Roundtable on the occasion of its first substantive plenary of the Paris Peace Forum entitled: Navigating the Challenges of AI in Cyberspace: From Fragmented Evidence to Collective Readiness
As advanced AI changes what is possible in cyberspace, States face a challenge of capacity: reading a fast-moving threat as it forms, while drawing on the same models for their own defence. Public-interest expertise at this intersection remains unevenly developed across the world. On the occasion of the first substantive plenary of the Global Mechanism on ICTs, the Paris Peace Forum and France convene this roundtable to advance a fair benefit-sharing of AI in cybersecurity.
Machine-readable formats: Plain text · JSON
Transcripts available through this tool are created by using automatic speech recognition and are not official records nor official documents of the United Nations. Official records and official documents are available on the Official Document System of the United Nations. Learn more
Thank you, everyone. Hi, thank you, everyone. Can you hear me well? Hi everyone. Thank you for joining today for what is one of the first side events of the first plenary of the Global Mechanism. I am Pablo Reis from the Paris Peace Forum, and today we partnered with colleagues from the French Ministry for Europe and Foreign Affairs to convene this roundtable on a matter which actually became quite a buzz topic over the past few months, and that you might hear quite a bit actually over the next few days, namely AI in cyber, AI for cyber, AI misused by cyber adversaries, and the cybersecurity of AI systems themselves, which was quite a bit a niche topic when we at the Paris Peace Forum started digging into this matter back in 2024. Has become a genuine geopolitical object since 2026. I won't recall the very latest developments on the matter, which I'm sure you are well aware of, but I would just like to point out that the notion of AI misuse, the misuse of AI in cyberspace, has been put at the core of many rationales underlying some measures at the government or at the companies level, especially to justify some stage of structured access, meaning access restriction to frontier proprietary models. And such modalities tend to become the new normal, even if in this space we should refrain from making too affirmative forecasts. The thing is, as it is often the case for high-profile, quickly evolving technological challenges, that the level of concern is at least as high as the degree of certainty we are all navigating when it comes to the actual cyber capabilities of advanced AI models, but also the modalities of AI uptake in cyber operation. As a result, any corporate or any government action can only be driven by evidence. The evidence gap we are facing is a challenge that no single country, no single organization can bridge alone, and this is why the need for cross-border, cross-sectoral, and of course multi-stakeholder cooperation is more critical than ever. This is why the Paris Peace Forum has launched earlier this month, this month, a new international initiative called INTECH, the Integrated Network for Trusted AI and Cyberspace, that aims to gather expertise across policy and technical circles spanning cyber and AI security communities, precisely to find avenues to overcome structural obstacles so that reliable evidence can emerge to inform international governance efforts on the matter. Today's discussion fits right into this endeavor, and even if we could have chosen to engage in other forums or other processes than the global mechanisms, because there are more and more initiatives in that sphere and that's a challenge in itself, we believe that it's still much needed to address this question at the UN in general and within the global mechanism in particular, and for 2 main reasons. The first reason is that the vast majority of states might have felt that they were a little bit left aside from the latest debates about AI and cyber that tended to be framed either around the transatlantic relationship or around a race between the most advanced powers. But if we agree all on the premise that AI may be one of the most transformative and systemic developments in global cybersecurity and stabilities, then at some point, All states should be at the table. The second reason is that, building on the OEWG achievements, the global mechanisms represent a real opportunity for states to advance on AI, on ICT capacity building. And the challenge at stake today is actually, first and foremost, a matter of capacity, the capacity of most states to see the AI-driven cyber threat landscape as it evolves, and the capacity to bolster defense accordingly, including, of course, by harnessing AI in that respect. Because let's not forget that AI holds an incredible potential in improving cybersecurity and cyber defense. And the key question I will invite you to reflect on as part of today's discussion is precisely how can we collectively progress towards a fair global benefit sharing of AI in cybersecurity. And to kick off the discussion, I will first give the floor to Mrs. Clara Schappaz, Ambassador of France for Digital Affairs and Artificial Intelligence, for some introductory remarks. Ambassador, the floor is yours.
