The Elara Edge
The Elara Edge is a thought leadership forum of military and industry experts providing commentary and analysis on the latest news developments in national security - with an emphasis in space and aerospace applications.
The Elara Edge
Chinese AI Closing Gap in Cybersecurity Vulnerability Detection
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
The race to artificial intelligence supremacy appears to be getting tighter. Earlier this summer, a Chinese AI model was found to match Anthropic's Mythos at discovering cybersecurity vulnerabilities despite trailing U.S. models on other tasks. The development carries real national security implications as the cyber domain increasingly operates at machine speed, while heightening the imperative for the U.S. government and commercial industry to partner together to streamline development and adoption of secure and reliable AI tools.
In this month's episode of "The Elara Edge," Maj Gen (Ret) Kim Crider, Lt Gen (Ret) Bob Skinner, and Mike Robbins break down the challenges and opportunities to effectively adopting and integrating artificial intelligence in a rapidly-evolving cybersecurity environment.
- Maj Gen (Ret) Kim Crider is a Founding Partner at Elara Nova and the first Chief Technology and Innovation Officer with the United States Space Force
- Lt Gen (Ret) Bob Skinner is an Executive Partner at Elara Nova, and the former director of the Defense Information Systems Agency (DISA) and former commander of the Joint Force Headquarters, Department of Defense Information Network (DODIN)
- Mike Robbins is a retired colonel with the United States Air Force and the former Director of the USSPACECOM Joint Cyber Center and Joint Ops Center
"The Elara Edge" is hosted and produced by Scott King of Elara Nova. The full story can be found on Elara Nova's Insights page here. Music was produced by Patrick Watkins of PW Audio.
Host: Scott King (SK)
SME: (KC):Maj Gen (Ret) Kim Crider, Founding Partner at Elara Nova; former Chief Technology and Innovation Officer at the United States Space Force
(BS): Lt Gen (Ret) Bob Skinner, Executive Partner at Elara Nova; former director of the Defense Information Systems Agency (DISA), and the commander of the Joint Force Headquarters, Department of Defense Information Network, (DODIN)
(MR): Col (Ret) Mike Robbins, Partner at Elara Nova; former Director of the USSPACECOM Joint Cyber Center and Joint Ops Center
00:02 - 01:06
(SK): The race to artificial intelligence supremacy appears to be getting tighter. Earlier this summer, a Chinese AI model known as Z.ai was found to match Anthropic's Mythos at discovering cybersecurity vulnerabilities despite trailing U.S. models on other tasks. The narrowing gap in AI-enabled cyber capabilities carries real national security implications as the cyber domain increasingly operates at machine speeds. It also heightens the imperative for the U.S. government and commercial industry to partner together and streamline development and adoption of secure and reliable AI tools.
Welcome to The Elara Edge! We have three guests today, here to discuss the ever-evolving and attention-consuming topic of artificial intelligence, as well as the challenges and opportunities to streamline adoption of these cutting-edge technologies in national security.
First, returning to the show is retired Major General Kim Crider, Founding Partner at Elara Nova and the first Chief Technology and Innovation Officer at the United States Space Force.
Ma'am, welcome back to the show!
01:07 - 01:08
(KC): Thanks, Scott. Great to be here.
01:09 - 01:27
(SK): Also joining us is retired Lieutenant General Bob Skinner. Bob is an Executive Partner with Elara Nova and the former Director of the Defense Information Systems Agency, DISA, and the Commander of the Joint Force Headquarters, Department of Defense Information Network, or DODIN.
Sir, welcome to the show!
01:28 - 01:30
(BS): Thanks, Scott.
Happy to be part of this esteemed group and panel.
01:30 - 01:43
(SK): We also have Mike Robbins joining us today. Mike is a retired colonel with the United States Air Force and a Partner at Elara Nova who previously served asthe Director of the US Space Command Joint Cyber Center and Joint Ops Center.
Mike, welcome to the show!
01:44 - 01:46
(MR): Thank you very much, Scott. Appreciate it. Really honored to be here.
01:47 - 02:04
(SK): Now, there was a Wall Street Journal article published earlier this summer that found a Chinese AI model now matches one of the most advanced U.S. commercial models in discovering cybersecurity vulnerabilities.
Mike, can you bring us up to speed on what the implications are for this finding? And what makes this recent development so concerning?
02:05 - 03:38
(MR): Appreciate it. Scott. So it's not a real surprise the Chinese are actively seeking to advance their technology, not only do they have human resources, but they want to be able to leverage all the technology that they can. So nothing shocking about that for those that have been paying attention to what our adversaries have been doing in the cyberspace and cybersecurity realm for the last 20 plus years.
It is a common theme for the Chinese to steal both intellectual property from our defense industrial base, as well as from the government itself, on how they can maximize the capabilities that they have at the lowest cost to themselves. They've actively sought ways to exfiltrate data, exploit data, and embed themselves into our systems.
And if you take a simple search of various academic and industry periodicals, the U.S. assessment has been clear that the Chinese have the intent to leverage AI wherever they can, and they want to advance their technology, whether it's through the chipsets that they are trying to develop or procure through whatever means necessary, or whether it's their models and how they are trying to exfiltrate and learn from our most advanced models.
