By Larry Clinton, President, Internet Security Alliance
AI has converted cyber risk from a firm-level technology problem into a shared economic, safety, resilience, and national defense problem. Just as with the “space-race” and the need to quickly create medications for the COVID pandemic, AI compels government and industry to evolve their roles in a creative partnership—a social contract—to address the novel challenges created by economic and security gaps AI creates.
Previous blogs in this series (blog 1, blog 2, blog 3) reported on ISA’s study entitled “Defining an Effective and Sustainable Model for AI Deployment in Critical Infrastructure,” which is based on reviews by CISOs from 5 critical sectors (defense, energy, financial services, healthcare, and IT. Results from the first two phases of the study identified a series of common policy gaps AI is already creating in all these sectors.
The next, ongoing, phase of this study seeks to articulate a new public-private model reflective of the technical and economic realities of the AI era and focused on coordinated action and measured effectiveness.
An extended report on this study, including presentations from the CISOs who conducted the original research, will be part of a congressional staff briefing at noon on September second in Rayburn 2045.
THE NEED FOR A SOCIAL CONTRACT
The earlier phases of the study generate several common themes:
- Threat discovery, fraud, decisions, and response now outpace human-only controls
- Agents can act with legitimate access while identity monitoring and retirement are immature
- Poising leakage provenance, drift, and reconstruction create a new assurance discipline
- Vendors, clouds, foundation models, open tools and small partners create correlated risk
- Point-n-time review cannot govern systems that change and act continuously
- Small providers, utilities, banks, suppliers, and contractors face the same threats with fewer resources.
Historic governance models were not designed, nor are they capable of effectively managing this new environment.
Industry and government must come together — as they did in the space-race and COVID Pandemic — to create a new model, an AI Social Contract, that is both effective and economically sustainable.
While the full details of such a new model are beyond the province of this one study, and will need to include sector specific modifications, a number of specific elements of the AI Social Contract can be suggested.
What industry commits to
The industry obligation is, in the first instance, a governance obligation. Industry must commit, from the board level and enterprise wide on to following cyber risk principles and practices that have been assessed and shown to produce cost-effective security enhancements. This would include an on–going assessment of cyber risk, which is affirmatively folded into the business plan, consciously measured and managed from an eco-system perspective – not just from the individual organization’s security.
The Director’s Handbook for Cyber Risk Oversight Cyber-Risk created by National Association of Corporate Directors (NACD) and ISA provides six oversight principles that can be applied to AI. These practices have been independently assessed by PwC, MIT, and the World Economic Forum, and found to generate significant security enhancements on a cost-effective basis. Based on these independent assessments, the Handbooks define what “reasonable security” i.e. cost-effective—security, means on a sustainable basis. Additional regulatory requirements can be added subject to cost benefit analysis: The NACD-ISA model states:
- Treat AI cyber risk as a strategic, enterprise risk owned by the board and CEO — not a technical matter delegated to the technical team. The single most common failure mode in AI adoption is treating this strategic risk as a primarily engineering detail.
- Understand the firm’s specific legal and disclosure obligations arising from AI use, deployment, and incidents
- Ensure board access to combined AI-and-cyber expertise.
- Set the expectation that management runs an enterprise-wide AI-security framework with adequate staffing and budget (Principle 4) — covering model provenance, red-teaming, pipeline security, and third-party model risk.
- Identify and quantify financial exposure to AI cyber risk, and decide deliberately which risks to accept, mitigate, or transfer. This is where insurance enters as a governance instrument, not just a financial one.
- Commit to AI risk assessment and mitigation on an eco-system basis by Participating in collective, systemic resilience through information sharing and collaboration with peers, government, and law enforcement
What Government Must Do
Government needs to acknowledge that modern technology has placed the private sector at the front line of the nation’s defense. The market economics of private entities were not designed to absorb blows of nation state digital attacks which can, and are, undermining our critical infrastructures. A large share of the benefit of any firm’s security is an externality the firm cannot capture — spillover protection for its partners, its sector, and the digital commons.
On top of the governance commitments sit concrete operational requirements such as secure-by-design model development, a provenance and bill-of-materials discipline for models and training data analogous to the software SBOM, structured red-teaming of deployed systems, and timely reporting of AI-specific incidents into a sharing mechanism. These requirements may be articulated in regulation – but only if that regulation is harmonized to eliminate wasteful duplication and subject to cost benefit analysis (CBA) with mandatory sunsets for regulations’ that do not meet CBA requirements:
Organizations that comply with the governance model described above should be eligible for tailored market incentives. To be effective these incentive programs need to contain several the following key elements:
- There needs to be a “cyber strike zone” – a qualifier for earning the incentive. Essentially incentives are designed for “good actors.” The bar needs to be realistically set based on results of a certified sophisticated cyber risk assessment and mitigation or sector specific mandates.
- The incentive needs to be appropriate for the industry. For example, procurement incentives might be best for DIB companies, regulatory forbearance for traditionally regulated entities. Patent or permitting “fast tracks” for others.
- The incentive needs to be economically powerful enough to change behavior.
Examples of market incentives are:
- Procurement — “buy secure AI.” The government should condition its own purchase of AI systems and AI-enabled services on adherence to recognized security practices (NIST AI RMF plus secure-by-design baselines).
- Liability protection and safe harbors — the strongest behavioral lever, reserved for the largest externalities. A SAFETY Act–style safe harbor for AI developers and deployers who adopt recognized security and red-teaming standards
- Cyber insurance plus a government systemic backstop — the Dust Bowl model, applied to model concentration.
- Protected information sharing. Extend CISA 2015–style legal protections explicitly to AI-specific threat and incident data — model vulnerabilities, jailbreak techniques, poisoning attempts
- R&D and workforce investment — Operation Warp Speed for defensive AI security. Sustained public investment in defensive AI-security research and in the AI-security workforce addresses the under-adoption gap and the immaturity of attack-surface practices.
- Targeted cost-sharing, tax incentives, and grants for the laggards. Smaller firms and under-resourced critical-infrastructure operators face a gap that is about capital, not will.
