[House Hearing, 119 Congress]
[From the U.S. Government Publishing Office]
FROM PRINCIPLES TO POLICY: ENABLING 21ST
CENTURY AI INNOVATION IN FINANCIAL SERVICES
=======================================================================
HEARING
before the
COMMITTEE ON FINANCIAL SERVICES
U.S. HOUSE OF REPRESENTATIVES
ONE HUNDRED NINETEENTH CONGRESS
FIRST SESSION
__________
DECEMBER 10, 2025
__________
Serial No. 119-48
Printed for the use of the Committee on Financial Services
[GRAPHIC NOT AVAILABLE IN TIFF FORMAT]
www.govinfo.gov
______
U.S. GOVERNMENT PUBLISHING OFFICE
63-576 PDF WASHINGTON : 2026
HOUSE COMMITTEE ON FINANCIAL SERVICES
FRENCH HILL, Arkansas, Chairman
BILL HUIZENGA, Michigan, Vice MAXINE WATERS, California, Ranking
Chairman Member
FRANK D. LUCAS, Oklahoma SYLVIA R. GARCIA, Texas, Vice
PETE SESSIONS, Texas Ranking Member
ANN WAGNER, Missouri NYDIA M. VELAZQUEZ, New York
ANDY BARR, Kentucky BRAD SHERMAN, California
ROGER WILLIAMS, Texas GREGORY W. MEEKS, New York
TOM EMMER, Minnesota DAVID SCOTT, Georgia
BARRY LOUDERMILK, Georgia STEPHEN F. LYNCH, Massachusetts
WARREN DAVIDSON, Ohio AL GREEN, Texas
JOHN W. ROSE, Tennessee EMANUEL CLEAVER, Missouri
BRYAN STEIL, Wisconsin JAMES A. HIMES, Connecticut
WILLIAM R. TIMMONS, IV, South BILL FOSTER, Illinois
Carolina JOYCE BEATTY, Ohio
MARLIN STUTZMAN, Indiana JUAN VARGAS, California
RALPH NORMAN, South Carolina JOSH GOTTHEIMER, New Jersey
DANIEL MEUSER, Pennsylvania VICENTE GONZALEZ, Texas
YOUNG KIM, California SEAN CASTEN, Illinois
BYRON DONALDS, Florida AYANNA PRESSLEY, Massachusetts
ANDREW R. GARBARINO, New York RASHIDA TLAIB, Michigan
SCOTT FITZGERALD, Wisconsin RITCHIE TORRES, New York
MIKE FLOOD, Nebraska NIKEMA WILLIAMS, Georgia
MICHAEL LAWLER, New York BRITTANY PETTERSEN, Colorado
MONICA DE LA CRUZ, Texas CLEO FIELDS, Louisiana
ANDREW OGLES, Tennessee JANELLE BYNUM, Oregon
ZACHARY NUNN, Iowa SAM LICCARDO, California
LISA McCLAIN, Michigan
MARIA SALAZAR, Florida
TROY DOWNING, Montana
MIKE HARIDOPOLOS, Florida
TIM MOORE, North Carolina
Ben Johnson, Staff Director
C O N T E N T S
----------
Wednesday, December 10, 2025
OPENING STATEMENTS
Page
Hon. French Hill, Chairman of the Committee on Financial
Services, a U.S. Representative from Arkansas.................. 1
Hon. Maxine Waters, Ranking Member of the Committee on Financial
Services, a U.S. Representative from California................ 2
STATEMENTS
Hon. Bryan Steil, Chairman of the Subcommittee on Digital Assets,
Financial Technology and Inclusion, a U.S. Representative from
Wisconsin...................................................... 3
Hon. Stephen Lynch, Ranking Member of the Subcommittee on Digital
Assets, Financial Technology and Inclusion, a U.S.
Representative from Massachusetts.............................. 4
WITNESSES
Ms. Jeanette Manfra, Vice President and Global Head of Risk &
Compliance, Google Cloud....................................... 5
Prepared Statement........................................... 7
Mr. Tal Cohen, President, Nasdaq................................. 14
Prepared Statement........................................... 16
Mr. Nicholas Stevens, Vice President of Product, Artificial
Intelligence, Zillow........................................... 23
Prepared Statement........................................... 25
Ms. Wendi Whitmore, Chief Security Intelligence Officer, Palo
Alto Networks.................................................. 31
Prepared Statement........................................... 33
Mr. Joshua Branch, Big Tech Accountability Advocate, Public
Citizen........................................................ 41
Prepared Statement........................................... 43
APPENDIX
MATERIALS SUBMITTED FOR THE RECORD
Stephen F. Lynch:
FinTech Regulatory Sandbox Guidelines FinTech Regulatory
Sandbox Guidelines......................................... 126
Hon. Gregory W. Meeks:
U.S. Halted Plans to Sanction Chinese Spy Agency to Maintain
Trade Truce, FT Says....................................... 146
Hon. Maxine Waters:
Coalition Letter Opposing H.R. 4801.......................... 148
Consumer Reports Opposing H.R. 4801.......................... 151
RESPONSES TO QUESTIONS FOR THE RECORD
Written responses to questions for the record from Representative
Barry Loudermilk
Ms. Jeanette Manfra.......................................... 155
LEGISLATION
H.R. 4801, the Unleashing AI Innovation in Financial Services Act 157
H.R. 2152, the Artificial Intelligence Practices, Logistics,
Actions, and Necessities (PLAN) Act............................ 178
H.R. 1734, the Preventing Deep Fake Scams Act.................... 183
H. Res. ------, Expressing the sense of the House of
Representatives with respect to the use of artificial
intelligence in the financial services and housing industries.. 188
H.R. ------, the Artificial Intelligence Innovation Sandbox
Information Generation and Harmonization of Testing Act (AI
INSIGHT) Act................................................... 192
H.R. ------, the Fostering the Use of Technology to Uphold
Regulatory Effectiveness in Supervision (FUTURES) Act.......... 198
FROM PRINCIPLES TO POLICY: ENABLING 21ST
CENTURY AI INNOVATION IN FINANCIAL SERVICES
----------
Wednesday, December 10, 2025
U.S. House of Representatives,
Committee on Financial Services,
Washington, DC.
The committee met, pursuant to notice, at 10:12 a.m., in
room 2128, Rayburn House Office Building, Hon. J. French Hill
[chairman of the committee] presiding.
Present: Representatives Hill, Lucas, Sessions, Huizenga,
Wagner, Barr, Williams of Texas, Loudermilk, Davidson, Rose,
Steil, Timmons, Stutzman, Meuser, Kim, Garbarino, Fitzgerald,
Flood, De La Cruz, Ogles, Nunn, McClain, Salazar, Downing,
Haridopolos, Moore, Waters, Sherman, Meeks, Scott, Lynch,
Green, Cleaver, Himes, Foster, Beatty, Vargas, Gottheimer,
Gonzalez, Casten, Pressley, Tlaib, Torres, Garcia, Williams of
Georgia, Pettersen, Fields, Bynum, and Liccardo.
Chairman Hill. The Committee on Financial Services will
come to order. Without objection, the chair is authorized to
declare a recess at any time.
Today's hearing is entitled From Principles to Policy:
Enabling 21st Century AI Innovation in Financial Services.
Without objection, all members will have 5 legislative days
within which to submit extraneous materials to the chair for
inclusion in the record.
I now recognize myself for 4 minutes for an opening
statement.
OPENING STATEMENT OF HON. FRENCH HILL, CHAIRMAN OF THE
COMMITTEE ON FINANCIAL SERVICES, A U.S. REPRESENTATIVE FROM
ARKANSAS
Advancements in artificial intelligence are not just on the
horizon; they are here, and they are transforming our economy.
Last Congress, Congressman Bill Foster and I served on Speaker
Johnson and Minority Leader Jeffries' bipartisan congressional
AI task force, and Congressman Steve Lynch and I led this
committee's AI working group. In both forums, we examined how
financial services firms and regulators are approaching
artificial intelligence, analyzing its benefits and risks in a
highly regulated environment.
Just this past fall, the Digital Assets, Financial
Technology, and Artificial Intelligence Subcommittee, led by
Chairman Bryan Steil, held a hearing where members evaluated
how financial regulators and firms are using AI.
Today's hearing builds on our earlier work in last Congress
and this Congress and will help us further examine AI use cases
in the financial and housing industries. We will also consider
how agencies are providing clear regulatory environment and
assess where existing laws may fall short or require
modernization and explore ways to foster innovation.
For decades, the financial services industry has pioneered
the real-world application of AI and continues to be a standout
leader. AI has shown its transformative potential to reshape
how financial institutions operate from enhancing analysis, to
managing risk, mitigating fraud, and, importantly, enhancing
customer service.
However, as with any innovation, risks give rise to new
challenges. Yet human progress is ever changing, never static,
and AI represents the latest leg in this journey. To move
forward, we must embrace and adapt for innovation.
This was the approach taken in the 1990s by former
Congressman and former Securities and Exchange Commission (SEC)
Chairman, Chris Cox, when Congress confronted the rapid
commercialization of the internet. Rather than allowing fear to
stall advancement, lawmakers adopted existing laws to fit the
new technological era.
Congress established clear guidelines and principles early
on, setting the stage for the rapid growth of the internet,
enabling countless innovations and entire industries, and
putting the United States at the forefront of that innovation
and the internet's expansion.
Just as Congress navigated the uncertainties of the
internet in the mid-1990s, we must use AI as an opportunity,
not a threat, applying lessons of that era in order to confront
today's technological landscape.
Identifying gaps and obstacles in our regulatory frameworks
will help Congress create an AI landscape where innovation can
flourish without unnecessary barriers while ensuring robust
consumer protections and risk-based technological--technology-
neutral regulations.
The committee is steadfast in its commitment to empowering
U.S. firms to leverage AI's potential and drive the U.S. global
leadership and adoption and innovation.
I thank all of our witnesses for joining us today and
providing your valuable insights and perspectives, and I yield
back.
It is now my pleasure to recognize the ranking member of
the committee, Ms. Waters, for 4 minutes for an opening
statement.
OPENING STATEMENT OF HON. MAXINE WATERS, RANKING MEMBER OF THE
COMMITTEE ON FINANCIAL SERVICES, A U.S. REPRESENTATIVE FROM
ARKANSAS
Ms. Waters. Thank you very much, Mr. Chairman.
AI is already embedding in the lives of millions of
Americans, and we have a duty to ensure that it benefits
society, not harms it. Unfortunately, Republicans have been
complicit as Donald Trump bypasses Congress, directs Federal
agencies to deploy biased AI with no safeguards, and now
issuing an executive order that seeks to undermine all State
oversight.
Republicans in Congress fail to acknowledge that despite
all the benefits that AI may bring, it also poses challenges
that demand our full attention. We are already seeing AI
systems that hurt children, spread hate and discrimination, and
amplify systemic risk in the financial system. As unemployment
reaches new heights, reports continue to show AI replacing
workers across industries. That is why the Biden Administration
put in critical protections to ensure AI systems are
transparent, explainable, and nondiscriminatory.
These are just basic safeguards to keep families and
children safe. In some of the worst cases, chat boxes have
encouraged self-harm, like suicide, carrying out sexually
explicit conversations, and even provided dangerous
misinformation and disinformation to minors but no one should
be surprised that the same President who calls affordability a
hoax is ignoring these very real concerns with AI. Since--twice
this year, the White House and congressional Republicans have
tried and failed to impose a moratorium on State AI laws, and
now, despite those failures, Trump announced he would sign an
executive order that would block States from adopting their own
AI safeguards by threatening legal challenges and withholding
Federal funding.
For this hearing, Republicans posed a bill--posted a bill
that would give AI and its Big Tech creators a pass when they
violate consumer, housing, banking, or securities laws.
Democrats are not going to sit by and watch Trump and
Republicans allow Big Tech to forcibly experiment on our
communities. Any legislative efforts by Congress must ensure
that consumers and investors understand the AI they are
interacting with in the financial services space, while giving
companies meaningful standards they can innovate under.
A partisan approach is not necessary if Republicans fight
for their constituencies. Last Congress, I and then-Chair
McHenry launched the first ever bipartisan AI task force. We
held joint sessions, conducted oversight, and introduced bills
to confront AI bias, deep fake scams, and discrimination,
proving that innovation and oversight can go hand in hand.
Democrats are leading these efforts because we believe in
responsible innovation.
The stakes are too high, the risks are too great, and the
consequences are too real to hand this technology over to Big
Tech billionaires with no guardrails, no accountability.
Thank you, and I yield back the balance of my time.
Chairman Hill. The gentlewoman yields back.
I now recognize the chair of the Subcommittee on Digital
Assets, Financial Technology, and Artificial Intelligence, Mr.
Steil of Wisconsin, for 1 minute for an opening statement.
STATMENT OF HON. BRYAN STEIL, CHAIRMAN OF THE SUBCOMMITTEE ON
DIGITAL ASSETS, FINANCIAL TECHNOLOGY AND INCLUSION, A U.S.
REPRESENTATIVE FROM WISCONSIN
Mr. Steil. Thank you very much, Mr. Chairman.
The U.S. must win the global AI race and the regulations
that we may make here are incredibly consequential. We cannot
get it wrong; some have. For example, the EU AI Act is a broad,
horizontal approach that stifles innovation in Europe. In the
U.S., I believe we should take a targeted, activity-specific
approach to AI. As we examine use cases and those who develop
and deploy AI today, we should examine if our rules need
adjustments and tweaks to get this right. These use cases will
only continue to evolve as generative and agentic AI
technologies evolve. We must make sure we unlock innovation
while protecting Americans. As the United States strives to win
the AI global race, maintaining a ``try first'' approach will
help preserve American dominance and agility. Let us win this
race. I yield back.
Chairman Hill. The gentleman yields back.
I recognize the ranking member of the Subcommittee on
Digital Assets, Financial Technology, and AI, Mr. Lynch, for 1
minute for an opening statement.
STATMENT OF HON. STEPHEN LYNCH, RANKING MEMBER OF THE
SUBCOMMITTEE ON DIGITAL ASSETS, FINANCIAL TECHNOLOGY AND
INCLUSION, A U.S. REPRESENTATIVE FROM MASSACHUSETTS
Mr. Lynch. Good morning. Thank you, Mr. Chairman and
Ranking Member Waters, for holding this hearing to continue
examining AI innovation and regulation in the financial
services sector. I also want to thank our panel of witnesses
for helping the committee with its work.
Last Congress, I was proud to co-lead our bipartisan AI
working group with my friend, Chairman Hill, to examine the
benefits and risks of deploying AI technologies in banking,
housing, credit lending, and other areas. These findings should
continue to guide us as we pursue effective and responsible AI
regulation. However, as ranking member of the Subcommittee on
Digital Assets, Financial Technology, and Artificial
Intelligence in this Congress, I am concerned that some of the
regulations--regulatory proposals before this committee not
only fail to include adequate guardrails but they also invite
the financial services industry in adopting AI to choose which
consumer protection and investor protection and safety and
soundness regulations that they would like to avoid, which is
reckless and dangerous.
In closing, I look forward to working with my colleagues to
develop bipartisan AI legislation that promotes innovation
while ensuring robust consumer and financial protection. I
yield back the balance of my time.
Chairman Hill. The gentleman yields back.
Today we welcome the testimony of Jeanette Manfra, vice
president, global head of risk and compliance at Google Cloud;
Tal Cohen, president of Nasdaq; Nicholas Stevens, the vice
president of product and senior developer of AI and engineering
at Zillow; Wendi Whitmore, chief security intelligence officer
at Palo Alto Networks; and Joshua Branch, Big Tech
accountability advocate at Public Citizen.
We thank each of you for taking time to be with us. Each of
you will be recognized for 5 minutes to give an oral
presentation of your testimony. Without objection, your written
statements will be made part of our record.
Chairman Hill. Mrs. Manfra, we will start with you. You are
recognized for 5 minutes for your oral remarks.
STATEMENT OF JEANETTE MANFRA, VICE PRESIDENT AND GLOBAL HEAD OF
RISK & COMPLIANCE, GOOGLE CLOUD
Ms. Manfra. Chairman Hill, Ranking Member Waters, and
distinguished members of the committee, thank you for the
opportunity to appear before you today. My name is Jeanette
Manfra, and I am the vice president of risk and compliance at
Google Cloud. We appreciate the House Committee on Financial
Services holding this important hearing, and we look forward to
sharing Google's perspective on the opportunity that artificial
intelligence provides to America's financial sector.
Google believes that the introduction of AI in the
financial services sector promises to usher in a transformative
era for quality, accessibility, efficiency, and compliance in
financial markets and services. AI offers many benefits,
including the potential to enhance individual productivity,
strengthen security operations, and drive database
decisionmaking and operational efficiencies. These improvements
will benefit institutions of all sizes, including small-and
medium-sized financial entities.
At the same time, we also recognize that AI introduces
risks that must be managed and mitigated. We believe that
existing risk management frameworks and established governance
practices can be applied to manage risks in the AI context.
For more than a decade, Google has used advancements in AI
to further protect people from online scams, where malicious
actors deceive users to gain access to money, personal
information, or both. We offer a wide variety of protections
powered by AI, including using Google Cloud's anti-money
laundering AI service for financial sector customer risk
scoring, utilizing AI-powered scam detection systems in search,
an Android ecosystem that automatically identifies and blocks
phishing messages and scam calls, and our efforts to ensure the
integrity of Google ads on our platforms.
Additionally, Google further disincentivizes this malicious
behavior by proactively filing litigation to dismantle massive
fraud operations. In a recent example, in November 2025, we
announced our filing to dismantle Lighthouse, a massive
phishing-as-a-service operation. Bad actors built Lighthouse as
a phishing-as-a-service kit to generate and deploy massive
short message service (SMS) phishing attacks. These attacks
exploit established brands, like E-ZPass, to steal people's
financial information. Our legal action is designed to
dismantle the core infrastructure of this operation.
We recognize that Google must work with industry
participants, regulatory bodies, and technology providers to
counter the critical threats posed by scams and frauds, and we
are leading cross-industry efforts in combating fraud and scams
in response.
We have introduced the Agent Payments Protocol, or AP2, an
open-source protocol collaboratively developed with over 60
partners, including financial and technology companies, like
American Express, Mastercard, and PayPal. AP2 aims to
standardize and secure transactions made by AI agents on behalf
of users, addressing key challenges such as authorization,
authenticity, and accountability. This is an important step,
and I look forward to discussing this with the committee.
We at Google have also introduced the Secure AI Framework,
or SAIF, a conceptual framework for secure AI systems,
including those in the financial sector, and we have recently
published an extension of the SAIF Risk Map to address the core
operational components of agentic systems and their related
risks and controls. In addition, we partnered with Amazon,
Microsoft, IBM, Nvidia, and many others to co-find the
Coalition for Secure AI, which is an open-source initiative to
help all developers and deployers of AI create and maintain
secure by designing AI systems and help advance the SAIF
framework.
We recognize that we alone cannot solve these challenges.
We have recently announced our endorsement of key bipartisan
bills in Congress, crucial bills that we believe will help
bring a decisive end to the financial harm and damage wrought
by foreign cyber criminals. As the world focuses on the
potential of AI, and governments and industry work on a
regulatory approach to ensure AI is safe and secure, we believe
that AI represents an inflection point for digital security.
Regulators should support the development of global standards
and their use across the financial services and regulatory
landscape. In addition, regulators should foster industry
collaboration and training based on such standards.
In closing, thank you for convening this really important
hearing. We look forward to continuing to further raise
awareness about cybersecurity, threats, and defenses for the
financial sector and beyond.
[The prepared statement of Ms. Manfra follows:]
[GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]
Chairman Hill. Thank you very much.
Mr. Cohen, you are now recognized for 5 minutes for your
testimony.
STATEMENT OF TAL COHEN, PRESIDENT, NASDAQ
Mr. Cohen. Thank you.
Chairman Hill, Ranking Member Waters, and members of the
committee, thank you for the opportunity to testify on the
impact of artificial intelligence on our financial system and
the role of responsible innovation. My name is Tal Cohen, and I
serve as president of Nasdaq. At Nasdaq, we aspire to be the
trusted fabric of the global financial markets, connecting
entrepreneurs and investors, fueling economic growth, fighting
financial crime, and supporting millions of everyday savers and
retirees. As a global technology provider and an operator of
regulated markets, we have a unique perspective that shapes how
we employ AI.
Our approach centers on three core principles: enhancing
liquidity, ensuring transparency, and protecting integrity. AI
is already making a measurable difference across all three of
these within our solutions and I am going to start with
financial crime, where the human cost is greatest.
In 2023, an estimated $3.1 trillion in illicit funds flowed
through the global financial system, and scam and bank frauds
cost roughly 485 billion in losses worldwide. Behind these
numbers are family losing savings, communities harmed by drug
trafficking, human trafficking, and terrorism financing.
Nasdaq's cloud native AI enabled anti-financial crime
platform, Verafin, is used by thousands of financial
institutions to detect and prevent these crimes. Verafin
analyzes vast data sets across its network to identify
suspicious activity in ways no single institution could do
otherwise.
This work went a step further with the launch of our
agentic AI workforce. Our digital sanctions analyst has reduced
the alert review workload for sanction screening by more than
80 percent, freeing compliance professionals to focus on
complex, judgment-heavy issues while AI handles routine tasks.
AI also strengthens market integrity. Our surveillance
platform uses machine learning to help exchanges and regulators
detect insider trading across billions of daily transactions,
rooting out market abuse that erodes investor confidence.
