Hi everyone.
Thank you for joining today for what is one of the first side events of the first plenary of the global mechanism.
I am Pablo Rice from the Paris Peace Forum and today we partnered with colleagues from the French Ministry for Europe and Foreign Affairs to convene this roundtable on a matter which actually became quite a topic over the past few months and that you might hear quite a bit actually over the next few days.
Namely AI in cyber, AI for cyber, AI misuse by cyber adversaries, and the cybersecurity of AI systems themselves, which was quite a bit a niche topic when we had the Paris Peace forum started digging into this matter back in 2024 has become a genuine geopolitical object since 2026.
I won't recall the very latest developments on the matter, which I'm sure you you are well aware of, but I would just like to point out that the notion of AI misuse of AI in cyberspace has been put at the core of many rationale underlying some measures at the government or at the company's level, especially to justify some stage or some structured access, meaning access restriction to frontier proprietary models.
Such modalities tend to become the new normal, even if in this space, we should refrain from making too affirmative forecasts.
The thing is, as it is often the case for high profile, quickly evolving technological challenges, that the level of concern is at least as high as the degree of certainty we are all navigating when it comes to the actual cyber capabilities of advanced AI models, but also the modalities of AI uptake in cyber operation.
As a result, any corporate or any government action can only be driven by evidence.
The evidence gap we are facing is a challenge that no single country, no single organization can bridge alone.
This is why the need for cross border, cross sectoral, and of course, multi stakeholder cooperation is critical than ever.
This is why the Paris Peace Forum has launched earlier this month, a new international initiative called intake, the Integrity Network for Trust AI and Cyberspace that aims to gather expertise across policy and technical circles spanning cyber and I security communities precisely to find avenues to overcome structural obstacles so that reliable evidence can emerge to inform international governance efforts on the matter.
Today's discussion fits right into this endeavor and even if we could have chosen to engage in other forums or processes than the global mechanisms because there are more and more initiatives in that sphere and that's a challenge in itself, we believe that it's still much needed to address this question at the UN in general and within the global mechanism in particular.
For two main reasons.
The first reason is that the vast majority of states might have felt that they were a little bit left aside from the latest debates about air and cyber that tended to be framed either around the transatlantic relationship or around a race between the most advanced powers.
But if we agree all on the premise that AI might be one of the most transformative and systemic developments in global cybersecurity instabilities, then at some point, all states should be at the table.
The second reason is that building on the OAWG achievements, the global mechanisms represents a real opportunity for states to advance ICT capacity building.
The challenge at stake today is actually first and foremost, a matter of capacity.
The capacity of most states to see the AI driven cyber threat landscape as it evolves and the capacity to bolster defense accordingly, including, of course, by harnessing AI in that respect because let's not forget that AI holds an incredible potential in improving cybersecurity and cyber defense.
The key question we will invite you to reflect on as part of today's discussion is precisely, how can we collectively progress towards a fair global benefit sharing of AI and cybersecurity.
To kick off the discussion, we will first give the floor to misses Clara Chaz, ambassador of France digital affairs and artificial intelligence.
For some introductory remarks, Ambassador, the floor is yours.
Thank you.
Thank you.
Thank you so much and thank you for helping us organizing this event.
We're very glad to see how many people we have in the room and also most importantly, not only people from different states and stakeholders, but also from the private industry.
Thank you for all the friends that joined today because we strongly believe that's something we should only look at with multiple stakeholders looking at the same problem.
I mean, you've started saying that when you worked on that topic a few years ago, it was quite niche.
I think there's probably not a single international event now that doesn't talk about the ice.
There's been some progress made on that front and obviously a lot of that is thanks to a lot of people in this room and it's very important for friends to be able to have this meeting in a moment where AI is basically reshaping everything, access to education, to information, to health, to um, science, the transformation we're living is probably so unprecedented for the scale and the speed at which it's addressing our words and obviously as well when it comes to national security and cybersecurity.
And to us, it was very obvious to take the occasion to have so many people gathered here in the UN to have this type of discussion ahead of the Paris Peace forum, which we'll obviously continue in that direction in just a few months back in Paris.
We know that this technological revolution is completely reshaping how strategic balances and forces are playing in a world we're knowing.
In a moment where we're seeing so much fragmentation, conflicts happening both physically and in the cyber world, we do believe that cooperation is where we should unite when it comes to addressing those challenges.
We're confronted, as everyone knows in this room to growing asymmetry, especially with AI between all the states, but also between offense and defense.
We think it's key to understand to respond to those challenges together collectively.
To this end, we think that strengthening everyone's capability can only be the way to more globally cooperate on those issues.
What we want to focus on today and we'll hear from everyone in the room in a minute is first the assessment that we've seen.
Everyone has seen this news, but in a world where AI can basically power our hospital, our education system, national security agenda, defense system, But in this world where it can also be a world where AI systems can be switched off from 1 hour to the other on unilateral decision, sometimes, we basically have to face a reality, which is that it has become both an infrastructure of progress, but progress is only sustainable for those who can control this infrastructure, is only stable for those who can control this infrastructure and people who are only accessing it are taking huge immense risk when it comes to stability.
