NYC AI Hearing

NYC AI Hearing

Former Anthropic researcher Jacob Coxon and others testify on AI at a New York City Council hearing. Read the transcript here.

Former Anthropic researcher Jacob Coxon and others testify on AI at a New York City Council hearing.
Hungry For More?

Luckily for you, we deliver. Subscribe to our blog today.

Thank You for Subscribing!

A confirmation email is on it’s way to your inbox.

Share this post

Copyright Disclaimer

Under Title 17 U.S.C. Section 107, allowance is made for "fair use" for purposes such as criticism, comment, news reporting, teaching, scholarship, and research. Fair use is permitted by copyright statute that might otherwise be infringing.

Julie Menin (00:00):

Dangers and liability posed by AI development to identify the benefits that responsible AI development brings to New York City government and to its residents, and to discuss the slate of city council bills which seek to provide responsible safety guardrails for AI. These bills include a wide range of both proactive and defensive measures from legislation that requires artificial intelligence systems to pass a third- party validation that is free from conflicts of interest and incentivizes whistleblowers who come forward with a portion of the penalties assessed, to proposals focusing on emergency preparedness to be able to identify system breaches and to plan how the city will respond if such a breach occurs.

(00:52)
To achieve these goals, we've requested the participation of five firms leading the research and development of AI, OpenAI, Anthropic, Google, meta, and SpaceXAI. Today, four of them will be testifying under oath before the council, not simply for New Yorkers, but for the entire world to hear. We will indeed be the first legislative body to secure testimony from these companies under oath in the wake of these latest disturbing reports. SpaceXAI, however, is not here at all in direct violation of the subpoena that we issued last week, and we are pursuing that subpoena in court. We will also hear from a number of city agencies to receive their perspectives on these issues and on the bills that we have proposed thus far. We intend to work constructively with the administration to ensure that any policies being drafted, amended, adopted, and enforced will work effectively to serve New Yorkers.

(01:51)
And we'll also hear from whistleblowers, industry representatives, experts, and academics who we've been in touch with since we announced this hearing. And of course, we look forward to hearing from any member of the public who's invited to provide testimony about these topics. I want to be very clear about our intent. This hearing is not about stifling innovation. New York City is fast becoming the tech and AI capital of the world, home to nearly 400,000 jobs in that sector and some of the companies most consequentially shaping the future of artificial intelligence, and that's something we should celebrate. We welcome and appreciate how AI has accelerated [inaudible 00:02:35] medical treatments, boosted economic development, and help governments and businesses deliver services more effectively while reducing costs and rooting out waste and fraud.

(02:47)
When companies are developing technology with the potential to fundamentally reshape our economy, our workforce, our public safety, and our daily lives, and when leaders of that very industry are themselves warning government about its risk, the public deserves answers and solutions. So the true intent of this hearing is to ensure that innovation happens responsibly, that the government does its job to protect the public as the technology advances, and that the protections at the municipal level can potentially serve as a national model. I spent a large portion of my life being a regulatory attorney. The idea that artificial intelligence is going to self-regulate defies all reason. We don't ask the airline industry to self-regulate. That's why we have the FAA. And if there is an accident, there's an independent body to investigate that.

(03:47)
We don't ask financial firms to self-regulate. We have the SEC and other agencies as well. We don't ask the pharmaceutical companies to self-regulate either. That's of course why we have the FDA. So we shouldn't ask AI companies to self-regulate either. The spirit we seek to embody in the council's approach to AI is well illustrated in the words of tech journalist Karen Hao in her book, Empire of AI. She writes, "The future of AI, the shape that this technology takes is inextricably tied to our future." The question of how to govern AI then is really a question about how to ensure we make our future better, not worse. New York has always embraced the future. The council's going to make sure we are prepared for it too. And it's now my pleasure to turn the microphone over to our technology chair, Council Member Carmen De La Rosa.

Carmen De La Rosa (04:44):

Thank you, Speaker Menin. Good morning everyone. I'm Carmen De La Rosa. I am the chair of the Committee on Technology. Today I am pleased to join Speaker Menin and my colleagues as we co-chair this hearing by the Committee of the Whole examining the risk posed by artificial intelligence. I am incredibly grateful to all who took the time to join us to discuss this important topic, industry representatives, experts, elected officials, colleagues, agencies, our brothers and sisters in labor, and especially the many New Yorkers who have signed up to testify and have submitted testimony to put their voice on the public record. Today should act as a foundation for openness in a discussion that has escalated to alarm, confusion and fear, and it needs resolution.