It is concerning because as they advance their models, they make those models available to whoever will work with them and in whatever manner they want to work with them.
03:39 – 04:49
(BS): Hey Scott, I'd love to add a little insights into what Mike's talking about from a China standpoint. They have stated publicly that they want to dominate the emerging technology sector by 2030. That's a huge goal.
And really, I think we're talking more on artificial intelligence and quantum computing. If you think, okay, how can they best do that? Well, it's to continue their coercive manner of stealing where they can and disrupting the time continuum that it would normally take through research and engineering to get to a good spot. And so that's really what they are focused on is: how do they continue to coerce and steal their way to the top?
I am less concerned about their technology because I think in an autocratic environment, it's harder to innovate than it is in the United States. And so I would offer our LLMs, I think we will stay ahead of them from a technology standpoint.
But I don't think we can overstate what China is trying to do, but I think their normal manner just will not enable them to be at the top because of the innovative ways that the United States and our allies and partners, which is a key component of our ability to innovate where we're headed.
04:50 - 05:04
(SK): And Mike, what does this emerging AI-enabled cybersecurity environment change for the cyber operators on the ground at a place like the Joint Operations Center or Joint Cyber Center, who are now confronted with an operating environment that is moving at machine speeds, both offensively and defensively?
05:05 – 06:36
(MR): I'll go back to my Air Force roots and John Boyd. It's about the OODA-loop.
As an ops center, your job is to get information in, identify those things that you can exploit and move on and make a decision so that you are ahead of your adversary. So in an ops center, it's not really going to change what you're trying to do. The tools that you're using might change. And that's where you talk about moving at machine speed, moving in that machine learning environment.
I would propose today, if we're not already using AI in our ops centers to help synthesize data to help commanders in their OODA-loop, then we're already falling behind, right? So from a cybersecurity standpoint, a big risk we have is if I have somebody who's finding a zero day exploit on zero day or before zero day, I'm already at a disadvantage.
My challenge becomes how do I respond to that? What are the tools I am using to identify that zero day, and then have my defensive tools write a rule for me that says, ‘Hey, I found a zero day. Here's a rule that you can implement that will help prevent an attack or mitigate an attack on that,’ and then move forward.
So two separate things how the ops center works. And then what is it tactically my operators have to be able to do? I can't emphasize enough if we're not using AI already. We're behind the power curve.
06:37 – 07:17
(BS): I agree wholeheartedly with Mike. The cautionary tale with AI, though, is if you're just jumping into AI for AI’s sake, then that's going to cause more problems for your mission and your operations than what it's worth.
You have to understand what problems you're trying to solve and have the mindset of how can I leverage technology to achieve the gains and achieve the objectives that the mission requires? And that takes some thinking beforehand, because there's a whole litany of cautions from a fiscal standpoint, from a legal standpoint. But yet that's my only cautionary tale, is, that yes, you want to jump in, but you got to be careful that you don't jump in without understanding where you're trying to go.
07:18 – 07:25
(SK): So considering how quickly these models are being developed, how do you balance the adoption of these innovative technologies weighed against the inherent risks that might come with them?
07:26 - 08:07
(BS): The thinking model doesn't change because at the end of the day, as a commander, you are responsible for understanding the risk and managing the risk.
If we go into this with being risk averse, we are going to lose ground significantly. So you have to manage that risk. Part of managing that risk is understanding, so there's an education piece and a training piece. Understanding the technology well enough that you at least have kind of an understanding of what that risk is and what the potentiality is.
And then you can make the decision of, ‘Hey, do I need to slow down a little bit until I understand a little bit more, or do I need to go fast because I understand the second, third order implications of this technology and understanding the operational impacts and then just move out.
08:08 – 09:24
(MR): It's a risk management approach. And there's two things to that. There's what the commanders do in understanding the tools that they have available to them. And then there's what we want industry to do and we talk about our allies and how that works. We want to have the defense industrial base advancing as quickly as they can, and putting opportunities and options in front of commanders to use this.
We look at where we were in World War II, great example, the P-51. We needed the P-51 in 1942, but we didn't have it. We didn't get that until late 1942, 1943. And what really advanced the P-51 was the defense industrial base, combined with an ally to put the Merlin engine into a P-51 that made it what it is.
And then American industry took that and implemented it fully because the British could not meet the need. So it is truly about advancing as quickly as we can. And once we have a solution, let's go. And that's what we need to be in AI. We need to have all the industry partners working in concert with the government, and with what commanders are willing to accept risk on.
09:25 – 10:36
(KC): Yeah, I think I'll just add to that, Scott, is that there's an opportunity cost that's also a risk. The risk of not leveraging the technologies effectively to do what you need to do. To Bob's early point, first, you have to decide what your objectives are, and then you have to understand how can this technology help me achieve these objectives and then you need to be able to leverage that technology and move out.
But it's not just an individual unit leveraging the technology necessarily, because how we win is at scale. So we have to be able to leverage the technology at scale with the whole operational entity being able to employ it effectively, which includes not just pointy end of the spear operators, but all of that infrastructure that comes behind them: the acquirers, the policy makers, the defense industrial base all being part of how do we drive this technology into our operations to maximum effect?
