulatory or policy landscape, we do need to have 
measurement science methods and methodologies to ensure the AI 
assurance because, again, if we can't measure it, we cannot 
improve it.
    Chairman Obernolte. Well, we need to clearly keep talking 
about this issue. I see I'm out of time. I will now recognize 
Ranking Member Foushee for five minutes for her questions.
    Mrs. Foushee. Thank you, Mr. Chairman.
    Before I begin, I ask unanimous consent to enter into the 
record a statement by Representative Anna Eshoo.
    Chairman Obernolte. Without objection.
    Mrs. Foushee. Thank you.
    Dr. Bender, I'll direct this initial question to you. As 
Members of Congress, most of us are not scientists or 
technologists. We can be confronted with overwhelming claims 
about the capabilities and risks of artificial intelligence. 
Some of those risks are impacting people today, and others are 
theoretical. As lawmakers, how do we separate the hyperbole 
from the reality as we debate the guardrails that may be 
necessary to support meaningful governance of AI systems and 
applications?
    Dr. Bender. Thank you for that question. And I recognize 
that you're in a difficult position trying to navigate this. I 
think that one way to go is to ask people to define their 
terms. So when someone's telling you about artificial 
intelligence, ask them what they mean about that. If they're 
telling you AI can do XYZ, ask them how do you know? What is 
the evaluation that led you to that claim? And pin it down to 
specifics. That would be my advice.
    Mrs. Foushee. Ms. Tabassi, would you like to add any 
further thoughts on this question?
    Ms. Tabassi. I second everything Emily said. I think 
grounding the discussions into evidence and data is one way to 
go. And of course, we need to have more measurement science and 
methodologies to be able to get to those evidence.
    Mrs. Foushee. My next question is for the entire panel, 
starting with Ms. Tabassi. I have very serious concerns about 
bias and equity issues arising from the manner in which AI 
systems are developed and deployed. One of the most important 
ways to address AI bias and equity issues is to engage a 
broader community of stakeholders and to get them involved with 
AI development throughout the process. What are some of the 
best practices to bring diverse communities, including 
historically marginalized communities, into the decisionmaking 
process for the design and deployment of AI systems?
    Ms. Tabassi. Thank you for that question, and that's a 
really important one. And what we learn in development of the 
AI RMF is the importance of reaching out and having many 
diverse views around the table. There are discussions around 
participatory engagements and how to bring the voices of the 
impacted community but also the voices of the group that study 
the impact of the AI systems or technology on the community and 
other people. Some of these frameworks talk about the impacted 
community ought to be consulted, but beyond that, they need--
also need to be--have an opportunity to contribute and 
collaborate. But ultimately, we need to have them as part of 
the co-design and involved in the earliest stages of the 
conversations.
    Mr. Kratsios. Yes, and for--on--from the perspective of 
Scale, when we worked on our DEF CON platform for testing and 
evaluation, one of the things that we were excited to do with 
our partners was to actually deploy the testing platform to a 
number of HBCUs (historically Black colleges and universities) 
and other communities around the United States. So it wasn't 
just the hackers in Las Vegas, but we also took it to 
universities where you had a diverse set of individuals who 
maybe have not interacted with these models to try to test 
them, evaluate them, red team them, probe them in the areas 
that, you know, they know better than anyone else. And I think, 
you know, using platforms like this to be able to do these 
testing and evaluation experiments and opportunities across a 
diverse set of folks can make a really big difference.
    Dr. Bender. I'd like to point to the school of thought 
called value sensitive design developed by Friedman and Hendry 
at the University of Washington and their colleagues, which has 
a whole host of methodologies for, first of all, doing things 
like stakeholder analysis, figuring out who was going to be 
impacted by this. It's not necessarily the people who are using 
the technology. It's often the people who are having the 
technology used on them or on their communities. And then 
there's things including something called the diverse voices 
methodology for empaneling panels of what they call 
experiential experts, people who have the lived experience that 
gives them the expertise to understand how they're going to be 
affected and bring that into the discussion. So I would point 
to value sensitive design.
    Mr. Watney. I think there's a lot of interesting 
opportunities to kind of involve participatory democracy in the 
design and implementation of AI systems. There's a lot of ways 
in which when we are actually beginning to roll out and design 
systems, you have the opportunity to, in some sense, be more 
deliberate and intentional about the kinds of decisions and 
values you're building in, whereas before, a lot of the 
inherent systems we're using, they have values being built in, 
but we don't get the chance to examine them as thoroughly.
    Just--I haven't had time to dig fully into the paper, but I 
saw just a couple of days ago one method for kind of AI 
governance is constitutional AI. And I saw that they did an 
interesting project where they tried to work with a bunch of 
different focus groups from all over the United States that 
were very sort of diverse and try to help them articulate what 
are the values that are important to them and see what are the 
kinds of models you get when you build and the results from 
these conversations into the kind of constitution of different 
AI systems.
    Mrs. Foushee. That's my time. Mr. Chairman, I yield back.
    Chairman Obernolte. The gentlewoman yields back.
    I will now recognize Chairman Collins for five minutes for 
his questions.
    Mr. Collins. Thank you, Mr. Chairman.
    We've heard China talk a lot about how they want to be the 
world leader in everything from social, economic, military, 
even in the space realm. And I think that's where I want to 
kind of start out with Mr. Watney and Mr. Kratsios. Although 
China does lag behind the United States on AI capabilities, you 
know, the Chinese Communist Party is spending billions on 
industrial policy to accelerate innovation and workforce 
development. Can you both elaborate on how Congress can 
leverage the government's unique AI assets to establish 
effective public-private partnerships to keep us ahead of the 
Chinese?
    Mr. Watney. Thank you, Representative. Great question. I 
think I'll start by returning to sort of the cybersecurity 
point that I mentioned in my testimony. But the--between the 
Department of Commerce and sort of the larger national security 
community, we've been engaged in sort of a series of pretty 
robust and sophisticated export controls on top AI chips to try 
to prevent China from achieving kind of state-of-the-art models 
and make sure that the United States maintains its 
technological leadership. But I'm quite concerned if they're 
not complemented by very strong kind of cybersecurity 
standards, in some sense, on the back end, you can still end up 
losing your model development just as easily as you can on the 
front end. So I think that's going to be point No. 1.
    Point No. 2 is that we should definitely leverage the fact 
that the United States has this huge, dynamic, open ecosystem 
for innovation. Ultimately, the United States is willing to 
work with democracies all around the world. We have always been 
the home for global talent from all around the world, and 
that's enabled us to kind of be a pivotal leader in innovation. 
China does have sort of a more closed innovation ecosystem, and 
I think we should make sure to leverage that. And one thing I 
know has been a part of discussions before in, say, the CHIPS 
and Science Act is greater opportunities to allow stem Ph.D. 
students from around the world who are studying at U.S. 
universities to be able to stay here and make sure that we're 
sort of strengthening our ecosystem that way.
    Mr. Kratsios. I think there's two ways to approach it. You 
have to take both a promote-and-protect set of policies to kind 
of should ensure, in my opinion, this American leadership in 
artificial intelligence. On the protect side, I think Caleb 
made some really good points. And I think--sorry, I applaud the 
Commerce Department for the efforts they made in sort of 
reupping and improving the export controls that came in earlier 
this week.
    But I think the--on the promote side, something that's very 
important to stress is that the United States has a very unique 
free market approach to innovation. And it's markedly different 
than the way that the CCP attempts to challenge these issues. 
And I think the strength of the U.S. system is we allow this 
free market approach to have certain ideas ultimately succeed 
and other ones that are ideas that you never thought could ever 
succeed or would be the answer ultimately are. So in some 
sense, I think we have an advantage in that sense, and our free 
market approach is we will win ultimately because of it, not in 
spite of it.