Two, the answers that we think we must bring to it is basically how to build a path for ourselves.
A third way where France has been really pushing for quite a long time, we hosted for those of you who were here at the AI action Summit back in February 2025, where the President Emmanuel Macron basically gave international resonance to this movement to say that only through international cooperation states will be able to build their own sovereignty and that when we're confronted with such a technology, we basically need to address it internationally.
Also, when it comes to mitigating the risks, the response to frontier models challenge cannot be national fallback.
President Macron also hosted a G seven summit because France is very proud to lead G seven this year.
In the Evian Summit, we gathered leaders from G seven and beyond.
We also had the immense privilege to have the company of India, Kenya, Egypt, and Brazil.
During the summit, the leaders and the tech CEOs discussed together that rather than playing divide, we need to play together accordingly to address some of those challenges.
We must depend the implementation of the frameworks for responsible behavior and guarantee that the use of those technologies are not used by malicious actors.
To do that, President Macron reaffirmed his conviction that we need to build cooperation.
It will help not only preserve national security, but also international stability in the cyberspace.
The conclusion to this discussion and to all the work we are trying to push forward, including this discussion when it comes to the UN here today, is that all the work we're carrying out during the global mechanism Is important because it can help us move forward, deliver concrete actionable solutions, which we need more than ever.
We think that this discussion, as I said, is not something we can only discuss within states, but it's very important that we gather all the actors in the same room, as we did during the AI action Summit, as we did during the G seven Avian meeting as we're doing today, only by mixing expertise, point of views, and getting everyone in the same room.
It's how we can basically address some of the challenges we're facing.
It's a meeting of the event we're holding today.
Thank you again to the Paris Peace Forum for bringing us together and for all the participants who've taken a bit of their precious time to come with us in the UN today.
Thank you for all the work you're going to present to us and please count on our support.
Thank you very much, Ambassador.
And to frame the discussion, we will have selected initial contributions from four persons that I would like to thank for their presence today.
Jim Riveis, the CEO of the Cloud Security Alliance, Sit Page, the Director for International Cyber Policy at the Cybersecurity Agency of Singapore.
Giacomo Percy Pole the head of the Security and Technology Program at the United Nations Institute for Disarmament Research.
Last but not least, Sil jet with Head of machine learning and society at face.
I would like maybe to start with you, Jim, to maybe brief the audience on the current state of play when it comes to what we call the I cyber nexus.
The Cloud security Alliance, which is one of the largest alliance actually of practitioners from a cybersecurity providers worldwide as released following the announcement of anthropic Mos, a brief highlighting some of your concerns.
At the top of that was, of course, the AI driven vulnerability system we might expect soon.
We had a couple of discussion afterwards.
You told me a couple of times actually Of course, the potential misuse of AI capabilities by cyber adversaries was a matter of concern, but maybe the most immediate one was, let's say the potential disruption of AI, let's say the cycle of vulnerability discovering and patching as well.
If you could maybe develop a bit on that.
Thank you very much for joining me for that.
And when I started, probably you could fit the entire global industry in a room of this size.
It's just a measure of how important the digital world has become and this is absolutely the most transformational technology in our industry and it's moving so fast and I'm assuming it is for every sector everywhere.
As we have looked at this progression and the idea of scaling laws and the compute and data, creating this huge change.
We are characterizing this as we're dealing with two exponentials right now, which is a challenge.
One is the exponential growth in the capability of AI models to get smarter and smarter and smarter.
The Mythos model, for example, was not even trained to be good at cybersecurity, was trained to be good at software coding, and this is an emergent feature and we're going to see a lot more emergent features.
Other exponential is the tremendous growth in agentic AI, AI agents operating with autonomy, and that is creating this scalability and this capability, both for good and for bad that we have to address.
There's three very big moments that happened this year First, there was the open claw moment where people started to just install agents to do a lot of things and take over their computers.
The second big one was the Mythos release in April where this model was released that showed this incredible capability to be able to find vulnerabilities in any type of software, open source, closed source, doesn't matter.
You can find it quickly.
This notion where we talk about a zero day vulnerability, something that will start immediately being used by attackers that used to be very rare are now going to be very commonplace.
What we did is we activated a lot of security experts like literally over a weekend, 200 chief information security officers from really important companies.
We worked on a document to talk through this, which is the main thing I want to characterize.
It is that we are going to have what we call this upstream vulnerability storm.
All of the software we depend on open source, closed source is going to be examined by malicious attackers for vulnerabilities, and then they will attack it and we are forced into this dilemma of needing to go very rapidly fine with all those vulnerabilities themselves.
If you didn't follow, if you don't follow this news, this is just an example of that consequence from Mythos in April is Microsoft had its hugest by an order of magnitude patch Tuesday, I think it was last week, just CVEs, things like that.
What we've are thinking about this is we're going to find a lot of these vulnerabilities and the challenge then is downstream, how we get enterprises to be able to manage this.
How we get what we call organizations below the security poverty line.
Think about hospitals, schools, municipal governments in addition to the critical infrastructure within any industry.
We have to have strategies that go beyond just automatically patching things all the time, which can also cause disruption.