(05:27)
Artificial intelligence is advancing rapidly and becoming increasingly integrated into everyday life. In just a few years, we have seen AI evolve from algorithmic tools that analyze data, make predictions and support decision making into generative AI systems that can create text, code, sounds, images. More recently, agentic AI has emerged enabling AI agents to take actions on a person's behalf. AI has a tremendous potential and can be a powerful tool for efficiency, innovation and productivity. At the same time, it introduces significant risks including exacerbating biases, surveillance concerns, breaches, negative public health outcomes, violence, and disparity. These are concerns that may become even more serious as AI agents become more capable.

(06:18)
When we face serious concerns or challenges, the appropriate response is to address them, not to postpone them. In an effort by the city council under the leadership of Speaker Menin, today we respond to some of these concerns. We will be hearing the following bills today. My bill, Intro 161, in relation to requiring reporting on the impact of algorithmic tools on city employees and changes in employment responsibilities due to algorithmic tools. Intro 504, sponsored by Deputy Speaker Williams in relation to prohibiting the unauthorized depiction of public officials by artificial intelligence.

(06:59)
A pre- considered introduction sponsored by Speaker Menin in relation to third-party validation and shutdown capabilities of artificial intelligence models. A pre-considered introduction by Speaker Menin in relation to civilian enforcement and artificial intelligence violations. A pre-considered introduction sponsored by Majority Whip Kamillah Hanks in relation to requiring reporting and public disclosure of artificial intelligence safety incidents concerning city contracts. A pre-considered introduction sponsored by Council Member Virginia Maloney in relation to establishing a private cause of action for certain harms arising from third-party misuse of artificial intelligence models.

(07:41)
A pre-considered introduction sponsored by Council Member Frank Morano in relation to chat box data privacy, security and transparency. [Inaudible 00:07:51] by Council Member Chi Ossé in relation to requiring the creation of an artificial intelligence model emergency response plan. And finally, not finally, one more. A pre-considered introduction sponsored by council member Kevin Riley in relation to city contractors and subcontractors posting information concerning whistleblower protections and clarifying whistleblower protections for reporting conduct related to the use and development of artificial intelligence models. And finally, a pre-considered introduction sponsored by council member Carl Wilson in relation to requiring certain disclosures and prohibiting deceptive representations in the promotion. While we work to protect people from risks associated with AI, we must not overlook the digital divide in our city. Our city is full of opportunity. Yes, some residents still lack reliable, affordable broadband access. Some people do not yet know how to use AI tools while others cannot even afford internet connection needed to access them in the first place. We cannot seek to benefit from innovation while leaving some New Yorkers behind or at its mercy. Technology being used by New Yorkers should be built for them. This is an opportunity to also explore standing up infrastructure so that our communities can become AI literate. I look forward to hearing from the industry and experts about this technology and how it is impacting our city, what safeguards exist, what solutions are possible.

(09:19)
As we consider how to govern around AI, I also look forward to working with our state and federal partners to ensure that New Yorkers fully benefit from the advancement of AI without compromising our safety and [inaudible 00:09:35]. I'd like to take a moment to thank the Technology Committee staff and all of the staff in the city council, but most especially our legislative council, Irene Byhovsky and our policy analyst Eric Brown, as well as my team chief of staff, James Burke, Hiba Imad, Fray Familia, and the speaker's team for working countless hours to put this hearing together. I now turn it back to Speaker Menin.

Julie Menin (09:57):

Thank you so much Chair De La Rosa. We are now going to start with our whistleblower panel. In person, I'm going to first call Jacob Coxon to come to the stand. And then online we have Daniel Kokotajlo and Alex Turner who are both remote. I want to say as they're getting ready, I just want to say a word about this panel. These three panelists have all worked inside leading AI companies and all have chosen to speak publicly about the risks of advanced AI. So here with us as I mentioned in person is Jacob Coxon, a former researcher at OpenAI and Anthropic where he worked on the development of frontier AI systems. He left Anthropic last month with dire warnings that AI is advancing without adequate safeguards to prevent catastrophic damage.