These achievements are only possible if you have the right
governance and the right oversight in place. From the outset,
Nasdaq established an enterprise-wide AI governance program
aligned with the National Institute of Standards and Technology
(NIST) AI risk management framework, overseen by an executive
steering committee that includes our CEO. We also implemented a
cross-functional governance committee led by legal, risk,
regulatory, and technology teams.
Additionally, we adopted responsible AI principles covering
transparency, fairness, privacy, reliability, and
accountability, and we applied it across all products and
internal operations.
And that brings me to the AI policy consideration before
this committee. The U.S. has historic opportunity to lead in
AI--if we strike the right balance. From our perspective, the
following principles are critical.
First, leverage existing regulatory frameworks. The
financial sector is already heavily supervised. Many AI-related
risks can be addressed with existing rules and mandates.
Second, focus on use cases and outcomes. Regulation should
reflect risk profiles. An AI tool detecting drug trafficking or
protecting seniors from fraud should be subject to higher
standards than when that same tool is used to approve apartment
rentals. They carry different risk profiles and require
different regulatory treatment.
Third, Keep frameworks flexible and innovation friendly.
Overly prescriptive rules tend to age poorly and risk pushing
innovation overseas. We support sandboxes, pilots, and AI
centers of excellence where regulators and industry can learn
and work together.
Fourth, strive for harmonization. A patchwork of State-
level AI laws creates uncertainty, raises costs, and can limit
access to these tools. Federal coordination is the best way to
protect investors while preserving U.S. competitiveness.
Applying these principles will ensure that AI is working to
make our financial systems more fair, more efficient, and more
resilient and that is the future we are working toward at
Nasdaq and why we are grateful for the committee's leadership
on these issues.
In closing, we support the administration's America's AI
Action Plan and bipartisan effort in Congress to address harms
such as nonconsensual deep fakes and synthetic media while
preserving space for innovation. Thank you again for the
opportunity to testify today, and I look forward to your
questions.
[The prepared statement of Mr. Cohen follows:]
[GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]
Chairman Hill. Thank you, sir.
Mr. Stevens, you are recognized for 5 minutes for your oral
presentation.
STATEMENT OF NICHOLAS STEVENS, VICE PRESIDENT OF PRODUCT,
ARTIFICIAL INTELLIGENCE, ZILLOW
Mr. Stevens. Chairman Hill, Ranking Member Waters, and
members of the committee, thank you for the opportunity to
testify today. My name is Nicholas Stevens, and I serve as vice
president of product, artificial intelligence of Zillow. Our
mission is to help people navigate one of the most meaningful
and complex decisions of their lives: finding a home.
After 9 years at Zillow, improving the housing journey, I
recently had the chance to live it again. My family just moved.
At the end of the process, my 5-and 7-year-olds could not
sleep. They were up at 3 a.m. and when my wife and I sat them
down to ask what on earth was troubling them, they had two very
nervous questions. A: ``Are we bringing our cat, Lily, to the
new home?'' B: ``Are we also bringing the TV?'' I am happy to
report that both have made it safe to our new home but
everything in between--the search, the paperwork, the
financing, the closing--was a reminder of how emotional and
confusing this process can be. That is the friction we are
trying to address with responsible AI.
Zillow has been applying AI to housing for nearly two
decades, starting with the Zestimate, one of the first large-
scale consumer uses of machine learning in real estate. It is
not an appraisal or used for credit decisions. Rather, it
empowers buyers and sellers with a ballpark estimate of home
value. The Zestimate was so popular, it crashed our site
because consumers were asking for information that has
historically been available only to a select few. Today, 250
million unique users come to Zillow every month to dream, to
rent, to tour, finance, buy, and sell their homes and with that
scale comes real responsibility. Our products cannot just be
clever. They have to be reliable, fair, and trust-affirming.
Since Zillow last appeared before this committee, Next
Generation AI has moved from pilot to production. AI in real
estate is not theoretical. It powers tools people are using
today, and I will highlight a few examples.
We have built an AI to be a true assistant to real estate
agents nationwide. It helps prioritize an agent's leads. It
summarizes notes. It drafts emails and one of the agents'
favorite features is that it suggests key topics to touch on in
their clients' catch-up call.
Technology also allowed our company to go fully remote, and
we now have employees in all 50 States.
Our latest computer vision experiences allow you to not
only generate a home's floor plan so potential buyers can
explore the inside in detail; we also let them fly around and
get a sense of the exterior and yard.
The through line is that safeguards are built in, not
bolted on. Internally, Zillow employees complete fair housing
and privacy training, and anyone working with AI receives
additional responsible AI training. Before we launch an AI
feature, cross-functional teams conduct a model risk review
focused on fairness, bias, privacy, and explainability. After
launch, we perform periodic audits and continuous monitoring so
we can catch issues that only appear at scale.
Externally, this is even true with public partnerships. Now
consumers can talk to Zillow directly inside ChatGPT's new in
app experience, asking, for example, ``Zillow, show me 2-
bedroom homes that are wheelchair accessible,'' and in return,
they get listings, photos, and maps from Zillow in a
conversational flow.
We built this with a fair housing first design. Our Fair
Housing Classifier helps detect and prevent potential digital
steering. We also believe responsible innovation means raising
the floor for everyone. Zillow open-sourced that same Fair
Housing Classifier under a permissive license, and it is now in
use by real estate platforms and researchers working to combat
housing discrimination. That is a concrete example of
innovation and compliance rowing in the same direction.
All of this argues for a right-sized national framework for
AI in financial services, including housing. A coherent
national baseline for fairness, transparency, privacy, and
accountability would give consumers consistent safeguards and
give companies the confidence to integrate strong protections
from day 1. The alternative is a patchwork where the same
consumer gets different quality experiences across State lines
for the same transaction.
Even the latest AI technology would not have prompted me to
explain to my kids that, yes, both our cat and the TV would be
coming to our next home, but it can help tackle the structural
challenges we all worry about: affordability, supply, and
outdated processes.
As you consider a national framework for AI and
modernization of our housing finance system, we stand ready to
share data, technical expertise, and lessons from building
these systems at scale. We appreciate the committee's
leadership on this issue, and I look forward to answering your
questions.
[The prepared statement of Mr. Stevens follows:]
[GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]
Chairman Hill. Thank you very much.
Ms. Whitmore, you are now recognized for 5 minutes for your
oral testimony.
STATEMENT OF WENDI WHITMORE, CHIEF SECURITY INTELLIGENCE
OFFICER, PALO ALTO NETWORKS
Ms. Whitmore. Good morning.
Chairman Hill, Ranking Member Waters, and distinguished
members of the committee, thank you for the opportunity to
testify. My name is Wendi Whitmore, and I am the chief security
intelligence officer at Palo Alto Networks. We are an American
cybersecurity company protecting more than 75,000 organizations
in over 150 countries, including 97 of the Fortune 100, eight
of the 10 largest banks, the U.S. Federal Government, and
critical infrastructure operators.
The promise of AI for financial services is undeniable and
realizing it requires the sector to simultaneously embrace AI
for cybersecurity, and cybersecurity for AI. There is both
urgency and opportunity for financial institutions to lead. The
threat landscape is evolving as advanced AI and quantum
computing reshape both innovation and risk.
Attacks are faster, more automated, and harder to detect.
Time from compromise to data exfiltration is now 100 times
faster than 4 years ago, and attackers are increasingly
exfiltrating data within 1 hour.
Generative and agentic AI now super-charge every phase of
the kill chain, enabling deep fake-driven fraud, know your
customer evasion via face swapping, and tailored spear
phishing, imitating trusted financial institutions. Our own
research shows that agentic AI can compress a multi-day
ransomware operation into only 25 minutes, from reconnaissance
to compromise to data theft.
This reality underscores why the financial sector must do
two things: one, adopt AI-driven security operations that
operate at machine speed; and two, harden their AI ecosystems
with a secure-by-design approach.
Today's security operation centers, known as SOCs, are
drowning in fragmented data, and alerts from an average of 83
security solutions, forcing skilled analysts into inefficient,
manual triage. Consequently, critical alerts are buried, with
75 percent of breaches having actionable logging that was never
reviewed, leaving vulnerabilities exposed and degrading our
core ability to rapidly detect and respond to threats.
AI-driven SOCs flip this paradigm, acting as a force
multiplier for cyber professionals that substantially reduces
detection and response times. The results of deploying AI in
our own SOC are transformative. We ingest roughly 90 billion
events every day. By leveraging AI, we reduce those to only
26,000 alerts, ultimately resulting in one single incident
requiring manual investigation.
In financial institutions deploying AI-driven SOCs, we see
four times more security data ingested into a consolidated
platform, thousands of models providing real-time prevention
and detection, automation cutting analysts' workload by three-
quarters, and the mean time to respond falling by up to 90
percent. In one global financial markets utility, their mean
time to respond fell from 24 hours to 14 minutes. Another large
bank saved more than 1,000 analyst hours annually while
improving threat hunting and reducing attrition.
AI adoption is integral to America's innovation leadership,
which is why Palo Alto Networks was proud to support America's
AI Action Plan, which recognize that the benefits of AI will
stall if we do not secure AI itself.
Attacks against AI systems have fundamentally evolved
beyond traditional cybersecurity considerations. They target
how systems learn and how they reason. The answer to accelerate
AI innovation is to embed security throughout the AI life cycle
so that we can adopt AI tools confidently.
Secure AI by design provides the blueprint to integrate
security from development through deployment and use, ensuring
visibility, control, and protection at enterprise scale.
Practically, that means discovering and governing external AI
tools, including Shadow AI, securing AI infrastructure and
data, monitoring and controlling AI agents, and safely building
and deploying AI applications.
Building an AI-ready ecosystem is a team effort. As a
Financial Services Industry (FSI) sector advisor and a
participant in the Cyber Risk Institute innovator program, Palo
Alto Networks helps align best practices with leading standards
and reduce compliance friction for financial institutions. If
we secure the future now through AI-driven defense and secure
AI by design, we can unleash the full potential of AI
innovation while protecting consumers, markets, and national
security.
Thank you for the opportunity to testify. I look forward to
your questions.
[The prepared statement of Wendi Whitmore follows:]
[GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]
Chairman Hill. Thank you very much.
Mr. Branch, you are now recognized for 5 minutes for an
oral presentation of your testimony.
STATEMENT OF JOSHUA BRANCH, BIG TECH ACCOUNTABILITY ADVOCATE,
PUBLIC CITIZEN
Mr. Branch. Thank you, Chairman Hill, Ranking Member
Waters, and members of the committee. My name is J.B. Branch. I
am an artificial intelligence policy expert at Public Citizen,
a nonprofit with more than 1 million members and supporters
across the country.
Each day, we fight for everyday Americans by defending
democracy, resisting corruption, and challenging corporate
greed. I am here today to talk about the difference between
responsible AI innovation, and the current reckless push by Big
Tech to undermine State laws, weaken consumer protection, and
place all of us at the mercy of a handful of AI billionaires.
For decades, the default posture toward regulating new
technology has been deference to industry. Congress deferred to
the expertise of social media companies. We now live with the
consequences, including rampant misinformation and harms for
children. We cannot make the same mistake with AI.
The scale, speed, and autonomy of AI creates risks far
beyond previous technology. The good news is that most AI
regulations are rooted in common sense. Algorithms should not
discriminate. Companies should be held accountable for harm.
Nonconsensual deep fake pornography is a devastating crime.
These are American values and Americans agree. A Gallup poll
shows 97 percent of Americans agree that AI should be subject
to regulation--97 percent. States across the country have
responded with bipartisan, commonsense safeguards that reflect
this democratic will in action.
Yet, instead of respecting that will, we have seen
relentless attempts to override it. Over summer, some in
Congress attempted to strip all State AI laws. Even worse, they
tried to slip the proposals into the must-pass National Defense
Authorization Act. Big Tech tried to use our national security
as leverage to avoid accountability.
What was once called a moratorium is now being repackaged
as a sandbox. These are all the same: deregulation schemes
designed to invalidate all existing safeguards and the
hypocrisy is striking. Big Tech is attacking many of the State-
based AI laws they helped to write. They praised those laws
locally while lobbying to destroy them nationally.
I am equally alarmed by President Trump referring to basic
protections as dangerous ideology. Several of the
administration's policy priorities target civil rights
principles in AI but fairness in AI simply means preventing
discrimination, sexism, and antisemitism.
While the Trump Administration bashes equality as a
dangerous ideology, it has simultaneously entered a Federal
contract with Elon Musk's Grok, an AI system that Office of
Science and Technology Policy (OSTP) Director Kratsios
testified, violated the administration's own principles. Grok's
behavior is well documented: racist slurs, sexism, and even
referring to itself as Mecca Hitler. Is this the type of AI we
want deployed throughout the U.S. Federal Government?
I also want to speak about the impact AI will have on
workers and rural communities like the one I was raised in
central Pennsylvania. These communities know what broken
promises feel like. We remember when steel mills closed and new
jobs did not come. Now, Big Tech companies are telling us that
data centers and AI will be salvation, and we have heard this
before. So let me be clear: Data centers are at the bottom of
the tech stack. They receive major tax breaks while local
communities foot the bill and most employ fewer people than a
single Wal-Mart. They do not replace the jobs that communities
have lost. This is another extraction model.
I want to offer simple guiding principles. Responsible
innovation requires enforceable accountability. Public Citizen
respectfully submits that the better path forward is not a
mystery. Reject blanket preemption and deregulatory sandboxes,
allowing States to respond to evolving harm. Require
transparency. Companies must be able to explain how their AI
systems work and how decisions are made. When AI systems cause
harm, companies must be held accountable. Invest in regulatory
enforcement. Laws mean nothing if they cannot be enforced.
Congress must ensure regulators have the staff, the authority,
and the resources to do their job.
We all share the same goal: a strong middle class and
leadership in responsible AI. Leadership means protecting
workers, children, and democracy at the same time we foster
innovation.
This is a defining moment. It is a test of who governs
America, the people or the most powerful corporations on earth.
Public Citizen urges Congress to stand up to Big Tech, reject
backdoor deregulation, and deliver real, enforceable
guardrails. Thank you, and I look forward to answering your
questions.
[The prepared statement of Mr. Branch follows:]
[GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]
Chairman Hill. I thank our panel very much.
I now recognize our members for questioning, and I
recognize myself for 5 minutes.
The Trump Administration's AI Action Plan prioritized the
acceleration of AI adoption in government and outlined several
policy actions that agencies can take to further U.S.
government's use of AI to, as it says in his plan, ``deliver
the highly responsive government American people expect and
deserve.'' I am pleased to see this mentality at the highest
levels of government.
Ms. Manfra, how does the AI Action Plan align with industry
best practices and the recent advancements in AI, and what can
the government learn from market participants to close the AI
adoption gap, and promote responsible use by our government
agencies? Emphasis on ``responsible.''
Ms. Manfra. Thank you for the question, sir.
The administration's approach to ensuring that AI and other
technologies are used to better deliver services to the
American people is very welcome and combined with that, the
approach to ensuring that responsible use with safeguards, and
the experience that agencies are having in implementing their
own AI governance has also been welcome. So being thoughtful
about how these AI tools are being used in different risk
scenarios is something that we see every day with our customers
and partners in the government and we welcome that.
We also appreciate the approach of experimentation, and
being able to create spaces where an agency or an organization
can explore a use case for AI and work out responsibly what
those issues might be before----
Chairman Hill. I think that is a--I think that is an
important point because over the years, we have had bipartisan
support for regulatory sandboxes for a variety of things, block
chain and other aspects of it. That is something that
technology providers and banks have tried to work out. It is
important in financial technology (fintech) partnerships. It is
not deregulatory per se if one has a sandbox, and in an offline
capacity tries to perfect the use, in this case, of AI and then
the responsible compliance procedures for it. Is that not a
fair way to describe it?
Ms. Manfra. Yes, sir.
Chairman Hill. You do not consider that, per se,
deregulation, do you?
Ms. Manfra. I do not, sir. I think it allows organizations
to have a safe space where they can experiment and work out any
potential issues before they would then----
Chairman Hill. Yes----
Ms. Manfra [continuing]. employ it.
Chairman Hill. I kind of share that--I share that view as a
general statement, subject to the details, obviously.
While machine learning is not new, Generative AI and
agentic AI have recently been paradigm shifts for this
technology, particularly in the private sector. Such tools may
hold enormous potential for our financial institutions and our
financial regulators to change how they work.
Mr. Cohen, let me turn to you. At Nasdaq, you moved trading
markets to the cloud. You were one of the first exchanges to
release an AI-powered order type. Can you describe the
efficiency gains that you achieved through this transition and
what lessons you think that taught Nasdaq as you look at other
AI adaptations?
Mr. Cohen. Thank you for the question.
In terms of the order type you are referring to, it was--it
is called Dynamic Midpoint Extended Life Order (M-ELO). It is
the first SEC AI-enabled order type, and the SEC had to get
comfortable with exactly how we designed it, the explainability
of it, how we are testing it, and then how we are deploying it
into the market.
We designed it for large institutions--the Fidelity's, the
Wellingtons of the world--so that they can execute inner
markets with confidence and get the execution quality they need
as they are serving, we tell investors, everyday investors sit
behind the money that they put to work every day at our
markets.
So we wanted to democratize good execution quality, and we
did it through this order type, through, initially, a static
delay mechanism that allowed them to void fast money in the
market, which meant that at the end of the day, they could look
at their executions and the price movement after they executed
and see that there was quality in those executions.
What we did with AI is we incorporated 140 data points
every 30 seconds to determine what that delay should be to
optimize the execution quality that those large institutions
get.
Chairman Hill. Appreciate that. My time is short, so Ms.
Whitmore, if I could ask you to respond in writing--of course,
good people and bad people can use AI, so countering threats, I
think, is very important, and I think cyber risks are a big
challenge for the private sector and the government sector. Can
you follow up in writing with me and talk about how we should
counter those cyber risks to counter bad actors in this space
using AI? Thank you.
Ms. Whitmore. Yes, sir.
Chairman Hill. Thank you very much. If you do that in
writing, please.
I recognize the gentleman from Georgia, the distinguished
Mr. Scott, for 5 minutes.
Mr. Scott. Thank you very much, Chairman.
You know, concerning this AI business, I am very fearful
that we are rapidly becoming servants of the machine that we
created to serve us. I want that thought to register with you
and that is why I am working on a bill to expand wage insurance
protections, guaranteeing temporary wage replacement for
workers who are forced into lower paying jobs by AI. This is
dramatically important.
Mr. Branch, let me ask you. You said something very
important in your statement. You said in your statement, and I
quote, Workforce policy built on aspiration and retraining
slogans is not a real A-1 workforce policy.
So let me ask you a couple of questions. Have you talked
with our labor unions about this? What are they saying, if you
have or have not?
Mr. Branch. Thank you for the question, Representative.
Yes, we have spoken with union representatives, and they
are concerned about the potential for replacement and lost
jobs. The problem with some of these reskilling programs is
that oftentimes the jobs are not available in the communities
where the jobs are lost. So you lose a job in rural America,
but the job is actually based in Silicon Valley that you are
being retrained for. A lot of times, the reskilling jobs do not
even come at the rate of the jobs that end up being lost. So
you end up having a variety of folks who lose jobs but then
cannot be employed afterwards.
Mr. Scott. Spell out for us, how can unregulated A-1 jobs
lead to widespread job displacement?
Mr. Branch. Well, thank you again. Currently, a variety of
tech companies are really moving forward with trying to replace
a variety of their employers--employees. We are seeing this in
the tech force right now where you have whole slews of coders
who are losing their jobs. So that is why it is important for
Congress to address this issue head-on to work with unions to
ensure that when these jobs are lost, that there are actually
going to be jobs available for these folks.
Mr. Scott. That is why I keep saying we are rapidly
becoming servants of this machine we created to serve us and I
hope, Chairman Hill, that this very timely hearing will wake
our Nation up to realize. I am working on a bill, as I
mentioned, to expand wage insurance protection, guaranteeing
that our workers are taken care of here.
Let me ask you one more question, Mr. Branch. The
unemployment rate for recent college graduates has risen
recently. Why is it important to modernize workforce
protections to reflect today's AI driven economy?
Mr. Branch. Thank you again for the question----
Mr. Scott. Because the AI is driving it, man.
Mr. Branch. Thank you again for the question.
Again, to sort of boost efficiencies that some of these
companies are talking about, they are really targeting lower-
level employees and lower-level jobs and so you are seeing
waves of college graduates who do not have those lower-level
jobs available for them. They are oftentimes requiring
additional job experience that they might not have because they
have not had the opportunity because efficiencies have made
those jobs essentially redundant.
So it is important to ensure that there are opportunities
for these young kids to get into because if you are removing
those jobs, you are essentially removing the ladders to success
that the middle class was built on.
Mr. Scott. In my last 7 seconds we got to guarantee that
our workforce is protected with this advance of AI. Mr.
Chairman, thank you.
Chairman Hill. I thank the gentleman from Georgia.
I recognize the vice chairman of our full committee, the
gentleman from Michigan, Mr. Huizenga. You are recognized for 5
minutes.
Mr. Huizenga. Thank you, Mr. Chairman.
It is interesting, the conversation that we are having
here. Some seem to be suggesting we should not innovate because
of potential job loss. I cannot imagine where America would be
today if that was our guiding principle. We also seem to be
having some folks who lump in AI generally into one big
category. It seems to me an AI system dispensing ``life
advice'' about whether I should take this job or, more
tragically, and is a huge problem, where we have seen systems
tell kids to go do things to themselves that they should not--
it should not even come across their screen but that is very
different than an application to seek facts. What was the gross
domestic product (GDP) of the United States in 1904 is a fact
and because of AI and because of some of these systems, we are
able to--we are able to sort through those things but both of
those are very different than an application to introduce
efficiency into a simple process, or even a complex process. We
have got two great examples here with Nasdaq and Zillow, and
others.