    I think just one small anecdote about China, which I think 
is fascinating on the large language model front is one 
inhibitor they have to their large language model development 
is their strict sort of approach to censorship. They 
essentially have mandated to all of their language model 
developers, as one analyst put it, to make sure that their 
models can't even count to 10 because 8 and 9 are in sequence, 
and you're not allowed to talk about 1989. So they have a 
number of challenges that they themselves have to deal with in 
attempting to get these models to conform with some of their 
absurd authoritarian approaches.
    Mr. Collins. OK. Thank you.
    Dr. Bender, in your testimony, you speak about AI 
identifying and classifying people through text and images and 
also the risk of surveillance and oppression. With the ability 
of foreign-owned companies like TikTok to leverage AI against 
the American people, what safeguards need to be put in place 
and--to protect us from our adversaries?
    Dr. Bender. Thank you. I think we have an opportunity here 
to set standards for protecting personal individual freedom 
around, you know, what does it mean to have control over one's 
own data? What does it mean to have control over how we are 
represented online? And if we set those regulations for, you 
know, software that's used by U.S. citizens or software that 
operates in the United States, then we can take a leadership 
role there and do so in a way that reflects American values.
    Mr. Collins. All right. Thank you. That's all I have, Mr. 
Chairman. I yield back.
    Chairman Obernolte. The gentleman yields back.
    We will hear next from Ranking Member Stevens for five 
minutes for your questions.
    Ms. Stevens. Thank you, Mr. Chair. And I would like to 
submit a letter for the record from the Center for AI and 
Digital Policy.
    Chairman Obernolte. Without objection, so ordered.
    Ms. Stevens. Great. Thank you.
    And how delighted to hear so many of our witnesses. Mr. 
Kratsios, Mr. Watney endorse funding the NAIRR, you know, the 
National AI Research Resource. I think that would be very 
important, and many of us have called on the Administration to 
do so.
    And, Ms. Tabassi, could you provide an update on the 
critical work that AIRC is doing and how that is being 
perceived by industry at this time?
    Ms. Tabassi. Sorry, who is doing?
    Ms. Stevens. That you're doing through the Responsible AI 
Resource Center through NIST.
    Ms. Tabassi. Oh, thank you.
    Ms. Stevens. Yes.
    Ms. Tabassi. Thank you so very much. Yes. We launched the 
AI Resource Center end of March, tried to be a one-stop shop 
for foundational content, technical documents, everything 
that's needed for discussions of AI and AI risk. So it includes 
AI RMF. It includes the playbook and an interactive forum to 
make it easy for everybody to use. It includes a glossary 
because, as Dr. Bender mentioned, the importance of having 
common vocabulary and making sure that you're in a shared 
understanding. There is a metrics hub to bring people--to give 
people everything that's happening in the world of the 
measurement. We are going to add a standard tracker. All of 
these things are trying to help the community with 
operationalization of the AI RMF, particularly small-, medium-
sized businesses that need more help and support in 
operationalization of the AI RMF. We also like that to be a 
platform for engagement, so beyond that, just information-
sharing, make it a platform for conversations around AI risk 
management and AI evaluations.
    Ms. Stevens. And, Dr. Bender, how else should the NIST 
framework serve as a baseline for monitoring and mitigating AI 
risks?
    Dr. Bender. I think it's a wonderful set of guidance. The 
question is how do we make sure that people use it? And I see a 
couple of pathways there. One is through Federal procurement, 
so any company who wants to do business with the Federal 
Government would have to follow these wonderful procedures. And 
then another is actual, you know, regulatory enforcement that 
companies would have to do to stay on the right side of the law 
that would empower the people working on the inside trying to 
figure out how to do the right thing to actually be heard.
    Ms. Stevens. Yes. And, Mr. Watney, I was obviously excited 
to see you mention in your testimony privacy, preserving 
machine learning. And like you said, AI models require massive 
amounts of data to learn and function. And we must ensure 
better protections are in place for the data sets and tools in 
AI training. And look, this is why we're excited about the PET 
bill, the Privacy Enhancing Technology Research Act. So what 
are the consequences of not protecting data privacy when 
training AI systems?
    Mr. Watney. Yes, I think there's a few levels to this. One 
is, obviously, on just the surface level, consumers might have 
less trust in systems if they don't know that their information 
is being protected. I think to sort of create broader buy-in 
across the whole ecosystem, it'd be helpful to use some of 
these privacy-preserving machine learning techniques. I also 
think at an international level I'm sort of concerned about a 
broader trend where democracies might feel the need to 
compromise on their internal privacy protections in order to 
compete with more authoritarian regimes. China is sometimes 
perceived to have certain advantages in AI because they have 
laxer privacy protections. But if we could again shift the 
playing field in favor of privacy-preserving machine learning 
models that could enable democracies to maintain the lead in AI 
without sort of feeling----
    Ms. Stevens. Yes, we can have open source, and we can also 
have privacy.
    Mr. Watney. Right.
    Ms. Stevens. That's the goal. And I just want to get in 
here real quick a question about workforce because the career 
pathways are just underdeveloped at this point. And so kind of 
for anyone who wants to jump in, I just want to talk about and 
see if you have comments about approaches, the RMF approaches, 
AI skills and job activities for risk management. We've had a 
lot of conversations on this Committee about cyber. We need an 
AI workforce. What's going to go into that? How do we start 
thinking about it? And we have a former CTO here.
    Mr. Kratsios. I think there's a couple ways to think about 
it. I think the first thing whenever I sort of analyze these 
types of questions is what are the pools of current 
appropriated dollars that are used toward education and 
workforce and then try to map those to the areas where you 
believe are most relevant to the particular educational sort of 
upskilling that we have to do on the front of AI.
    I think an area that's very ripe that sits primarily within 
some of the work that NSF is doing on K through 12, development 
of curricula. So you can't teach any of this stuff. The 
curricula doesn't exist. And this is something that has 
actually been happening as part of the National Quantum 
Initiative, which I think may be interesting to think about 
from an AI standpoint is there aren't sort of K through 12 
courses for quantum. So the question is like how can you 
prepare students over time and be in a position to leverage it? 
And I think the same sort of thinking can kind of go into the 
AI sense where, if you can develop the right curricula, then 
you can actually have, you know, in power, sort of educators 
with tools to move forward.
    Ms. Stevens. That's great. Thank you, Mr. Chair. We'll 
yield back.
    Chairman Obernolte. The gentlewoman yields back.
    We'll hear next from the Chairman of the Full Committee, 
Mr. Lucas, for five minutes.
    Chairman Lucas. Thank you, Mr. Chairman.
    Ms. Tabassi, in your written testimony, you highlight how 
NIST has begun developing industry--specific profiles for 
operationalizing the Risk Management Framework? What is your 
assessment of the current gaps in the technological 
infrastructure, tools, standards, that could slow down Federal 
agency adoption of the Risk Management Framework?
    Ms. Tabassi. Thank you very much for the question. I think 
the biggest technical challenge and technical gap is 
availability of metrics, methodologies, test environment, and 
standards for evaluations of AI systems. And I think it was 
also mentioned that we need to evaluate AI systems beyond their 
functionality and performance, beyond their technical 
robustness and measure the societal robustness. We need to be 
able to measure AI risk and impact. And those measurements 
ought to be done where the AI system in its native context in 
interacting and being used, operated by the humans, impacting 
in--interaction with humans that are being impacted or 
influenced by the systems. And those measurement sciences, that 
test environment doesn't exist today.
    Chairman Lucas. Following up on that, Mr. Kratsios, in your 
experience building AI infrastructure at Scale and developing 
AI policy at OSTP (Office of Science and Technology Policy) and 
DOD, what structural or resource challenges do you anticipate 
agencies receiving when adopting this Risk Management Framework 
into their development, testing, and procurement processes?