It's not just as simple as saying we're just going to leverage technology, but we have to be able to do it at scale, and we need the entire enterprise to be able to work together to that outcome to get us the maximum benefits that we want to achieve.
10:36 – 11:20
(BS): And, Scott, I'll give you a perfect example on risk. As a commander, as you leverage AI, you have to understand that you're going to get a non-deterministic answer. You can have the same input and you can put it in twice and you get two different answers. And so you've got to understand that just leveraging AI isn't necessarily going to give you the right answer that you need for the problem that you're trying to solve.
And so as long as you understand that and you understand that risk, I think you can be successful. I have a concern with those who are leveraging AI and thinking AI is going to give them 100% right answer every single time. And that can be devastating when you're thinking about security and you're thinking about potential lives on the line, on the front lines and or even in the rear echelon.
11:21 – 11:32
(SK): To take the idea of risk one step further, how do you go about trusting the answer that you’re receiving from an AI-model on whether or not a vulnerability exists, or that after it’s been identified, it’s been effectively patched?
11:33 – 12:53
(BS): The first thing is industry and the government has to do a better job of validating and auditing LLMs. Being able to ensure that the success rate, because every model has a different success rate when you're talking about the prompting and the answering that it's doing and I'm just talking about the prompting part, right? There's a whole bunch of other AI that's going on. That's the first thing.
The second thing is what kind of testing mechanism do you have as an organization? That is, once you get those answers, than how are you validating and testing? Are you finding? Do you have a way to quickly find like, say, there's X, Y, and Z vulnerabilities in X, Y, and Z systems?
How are you able to assess and validate in a quick manner, sometimes autonomously, X, Y, and Z vulnerabilities are in X, Y, and Z systems, and then you start building the confidence levels that the model is providing the right information, realizing that it may go off periodically, but I think that there's this validation step that and I know we talk about the risk management framework, which I'll tell you that that three letter word is like a four letter word in a lot of vocabularies because of the way that is implemented.
And so how do you have continuous monitoring, continuous validation, continuous auditing to highlight and showcase that things are operating nominally. That to me is where we as a Department and we need commercial industry and our allies and partners to help us get there.
12:54 – 13:39
(MR): I can follow up on that, Sir. You want to have that model that works for your environment. You can't afford to have your model exposed where the adversary could potentially inject things into it through a concerted effort to change what the model is looking at. That's where as we look at space systems, we're going to be in a position of how do I have a model that is developed at the scale that the commercial world can do it at, at the speed they can do it at and still be focused enough on a what's my niche that I need to have my model work because I can't on a classified system have my model call home. It can't go out to the dirty internet and call home. I've got to have a model that works in my environment.
13:40 – 13:59
(SK): Now Mike, on the note of space systems: it’s well known that both space and cyber capabilities underpin all of the operations across the Joint Force.
So when it comes to cybersecurity risks and threats, not only to IT networks and systems terrestrially, but to space systems themselves, what are the implications for those risks?
14:00 – 14:52
(MR): Everything. General Burt a number of years ago had a quote. That was when she was at SPOC. It was, you can't have space heroes without ones and zeros. And that is true. I would propose that you absolutely cannot separate space and cyber, because you cannot get to your space vehicles without those ones and zeros without cyber to do that.
Yeah, there's RF signals involved. There's electronic warfare that's involved. But fundamentally you're talking about commands at the basic level that we're sending to space vehicles to do things and those commands are cyber.
That's a computer programming thing and has been since the dawn of the space age and without effective cyber operations, space operations will cease to be effective both in the space vehicles and on the ground systems and the networks that connect those ground systems.
14:53 – 16:51
(KC): I think it's important to recognize that a space system is not just the network. Mike kind of touched on this. It's really an interconnected system that includes the spacecraft, the ground segment, the links between them, the user terminals, and then any extended cloud infrastructure and supply chain that may be connected to that. So the attack surface is pretty extensive.
But what's also interesting is that an adversary doesn't have to necessarily hack a satellite. You can get into this environment in a variety of different ways and the most accessible entry point still is the ground segment. But that's not to say that these other parts of the system are not vulnerable. So it's an integrated system. It has multiple components that are threatened. And you can't really think about space cybersecurity. Therefore, just as our general understanding of enterprise IT cybersecurity extended into orbit. It's an entirely different system, and the consequences are a little bit different as well.
When a traditional IT enterprise is hacked, there's a recovery process. It could involve rebuilding a server, isolating the attack, maybe restoring data from a backup. But when you're talking about a space system that's been compromised in some way, even if the compromise starts in the ground but then impacts the entire system, that attack may not be noticed right away.
It might be a limited, gradual degradation of the system, and it might not be something that you can immediately address through an immediate recovery or restoral process. Space architectures are different than a more traditional ground-based IT enterprise architecture, which raises the stakes of what we're talking about here. And to Mike's point, the dependency on that environment is at the heart of everything that we're able to do in space. Those are important subtleties to keep in mind.