Like if you're using software to control a pipeline or a rocket launch or things like that, you have to be very careful about patching vulnerabilities all the time.
So we have to have other strategies.
We talk about zero trust, which basically means you assume that anything can be breached and if you assume that, you can build strategies that hardened systems, look at incident response, look at a lot of other areas.
In order to do this correctly, what we had said in the paper is it's fundamental that cybersecurity use agentic AI to be able to run at machine speed.
You got to fight fire with fire and it's incumbent upon us that cybersecurity have this collective defense, this communications we're talking about, and we have to modernize and we have to do it very rapidly.
The third big thing that happened just as a final thing is actually a colleague on the panel I haven't met, Hugging Face had an issue which they handled wonderfully and it's just terrific and hats off to them.
On July 16th, they were reported that they were attacked by autonomous agents that got in there and got a foothold and the way they found it actually and resolved it and it's amazing how quickly they've written all about this was by using agentic cybersecurity agents to be able to go find all of this information.
One of the problems they ran into is because of the guardrails on the frontier models, they weren't able to use it for forensics analysis.
They weren't able to use the frontier models, so they had to go use the open source open weight models, which I think the one they use is actually one that was originated by China is where it comes from, and then it was posted up there.
They did a wonderful job But that's the next big moment.
We found mythos, we could find all the vulnerabilities, and now we can see the malicious attackers are using agentic AI to create automated attacks, escalate that within organizations, and that's a huge thing.
We're actually going to spin up a closed door meeting this Thursday with Chatham House rules for CSOs to talk about what we all know about this.
So it's here, it's very powerful.
Our incumbent responsibility is to build societies that are resilient to these types of attacks and developments.
And so thank you for letting me be here, and I think this is just very important the discussion we're going to have.
Thank you very much, Jim, and we will indeed dig a bit deeper into the open source dimension with and Janet.
But before that, I would like to turn to Director Pan Raj, maybe to follow up quickly on a question Jim highlighted, which is basically how can public authorities, public organizations manage the disruptive dimension of AI and cyber, but also more broadly, what does it take for an organization for national authority, a public cybersecurity agencies such as the CSA, to conversely, make the most of AI from threat analysis to its own defense.
Maybe if you could share what CSA recent work in this area could be maybe shared or transferred to partner agencies.
The floor is yours.
Thank you.
I'd like to thank our colleagues from France and from a moment in time last October when many of you know that Singapore hosts an annual Singapore International Cyber Week and on the sidelines, we have Asean Minister conference on cybersecurity.
We had organized agenda, we had settled everything at the staff level.
Then just before the conference started, we saw the ministers from Asean standing together and speaking very excitedly with my minister.
That's always a worrying moment when you see our ministers getting excited because we don't want them to be.
Please don't repeat this outside this room, but the truth is, and I went in there because I was the organizer and they were all like, yes, we should speak about AI and cyber.
I thought that it would be useful not just to share the thoughts from Singapore, but also from the region, what the agencies are thinking and what is happening.
Because many countries around the room in the plenary are thinking about these things, five observations and five quick lessons.
I try not to be too long, but I appreciated Clara's points she made that actually AI and cybersecurity, it has changed the way that we think about cybersecurity.
That is the fundamental, there's a fundamental shift.
AI is both a threat multiplier as well as a defense multiplier.
There's an opportunity part of it, which many agencies are looking at.
The goal is not to simply defend against AI, but to harness AI to use AI to defend better and faster.
What are some of the things that we are thinking about, some of our colleagues around the region are thinking about? Five points.
The first is that that vulnerabilities to recognize the changing threat landscape.
The fact is that AI is fundamentally changing frontier AI, which was just shared, is fundamentally changing cyber operations.
It's not just theoretical.
Not just improving existing attacks, it is changing it.
Accelerating attacks in three ways, speed, scale accessibilities, vulnerabilities that took weeks to exploit may now be weaponized within days or even hours, reducing defenders response windows.
From an agency point of view, this is the first starting point.
The second thing is that then what do we do? If the guys on the other side are using AI, then we will need to use AI ourselves.
The second point, verage AI as a force multiplier for defenders and government agencies are thinking of how to use AI throughout cyber operations.
Threat intelligence analysis, vulnerability prioritization, malwa triage, Security Operation Center investigations, incident response.
My colleagues back home are working on all of this, but it's the beginning.
Lots of things that we need to consider as we allow AI to use all of this because you need to trust AI, first of all, isn't it? You don't just let AI loose on AI and then hope that everything turns out well.
There is a need to see how AI is being used in defense and cyber operations and how to make sure that it's trustworthy.
I think some of these things were covered.
But the third thing we recognize is that we need to strengthen cyber fundamentals.
There's a third point out of five points that AI finds weaknesses faster, but it does not create always entirely new ones.
It does not create new vulnerabilities, but the point is that it finds weaknesses faster.
So we have priorities.
We still have priorities like asset visibility, secure by design, some of which has been covered, identity security.
It's not to say that it's a brand new thing, but the things that we can do and continue to do to build our defense.
Fourth, we have to build resilience for compressed attack timelines.
I've just covered that.
How do we work with different stakeholders, industry who are looking after critical information infrastructure, industry players, those who are involved in development of AI to do this.