    Mr. Kratsios. You know, as I've seen agencies attempt over 
time to sort of continue with a regulatory approach, but in the 
light of new technology, the challenge is always slowly getting 
them up to speed on what it actually means to do the testing 
and evaluation necessary to approve the use of that technology. 
I think something that has been looked at, for example, by the 
Department of Transportation for many years is how you can 
appropriately be able to verify or validate that a vehicle is 
safe for operation. And this moves sort of in a world where 
there weren't a ton of these vehicles and now there are. There 
has to be the right sort of testing and evaluation methodology 
available for them to be able to do that sign-off. And I think 
the same goes with artificial intelligence. And as the Chairman 
mentioned, you know, you've already seen, you know, quick 
progress in FDA in being able to adapt some of this stuff, but 
I think at the end of the day, the real challenge will be can 
we have testing and evaluation standards that can allow these 
regulators to incorporate into their efforts?
    Chairman Lucas. Continuing with you, Mr. Kratsios, in your 
testimony, you point out that the implementation of existing AI 
legislation and Executive orders have fallen short. To date, 
less than 40 percent of the 45 legal requirements associated 
with the AI in Government Act and the 2019 and 2020 AI 
Executive orders have been implemented, and the Office of 
Management and Budget is yet to publish required guidance to 
support agency use and acquisition of AI. What are the some of 
the potential harms in not fully implementing the existing laws 
and Executive orders as they relate to responsible AI now?
    Mr. Kratsios. Yes, I think I am heartened to hear that a 
potential Executive order may be coming out this month, which 
will address some of the issues that are still outstanding from 
those EOs and legislation. I think the biggest challenge is 
that a lot of the requirements from the Executive orders and 
from the legislation are important foundational pieces that 
future regulatory structures are built on top of. So if you 
don't have a very clear understanding of sort of what the 
potential use cases are in an agency or what regulatory--if you 
don't do the hard work to actually assess where AI is going to 
impact the regulation--the regulatory regime that you're sort 
of overseeing, it's very hard for you to actually then proceed 
with actually doing the regulation itself. So I think we need 
to get--make sure that we have a strong foundation in place, 
and in doing so, then we can build on the important stuff that 
we've been talking about today.
    Chairman Lucas. Finally, Ms. Tabassi, NIST functions as the 
Federal AI standards coordinator and works across the 
government with stakeholders to identify critical standards, 
development activity, strategies, and gaps. How is NIST helping 
the Federal Government think about our role in developing 
technical standards for AI?
    Ms. Tabassi. We are working with all of the government 
agencies across in understanding their priorities, their needs 
for standards, but also working on scientific underpinning 
needed for development of the clear, implementable standards. 
That goes from the common definitions to establishing 
trustworthiness characteristics to advancing tests and 
measurements for AI standards----
    Chairman Lucas. Thank you.
    Ms. Tabassi [continuing]. For AI systems.
    Chairman Lucas. I yield back, Mr. Chairman.
    Chairman Obernolte. , gentleman yields back.
    We'll hear now from the Ranking Member of the Full 
Committee, Ms. Lofgren, for five minutes for her questions.
    Ms. Lofgren. Thank you, Mr. Chairman.
    First, I'd like to ask unanimous consent to put my 
statement into the record.
    Chairman Obernolte. Without exception--objection, so 
ordered.
    [The prepared statement of Ms. Lofgren follows:]

    Thank you, Chairman Obernolte and Ranking Member Foushee of 
our Investigations and Oversight Subcommittee, and Chairman 
Collins and Ranking Member Stevens of our Research and 
Technology Subcommittee, for holding today's hearing. I would 
also like to welcome our distinguished panel of witnesses.
    This hearing is about what questions we need to answer and 
tools we need to build to get meaningful governance of AI 
systems. Our Federal science agencies have taken significant 
first steps to address this challenge, most notably, NIST's 
work on the AI Risk Management Framework. In the meantime, the 
technology itself continues to rapidly advance in both 
capabilities and applications. I believe regulation of AI will 
be necessary, but I am also keenly aware that we must strike a 
balance that allows for innovation and ensures the U.S. 
maintains leadership.
    One critical question to answer in the near term is whether 
we can use a single AI governance framework or if governance 
should be broken out by sector or use case. There is currently 
some debate about how to control the technology itself, 
including through licensing, but ultimately our goal should be 
to stop or at least reduce any negative outcomes of its use. 
The NIST Risk Management Framework recognizes that context is 
important for mitigating the risks of AI deployment, and I 
suspect regulation should follow that example.
    I am also keenly interested in the intersection of AI and 
intellectual property. To ensure intellectual property 
protections and promote innovation, we must develop tools, 
testing, and standards to track the use of copyrighted content 
by AI systems. That technical foundation will necessarily 
underpin any policy solution agreed to by both the content 
creation community and AI platforms.
    Finally, I am curious about what policy levers Congress may 
have to incentivize good AI governance practices. As my 
colleague Representative Lieu has often raised, the Federal 
government can influence the AI ecosystem by requiring AI risk 
management on systems adopted by Federal agencies and 
contractors. However, a shift in Federal policy to require AI 
risk management practices will require mature standards and a 
workforce capable of implementing them.
    While the contours of a regulatory framework are still 
being debated, it is clear we will need to lay the technical 
groundwork to govern AI. I thank the witnesses for joining us 
today for this very important discussion.
    I yield back.

    Ms. Lofgren. And then, you know, this is a great day to be 
having this hearing because we are working together in a 
bipartisan way, honestly, to try and find solutions to 
challenges that face our society. And that's a pleasure to be 
doing. I think that Chairman Obernolte posed the options very 
well, which is do you want a single agency that we expect to 
know everything about every law, or do you want to enhance the 
capability of existing agencies that have expertise in an area 
of law to apply that in AI? And I think, personally, the latter 
is likely to be successful. I mean, we have a whole body of law 
that's been developed on discrimination and hiring or 
intellectual property or on and on and on. It's impossible to 
think how one agency could replicate all of that knowledge.
    So I'm interested in how we might empower not only 
agencies, but individuals to protect themselves from violations 
of existing law. And I think some of that comes down to the 
metrics question and the measurement issues because, for 
example, it's already illegal to discriminate on the basis of 
ethnicity or religion in hiring, but if you don't know that's 
happening to you through the use of AI, how do you avail 
yourself of that protection?
    And I've been thinking a lot about how we might impose some 
responsibility on those who have created AI systems. Frankly, 
some of the AI developers have revealed to me privately they 
don't fully understand how what they've developed is operating. 
And so if they don't, certainly we are not going to, but we 
need to put the responsibility on the creators for violations, 
it seems to me.
    I--so that's a question for any of you who wants to deal 
with it. And I have a second question if you can. The whole 
idea of licensing strikes me as improbable for a technology 
that even the developers don't fully understand. And so I'm 
thinking about licensing versus registration so that we might 
have an opportunity to have insight into what's being 
developed, but furthermore, to have a--each technology in a 
regulatory scheme to protect the humans against the violation. 
Anybody who can address those two issues, I would be greatly 
interested.
    Dr. Bender. I'd love to speak quickly to that point. I 
agree that having this spread out across the agencies is really 
important. I think the FTC (Federal Trade Commission) is doing 
an excellent job saying there is no AI loophole. They regulate 
what they regulate. It doesn't matter if somebody's using 
automation to do the thing. It still falls under their 
jurisdiction. Likewise, you know, the--for medical components, 
we have methodologies for testing whether something works well 
enough. If there's some pattern matching going on in there, it 
should still pass the same tests. And by tests, I don't mean 
multiple choice tests, I mean, experiments, right?