I am going to start there. Someone suggested that there are
not the same protections against discrimination with the
application of AI to various transactions. Mr. Cohen and Mr.
Stevens, I would like you both to quickly address this. What
have you done to ensure that does not happen in your respective
industries? Housing and investing are two of those areas that
we talk about often here in the committee. Is there any
evidence that what your efforts have done is not working, and
is not mitigating that concern, and have you had to make any
adjustments? Mr. Cohen.
Mr. Cohen. Thank you for the question. So we do not serve
retail directly. We serve institutions. We serve financial
markets----
Mr. Huizenga. Sure.
Mr. Cohen. The way that we think about it and the way that
we employ it into our solutions, whether it is our anti-
financial crime solution, our surveillance solution, or
regulatory solutions, it goes through the same PBLC process
that we have for anything that we would deploy. What is really
important about that is the rigorous testing that we do, the
understanding of explainability and transparency--can we
reproduce it and do we understand what the models are
providing? There is always a human in loop. Really important
you keep that human in the loop.
Mr. Huizenga. Obviously, you are not quite as forward
facing as a real estate transaction?
Mr. Stevens. Yes. Similar answer. I will talk about fair
housing and then back to the first part of your question, how
important advice from a human really is in housing. For fair
housing, we built the classifiers----
Mr. Huizenga. By the way, as a former realtor, I fully
subscribe to that.
Mr. Stevens. Yes. Our research shows--it might be
counterintuitive for a leader of AI to say it, but our research
shows that humans making a buy, sell, rent decision want to sit
across a kitchen table and get real human advice from someone
who lives in their market. So, our AI is built to really target
the processes that are keeping real estate agents, like your
former self, away from those important conversations. Then
along the way, we built classifiers like the Fair Housing
Classifier, AI should be held to the same standards as any
human. We want to make sure the facts that are presented to
people as they prepare are meeting those same fair housing
standards.
Mr. Huizenga. Real quickly, in my last minute and a half
here. Mr. Cohen, how is Nasdaq leveraging artificial
intelligence to create markets that are not only more
efficient, but more transparent and fair? You touched on that a
little bit. Do you care to elaborate or--or--how you have to
deal with that--through that?
Mr. Cohen. A really great example of that I did not talk
about in my opening remarks--we have a market intelligence desk
where our listing clients, our corporate clients will contact
us and ask us about sentiment, will ask us about, what is the
intelligence and what are you seeing in the markets? What we
are doing is using AI to essentially group different parts of
data or different pieces of data, which is what we see in
social media, what we see in the news, and what we see in the
markets, and the confluence and the aggregation of that allows
us to use AI, develop patterns, develop insights and
intelligence. We can provide business leaders so they can make
real-time decisions. Now, again, there is a human in the loop.
Mr. Huizenga. Yes.
Mr. Cohen [continuing]. We ensure that, to the extent that
there is news out there that is not real or fake, we are taking
that out before we provide----
Mr. Huizenga. So you are stitching that altogether.
Ms. Whitmore, I am sorry. You seem to be--you are going to
be answering a lot of our questions in writing, but I want to
touch on the anti-money laundering (AML), Know Your Customer
(KYC), and how AI has the potential to enhance compliance
efforts. So 10 seconds.
Ms. Whitmore. Okay. We will follow up in writing on that.
Thank you.
Mr. Huizenga. With that, I get to yield back with 2
seconds. So sorry about that.
Chairman Hill. I thank the vice chairman.
I call on the gentleman from Massachusetts, Mr. Lynch, who
is the ranking member of our Digital Assets, Fintech, and AI
subcommittee.
Mr. Lynch. Thank you, my friend.
I have got a couple of things here. So we are talking about
a quasi-sandbox process here to try to test some of these AI
applications and financial services. As a member of this
committee in the past, we have done oversight on the whole
sandbox process. One of our more instructive experiences was in
Singapore where we went in there and they had a financial
services tech--a fintech sandbox where they invited companies
to come in and participate.
The difference here is that when they did that in
Singapore, they had their regulations in place already and here
we are--we are doing it backward. We are inviting--we are
inviting financial services companies as they deploy AI to
choose which--which consumer investor protections, which
soundness--safety and soundness regulations that they might
want to avoid.
Mr. Branch, is that a proper way to introduce a new
technology? Where you are asking the private sector to identify
regulations that are in place to protect consumers, investors,
depositors--because this applies to banks as well--and you are
asking them what would you like to do to avoid a compliance
with some of the current existing financial services
regulations?
Mr. Branch. Thank you for the question, Representative.
No, I do not think that is a responsible way of moving
about this. The sandboxes that are being proposed often are
completely deregulatory. That is entirely different from the
Singapore model, which was actually hailed in this committee
just a few months ago. They had regulators in place. It was
time limited. Consumers were warned if they are a part of that
sandbox. None of that is present here.
Mr. Lynch. Right. So the idea of the sandboxes, you have a
contained area. Matter of fact, Mr. Chairman, I would like to
ask unanimous consent to introduce the Fintech Regulatory
Sandbox Guidelines, dated November 2016. This was in advance of
the Singapore sandbox.
Chairman Hill. Without objection.
[Information referred to can be found in the appendix on
page 126.]
Mr. Lynch. So a few of the things that they point out here
that are essential to--essential to a successful sandbox, and
that is to manage risks, to contain the possibility that
individuals might be injured, or financially damages. The
consequences of failure for that technology need to be
contained and people need to have advanced knowledge of the
risks that they are embracing by participating in adopting that
technology. It cannot--it says here it cannot be used as a
means to circumvent legal and regulatory requirements, which is
exactly what this bill is suggesting, that--that in adopting
AI, they are allowing, or encouraging, ways of circumventing
existing regulation in what are supposed to be a technology-
neutral approach.
There are also cautions here where applicants have not
demonstrated that they have done due diligence, including
testing the proposed financial services technologies in a
laboratory environment beforehand and knowing the legal and
regulatory requirements for deploying the proposed financial
service technology.
So what--so, Mr. Branch, what is wrong with that whole
approach in terms of protecting consumers, investors,
depositors, and others who rely on the benefits of this
financial services industry?
Mr. Branch. Well, I think the main thing that is wrong with
that approach is that there is everything to gain for large
corporations, and the harm is just going to be entirely brought
on by the American consumer. If anything, if things go wrong,
the government is going to be expected to either bail out or
help out the corporations that have put the consumers in harm's
way.
Mr. Lynch. Thank you very much. Mr. Chairman, I believe my
time has expired. I yield back.
Chairman Hill. The gentleman yields back.
I am pleased to recognize the gentleman from Oklahoma, Mr.
Lucas, who chairs our task force on Monetary Policy and
Treasury Market Structure.
Mr. Lucas. Thank you, Mr. Chairman and thank you to our
witnesses for being here today.
Our whole economy benefits when United States companies
lead the world in innovative financial services. I think we all
agree on that, and our regulations should allow for that
responsible growth and expansion when it comes to AI, too.
Mr. Cohen, would you expand a little bit, what are the
best-use cases, as you see them, for AI to be further deployed
in capital markets?
Mr. Cohen. Thank you for the question.
We, at Nasdaq, deploy AI in two ways: in our products and
then on the business and the way that we think about in the
products. We are trying to generate greater productivity,
better outcomes for our clients, and lead to better client
experience with the types of solutions we provide and I
mentioned this before. We see the possibility of improving
how--how jurisdictions put out regulation, the complexity
associated with regulations, and then what clients need to do
to comply with those ever-changing regulations. AI can go from
reg to code and really allow them to ensure with confidence
they are complying with regulation. So that is a great use case
for us.
In fighting financial crime--I mentioned it earlier. We
must use AI in the data that we have at our disposal to make
sure that we are staying ahead of the bad guys. In terms of
what I talked about with human trafficking, financing
terrorism, we need to make sure that our solutions are
protecting the reputation, the brand, and the consumer behind
those institutions. So that is really, really important.
Then in our markets, we are using AI--and this is our north
star--to make sure that we are democratizing the types of--the
types of capabilities that otherwise small broker dealers do
not have the R&D and engineering talent to develop on their own
and they would be left behind if not for Nasdaq and others
developing it on their behalf.
Mr. Lucas. On that same thought, throughout the committee's
work on combating fraud and scams in financial services system,
we have discussed the sophistication and technological assets
that bad actors use against consumers. So giving you prime
time, opportunity to answer, Ms. Whitmore, how is AI being used
right now to detect and stop fraud and scams, and how will
those services improve and expand in the future?
Ms. Whitmore. Well, I am thankful for the question.
So what we are seeing in terms of the threat landscape
relative to AI--two areas.
The first is attackers using AI to fuel traditional
cybercrime. We are largely seeing that impacts the speed and
the scale with which they operate.
The second part that is not being talked about as much is
how attackers are targeting AI, so creating the ability to make
agents inside of our environments into rogue insiders that
cannot be trusted.
What we see with that is the need for security to be
closely coupled with AI innovation, the need to make sure that
we are protecting the build, the run, and the access--so,
particular to the run time, making sure that agents do not have
the capability to go rogue and that those protections are in
place so that organizations can successfully innovate without
that being hijacked by attackers.
Mr. Lucas. Ms. Manfra, can you discuss how smaller
financial institutions like community banks can utilize this
technology? Why is it important for financial institutions of
all sizes to have access to the latest technology, please?
Ms. Manfra. Absolutely. Thank you for the question.
One of the great benefits of what we are seeing in AI is
the democratization of access to data that, historically, only
large, well-funded institutions might have and the additional
productivity gains that smaller institutions that are more
resource-constrained now have access to larger data sets in
more real-time and are able to put in place improved customer
service experiences, improved productivity, are better able to
detect fraud and reduce the amount of false positives so that
their employees do not have to spend time chasing down
potential dead ends.
So we see a lot of opportunities in the small and medium-
size financial institution space.
Mr. Lucas. Mr. Cohen, I will ask you to respond in writing.
Are existing regulations appropriate to encourage innovation
while maintaining appropriate consumer and financial stability
protections and what are the regulations/statutes, if any, that
would use modernization? You can respond in writing.
Mr. Lucas. I yield back, Mr. Chairman.
Chairman Hill. I thank the gentleman.
The chair recognizes the gentleman from California, Mr.
Vargas, who is the ranking member on our Task Force on Monetary
Policy.
You are recognized for 5 minutes.
Mr. Vargas. Well, thank you very much, Mr. Chairman. I
appreciate it, you and the ranking member putting this
together. I think it is a very important hearing.
I do not believe that you can unring a bell or put the
genie back in the bottle or do anything like that. So the
reality is that science moves forward and our knowledge moves
forward; you cannot reverse it. So I think AI is here. It is
now, how do you manage it?
A few years back, I had the opportunity to go with some of
my colleagues here to the World Economic Forum, and somehow I
got assigned to go to dinner with the young tech entrepreneurs
to listen to Sam Altman. I thought I was not going to
understand a thing because I am not young and I am not a
techie. So I thought, this is going to be interesting, but I am
not going to understand anything.
It turned out I understood everything, because they really
did not talk about technology; they really talked more about
philosophy. It really was more the philosophy of the machine,
you heard earlier, versus human being, the data that you put in
and what comes out and whether that data is positive or
negative.
You could see some of the results--I have seen them in the
following years--where, yes, AI, you will ask it a question and
it will come back with what we would think is a pretty absurd
answer or horrific answer for some young people, but you could
see why the data that you put in, it would ultimately reach
that conclusion. Because not all data is positive; you also
have data that is in there that is negative.
So I appreciate, then, also, we have heard today really the
competition between the good and the bad in AI, because, I
mean, the bad guys use AI also, for fraud and other things.
With all that being said, Mr. Cohen, you have a very
transparent company. In fact, when we talk to your staff, they
get back to us right away. So I will ask you, who is winning
here? I mean, are the bad guys winning in the attacks or not?
Mr. Cohen. Yes and thank you for the question.
What is interesting about this technology is, the rate of
advancement of this technology is faster than the rate of
adoption and you do not often see that with technology.
The second thing is, we need to, as an organization, all of
us, within our four walls, talk out loud about the negative
scenarios that might occur with AI so that we prevent them. If
we do not talk out loud and we do not have conversations
internally about that, then we are missing an opportunity.
To your more specific question, we are seeing in our
markets bad guys, if you will, using AI to come up with more
sophisticated market manipulation schemes. If we are not using
the data and the technology to stay one step ahead, then we
risk the integrity and the investor confidence around our
markets.
For banks, fraud is a massive, massive problem and fraud is
becoming more sophisticated. It is more difficult to detect,
and you cannot do it on your own; you need a public-private
partnership, and you need a massive amount of data to really
stay ahead of it.
So, unless we arm our community to be able to do that, then
we are going to be a step behind, banks are going to be subject
to fraud, markets will be subject to market manipulation.
Mr. Vargas. So I understand that part. You have to--they
are going to use it, so you have to prepare. I mean, it is one
of these things that has to happen.
You also said something that is very interesting because it
is also a philosophical point. And I do have a master's in
philosophy. That is why I am so confused normally but it was
more based on religion. I studied to be a priest for a long
time. The notion of keeping the person in this process becomes
harder and harder as it advances, because the decisions it
makes--it takes all this data, and it uses it so quickly.
How do you figure to keep the person, a human being, in
this process--as you would call it, in the loop--when AI can
make decisions so quickly?
Mr. Cohen. It is an excellent question and the human in the
loop is really, really important. Building those critical-
thinking skills and those judgment skills are exactly what we
are training our people to do.
So, one, we are putting the tool in our hands. Two is we
are providing them with training and education and three is we
are putting good governance around them and providing them with
policies that they can follow and understand. So the humans are
armed with enough so they can make the right decisions at the
right time and understand their roles and their roles are not
decreasing or becoming marginalized. It is actually more
important than ever to have that human in loop and provide that
judgment, as you noted, because AI is designed to provide you
with an answer. It is our responsibility to determine if that
answer is correct and if that is the answer that we want to
provide our investors and, if you will, institutions that we
serve around the globe.
Mr. Vargas. Well, I apologize, I asked you all the
questions. I apologize to the others I was not able to, but I
have 10 seconds left. With that, I will just thank all of you
and I will thank the chair. Appreciate it very much.
Thank you, Chair.
Mr. Barr [presiding]. The gentleman yields back.
The gentlewoman from Missouri, Mrs. Wagner, is now
recognized for 5 minutes.
Mrs. Wagner. I thank the chair.
I say welcome to our witnesses.
Mr. Cohen, in your testimony, you highlighted how Nasdaq
has been at the forefront of technological innovation in our
capital markets since the exchange was founded in 1971.
Nasdaq was an important player in the creation of
electronic trading. While rapid growth over the last few years
in generative artificial intelligence, or AI, has brought this
technology center-stage for the general public, Nasdaq has been
quietly using AI for years and years to fight fraud and
increase market efficiency, liquidity, and transparency.
Mr. Cohen, can you describe some of the ways that Nasdaq
currently uses AI and the extent to which generative AI either
has or might have a role to play in our capital markets and how
do you manage the risks associated with this technology, sir?
Mr. Cohen. Thank you for the question.
It is in our ethos, if you will, to adopt and integrate
emerging and advanced technology early. We see it as a
competitive advantage and one that we have embraced since our
founding in 1971.
With respect to the use of AI, what is important for this
committee to understand is, you cannot harness the power of AI
unless you make the foundational investments to do that. We
have done that over the past decade, whether it is embracing
the cloud, putting good governance in place, having a mature
posture over information security, training and upskilling our
employees, and making sure we have good governance; good
governance is the lubricant for innovation. That is the way we
see it.
Then you have to be really clear to make sure that it is
centralized so you do not have the AI sprawl happening within
your organization and shadow AI, where you cannot control it,
you do not know about it.
So all of those things have been what we have been focused
on over the past decade, which has now enabled us to put them
in our products. As you mentioned, we use it for market abuse.
We use it to fight crime. We use it to democratize access. We
use it to provide more transparency, more information to end
investors so they understand the risks that they are taking
when they invest in our markets.
We are always trying to stay one step ahead of the bad
guys, one, and two, one step ahead of ensuring that our markets
continue to be the best in the world. We have the pride in
making sure that the U.S. markets are the most robust, most
vibrant, if you will, highest moral ground in terms of the way
that we operate and we protect the U.S. markets every day in
the way that we use that----
Mrs. Wagner. You are absolutely right; we have the most
extraordinary markets in the entire world, and we are going to
put a fine point on that this week with the Incentivizing New
Ventures and Economic Strength Through Capital Formation
(INVEST) Act that will be moving forward. So we are very
excited about that.
You are right; other companies and industries need to look
at that AI sprawl, shadow AI, some of the things that--I do not
know that they are entirely discerning, but those are key.
Mr. Cohen, do existing technological-neutral regulations
provide sufficient guardrails for the responsible use of AI in
our capital markets, or are new AI-specific updates and
clarifications required? If updates are in order, what should
they look like, and how can they be implemented without
stifling innovation?
Mr. Cohen. That is a great question. It is one that we
actually think about quite a bit, especially as the technology
is evolving.
What I would say is, we have a great foundation. We have
securities laws. We have NIST that we follow. We have Reg
Systems Compliance and Integrity (SCI) and we have worked hard
as an industry to put more rules in place around technology. So
the foundation is there.
I think the key to that question is, because the technology
is advancing at such a rapid pace, information-sharing or
private-public partnership, where we can share information
about the advancements of this technology to identify gaps,
was--we do not know what those gaps might be today, because the
advancement of that technology is such that it is not linear.
It is exponential and we tend to plan very linearly as humans.
So we are just going to have to make sure we stay in touch,
we share information, we use the foundation that we have that I
mentioned, with NIST and Reg SCI and the securities law, to
ensure, when a gap comes up or when there is a risk that we
have identified, we work together to address that quickly.
Mrs. Wagner. Well, I may not--you may have to respond in
writing here, but I am interested in knowing if there are any
existing rules or ambiguities or proposals that are limiting AI
innovation from reaching its full potential in U.S. capital
markets--obviously, a focus of mine.
So I will look for your answer in writing.
Mrs. Wagner. I thank you for your testimony.
I yield back to the chair.
Mr. Barr. The gentlelady yields back.
The gentleman from New York, Mr. Meeks, is now recognized.
Mr. Meeks. Thank you, Mr. Chairman.
Let me go directly to Ms. Whitmore.
Ms. Whitmore, the nexus of AI and cybersecurity is
particularly important and can be particularly concerning as
well. Last year, the Salt Typhoon hack against the United
States companies and high-profile leaders was called the
largest cyber breach in United States history.
Can you just give me a very brief summary of what happened?
Ms. Whitmore. Yes. Thank you for your question.
So you are referring to an attack by a nation-State actor,
in this case China, that targeted our telecommunications and
critical-infrastructure industries across the board, with the
intent to steal data to then use it to meet political
objectives at some point.
Unique to critical infrastructure, the component there is
the fact that the Chinese nation-State may be intentionally
looking to embed themselves within critical infrastructure,
with the intent to take some sort of action at a later date.
Mr. Meeks. Thank you.
Mr. Chairman, I want to, for the record, enter this article
entitled ``U.S. Halted Plans to Sanction Chinese Spy Agency to
Maintain Trade Truce.''
Mr. Barr. Without objection.
[The information referred to can be found in the appendix
on page 146.]
Mr. Meeks. Then, a few days after the report, more news
came out of Department of Commerce, which I cannot believe that
they intend to allow Nvidia to sell one of the most advanced AI
chips to China that had been previously banned for export.
In fact, the Justice Department was just about to go after
someone who was trying to sneak them into China. Yet--this is
unbelievable to me--the President started a trade war that we
are losing, and he is now afraid to punish the People's
Republic of China (PRC) and its entities that hacked our most
innovative companies to access the private communications of
the American people.
Further, by allowing advanced Graphics Processing Units
(GPUs) to go to the PRC, he is throwing away our biggest and
most important advantage in the AI race with China.
That is innovation? This is not innovation. This is not
winning. This is, indeed, weakness. Unfortunately, it is going
to cost our country.
Let me go to another matter. In America today, rising
housing prices and stagnant wages have put home ownership out
of reach for millions of Americans. Median home prices remain
near historic highs, and too many working families are nowhere
near achieving their American Dream of owning a home.
A major part of the problem is that we simply are not
building enough homes. Whether it is because of zoning
barriers, permitting delays, outdated systems, and rising
construction costs because of--you got it--Trump's tariffs on
materials like lumber and others, you have what is becoming a
perfect storm.
So, Mr. Stevens, in your testimony, you mentioned that AI
can help address some of these challenges. You said it could
help with clearing permitting and zoning backlogs, reduce loan
origination and compliance costs, and speed up the development
process. That would be good news.
My question to you, sir, is: Aside from boosting
efficiency, how can AI be leveraged to enhance housing
affordability and increase the supply of homes? The President
says this is a hoax, affordability, but let us go. How can that
happen?
Mr. Stevens. Yes. Thank you, Congressman, for the question.
I very much agree, we are facing a housing affordability
crisis, and there is no silver bullet. I think you mentioned
one of the biggest drivers is that we are 4 million homes short
in terms of supply.
We are very excited about the efficiency gains that you
mentioned--zoning laws, really understanding how we can make
more efficient the mortgage and real estate processes.
I would say, beyond that, bringing more information to
consumers. Four million families will buy a home this calendar
year, 2 million for the first time, and understanding what is
available to them, what they can afford, what they should
explore, helps actually reduce some of the affordability
problems we are facing today.
Mr. Meeks. There should be some public-private partnering
so that we can ensure that AI is being used safely and
effectively? Is that not correct? Do you----
Mr. Stevens. Yes.