Thank you. Thank you. Thank you so much. And thank you for helping us organizing this event. We're very glad to see how many people we have in the room. And also, most importantly, not only people from different states and stakeholders, but also from the private industry. So thank you for all the friends that joined today, because we strongly believe that's something we should only look at with multiple stakeholders looking at the same problem. I mean, you've started saying that when you worked on that topic a few years ago, it was quite niche. I think there's probably not a single international event now that doesn't talk about AI. So there's been some progress made on that front. And obviously, a lot of that is thanks to a lot of people in this room. And it's very important for France to be able to have this meeting in a moment where AI is basically reshaping everything— access to education, to information, to health, to science. The transformation we're living is probably so unprecedented for the scale and the speed at which it's addressing our world, and obviously as well when it comes to national security and cybersecurity. And so to us, it was very obvious to take the occasion to have so many people gathered here in the UN to have this type of discussion ahead of the Paris Peace Forum, which will obviously continue in that direction in just a few months back in Paris. We know that Um, the— this technological revolution is completely reshaping how strategic balances and forces are playing in the world we're knowing. And in a moment where we're seeing so much fragmentation, conflicts happening both physically and in the cyber world, we do believe that cooperation is where we should unite when it comes to addressing those challenges. We're confronted, as everyone knows in this room, to growing asymmetry especially with AI, between all the states, but also between offense and defense. And we think it's key to understand, to respond to those challenges together collectively. And to this end, we think that strengthening everyone's capability can only be the way to more globally cooperate on those issues. What we want to focus on today, and we'll hear from everyone in the room in a minute, is First, the assessment that we've seen. I mean, everyone has seen this news, but in a world where AI can basically power our hospital, our education system, national security agenda, defense system, but in this world where it can also be a world where AI systems can be switched off from one hour to the other on unilateral decision sometimes. We basically have to face a reality, which is that it has become both an infrastructure of progress, but progress is only sustainable for those who can control this infrastructure, is only stable for those who can control this infrastructure. And so people who are only accessing it are taking huge, immense risk when it comes to stability. 2, the answers that we think we must bring to it is basically how to build a path for ourselves. A third way where France has been really pushing for quite a long time, we hosted, for those of you who were here, the AI Action Summit back in February 2025, where the President Emmanuel Macron basically gave, you know, international resonance to this movement to say that only through international cooperation, states would be able to build their own sovereignty. And that when we're confronted with such a technology, we basically need to address it internationally. Also, when it comes to mitigating the risks, the response to frontier models challenge cannot be national fallback. President Macron also hosted G7 summit because France is very proud to lead G7 this year. And in the Evian summit, we gathered leaders from G7 and beyond. We also had the immense privilege to have the company of India, Kenya, Egypt, and Brazil. And during this summit, the leaders and the tech CEOs discussed together that rather than playing divide, we need to play together accordingly to address some of those challenges. We must depend the implementation of the frameworks for responsible behavior and guarantee that the use of those technologies are not used by malicious actors. And to do that, President Macron reaffirmed his conviction that we need to build cooperation. It will help not only preserve national security, but also international stability in cyberspace. The conclusion to this discussion and to all the work we're trying to push forward, including this discussion when it comes to the UN here today, is that all the work we're carrying out during the Global Mechanism is important because it can help us move forward, deliver concrete, actionable solutions, which we need more than ever. And so we think that this discussion, as I said, is not something we can only discuss within states, but it's very important that we gather all the actors in the same room, as we did during the AI Action Summit, as we did during the G7 Evian meeting, as we're doing today. Only by mixing expertise point of views, and getting everyone in the same room, it's how we can basically address some of the challenges we're facing. So it's the meaning of the event we're holding today. Thank you again to the Paris Peace Forum for bringing us together, and for all the participants who've taken a bit of their precious time to come with us in the UN today. Thank you for all the work you're going to present to us, and please count on our support.
Thank you very much, Ambassador. And to frame the discussion, we will have selected initial contributions from, from 4 persons that I would like to thank for their presence today. Jim Rivis, the CEO of the Cloud Security Alliance. The Director for International Cyber Policy at the Cyber Security Agency of Singapore. The Head of the Security and Technology Program at the United Nations Institute for Disarmament Research. And last but not least, Yacine Jannit, who is Head of Machine Learning and society at Hugging Face. And I would like maybe to start with you, Jim, to maybe brief the audience on the current state of play when it comes to what we call the AI-cyber nexus. The Cloud Security Alliance, which is one of the largest alliances actually of practitioners from cybersecurity providers worldwide, has released following the announcement of Anthropic Mythos, a brief highlighting some of your concerns. And at the top of that was, of course, the AI-driven vulnerability storm we might expect soon. And we had a couple of discussions afterwards. And you told me a couple of times that actually, of course, the misuse, potential misuse of AI capabilities by cyber adversaries was a matter of concern. But maybe the most immediate one was, let's say, the potential disruption of AI on the, let's say, the cycle of vulnerability discovering and patching as well. So if you could maybe develop a bit on that.