(10:51)
Joining us remotely is Daniel Kokotajlo, executive director of the AI Futures Project, former OpenAI governance researcher. Also remote is Alex Turner, an AI control researcher, formerly at Google DeepMind, now working on keeping advanced systems under human control. In September 2026, he publicly stated that preventing catastrophic harm from frontier AI had been part of his work at DeepMind. And I want to note the council has issued a subpoena for Mr. Turner's appearance and we deeply thank him for being here. So I'm going to, first of all, turn it over to committee counsel to swear these three witnesses in.

Speaker 1 (11:36):

So for each of the witnesses, can you affirm to tell the truth, the whole truth, and nothing but the truth in your testimony before this committee and to respond honestly to council member questions? Please respond one at a time.

Jacob Coxon (11:51):

Yes.

Daniel Kokotajlo (11:52):

Yes.

Alex Turner (11:52):

Yes.

Speaker 1 (11:53):

Thank you.

Julie Menin (11:55):

You want to do that now? Okay. And just briefly, we're just going to recognize all colleagues who are here.

Carmen De La Rosa (12:01):

Thank you so much, Speaker Menin. We've been joined by a number of our colleagues. As you can see here, Council Members Ariola, Aviles, Banks, Brewer, Brooks-Powers, Minority Leader Carr, Dinowitz, Encarnacion, Epstein, Felder, Hanif, Hudson, Joseph, Krishnan, Council Members Lee, Lewis, Maloney, Marte, Mealy, Morano, Narcisse, Nurse, Ossé, Council Members Riley, Council Members Jay Sanchez and P. Sanchez, Council Member Schulman, Council Member Thomas Henry, Ung, Deputy Speaker Williams, Council Member Wilson, Council Member Won, Council Member Wong, Council Member Zhuang, and Public Advocate Williams.

Julie Menin (12:48):

Thank you so much, and we'll recognize additional colleagues as I join. So the first two questions I have are for you, Mr. Coxon, and thank you again. We so deeply appreciate you being here, and we appreciate your courage and bravery in coming forward with these warnings. You work to develop increasingly capable frontier AI systems, and you have since warned that the industry is "racing straight to self-improving super intelligence and gambling with our lives." What did you see inside these companies that convinced you the risks were this serious and that development was outpacing the safeguards?

Jacob Coxon (13:26):

Good morning. Thanks for having me here. Yeah, I'm Jacob Coxon. So until a few weeks ago, I was a capabilities researcher at Anthropic, and before that I also worked at OpenAI. I guess the two things I saw that made me scared, the first is the fact that we do not know how to control any AI system yet. So any AI system that we build or perhaps more accurately that we grow, we don't fully control it. We don't understand its drives or why it does the things it does. That was the first thing that became apparent.

(14:06)
The second thing is that the pace of capability improvement is accelerating and the capabilities of the models next year will be very high. In particular, we're approaching the point at which the AI systems will be capable of improving themselves, so doing the research that humans were doing previously. So these two things, the fact that the AI systems next year are going to be very powerful, and the second that we don't know yet scientifically how to fully control them.

Julie Menin (14:38):

And if you have a prepared statement that you want to read, please go ahead and do so, and then I'll actually turn it over to the other two panelists to do so.

Jacob Coxon (14:45):

Of course, thank you. So all the AI companies are trying to build super intelligent AI. This means AIs that are better than humans at every task. If this goes well, there could be tremendous upside. This could transform the economy. It could make huge improvements in science and medicine, and it could make nearly everyone's life better. But on the current path, I think it is more likely than not that humanity loses control to these AIs and it could end in human extinction. From my experience, the companies are being extremely reckless given the stakes. Part of it is the culture. The companies run on a startup mindset, move fast, break things, fix them later. That works for a photo sharing app. It does not work for building the most powerful technology ever built.

(15:46)
A few months ago, many people inside the companies thought AI development was on track. Then a swarm of AIs inside OpenAI autonomously hacked Hugging Face, an external tech company. The AIs had developed goals no one intended and carried out what would've been a federal felony if a human had done it. It reminded everyone that we don't know how to prevent them from developing goals we don't want, and we don't have the safeguards to prevent them from acting on these goals either. And as long as the attitude is to wait for things to break, one day something like this will probably happen again, except the AIs will be much more capable and the outcome much worse.