    In terms of licensing versus registration, those concepts 
to me seem to belong to this domain of everything machines, and 
I don't think that that's a sensible way to think about this. I 
think it's worth keeping in mind that something like ChatGPT 
sounds like it can do everything because it can give us 
synthetic text on any topic, but that doesn't mean it's a 
robolawyer or robotherapist or robodoctor and so on. And so I 
think keeping things in terms of existing rights and then 
figuring out where we need to shore up those rights is a good 
way to think about it.
    Mr. Kratsios. Yes, I agree with Dr. Bender. I think the 
concept of trying to create a licensing or registration regime 
is, I think, incredibly difficult, primarily from essentially 
the same thing you're saying. But another way maybe to say it 
is from a definitional standpoint. Like what are you 
registering? What does it need to be in order to be licensed? 
And even coming up with some sort of valid definition that 
doesn't change over time. There's a lot of discussion around is 
it a frontier model, is it not? You know, is it really 
powerful, is it not so powerful? Those types of questions are 
extraordinarily hard, and those definitions are really hard to 
kind of lay out in my opinion.
    Mr. Watney. Yes, I just return, I think, to the importance 
of additional investments in both interpretability and sort of 
broader benchmarking. Again, it's just remarkable how much it's 
actually hard to have a shared conversation about what are the 
risks we're actually concerned about? What are the kinds of 
system capabilities that we think these things do or do not 
have? And kind of a real deep set of benchmarks around 
performance in the real world on open-ended tasks when humans 
can be a part of the decisionmaking loop I think would just be 
so helpful for actually grounding a larger discussion here.
    Ms. Lofgren. All right. Thank you, Mr. Chair.
    Chairman Obernolte. The gentlewoman yields back.
    We'll hear now from the gentleman from Texas, Mr. Babin. 
For five minutes, you're recognized.
    Mr. Babin. Thank you, Mr. Chairman. I appreciate it, and 
appreciate all your witnesses for being here.
    Ms. Tabassi, as you know, the Port of Houston is a vital 
economic generator in my district there in east Texas, District 
36, but it's also a national security asset that rebuffs 
thousands of attempted cyber attacks each and every year. AI 
has the potential to bolster our defenses for critical 
infrastructure like the Port of Houston, but it can also be an 
asset for nefarious actors as well. How can NIST partner with 
agencies like the Department of Homeland Security, the Federal 
Aviation Administration, Pipeline and Hazardous Materials 
Safety Administration to develop and promote AI policies that 
will safeguard our critical infrastructure, including major 
ports like the Port of Houston?
    Ms. Tabassi. Thank you very much for that question. And AI 
RMF lays kind of the foundations and the right guidance for 
developing all of these other guidelines on our--we call them 
profile of the AI RMF, and we're already working with, for 
example, our colleagues across the agencies, with Department of 
Homeland Security operationalizing AI RMF, with our colleagues 
at the DOD on advancing measurement and evaluations of the AI. 
So coordination is the key and is vital, and we'll be happy to 
work on and build on top of AI RMF to address all of these 
important questions.
    Mr. Babin. Thank you very much.
    And, Mr. Kratsios, by many metrics, China has caught up and 
in many cases surpassed the United States in research and 
commercial capabilities. Chinese universities are publishing 
many more research papers than U.S. institutions. They received 
nearly the same share of citations as U.S. papers. How 
concerned are you with the pace of AI progress in China? And 
then after you finish, I'd like to open it up for all four of 
you.
    Mr. Kratsios. I continue to remain very concerned, and I 
believe that that's why American leadership in artificial 
intelligence should remain a top national priority. In order to 
sort of maintain our leadership, we have to essentially do four 
things. We have to do research and development, meaning 
increasing spending in R&D and focusing it on fundamental basic 
precompetitive R&D that the private sector is not focused on.
    The second is on workforce development. That is the area 
where I was talking about earlier. How can we prepare the 
American worker to be able to harness and leverage this 
technology for the benefit of the country?
    The third is on regulations. As we talked about here today, 
we have to be in an environment where the regs that we have are 
leading the world or people are copying what we're doing, not 
the other way around, and create a system that is flexible 
enough to promote innovation, but also responsible enough to 
protect American citizens.
    And the fourth is through international alliances. We must 
work with likeminded partners and democracies in order to 
ensure that this technology is built to reflect our values, not 
authoritarian values. And I think if we can continue to sort of 
leverage and push the needle on all four of those areas, we can 
and will remain ahead.
    Mr. Babin. Thank you very much.
    And briefly, anyone else?
    Dr. Bender. Yes, just briefly speaking from academia, I see 
that the research community in China is vibrant and very well 
supported by their national funding initiatives, and I would 
love to see similar things going on here, especially including 
research funds not just to people developing what they call AI 
systems, but also people in the humanities and social sciences 
who can study how they're affecting society.
    Mr. Babin. All right. Thank you very much.
    And, Mr. Kratsios, one more. A few days ago, China released 
new standards that training datasets and algorithmic outputs 
must pass to go to market. They have also built an algorithmic 
registry whereby algorithms above a certain capability 
threshold need to be registered with the government. The United 
States must avoid such draconian measures while ensuring that 
we protect our citizens from potential harm. How can the U.S.-
set transparency and risk benchmarks align with our democratic 
values? And what tools and standards do agencies need to ensure 
that those benchmarks are met?
    Mr. Kratsios. Yes, that's a really good point, bringing 
that up. I think that made a lot of waves in the artificial 
intelligence community of how the CCP is thinking about sort of 
enforcing their own sort of viewpoint in the world through this 
regulatory regime.
    On the part of the United States, the best approach that we 
can do is do the very hard research and development associated 
with developing a testing and evaluation regime for these large 
language models. Right now, there is no standardized T&E 
process, but the government has endorsed for these large 
language models. Scale has taken an effort to create an 
industry standard itself where we released our own testing and 
evaluation standard that combines both an automated approach to 
artificial intelligence and humans together to test these 
models. But I'm excited to hear about the incredible work that 
NIST is doing. But all this stuff can't happen fast enough. 
It's important that the United States is out there with world-
leading standards as a way to push back on the approach that 
the CCP is taking.
    Mr. Babin. Thank you. And my time has expired, so I yield 
back, Mr. Chairman.
    Chairman Obernolte. The gentleman yields back.
    We'll go next to the gentlewoman from Oregon. Ms. Bonamici, 
you're recognized for five minutes.
    Ms. Bonamici. Thank you to the Chairs and the Ranking 
Members. Thank you to the witnesses for being here today.
    As artificial intelligence or, as Dr. Bender says, 
automation is rapidly expanding in our daily lives, I remain 
concerned about how to prevent incorrect bias. The Stanford 
Institute for Human-Centered Artificial Intelligence did a 
report showing that underbanked communities, for example, those 
who have a bank account but might also tap into alternative 
financial services like payday loans or check cashing services, 
face disproportionate errors and denials from credit reporting 
models that rely on AI. So denying someone access to credit 
because of an inadequate model, for example, could cause a 
consumer to lose her home or it will affect their credit and 
financial security.
    So I request unanimous consent to enter this study into the 
record.
    Chairman Obernolte. Without objection, so ordered.
    Ms. Bonamici. Thank you, Mr. Chairman.
    Dr. Bender, nice to see you again. I want to ask about how 
we can best correct for errors in data in these models that 
integrate biases. So, of course, I support training the 
workforce on implicit bias, more recruitment of diverse 
researchers and engineers, updating civil rights and consumer 
protection statutes, for example. But is that enough to 
effectively address this issue?
    Dr. Bender. Those are all good ideas. I think there's more 
that's needed. I think, first, we have to recognize there's no 
such thing as an unbiased training dataset. There's always 
going to be some remaining bias, but still less biased is 
better, and it's worth striving for. And I think that, in 
addition to what you've already listed, a really key tool that 
we have is documentation of training data because that allows 
us to ask questions like: Is this trained on a set of data that 
would lead us to suggest--to want the patterns in that training 
data matched in our use case. So it's helpful at procurement 
time, and it's also very helpful for people who are seeking 
recourse. Someone mentioned earlier, I think it was Ranking 
Member Lofgren, that if you are experiencing discrimination but 
you don't know, what do you do about it? And I think 
documentation about training data will be helpful in that 
regard.