Thank you very much for joining us. I have been in cybersecurity for 35 years, and when I started, probably you could fit the entire global industry in a room of this size. So it's just a measure of how important the digital world has become, and this is absolutely the most transformed transformational technology in our industry, and it's moving so fast. And I'm assuming it is for every sector everywhere. So, as we have looked at this progression and the idea of scaling laws and the compute and data creating this huge change, we are characterizing this as we're dealing with 2 exponentials right now, which is a challenge. One is the exponential growth in the capability of AI models to get smarter and smarter and smarter. And the, the Mythos model, for example, was not even trained to be good at cybersecurity. It was trained to be good at software coding. And this is an emergent feature. And we're going to see a lot more emergent features. The other exponential is the tremendous growth in agentic AI, AI agents operating with autonomy. And so, that is creating this sort of scalability and this capability, both for good and for bad, that we have to address. So, there's 3, like, very big moments that happened this year. First, there was the OpenCLAW sort of moment where people started to just install agents to do a lot of things and take over their computers. The second big one was the Mythos release in April where this model was released that showed this incredible capability to be able to find vulnerabilities in any type of software, open source, closed source, doesn't matter. It can find it, can find it quickly. And this notion where we talk about, hey, a zero-day vulnerability, something that will start immediately being used by attackers, that are— that used to be very rare are now going to be very commonplace. So, how— what we did is we activated a lot of security experts, like, literally over a weekend, 200 chief information security officers from, like, really, like, important companies. And we worked on a document to talk through this, which is the main thing I want to characterize. It is that we are going to have what we call this upstream vulnerability storm. So, all of the software we depend on, open source, closed source, is going to be examined by malicious attackers for vulnerabilities, and then they will attack it. And so, we are forced into this dilemma of needing to go very rapidly find all those vulnerabilities themselves. And if you didn't follow— if you don't follow this sort of news, like, this is just an example of that consequence from Mythos in April, is Microsoft had its, like, hugest by an order of magnitude Patch Tuesday. I think it was last week. Just many, many CVEs, things like that. So, what we've, like, are thinking about this is we're going to find a lot of these vulnerabilities, and the challenge then is downstream, how we get enterprises to be able to manage this, how we get what we call organizations below the security poverty line. Think about hospitals, schools, municipal governments, in addition to, like, the critical infrastructure within any industry. So, we have to have strategies that go beyond just automatically patching things all the time, which can also cause disruption. Like, if you're using software to control a pipeline or a rocket launch or things like that, you have to be very careful about patching vulnerabilities all the time. So, we have to have other strategies. We talk about zero trust, which basically means you assume that anything can be breached. And if you assume that, you can build strategies that harden systems, look at incident response, look at a lot of other areas. In order to do this correctly, what we had said in the paper is it's fundamental that cybersecurity use AI, agentic AI, to be able to run at machine speed. You got to fight fire with fire, and it's incumbent upon us that cybersecurity have this collective defense, this communications we're talking about, and we have to modernize, and we have to do it very rapidly. The third big thing that happened, just as a final thing, is actually a colleague on the panel who I haven't met. Hugging Face had an issue which they handled wonderfully, and it's just terrific, and hats off to them. On July 16th, they reported that they were attacked by autonomous agents that got in there and got a foothold. And the way they found it, actually, and resolved it— and it's amazing how quickly they've written all about this— was by using agentic cybersecurity agents to be able to go find all of this information. One of the problems they ran into is because of the guardrails on the Frontier models, they weren't able to use it for forensics analysis. They weren't able to use the Frontier models, so they had to go use the open-source, open-weight models, which I think the one they used was actually one that was originated by China, is where it comes from, and then it was posted up there. So, they did a wonderful job, but that's the next big moment. We found Mythos, we could find all the vulnerabilities, and now we can see the malicious attackers, are using agentic AI to create automated attacks, escalate that within organizations. And that's a huge thing. We're actually going to spin up a closed-door meeting this Thursday with Chatham House Rules for CISOs to talk about, like, what we all know about this. So, it's here. It's very powerful. Our incumbent responsibility is to build societies that are resilient to these types of attacks and developments. And so, thank you for letting me be here, and I think this is just very important, the discussion we're going to have.
Thank you very much, Jim, and we will indeed dig a bit deeper into the open-source dimension with Yassine Jannid. But before that, I would like to turn to Director Paul Raj, maybe to follow up quickly on a question Jim highlighted, which is basically how can public authorities, public organizations manage the disruptive dimension of AI and cyber, but also, and more broadly, what does it take for an organization, for a national authority, a public cybersecurity agency such as the CSA, to conversely techs make the most of AI, from threat analysis to its own defense. Maybe if you could share what CSA recent work in this area could be maybe shared or transferred to partner agencies. The floor is yours. Thank you.
I'd like to thank our colleagues from France and This is just sharing from Singapore's perspective. I thought it would be useful to share from a moment in time in last October when we— many of you know that Singapore hosts an annual Singapore International Cyber Week, and on the sidelines we have ASEAN Ministerial Conference on Cybersecurity. And so we had organized an agenda, we had settled everything at a staff level, and then Just before the conference started, we saw the ministers from ASEAN standing together and speaking very excitedly with my minister, and that's always a worrying moment when you see our ministers getting excited because we don't want them to be. Please don't repeat this outside this room. But the truth is, and I went in there because I was the organizer, and they were all like, yes, we should speak about AI and cyber. I thought that it would be useful not just to share the thoughts from Singapore but also from the region, what the agencies are thinking and what is happening, because many countries around the room in the plenary are thinking about these things. 