16:52 – 17:52
(BS): Well, you know, I think Kim's hit it on the head. If you think about a mom and pop shop in the Midwest that an adversary has exploited that has a connection either from a supply chain and or a connection to a power supply, to a data center, to something else that is critical to space operations or critical to those space systems operating. That's pretty powerful.
And you may not know because leveraging AI, they can find it, they can sit low. And we've got to be able to do a better job of countering that because as of right now, I would offer AI has given the adversary a leg up or the attacker a leg up until the defensive systems and processes and technology catches up, but it is significant as you think about the operational technology and the nontraditional IT that Kim was talking about. I think that is a huge challenge, but also an opportunity to get things better in the future.
17:53 – 19:06
(SK): Thank you, Sir. Now it’s important to note that to date, the leading AI models have been coming from U.S. commercial industry. In the context of our conversation today, we’re referring to Anthropic’s Mythos model and the Chinese model Z.ai that appears to have matched its cybersecurity capabilities.
This development follows a series of years where federal export control orders were increasingly used to restrict the AI chips that could potentially empower them in the national security environment.
But in June, the U.S. government went a step further to place an export control order on the Mythos model itself. And because Anthropic could not assure the foreign national status of every user, the company revoked access to Mythos entirely. But this also had a collateral effect for other government users relying on that model, including the National Security Agency.
So all that being said, General Skinner, you spoke of the vetting process that goes into ensuring the AI tool is suited for the job, weighed against its risks.
So Sir, can you take us behind the scenes of the vetting process to ensure a commercial AI model is both reliable and secure? And then walk us through what happens when that model disappears on short notice, whether it's due to a flaw within the model itself or an adversary’s action to compromise it?
19:07 – 20:56
(BS): Yeah Scott, to me, it all starts with the approval for a system to operate on a DoD network. DISA being a big part of that, although not the only part because you have authorizing officials throughout the entire department who helps enable that. I think it starts there. Again, it's a very slow process and one that continues to need to be refined to catch up.
I will tell you from an operational standpoint, it really drives home the fact of what is your PACE plan, right? Mike talked about John Boyd's OODA-loop. A PACE plan is probably been around as long as the OODA-loop, where you're really focused on what's your primary, alternate, contingency and emergency. People look at it from a communication standpoint more so than anything else, but I look at it from an operational and a mission standpoint.
It's: what happens if you do not have something that you are relying on? I mean, we used it in a Space Command. We used to do “A day without space,” and you would have the combatant commanders or the component commanders come in and you kind of walk through that. We have to do the same thing from a cybersecurity standpoint.
What happens if you are no longer able to use this capability, whether it's because of an export control, whether it's because there's an eccentric CEO who decides that their patriotism has a limit if the dollars don't come with it, or is there a cybersecurity issue that you need to stop? And so I think that really comes into play is: how resilient are you in your operations and what kind of PACE plan do you have to really understand what your next move if something like this happens?
And it goes back to risk, as a commander, you have to understand the risk, not just the risk from an adversary, but risk of your own operations and how you need to leverage that to move forward. And I think that's going to bring them to bear how important a PACE plan really is, at least from a planning standpoint, and then have the flexibility and the adaptability to change as necessary as you're moving forward.
20:57 – 22:00
(MR): It's no different than any other tool, AI and whatever the tool it is. If you look at another space system, GPS and what are operators having to do understanding the risk to GPS? They have to go out and figure out, well, how do I operate? If you're in the Navy, maybe you're using a sextant again, very old school type things, but that's what you have to do. If I have to do analysis on my own because I lost access to a model, how do I do that?
The second part of this, the export control right, is then you start to get into: how involved is the government in deciding what industry and not defense industrial base, what the commercial capital market will be able to do and not do? And how much constraint do we put on our innovation if we say, ‘Hey, the government's going to get involved in that and what you can and can't do,’ because the Chinese government's not going to put that constraint on their industry. They want them to go as fast as possible.
22:01 – 22:15
(SK): And General Crider, speaking from your perspective as the former Chief Technology and Innovation Officer with the Space Force, how do you go about leveraging these systemic processes that are put in place across the government to adopt a tool that is oftentimes iterating faster than the approvals can keep up?
22:16 – 24:46
(KC): This challenge, this conundrum that we face is not necessarily new and is certainly not specific to space. It really is kind of a broader cultural challenge that we've seen over and over again, where technology is very often moving faster than the organizations can adopt it.
We've seen it in the case of nuclear technology, where we had advances in nuclear capabilities that moved a lot faster coming out of the labs and policy was prepared to address. We saw it in the internet. When the internet boom first happened, the internet spread pretty quickly, faster than policies and organizations could adopt it effectively.
So this happens a lot, right? I would say what's different this time around with AI is that AI is literally just exploding on the scene, and the velocity of change that we're seeing in AI since it first really came out in a grand way, has just been moving very, very quickly.
The advances in technology that I talked about earlier. These things unfolded over several years and decades. But with AI, the capabilities are quickly evolving in a matter of months. So it's really hard to get in front of that, especially when large organizational processes, policy acquisition, workforce development, governance, these move on multi-year timelines. So you've got a technology that's evolving very rapidly in a matter of months, and you've got organizational adoption through those sort of mechanisms taking years.