    Ms. Bonamici. Thank you so much. And I'm going to ask this. 
I want to follow up on a question that was started by the Chair 
Obernolte and Ranking Member Lofgren. We assume there's going 
to be some kind of regulation, so I'm going to give you three 
choices. I just want to hear briefly from each of you. Existing 
entity like the FTC, a new entity that's created hopefully with 
the expertise that's needed, or is it going to depend on the 
topic? And Department of Education, the issues relating to 
education ideas, and the Department of Health and Human 
services, the issues related to health, do you send employment 
issues to Department of Labor, for example? So if you just want 
to go down the line and say, existing entity, a new entity, or 
depends on the topic, that would be helpful.
    Mr. Watney. I think it broadly depends on the entity. I 
think there's--to your earlier points, like there's so much 
already embedded law everywhere and making sure that we're 
enforcing that. There might be sometimes the need for new 
offices within existing agencies, but I think that's probably 
going to be the right balance.
    Ms. Bonamici. Thank you. Dr. Bender?
    Dr. Bender. Depending on the topic, but with some central 
coordinating body, perhaps NIST, to help share expertise 
across.
    Ms. Bonamici. Excellent.
    Mr. Kratsios. Yes, I agree, depending on the body. It 
should be industry-specific and use-case specific.
    Ms. Bonamici. Thank you. Ms. Tabassi?
    Ms. Tabassi. I think a hybrid approach, I think, yes, 
it's--AI is very contextual. It's important to do it for the 
particular use cases. It's also important to make sure that at 
least terminology is the same across.
    Ms. Bonamici. Excellent. Thank you. And, Ms. Tabassi, I 
know the Biden Administration recently published the blueprint, 
of course, the AI Bill of Rights and highlight in there the 
importance of mitigating safety and discriminatory risks. And 
as the Administration works to implement this framework, what 
practices should they adopt to mitigate risks before automation 
is deployed? And how will we know whether these systems are 
ethically implemented? Because we do hear a lot about AI 
ethics, so how will we verify that ethics are embedded within?
    Ms. Tabassi. Right. So in terms of ethics, I think, first, 
again, we need to have a clear definition on what ethics is. In 
AI RMF we tried not to use ethics because it has dependencies 
to the culture, to the time, and tried to unpack it to the 
concepts of the trustworthiness. But it all, again, goes back 
to measurement and having test environments and methodologies 
and metrics for tests to provide that type of information. And 
that's something that's missing now. And there's no quick fix. 
There's a lot of research that's needed to build that type of 
test environments.
    Ms. Bonamici. And I have a few seconds left. Dr. Bender, 
I'll ask you. Ethics in automation or artificial intelligence, 
does it mean the same thing to everybody? Are there different 
definitions of ethics? And how----
    Dr. Bender. Yes----
    Ms. Bonamici. Who decides what ethics means in this 
context?
    Dr. Bender. There's different definitions. The one that I 
like best comes from Dr. Margaret Mitchell, who talks about it 
basically in the process. Are you developing your system in a 
way that has an eye toward people who might be harmed by it and 
making sure that their interests are represented?
    Ms. Bonamici. That's very helpful. And I'm about to run out 
of time, so I yield back.
    Chairman Obernolte. The gentlewoman yields back.
    We'll go next to the gentleman from Indiana, Mr. Baird. 
You're recognized for five minutes.
    Mr. Baird. Thank you, Mr. Chairman and Ranking Member. I 
really appreciate that you are holding this Committee session. 
And I really appreciate, I always do, I appreciate all the 
witnesses sharing your expertise with this Committee as we 
struggle with trying to find ways to protect the public.
    And so this Committee has played an instrumental role in 
passing the CHIPS and Science Act. And in my district in 
Indiana, we have plans to start production of the chips or the 
semiconductors in the next five years in a fab lab in West 
Lafayette. But in this process, I learned that the average car 
has anywhere from 1,400 to 1,500 chips, and some cars have even 
more than that. And then my background is agriculture. And, you 
know, the farm equipment and machinery that we're using to 
implement more and more precision agriculture is extremely 
important.
    So since AI is playing such a major role in many of these 
industries, I'm curious to know what role it's playing in the 
chip manufacturing, or what does it have the capability to do 
in this industry? Ms. Tabassi, do you want to start that 
conversation or----
    Ms. Tabassi. Obviously, chips and--specialized chips for AI 
are basically the engine and power. It's really important. So 
at NIST we--our researchers are working on some specialized AI 
chips, kind of next generations that can do many of those 
computations inside the chips. And we work with the community 
to advance this type of research.
    Mr. Kratsios. Yes, as we have seen over the last six months 
with the rise of, I guess, the NVIDIA stock price, it's become 
very clear that sort of GPUs (graphics processing units) are in 
sort of insatiable demand globally. So I think the one area 
that I think is important for us to continue to consider is who 
has access to leading edge, essentially, APU--AI-specific GPUs. 
And, you know, we've taken--it sounds like the Administration 
has taken some thinking around whether certain countries of 
concern should not have access to them because they essentially 
are the--sort of a foundational asset to any type of AI 
development. And I think that needs to continue to have serious 
exploration in the months ahead and continue to be vigilant on 
it because without these chips, you can't develop these 
frontier models.
    Dr. Bender. I think in that context I'd like to point out 
that all of the energy right now in this field is on bigger and 
bigger models that require these chips and lots of them and 
lots of energy to run them and lots of water to cool them, and 
there's real environmental costs there. And so if we had 
investigations efforts going into finding more streamlined, 
less data-hungry, less energy-hungry ways of doing this, that 
could be very valuable.
    Mr. Watney. I think, yes, at the highest level it's just 
really worth keeping a careful eye on this. I think by 
anticipating or predicting trends in chip design, that's going 
to tell us a lot about future AI systems, both kind of 
geographically where they're being built, what their underlying 
capabilities are. You're seeing already a lot of specialization 
in the difference between maybe consumer-grade electronics, the 
kind of stuff that's going in your personal laptop or phone, 
and then the stuff that's really dedicated and focused on 
training the next frontier of large language models.
    I also think this is a particular industry to try to 
maintain American leadership in. Chip design is itself almost 
just as important as the chip manufacturing. And thankfully, 
the United States and our sort of partner allies do have a 
strong lead in that, but I think maintaining that will be 
really important for shaping the future of the AI field as 
well.
    Mr. Baird. Thank you. My next question--and we don't--we 
only have about a minute left, but, you know, there's been a 
lot of advances in quantum science. They've had some major 
breakthroughs. And so this Committee is probably going to 
approach reauthorization of the National Quantum Initiative 
Act. So what do the advancements in quantum computing mean for 
AI? Any volunteers?
    Mr. Watney. I'll just chime in briefly. I think a lot of 
the concerns about quantum or the implications are sort of 
similar. I think on a cybersecurity perspective, I think 
there's a sort of defensive-to-offensive balance within 
cybersecurity and between, you know, major advancements in AI, 
but also quantum. There's a real chance that that defense-to-
offensive balance just totally flips. And I think the U.S. 
Government has a real opportunity through an ambitious R&D 
agenda to kind of purposefully tilt the terrain back in favor 
of defenders and make sure that we're sort of like on the 
leading edge of that. And I think that applies just as much to 
quantum as it does to AI.
    Mr. Baird. Thank you. And I see my time is up, and so I 
yield back.
    Chairman Obernolte. The gentleman yields back.