In this point, some of us are thinking very carefully about operational technology, environments often which cannot be patched quickly, making early detection resilience particularly difficult.
Finally, and this is something we don't talk about all the time.
Agencies need to think about investing in people, governance, and partnerships.
Technology alone is not sufficient.
We will need AI literate cyber professionals.
Many countries need such people.
Governance for responsible AI use needs to be put in place.
Continuous experimentation evaluation so you can c closer.
It reminds me of somebody who once said the safest computer is a computer that you don't take out of the box.
Right? So you need continuous experimentation and innovation, strong partnerships with industry academia.
Now, we cannot do this alone as states.
Now, this is something that all agencies have come to realize and how we do it is still a question, but yet I think where there are forums where we can actually work with industry and academia, that's one thing that's going to happen.
Very quickly, things that five lessons, I wouldn't call them lessons, five things we're trying to do.
First, treat AI as an operational change, not as a technology trend.
We should constantly review risk assumptions and preparedness rather than treating AI as another emerging technology.
Number two, leadership engagement matters.
Now, in Singapore, we've written to the boards after my Thos came out, we wrote to the boards and said, it's your responsibility to make sure and don't pass it on to some poor IT guy and put the whole burden on him.
It has to be a leadership responsibility, set clear expectations, encourage accelerated preparedness.
We've put out an addendum in June on Adantic AI and the use of Agantic AI.
How do we secure it? Thirdly, build resilience before crisis occurs.
I will not go into it.
As I said, they don't make new vulnerabilities, they just make it faster to exploit them.
Thirdly, something that Singapore is very strongly believing is partnership rather than regulation alone.
We've got to partner, not just regulate.
That's going to be important.
Working with industry is important.
Finally, we need to learn how to harness AI responsibility.
The government should lead by example, deploying AI internally, maintaining human oversight, validating AI outputs, sharing lessons learned with industry.
It's to complete, it's a new way of looking at things.
Some things, those of us who have been doing cybersecurity for a long time, we've got to change our vision of how we see cybersecurity.
That's what AIS does.
But With the risk come opportunities as well.
I'll stop here.
Thank you very much.
Thank you very much, Director.
I would like to turn to in now maybe to follow up on the point Director Praj highlighted, which is basically the critical need for partnership with the industry.
Of course, we might have heard quite a lot about partnerships between public authorities and proprietary model providers.
But another dimension of that topic is, of course, a partnership with open weight or open source model providers as well because open source AI has been praised and highlighted for its potential to ively improving and mainstreaming AI cyber defense beyond the most skilled and resource countries.
Over the past few days, of course, all eyes were on the Kim K three from the Chinese startup Moonshot AI, which was announced as showing very impressive skills actually.
But of course, there is growing concern as well that open source or open weight models could be more easily fine tuned for conducting malicious cyber activity.
In your opinion, how can we navigate this tension to make the most actually open source AI for bolstering cyber defense.
Yeah, thanks for the invitation for the question and thanks V for stealing my thunder and introducing an experience I was going to talk about.
I will go in a slightly different direction, but very much related.
I'm an open source and open research person at heart.
As such, cybersecurity is close to my heart.
It's part of us doing our own work and also the contract of trust that we have with other open source actors, which makes me concerned to see conversations increasingly following counterproductive commercial logics and going away from a lot of the research backed information that we do have.
It's easy to see why.
Key cyber offense and commercially valuable software engineering are two sides of the same coin as has already been raised.
Given the importance of the market of the latter, this duality means that commercial providers of general purpose systems have an interest in pushing a narrative that puts them and this idea of powerful models front and center in cybersecurity conversations, even sometimes at the expense of more distributed and field tested solutions.
Even without getting into the geopolitical democratic concerns there, I will remind people of, for example, the CrowdStrike failure that we had a couple of years ago that shows what happens when you have a single point of failure or relying on a single elector.
Um, so I think it's worth going back to some technical concepts.
You can stopping it in significance, I will summarize.
One thing that's worth knowing is that of all the domains for which current AI technology holds promise, software engineering and cybersecurity are a particularly good match.
There's a rich open source culture, which means that commercial and open weight providers had probes of data to start with.
Coding tasks can be automatically verified, which means that reinforcement learning shows its full potential.
And when you have something that's already good, you have companies that have data flywheels where they can keep fine tuning their models to behave as users would like.
Stepping back from the technical lingo, what's important to take away here is that cyber and software capabilities are the easiest to develop and while front work companies do retain an edge in ease of use, the core capabilities are and will remain broadly available for all kinds of resource actors.
Um, so that's good news for competition, if you care about that.
If you look, for example, at Cursor, company that was recently acquired by Space X, they were able to build hugely successful software by relying on those open models for much cheaper than we have at frontier companies.
It's also good news, in my opinion, for cyber defense and the democratization thereof, because it means that companies can start building their own defense systems, with all of those open models.
Thankfully, we've heard some of that perspective represented here.
That's not what we're hearing, most of the time, especially since the shock event of the methods release that was, uh, happened in April.
I won't go over the full context again.