So it's really about how do we build our institutions to be much more flexible and adaptable? How do we get ahead of some of these changes? How do we become much more flexible in our ability to leverage these technologies? Hopefully we're going to get smarter as organizations because we've talked about AI for quite some time.
I remember running around the country talking about AI was such an important capability and we need to take advantage of it. It wasn't until the advancements of ChatGPT, when it went out into the marketplace that people actually started to realize, ‘Wait a minute, this really is a thing.’ And then all the other frontier models came out and things started to rapidly take off. But still, the organizations then and now, struggling to catch up, struggling to find ways to integrate it, struggling to find ways to have the right policy to adopt it, to manage it, to control how it's applied in the most effective way.
24:47 – 25:03
(SK): And to bring it back to General Skinner, how would you respond to the questions that General Crider just posed?
Does the example we saw this summer that played out with the Mythos model, where there was approval, implementation, a temporary revocation before it was ultimately restored, change anything about the current vetting and approval process?
25:04 – 28:07
(BS): I would offer it validates that the current process is not flexible enough, but that's something that we've known for decades now. And it's just it's so hard to get over the hump when you're talking about authorizing officials who have a fiduciary responsibility on: I am a signing off that this system or this application is secure enough that it will not cause mission impacts by putting it onto the network. And so it's the dichotomy of how do I go faster? But also, excuse my French, my butt's on the line because I'm authorizing this. And so I think that's the dichotomy that Kim was talking about.
I would offer there's a couple of ways. There's an education piece. Being able to educate, authorizing officials not only their duties, but also on the missions and the understanding of the technology underneath those missions. I think helps, because the more comfortable they are with the systems and the missions and the software, the more comfortable they are to accept a certain level of risk based on that understanding.
I think there's partnerships. Too many authorizing officials I would offer and too much within the Department. We think, well, just because the Army approved it doesn't mean that I should approve it or the Space Force approves it, so the Navy is not going to prove it. Well, there's a foundational reciprocity that we have the authority already out there to leverage, but we don't leverage that enough.
And I think because there's a trust part of this, that I'm not going to trust them because I'm the one that is going to get in trouble if something goes wrong versus how do we have a foundational education, foundational training, foundational certification to ensure that people are staying up with the technology and the processes? So I think the reciprocity from a partnership standpoint is also important.
And then I think we don't leverage technology enough from a validation standpoint. There is technology out there that we can leverage to improve our understanding and improve our probability of risk percentages to the technology and to the mission. And we just don't leverage that enough. And part of that is, is some of the workforce within the Department is mature. And we've got to make sure that they are educated and trained with the new technology versus just understanding the processes that they've learned over the past decade and or two.
So I think it’s a multi-pronged approach, and I see Mike laughing because of my mature comment. But I think that plays into it because I would offer if I'm in charge of auditing and authorizing, I have a much different mindset than a person who is 20 now or 25 or 30 who has basically lived with the technology that we have today.
And there's a culture piece of that we don't usually talk about enough that I think plays into how do you understand the risk management part of all this versus being risk averse? Because the easiest thing to do is be risk averse, and I'll get in less trouble if I'm more averse.
28:08 – 30:41
(MR): So the mature comment, I think, Sir, I think we're part of that mature group. We just happen to have a better understanding of the technology. So I'll bring up a couple of things. We talk about how AI is going to do all these things and the advancements and the speed. This is no different than many other technologies that have come into the services over the last 40 to 50 years. How quickly can we adapt the technology into what we operationally need to do?
It just so happens AI is moving so much faster than those technologies have before. How do we address that? I think we address that with good design. The systems we have authorizing officials signing off on today, in the last 20 years have all been, ‘Hey, we're just going to go throw this system out there and we're going to go do some software development, and you end up with poor design habits, poor systems engineering because computer processing and computer power got cheap, we were able to do things a lot faster.
But we didn't maintain good design practices, good engineering practices to ensure we had a foundationally secure software application or network. We just kind of had things happen. So we have authorizing officials that are trying to make decisions based on that history. Now, we're not going to fix that overnight.
But I would also propose that there are authorizing officials that are both accepting risk on behalf of an operational commander, that that operational commander then does not know that somebody has accepted for them and therefore they can't make decisions.
But I would also propose there are times when authorizing officials are too restrictive, because the operational commander might be willing to accept the risk on something because they're going to be able to move inside the OODA-loop of the adversary and make the fact that there is a risk on their system not a factor, but that authorizing official doesn't always think about that way.
And that goes to what General Skinner talked about, is helping authorizing officials have better understanding of missions and systems, not just from a pure technology standpoint. There's a lot of times where we try and evaluate things and it's, ‘well, there's a risk to the system, which means there's a risk to a router, a server, a software application,’ but there's not a good understanding of what the risk to the mission might or might not actually be.
30:42 – 30:50
(SK): And Sir, who in your mind is responsible for that educational piece? Does that come from the industry partners developing these tools or some other leadership within the Department?
30:51 – 31:42
(BS): I'm always most cautious because when I say shared responsibility, then a lot of people think that is nobody's responsibility. But I do think it's a shared responsibility.