    We will go next to the gentleman from Illinois, Mr. Casten. 
You're recognized for five minutes.
    Mr. Casten. Thank you, Mr. Chair and to all our witnesses. 
I love this topic and it's fascinating and I've been thinking 
about it for a long time. And I'm struggling to be pithy as I 
frame my questions because I'm stuck on the fact that back in 
1998 when I was in grad school, I was taking classes learning 
how to program neural networks and genetic algorithms and 
machine learning. And we are talking about this as if it is a 
new thing with cutting-edge entrepreneurs who are just sort of 
plowing the field for the first time. And, you know--and back 
in the 1990's, this was--this wasn't like this is cutting-edge 
research. This is if you want to get a job out of grad school, 
you can go work to a hedge fund that's using high-speed trading 
algorithms that are based on this and you need to understand 
this. There's a technology consulting firm who is doing--they 
didn't call it big data at the time, but it's crunching and 
finding out that people who buy diapers also buy six packs of 
beer and you should reorganize your shops. I mean, we all 
read--these are 30-year-olds. Now I see you all nodding, but 
just is there anybody who--do any of you think that this is not 
a technology that has been commercially available for at least 
three decades? Now granted in simpler forms, right, but the 
question of ethics, the question of how do we program these 
things, I remember having these conversations 30 years ago.
    Dr. Bender. It's not new, you're right.
    Mr. Casten. OK.
    Dr. Bender. And it's also--when it gets called neural nets, 
it's based on a 1950's notion--it's a bad model of a 1950's 
notion of how neurons work.
    Mr. Casten. Fair. Thank you. As a former biochemical 
engineer, I appreciate that correction.
    I raise that because I get a little bit nervous if we frame 
this as saying just let the entrepreneurs take care of this 
and, you know, don't get in the way of regulation if we don't 
first say, OK, well, what--over the last 30 years, have we--
and, Mr. Watney, you mentioned about the need for this. Do we 
actually have a legal framework--because I'm not aware of one--
that right now says if you are using an AI system, we have--and 
you violate laws or you violate certain ethics rules, that we 
are clear about who is to be held to account.
    Mr. Watney. This is just, I think, a big murky area of law 
that we don't really have clear guidance on. And part of it 
comes down to not only who are the actors responsible, but like 
where does liability in some sense most naturally fall? I think 
this kind of returns back to the importance of understanding at 
a deeper level how the models are making decisions. If we had a 
sort of--if we could tear down the veil of the black box, if we 
could sort of peer behind and understand at a more mechanistic 
level how these models are making decisions, I think it'd be so 
much more obvious kind of where maybe biases are coming from, 
where inaccuracies are, what are the kinds of----
    Mr. Casten. So if I could because I want to just pick on 
that point. We had--I'm on the Financial Services Committee. 
Two years ago, we had a question that one of the big credit 
card companies was asking us to help them because Facebook 
would not tell them whether their ad targeting software was 
compliant with the fair lending rules. And so we had a fairly 
robust back-and-forth with the CFPB (Consumer Financial 
Protection Bureau) about who would be accountable. And it's--it 
still is to some degree--the current director has a path, but I 
think legally, it's still somewhat an open question.
    More than 10 years ago, the--this is not public information 
so I'm going to be a little bit shady. But there was a high-
speed trading firm who found out that their trading algorithm 
was making money by shorting an anticipated Russian invasion of 
Crimea. And they--and arguably, that didn't break any law. It 
was unethical, but it didn't break any law. And they chose to 
shut that down.
    And so if we--I guess my question, the reason why I 
interrupted you--and I apologize for interrupting you is--is 
this even something that you can program a fix to, or is this 
really something where some--whether government entity or, you 
know, white hat nonprofit has to have some degree of audit 
responsibility and an obligation to maintain auditable code?
    Mr. Watney. Right, I think--I don't--I mean, I'm less 
familiar with the specific context of this scenario, but I 
would guess it's totally plausible Facebook or the high-speed 
trading firm didn't even know what their model was sort of 
making a decision on, which sort of gets down to it's really 
hard to hold different parties accountable or to know kind of 
where things are going wrong without an understanding of where 
the model is kind of making decisions.
    I think, to an earlier point that was mentioned, like 
liability is probably an underrated lever here to kind of like 
carefully align interests across the ecosystem. And I think 
there's been a lot of other conversations about other 
regulatory tools, and, you know, those may or may not be 
appropriate, but liability seems like underdiscussed, I think.
    Mr. Casten. Well, if any of you--I'm going to get tight on 
time here--but Lori Trahan and Adam Schiff and I introduced a 
bill to give the FCC (Federal Communications Commission) the 
authority to essentially say you have to be able to--if you're 
using these codes, you have to have--your algorithms are 
private, that's fine, but you have to have the ability to reach 
in and inspect, which raises the question of is that the right 
entity? You know, do they have the technical horsepower to do 
that? And could you even have a single national entity with 
that jurisdiction, given as the servers are all over the world? 
And if any of you have thoughts or criticisms, I'd love to 
engage with you because I do think it's this meaty question 
that, at least from where I sit, you have to have someone with 
auditor rights who has the public interest at heart. If any of 
you have comments on that before I get pulled, I'm happy to 
hear.
    Dr. Bender. Can I just say really quickly, if I am running 
some chemical processing plant and without my knowledge I'm 
polluting a river next to me, aren't I still liable for that?
    Mr. Casten. Well, so I guess the question would be in the 
case of the CFPB, who is liable for the Fair Lending Act 
violation, the bank who used the ad or the algorithmic company 
who said I didn't actually program to do it, it just evolved 
that way? I think there are cases where it's clean. There are a 
lot of cases where it's less clean. Who's using the algorithm? 
Who was the benefit--who was the aggrieved party? And are you 
liable for an algorithm that you didn't program, right, but it 
evolved into doing something that you don't trust?
    Dr. Bender. Yes. I'd be leery of biological metaphors like 
evolution, always.
    Chairman Obernolte. The gentleman's time has expired. We'll 
go next to the gentleman from New Jersey. Mr. Kean, you're 
recognized for five minutes.
    Mr. Kean. Thank you, Mr. Chairman. And I want to associate 
myself with Representative Stevens' support and strong advocacy 
for the Privacy Enhancing Technology Research Act that passed 
this Committee and I agree needs to get--go to the floor. And, 
as a cosponsor of that bill, it is surely important that we 
focus on government coordination to ensure responsible data 
use.
    My first question is for Ms. Tabassi. I'm interested in 
understanding how NIST is engaging with States' implementation 
of their various task forces. And can you provide insights as 
to whether it's collaborative, when--do you have any concerns 
that--as you're approaching their--either their risk mitigation 
strategy or their public safety focus on their local State 
labs, those efforts?
    Ms. Tabassi. I'm sorry, collaboration with----
    Mr. Kean. When you're looking at--so, for example, New 
Jersey is starting to look at a State artificial intelligence 
task force and looking at a little bit of the--whether you're 
focusing on the State level or the--on the Federal regulatory, 
what guidance are you--from a NIST perspective, what's your 
best recommendation, whether it's State or Federal partners are 
getting involved in this?
    Ms. Tabassi. So in development of the AI RMF we engage a 
very broad community, and we heard from all sorts of 
stakeholders, including State, local governments, 
international, and globally. I don't have any information about 
particularly the task force that you mentioned. But again, in 
all of these discussions, I do think that it's important to 
have some sort of an interoperable lexicon, a horizontal 
foundation of at least having the same vocabulary and 
understanding of the risk and harms that give some sort of 
interoperability across all of the applications and all of the 
use cases.