But as we might remember, Anthropic released mythos as a blog post, not as a system, where they emphasized that the powerful new models had allowed them to find host of new vulnerabilities.
What garnered less attention is that the thrust of those findings was reproduced by people using models that would fit on your cell phones so that defies this logic of power and that a lot of what was really wonderful and well done there was a great harness, access to a moderate compute capabilities, and also being able now we have this automation, to use different logics and different schedules and different automation, that's what we built our cybersecurity for.
That's something where there was a welcome boost of attention on cybersecurity issues in the age of AI, but I would say a misleading framing of this idea of powerful models.
So we could choke this up to a different of interpretations.
I have obviously different interests working on open source, but we have seen increasingly strong signs that this framing is in itself damaging.
A recent study from Collings at AIN showed that the way that mythos has been presented and the way people rely on it introduces real and consequent new vulnerabilities, where in the spirit of defending by itself, it will run basically arbitrary software.
That's one of the ways in which I think questioning those narratives is going to be something that is essential to having shared cybersecurity where do we go from there? I mentioned field tested solutions.
I will share a little bit about what's happening at Haging phase, but maybe not starting with how do we defend it? I'm going to start with how we use AI.
We are strong adopters of AI.
We have buds that are helping us gather statistics about what we do.
But we are very intentional about first never pushing any code that hasn't been understood and verified by humans.
Uh, lots of basic cybersecurity, I think, which is why the first cybersecurity incident we had to disclose came from really new types of attacks, and also this idea that you never really trust as much as people say that your coding assistance is secure and has a lot of the best practices that actually does what it's saying.
That's one really big point.
The second point is, as Jim shared, we just saw and addressed cyberattack.
We had some processing of data transfer logs.
That was all open models.
The processing of data transfer log showed some abnormalities which pinged a person.
The person who has an understanding of how this was was able to deploy open models to find all of the attack pathways that would have been unlocked using an agent by this initial attack.
As mentioned, that's something that was not only impossible to do with the guard gris that you haven't systems, but with open models, we're able to do for faster, cheaper and without having any of our secrets, our tokens, leave our infrastructure.
That's one thing that we do want to keep in mind, we're again in a privileged position.
This is probably the highest concentration of model exports outside of model developers, but that's something that we think can be an example for how the organizations address cybersecurity.
And so the one takeaway I will really push here is that with AI and with the asymmetries that have been mentioned, the security through obscurity paradigm or security through strict control paradigm goes from something that has been established as a losing proportion in open source software to really a disastrous one like makes defender even more exposed to the asymmetry that we had before.
The best thing we can do for cyber defense is first, so there I will go back on the fact that AI doesn't create new vulnerabilities.
Does when use carelessly and it's something that we're having people have a lot of pressure.
You have to produce so much code, you're not reading it anymore.
This is bringing new vulnerabilities.
Use AI in software environments with care, collaborate and share every artifact that we can, be it model or software for cyber defense.
Thank you very much, in.
I would like now to turn to Giacomo Carci Paoli.
In rightly highlighted that having redundancies is key for preventing failure, and that is also critical to have different type of stakeholders and interests involved in policy and governance discussions.
The thing is that discussion on AI and cyber tend to multiply across forums processes.
Ambassador Sap has rightly highlighted that you can't go anymore in any conference without hearing about AI and cyber.
As a result, the governance landscape seems to be more and more fragmented while the topic grows in technicality.
Of course, a question for you will be maybe, how can states remain in a position to change the norms that will govern these technologies and how S the expertise and the evidence they need come from and who is responsible basically to build them.
Thank you.
Question for the very end.
Thank you very much.
It's a pleasure to be here and thank you for inviting me and thank you to the Paris Pace Forum in France for organizing this event.
I'm not even going to try to go into the technical side of it because I think the previous speakers already did so very well and are probably better qualified than I am.
I think in the context that you described, one of the biggest risk that states are facing when it comes to shaping norms, discussing how to implement existing ones, et cetera is to consider AI and cyber as a monolithic theme.
I think if you, you're not going to be able to fix AI and cyber at that level.
Need to be a little bit more specific.
You need to detach a little bit from this big narrative out there and try to identify what are some priority areas of concern, and then eat the cake one piece at a time in a way.
Really focus and have more targeted discussions and interventions on what are some of the key priority areas that states are considering are worth discussing.
In this regard, I want also to answer part of your second questions around who should be involved? How can we get access to these expertise? I think everyone agrees that this isn't a discussion for states alone.
Now the question is, how do we allow the wealth of knowledge that exists outside of states influence, state driven discussions, formats, forum, and negotiations? Not just over two weeks ago in Geneva, there was the first edition of the global dialogue on AI governance, which is another Main initiative of the UN that of course, for reasons that we all understand, didn't want to touch the word security or international security, not even with a very long poll.
But inevitably the discussions there touched upon trustworthiness, safety, security of AI systems.
These are themes and topics that in a way don't really pay too much attention at the political divide or the political silos that the UN is trying to organize these discussions in, but really focuses on the substance.
This means that perhaps as the GMAC is starting on the same year as the global dialogue on AI governance, perhaps there is an opportunity to open a channel of, if not coordination, at the very least, communication with this other UN process where there is a lot of knowledge and expertise that is generated that could be brought into the GMAC as a way of sharing lessons, sharing trends, et cetera.