I think at the end of the day, since authorizing officials fall under the DOWCIO from a policy and procedure standpoint, they're the ones who are ultimately responsible. But it has to be a shared responsibility with industry and with mission owners so that we can make sure that authorizing official, they got to be educated on the process itself and their responsibilities, but also whatever missions that they're assigned as an authorizing official for and then industry, which I would offer industry loves to make things complex way too often.
And the more complex you make something, the less comfortable that people are leveraging that technology and or authorizing it. And so the simpler that you can make it, the better at the end of the day.
31:42 – 32:03
(SK): We should note that the Department of Commerce is the one that issued the export control order that temporarily restricted the Mythos model.
What does that demonstrate about the delegation of responsibilities and authorizations across the various departments of the U.S. government? How does that delegation complicate the vetting and approval process, and what can the U.S. government do to overcome that challenge?
32:03 – 33:08
(BS): Whenever you have multiple organizations involved in something that makes it more complex, and I talk to the industry about this all the time: you cannot have a transaction relationship and be successful. It's got to be a partner relationship.
And so as the Department of Commerce is making determinations on export control decisions, they have to be discussing with the Department of War, and I would say the State Department and others, to make sure that they understand all the implications of what that decision is going to entail, whether it's going to be a productive one or if it's going to hinder operations and or capabilities.
And then at the end of the day, right there, the ones that ultimately held accountable and responsible. But it also gives an opportunity for the Department of War to go to the President as an example and say, “Mr. President, here's the implications of this. We don't agree with what the Commerce Department is going to do.” And then the President is the one ultimately who will make the decision based on national security.
So I think there's a partnership that has to be there in order for us to be successful, when we're thinking about the export control and what it means to us.
33:09 – 33:57
(KC): I think that I would agree with the point that it really comes down to communication and partnership. Before we start to develop specific policy, we should be thinking about what is the outcome that we're trying to achieve collectively? Put on that commander's risk hat. What level of risk does one policy decision or another create to the mission? What are the effective controls that are appropriate to mitigate risk?
So in all cases, I think the policy measures, really should come down to being risk-based, continuously informed with some data and evidence of their effectiveness and executable in a way that supports mission outcomes.
33:58 - 34:19
(SK): So in some ways the vetting and approval process can be described as “export control, plus trusted access.” But given the size and scale of the Department of Defense Information Network (DODIN), which includes the joint force, the defense industrial base, and international allies alike, is this process positioned to accommodate that size and scale required for the mission?
34:20 – 35:56
(BS): Well, I say it has to. I mean, at the end of the day, and I think that's where the partnerships come into play is to enable that scaling. You mentioned the scale of the Department of Defense, Department of War networks. Think about: it is the third largest number of addresses in the world, the United States number one, China's number two and the Department of War is number three. So that is significant from a scale standpoint.
We all heard the saying of, “bureaucracy or headquarters staff simulate the enemy in peacetime.” And I think that there’s friction in peacetime of those processes and the amount of time that it takes to get through your approvals or the amount of time that takes to get those partnerships and those interagency, I'll say, task force together to address.
And so I would offer they are not where they need to be. And I think senior leaders know that and understand it. And they take that into their risk calculus, whether it's something that's internal that they're working through or it's something that's external from an export control standpoint, they just continually work through that as part of their risk management process.
But it's still too slow. And the leveraging of technology has to be at the forefront because you have to understand them. And then you can make changes as necessary. And I just don't think we're there yet with all the different policies and procedures and understanding across the partnership realm.
35:57 – 37:48
(MR): And Scott, following up as General Skinner said, right? We're talking about the DOW here and the impact of export control, which is very much national security based. But the challenge is the US does not have a lock on smart people and it's a numbers game. There are 1.5 billion Chinese five times or whatever it is more than we have of U.S. citizens in this country.
And we'll go back to the nuclear weapons and coming out of World War II, that was a nation state it took to develop those capabilities. And we were utterly shocked how fast, despite our best efforts to control that technology and that information, how fast the USSR developed weapons with that.
Move that to computers, we still try and control that and that's part of what we're using to control AI is the compute power to have the models run fast enough and generate that. As we move into models, once you have the compute power. And oh, by the way, every other country can develop that compute power, this is almost less about what the DOW does internally. We ought to be finding ways to use that technology.
But the genie's out of the bottle on AI. It's not a matter of whether we can control it through export control. We tried that with nuclear weapons. We've tried that with compute power, and the same thing is going to happen with AI. We are going to have to be able to move fast, be agile, and honestly get out of industry's way to allow them to develop fast enough.
Because, as General Skinner said, our innovation is going to be better just because of the environment we're in than an autocratic society is. If we try to control things in an autocratic manner, we're not going to be successful. That's fact. Industry and our commercial world develops fast enough, and that's where we need to control what we can, but understand it's not going to stay in the bottle forever.
37:49 – 38:00
(SK): And what about our international partners? They may have different policy, procedures, and approval processes in place when it comes to adopting innovative AI technologies.
So in what ways does that factor into our discussion here?
38:01 – 39:15
(KC): I think I'll jump in on that one. Scott. This becomes more of an alliance and international partner problem than a technology problem.