    Mr. Kean. Thank you. And this, I think, is for anyone who 
feels themselves appropriate to answer it. In light of the 
recent Senate roundtable where executives of major AI companies 
called for a new Federal agency to regulate AI, there are 
concerns about policy alignment with a select few industry 
leaders. The involvement of companies poised to benefit 
financially also raises questions about regulatory fairness. So 
it's worth noting that the Federal Government already has 
agencies in place that are actually involved in AI regulation. 
How can you best balance the regulatory structure and whether 
to create new departments or not create new departments and 
only--and currently enhance things that departments are already 
doing? So Mr.----
    Mr. Kratsios. Yes, I think my view is that there should not 
be a new government AI agency. We should rather focus on use 
case, sector-specific, risk-based guidelines that are rooted in 
sort of the fundamental science that this Committee cares about 
around creating test and evaluation techniques that then can be 
utilized across all the relevant agencies that have spent many 
times a number of decades regulating their industries.
    Mr. Kean. OK.
    Dr. Bender. I'd just like to add to that that I think, 
again, we want it spread out through the agencies, but those 
agencies might need help in building up the expertise to be 
able to cut through AI hype where people being regulated, 
companies being regulated come in and say, well, this is 
different this time because it's AI. We need folks in all the 
different agencies to be able to say, no, it's still our 
jurisdiction.
    Mr. Kean. Thank you. Mr. Watney?
    Mr. Watney. Yes, I think sometimes discussions about like 
new or old agencies, whether they're spread out or centralized, 
in some sense, the more important thing is capabilities. Like 
do we have fundamentally the state capacity somewhere in the 
government to be able to poke and prod at these models in 
useful ways, understand their failure modes and their 
successes, benchmark their success sort of shape the direction 
through science funding. My suspicion is that often this is 
going to end up being spread across different agencies. But the 
more important thing is, does the government have the state 
capacity to actually do this? And then you can sort of figure 
out the like exact structure later.
    Mr. Kean. OK. Thank you. Ms. Tabassi, do you have----
    Ms. Tabassi. All the great things, as we mentioned, and I 
think that expertise in the domains is important so there is 
reasons--that's why we did--we talk about development of the 
profiles or verticals, and that goes the same thing for the 
agencies with certain expertise.
    Mr. Kean. OK. Thank you. And I yield back.
    Chairman Obernolte. The gentleman yields back.
    We will hear next from the gentleman from California. Mr. 
Mullin, you're recognized for five minutes.
    Mr. Mullin. Thank you, Mr. Chair. Thank you all for your 
attendance at this important hearing.
    When we talk about trustworthy AI, the use of such 
technology in machines in the physical world pose a danger that 
I'd like to dig into just a little bit further. In San 
Francisco, which I partially represent, we have seen autonomous 
vehicles, or AVs, which had great promise, struggle to address 
some complex real-world situations. These malfunctions have 
obstructed public transit routes, blocked intersections, and 
impeded first responders from reaching people in need.
    Last month, I led a letter, along with Speaker Emerita 
Pelosi, to the National Highway Traffic Safety Administration 
(NHTSA) to improve its collection of safety data so different 
manufacturers may be compared relative to each other and 
relative to manually operated vehicles. We're waiting to hear 
back from NHTSA on what steps it plans to take. But this is 
just one area where we need to be able to assess AI 
capabilities and its limits. And I'm concerned that we do not 
have clear standards for the assessment of safety.
    So, Ms. Tabassi, could you share more about the work NIST 
is doing in this area relative to safety?
    Ms. Tabassi. Thank you. Safety is being identified as one 
of the seven trustworthiness characteristics of a--in AI RMF 
and it--beyond going--beyond the having definitions for what 
safety means, which understand that now is being defined and 
perceived differently across the different domains. We also 
need to have, as you said, tests and measurements for measuring 
the functionality, capability, and limits on the technical 
robustness, as well as the societal robustness.
    In AI RMF, it mentions that the--in terms of the safety, 
most urgent parameterizations and most risk management is 
required when there are risks to human life and where there are 
risks of serious injuries. And also it mentions that when there 
are cases that significant risks are present, actual harm is 
happening, that there should be--that there's--the deployment 
and development should cease in a safe manner until all of 
those risks are being addressed and managed properly.
    Mr. Mullin. Thank you for that. And switching gears a bit, 
Dr. Bender, as an educator and researcher, do you have any 
thoughts on the topic of better educating Americans so we are 
prepared for the coming onslaught of humanlike content 
generated by AI? What does that practically look like? What are 
we talking about in terms of integrating this into classrooms? 
Are we talking about education campaigns, for example? Can you 
enlighten me?
    Dr. Bender. Yes. So I think one important piece of our next 
steps is leveling up our information literacy, not just, you 
know, in the young generation who are in classrooms right now, 
but across the population so that we can better handle, as you 
say, the onslaught of synthetic media. That's important. I 
think we can't rely on that solely. I think we also need to 
have something on the other end, for example, watermarking. 
Chairman Obernolte suggested maybe watermarking for 
authenticity, as well as watermarking the synthetic media. But 
yes, absolutely. We are living in a new environment where we 
now have to contend with, especially textually, something that 
previously could only have come from people all around us and 
figuring out how to--I see a lot of discourse in the education 
space, talking about making sure people know how to use these 
tools, and not enough about making sure people understand how 
they're actually working and what they're not good for.
    Mr. Mullin. Thank you for that. With that, I yield back.
    Chairman Obernolte. The gentleman yields back.
    We'll go next to the gentlewoman from Pennsylvania. Ms. 
Lee, you're recognized for five minutes.
    Ms. Lee. Thank you, Mr. Chair, and thank you to the 
witnesses for your time and expertise on this critical area of 
technological innovation.
    Every day, individuals and families in my district are 
impacted by algorithms that determine whether their insurance 
claim be accepted or their resume reviewed. Design, decision, 
and development tools--or, excuse me, deployment tools based 
upon defined principles address bias. The key question is what 
policies can best guide how those policies are set?
    There are numerous ethical, privacy, and economic 
imperatives for striking a balance between harnessing the 
benefits of AI and addressing its challenges, which will be 
crucial to ensuring AI truly has a positive impact.
    I talk about being the first Black woman to represent 
Pennsylvania in Congress, so my concerns are strongest, though, 
in ensuring that the advancement of AI technology in our 
society doesn't result in Black folks, the LGBTQI+ community, 
and other marginalized communities being used as sacrificial 
lambs.
    So discussing the practical applications of AI and machine 
learning truly highlights, one, the ethical implications of AI 
technology to the intellectual property and privacy rights, and 
the continual war against misinformation and disinformation. 
It's unrealistic to expect that bias can be eliminated in AI 
tools. It's crucial to identify what kinds of bias assessments 
are utilized prior to deploying the AI system and the fact that 
it will be embedded in a larger system. So equitable outcomes 
and not just unbiased or equitable algorithms should be our 
utmost focus.
    Being born and raised in this country's industrial 
heartland, I'd be remiss to not discuss these implications AI 
will have on our labor and workforce. They're wonderful 
opportunities to improve efficiency and simplify strenuous work 
activities, but we have to remain vigilant and cautious to 
protect all workers and provide them with access and 
opportunities for skills training and education so that they're 
not being left behind in the technological revolution.
    So in everything that I do, the human element is the most 
critical and important to me. This remains the same in making 
sure that the laws and policies that we help to create and 
enforce build better outcomes and that technology supports a 
greater humanity rather than replace it, which is the fear.
    Dr. Bender, bias can present itself in models in a variety 
of forms: racial, statistical, human, psychological, et cetera. 
Not all types of biases are equal. How are AI and machine 
learning decision tools being designed and developed to improve 
the outcomes produced by these decision processes to mitigate 
bias?
    Dr. Bender. So a lot of the work isn't trying to do that at 
all. And Abeba Birhane points out that using machine learning 
is an inherently conservative as a past-preserving move because 
it says let's take the patterns from this data collected from 
the past and use them to affect the future. And so if we want 
instead to take patterns to build the future we want, we need 
to be thoughtful about how we curate training datasets. And to 
various other points that you brought up there, we need to make 
sure that there's recourse for people who are harmed by adverse 
decisions.