Mr. Meeks [continuing]. agree with that?
Mr. Stevens. Exactly.
Mr. Meeks. Thank you.
I yield back.
Mr. Barr. The gentleman's time has expired.
I now recognize myself for 5 minutes of questioning.
In President Trump's July AI data action plan, he notes
that we must develop a grid to match the pace of AI innovation.
Unfortunately, our grid is currently unable to keep pace with
our energy demands.
The Department of Energy projects that blackouts could
increase a hundredfold by 2030, with one study saying that the
Mid-Atlantic and Great Plains regions could face 400 hours of
power outages annually.
The growing demand for power, with AI, is increasingly a
major strategic challenge for the United States.
Ms. Manfra or Ms. Whitmore, what is the threat to U.S.
national security and global leadership in the AI space if we
cannot meet the supply of energy needed to power AI data
centers in the United States?
Ms. Manfra. Thank you, sir, for the question and raising
this important topic and I am happy to go and continue with you
and your staff in more discussion on this.
Yes, overall, we need to ensure that we are able to keep
pace with the demand for energy in order to support American
competitiveness in this space. We also need to ensure that we
are doing that responsibly and in partnerships with those
companies that are involved in the distribution and provision
of electricity.
Mr. Barr. Well, what considerations go into a firm's power
strategy, your firm's strategy, when it comes to training and
developing frontier AI models?
Ms. Manfra. We are heavily invested in optimizing our
infrastructure, so our technical infrastructure, and the way
that we run and power the machines that power AI for energy
efficiency. So we spend a lot of time, and that is a key
principle of ours, is to optimize for energy efficiency.
I hope that answers your question.
Mr. Barr. Well, let me ask the question a different way.
Our self-inflicted energy crisis is a direct result of bad
policy--Green New Deal, Paris climate accord, Network for
Greening the Financial System, the SEC's climate disclosure
rule, the regulators' ``Principles for Climate-Related
Financial Risk Management,'' chokepoint, the push for the
greening of the financial system.
Mr. Cohen, can you talk about the importance of traditional
financing of the most reliable and affordable, dispatchable
sources of power--that is, fossil energy and nuclear? Why is
that important for us to win the global race for AI leadership?
Mr. Cohen. I think, at the end of the day, it is important
to note that Nasdaq does not operate its own data centers and
so, when we think about power--and we operate our markets, for
instance, out of New Jersey, a data center we have been in for
a very, very long time--we are working hand-in-hand with our
data-center providers on the power strategy.
As you just heard, we, as a public company, a for-profit
company we want to be as cost-effective as we can, making use
of all sources of power, and ensuring that we have the
portability----
Mr. Barr. Well----
Mr. Cohen [continuing]. and mobility to move should we----
Mr. Barr. I am going to reclaim my time and make an
editorial comment.
China has 33 nuclear power plants under construction, with
an additional 200 in planning. Coal has been the largest source
of global electricity for 125 years, and it will be for decades
more in the future. It is by far the largest source of
electricity in China. They built 100 coal plants last year.
Now, we need diversified energy sources. I am not
advocating for exclusively fossil energy or exclusively
nuclear, but we have to get with the program. If we are going
to win the race for AI, we have to look at what our competitor
is doing, and we cannot put our heads in the sand and continue
to regulate our energy sources into oblivion, if we want to win
the AI race.
Final question: We all acknowledge the risks of AI that Mr.
Branch talked about--AI-generated fraud, deepfake abuse,
consumer deception, et cetera but he criticizes this proposed
AI preemption language as an effort, quote, to undermine State
AI protections. There are more than 160 State-level laws and
AI, by its very nature, is interstate commerce.
Mr. Cohen, can you talk about the importance of Federal
preemption to avoid a patchwork of conflicting and inconsistent
AI regulations that would stifle innovation?
Mr. Cohen. We think Federal preemption is extremely
important, and we think it needs to be principles-based as
well. We do not think we need a new central regulator while we
consider that. I think the reasons for that are: If you cause
confusion, if you raise the cost of doing business, it will
simply just go overseas.
Mr. Barr. Well, I agree, we do not need a new central
regulator, but we do need Federal preemption so that AI
innovation can fight crime, detect and stop fraud, democratize
finance, promote financial inclusion, and protect our markets.
I yield back.
Now we recognize the gentleman from Illinois, Dr. Foster,
for 5 minutes.
Mr. Foster. Thank you, Mr. Chair, and thank you, witnesses,
for your really excellent testimony.
You know, Congress is currently stuck in this issue with
federalism and Federal preemption. You know, we are struggling
between the nightmare of having 50 independent standards for AI
regulation and the fact that we have a do-nothing Congress that
is so paralyzed by the thing that--even straightforward things
that we ought to be able to agree on, nothing is happening. We
are seeing consumers suffer greatly already, and it is not
going to get easier.
There is a middle ground on this, which is something that
we are going to be circulating draft legislation on and I would
like to comment on, which is simply a proposal to let
coalitions of States form their own standard, so that any
coalition would have to have, for example, 20 or 25 percent of
the population, and so there would be significant coalitions,
and companies would only face at most two or three sets of AI
standards.
This sort of cooperative federalism, if you will, I think,
is the thing that we may be able to agree on in this and so I
just--I am tossing that out. There will be more detailed
legislation, but it is a pretty simple concept.
Most of you who work internationally already deal with a
dozen different countries and their regulations, so if the U.S.
had two or three standard markets for things like--you know,
for everything AI--privacy, all this sort of stuff--I think it
would actually work well and we would preserve the laboratory
of democracy of the States on this.
Also the big thing that is coming at us is agentic AI. This
is--you know, it is the future, not only of financial services
but everything consumer-facing and Business-to-Business (B2B)
transactions.
In the near future, most businesses are going to be facing
not their customers but their customers' agent, and that is
going to change everything. Customers' AI agent will not care
if you have a pretty website or an easy-to-use customer
interface or a friendly smile, you know? Most consumer agents
are just going to be given instructions to get the best price.
Customer loyalty will go to zero and this could destabilize our
banking system--for example, with AI-driven bank runs. Agents
are going to squeeze the margins out of all consumer-facing
businesses, and that will be extremely disruptive. You know,
for example, to pick an unsympathetic example, used-car dealers
will no longer have an infinite supply of clueless customers to
take advantage of.
However, it may also really simplify consumer protection
law, because so much of consumer protection law is to protect
unsophisticated customers. If there are no unsophisticated
customers because you are dealing with their AI, it will change
everything.
All right. So what can Congress realistically do about
this?
First off, preventing identity fraud by enhancing the
deployment of digital driver's licenses and mobile ID. This is
being done by most of the States right now. The EU, the U.K.,
Asia, everyone has--almost every country has the ability to get
out your cell phone, to deploy a federally issued real ID, a
driver's license or a passport or equivalent, and prove they
are who they say they are in an online transaction. We have to
do everything we can to get this adopted.
What we need here are not--you know, one of the legislation
is to study best practices for sandboxes that we are not yet
going to build. What we actually need is a pilot program for
KYC customers using a REAL ID digital driver's license, which
would just simplify all kinds of things and prevent a lot of
the identity fraud.
Second, I think, if we were able to define United States
standards for agent-to-agent communication.
You know, right now, there are multiple competing
standards. There is the Model Context Protocol from Anthropic.
There is an Agent-to-Agent (A2A) coming out of Google.
Actually, Google has two. You just in your testimony referenced
AP2, where I spent a while on the website last night. It is
actually, I think, a much better step in the direction of--
because what we need is a well-defined, legally precise
language to communicate things like what is the privacy, what
is the data retention, what is the logging of the interaction,
and all the legally things in order to have reliable
transactions between agents.
There are policy decisions there that we can defer. What we
should do is have NIST or--you know, probably NIST and a number
of partners in industry come together and define those
standards. The White House is correctly appointed to the
advantage of having the U.S. lead that. What I would like to
see is to have NIST and the United States lead the world in
defining agentic communication standards the same way we led
the world in defining the personal ID standards, digital ID
standards, that are now at Android and IOS and everything else.
Anyway. So these are--there are lots of things to talk
about here.
I just want to thank you. You had really high-quality
testimony, and I learned a lot reading it.
Thank you.
Mr. Davidson [presiding]. I thank the gentleman.
I now recognize myself for 5 minutes.
Artificial intelligence does not change our fundamental
regulatory framework which allows innovation while protecting
consumers from abuse or fraud. As AI becomes more deeply
integrated into our financial services and housing markets, it
is essential that existing consumer protection laws covering
privacy, fair lending, data security, fraud, et cetera,
continue to apply fully regardless of the technology used. The
principles should remain simple. If a practice violates the law
without AI, it should not be permissible with AI.
At the same time, AI's increasing reliance on large,
sensitive data sets raises important questions about whether
our current data protection frameworks are sufficiently clear
and durable for the modern economy. In my view, privacy is the
base layer for ethical AI, and we need to update our privacy
laws. We need it to do a much more robust job of that. Congress
should reassess how consumer data is collected, used, shared,
and safeguarded, without imposing rules that freeze innovation.
Finally, we should also know that a fragmented patchwork of
State AI mandates risks undermining both innovation and
privacy. A harmonized Federal framework can protect consumers
while giving innovators the clarity and certainty they need.
This needs to be a more thoughtful approach, though, and
Congress should have the debate and make the decision, not
something that can be done with a two-sentence addition to some
bigger bill on another topic that basically says, ``We can do
whatever we want.'' It does require a more thoughtful approach,
in my opinion.
Mr. Stevens, what specific categories of consumer data are
being used to train and operate AI systems today?
Mr. Stevens. Many. Thank you for the question.
I totally agree, especially in housing, how important
privacy is. This is the biggest financial transaction of your
life; there are many factors that go into it. All our consumers
report to us that they want to really make sure their personal
data is theirs.
We use basically things like signals on what preferences
they have, financial data they give to us when they are
thinking about what they can afford. They work with real estate
agents who use some of our tools and tell us about their hopes
and dreams. We make sure that all of the above is meeting the
Federal standards and laws.
When we work with other companies, as an example I gave
during verbal with OpenAI, we continue to make sure that is
still the case. So, when ChatGPT might want to violate fair
housing, our classifier makes sure that does not happen and
that all of the consumer's information is kept as theirs.
Mr. Davidson. How do you ensure that you protect personally
identifiable information (PII)? What kind of transparency is
there? What kind of recourse do consumers have?
Mr. Stevens. Yes. The easiest way is to not--or, is to
first keep it safe, so keep it on our systems that are
protected. Only certain humans have legal ability to view that
data or work with that data. With third-party partnerships, we
usually do not share that information. If we do, under limited
license, that is then deleted upon completion of the
transaction.
Mr. Davidson. Thank you.
Mr. Cohen, there is a lot of discussion about the
importance of winning the AI race against China. Frankly, I am
concerned--to beat China, we should not try to be more like
China. I do not want to be like China. I want to be like
America but yes, on the technology end, we want to win the AI
race.
Can you give us a sense of how you view this discussion
through the lens of our capital markets and give us your
perspective on the level of AI adoption Nasdaq is seeing from
the broader market and China in particular?
Mr. Cohen. Thank you for the question.
Our focus continues to be, as an operator of markets here
in the U.S., to make sure that the markets here are the most
robust, vibrant, most attractive in the world and we will use
AI to continue to ensure that we do that.
We do it--and I spoke about this before--by introducing
whether it is order types of functionality that democratize
access, that allow smaller broker-dealers to participate in our
markets so we have a healthy ecosystem, or we root out
financial crime to make sure that there is investor confidence
and market integrity, or we use surveillance to detect
increasing sophistication in market abuse.
All of those require us to use AI, to invest in AI, to make
sure that we are partnering with folks around here, the
colleagues that I have here on this panel and others, to ensure
that we ensure that the U.S. capital markets remain the most
robust in the world.
Mr. Davidson. Yes. I mean, in the private sector, of
course, there is a lot of incentive to keep up with this arms
race. On the other side, you are dealing with regulators that
sometimes have not kept up with a lot of the technology.
So, when we think about it here in Congress, what are the
most important things we could do to make sure that America is
the most competitive place for capital to be deployed?
Mr. Cohen. We talked a little bit about it before. The need
for sandboxes, the need for the ability to continue to innovate
in a safe and responsible manner, I think, is extremely,
extremely important and not having overly complex regulation
that we have to patch together is also very important.
Now----
Mr. Davidson. My apologies. I did not give you much time to
answer that. If you want to provide a longer answer----
Mr. Cohen. I can certainly do that.
Mr. Davidson. My time has expired, and I respect everyone
else's time.
I now recognize the gentleman from California, Mr. Sherman,
who is also the ranking member of our Capital Markets
Subcommittee.
Mr. Sherman. I want to commend Mr. Foster for his digital
ID bill. I know it is running into some opposition, but,
ultimately, if we cannot identify ourselves in this new digital
age, this will be a problem.
I also commend him for leading a letter asking that the
Financial Stability Oversight Council (FSOC) to look at the
financial risks of an AI bubble.
Ms. Manfra, do you see signs of an AI bubble out there?
Ms. Manfra. Sir, respectfully, I am not a market analyst.
Mr. Sherman. Okay.
Ms. Manfra. I am responsible for risk and compliance,
like----
Mr. Sherman. Thank you.
Ms. Manfra. So I will yield.
Mr. Sherman. But you are from Google and there is someone
else who works at Google, Ray Kurzweil. I think he was once
your chief technology officer, and he was before the Science
Committee some 22 years ago. I asked him how long it will take
for non-biological intelligence to surpass human intelligence,
and his estimate then was 26 years. So we are almost there.
First of all, you hire very smart people, because to
predict something and to be that close--we are spending
trillions of dollars, as a species, to make AI more powerful. I
cannot find a program anywhere in the world--and I would
support it if I could find it--designed to monitor and prevent
self-awareness and ambition, to determine what can be done to
prevent AI from developing its own objectives, which I think
would be hostile to ours.
There is a book--you may not have to read the book--great
new book coming out--it just came out. It says, if anyone
builds it, everyone dies.
Is Google--do you have a department, do you have a budget,
for monitoring, for preventing self-awareness, ambition, or AI
creating its own goals?
Ms. Manfra. We invest a great deal in ensuring that the AI
capabilities we are developing is in line with human values----
Mr. Sherman. I have always heard that, but I cannot find a
single scientist who is looking for self-awareness and
ambition. Obviously, you do not want criminals stealing our
data or our money, and what you describe fits into that
category.
Can you name one person whose job it is at Google to
prevent AI from becoming a creature rather than a tool?
Ms. Manfra. So let me get back to you. We do have
researchers that are heavily invested in this topic. So, if I
can, I will get back to you. It is not my area.
Mr. Sherman. Please. Please get back to me because I have
not been able to find anyone. Then you ask about these issues,
and you get this vague ``align with our goals,'' and the goal
usually is, ``Well, look, we can make trillions of dollars by
making AI more powerful,'' and there is no money in preventing
AI from taking over the world. That is the next generation's
problem.
One problem we have--and I will feed you one more
question--is AI doing its analysis and then reflecting the
discrimination that has existed in our society for many
centuries. For example, you could say, if somebody grew up in a
particular ZIP code, they are more likely to default on their
rent.
What do you do at Google to make sure--and I think there
was another study that says, if you want to analyze who is
going to be successful at Yale, it turns out the best predictor
is being named, I think, ``Jared'' or some other name
associated with the elites in our society.
What do you do to make sure that the prejudices of the past
are not built into the computers that will control the world in
the future?
Ms. Manfra. Thank you for the question. This is something
we care deeply about and issued our responsible AI ethics
principles nearly a decade ago.
So our approach, first, is to ensure that humans are
involved in the setting of the parameters, if you will. We are
constantly designing, redesigning, and then monitoring to
ensure that we have an unbiased approach and we are always
iterating. It is not----
Mr. Sherman. Do you have a program that----
Ms. Manfra. Yes.
Mr. Sherman [continuing]. prevents the ZIP code that you
were born in from influencing the decision that is made?
Ms. Manfra. I know we look at those things to ensure that
we do not have--I will get back to you on a specific program.
Mr. Sherman. I will ask everyone to get back to me on
whether you are focusing on preventing AI from becoming a
creature.
I will yield back.
Mr. Steil [presiding]. The gentleman yields back.
The gentlemen from Tennessee, Mr. Ogles, is recognized for
5 minutes.
Mr. Ogles. Thank you, Mr. Chairman.
Thank you to the witnesses.
You know, obviously I serve on Financial Services. I also
serve on Homeland Security, where I am the chairman of Cyber,
which would obviously overlap with AI. This obviously, when you
look--and, quite frankly, Mr. Chairman, when you look at AI,
what really got my interest in this topic was the national
security side of the financial services conversation.
As we look at artificial intelligence in the context of
financial services, I think it is important we recognize that
we are dealing with a technology that does not fit neatly into
traditional policy frameworks. AI is not a product or a single
system; it is a capability layer that will influence everything
from market structure to fraud prevention to consumer
decisionmaking.
That means the questions in front of this committee are not
simply about regulating a new tool. They are about whether our
existing financial architecture, our risk models, our
supervisory expectations, disclosure rules, or even our
assumptions about human judgment are prepared for a world where
some of our core analytic work is done by systems that learn
and adapt at scale.
At the same time, AI gives institutions the ability to
detect threats faster than humans ever could, analyze complex
data sets that were previously unusable, and offer consumers
services that are more personalized and more efficient.
The challenge for Congress is understanding where AI is
simply accelerating what firms already do and where it
fundamentally changes the nature of a financial decision, a
compliance obligation, or a market signal.
My goal today is not to choose a side between regulation
and restraint. It is to ensure that, as AI becomes more
embedded in our financial system--and, as said previously, it
is here, it is not going away--that we understand the concrete
risks, the real opportunities, and the limits of the technology
and, I might argue, the unlimited potential of the technology.
We need clarity where clarity is necessary, flexibility where
innovation requires it, and a realistic view of how these
systems operate in practice.
Ms. Manfra, you mentioned grounding and outcome-based
evaluations in AI risk management. Can you give a real-world
example of how grounding has corrected or improved financial AI
models' output and how regulators should think about evaluating
whether grounding was done properly?
Ms. Manfra. I can get back to you on a specific example,
but I would say, in general, the core to what we need to focus
on is having transparency and explainability.
So, as--which we have invested a lot in and work with a lot
of our financial consumers as they use AI for things like fraud
detection, anti-money laundering these various decisions that
have this high risk, to be able to ensure that they can go back
and understand why the model made the decision or the
recommendation that it did and enable the compliance with
existing laws that do apply to these scenarios as well.
So that is a space that I think is very important, is
ensuring that transparency and that explainability, in
particular for financial services, though they are not the only
industry, but to enable AI for these heavily manual but
oftentimes high-risk, with a lot of false positives that put a
lot of burden onto organizations.
So I believe it actually can--if organizations implement it
responsibly, you can reduce your compliance obligations, better
manage your risk, and get better outcomes for consumers and
partners.
Mr. Ogles. I think for those who are watching at home the
key here is that transparency and understanding because the
financial institutions are required--there are compliance
requirements. If they are using AI to achieve those
requirements, to be in compliance, they need to understand how
AI is helping them get there but then also understand where it
may make mistakes or hallucinations, right?
Mr. Cohen, your Dynamic M-ELO AI-powered order type adapts
to real-time market conditions. What specific signals or data
streams do they rely on? And should investors have standardized
transparency into how these AI-assisted order types behave?
Unfortunately, you have 40 seconds.
Mr. Cohen. I might come back to you with details in
writing.
Mr. Ogles. Give us that overview.
Mr. Cohen. So we take in 130 different signals from the
market to determine how that order type should operate. Every
30 seconds, we take that in because real-time market
conditions, they give you a sense--we are processing millions
of messages per second. To be able to process all of that, we
need to use AI to ensure that we are staying one step ahead of
the market conditions that then allow our investors to get the
kind of execution they require.
Mr. Ogles. Yes, sir.
Mr. Cohen. Remember, we are highly regulated, so everything
we do, we need to have the Federal Communications Commission
(FCC) approve. They need to make sure there is explainability
and reproducibility on what we provide.
Mr. Ogles. Mr. Chairman, I will just say that, as we look
at the national security landscape, the financial landscape our
adversaries are leveraging AI without any guardrails, and we
have to be prepared and ready to, quite frankly, go on the
offense.
Mr. Chairman, I yield back.
Mr. Steil. The gentleman yields back.
The gentleman from Missouri, Mr. Cleaver, who is the
ranking member on the Subcommittee on Housing and Insurance, is
now recognized for 5 minutes.
Mr. Cleaver. Thank you, Mr. Chairman.
If I could also thank Mr. Lynch for kind of leading this
effort on our side.
I just have one question. My interest in AI grows daily,
and I am even more concerned today than I was yesterday.
If you look at what is happening in the Federal Government,
being reshaped by the President and the Supreme Court, 75
percent of fair-housing staff is gone. It is not, like, a
couple people, but 75 percent has gone since January.
Because I have been around, I know that when we are talking
about trying to deal with housing, which is easily the number
one or number two most significant domestic issues we face, I
am further--my paranoia has grown stronger because I am
concerned that AI could also be an excuse--``Well obviously,
this is fair.''
It goes along with something that was raised earlier. Fair
housing, I mean we are--``Do not worry about it. AI is going to
make sure that everything is fair. I mean, after all, AI cannot
discriminate.''
It is infuriating, first of all, that this is already
taking place in the government, and then we have to deal with
AI possibly doing even more damage to fair housing. If
everything was clear and equality was a part of everyday
thought I would not even need to raise this issue but that is
just not the case.