I mean, the fact is that every international partner has a different set of legal authorities, privacy rules, security processes, and we shouldn't expect identical approaches or identical laws. But we can establish a common set of mission assurance standards. So I think it really comes down to working towards that outcome and fundamentally getting to the point where with our allies and partners, we have some degree of federated trust.
They have their policies and procedures, we have ours, but we have some common standards between us so that we have a federated trust. And we can verify that through those managed standards and credentials that we agree to as allies and we agreed to as coalition partners.
This enables our partners to maintain sovereignty in their approaches. But we can still have interoperability, and we can still have a degree of trust to employ these technologies effectively in our coalition operations.
39:16 – 40:40
(BS): And I think, Scott, in my travels within the government and since I've been out of the government, our allies and partners, the first question they ask is what is DOW doing? So we have a leadership opportunity and they are looking at the U.S. relationship. That doesn't mean, again, as Mike said, right? We don't have monopoly on the talent. We don't have a monopoly on the technology, but they're looking at how we're doing it, because what they understand is the things that we use.
We develop playbooks, we develop TTPs, tactics, techniques and procedures. We develop all this around the technology from an operational success standpoint and operational maneuverability and or implementation and they like that. They want to see that because they don't have the staying power and the buying power that we have. It's just they just don't. And that's okay.
So I think as we kind of continue these partnerships with our allies and partners and we continue this federated trust, I think it's a golden opportunity because I think, again, at the end of the day, I think our allies and partners is what's going to save the day against whatever China is trying to do in changing the rules-based international order.
And technology is a good way of helping maintain that trust, because we can all see what the pros and the cons and the challenges and the opportunities are with that technology. So I think it's while they do have different rules and different laws, and I think it is a force multiplier with allies and partners more so than it's not.
40:41 – 41:04
(SK): Now, if you’re a commercial industry executive, and you’re providing a capability to one of the military services within the Department, what should your takeaways be from these recent developments on AI adoption, integration, and risk?
And how should they, like the Department of War, similarly navigate this rapidly evolving environment where these innovative technologies are becoming available faster than the institutional procedures are capable of vetting them?
41:05 – 43:22
(KC): I think we've said a lot of this already, so I'll footstomp a few of the points that have been made. First of all, it begins with moving beyond a transactional relationship, as Bob said, really has to be a partnership. As AI becomes part of our operational infrastructure in how we intend to employ our operations and enable our decision-making resilience relative to that, AI also needs to be built in together in a partnership.
There needs to be active dialogue on policy and understanding how to present this information in a way that authorizing officials can understand the importance to mission, the risk to mission of certain controls. Industry can be a part of those conversations. Industry can be a part of the joint exercises and thinking through how the capability gets applied.
I also think that it's important for industry to recognize that, as we've said earlier, their AI capability may not always be there as something that we would employ or would be employable. For any number of reasons. It may become unavailable to the user. The biggest risk we can have with AI is overdependence on it, so we need to be thinking through that.
And if there is a reason for that particular tool not to be available from a cyber standpoint, export controls, whatever the case may be, industry needs to be part of helping to ensure that there is enough resilience built into the capability that the mission can still be accomplished, the operator can still make the decisions, can still operate the capability effectively, and there's graceful degradation.
There's continuity plans to ensure mission assurance. So industry and government need to be thinking about all of those aspects of working together with AI, not just all of the promise of leveraging the technology, but how to employ it through the enterprise. With all the enterprise factors at play, including policy and governance, and recognizing that resilience when it's not available is just as important as being able to maximally leverage it when it is.
43:23 – 44:23
(BS): Industry, you got to know your own exposure, and that exposure can be internal to your organization. It can be the technology that you're leveraging and or producing. It can be your supply chain. And Kim will love this one, right? It's: understand your data flow. And that data flow will show you your dependencies and your potential issues and challenges across the board.
And I think if you understand that as a company, then you can do the contingency planning that Kim talked about. You can enable a disaster recovery if necessary. You understand where you're vulnerable to export control decisions before they even happen. And then you can actually advocate for yourself and or your position better. But if you don't know your exposure, then you're blind.
And if you're blind, then you're more apt to be caught off guard by some of the decisions that the government may make in regards to your company and or the controls and or technology that you're leveraging.
43:24 – 45:36
(MR): Sir I’d add to that, also is when I joined the military, 35 plus years ago, the DoD had the best computers in the world on my desktop. Within three years, I could buy a better computer for 10% of the cost, and the DoD stopped being able to drive requirements on the industry. So I think the government also has to be cognizant that despite what transactional approach you want to have to declare a model or a company to be not in vogue right now, if it's the best model in capitalism, that best model is going to win.
So the DOW and the U.S. government also has to be aware that they can't cut their nose off to spite their face, just because they disagree with something industry has done or a company has done. We have to be able to work as we've talked about. It's a partnership. It can't be transactional. If we want to advance and be competitive as we move forward with AI and not allow the Chinese to take the lead that they want to take, we have to be partners and not transactional.
45:37 – 45:46
(SK): And so on that note: what steps can the government take to proactively facilitate those touch points with industry, so that industry leaders can recognize those opportunities when they're presented?