5 observations and 5 quick lessons. I'll try not to be too long, but I appreciated Clara's points that she made. That actually AI and cybersecurity, it has changed the way that we think about cybersecurity. That is the fundamental— there's a fundamental shift. AI is both a threat multiplier as well as a defense multiplier. There's an opportunity part of it which many, many agencies are looking at. So the goal is not to simply defend against AI, but to harness AI, to use AI to defend better, and faster. So what are some of the things that we are thinking about, some of our colleagues around the region are thinking about? 5 points. The first is that vulnerabilities that, you know, to recognize the changing threat landscape. The fact is that AI is fundamentally changing. Frontier AI, which was just shared, is fundamentally changing cyber operations. It's not just theoretical, not just improving existing attacks. It is improve— it is changing it, accelerating attacks in 3 ways: speed, scale, accessibility. Vulnerabilities that took weeks to exploit may now be weaponized within days or even hours, reducing defenders' response windows. So from an agency point of view, this is a first starting point. The second thing is that then what do we do? I mean, if the guys on the other side are using AI, then we will need to use AI ourselves. The second point, to leverage AI as a force multiplier for defenders. Government agencies are thinking of how to use AI throughout cyber operations— threat intelligence analysis, vulnerability prioritization, malware triage, security operations center investigations, incident response. My colleagues back home are working on all of this, but it's not— it's the beginning. There are lots of things that we need to consider as we allow AI to use all of this because You need to trust AI, first of all, isn't it? You don't just let AI loose on AI and then hope that everything turns out well. And so there is a need to see how AI is being used in defense and cyber operations and how to make sure that it's trustworthy. I think some of these things were covered. But the third thing we recognize is that we need to strengthen cyber fundamentals. There's a third point out of 5 points that AI finds weaknesses faster, but it does not create always entirely new ones. It does not create new vulnerabilities, but the point is that it finds weaknesses faster. So we have priorities. We still have priorities like asset visibility, secure by design, some of which has been covered, identity security. So it's not to say that it's a brand new thing. But the things that we can do and continue to do to build our defense. Fourth, we have to build resilience for compressed attack timelines. I've just covered that. How do we work with different stakeholders, industry who are looking after critical information infrastructure, industry players, those who are involved in development of AI to do this? And in this point, some of us are thinking very carefully about operational technology environments, often which cannot be patched quickly, making early detection resilience particularly difficult. And finally, and this is something we don't talk about all the time, agencies need to think about investing in people, governance, and partnerships. Technology alone is not sufficient. We will need AI-literate cyber professionals. Many countries need such people. Governance for responsible AI use needs to be put there in place. Continuous experimentation, evaluation, so you can't close up. It reminds me of somebody who once said, the safest computer is a computer that you don't take out of the box. You need continuous experimentation and innovation. Strong partnerships with industry and academia. Now, we cannot do this alone as states. Now, this is something that all agencies have come to realize, and how we do it is still a question, but yet I think where there are forums where we can actually work with industry and academia, that's one thing that's going to happen. Very quickly, 5 things that— 5 lessons. I wouldn't call them lessons, 5 things we're trying to do. First, treat AI as an operational change, not as a technology trend. We should constantly review risk assumptions and preparedness rather than treating AI as another emerging technology. Number 2, leadership engagement matters. Now, in Singapore, we've written to the boards after MITRE's came out. We wrote to the boards and said, it's your responsibility to make sure, and don't pass it on to some poor IT guy and put the whole burden on him. It has to be a leadership responsibility. Set clear expectations. Encourage accelerated preparedness. We have put out an addendum in June on agentic AI and the use of agentic AI. How do we secure it? Thirdly, build resilience before crisis occurs. I will not go into it. As I said, they don't make new vulnerabilities, they just make it faster to exploit them. Thirdly, something that Singapore is very strongly believing is partnership rather than regulation alone. We've got to partner, not just regulate. That's going to be important. Working with industry is important. And finally, we need to learn how to harness AI responsibly. Government should lead by example, deploying AI internally, maintaining human oversight, validating AI outputs, sharing lessons learned with industry. So it's— to complete, it's a new way of looking at things. Some things, those of us who have been doing cybersecurity for a long time, we've got to change our vision of how we see cybersecurity. That's what AI does. But with the risks come opportunities as well. I'll stop here. Thank you very much.
Thank you very much, Director. I would like to turn to Yacine now, maybe to follow up on the point Director Ponnraj highlighted, which is basically the critical need for partnership with the industry. And of course, we might have heard quite a lot about partnerships between public authorities and proprietary model providers, but Another dimension of that topic is, of course, the partnership with open weights or open source model providers as well, because open source AI has been praised and highlighted for its potential to precisely improving and mainstreaming AI cyber defense beyond the most skilled and resourced countries. This over the past few, few days, of course, all eyes were on Kimi K3 from the Chinese startup Moonshot AI, which was announced as showing very impressive skills, actually. But of course, there is growing concern as well that open source or open weight models could be more easily fine-tuned for conducting malicious cyber activities. So in your opinion, Yacine, how can we navigate, you know, this tension to make the most actually of open weight, open source AI for bolstering cyber defense?