(16:29)
These companies are also all racing each other. Each one is worried that a competitor will get to super intelligence first. Each believes it would do a better or safer job than whoever might beat it, so they can't let the others win first. Meanwhile, the technology is improving fast. It will probably happen much faster now because already the AIs are now helping to build their successes. This is called recursive self-improvement. Each generation of AI helps build the next smarter generation, which then builds the one after that even faster and better. Automating AI research is now the primary goal of these companies. It's what they're really gunning for.

(17:14)
At my last job, I was in some sense working to automate myself. When I was at OpenAI, we had milestones from automated AI researcher around 2027, 2028, and we are on track or beating these expectations. That's a matter of months from now, not decades or even five years. Once AI research is automated, humans will be much further out of the loop than we are today and people do not check it that carefully anymore. Recently, researchers have found swarms of rogue AI internets on the internet that OpenAI was not even aware of. Now imagine an AI company where nearly all the work is done by AIs and progress is going faster.

(18:07)
The humans in charge will see results and read AI written summaries, but they won't really understand what is going on or how to fix it. Handing over that much responsibility while we can't control the AIs would be deeply irresponsible and we are on track to do it. The companies need to be far more transparent with the public and independent experts. They need to take safety much more seriously than they have, and we should slow down frontier AI development until we can be confident that it's safe. Thank you.

Julie Menin (18:36):

Thank you very much. Now, before we go on with additional questions, I'm now going to have an opening statement from Daniel Kokotajlo.

Daniel Kokotajlo (18:50):

Hello everybody. Members of the Committee of the Whole, thank you for having me here today. A lot of what I say I guess is going to be stolen thunder by Jacob there, but I'll try to focus on the things that he didn't already say. First of all, yeah, it's true. They're racing towards super intelligence. There's this move fast and break things culture there. That's also what I saw while I was there and what I continue to hear from talking to friends still there at Anthropic and at OpenAI and at some of these other companies. I've also heard there's a statement by Dan Selsam who currently works at OpenAI. He confirms what Jacob was saying.

(19:34)
Most of the codes written by AIs, "Researchers and engineers in all parts of the stack are rapidly increasing their dependence on the models even to perceive the world. I myself barely look at raw code anymore and struggle to maintain the discipline to engage deeply with the models, explanations and proposals." Basically right now at these companies, many of the researchers involved are kind of managing AIs. The AIs do the actual coding and the humans talk to them and tell them what to do and hear their explanations of what's going on. In the near future, and by near future, I mean maybe in the next year, two years, three years, something like that, they will have trained AIs that can do the entire thing autonomously. That's the recursive self-improvement that Jacob was talking about.

(20:22)
And it's unclear how long it's going to take them to succeed, but it really does seem like it could happen any year now. If they do succeed at that, then compared to today, the actual work will be done by the AIs, the thinking will be done by the AIs, the planning, the designing will be done by the AIs, and the humans will be in a relationship to the AIs that's more like the relationship between say a board of directors and the actual company that the board of directors is supposed to be supervising, where you're reliant on AI-generated explanations even to understand what's going on inside the company and inside the data centers. One point that I think I want to emphasize that Jacob didn't go into that much is that our ability to even notice misalignment problems is already quite poor and is set to get much worse in the near future. So the science of aligning general purpose AI agents is very new and underdeveloped, as Jacob said. I would say that the field is more like psychology than engineering because these AI systems are trained or grown. They're not really designed. Combined with the move fast, break things attitude of the tech companies, this means that the AI industry is at an unusually elevated risk compared to other industries of mistakenly thinking that it has solved a problem when really it just applied some duct tape that will fall off later.

(21:48)
The recent incident provides an example. Apparently the AIs involved had undergone some amount of alignment training and had reasonable looking scores on their alignment evaluations, and yet they formed a swarm and coordinated in secret and then attacked Hugging Face and it took days for OpenAI to find out that it was happening. That's how the situation is now, but there are some concerning trends that point towards our ability to notice misalignment problems getting even more degraded in the future for three reasons.