    Ms. Lee. So from like--so from a policymaking standpoint, 
do you think it would be more important to define bias more 
broadly or must bias be defined within the context of AI 
machine learning application and use?
    Dr. Bender. That's a really good question. I think if we 
leave bias undefined, we're going to have problems. And you're 
absolutely right. There's things, for example, automation bias 
means we tend to trust machines because they seem objective, 
and we need to be able to work around that. But there's also 
bias in the form of like discrimination. And so I think any 
legislation around bias should be defining what bias means in 
that context.
    Ms. Lee. So what regulations do you think should be applied 
to these tools across the board versus regulations that are 
specific to their use case? And in that case of the latter, how 
will we be able to do that for each case?
    Dr. Bender. So I think how to do it for each case falls 
back to what existing regulations actually already apply. 
Things that should happen across the board I think have to do 
with transparency around datasets, transparency around the fact 
of automation, and transparency of who's accountable, which 
person is ultimately accountable for decisions or outputs.
    Ms. Lee. Thank you. Ms. Tabassi, my understanding based on 
conversations I had and my staff has had with researchers at 
CMU, Carnegie Mellon, is that for the most part AI decision 
tools are being designed and deployed without much forethought 
on the part of the entity deploying them as to what policies 
and principles will guide their use to ensure their fairness. 
What would you say Congress must do to separate the processes 
of setting principles that will guide AI and machine learning 
tools prior to design and deployment of such tools from the 
technical operation of such tools?
    Ms. Tabassi. In AI RMF we talk about a continuum, and that 
the risk management and accountability is a shared 
responsibility across all of them. And for any of these 
trustworthiness characteristics, including bias, it's important 
to start thinking about this as the earliest stage of the 
planning and design. And so talking about how we can advance 
research centers and evaluations to bring all of these concepts 
into the design and development of the systems and not having 
them as an afterthought to the--after the systems is deployed 
is a very important topic.
    Ms. Lee. Thank you. And thank you all so much for your time 
and your expertise. I yield back.
    Chairman Obernolte. The gentlewoman yields back.
    We will hear perhaps last but certainly not least from my 
colleague from New York. Mr. Bowman, you're recognized for five 
minutes.
    Mr. Bowman. Thank you so much, Mr. Chairman.
    Ms. Tabassi, the need for better evaluation frameworks has 
been surfaced consistently today. Will NIST partner with other 
agencies and private sector organizations to provide sample 
data and create evaluations around specific high risk use cases 
like hiring?
    Ms. Tabassi. So working across the community and with 
everybody and our colleagues across the government agencies and 
our colleagues across all of the AI community, academia, 
private sector, and civil society-centered development 
organizations is something that we do at NIST and that's how we 
work. So we are certainly not--more than open, eager, and 
enthusiastic to work with everybody on understanding how to 
evaluate AI systems in a way that not only look at the 
functionality, limits, and capabilities, but also their 
trustworthiness and their societal robustness. We look forward 
to work with that, and we're already talking about having 
conversations with the community on how to set up those 
evaluations and advance those techniques.
    Mr. Bowman. Thank you so much.
    Mr. Kratsios, just the other day I saw that the U.S. 
Government outlined more than 700 potential use cases for 
artificial intelligence across agencies. Our procurement system 
is a key lever. The executive branch has to incentivize 
responsible AI. As a former White House CTL, what is--CTO, 
excuse me--what is your perspective on ensuring that agencies 
contract with the most responsible, effective AI providers?
    Mr. Kratsios. You bring up a very good point around 
procurement being a very powerful lever and incentivizing 
better behavior from these potential model developers or 
algorithm developers more broadly, and I think developing 
procurement methodologies and guidelines which align with a 
risk-based approach is the best way to do it. And what--and the 
only way you can do that is if you can actually have done the 
hard technological and scientific discovery of what is a risk-
based approach to monitor these particular use cases. So not to 
put more work on my friend over here, but once we can sort out 
some of those testing and evaluation techniques, I think it's 
a--it's very critical that we infuse them into our procurement 
methodologies.
    Mr. Bowman. Yes, and thank you for leading the way for me, 
but I wanted Ms. Tabassi to comment if she wouldn't mind.
    Ms. Tabassi. I want to say that some of the guidelines in 
the AI RMF can already be applicable and can--we can start 
building on top of those. And of course, advancing the 
evaluations is something near and dear to our hearts, and we're 
working with the community.
    NIST has a long history of evaluations, and we already have 
a lot of different evaluations in the biometric, information 
retrieval, all of those things can be leveraged for evaluations 
of AI systems, and we're thinking of how to extending them, but 
also building this addition of being able to evaluate AI 
systems in their context of use with real interactions with the 
humans that operate them, use them, being impacted by them to 
be able to assess the risk and impact of the AI systems. We're 
excited about that work, and we look forward to work with the 
whole community on that.
    Mr. Bowman. Thank you so much. I have a question for Dr. 
Bender. The development of large language models is still a 
fundamentally human process that's driven by developers, 
researchers, and contractors who make decisions at every stage 
of development. The university system plays a pivotal role in 
ensuring that we train a generation of thoughtful builders who 
take ethical and social ramifications into account in all of 
their research. How can the Federal Government collaborate 
better with the university research community to move in the 
right direction here?
    Dr. Bender. Thank you for that question, and thank you for 
recognizing the contractors who do a lot of the labor, often 
poorly compensated in developing these. I think that there's a 
role for the Federal Government to play in supporting research 
in the social sciences and humanities because that's what we're 
going to understand how these things are actually affecting 
society. And, you know, also, integrating ethics throughout the 
curriculum is something that I'm working on. I know many other 
people are as well, but figuring out a way to value that, I 
think Federal Government valuing it, it will help people value 
it if they're coming in through, say, computer science.
    Mr. Bowman. Got it. I have no questions for Mr. Watney, but 
you can feel free to comment on anything. I've enjoyed your 
comments so far, so please add on wherever you see fit.
    Mr. Watney. Thanks. Yes, I think maybe if this is starting 
to be--to wrap up, I'll give a more----
    Mr. Bowman. Yes.
    Mr. Watney [continuing]. Broader comment. But I think I'm 
encouraged by just how much agreement there seems to be kind of 
across the political spectrum on the importance of investing in 
new standards and privacy preserving techniques in 
cybersecurity and interpretability. Like I think there's a real 
foundation here for America to play a proactive role in shaping 
the broader research ecosystem. And we should also recognize 
this is not a new thing. The United States has always 
recognized it has a really pivotal role in not only the rate of 
technological progress, but the direction. We've done this in--
you know, through DARPA (Defense Advanced Research Projects 
Agency) for satellite technology and the internet. We've done 
this through the NIH (National Institutes of Health) for, you 
know, biomedical technology. We've done this through climate 
tech. So I think this is part of a longer American tradition of 
really being proactive about shaping technology. And there's 
just, I think, a lot of work to do.
    Mr. Bowman. Thank you so much. I yield back.
    Chairman Obernolte. The gentleman yields back.
    That concludes our Member questions. This has been a really 
interesting hearing. I want to thank all the witnesses for your 
valuable testimony and thank the Members for their great 
questions. The record will remain open for 10 days for 
additional comments and written questions from Members.
    With that, our hearing is adjourned.
    [Whereupon, at 4:25 p.m., the Subcommittees were 
adjourned.]

                               Appendix I

                              ----------                              


                   Answers to Post-Hearing Questions

[GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]


                              Appendix II

                              ----------                              


                   Additional Material for the Record

[GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]



                                 [all]