Yeah, thanks for the invitation and for the question. And thanks, Jim, for stealing my thunder and introducing an experience I was going talk about. Okay, so I will go in a slightly, slightly, I think, different direction, but very much related. I'm an open source and open research person at heart. As such, cybersecurity is close to my heart. It's part of us doing our own work and also the contract of trust that we have with other open source actors, which makes me kind of concerned to see conversations increasingly following counterproductive commercial logics and going away from a lot of the research-backed information that we do have. So, it's easy to see why. Cyber offense and commercially valuable software engineering are two sides of the same coin, as has already been raised. So, given the importance of the market of the latter, this duality means that commercial providers of general-purpose systems have an interest in pushing a narrative that puts them and this idea of powerful models front and center in cybersecurity conversations, even sometimes at the expense of more distributed and field-tested solutions. So even without getting into the geopolitical or democratic concerns there, I will remind people of, for example, the CrowdStrike failure that we had a couple years ago that shows what happens when you have a single point of failure or relying on a single actor. So I think it's— worth going back to some technical concepts. You can stop me at any point in seconds. I will summarize. One thing that's worth knowing is that of all the domains for which current AI technology holds promise, software engineering and cybersecurity are a particularly good match. There's a rich open-source culture, which means that commercial and open-weight providers have troves of data to start with. Coding tasks can be automatically verified, which means that reinforcement learning shows its full potential. And when you have something that's already good, you have companies that have data flywheels where they can keep fine-tuning their models to behave as users would like. So stepping back from the technical lingo, what's important to take away here is that cyber and software capabilities are the easiest to develop. And while frontier companies do retain an edge in ease of use, The core capabilities are and will remain broadly available for all kinds of resource actors. So that's good news for competition, if you care about that. So if you look, for example, at Cursor, a company that was recently acquired by SpaceX, they were able to build hugely successful software by relying on those open models for much cheaper than we have at frontier companies. It's also good news, in my opinion, for cyber defense and the democratization thereof. Because it means that companies can start building their own defense systems with all of those open models. Thankfully, we've heard some of that perspective represented here. That's not what we're hearing most of the time, especially since the shock event of the Mythos release that happened in April. I won't go over the full context again, but as you might remember, Anthropic released mythos as a blog post, not as a system, where they emphasized that the powerful new models had allowed them to find hosts of new vulnerabilities. What garnered less attention is that the thrust of those findings was reproduced by people using models that would fit on your cell phones, so that defied this logic of power, and that a lot of what was really wonderful and well done there was a great harness access to moderate compute capabilities, and also being able, now that we have this automation, to use different logics and different schedules and different automations. That's what we built our cybersecurity for. So that's something where there was a welcome boost of attention on cybersecurity issues in the age of AI, but I would say a misleading framing of this idea of powerful models. So we could chalk this up to a difference of interpretations. I have obviously different interests working on open source, but we have seen increasingly strong signs that this framing is in itself damaging. A recent study from colleagues at AI Now showed that the way that Mythos has been presented and the way people rely on it introduces real and consequent new vulnerabilities, where in the spirit of defending by itself, it will run basically arbitrary software. So that's one of the ways in which I think questioning those narratives is going to be something that is essential to having a shared cybersecurity defense that works. Okay. So where do we go from there? And I mentioned field-tested solutions. So I will share a little bit about what's happening at Hugging Face, but maybe not starting with how do we defend it. I'm going start with how we use AI. We are strong adopters of AI. We have bots that are helping us gather statistics about what we do. But we are very intentional about first never pushing any code that hasn't been understood and verified by humans. Lots of basic cybersecurity, I think, which is why the first cybersecurity incident we had to disclose came from really, really new, really new size of attacks. And also kind of this idea that you never really trust as much as people say that your coding assistant is secure and has all of the best practices, that it actually does what it's saying. I think that's one really big point. The second point is, as Jim shared, we just saw and addressed a cyberattack. So we had some processing of data transfer logs. That was all with open models. The processing of data transfer log showed some abnormalities, which pinged a person. The person who has an understanding of how that was, was able to deploy open models to find all of the attack pathways that would have been unlocked using an agent by this initial attack. So as mentioned, that's something that was not only impossible to do with the guardrails that you have on commercial systems, but with open models, we're able to do it faster, cheaper, and without having any of our secrets or tokens leave our infrastructure. So that's one thing that we do want to keep in mind. Like, we're again in a privileged position. This is probably the highest concentration of model experts outside of model developers. But that's something that we think can be an example for how other organizations address cybersecurity.
security.
So the one takeaway I will really push here is that with AI and with the asymmetries that have been mentioned, the security through obscurity paradigm, or security through strict control paradigm, goes from something that has been established as a losing proposition in open source software to really a disastrous one, like makes defenders even more exposed to the asymmetries that we had The best thing we can do for cyber defense is first— so there I will go back on the fact that AI doesn't create new vulnerabilities. It does when used carelessly. And it's something that we're having people have a lot of pressure, right? You have to produce so much code, you're not reading it anymore. This is bringing new vulnerabilities. So use AI in software environments with care. Collaborate and share every artifact that we can. be it model or software for cyber defense.
Thank you very much, Yassine. And I would like now to turn to Giacomo Percipaoli. Yassine rightly highlighted that having redundancies is key for preventing failure, and that is also critical to have different types of stakeholders and interests involved in policy and governance discussions. The thing is that discussions on AI and cyber tend to multiply across forums, processes, and Ambassador Chapa has rightly highlighted that you can't go anymore in any conference without hearing about AI and cyber. As a result, the governance landscape seems to be more and more fragmented, whilst the topic grows in technicality. And so, of course, a question for you will be maybe, how can states remain in a position to shape the norms that will govern these technologies? And where should the expertise and the evidence they need come from? And who's responsible, basically, to build them?
Thank you.