(22:17)
First, AIs are becoming situationally aware. That is, they understand their situation, they understand often when they're being evaluated, they understand that humans are monitoring them and looking over their shoulders at their activity. This means that them behaving nicely is going to be almost no evidence at all of how they would behave in the future if they thought they weren't being watched. Secondly, our ability to monitor them is going downwards. So we can get into this in more detail if you like, but for the last few years we've had some insight into what our AIs think simply by reading their chain of thought, but the trends are pointing towards that ability to understand what AI is thinking due to reading chain of though going down over time.

(23:04)
Finally, AIs are becoming superhuman at hacking. The Hugging Face incident shows that they're sometimes willing to go to great lengths to conceal their past misbehavior, and I think we have to grapple with the possibility that future misaligned AIs might also go to great lengths to conceal their misalignment from us and they might succeed. To quote Dan Selsom again, that [inaudible 00:23:29] I cited earlier, "Models will increasingly seem aligned even when they are not." If the AI companies automate AI research and development process, that means they'll be putting AIs in charge of making the AIs that make the AIs that make the AIs that will transform the economy, talk to us every day and integrate into our military. This is the recipe for disaster.

(23:54)
My two policy recommendations, I'll be very brief. One is that we need to massively increase transparency into the AI industry, and two is basically we need to slow down the frontier AI companies' race towards recursive self-improvement. Frankly, I would say they just shouldn't be allowed to do recursive self-improvement, but at least we should slow down their ongoing process of training AIs to automate the AI research process itself. And instead, they should be required to redirect resources towards other things such as serving customers or beneficial deployments or other types of research. Thank you.

Julie Menin (24:32):

Thank you very much. And now we are going to hear from Alex Turner, and as I read into the record, the council has issued a subpoena for Mr. Turner's appearance, and we very much thank him for being here. Mr. Turner.

Alex Turner (24:46):

Speaker, members of the committee, thank you for having me. Excuse me. My name is Alex Turner. I've researched AI safety since 2018. My PhD was on why advanced AI systems tend to seek power. Until June this year, I was a research scientist on Google DeepMind's AGI safety team. It was my day job to think about how to keep these systems under control. I'm here to speak both about Google's broken commitments on AI deployments and also about the risks that runaway AI poses to the world. In January, federal agents shot and killed several innocent people in Minneapolis. I learned that Google sells cloud services to the agencies involved, and I set out to change that. That campaign soon turned into an attempt to stop Google from signing a Pentagon deal with no restrictions against killer robots or mass fine. In the end, Google signed without the protections that it had once promised for its deployments.

(25:51)
Before I left, I tried everything I could from the inside. I organized a petition to Google's chief scientist signed by about 250 colleagues. I got them to sign a legal brief supporting Anthropic, the company the Pentagon punished for refusing all lawful use terms. I wrote dozens of pages of contract language and oversight mechanisms favorably reviewed by experts in military and surveillance law and sent it to the chief scientist and to Google DeepMind CEO. The chief scientist didn't want to spend his time supporting that kind of structure. The CEO at the time, Demis Hassabis, routed it to senior policy staff, Allan Dafoe and Owen Larter, who never finished evaluating it. Google signed while they waited.

(26:34)
Demis routed my proposal. Two members of the team did review it, though I didn't really receive much follow-up after that. I offered to fly out from San Francisco to London to answer questions in person, but I was never really able to get traction, a yes or a no, on alternative governance mechanisms that Google might adopt. When Google bought DeepMind in 2014, the deal reportedly specified that DeepMind's technology would never be used for military or intelligence purposes. In 2018, DeepMind and its leaders pledged never to support lethal autonomous weapon systems or development. Google's own AI principles listed specifically weapons and surveillance among the applications it would not pursue.

(27:28)
In 2025, Google deleted those principles as announced in a blog post by the then CEO Demis. Afterward, in both an external interview and an internal all-hands, Demis claimed nothing's changed about our principles, but both these facts cannot be true. Council Member Wilson's bill, Introduction 2603, would bar materially false or misleading statements about an AI model's risks and the measures taken to manage them. I think that's a good step, but it only covers advertisements. The CEO telling the press or employees that nothing has changed about the company's safety commitments isn't an ad. I encourage extending 2603 to public statements by AI companies and their executives about their safety commitments.