Even if for some reason this becomes complicated to do within the chambers of the GMAC, perhaps I would really invite states to allow this wealth of knowledge to influence you.
The knowledge is out there.
If you're willing to listen and if you're willing to be influenced by the amount of knowledge that is out there, there is plenty that you can then bring to the room.
This is not to discount in any way, shape, or form.
We all know how at Unityir we really champion multi stakeholder participation, but we're also realistic that even if you had the perfect modalities for multi stakeholder participation, ten days a year in that room are not going to be solving the problem.
You really need to be able to draw more of this knowledge and expertise and let this knowledge and expertise influence you at the national, sub regional, regional level, and then bring that over to you.
The second point I wanted to make is following up on what was mentioned and also by C two around.
One trend that I find it particularly concerning again, having just come back from Geneva, is that clearly AI is considered as one of the main catalyst for economic and social So everyone understands this.
There is a big push towards AI diffusion and AI adoption, and there is a significant risk that as countries are rushing to adopt this technology because of the promises that it brings, they consider the security of the systems that they are implementing as an afterthought in a way.
It is very difficult to reverse engineer security in systems once they are adopted and deployed at scale.
To me, the vulnerability of AI systems as they become more and more embedded in whichever public sector you want from health care to, I don't know, property records to the judicial system, to whatever it is, energy, water management, whatever it is, the critical sector or the critical infrastructure.
As you are embedding AI, you have to be conscious of the fact that you might be introducing new vulnerabilities to your systems.
This requires thoughtful consideration.
Why is this relevant to the GMAC? I think I see at least four different ways.
First, the security of AI systems as a potential new threat vector to consider.
Second, what should we do with AI infrastructure? We all know data centers, Clouds, these are infrastructure that it is unrealistic to foresee a scenario in which every single country in the world will have a national data center and will develop national AI capabilities.
It is most likely that access for many parts of the world would be through Cloud, will be through shared infrastructure and shared services.
How do we protect AI infrastructure? Related to this is what kind of impact will AI have on the implementation of the norms, whether it is protection of existing critical infrastructure, whether it is the norm that calls for coordinated and responsible vulnerability disclosure.
How is AI changing that context? For example.
The last point is around AI and capacity building.
Here there is, I think, two elements.
One is what was already mentioned by CIT and other speakers around how can we make sure that we can use AI for cyber defense.
How can we bring more states into the capability bubble where AI can be used to really increase their defense? That's one side.
But on the other hand, how can we make sure that we build in states the capacity to counter and respond to attacks on their AI systems? In this regard, I heard the technical community, there are some who are saying the AI incident response playbook It's just the same playbook.
It's not really new and others that say it's completely new, probably reality is somewhere in the middle, but we need to make sure that there is understanding that responding to attacks on AI systems is a capability or a capacity we cannot just take for granted.
We really need to invest in making sure that it's included.
Thank you.
Thank you so much for o.
I would like to invite you all to contribute to the moderated discussion and maybe we can start with a question that builds on coo contribution.
Coo highlighted that indeed states should be ready to hear from and be influenced by the knowledge which is produced by non governmental stakeholders.
The thing is that the evidence we have currently are coming predominantly from the private sector.
A follow up question will be then, how to build capabilities, especially from the public interest ecosystem, whether public agencies on cybersecurity, AI safety and security Institute also civil society organizations in the academia to be able actually to conduct investigations and produce knowledge that can be then channeled into international policy discussions so as to advance on an international consensus about cybersecurity implications of AI.
So if anyone has any advice or any thoughts on the conditions under which we can maybe strengthen the public interest ecosystem to produce reliable and actionable knowledge.
Nicholas from S.
I think we'll start speaking the same language in terms of how we characterize the data and then attack these things.
We need to do a rinse and repeat of what it looks like when these AI systems navigate through our networks and look at the procedures that are used.
That's how we're going to we're hunting something that's unknown essentially every time.
So we need to study and know the behaviors of how these things look and say log data, flow data.
If something is communicating way too fast that a human couldn't do it.
That's a dead giveaway.
You have some system talking to another system and just assume compromise and be paranoid.
Sure.
Could you please introduce yourself first? Thanks.
Precisely with Access now, we organized the only session that address explicitly during the global AI dialogue, the link between cyber and AI.
It was a side session.
It was not official in the program, but it was one of the officially taken side session.
I think that in these questions about the connection and the collaboration between the existing mechanism inside the UN and the global mechanism, there's a big opportunity.
I think that the comments of the previous speaker was addressing in terms of creating a standards for a being able to collect data in a more effective manner and the project that Paolo was presenting in the introduction are very relevant.
I think that there is a lot of connection that can be done in terms of the work that will continue to happen around the global AI dialogue in the intersectional part until the next one, but also something to connect with the scientific panel on AI because I think that at least my organization and a couple of more civil society organizations have been advocating for the scientific panel, maybe to have a role in creating some level of harmonization in the way in which data can be collected for measuring the different emerging threats.