I'll save the big question for the very end. Thank you very much. No, it's a pleasure to be here and thank you for inviting me and thank you to the Paris Peace Forum and France for organizing this event. I think it's— I'm not even going to try to go into the technical side of it because I think the previous speakers already did so very well and are probably better qualified than I am. But I think in the context that you described, one of the, of the biggest risks that states are facing when it comes to shaping norms, discussing how to implement existing ones, etc., is to, to consider AI and cyber as a, as a monolithic theme. I think it's— if you try, you're not going to be able to fix AI and cyber at that level. You need to be a little bit more specific. You need to detach a little bit from this kind of a big narrative out there and try to, to identify what are some priority areas of concern, and then, you know, eat the cake one, one piece at a time, in a way. So really focus and have more targeted discussions and interventions on what are some of the key priority areas that states are considering are worth discussing. And in this regard, I want to also to answer part of your second questions around who should be involved, how can we get access to this expertise. I think everyone agrees that this isn't a discussion for states alone. Now, the question is, how do we allow the wealth of knowledge that exists outside of states' influence state-driven discussions, formats, forum, and negotiations. And, you know, not only— well, just over 2 weeks ago in Geneva, there was the first edition of the Global Dialogue on AI Governance, which is another main initiative of the UN that, of course, for reasons that we all understand, didn't want to touch the word security or international security, not even with a very long pole. But inevitably, the discussions there touched upon trustworthiness, safety, security of AI systems. These are themes and topics that in a way don't really pay too much attention at the political divide or the political silos that the UN is trying to, to organize these discussions in, but really focuses on the substance. And this means that perhaps As the GMAC is starting on the same year as the Global Dialogue on AI Governance, perhaps there is an opportunity to open a channel of, if not coordination, at the very least communication with this other UN process where there is a lot of knowledge and expertise that is generated that could be brought into the GMAC as a way of sharing lessons, sharing trends, etc. And even if for some reason this becomes complicated to do within the chambers of the GMAC, perhaps I would really invite states to allow this wealth of knowledge to influence you. The knowledge is out there. If you're willing to listen and if you're willing to be influenced by the amount of knowledge that is out there, there is plenty that you can then bring to the room. And this is not to discount in any way, shape, or form— you all know how at UNIDIR we really champion multi-stakeholder participation, but we're also realistic that even if you had the perfect modalities for multi-stakeholder participation, 10 days a year in that room are not going to be solving the problem. So you really need to be able to draw more of this knowledge and expertise and let this knowledge and expertise influence you at the national, sub-regional, regional level, and then bring that over to you. The second point I wanted to make is kind of following up on what was mentioned and also by Situ around one trend that I find it particularly concerning, again, having just come back from Geneva, is that clearly AI is considered as one of the main catalysts for economic and social development, right? So everyone understands this. There is a big push towards AI diffusion and AI adoption. And there is a significant risk that as countries are rushing to adopt this technology because of the promises that it brings, they kind of consider the security of the systems that they are implementing as a kind of a— as an afterthought in a way. It is very difficult to reverse engineer security in systems once they are adopted and deployed at scale. So to me, the vulnerability of AI systems as they become more and more embedded in whichever public sector you want, from healthcare to, I don't know, property records to the judicial system to whatever it is, energy, water management, whatever it is, the critical sector or the critical infrastructure, as you are embedding AI, you have to be conscious of the fact that you might be introducing new vulnerabilities to your systems. And this requires thoughtful consideration. And why is this relevant to the GMAC? Um, I think I see at least 4 different ways. First, the security of AI systems as a potential new threat vector to consider. Second, what should we do with AI infrastructure? We all know data centers, clouds, like these are infrastructure that allow— it is kind of unrealistic to foresee a scenario in which every single country in the world will have a national data center and will develop national AI capabilities. So, it is most likely that access for many parts of the world would be through cloud, will be through shared infrastructure and shared services. How do we protect AI infrastructure? Related to this is what kind of impact will AI have on the implementation of the norms? Whether it is protection of existing critical infrastructure, whether it is the norm that calls for coordinated and responsible vulnerability disclosure. How is AI changing that, that, that context, for example? And the last point is around AI and capacity building. And here there is, I think, 2 elements. One is what was already mentioned by, by Situ and other speakers around how can we make sure that we can use AI for cyber defense? How can we bring more states into the capability bubble where AI can be used to really increase their defense? That's one side. But on the other hand, how can we make sure that we build in states the capacity to counter and respond to attacks on their AI systems? And in this regard, I heard the technical community— there are some who are saying, you know, the AI incident response kind of playbook is just the same playbook. It's not really new. And others that say it's completely new. Probably reality is somewhere in the middle, but we need to make sure that there is understanding that responding to attacks on AI systems is going— is a capability or a capacity that we cannot just take for granted. We really need to invest in making sure that it's included. Thank you.
Thank you so much, Giacomo, and I would like to invite you all to contribute to the moderated discussion, and maybe we can start with a question that builds on Giacomo's contribution. Giacomo highlighted that indeed states should be ready to hear from and be influenced by the knowledge which is produced by non-governmental stakeholders. The thing is that the evidence we have currently are coming predominantly from the private sector, right? And so a follow-up question would be then how to build capabilities, especially from the public interest ecosystem, whether public agencies on cybersecurity, AI, Safety and Security Institute, but also civil society organizations and the academia to be able actually to conduct investigations and produce knowledge that can be then channeled into international discussion, policy discussions, so as to advance on an international consensus about cybersecurity implications of AI. So if anyone has any advice or any thoughts on on the conditions under which we can maybe strengthen the public interest ecosystem to produce reliable and actionable knowledge. Nicholas from Sequoia, sure.
I think we all start speaking the same language in terms of how we categorize the data and then attack these things. And we need to, like, do a rinse and repeat of what it looks like when these AI systems navigate through our networks and look at the procedures that are used. That's how we're going to— we're hunting something that's unknown essentially every time. So we need to study and know the behaviors of how these things look in, say, log data, flow data. Like if something is communicating way too fast that a human couldn't do it, that's kind of a dead giveaway. You have some system talking to another system and just assume compromise and paranoid.
Sure, could you please introduce yourself first?
Thanks.