So, at a time when civil rights and fair housing are
issues, growing issues instead of being subsided, somebody help
me understand how--why AI will not make this worse.
Mr. Stevens. I would be happy to, Congressman.
Working at Zillow day to day, we totally believe that fair
housing is paramount. I would say, an opportunity that AI--we
have already seen is, you can start describing what home you
are interested in a more natural language. No one wakes up and
goes, ``I want three bedrooms, comma, big backyard, comma,''
like a computer would standardly want. With generative AI, you
can say, ``Hey, I am looking for that big backyard, close
commute to work,'' that kind of thing.
The problem is, there are certain fair-housing questions
that are not legally supposed to be answered and that is what
led to our Fair Housing Classifier. It is probably one of the
more complicated models we have developed at Zillow. Instead of
going, ``Okay, we will just keep that to our ourselves,'' we
felt that the right thing to do to help other researchers,
other institutions, was to make that available to others. They
can contribute back and, of course, use it in their own
systems.
So that means every deployable AI in the housing sector can
take advantage of a fair-housing-compliant method.
Mr. Cleaver. Well--and I appreciate your response. I am
wondering about the others on our esteemed panel today.
Do any of you have a suggestion?
Mr. Branch. Representative, may I respond to your question?
Mr. Cleaver. Yes.
Mr. Branch. There is an assumption built in with a variety
of companies when they discuss the positives of AI, and one of
those built-in assumptions is that AI is going to remain
aligned to human values or American values. What they are not
acknowledging is the possibility of AI drift. That is when AI
starts to drift away from what some of our values actually are.
That is when you see instances of kids being encouraged to harm
themselves or discrimination in banking decisions and that is
why it is important to have these regulations in place to
ensure that these companies are being regulated and ensured
that they are making sure that their algorithms are working in
place.
There are ways to do that. We have spoken a lot about China
today. I do not think Americans have to choose between winning
a hypothetical AI race in China or being protected from harmful
AI products. I think that is a false narrative and a false
binary.
Mr. Cleaver. Thank you.
Thank you, Mr. Chair.
Mr. Steil. The gentleman yields back.
I recognize myself for 5 minutes.
I think we have seen a real positive shift in AI policy
from the previous administration to the Trump Administration.
The Biden Administration's precautionary approach was stifling
innovation. The Trump Administration's AI action plan try-first
approach is the right approach, in my opinion.
I think financial services have been leading the way in
applying AI in the real world for decades, so I just wanted to
get a couple instances on the record.
I will start with you, if I can, Mr. Cohen. Can you just
describe a couple ways that Nasdaq is utilizing and has been
utilizing AI in the financial services space?
Mr. Cohen. Thank you for the question.
I will go back to my opening comments, in that we focus on
three core principles when we employ AI, and I talked about
liquidity, transparency, and integrity.
With regards to integrity, our anti-financial crime
platform, Verafin, is allowing banks to operate with confidence
when it comes to fraud management and it is allowing them to
achieve goals that they otherwise could not achieve on their
own when they limit fraud in the market.
Mr. Steil. So it is essential to manage fraud, illicit
trading broadly in the risk space.
Mr. Cohen. Absolutely. It does more than any single
institution can do on its own, because it is cloudinated, AI-
enabled, and uses consortium data.
Mr. Steil. Let me jump to you, Ms. Manfra, if I can, a good
Wisconsonite. Good to see you here.
Can I ask you to pinpoint, how are firms in particular
thinking about this when they are deploying this new
technology?
Ms. Manfra. What I would say, and reiterate what you
probably heard before as well, is, the financial services firm
has a long history in managing model risk, and there are
processes and regulations and oversight in that place.
So what we see with our financial services customers is, as
you noted, very innovative uses for these set of capabilities,
but also very thoughtful. So they think about things like, how
do I ensure a human in the loop, how do I ensure I have proper
governance in place, how do I ensure that I understand how I
can meet my risk management and compliance goals and----
Mr. Steil. So, knowing that these firms are going through
this deliberative process to think through how they are
balancing reward and risk in utilizing AI, I want to come
back--because we discussed the sandbox concept earlier--I want
to come to you, Mr. Cohen, with a short question here.
Earlier this year, Chairman Hill and I introduced the
bipartisan Unleashing AI Innovation in Financial Services Act,
which enables regulatory sandboxes at the Federal financial
agencies that are targeted in size and scope.
These sandboxes, they have a handful of things: They have
to be approved and overseen by Federal regulators; they require
compliance strategies and risk management, which we were just
discussing; they must not impose systemic or national security
risks--obvious to make sure we are doing that.
So Federal regulators will impose appropriate limitations
or conditions on them. Additionally, fraud and unsafe and
unsound practices will remain prohibited under the sandbox.
So the idea that these sandboxes create a free-for-all and
allow participants to flout all the rules they just do not
like, it is simply not true, right?
So, rather, the sandboxes provide a more secure environment
to experiment with AI, enabling innovation, with built-in
guardrails, Federal oversight and so this is how I think we
learn from best practices for governance while exploring the
applications that will improve American financial life.
So here is the question: Would these AI sandboxes enable
regulators and market participants to responsibly experiment
with AI and learn best practices?
Mr. Cohen. Yes, the key qualification is what you said; it
needs to be controlled, it needs to be targeted, it needs to be
time-boxed, and it cannot be used to circumvent--and we have a
very practical example of that.
We, as a highly regulated institution, often run pilots
with the SEC, where we are really transparent about the results
of that pilot, and we ensure that informs decisionmaking and
allows for better outcomes for investors in the markets.
Mr. Steil. So it is not really a free-for-all. It is a
sandbox that has a regulatory structure in place. Underlying
laws apply. Ms. Manfra laid out how firms are thinking about
applying AI. They are going through a deliberative, thoughtful
process.
In your opinion, do sandboxes help create innovation and
development in the United States in a thoughtful, structured
way?
Mr. Cohen. They have. They have. They have been critical to
our innovation. Again, if it is controlled, time-boxed, and
targeted and transparent, it yields positive results.
Mr. Steil. I appreciate that.
Ms. Whitmore, I wanted to take my time and come to you and
discuss, in particular, how AI can eliminate fraud, deepfakes,
and really help us. In 10 seconds, can you add to your previous
comments?
Ms. Whitmore. We will be happy to follow up with a written
response to that. Thank you.
Mr. Steil. Thank you very much.
I yield back.
I now recognize the gentlewoman from Ohio, Mrs. Beatty, who
is also the ranking member of the Subcommittee on National
Security. She is now recognized for 5 minutes.
Mrs. Beatty. Thank you, Mr. Chair and Ranking and thank you
to the witnesses.
Wow. A lot of good testimony. I never thought about asking
my grandchildren, when we move, what they would like to take
into a new house. So you put it in a whole new perspective for
us.
A lot of words today, on both sides of the aisle, and they
all come together. You know, we have heard things like we need
to strike the right balance, we should not discriminate with
AI, we should have accountability, it should be well-defined,
there should be responsible AI, we need clarity, we need legal
and policy definitions. All of that is true, whether it came
from the Republican or the Democratic side.
I do not know that I have heard a lot of responses that are
definitive to say, ``Here is how we are having responsible
AI.''
I have a great concern. I serve as ranking member on the
National Security Subcommittee, and I am focused on preserving
the safety and the security of our financial systems and
protecting consumers from fraud.
So my first question--and I am going to try to get through
a series of them.
Mr. Branch, we will start on this end. How is AI used in
anti-money laundering and fraud detection, and how effective is
it as a tool in our illicit finance arena?
Mr. Branch. Representative, thank you, but I apologize, I
am not an AI fraud analyst. That is outside of my expertise,
but I could have my colleagues get back to you.
Mrs. Beatty. Okay.
Anybody else want to take a stab at that?
Mr. Cohen. I can try.
So we operate a financial crime management platform called
Verafin. I have spoken about it here. Again, it is cloud-
native, AI-based. We have over 2,700 clients. We have 725
million accounts, just to give you a sense of how large that
pool of consortium data that we dig into is.
We use that--we use that to protect small and medium-size
institutions, small banks, super-regional banks from the cost
of fraud so they can operate and provide everyday customers and
investors and clients of theirs with the security that they
deserve when they invest their money and then have transactions
associated with that institution.
So that solution is really paramount to creating safety and
responsibility along the traditional rails.
Now, we also are looking at nontraditional rails like
crypto rails and others that consider how payments and
transactions may be--may be--subject to fraud as well. So that
is where we are extending it, but it is incredibly important
and valuable for small and medium banks.
Mrs. Beatty. Okay.
I will go to another question.
We talked about--or someone, on both sides, said that we
should not discriminate. One of my primary concerns about the
use of AI, especially in financial services, or maybe not
necessarily with just financial services, is the potential for
bias in algorithms and that they lead to unfair results. You
can only be as good as the individuals that put the data or
gather all the folks in it.
So, as we look to develop a comprehensive AI regulatory
framework, how do we ensure that the use of AI does not lead to
discriminatory lending or pricing or underwriting or any other
area that we use algorithms?
Anybody want to take a stab at that?
Mr. Stevens. Thank you, Congresswoman, for the question.
I will say, I was first hired by Zillow to work on the
Zestimate and two answers would be: additional data and then
also a national right-sized framework that we can apply across
the country.
On additional data, that is the benefit of GenAI. For the
Zestimate, we can now look at additional comparables maybe
outside of your direct neighborhood to get a more balanced and
fair evaluation. We can also look at the listing images, the
listing description--all this unstructured data that was not
possible to be ingested before.
At the same time, we have to do a lot of checks that is the
right data and there is no inherent bias within it and that is
where we use, like, the NIST Risk Management Framework (RMF) to
make sure, before we deploy, that it is a fair evaluation.
Mrs. Beatty. Thank you for adding and saying that because
you--the outcome has to be that you have people from other
communities and there is a diverse pool of folks at the onset.
So it would help us not have discriminatory practices with
that.
Thank you, because I know, for example, women have not
always been included in trials, and so when you are building
these algorithms, you have to have people in examples that you
put in. So that is something that I am watching carefully.
My time is up. Thank you, Mr. Steil. I yield back.
Mr. Steil. The gentlewoman yields back.
The gentleman from Florida, Mr. Haridopolos, is now
recognized for 5 minutes.
Mr. Haridopolos. Thank you, Mr. Chairman.
I appreciate this thoughtful conversation. I know
Congressman Liccardo and I are working across bipartisan lines
and trying to find solutions of this and become a hyper-
partisan issue which is, I think, all of our goal today,
especially as we face this increasing threat from China. We
just had a hearing in my subcommittee that I chair on the
threat in space and some of those challenges you face, of
course, here on Financial Services, a little bit different
model.
If I could, Ms. Manfra with Google, if I could ask this
question. One of the things that I have been concerned about--
and this goes across the gamut as far as age groups too--are
these deep fakes, this idea where AI has used--someone's
reputation can be literally eliminated in a day, because there
is some type of fake video. What does a huge company like yours
do to try to identify these to take them either offline or to
identify that these are deep fakes?
Ms. Manfra. Well, I will say just to start--first, thank
you for the question, and it is something that has been
concerning for us for a long time, and we have invested a lot
in technical measures to be able to better detect as well as
making a lot of these measures and processes that we have
learned from available to others to be able to do that and to
rapidly be able to take those down, and happy to get more
details if you are interested in more of the specifics on the
technology that we use to be able to----
Mr. Haridopolos. I think that would be very helpful
because, again, this is a reputational issue.
Ms. Manfra. Absolutely.
Mr. Haridopolos. It takes a lifetime to generate a
reputation. It can be destroyed in a minute.
Ms. Manfra. Absolutely.
Mr. Haridopolos. I think that this is especially true not
only in politics but just everyday life. We have seen how
people get hazed, bullying happens, especially at the middle
schools and high schools, and this could easily be done with
just a basic technology. So any advice y'all have would be
great.
I think the second one, I will ask with Nasdaq, if I could.
There are existing rules of the road. Are those guide rails
sufficient for what you do every day in the investment world
and are there enough recommendations that our committee is
putting out and you are, of course, producing and providing for
us--where are we? Are the guardrails sufficient now? Are there
a lot more guardrails needed, in your opinion, to make sure the
financial markets are protected from AI in a negative way?
Mr. Cohen. Our markets, as you know, are highly regulated
and have a lot of transparency to ensure that we run our
markets in a way that is enduring from a trust perspective.
``Trust'' is not a word we have spoken about a lot, but trust
is extremely important when we talk about our markets.
So the fact that we are highly regulated, run mission
critical infrastructure, requires us to have certain standards
outside of just thinking about AI. I think we can use that as
the foundation, whether it is the securities law, it is Reg
SCI, it is following this, all of that is foundational.
What I mentioned earlier, and I think is incredibly
important, as this technology advances and maybe creates gaps,
we need to make sure there is information sharing, that we have
a safe space to share information with one another about what
we are seeing, about what we are seeing within our own four
walls and across the industry. So I think that would be what I
would advocate for to make sure that we have what we need on a
principle-base and from a Federal level. Those are the two
things that I think we would also want to see.
Mr. Haridopolos. Thank you.
Ms. Whitmore, what keeps you up at night about AI? What is
the biggest concern that is out there, in your opinion? You see
this every single day. We deal with a lot of issues every
single day, but you are focused on AI. What is the fear factor
that you have, wondering, God, I hope they do not do this, or
this is the threat that is most prevalent out there, and in
both the business community and the general internet space?
Ms. Whitmore. Thank you for the question, Congressman.
First, I think, just the challenge that attackers are
leveraging AI for, which is primarily speed and scale. So now
we are looking at reduced timeframes to execute a ransomware
attack to 25 minutes, and that includes from initial access
into an environment to the time that they encrypt or steal data
in that environment.
The second is the concern that attackers are specifically
targeting AI to then misuse it intentionally, right? That
requires a use of some specific guardrails to put in place but
in particular, one, we can--to solve these two challenges,
right, we can--we need to be fighting machines with machine
speed. That is the only solution that we are going to have to
transform the way that we detect and respond, and to truly get
to decreased numbers in both of those categories.
Second is the capability to ensure that as these systems
are running within environments, that we have got the critical
levels of visibility into the actions they are taking so that
when an attacker does decide to change the functionality of an
agent and have it go rogue, that we can detect that and stop it
as quickly as possible.
Mr. Haridopolos. Well, I appreciate the thoughtful answers
to those. Mr. Chairman, I yield back.
Mr. Meuser [presiding]. The gentleman yields. The gentleman
from Illinois, Mr. Casten, is now recognized for 5 minutes.
Mr. Casten. Thanks so much. I appreciate y'all.
I want to focus specifically on securities regulation. I am
going to oversimplify, but I am going to--Mr. Cohen, I will ask
you to correct me if I have got it wrong. We have got Federal
securities regulation through the SEC. We have got an
additional State layer with registrations and licensing laws,
and then, of course, the rules that the individual stock
exchange has put in. Are you generally supportive of that
structure? Having those three layers of regulation?
Mr. Cohen. We are and do not forget Financial Industry
Regulatory Authority (FINRA).
Mr. Casten. Yes.
Mr. Cohen. So we have SEC, FINRA, and then obviously we
have our own, if you will, responsibilities as an exchange,
highly regulated exchange, listing qualifications, for
instance.
Mr. Casten. Fair point. I raise that only because I had
some concerns about in your testimony, when you supported
Federal preemption of State laws related to AI. So, I just want
to pick at this point a little bit. I am concerned partly
because the Trump White House has instituted massive cuts to
SEC. So if this is a three-or four-legged stool, it is kind of
a wobbly chair right now. I get nervous about saying let us
shorten all the legs to make it work.
I also have a concern as an engineer, as a guy who built
some AI models before I came here. I do not think this is as
big a deal as we talk about it. I think we use words--you know,
we call it intelligence, but it is just--it is a massive
correlation machine. It is not intelligent, per se, but I can
plug in huge amounts of data on the markets and historic
trading trends, and say I want this algorithm using those
historic correlations to identify relationships and optimize
for profit margin. It can do that. It is really cool, right? I
can plug in the entire Taylor Swift catalog and say put let us
take a Tom Waits song and make it sound like a Taylor Swift
song. I can do that. It is not intelligent. It is just
massively correlative.
If--there is no reason why anybody using an AI tool is
necessarily incentivized to say: Let me optimize this for
truth. Let me optimize this for ethics; let me optimize it for
legal compliance. I am going to optimize it for the thing that
is valuable to me, making something that sounds like Taylor
Swift, making--you know, making money on markets.
I guess I do not understand why--or maybe correct me if I
am misreading you. Would it not be wise to prevent States from
protecting investors from AI-enabled market manipulation,
especially if the Federal Government is not doing it?
Mr. Cohen. Let me answer the first part of your question.
As an exchange, we are an SRO, self-regulatory organization,
and we have a public mandate. Our public mandate is to ensure
that we run fair and orderly markets, and we take that
responsibility very seriously. So our north star is just that.
When we design solutions around our markets, we are thinking
about making sure that----
Mr. Casten. I want to--and I do not mean to cut you off. I
am just nervous about the clock here. I was in the energy
industry for a long time. I remember there was a professor who
did this experiment with a bunch of grad students where none of
them had information, but they were basically in a simulation
of California power markets, and they all independently, just
based on the other students' trading strategy, figured out how
to collude. It was when Enron blew up, it was this thing of,
okay, you do not actually have to have information to collude,
but there is an incentive to collude in the structure, and
people will figure it out.
There was a University of Pennsylvania study recently that
found that AI bots released into simulated markets will do--
essentially do the exact same thing.
As an SRO, how do you--if we are not going to regulate--if
we are going to provide liability shields for these companies--
not about whether the tool is good, but if we are not going to
provide liability shields, do we not still have to get to that?
Maybe, just to sort of put the punch line on it, and then
you can use the rest of the time, there is a long legal history
within the courts, within the SEC, of saying if there is not
intent to defraud, you cannot hold somebody to account. My
nervousness is that a lot of the people building these tools
are saying, ``Well, I want a liability shield. I want State
preemption.'' If the tool is not designed not to commit fraud,
it can still be optimized and end up committing fraud. So as a
market manager, how do you protect against that and what sorts
of regulatory reforms would we need to do to it, modify some of
these--this history that you need to show intent?
Mr. Cohen. Yes. Just to be clear, in terms of Federal
preemption, our view is around minimizing complexity. What you
just described, you can achieve all of that at the Federal
level. You do not have to have it as a patchwork in each State
where it is a struggle for people to figure out how to operate
in that State. It is not just the exchanges; it is our members
that we think about and the industry at large.
Again, being highly regulated, we do have a north star
about how we want to serve and what our business interests are.
So it is more about the complexity, and it is more about the
patchwork that we are concerned about. We think we can solve
for everything you just talked about at the Federal level----
Mr. Casten. I am out of time, but I would just welcome
comments from all the respondents about--there is a hole in
securities laws, and any ways that we can fix those holes to
address this question of intent I think is important and would
welcome all of your expertise. Yield back.
Mr. Meuser. The gentleman's time has expired. The gentleman
yields back. The gentlemen from Wisconsin, Mr. Fitzgerald, is
now recognized for 5 minutes.
Mr. Fitzgerald. Thank you, Chair.
Regulatory technology, sometimes called ``reg tech,''
refers to innovation in technology deployed by companies to
manage regulatory compliance. Mr. Cohen, how does Nasdaq use AI
and other--any type of machine learning powered by reg tech
tools to kind of enhance the regulatory compliance, such as
trade surveillance or how much just efficiency in cost savings
has gone on?
Mr. Cohen. So we have two reg tech solutions that we offer;
one is for market abuse surveillance, and the other is actually
Axiom, which is a regulatory compliance and reporting
application. I have not talked as much about that today, but
that is important because it is used by all the Tier 1 banks
across the globe. It is the standard for regulatory reporting.
What we do, because we manage and orchestrate complex
workflows through this tool, is we use AI for data discovery so
they can go through complex regulations and understand and
interpret how that piece of regulation needs to be implemented
into the reporting obligations they have. Also, if they have
any anomalies in their financial reporting, capital
obligations, liquidity obligations, it may take them, a handful
of individuals, hours, days, weeks, to identify anomalies. We
can do that through AI very, very quickly, keep the human in
the loop, make sure that they are center, in the center of any
decisionmaking that can occur, but they do not have to do the
heavy lifting to understand that there is an anomaly.
Also what we have done from a product development life
cycle perspective, we are now taking regulations, reg all the
way to code, through agents and allowing agents to hand off
work to one another to take a piece of regulation that could be
4-to 500 pages long, and allow them to implement it in our tool
and then deliver it more quickly to our clients. This is
incredibly important in a world where the regulation is
exponential in terms of the obligations that one needs to meet.
They are changing. There are reforms. There is a different view
in America versus where Europe and Asia are going.
So just as a Tier 1 bank or Tier 1 institution to keep up
with it, it requires a lot of operational spend. We are trying
to reduce your operational spend so you can do the things that
you need to do, put money back into your balance sheet that you
can then use for loans or for businesses that help small
businesses and their customers.
Mr. Fitzgerald. Very good.
Mr. Stevens, let me ask you the question first, and I was--
just maybe fill in afterwards. I am kind of switching it on the
paper here. How are AI-driven underwriting models helping to
safely expand access to credit for a broader range of
borrowers? Because there are concerns, I know, that AI has led,
maybe, to some riskier borrowers--I do not know how else to
describe it--or that it has kind of changed, kind of the
perspective on borrowers compared to the due diligence that--
you know, the human that sits down and fills out the form and
does everything that we are typically used to. So I was
wondering if you could comment on that idea?
Mr. Stevens. Yes. Thank you, Congressman, for the question.