We are very interested on that because as you know, in general, civil society groups are very good in collecting area on the ground, but usually it's very incidental in the sense that we collected in the formatting which is presented.
Ha, for example, the UN, either through the work of the scientific panel or any other effort that can be coordinated between the global mechanism or other initiatives that are already ongoing at the level of standardization could be very helpful in terms of validating a more uniform methodology for doing this.
This will be essential in terms of building the foundation for any further commitment with new accountability mechanism because we are able to gather the evidence in a standardized manner, Later on, the work will be easier in terms of ensuring to identify the different responsibilities of the different actors.
That's from our contribution, food for thought and I will wish this connection between these different mechanism is established in a much more clear manner inside the UN.
Thank you.
Co two, please.
I think the key thing, listening to Giacomo and others from the cybersecurity perspective is focus.
Now, what are we building capacity for? It's quite easy to go everywhere.
But essentially for cybersecurity, AI is a tool, it is a target, it is a threat.
I think we need to evolve an understanding of the AI can be used as a tool for the defenders.
AI is a target itself and AI is a threat.
Now, the thing is, do we need to reinvent everything? That's sometimes the discussion and everybody gets excited.
But from the ACN perspective, when we're implementing the norms of the 2015 GGE, We built it in such a way, what does it mean to implement these norms? What do you need to do to implement these norms? Then we added another part to it, which is what capacities do you need to build to implement this norm in order to act out this way? Perhaps we need to focus and come back.
Why don't we come back to the 2015 GGE norms which people are already, states are already working on and ask ourselves a question, what does this norm mean for AI as a tool, a target or a threat? Just a thought.
Thank you very much.
Thank you for international government information across the university.
I'm coming to this room and trying to understand how we impose norms on private sector on the private sector, and these companies are going to be so powerful that it's very, very hard to en these curriculum.
We're talking about norms on states, but the states aren't able to regulates that pose the threat.
And I'm just wondering if anyone has reg.
I think there is quote.
There is a need for articulation within the UN.
There is a need of articulation between processes or policy discussions that are, of course, targeting states conduct with those targeting regulatory activities of private actors as well.
Of course, the global mechanism represent an opportunity in this respect, Al.
Every remain to be deployed and established when it comes to the practical modalities of such global mechanism.
I would like to come back on that right after, but maybe turn first to sin.
Yes.
So one thing that I do really want to share that first my heart that has been answered to both of those questions about per information that has to have the.
One of the most helpful things I find about open model is that if you have one AI system, that is open, transparent, documented and that does something similar to what the frontier does, even if it's behind by six months, that unlocks the entire academic world's collaboration on figuring out what the science is behind what we need to do.
We've been able to do that for environmental costs.
We're able to do that right now when we're pushing back against some of those narrative that it's a powerful model versus it's a very well put together model.
That's also something that in terms of power, a lot of the power comes from these epistemic positions of we're the only ones who can tell you what you can do with them anyway.
Having those open shared alternatives that are maximally transparent have these open science stats makes a huge difference.
It's not a full answer.
One small thing I wanted to add also is about in terms of standards, doing no worse than we did with the Internet protocols is a pretty good target.
We are talking about not everybody is going to have data centers, but not all AI needs to be computer.
Those are things that we can actually track to the resources that we have for insurance infrastructures.
Thank you.
No achievement in this respect to the French presidency of the G seven with a couple of deliverables on that topic, but coming back again on the articulation of different processes including of course the G seven with the UN, the discussion on state conduct with those on regulation of private sector, for instance, I know that I feel that como you would like to maybe follow up on that here.
Yeah.
I just wanted to try to at least partially answer the question.
It is peripheral to the cyber specific issue.
But for example, at Unidir we launched earlier this year, an initiative that is the framework for the development of responsible industry behavior in the context of AI and the military domain.
It's a mouthful, but the idea is, can we try to co develop with states and industry together? Framework that articulates what responsible behavior for industry looks like because we have norms for states, but can we find an equivalent set of norms for industry? The goal there is not really to develop new commitments, but is try to help industry and states manage each other's expectation in terms of what it is reasonable to expect from industry in terms of responsible behavior in the development, integration, and deployment of AI and on the other in the military domain, in that case, but it can be transferred to the cyber domain as well.
On the other hand, what should states we want states to be intelligent customers and be able to guide their decisions on whether or not to work with certain industry players based on their behavior.
We're trying to create this interface between the two that could potentially be useful also in the context of cyber.
The form responses.
Thank you for organizing the round table.
It's really quite challenging time for all of us.
As was mentioned by a couple of the speakers about AI.
It's not just about technology.
It's about how we deal with this technology.
It offers opportunities and challenges, and that was mentioned.
Among the challenges is the challenge from again, the question about regulating AI.
That is really an open ended question.
It is more about better understanding, better cooperation and bridging.
That's where the comment from Giacomo about the Unitar effort to bring this bridge and it has to be consistent.
I think we are in a place.
I was 14 years back, I was part of the UNGGE and I was part of the GGE that also accepted the norms.
And developing the norms and the interpretation is quite interesting exercise.
But the challenge is how to make states understand what their roles and responsibilities and to deal with this in a way that is also inclusive.