Precisely with Access Now, we organized the only session that addresses explicitly during the Global AI Dialogue the link between cyber and AI. It was a side session. It was not official in the program, but it was one of the officially taken side sessions. And I think that in these questions about the connection and the collaboration between the existing mechanism inside the UN and the global mechanism, there's a big opportunity. I think that what the comments of the previous speaker was addressing in terms of creating standards for, like, kind of like being able to collect data in a more effective manner, and the project that Paulo was presenting in the introduction are very relevant. And I think that there is a lot of connection that can be done in terms of the work that will continue to happen around the Global AI Dialogue in the intersectional part until the next one, but also something to connect with the scientific panel on AI. Because I think that at least my organization and a couple of more civil society organizations have been advocating for the scientific panel maybe to have a role in creating some level of harmonization in the way in which data can be collected for measuring the different emerging threats. We are very interested in that because, as you know, in general, civil society groups are very good in collecting evidence on the ground, but usually it's very incidental in the sense that we collect it in the format in which it's presented. So having, for example, the UN, either through the work of the scientific panel or any other kind of effort that can be coordinated between the global mechanism or other initiatives that are already ongoing at the level of standardization, could be very helpful in terms of validating kind of a more uniform methodology for doing this and This will be essential in terms of building the foundation for any further commitment with new accountability mechanisms, because if we are able to gather the evidence in a standardized manner, later on the work will be easier in terms of ensuring to identify the different responsibilities of the different actors. That's from our contribution, Food for Thought.
Thank you.
wish this connection between these different mechanisms is established in a much more clear manner inside the UN. Thank you.
Yes, so call me C2, please. I think the key thing, listening to Giacomo and the others, from the cybersecurity perspective, is focus. Now, what are we building capacity for? It's quite easy to go everywhere. But essentially, for cybersecurity, AI is a tool, it is a target, it is a threat. And I think we need to evolve an understanding of the— AI can be used as a tool for the defenders, AI is a target itself, and AI is a threat. Now, the thing is, do we need to reinvent everything? And that's sometimes the discussion, everybody gets excited. But from the ASEAN perspective, when we're implementing the norms of the 2015 GGE, We built it in such a way, what does it mean to implement these norms? What do you need to do to implement these norms? And then we added another part to it, which was what capacities do you need to build to implement this norm in order to act out this way? Perhaps we need to focus and come back. Why don't we come back to the 2015 GGE norms, which people are already working, states are already working on, and ask ourselves the question, what does this norm mean for AI as a tool, a target, or a threat? Just a thought. Thank you very much.
Thank you.
Yes.
to be so powerful that it's very, very hard for states to regulate. I mean, we're talking about norms upon states, but then states aren't able to regulate on those norms and models that pose a threat.
And so I'm just wondering if anyone has a better solution than I can come up with, because I can't find one. Actually, I think there is a need for articulation within the UN. There is a need of articulation between processes or policy discussions that are, of course, targeting states' conduct with those targeting regulatory activities of private actors as well. And, of course, the global mechanism represents an opportunity in that respect. Also, everything remains to be deployed and established when it comes to the practical modalities of such a global mechanism. I would like to come back on that right after, but maybe turn first to Yacine.
Yes.
So one thing that I do really want to share that's close to my heart, and answer to both of those questions about where to get information and how to have the power. One of the most hopeful things I find about open models is that if you have one AI system that is open, transparent, documented, and that does something similar to what the frontier does, even if it's behind by 6 months, that unlocks the entire academic world's collaboration on figuring out what the science is behind what we need to do. We've been able to do that for environmental costs. We're able to do that right now when we're like pushing back against some of those narratives around like it's a powerful model versus it's a very well put together model. And that's also something that in terms of power, a lot of the power comes from these epistemic positions of like, we're the only ones who can tell you what you can do with them anyways. Having those open shared alternatives that are maximally transparent, have this open science ethos, makes a huge difference. It's not a full answer. One small thing I wanted to add also is about like, in terms of standards, doing no worse than we did with the internet protocols is kind of a pretty good target. You were talking about like, not everybody's going to have data centers, but not all AI needs heavy compute either, right? Like, those are things that can actually track to the resources that we have for internet infrastructures.
Thank you. And not to oversell France's achievement in that respect, but France also was at the very top of the priority of the digital track of the French presidency of the G7. We have a couple of deliverables on that topic. But coming back again on the articulation of different processes, including, of course, the G7 with the UN discussion, the discussion on states conduct with those on regulation of private sector, for instance? I know that— I feel that, Giacomo, you would like to maybe follow up on that.
Yes, I just wanted to try to at least partially answer the question. It is peripheral to the cyber-specific issue, but, for example, at UNIDIR, we launched earlier this year an initiative that is the response— the framework for the development of responsible industry behavior in the context of AI and the military domain. So it's a mouthful, but the idea is, can we try to co-develop with states and industry together a framework of what— that articulates what responsible behavior for industry looks like? Because we have norms for states, but can we find an equivalent set of norms for industry? And the goal there is not really to develop new commitments, but it's try to help industry and states manage each other's expectation in terms of what it is reasonable to expect from industry in terms of responsible behavior in the development integration and deployment of AI, and on the other, in the military domain in that case, but it can be transferred to the cyber domain as well. And on the other hand, you know, what should states be— you know, we want states to be intelligent customers and be able to guide their decisions on whether or not to work with certain industry players based on their behavior. So we're trying to create this kind of interface between the two that could potentially be useful also in the context of cyber.
Yes, sir.