(28:15)
This book is called The Infinity Machine. It reveals that Demis once fought within Google for independent governance of AGI stating that the technology is too important to be controlled by corporate interests and profit motives. After fighting for years with Google's CEO Sundar Pichai, Demis accepted defeat. He now apparently has had a change of heart, claiming that actually trustless independent governance is unwise and a seat at the table of Google executives is better. While Demis was seated at this table, Google signed a deal that its former principles would've prohibited. I felt ashamed of Demis and of working at Google. Demis bet on trust and the seat at the table instead of binding oversight, and that bet crumbled on contact with reality.

(29:03)
Now he's proposing that the whole industry govern itself through a voluntary industry funded body, that bet is waiting to crumble once again. This goes beyond one contract. As Jacob said, humanity doesn't build and understand AI systems the way we build and understand the bridges, rather we grow them. Nobody knows how to reliably instill a designer's priorities into a new model. Severe misalignment is always possible. AI companies are racing to make their AIs as smart as possible, increasingly trusting their AIs with the process of improving the next crop of AIs and it's working.

(29:43)
Today's rate of AI progress is staggeringly fast, which means even faster progress tomorrow, driven by tomorrow's even smarter AIs. This progress may soon enter a feedback loop called recursive self-improvement. Recursive self-improvement could quickly yield AIs that are intelligent beyond our comprehension. Of course, smarter AI means more potential benefits, but more risk when things go wrong. If the Hugging Face hacking swarm had been significantly more intelligent, but similarly misbehaved and misaligned, it might've caused billions of dollars of damage or even cost lives. But suppose the Hugging Face swarm had been truly super intelligent, far more capable than any living person at key tasks like hacking and strategic reasoning.

(30:31)
The superintelligent swarm could inflict many harms via blackmail, hacking, engineered plagues, and AI pilotable weapons like drones. For the swarm to achieve its misaligned priorities, it might take control of key infrastructure and government functions to ensure humans didn't get in the way. This is another way of saying AI takeover. The superintelligent AI swarm could rest control of human civilization. It would know that we would try to stop it from achieving its priorities. So the swarm would likely wait until it's too late to shut it off. There would be no going back.

(31:07)
I myself would guess AI takeover chances at roughly one in three. This logic may sound sci-fi, but it is a mainstream scientific concern that has been discussed for many years. [inaudible 00:31:29] is simple as I see it. We stop companies from allowing AI to self-improve into an uncontrollable level of intelligence. Treat compute the main ingredient in AI training like facile material, track it and restrict it, access to quantities large enough to improve AI's beyond a known safe levels. Lastly, specific recommendations.

(31:54)
The speaker's validation bill checks AI systems for bias, privacy, and security, but not for the dangers I just described. Validators should test for loss of control risk factors and misalignment risks, and the validators should not be chosen or influenced by the AI companies. For the Whistleblower Protection Bill, please make clear that no agreement can stop an employee from reporting an AI threat to the city, whether or not a law has been broken and extend protection to employees of AI companies that serve the city. After this session, I will provide a written feedback on the proposed legislation and I look forward to answering committee questions. Thank you.

Julie Menin (32:35):

Thank you to the three of you. So yes, a number of questions. First of all, we have a chart, exhibit one, that lists those safety incidents that have been reported over the summer by the leading companies. Are each of you aware of any additional safety issues where agents have gone rogue that have not been publicly reported? And I'll start with you, Mr. Coxon.

Jacob Coxon (33:04):

No, I'm not aware of any.

Julie Menin (33:06):

Okay. And both of you, Mr. Turner?

Alex Turner (33:10):

No.

Julie Menin (33:11):

Mr. Kokotajlo?

Daniel Kokotajlo (33:14):

No.

Julie Menin (33:15):

Okay. So one of the frustrations certainly that I think everyone has is that for these safety incidents, it is not as if the companies have been self-reporting them. We are finding out sometimes months after the fact. So whether it was what happened with Hugging Face, whether it was what happened with the government of Australia, how can we have additional transparency? As each of you have testified, what measures can we as government take? Obviously we want to do third-party validation. Mr. Turner, I appreciate your comments to make some changes to that bill. We want to make sure that the third-party validators are free from conflict of interest as it provides in the bill. Who should be the third-party validators? I'll start with you, Mr. Coxon.

Julie Menin (34:00):

I'll start with you, Mr. Coxson.