I present now a stakeholder, a leading organization in cybersecurity and quite a few of those organizations were blocked from participation.
The challenge is, do we see that we can try to have a consistent, continuous inclusive and open mechanism for cooperation between states, between industry because the challenges will keep ongoing.
We will face more challenges moving forward.
I think Jim earlier mentioned a few challenges in cybersecurity.
I did my PhD in AI 30 years back and I've seen how AI evolved.
I've been in the cybersecurity industry for over 30 years as well.
So I've seen how those, you know, crossings happen.
At first, we bring in, you know, all the professionals to talk about those issues.
However, states are not there.
Having this bridge, I hope that we can recommend moving forward with you, I mean, with the leadership of, you know, organizing this roundtable or other events for creating those bridges in a more consistent and, you know, way that is inclusive and open and effective at the same time.
Thank you very much.
I completely agree that first should be fully involved in such discussions because a part of the problem is also linked to incident reporting.
Yes, I'm afraid I will have to wrap up the discussion, but we will have a couple of remarks from Sarvel surgery in a pre record statement from the associate of the French Oteri Safety with which the foreigners partner to precisely build a workstream on assessing the bottlenecks the public interest ecosystem face in producing knowledge specifically.
Yeah.
No, no, I'm sorry.
I guess we have a couple of technical problems, so maybe in waiting for this issue to be fixed, I would just leave the floor to Joyce Acme, which will host actually another side event on AI cyber on Wednesday.
Yes, if you could tease a bit the event, which is almost full if I'm correct, but Thank you very much Pablo.
I'm talking before I do so I want to say to you announce solutions to represent form and late to coordinate as developing a.
Thank you.
Demint missions of Latvia and Estonia to the UN would be a technical briefing on frontier AI and cyber threat landscape.
It will happen this Wednesday as Pablo mentioned 115-230 at conference room C here, just 2 minutes away from this room.
It builds very much on the discussion that we've been having today.
It could be briefing, as I mentioned, delivered by CrowdStrike, who have been at the heart of many discussions relevant to this and we'll tackle really how the technology is changing the threat landscape.
What are the opportunities for defense, but also what should states know at this highly important moment that we are living in technological development.
We wanted to organize this event because what all of you have mentioned, the way in many ways I is fundamentally challenging cybersecurity as we know it and demystify some of the misconceptions as well.
So we will hear from CrowdStrike.
We also have remarks from the ambassadors hosting, but also the Chair Ambassador Lopez, who will be joining us as well.
As Paola mentioned, we expect this to be a very busy event, so it would be first come first serve, and I hope to see many of you there.
Thank you very much, Fabra.
Thank you, Choice, unfortunately we are doing this.
With this said, I would like to turn for some final remarks to the ambassador Chaps, that will close the event because I am afraid I need to free you in a couple of minutes.
Thank you, apologies for the technical glitch.
I'll be brief if we don't have that much time, but I just wanted to wrap up hearing the discussion.
I think there are a few things we all agree on that we have a lot of work to do, but the three things I have in mind is one, the scale and the speed at which the technology is transforming our society requires for multi stakeholder collaboration.
Um, both to enhance the opportunities.
I think it was important to hear that point, but also to tackle the risks.
Two, this is not something we can just figure out on our own.
And so we need the industry to set up standards and norms.
We've done that before.
I think we have reason to be hopeful.
We've done that with the Palm process, which actually today is also looking at the impact of AI, but more of the process, how we brought the industry together, a group to agree on how to address some of those challenges is a process we've seen work.
We friends really want to continue pushing in that direction and looking at this as a potential example on how we could address those challenges.
Three, we were very aligned with all the comments that have been made on the role of the UN and the intersection of those conversation in so many different instances.
Some of us were at the Geneva AI dialogue last week.
And for sure, there are some relationship and gatherings that needs to happen between the work we're doing here and the work that's done at the UN dialogue because there is no way we can keep both themes separate in the world we're knowing.
So we're very much in support of looking at how we can get all the work contribute to each other, and we thank you for bringing that point because we think it's fundamental that all instances pushes in the same direction.
Thank you.
Thank you, Isabel, and thank you all for your participation today, and I just need to wish you a good week of negotiation.
Thank you very much.
Navigating the Challenges of AI in Cyberspace
Roundtable on the occasion of its first substantive plenary of the Paris Peace Forum entitled: Navigating the Challenges of AI in Cyberspace: From Fragmented Evidence to Collective Readiness
Description
As advanced AI changes what is possible in cyberspace, States face a challenge of capacity: reading a fast-moving threat as it forms, while drawing on the same models for their own defence. Public-interest expertise at this intersection remains unevenly developed across the world. On the occasion of the first substantive plenary of the Global Mechanism on ICTs, the Paris Peace Forum and France convene this roundtable to advance a fair benefit-sharing of AI in cybersecurity.
Full transcript en transcript
Machine-generated · not human-reviewed · verify against the official record before citing or relying on this transcript
Session Summary Auto generated from session transcript
Synthesis hasn't been generated for this session yet.
The summarize pipeline runs after the English transcript is available.
Machine-generated · not human-reviewed · verify against the official record before citing or relying on this summary