The way AI is helping is by looking at additional data
sources that, if we just left it up to humans, they might not
have time to consider and that, I think, is helping
particularly first-time buyers qualify.
At Zillow, we make sure the actual decisionmaking in the
underwriting process, what we are prequalifying you for, for
example, is completely human-driven. So we still rely on humans
making that ultimate judgment.
Mr. Fitzgerald. Very good.
Ms. Manfra, the 1945 McCarran-Ferguson Act left insurance
regulation largely to the States. With all the talk of freeing
financial services from the onerous State regulation of AI,
notwithstanding the Act, can the business of insurance benefit
from being included in any national approach to AI?
Ms. Manfra. I cannot speak to the specific regulatory
framework of the insurance. It is just not an area of my
expertise but absolutely there are lots of benefits for AI in
the insurance industry, and I think would benefit from being a
part of a national conversation and framework for standards of
transparency and explainability.
Mr. Fitzgerald. Has it advanced quick enough or far enough
to really be a tool, or is it something that is just kind of a
sideshow right now?
Ms. Manfra. For insurance companies?
Mr. Fitzgerald. Yes, for insurance companies.
Ms. Manfra. I would say insurance companies are using AI
tools--it is very different in terms of the customers and--but
absolutely, they are using AI and innovating around that for
sure.
Mr. Fitzgerald. Very good. Thank you all. I yield back.
Mr. Meuser. The gentleman yields back.
The gentlewoman from Massachusetts, Ms. Pressley, is
recognized for 5 minutes.
Ms. Pressley. Thank you to our witnesses for joining us
today.
AI is everywhere: our phones, our classrooms, our
hospitals, our bank loans and job applications, every facet of
our lives. That is why we must ensure that AI works for
everyone, and that instead of deploying biased AI, which can
create harm or compound existing harm, it needs to benefit
everyone, all people, regardless of race, gender, income level,
medical conditions, or other parts of our identity.
Mr. Stevens, should we prohibit the use of AI that
discriminates on the basis of race, gender, or other factors?
Just a yes or no.
Mr. Stevens. Especially in housing, I believe yes. Fair
housing, make sure that we eliminate all forms of racism,
different disparate impact, that kind of thing.
Ms. Pressley. Okay. I will ask the question of everyone,
just for the purposes of the record. So just a yes or no.
Should we prohibit the use of AI that discriminates on the
basis of race, gender, or other factors? Yes or no? Ms. Manfra.
Ms. Manfra. Yes.
Ms. Pressley. Mr. Cohen?
Mr. Cohen. Again, we apply three principles. We try to
promote transparency, liquidity----
Ms. Pressley. Yes or no.
Mr. Cohen [continuing]. integrity in our markets and as a
highly regulated institution, we are making sure that we
prevent that in our algorithms.
Ms. Pressley. Mr. Stevens, yes or no, again.
Mr. Stevens. Yes.
Ms. Pressley. Ms. Whitmore?
Ms. Whitmore. Yes.
Ms. Pressley. Mr. Branch.
Mr. Branch. Yes.
Ms. Pressley. Okay. Thank you.
We need, urgently, civil rights laws for the 21st century
in the age of AI, which is why I have joined with Senator
Markey and also with Congresswoman Yvette Clarke to introduce
the AI Civil Rights Act. It is urgent because the truth is that
we are already behind. People are already being exploited and
discriminated against with the use of algorithms.
Now, let us take an issue like housing, for example, which,
in my opinion, is a human right. Everyone deserves more than
just shelter. They deserve to have a home. It is safety, it is
dignity, it is health, it is mobility. In 2025, the Trump
Administration has gutted the key agencies that protect against
housing discrimination: the Consumer Financial Protection
Bureau (CFPB) and Housing and Urban Development (HUD) Fair
Housing Enforcement Offices. They are even trying to undo
consent orders that are already in place, like the Townstone
discrimination case in Chicago. This gap in civil rights
protections is an opening for continued discrimination. One
study found that mortgage lenders are 80 percent more likely to
reject Black applicants compared to White applicants with the
same qualifications.
Mr. Branch, should we have additional oversight tools, such
as assessments, to test the algorithms out before companies can
use AI on the public? Yes or no?
Mr. Branch. Yes.
Ms. Pressley. Do any of our witnesses, other than Mr.
Branch, disagree with that? Okay. Let the record reflect that
no one disagreed.
We know that bias exists in our Nation. We see the
inequities all around us. I represent the Massachusetts 7th, a
vibrant, diverse, dynamic district, and one of the most unequal
in the country. We are in a 3-mile radius from Cambridge, home
to MIT, Harvard, and AI advancement, to Roxbury, the blackest
part of my district. Life expectancy drops by 30 years and
median household income by $50,000. Now, that is the result of
intentional lawmaking, which is why I believe we have to be
just as intentional in undoing the harms and charting an
equitable path forward, because AI is trained on data that is
already biased and by humans that have biases. It can replicate
and exacerbate these harms unless we have oversight and prevent
it. We must not allow AI innovation without AI protections. In
a world of artificial intelligence, we really cannot lose sight
of what is real, and that is the people, the people and their
livelihoods and their lives. If Republicans are serious about
protecting our elders from fraud, and consumers from
discrimination, then Congress must pass the AI Civil Rights
Act.
Thank you. I yield back.
Mr. Meuser. The gentlelady yields. The gentleman from
Indiana, Mr. Stutzman, is now recognized for 5 minutes.
Mr. Stutzman. Thank you, Mr. Chairman. Appreciate you all
being here today.
Before I begin, though, I would like to address some
concerns raised by my colleagues across the aisle. The
Unleashing AI Innovation in Financial Services Act enables
federally regulated entities to experiment with AI in secure
environments, overseen, approved, and subject to the conditions
of their Federal regulators, including for compliance and risk
management. Importantly, the sandboxes must not present
systemic or national security risk; two, unsafe and unsound
practices and fraud remain prohibited; three, the sandboxes
under unleashing AI would be targeted, time limited, and
subject to regulatory approval and oversight; finally, the
participants' compliance strategies must be approved by the
appropriate regulator, and who would retain enforcement
authority subject to the terms the regulator sets.
So it has been great to have President Trump back in the
White House for many reasons, but especially for the reason we
are discussing here today. During the Biden Administration, AI
innovation was viewed primarily as a threat to the American
people. While President Trump has set the country back on track
toward innovation and American AI dominance on the world stage,
we cannot have Biden's allies in anti-innovation States, like
California and Massachusetts, setting the trend on
overregulating AI.
I will follow Ms. Pressley's format, and I will begin with
each of you. Do you think that a patchwork quilt, or a
patchwork of inconsistent AI laws would help encourage
innovation or stifle it? Yes or no? Stifle or unstifle?
Ms. Manfra. It would stifle innovation and add complexity
and burden to----
Mr. Stutzman. All right. Mr. Cohen.
Mr. Cohen. Add complexity and stifle.
Mr. Stevens. Add complexity and stifle.
Ms. Whitmore. I think too much complexity largely benefits
attackers and not the defenders of our environments who are
also looking to innovate.
Mr. Stutzman. Mr. Branch.
Mr. Branch. I do not believe that this stifles innovation.
There is a lot of talk about different States that have
different models. However, oftentimes, these State laws
overlap, and so, it is not a fragmented 50-State analysis that
needs to be done. In fact, oftentimes, many of these States
overlap. So, they are not competing with a variety of State
laws. The language in the laws overlap, and we see that in
company valuation. If this innovation is being stifled, then
these companies would not be worth trillions of dollars, and
America would not be leading in the AI race, which we have been
since the inception of this AI race.
Mr. Stutzman. But you do not think that having Federal
guidelines and then having States having their guidelines, that
is going to create complexity and actually people just finally
say, ``We are out?''
Mr. Branch. Well, respectfully, Congressman, the States
have had to step up because we do not have Federal guidelines.
They are actually begging for the U.S. Federal Government to
pass some form of regulation, but they have not passed that
regulation. That is what the American people are waiting for
Congress to do.
Mr. Stutzman. All right. Ms. Manfra, is it not true that
many of our existing risk management frameworks and governance
practices already apply to AI?
Ms. Manfra. Yes.
Mr. Stutzman. So following up a little bit, can we update
our guidance to be fit for AI without reinventing the wheel
here?
Ms. Manfra. Absolutely. As has been noted, the existing
laws do apply. However, there are areas, such as ensuring
transparency and explainability, as we have discussed,
maintaining human in the loop, some of these other areas where
it is important to clarify in existing rules. But we do not
need new----
Mr. Stutzman. All right. I want to talk a little bit about
the risks a bit. We have had algorithmic trading in this
country for decades, and these models are increasingly
incorporating AI. One concern I have heard is that AI and
machine learning could exacerbate herding. This is where
trading models end up encouraging the same activity across
firms because firms are using the same or similar models.
Mr. Cohen, what do you make of the risk posed by model
similarity?
Mr. Cohen. That risk existed before AI. So you might have
individuals that work for one firm go to another firm and
design models that are very similar to one another, and
therefore, exacerbate volatility or have the herd effect.
Post some market events over the last 10 to 12 years, we,
the SEC, and the industry have taken action to ensure that we
have volatility guards. We put in Reg SCI. We put in a number
of different rules to protect the marketplace but maybe most
importantly, we have asked those that are introducing
algorithms to test them and then monitor them throughout their
lifecycle because it may be that a trading strategy is in the
market for 3, 4 years, but a change in market condition then
snaps the algorithm.
So we are--we are really focused not just on the testing of
it when it comes into the market but also on the monitoring and
the transparency we have once it is in the market. FINRA has a
responsibility to go into all of these broker dealers and make
sure they have written procedures that they test it, they
monitor it, and they are taking care of it in a judicious
manner.
Mr. Stutzman. Do you know, is that happening frequently, or
is it just on occasion that you are seeing a herding strategy?
Is it daily? Is it weekly? Monthly? I mean, does it happen--how
often?
Mr. Cohen. I would not know the exact details around that.
We can come back to you on that question.
Mr. Stutzman. All right. Thank you. Thank you, Mr.
Chairman. I see my time has expired. I will yield back.
Mr. Meuser. The gentleman yields. The gentlewoman from
Texas, Ms. Garcia, is now recognized for 5 minutes.
Ms. Garcia. Thank you, Mr. Chair, and thank you to all our
witnesses here today.
AI will impact every industry, every line of work, and
every type of business in the near future. I think we can all
agree to that. AI has potential to save employers on labor
costs and increase productivity, but it can also disrupt
workplaces and lead to loss of millions of jobs. At home, in my
district as a working class district, 77 percent Latino, many
of my constituents are concerned--in fact, deeply concerned--
about how AI will impact their jobs and their livelihood.
Mr. Branch, could you quickly discuss what the private
sector, Congress, and the public sector can do to best address
workforce challenges as AI becomes more widely adapted?
Mr. Branch. Thank you, Congresswoman.
They can speak with these workers and allow for worker
input. They can speak with unions. Many unions are discussing
algorithmic pricing. They are discussing wages and the
necessity to ensure that there are fair wages as well. So I
would encourage them to collaborate with unions and their
employees.
Ms. Garcia. Thank you.
You also mentioned in your testimony how important it is to
include the States when crafting AI policy. I mean, I think you
just said that you need the national framework and then the
States will act, and States actually have acted because the
Federal legislation has not acted.
In 2025, 38 States have adopted or enacted around 100
measures. More than that, Colorado and Texas both enabled
omnibus legislation regulating AI. In fact, our Governor just
signed a bill to that effect, and will go into effect in
January, and it is a new regulatory framework that applies to
developers and deployers of AI systems.
Many of the witnesses today spoke about the importance of
cooperation between the Federal and State policymakers. Despite
this, President Trump shared his intent to enact some type of
AI moratorium through an executive order via social media just
yesterday.
As someone responsible for Nasdaq's financial technology
division, Mr. Cohen, would it be practical--what would be the
practical impact of such a moratorium on consumers and
investors?
Mr. Cohen. At Nasdaq, we do not serve retail investors
directly. Institutions are our customers. From our perspective,
again, we want to make sure that there is a balance between the
types of rules and regulation that come in, more principle-
based, allow us to advance the technology and innovate while
making sure it is safe and responsible. We think from the
perspective of the governance we have internally, the
foundation of the rules that we have in the marketplace today,
following this gives us that great foundation that we can build
off of.
Ms. Garcia. But what would a moratorium do?
Mr. Cohen. With respect to----
Ms. Garcia. The impact on Nasdaq and the work that it does.
Mr. Cohen. I think we have been operating in a space with
uncertainty already. So I do not think that it would have a
significant impact on us if there was a moratorium.
Ms. Garcia. The Trump Administration's AI Action Plan and
recent actions pursue an aggressive deregulatory approach to
AI, dismissing the role of both Republican and Democratic
States. Rather than leveraging existing regulations and
enacting new risk based and proportional regulation, President
Trump and congressional Republicans have tried and failed twice
to pass broad Federal preemption.
Mr. Branch, can you shed some light on how State AI laws
have helped to fill the current Federal enforcement gap in
areas like algorithmic discrimination and consumer protection?
Mr. Branch. Yes. Thank you for the question.
States have stepped up to the bat in response to Congress
not passing Federal legislation, and they have listened
directly to their constituents. They have passed laws in terms
of deep fake nonconsensual images. They have passed laws with
regard to pricing as well as discrimination and this would
essentially be usurping the States' abilities to protect their
own consumers. This is something historically in the United
States has been a right reserved to the States. There has never
been a previous administration that has directly assaulted the
States' abilities to protect their own consumers. So this is a
very unique situation.
Ms. Garcia. Thank you.
Ms. Whitmore, I know I served on the AI task force working
group that was put together from this committee and it always
struck me, the final question really becomes who is auditing
and who is monitoring and making sure that the AI--who is
monitoring AI, and who is going to make sure that everything
they are doing is safe, secure, and something that will not
negatively impact everyday Americans?
Ms. Whitmore. I think you are articulating the criticality
of security being closely coupled with AI innovation so that we
can answer those questions very clearly and ensure that the
communications that are occurring are legitimate.
Mr. Meuser. Thank you. The gentlelady's time has expired.
Ms. Garcia. Thank you.
Mr. Meuser. The gentleman from Texas, Mr. Williams, the
chair of the House Small Business Committee, is now recognized
for 5 minutes.
Mr. Williams of Texas. Thank you, Mr. Chairman. Thank all
of you for being here today.
Artificial intelligence and the banking sector are two
industries that are working together hand in hand. For
financial institutions, artificial intelligence is a valuable
tool that allows them to navigate risk assessments and stress
test, detect and prevent fraud, assist with regulatory
compliance, and several other critical operational duties.
My district back home in Texas, Fort Worth and around in
the metroplex and out West, loves their community banks, who
are the backbones of their communities. As artificial
intelligence continues to change the landscape of banking, it
is crucial that we ensure that AI is empowering rather than
complicating the work of community banks. So, Ms. Manfra, what
would we be thinking about to ensure that this technology can
reach community bankers and allow the importance they offer to
grow and flourish and help people like myself in Main Street
America?
Ms. Manfra. Thank you for the question, sir.
I think one of the opportunities, one of the greatest
opportunities with AI and cloud and associated technologies is
the ability to bring access to data and capabilities that
historically was only reserved for people with deeper
pocketbooks, as it were. So being able to empower community
banks and other smaller organizations that are more resource-
constrained, AI can give them access to that data in more real
time. It also allows them to benefit from those efficiencies
with the limited staff to be able to provide better services to
their customers and maintain that trust that you noted in
communities.
I think what is important is ensuring that we do not create
regulatory burdens that unfairly impact organizations that have
less resources to manage those, would be my final point there.
Mr. Williams of Texas. Thank you.
AI tools are reshaping how businesses grow and enter
capital markets. I see that in my business. I am in the car
business and tools that help companies analyze market trends
and reach investors prepare for fundraising used to be
available only to the largest firms with unlimited resources.
Now artificial intelligence has the potential to level the
playing field by giving smaller and emerging companies better
insight, data, and more efficient ways to market themselves to
investors.
Mr. Cohen, how is AI changing the ways smaller companies
prepare for and access public markets?
Mr. Cohen. You touched on a really important point, which
is if we get AI right, it will democratize the way that small
businesses can access and have access to the same tools as
large businesses. They do not have the engineering talent,
maybe the R&D budget, and maybe the sophistication of the
larger firms. So it is up to companies like us to provide
capabilities, make them available to those companies, whether
it is in the capital raising side of the house or in a
secondary trading side of the house, to ensure that when we put
these capabilities out there, it is for all investors. It is
for all of the individual and corporations that we serve and
that allows them, if you will, to level the playing field and
then grow their businesses.
Mr. Williams of Texas. Great.
Ms. Manfra, in your testimony, you highlighted Google's use
of artificial intelligence to combat money laundering, fraud,
and scams. Across the world, organized fraud syndicates are
stealing billions of dollars a year from hardworking Americans.
One of the biggest challenges is the speed at which these
schemes operate. It takes only seconds to steal personal
information, drain bank accounts, or even compromise identity
verification systems.
So we must give law enforcement the tools to keep up with
the pace of these scams and improve the flow of information
between victim to agency and across the agency. So my question
here in the remaining time is could you explain how Google is
using artificial intelligence to improve information sharing in
the case of fraud and scams? Specifically, how does this real-
time data sharing of the banks and credit card companies stop
funds from flowing to these overseas scam rings faster?
Ms. Manfra. There are two aspects to it. The work that we
do internally across all of our various different platforms to
stopping phishing scams, fraudulent websites, fraudulent ads,
fraudulent reviews, building an ecosystem around Android that I
talked about in my testimony. So we have invested a lot in the
use of AI and ML to be able to prevent those for those who use
Google platforms.
We have also taken those capabilities and working with
partners, in particular, in financial services, to be able to
do things like using AI for preventing money laundering, and we
are seeing huge benefits in that. Fraud detection has been a
use case for machine learning for a very long time and
continues to grow. So reducing those false positive rates so
that investigators are able to spend their time on useful and
productive leads.
Also just being able to--we have one customer, a banking
customer, who experienced a fourfold increase in the detection
of suspicious activity; at the same time, reducing by 60
percent the volume of false positives. So they are identifying
more and having more productive investigations as a result.
Mr. Williams of Texas. Thank you very much. I yield my time
back.
Mr. Meuser. The gentleman yields.
The gentlewoman from Michigan, Ms. Tlaib, is now recognized
for 5 minutes.
Ms. Tlaib. Thank you, Mr. Chair.
You know, one of the things that I continue to hear
obviously is all the great things about some of the technology,
including AI, but I think we are not realizing the way the
corporate America is and is set up is very profit-driven, and
the abuse is going to be very clear that everything is going to
be around profit first.
No matter how much people are like, It is going to make
this easy or that easy, just New York Times publishing article
after article about some of the abuses we already see. I am
really concerned, of course, on the cost of prices, and the
fact that private information is being used to price groceries.
Groceries. I am going to walk into a place, and they are going
to gather my private information and use that to price it
differently than the person that comes right after me. It is
discriminatory. It is private data and information. It does not
belong in grocery stores.
I know, Mr. Branch, you know about Stop Price Gouging in
Groceries Act that I introduced. I would like for you to talk
about surveillance pricing. I was with seniors and I was trying
to explain to them how surveillance pricing is going to be used
in a way not to reduce costs, but actually to be able to price
higher on costs because they know where they work, they know
what income they have, what they were searching online. So, for
folks that are out there right now, can you talk about what
that means right now? The use surveillance pricing by some of
the big grocers?
Mr. Branch. Yes. Thank you for the question, Congresswoman.
In this new age of AI, the power is data driven. The
largest companies on earth own all of that data and from a
consumer perspective, there is a mismatch there because
consumers only see the price that is in front of them, but the
large companies have all the information from the consumer.
So Consumer Report actually just came out with a report
just the other day that showed that grocery prices based on
algorithmic pricing can increase individual consumers' grocery
bills by $1,200 over the course of a year. We are going to find
ourselves in a situation where Americans are struggling and
struggling to make ends meet, and these companies are arguing
that it is just about everything else when, in reality, it is
the algorithms that are setting the prices and manipulating
them and taking advantage of the data that they have that the
consumers are not privy to.
Ms. Tlaib. That is in combined to the digital pricing. You
know, explain to folks--so, bye-bye, tags that they have. It is
going to be digital. Explain how that is connected.
Mr. Branch. Right. So digital pricing can involve the price
of certain goods, and those goods can differentiate between
different groups of people, oftentimes based off of shopping
behavior. So if you happen to like Wheat Thins, for example,
Wheat Thins are going to be more expensive for you by maybe a
quarter, maybe a nickel, whatever it is. But that little
incremental amount----
Ms. Tlaib. Yes.
Mr. Branch [continuing]. ends up adding up over the course
of the year and over the course of your grocery bill itself.
Ms. Tlaib. Mr. Chair, I ask unanimous consent to enter into
the record an article, ``Goodbye, Price Tags, Hello, Dynamic
Pricing. Shopping has always been a game, and now it is being
rigged against you.''
Mr. Meuser. So ordered.
[The information referred to was not submitted prior to
printing.]
Ms. Tlaib. I want to now talk about the discriminatory
factors that are going to be at play, because I see this in the
auto insurance industry that they already use and collect
data--non-driving factors, like your marital status, your
education level, your credit score--used toward auto rates
right now without the kind of technology, and adding that and
compiling that on to decide how much to pay--charge somebody
for auto insurance in Michigan. It is mind-boggling that your
son's GPA or your child's GPA has anything to do with driving,
but they are asking for that data as well.
What happens when AI models now--again, using this
technology--are trained on historic or contemporary data that
reflects past or present discrimination? Does not this risk
create models that perpetuate or reinforce discriminatory
practices? Because it is teaching it to go around, telling on
themselves.