45:47 – 47:08
(BS): You can have better partnerships today without going awry, legal and or contractual limitations. I think that's first and foremost, because the more that you can sit down with industry and walk through your problems, the more industry can bring their commercial capabilities to bear to not only help DOW, but it also helps society as a whole. And you don't have these, I'll say one-off or two-off or unique government capabilities. That again, usually costs more and are less sustainable than if you can leverage the technology.
So I think part of this is, is okay, I have a process in place. I have a mission that I want to accomplish. If I understand the technology and the commercial company understands my process, there is a back-and-forth to get at a good solution to where I don't need a one-off technology solution. Maybe I just need to tweak my process a little bit, and then that allows me to take full advantage of this commercial capability.
There's very minimal technology that the government and or society takes advantage of fully. And I think that partnership can help bridge that gap to understanding how we can better take full advantage of the technology that we have first and foremost, and then we decide if we need more technology based on that. So I think we are so far ahead of where we were from a partnership standpoint, and we just have to continue with that trust but verify going forward.
47:09 – 48:22
(MR): Yes, sir. I totally agree. The transparency that has to be in the requirements part of the process, what is it the government needs from AI? What is it the government is willing to do? And I think where you get in trouble, you get the risk averse is nobody wants a protest on a contract that's let.
I think it becomes very important to be transparent up front so that every company has an equal opportunity to understand the problem set and help write what a requirement might be versus one company comes in and all of a sudden you drop a proposal that nobody else knew was behind it except 1 or 2 companies? I think that's where you get into risk-averse.
And then don't stop the conversation when the proposal is out there. You have to continue to have a conversation because the business develops things, they learn things and they want to actually have a conversation with the requirement owner. So it's that transparency through the process, keeping the conversations going. That's an important factor so that businesses can understand, ‘Okay, this is where I can actually bring value as opposed to, well, I really don't know what they're looking for.’
48:23 – 48:40
(SK): Thank you, Sir. Now each one of you represents a different role as part of Elara Nova’s Cyber, Data & Communications sector. So what can the strategic advisory firm, and the CDC team in particular, do to help provide that clarity and support needed to strengthen that partnership between the U.S. government and its industry partners?
48:41 – 49:35
(MR): I’ll go first as the junior partner here, I think the role that we have is to facilitate conversations with the right people. Each of us brings a different background and a different skill set. We bring a perspective that helps companies better understand what the government might be asking and how to shape their message to get their point across.
That's an important thing, especially for businesses that in the tech industry and the new environment, AI, right? Many companies have never been involved with the DOW before. You have to talk about the operational problem. You can't just say, ‘Hey, I have a cool solution.' You have to say the problem you're solving.’And I think that's what Elara Nova brings, is helping companies do that and then get in front of the right person to go, ‘Oh, I can use that technology.’
49:36 – 50:24
(BS): Mike was spot on. I think we bridged the gap with perspective and context for partnerships. That includes understanding the technology. It includes understanding the problem set includes understanding the challenges and where a technology and a problem can meet, and bringing them together in a faster manner than what they would to give optionality to the government, but also optionality to the technologist to understand other places that they can go and bring their technology to bear.
But just as important is how do we bring technology companies together to solve a problem, right? So it's this multidimensional, multi-domain understanding and context and perspective that brings all these organizations together for the common cause of our national security.
50:25 – 52:25
(KC): Bob and Mike really hit it on the head with a lot of why we created Elara Nova and what Elara Nova brings to bear.
It really is about being able to bring a variety of perspectives. You know, our partner portfolio consists of people who have spent their time in mission operations, in technology development, in systems acquisition, in policy writing, in cybersecurity operations. So we have all these perspectives, all these disciplines where we've got folks that have spent their careers working in different agencies, both in the government and in industry.
And so we can help bring together these entities, connect the dots, if you will, on all of these partners and help all sides understand how do you take this great idea, this great innovation, and make it available? So how can we, Elara Nova, help the government more fully leverage and take advantage of technologies?
We do that by making sure that industry is very adept at conveying their message. What is the mission that they're trying to solve with this innovation? But that they also understand the policy constraints and the challenges and how they need to work through those steps.
We help government understand what industry is bringing to bear. We help government understand where policy may or may not be hindering the ability to leverage this technology effectively with the appropriate controls that need to be in place. So we're really trying to bring all sides together and act as the connector in getting to resilient architectures that can leverage technologies in a way that can meet mission needs.
And that goes for AI, that goes for any number of technology innovations that might be coming forward. There's no company in the world that can do that. And so we're very excited to be part of that solution and to have a fabulous team of folks as part of Elara Nova, like Bob Skinner, like Mike Robbins, and like the 150 or so other partners that really can deliver on that outcome.
52:26 – 53:03
This has been an episode of The Elara Edge. Elara Nova is the trusted global security partner delivering decisive advantage.
As a strategic advisory firm, Elara Nova builds expert teams uniquely tailored for client needs to deliver actionable results. With the trusted insight to deliver your decisive edge, Elara Nova is your source for expertise and guidance in global security.
If you liked what you heard today, please subscribe to our channel and leave us a rating. Music for this podcast was created by Patrick Watkins of PW Audio. I’m your host, Scott King, and join us next time at the Elara Edge.