My name is Shiri Teicholz from the Forum of Business Responses. Thank you for organizing the roundtable. It's really quite challenging time for all of us. As was mentioned by a couple of the speakers about AI, it's not just about technology. It's about, you know, really how we deal with this technology. It offers opportunities and challenges, and that was mentioned. Among the challenges is the challenge from, again, the question about regulating AI. That is really an open-ended question. It is about more about better understanding, better cooperation, and bridging, and that's where the comment from Giacomo about the UNIDIR's effort to bring this bridge, and it has to be consistent. I think we're in a place— I was You know, 14 years back, I was part of the UNGGE, and I was part of the GGE that also accepted, you know, the norms. And developing the norms and the interpretation is quite an interesting exercise, but the challenge is how to make states understand what their roles and responsibilities are, and to deal with this in a way that is also inclusive. I come— I represent now a stakeholder, a leading organization in cybersecurity, and quite a few of those organizations were blocked from participation. So the challenge is, do we see that we can try to have a consistent, continuous, inclusive, and open mechanism for cooperation between states, between industry? Because the challenges will keep on going. We will face more challenges moving forward. I think Jim earlier, you know, mentioned a few challenges in cybersecurity. I did my PhD in AI 30 years back. And, you know, I've seen how AI evolved. I've been in the cybersecurity industry for over 30 years as well. So I've seen how those, you know, crossings happen. And at first we bring in, you know, all the professionals to talk, you know, about those issues. However, states are not there. So having this bridge, I hope that we can recommend moving forward with you, I mean with the leadership of organizing this roundtable or other events for creating those bridges in a more consistent way that is inclusive and open and effective at the same time.
Thank you very much. I completely agree that FIRST should be fully involved in such discussions because a part of the problem is also linked to incident reporting. So, so yes, I'm afraid I will have to wrap up the discussion, but we will have a couple of remarks from Charbel Sergery in a prerecorded statement from the CESIA, the French Center for AI Safety, with which the forum has partnered to precisely build a work stream on assessing the bottlenecks the public interest ecosystem face in producing knowledge specifically.
Thank you.
No noise, I'm sorry. So I guess we have a couple of technical problems. So maybe in waiting for this issue to be fixed, I will just leave the floor to Joyce Acme, which will host actually another side event on AI and cyber on Wednesday. And so yes, if you could tease a bit the event, which is almost full if I'm correct, but—
Thank you very much, Pablo, for giving me the opportunity to talk about the event. But before I do so, I wanted to say a big thank you to you and Elsa and the institutions who represent us this morning. and the French MFA for your example and willingness to coordinate as we were, uh, have been developing our respective plans.
So thank you.
So our events are organized in a couple of different parts, uh, hosted by the permanent missions of Latvia and Estonia to, uh, the UN. It will be a technical briefing on frontier AI and the cyber threat landscape. It will happen this Wednesday, as Pablo mentioned, between 1:15 and 2:30 at Conference Room C here, just 2 minutes away from, from this room. So it builds very much on the discussion that we've been having today. It would be a technical briefing, as I mentioned, delivered by CrowdStrike, who have been at the heart of, you know, many discussions relevant to this. And we'll tackle really kind of how AI, how the technology is changing the threat landscape, what are the opportunities for defense, but also what should states know at this highly important moment that we are living in, sort of technological development. And we wanted to organize this event because what all of you have mentioned, the ways in which— many ways in which AI is fundamentally challenging cybersecurity as we know it, and demystify some of the misconceptions as well. So we will hear from CrowdStrike. We also have remarks from the ambassadors hosting, but also the chair, Ambassador Lopez, who will be joining us as well. As Pablo mentioned, we expect this to be a very busy event, so it will be first come, first serve, and I hope to see many of you there. Thank you very much, Pablo.
Thank you, Joyce. Unfortunately, we have a problem. We need to cancel, inshallah, but we will, of course, follow up with the CESIA. I would like to turn for some final remarks to Ambassador Schappaz, that will close the event, because I am afraid I need to free you in a couple of minutes.
Thank you, Pablo, and apologies for the technical glitch. I'll be brief if we don't have that much time, but I just wanted to wrap up hearing the discussion. I think there are a few things we all agree on. Then we have a lot of work to do. But the 3 things I have in mind is, one, the scale and the speed at which the technology is transforming our society requires for multi-stakeholders collaboration, both to enhance the opportunities— I think it was important to hear that point— but also to tackle the risks. 2, this is not something we can just figure out on our own, and so we need the industry to set up standards and norms. And we've done that before. So I think we have reason to be hopeful. We've done that with the Palma process, which actually today is also looking at like the impact of AI, but like more the process, how we brought the industry together as a group to agree on like how to address some of those challenges is a process we've seen work. And so we, France, really want to continue pushing in that direction and looking at this as potential example on how we could address those challenges. And 3, we were very aligned with all the comments that have been made on the role of the UN and the intersection of those conversations in so many different instances. Some of us were at the Geneva AI Dialogue last week, and for sure there are some relationships and gatherings that need to happen between the work we're doing here and the work that's done at the UN Dialogue, because there is no way we can keep both themes separate in the world we're knowing. So we're very much in support of looking at how we can get all the work to contribute to each other, and we thank you for bringing that point, because we think it's fundamental that all instances push in the same direction.
Thank you.
Thank you, Ambassador, and thank you all Thank you all for your participation today, and I just need to wish you a good week of negotiation. Thank you very much.
Thank you.
Thank you.