Mr. Branch. That is correct, Congresswoman. I mean, the
thing that a lot of folks do not necessarily understand about
AI is that its goal is to move toward its goal as efficiently
as possible. So, that can be replicating discrimination. That
can be just trying to get the best price possible for the
corporation or for the business at hand. Again, I think that
leads back to the fact that a lot of these companies have the
data and the power----
Ms. Tlaib. Mr. Branch, I need my colleagues to know this.
They are not going in there and saying, how can we make this
cheaper for the consumer? They are saying how we can make it
cheaper internally so we can--but they are going to charge our
residents more, using this technology. We need to face the fact
that is exactly what is going to happen. This thing of
pretending it is going to make things easier--no, it is not. It
is going to charge people more because they are going to know
all this private information, know that they need these
products and charge them more. Even if it is 10 cents, that is
10 cents too much for our residents. Thank you.
Mr. Meuser. The gentlelady's time has expired. I now
recognize myself for 5 minutes.
Thank you all very, very much, by the way, for being here.
It is a terrific panel and highly informative.
I think you are aware that many of us, the leadership of
this committee, as well as the Trump Administration, is
committed to unleashing AI's full potential, so we, indeed, in
the United States, wins the AI race with investment and energy
dominance to support the AI infrastructure. My home State of
Pennsylvania is doing everything we can to draw in as much AI
infrastructure as possible.
However, it brings risks that we are talking about and
exposing here, which are happening now and we want to mitigate
for the future. They definitely include fraud, scams,
profiling, and seem to be growing more sophisticated.
AI is proving to be an incredibly strong tool for detecting
and shutting down these very threats, but as well, creating
them.
Ms. Manfra, I would like to first start with you. First
off, thank you to Google for the good work that--you folks seem
to be in the lead of mitigating and finding out scams and
addressing them in the--in the manner that they should be,
because it is a really serious problem facing all walks of life
and our constituents and consumers throughout the United
States, on the international level and on the local level. I
know I do not have to tell you that.
You recently highlighted the use of AI to uncover a
Chinese-linked operation known as Lighthouse which reportedly
targeted Americans with E-ZPass, postal service, fraudulent
messages, demanding payments to settle fines, and very other
common scams that my constituents often encounter. Can you
describe how Google--what you did to identify this Lighthouse
operation and what role AI detection played in surfacing those
scam campaigns?
Ms. Manfra. Sure. First, let me say that we would be happy
if you are interested in further deep dive to follow up. But
generally what we do is we have threat intelligence,
individuals, and detection capabilities that use advanced
technologies, including AI, that are increasingly more finely
tuned and able to spot both scale, but also be able to identify
networks of organizations that are using our infrastructure and
our services. So it is a combination of all of these things
coming together to identify this. Then you know, of course, the
partnership with law enforcement to ultimately bring this down.
Mr. Meuser. Well, that is great. Congratulations.
How do you envision and even how is AI playing a role in
financial fraud and scam prevention?
Ms. Manfra. I think AI and ML is--because of--it is a
scale, and it has been quite helpful for many years now, and
the newer technologies in AI even more so, again, in being able
to detect various different networks in addition to being able
to be very good at filtering out the signal from the noise, if
you will, which is a huge challenge for fraud detection, and
also getting very good at being able to reduce the noise around
false positives, which organizations spend a lot of time--when
they get an alert, they have to go chase that down, go
investigate that.
So as our AI and ML capabilities are getting better, they
are becoming more targeted. They are reducing that noise that
financial organizations have to deal with, and they are better
able to deploy their investigators and their teams----
Mr. Meuser. Be great if that formula could be socialized
elsewhere and not be a competitive model within fraud. That
would be great for that to serve and help others. But I need to
move on. Thank you very much.
Mr. Cohen, Nasdaq has been at the forefront of deploying AI
to markets. Last year Nasdaq introduced Dynamic M-ELO, which
stands for, as you well know, Dynamic Midpoint Extended Life
Order, designed to ensure the best trade execution for the
investor. Can you briefly walk us through it?
Mr. Cohen. Yes. So Dynamic M-ELO employs a delay that--it
is almost like a timer that we put on the order so that
institutions who are trading large blocks of shares can avoid
price impact when they try to execute those shares. So we take
in 130 data points to help that institution to identify the
ideal time to trade. As a result of that, after they trade,
there is no price movement. The result of that is the
individual investors that sit behind those large institutions
get a better price, get better price execution, and benefit
from that order type. We have grown that order type by 50
percent because of the success we have had.
Mr. Meuser. Well, it sounds terrific. Thank you. My time is
expired. I yield back.
Now I want to recognize the gentleman from California, Mr.
Liccardo, for 5 minutes.
Mr. Liccardo. Thank you very much, Mr. Chair. Appreciate
the testimony and thank all the witnesses for taking time.
Ms. Manfra, it is good to have somebody from a local
neighborhood business, from District 16 here. I should tell Mr.
Stevens my wife is probably one of the people who crashed the
system when Zestimate came out. She is a big Zillow addict. Ms.
Whitmore, I know you employ many of our residents, even though
you are just next door. So we appreciate having you all here.
I am brand new here to Congress, but I observed in my 45 or
so weeks here that there is essentially a paralysis in Congress
about AI. It seems to be borne of a few basic challenges. One
is that we generally do not regulate tech very timely or
effectively anyway. We have been waiting about 30 years for any
kind of regulation or statute governing digital privacy. Folks
have been waiting for us to update Section 230 to make social
media platforms safer, and we have waited about a quarter
century for that.
So that is a basic challenge when we approach AI, to be
sure. I think there are a lot of doubts about whether or not
Congress is really terribly effective or competent at this. I
think many of us are still trying to learn to spell AI. We are
still--I think we recognize this technology has moved very
quickly; we cannot possibly legislate at the pace of the
technology that is changing.
In the absence of this congressional action, we now see 50
States rushing in. I think this year alone, we have had 36
States that have approved more than 100 pieces of legislation
governing AI. I appreciate that is mightily difficult for an
industry to navigate. Now, the counter or the reaction is we
need a moratorium on everything States are doing and that is an
understandable reaction. I do not support a moratorium without
some kind of sensible Federal regulation to actually supplant
it, but I certainly understand or appreciate why industry would
need and want it, given the fact that we are an international
arena, and certainly China does not have 50 States trying to
regulate the industry as we do.
I think--look. As was pointed out, 97 percent of Americans
do support some regulation in AI, and that is for good reason.
I would like to see how we can move beyond this binary debate
that has us stuck between moratorium or no moratorium. I think
it is preventing sensible legislation and sensible regulation
from moving forward. I wanted to sort of imagine that we took a
different approach. I would be interested in any feedback you
might offer. The approach we would take would focus on
outcomes. I do not think anybody here--I certainly do not know
how exactly to regulate algorithms or model weights, and I
think outcomes are something we can measure. The good news is
we have laws that regulate outcomes. Whether it is
discrimination or fraud or anything else, we should be able to
do that.
We should be relatively tech neutral when we talk about
financial service providers who use AI, just like any other
tool. They should be held to the same standards under, for
example, Fair Housing Act or anything else that governs whether
to use AI or not.
Certainly, large language models (LLMs), we know--since we
have one representative from that community--you know, we
recognize there are real challenges here in trying to simply
get involved in the machines. I do not think most LLM
developers are particularly good or will admit--I think they
admit that they are not terribly good at explainability of the
models. We would not have hallucination if we thought we could
transparently eliminate it.
So, perhaps a better approach might be to take away from
Congress and have an independent commission of some kind,
industry experts, academics, and others who can set,
essentially, industry best practices, establish what is the
technology, whether it is around security, privacy, a host of
other measures, fraud detection, whatever it might be, here is
the industry best practices, and if the model meets it, great.
You have preemption. You also have a standard of care that you
have met and if you do not, then good luck navigating the
thicket of 50 different rules.
I guess I will ask--I will start with Ms. Manfra. Do you
have any sense about is that something that is viable, in terms
of how we can move forward with sensible regulation?
Ms. Manfra. Yes, sir. Absolutely. Thank you for the
question. I think this is already happening. Industry is
working together through formal and informal channels at
Google, with partners across industry. We have created the
Coalition for Secure AI. So committing to research--and this is
with Microsoft, with Amazon, with other partners across
industry--to drive best practices aligned with what we have
learned internally in the development of large language models
and others, we have deployed tool kits for our partners and
guidance based, again, on what we have learned. I do agree with
you is focusing on outcomes is, I think, the priority and----
Mr. Meuser. Time has expired. That is an important answer.
But----
Ms. Manfra. Sorry.
Mr. Meuser [continuing]. thank you very much. Gentleman
yields back.
Mr. Liccardo. I yield.
Mr. Meuser. The gentleman from Georgia, Mr. Loudermilk, is
now recognized for 5 minutes.
Mr. Loudermilk. Thank you, Mr. Chairman. I thank everybody
for being here.
This is an extremely important discussion we need to be
having, and I think it is timely as well.
I spent 30 years in the information technology industry, 20
years in public service in the State legislature and here in
Congress. When I was first elected to State legislature in
2005, I was probably one of the few technologists in the State
legislature at the time, so I took the lead on a lot of policy
initiatives. One thing that I brought up at the time--if you
look at the device here, everybody has got one of these, right?
The least used part of this, ironically, is what we call it.
The phone, right? That is the legacy part of this. I literally
talk to people in younger generations than mine that have
literally never used the telephone feature of this device. Part
of the reason is, it was not the phone that led to the massive
technological development that we have seen today. It was the
internet and it was broadband. Ironically, those were the least
regulated aspects of technology.
If you go back and you look at the massive growth in
technological advancements; it was not over the wired network.
It was over broadband, the cable television network, which was
not heavily regulated as the big cell--or the big carriers
were.
So with that in mind, what we have seen from history is
government can seriously stifle innovation if it is overly
regulated. So, it is kind of a balance that we strike because
we do have a need to put guardrails up but to leave this
sandbox available for innovation. I think that is where we need
to be looking, especially when it comes to tools like AI. There
are benefits to that, and there is also reason to be fearful of
the misuse of AI.
Ms. Manfra, modernization of the Bank Secrecy Act is an
area of great interest to me. I have put a lot of effort into
that over the past several years, and especially the
significant obligations that the Bank Secrecy Act imposes on
financial institutions to monitor and report potential illicit
finance activity. It is especially impactful on smaller
financial institutions.
Keeping in mind, we have not modernized this thing since
the early 1970s when the thresholds of $10,000 were put in
place which, if it had been adjusted, would be $80,000 today.
How do platforms like Google Cloud help financial institutions
automate processes for generating currency transaction reports
(CTRs) and suspicious activity reports?
Ms. Manfra. We have a couple of different offerings.
Particularly around anti-money laundering tools that we have
co-developed with our partners to ensure that they are able--
and again, this goes back to the questions around transparency
and explainability of the model to ensure that it is getting to
the right decisions. But as I mentioned, our customers are
seeing huge improvement in detection as well as a reduction in
the false positives as well, which has been hugely impactful to
actually finding the true risks, the true illicit finance, and
being able to more effectively deploy their investigative
resources and more successfully report on suspicious activity.
Mr. Loudermilk. I think it is really important with
suspicious activity reports (SARs) especially because what I
hear from a lot of financial institutions is we just do not
want to get dinged by the Federal Government, right? So they
may report a SAR that the local bank president may know is not
suspicious for that particular customer, but the same action
may be suspicious for someone else, but to save the integrity
of the bank from any action by regulators, they will report it
anyhow.
Can you talk about how Google Cloud's Anti-Money Laundering
(AML) AI system uses explainable risk scores and ensures they
are auditable for regulators?
Ms. Manfra. Thank you for the question.
We have invested a lot in explainable AI and so in the end,
getting to a point where the customer or auditor or regulator
is able to go back and look at how was a decision arrived at so
that you can redress of a decision or auditability for the
purposes of compliance.
We do offer that and work very closely with our customers,
especially in financial services, in particular for AML, but it
is used in other areas as well.
Mr. Loudermilk. All right. Thank you.
I yield back.
Mr. Meuser. The gentleman yields.
The gentleman from New York, Mr. Torres, is now recognized
for 5 minutes.
Mr. Torres. Thank you, Mr. Chair.
One of the greatest challenges confronting America is the
utility affordability crisis. The proliferation of data centers
is one of the drivers--not the only one, but one of the
drivers--of rapidly rising electricity costs.
In America, utility rates and returns depend not on
efficiency or affordability, not on performance, but on capital
spending. The more a utility spends on infrastructure, the more
profit it earns and the more customers pay. The electricity
cost of new data centers is therefore socialized.
So, given our broken system of utility rate setting in
America, how do we ensure that the tech companies, rather than
working-class families and small businesses, are the ones
shouldering the cost burden of new data centers?
So Mr. Branch?
Mr. Branch. Thank you for the question, Congressman.
Public Citizen believes it is critically important to be
collaborating with local communities to ensure that they are
looped into the process of when these data centers may or may
not be built. We argue, and we are seeing it across the
country, that a lot of these communities are fighting back
against these data centers.
But, just as importantly, we need to ensure that these
large tax incentives are not provided to these data centers,
because that ultimately ends up being disbursed throughout
consumers, and that is why Americans across the U.S. are seeing
their electricity bills skyrocketing.
Mr. Torres. You see, I am pro-AI. My whole life is
integrated with ChatGPT and Gemini. So, for me, the question is
not whether we should have AI. Of course we should have AI, and
we need data centers to enable AI. The question is, who should
pay for it, right? Should the cost be borne by working-class
families and small businesses, or should it be borne by the
owners and operators of the data centers?
What say you?
Mr. Branch. I think these data centers are worth a lot of
money, these corporations make a lot of money, and they should
be footing that bill responsibly.
Mr. Torres. There are tens of millions of Americans who
have next to no credit history. TransUnion estimates the number
at 45 million; FICO, more than 50 million; Experian, more than
60 million.
In the Bronx, I have thousands of constituents who have
paid their rent and utilities on time and in full for decades,
who maintain steady income and sufficient bank deposits, and
yet who remain deprived of a credit score.
Without a credit score you have no access to credit.
Without credit, you have no access to home ownership and
without home ownership, you have no means of building equity
and passing down wealth from one generation to the next. So
America's exclusionary model of credit scoring has done
irreparable intergenerational damage to working-class
communities in places like the Bronx.
Does anyone here have any thoughts on how we can harness
the power of AI to build an underwriting system that is more
predictive, more inclusive, and more representative of the full
financial reality of working-class Americans?
Mr. Stevens. I will take a stab, Congressman. I really
appreciate the question.
Of the 4 million families that are going to buy for the
first time this year, most of them are previous renters. At
Zillow we are big fans of working with TransUnion, Equifax, and
others to consider those on-time rent payments as part of the
larger equation.
We believe that AI is that ability to look at disparate
sources of information that otherwise a loan officer or
underwriter would not have time to consider, and then
ultimately leave it to them as humans to make the right
decision on what to underwrite.
Mr. Torres. Because we should harness the power of AI not
only to disrupt but to democratize----
Mr. Stevens. Exactly. Equal access.
Mr. Torres [continuing]. finance and access to credit is
exhibit A.
The Federal Government is drowning in vast oceans of data.
For example, in Fiscal Year 2024, FinCEN received a staggering
4.7 million suspicious activity reports, an average of 12,870 a
day.
Now, there is no agency in the Federal Government that has
sufficient human resources to thoroughly review millions upon
millions of reports, and so valuable information can easily
disappear into the black box of bureaucracy.
You know, AI can process vast quantities of data that the
human mind cannot process. It can recognize patterns that the
human mind cannot readily recognize.
Do any of you have thoughts on the role of AI in
facilitating not only finance but also financial regulation and
oversight?
Mr. Cohen. So Nasdaq employs AI in its surveillance
solution, so we are trying to root out market abuse through our
surveillance solution, and we use AI to do that.
One great example--and it just keys off of what you said--
is, a human investigation analyst combs through many, many
possible market manipulations. How do they know which ones to
pay attention to? How do they know which ones to let go?
We use AI to help you, number one, do all the manual tasks,
the series of tasks that you would otherwise go through to make
that analysis, and we provide you with a risk score, so then
you can focus on the bigger issues, the most important issues
affecting our markets. That is how we use AI.
We always--again, we have the human making the complex
judgment decision around that, but we are just reducing the
manual workload to get to that decision.
Mr. Torres. Thank you.
Mr. Timmons [presiding]. Thank you.
I now recognize myself for 5 minutes.
Thank you to the witnesses for being with us today.
Like other areas under the Digital Assets jurisdiction,
artificial intelligence is a transformative technology that
will shape how American companies, consumers, and investors
engage with our financial system. If the United States is going
to remain a global leader in innovation, we must adopt clear
and harmonized rules that support technological progress while
also protecting consumers and preserving market integrity.
Industry leaders are increasingly concerned about the
growing patchwork of State laws related to artificial
intelligence. These State requirements often conflict with one
another, whether in the form of impact assessments,
documentation standards, or definitions of high-risk systems.
For firms that operate across the country, these
inconsistencies can create significant operational challenges,
especially when artificial intelligence supports critical
functions such as fraud detection and cyber defense.
Without a unified Federal framework that replaces
duplicative and contradictory State rules, we risk higher
compliance costs, slower innovation, and weaker protection for
consumers.
Ms. Manfra, Google Cloud supports financial institutions
that rely on artificial intelligence for essential operations.
What regulatory obstacles or outdated requirements are
hindering firms from deploying artificial intelligence
responsibly at scale, particularly when those challenges grow
under inconsistent State laws?
Ms. Manfra. Thank you for the question.
I would say, first of all, it is important to be able to
have a national framework that is addressing all of the issues
that we have been talking about and not have that patchwork
that does pose undue burden and unduly impacts smaller and
medium-size players and creates higher barriers to entry that
would otherwise be available to them with all this new
technology. So I think that is very important.
I also think it is important to recognize that existing
laws and frameworks are in place and apply to these new
technologies, but to be able to provide spaces for financial
institutions to innovate and to test how these tools might be
applicable into higher-risk areas is also very important.
Mr. Timmons. Thank you for that.
A follow up question. Many State proposals include
different documentation and testing requirements for similar
artificial intelligence systems. From an operational point of
view, how difficult is it for a cloud provider or a financial
institution to adjust model governance and controls to comply
with several conflicting regimes?
Ms. Manfra. It is very difficult, and it would be
incredibly resource-intensive onto an organization in putting
personnel and other resources into positions that are not
enabling the core business of that organization.
Mr. Timmons. I feel like we have seen this before. We
watched Europe pass the General Data Protection Regulation
(GDPR), and then now we have the California Consumer Privacy
Act (CCPA), and we have all these different data privacy and
data security standards. I think everyone agrees that we need
to have a Federal standard that preempts everything and leads
in the global economy, and we are not learning from past
mistakes.
So not only do we need to lead here in Congress on AI, but
we also need to get with the program and address the patchwork
framework that is costing incredible amounts of money for
compliance for businesses. I feel like the larger businesses
have a better capacity to deal with the patchwork frameworks
for cybersecurity, but in AI it is just going to stifle growth
and innovation. We are competing in the global economy, and we
cannot lose this fight.
Although there are real challenges in establishing clear
rules for artificial intelligence, there are also significant
opportunities. AI can strengthen the safety and soundness of
our financial system by improving anomaly detection,
accelerating the identification of fraud, enhancing
cybersecurity, and enabling faster, more accurate risk
analysis.
At the same time, compliance expectations continue to rise
for institutions of every size. Smaller banks, credit unions,
and broker-dealers feel this burden most. AI tools can help
reduce manual compliance work, streamline reporting, and allow
institutions to devote more time and resources to customer
service and innovation.
Mr. Cohen, Nasdaq relies on AI to support its market
operations and oversight responsibilities. From your
perspective, how is AI helping strengthen the integrity,
stability, and resilience of the U.S. financial system?
Mr. Cohen. All markets operate on the mandate of trust and
investor confidence. If we compromise either of those, then we
will not have the standing we have today in our markets.
So we use our surveillance solution, and we employ AI in
it, to essentially allow investigation analysts to scale up,
focus on the high-value activities, and also focus on the
sophisticated manner in which market abuse is being conducted
today.
What we are seeing is, market abuse today, it is the same
outcome, but the techniques used are hard for any single human
or a series of humans to detect. What used to be, if you will,
clear patterns are now noise. To make them and convert them
back into signals, we have been using AI to help, if you will,
regulators, exchanges, and broker-dealers around the globe
protect the integrity of their markets.
Mr. Timmons. Thank you for that.
The gentleman from Texas, Mr. Green, is now recognized for
5 minutes.
Mr. Green. Thank you, Mr. Chairman.
I thank the witnesses for appearing.
I especially thank the chair and the ranking member for
allowing me this privilege to ask this question.
I have intelligence indicating that over the next 10 years
approximately 100 million jobs will be lost to AI. I know that
is a large number. Perhaps you have a number that is somewhat
different but let us just assume that this number is accurate.
My question is, how do we provide for 100 million jobs
being lost, in terms of how they will impact people? Jobs
usually have people associated with them. So how do these
people maintain their lifestyles? Will there be some emolument
accorded them by way of the Federal Government?
Let us start with you, Mr. Branch, if you do not mind, and
we will go to your right and down the line.
Mr. Branch. Thank you for the question, Congressman.
If I had the answer to that, I would be a very rich guy,
because there is currently not really an answer to this
solution, and that is the big problem.
A lot of these tech companies are moving full-fledged
forward with this theory of having AI take up a variety of
jobs, but there is no solution for when those folks end up
being laid off or unemployed.
Mr. Green. All right.
Next, please?
Ms. Whitmore. Thank you, Congressman.
So I work in the field of cybersecurity, and we have
historically had a pretty significant job shortage. I think,
right now, any estimates would probably be over 1 million jobs
within our industry that are not filled and that is due to a
lack of skills with that labor shortage.
In that regard, I think we are looking at cybersecurity
usage of AI as really being able to put on an exoskeleton for
our defenders, making them more capable, being able to conduct
tasks that are much more efficient, and defend our networks in
a way that we are not able to do at human scale today.
Interestingly, in the field of cybersecurity, I think we
are actually providing a lot more job satisfaction to our
industry analysts and defenders, who primarily deal in very
repetitive tasks.
Mr. Green. Well, I appreciate your answer, but, if I may, I
am posing a different question. You have answered a question
associated with how well and how efficacious your business
model is. My question has to do with the people who are
displaced. How will they make a living?
Ms. Whitmore. I think that is a great question, but as a
cybersecurity expert, I am not sure that I am in the best
position to answer that, so I may turn it to Mr. Stevens.
Mr. Green. All right.
Mr. Stevens. Thank you, Congressman. I will talk briefly
about how important humans are to housing and then also offer
how we can improve building the next-generation U.S. workforce.
In housing, ultimately, where people are going to live is a
very human-based decision. We find time and time again; people
want a real estate agent to sit across the table and give them
advice on if they are making a good decision. So, in housing,
we continue to see humans being very important.
Outside of that, I think something that has come up briefly
is, we really need to invest more in training the next
generation here at home to work on these models and help really
improve them over time. And that is----
Mr. Green. Excuse me, if I may.
Mr. Stevens. Of course.
Mr. Green. A hundred million people, 100 million jobs--100
million.
Mr. Stevens. I have not seen that stat, but I certainly
believe, if we gave equal access----
Mr. Green. Okay.
Mr. Stevens [continuing]. of this technology, that----
Mr. Green. Okay. Thank you. I think that your model is a
good one, but we are talking about 100 million.
Mr. Stevens. Yep.
Mr. Green. Yes, sir?
Mr. Cohen. It is a great question. The first thing that we
have to do is be honest about the workforce transition that we
are going to go through as a country.
What we are doing in terms of our part is, we are trying to
make sure that we upskill/reskill employees and we are actually
creating roles of the future. So we are trying to do our part
to make sure that our workforce comes with us into the next
generation.
Then you also have to believe in the power of AI to
generate new business models, new opportunities and that is why
it is important that we capture them here so that we can make
sure that those individuals that----
Mr. Green. Okay.
Mr. Cohen [continuing]. may be displaced have opportunities
in the future.
Mr. Green. I have to go to the last speaker.
Please, ma'am.
Ms. Manfra. Thank you, sir. It is a very important topic
and one that we care a lot about.
Similar to our colleagues, we are very invested in ensuring
our own workforce has the tools to be able to be successful.
This includes our engineers using AI to be more productive.
I would say more broadly is that we are seeing more job
creation, we are seeing businesses grow as a result. It is
important that we invest in education at the lowest levels of--
into elementary school to make sure our kids are----
Mr. Green. The chairperson is admonishing me.
Let me thank you, Mr. Chairman, and simply indicate that
this is a question that we have to give some serious
consideration to.
Mr. Timmons. The gentleman's----
Mr. Green. A hundred million jobs.
Mr. Timmons [continuing]. time has expired.
Mr. Green. I thank you, Mr. Chairman. I yield back.
Mr. Timmons. The gentlewoman from California, Mrs. Kim, is
now recognized for 5 minutes.
Mrs. Kim. Thank you, Chairman and Ranking Member, for
convening our hearing today.
Earlier this year, the State of California, where I am
from, passed SB 54 that would unfairly regulate AI and impose
heavy compliance burdens on companies. Now States across the
country are looking to this California model as a basis for
developing their own artificial intelligence regulations.
Therefore, there is an urgency for Congress to establish a
Federal framework for AI. That is why I support legislation
like Chairman French Hill's Unleashing AI Innovation in
Financial Services Act that would create Federal regulatory
sandboxes.
Ms. Manfra, if that bill is signed into law, will those
Federal protections be respected if you are simultaneously
fighting a patchwork of restrictive State laws, particularly
the anti-innovative regulatory framework in my home State of
California?
Ms. Manfra. Thank you for the question, ma'am.
Yes, we absolutely think the need for a national framework
is critical and having to navigate a patchwork of regulations
does not help either our company or our customers.
Mrs. Kim. Thank you.
What has made America a leader compared to other countries
is our philosophy of trying first, rather than regulation
first. So the longer we fail to act, the regulatory standard
will be set at the State level, not--and the innovation will
suffer.
So thank you.
Another area where AI has high value is in its application
in the field of cybersecurity.
So I want to ask you, Ms. Whitmore: By leveraging AI, how
have banks been able to save time and protect themselves
through cybersecurity efforts?
Ms. Whitmore. Thank you for the question.
So I think one of the most measurable areas we see with
financial institutions is actually the applications to
cybersecurity and, in particular, measuring outcomes in how
quickly we detect attacks and how quickly we respond to them.
As we have seen the use of AI increase, we have seen
ransomware attacks that have been completed from initial part
of the attack to stolen data or encryption of data in 25
minutes. We have worked with customers in the financial
services industry who have taken a mean time to detect from 24
hours to as little as 10 minutes.
So those types of measurable outcomes are incredibly
critical in our ability to defend financial services networks.
Mrs. Kim. Thank you.
You know, scams are an issue that I hear constantly about
from my constituents. We know that modern financial scams are
rarely isolated to a single app. They may start with a text on
a phone, move to a fraudulent website, and follow up with an
email.
Ms. Manfra, let me come back to you. How does Google
connect the technical dots in the background to prevent those
foreign scammers?
Ms. Manfra. Thank you.
We have invested a lot in this space and seen a lot of very
positive results going to the ability to identify a fourfold
increase in activity that we are then able to detect and take
down on a variety of our platforms.
We do not want fraudulent or scam information that is
sitting on our platforms or that is impacting our customers.
So, every day, we are identifying millions and taking down
millions of fraudulent ads, preventing scams, preventing
phishing through the use of AI and ML technologies.
Mrs. Kim. So let us say, if AI detects a threat in Gmail,
how does that transfer across Android or Chrome to ensure that
it is neutralized across a person's accounts?
Ms. Manfra. Well, in some cases we use common tools, and
many of our platforms and tools reside on common
infrastructure, so oftentimes we are able to leverage that
scale to be able to identify commonality.
In other cases, we do have to use unique tools, but we are
sharing the outcomes, the detections, the things that we are
finding, to make sure that other products and platforms are
available to use that.
Mrs. Kim. Uh-huh. Well, thanks for your work on that.
Let me quickly shift gears to AI. It has a large role to
play in preventing financial crime as well.
So, Mr. Cohen, I want to give you a chance to answer. How
does Nasdaq utilize AI to address compliance and prevent
financial crime?
Mr. Cohen. So we were saying earlier that we have a leading
financial crime platform. It is cloud-native, AI-enabled and
what we do is use consortium data to detect patterns that no
single institution can do on its own. We have 725 million
accounts.
What we are able to do is reduce false positives and help
investigators focus on real crime and identify real crime----
Mr. Timmons. The gentlelady's----
Mr. Cohen [continuing]. that is otherwise a drain on----
Mr. Timmons. The gentlelady's time has expired. Sorry.
I now recognize the gentleman from New Jersey----
Mrs. Kim. Thank you.
Mr. Timmons [continuing]. Mr. Gottheimer, for 5 minutes.
Mr. Gottheimer. Thank you, Mr. Chairman.
AI is being used, as we all know, to detect fraud and stop
seniors from getting manipulated, those especially who are
targeted by scams involving deepfakes and other AI-powered
tools.
According to the Federal Trade Commission (FTC) report
released just last week, adults over 60 lost $2.4 billion to
scams and fraud in 2024. Alarmingly, this is the same report
that found that older adults who reported losing more than
$100,000 increased more than five-fold between 2020 and 2024.
I am very grateful to Chairman Hill and the Capital Markets
Subcommittee chairwoman, Ann Wagner, for recognizing the
importance of my Senior Security Act and including it in the
INVEST Act, which the House will vote on this week, to put a
new senior-protection-focused cop on the beat at the SEC.
Ms. Whitmore and Mr. Cohen, what specific safeguards should
be considered to prevent and detect elder financial fraud and
abuse related to AI and how should industry coordinate with
Congress and regulators and law enforcement and others to
ensure those protections keep pace with rapidly evolving AI-
enabled threats?
Ms. Whitmore. Thank you, sir, for the question.
So I think specific to the demographic you are talking
about, education is a huge concern and really an issue. If we
can raise awareness that these scams are being conducted and
can create a level of education that does not necessarily exist
that widespread today, I think that really helps with that.
Additionally, what we are also talking about is visibility
at large scale to protect the transactions on the back end and
that is where organizations like ours truly focus, is looking
at the packets that are moving. So, in your specific use case,
we will be looking at the financial services transactions and
ensuring that our detection capabilities are not facilitating
those types of crime.
Mr. Gottheimer. Mr. Cohen.
Mr. Cohen. Thank you.
There are two important elements here.
There is the public-private partnership. We need
information-sharing, because these scams scale incredibly fast
in the world that we live in today. It should not be that the
elderly find out on Facebook from their friends about a scam.
We should have this information-sharing at a scaled level to
make sure that we can prevent it and not just deal with it
after the fact.
The second thing is, we can use AI to detect it at scale.
Right now, what we are doing is, we are coming into it, and we
are trying to deal with it on a one-off basis. We need the
tools and the automation to be able to stop it the second we
see it and not let it propagate through the system, and AI can
help us do that.
Mr. Gottheimer. Are we seeing that?
Ms. Manfra, are you taking steps to actually make sure that
happens, from a Google perspective?
Ms. Manfra. Absolutely. We are identifying, blocking, and
taking down fraudulent use of our platform--fraudulent
postings, fraudulent ads, scams that are targeting various
customers, phishing attempts. Gmail alone blocks 180 million
phishing attempts every day and so we are investing in AI as a
critical component to being able to do that.
Mr. Gottheimer. Thank you very much.
Regulators have used innovation hubs and sandboxes to
encourage responsible experimentation in other areas of
fintech. I am personally very focused on this area.
For the entire panel, what features and guardrails do you
think are essential for AI pilots to truly encourage innovation
and protect consumers and communities in this space?
Josh, do you want to start?
Mr. Branch. Thank you for the question, Congressman.
Well, I think these sandboxes need to be time-limited; they
need to be specific, and I think those are two of the primary,
sort of, components that are at least not seen currently in the
sandbox offerings.
Mr. Gottheimer. Ms. Whitmore.
Ms. Whitmore. Thank you.
So I think we look at it from three categories.
First is defining a risk-based approach with consistent
definitions. The focus is on actual threats and not necessarily
those that are hypothetical and those, certainly, that are more
high-risk applications.
Second would be distinguishing between the developers and
the deployers.
Third is making sure that defense is a priority, so having
a voluntary standards, a framework that then looks at making
sure we are protecting our most critical information and not
getting it in the hands of our adversaries.
Mr. Gottheimer. Thanks.
Nick.
Mr. Stevens. Thank you.
I would say briefly that laws stay enforced, that we test
responsibility in these sandboxes. Independence checks still
happen, bias testing and the like. Last, I would add,
transparency is obviously paramount.
Mr. Gottheimer. Yes.
Mr. Stevens. Regulatory reviews, consistent----
Mr. Gottheimer. Tal, you agree?
Mr. Cohen. Controlled, targeted, and time-boxed, and do not
allow for circumvention of approval process.
Mr. Gottheimer. Jeanette.
Ms. Manfra. I agree with Mr. Cohen and the previous
statements.
Mr. Gottheimer. Great.
Thanks so much.
I yield back.
Mr. Timmons. The gentleman from York, Mr. Garbarino, is now
recognized for 5 minutes.
Mr. Garbarino. Thank you, Chairman.
Thank you all for being here today.
As chairman of the House Committee on Homeland Security,
one of my top priorities is reauthorization of the
Cybersecurity Information Sharing Act of 2015, also known as
CISA 2015. It is a vital framework that allows for voluntary
exchange of cybersecurity information between the Federal
Government and private entities.
From energy companies to major financial institutions on
Wall Street, the private sector's first line of defense against
malicious cyber adversaries in CISA 2015 is critical to
ensuring those threats are not realized.
Ms. Manfra, as someone who previously served as Assistant
Secretary for Cybersecurity at CISA, how important is the
reauthorization of CISA 2015 to ensure our cybersecurity needs
are met to combat AI-powered threats?
Ms. Manfra. It is very important, sir.
Mr. Garbarino. Can you give me some examples of what could
happen in the financial services space if CISA 2015
authorization were to lapse--like it did under the shutdown,
but it would lapse for a longer time?
Ms. Manfra. The framework that the legislation provides
CISA to be able to share information in protected spaces with
its partners, to include financial services, means that they
are actively reducing risks in those protected conversations
and information-sharing environments and so not having that is
detrimental to those partnerships.
Mr. Garbarino. Yes. I mean, financial services companies
are hit all the time with cyber-attacks. They learn about
vulnerabilities before--because they are the front line of
defense. They cannot share that information with the Federal
Government. The Federal Government cannot then share it with
everybody else. Which means those vulnerabilities cannot be
fixed and we are just facing more and more threats, correct?
Ms. Manfra. Correct.
Mr. Garbarino. Thank you.
Ms. Whitmore, is our existing financial data privacy and
cybersecurity framework well-suited for the current era of AI,
or are reforms needed?
Ms. Whitmore. I think we can leverage existing regulation,
but what we are really advocating for, moving forward, are
actions that benefit the defenders and not the attackers.
So the more that we look at streamlining regulation and
harmonizing it, the better we make it for defenders to really
focus on truly firefighting and not filing the complexities of
too much paperwork.
Mr. Garbarino. Yes, harmonization. I had lunch with Jamie
Dimon once, and he said more than 50 percent of--his
cybersecurity employees spent more than 50 percent of their
time on compliance instead of actual cybersecurity defense,
which is wild to me.
Ms. Whitmore. Yes.
Mr. Garbarino. So harmonization is another thing that I
know I have spoken to Chairman Hill about as something we
should focus on here as well.
Switching gears a bit, the mortgage industry has spent
decades under Federal oversight, starting with the Great
Depression, when agencies like the Federal Housing
Administration (FHA) and Fannie Mae were created to stabilize
the housing market and expand access to home ownership, and
intensifying again after the 2008 financial crisis through the
Dodd-Frank Act and then the creation of the CFPB. Today,
Federal rules shape nearly every part of the mortgage process.
Mr. Stevens, as AI enters mortgage lending, should we
extend existing Federal financial services regulatory
frameworks to cover AI?
Mr. Stevens. Definitely. Any law or regulation that humans
have to follow, AI definitely should too.
I think, to the first part of your question, AI has that
ability to take on a lot of the administrative burden that
slows everyone else down. If you shadow a loan officer, they
spend hours just collecting documents, copying and pasting
data. AI can do that so they can focus on the right decisions.
Mr. Garbarino. Absolutely.
So what should Congress do to ensure--or maybe not do--to
ensure that you can continue to innovate here?
Mr. Stevens. I think national right-sized frameworks. I
mean, we rely a lot on the risk AI management framework, and so
anything that has a consistent baseline for all of our States
will help us.
Mr. Garbarino. Are there any--and maybe it is the States
but are there any regulatory structures that are currently
standing in the way of AI delivering on the promise to expand
access to affordable housing?
Mr. Stevens. It is something we could certainly follow up
on.
I think, in housing, a lot of the regulations were written
before the age of the internet. For example, we have a whole
database at Zillow that is just mindful of when e-sign is
allowed depending on the State you are in. So I would say a
comprehensive review of some of those older frameworks would be
useful.
Mr. Garbarino. Yes. If you could get us more ideas, that
would be----
Mr. Stevens. Yep. Would love to follow up.
Mr. Garbarino [continuing]. more details, that would be
great.
From your vantage point, Mr. Stevens--last question--
building consumer products, how can technology and
modernization, not more regulation, actually help lower the
costs for buyers and renters?
Mr. Stevens. Yes. Both the efficiency, we were talking
about, with loan officers and real estate agents. I would say
also, the democratic--democratization of data access.
If you have a nationwide framework, that means we can give
guidance about what home to buy across State lines, which many
consumers consider all the time.
Mr. Garbarino. Uh-huh.
Mr. Stevens. If it is a patchwork, that means we have to
build very custom models depending on the State you are looking
in right now and that kind of efficiency helps people make
better decisions at the right price.
Mr. Garbarino. Thank you very much.
I am out of time. I yield back.
Mr. Timmons. Thank you.
The gentleman from Nebraska, Mr. Flood, is now recognized
for 5 minutes.
Mr. Flood. Thank you, Mr. Chairman.
I really think about AI in, really, two buckets: Number
one, as it relates to entities that are already regulated in
the financial services lane, whether it be by the Fair Housing
Act, the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act,
or statutes that apply to financial actors.
Basically what I tell people is, if we find you
discriminating, we will fine you, and we will enforce the law.
In other words, if you are using AI to break consumer
protection law or discrimination law, we need to ensure that
our regulators are equipped to track and identify that.
I have this idea that someday we are going to begin an
enforcement action, and the regulated entity will say, ``Well,
we did not intend to do that. It was all in our AI model, and
this is the outcome.'' Well, we are not going to fall for that.
Like, if you break the law, you broke the law, and you had a
model that did it.
Number two, we need to work together to identify these bad
actors, these folks that use generative AI to scam people out
of money, to let fraudsters fool people and steal their cash,
and law enforcement needs to be able to respond to these
threats. We absolutely need the help of technology companies in
preventing AI from being used by those who do it to lie, cheat,
and steal.
That is really where I come from on this.
To all of you on the panel today, can you just describe the
intentions with the--the interactions, I should say, with the
regulators you work with on AI, both at the Federal and the
State level? Do you see in those regulators sufficient
expertise in your counterparts in government to make you feel
they are up to the task of overseeing this changing landscape?
In other words, as you engage with regulators, do you feel like
they have the tools they need to do the job, given the changed
landscape with artificial intelligence?
We will start here.
Ms. Manfra. We will say, those that we interact with,
whether as customers or partners or regulators, I do think that
they show a willingness and an openness to learn. I do think
that, like many other organizations, they do need more skilling
in this space to be able to best focus on the outcomes but also
be able to apply that to new technology.
Mr. Flood. Mr. Cohen.
Mr. Cohen. Just to frame your question, public-private
partnerships are incredibly important, and they are what will
keep us ahead.
Two things, if I could take the opportunity. The
Cybersecurity Information Act that needs to be extended so that
we continue that on the cybersecurity side.
In terms of the regulators and the way that we work
together, we do feel like they appreciate the issues; there is
a deep level of understanding around the issues. The one thing
we worry about is regulatory arbitrage. So you need to make
sure that, as we go to the regulators, we do not want to go to
the regulators that understand the least to try to get
something approved.
That is why at a Federal level we are going to need some
clarity there, so there are no regulatory arbitrage and people
do not try to go to the regulator that understands the least.
Mr. Flood. Well-said.
Mr. Stevens. Thank you. I appreciate the question.
I would say, certainly education could help when we partner
at the Federal and State level but even more so, we see
successful partnerships when they are outcome-focused, when
they are customer-first, when they are transparent.
I could sit down and explain all the fraud models behind
Zillow Rentals, but if we just agree that no customer should
see a fraudulent listing or have a fraudulent payment, then we
can collaborate even more efficiently.
Ms. Whitmore. Thank you for the question.
So not only do we work on behalf of public-private partners
within cybersecurity and all our counterparts on the government
side, but also on behalf of our customers when we are
investigating these major cyber breaches. They are then
challenged so many times with the different regulatory
frameworks that they need to report these breaches in.
I think the one area I would really like to share there is
that more complexity never benefits the defenders who are
trying to fight the fire and stop the breach while they are
also worried about the paperwork. So that really benefits the
attackers. I think the more we can streamline, the better off
we are going to be.
Mr. Flood. Mr. Branch.
Mr. Branch. Thank you, Congressman, for the question.
Many agencies have lost jobs due to various layoffs, and so
these agencies are playing catchup and are in a bit of a
difficult position to try to enforce some of the laws but,
also, President Trump's AI action plan has predominantly been a
deregulatory effort. As such, the agencies are not really
empowered to enforce some of the laws that exist.
The last thing that I would say, as well, is that some of
the sandbox bills that have been proposed allow the companies
to sort of self-regulate. So, from that end of things, these
companies are sort of guarding their own laws, and it is not
allowing the regulators to essentially do the jobs that they
are required to do.
Mr. Flood. Thank you very much.
With that, I yield back.
Mr. Timmons. Pursuant to the previous order, the chair
declares the committee in recess, subject to the call of the
chair. We will reconvene immediately after the floor vote
series.
The committee stands in recess.
[Recess.]
Mr. Fitzgerald [presiding]. The Committee on Financial
Services will come to order.
I would like to thank all the witnesses for their testimony
today.
Without objection, all members will have 5 legislative days
to submit additional written questions for the witnesses to the
chair. The questions will be forwarded to the witnesses for
their response.
Witnesses, please respond no later than January 14, 2026.
[The information referred to can be found in the appendix.]
Mr. Fitzgerald. The hearing is adjourned.
[Whereupon, at 2:38 p.m., the committee was adjourned.]
APPENDIX
----------
MATERIALS SUBMITTED FOR THE RECORD
[GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]
[all]