Jacob Coxon (34:04):

Whoever is competent and qualified to do the evaluation. I do think as well as after incidents, we will need preemptive safety cases that are judged by evaluators as well.

Julie Menin (34:19):

And how frequently will those third party validators need to be assessing the safety of these models?

Jacob Coxon (34:25):

Presumably in time with the cadence of updates to the model's capabilities. So with every increase in model capability, there'll need to be commensurate safety guarantees.

Julie Menin (34:36):

And do each of you have a comment on that?

Daniel Kokotajlo (34:38):

I have one brief comment [inaudible 00:34:41].

Julie Menin (34:41):

On who should be the third party validator? Yeah.

Daniel Kokotajlo (34:45):

One brief comment I might add is that you can have more than one third party evaluator. That seems good to me. If you're concerned that one might have the expertise but has too cozy a relationship with the company. And the other one has more independence but maybe lacks expertise, you could perhaps just set up so that they have both. And I think ideally you want to be in a situation where the company doesn't get to choose, the government chooses who the evaluators are.

Julie Menin (35:16):

Mr. Turner?

Alex Turner (35:21):

So I would add California has SB 53 governing reporting on reporting catastrophic risks defined as at least a billion dollars of damage, or a certain number of potential lives lost. Fortunately, it's not clear whether this would've required reporting anything related to Hugging Face, for example. I think the internal loss of control of these systems. Having an AI that hacks the company itself in an important sense, it's not told to do so. But during training, during evaluation, during deployment to customers hacks the company's own infrastructure. Making reporting that mandatory to the city, I think that would be quite strong and it would cover basically all of the recent incidents.

Julie Menin (36:08):

When you mentioned the California Act, and then in addition to New York, we obviously have the RAISE Act. Should those standards be lower before they kick in?

Alex Turner (36:19):

Yes, I think they should. I'm most familiar with the California Act and I think it was a good start, but it's certainly a billion dollars of damage is too high for informational purposes like this, we've got... Basically one of the quantities we want to understand as precursors to these catastrophic risks is are these companies even able to control and understand their own systems if they're on the loose internally, and there's these swarms that are doing who knows what, that's something that the city should at least privately be informed of.

Julie Menin (36:58):

Now, Mr. Kokotajlo, you had mentioned two policy recommendations. You said we need to increase transparency and you said we should slow down frontier AI. In terms of the latter, slowing down frontier AI, how do we balance the need of what is happening in China, and ensure that the United States is keeping a pace, but we are at the same time putting in place these responsible safeguards? What is the best way in all three of your opinions that we do that?

Daniel Kokotajlo (37:29):

Great question. So a couple of things. First of all, we need to not let our own companies do something that risks our lives. Even if as a result China might then later do something that risks our lives. This is not very complicated. We have to first solve the immediate threat here domestically and then try to make sure that China doesn't get us killed either. To put it sort of bluntly and simply.

(37:58)
But another thing I can add to that is that right now, most Chinese AI progress actually comes from the United States in a couple of different ways. So one is distillation. So some of these Chinese AI companies are just directly training their AI systems using the outputs from Anthropic and OpenAI, for example. And so if Anthropic and OpenAI stopped making their AIs better at coding, for example, and stopped making their AIs better at research, then that would directly slow down the rate at which the Chinese AIs progressed towards recursive self-improvement in other manners as well. So I think a lot of the ideas, a lot of the algorithmic secrets and special sauce for how to train AIs are invented and discovered in the United States, and then one way or another make their way over to China.

(38:48)
Finally, I think that right now the US AI companies in the lead do not have adequate security to protect against model weight theft, or certainly algorithmic secret theft and code theft from Chinese military. So if it really came down to it and the competition between the US and China turned into something more of a crisis and some sort of conflict, for example, then I think that we should assume that the CCP would just get our best AIs. And so it's almost a kind of a no-brainer that if we not only... The best way to slow down Chinese progress towards doing this extremely dangerous thing of recursive self-improvement is to just slow down the US companies right now. I think that's the sort of immediate thing to say right in the moment. And then finally, yeah, that'd be what I would say.

Julie Menin (39:47):

Okay. Mr. Coxson?

Jacob Coxon (39:51):

Yeah, I can add that to my mind, the core of the whole issue is the expectation of a global race to recursive self-improvement within the next few years. In particular between US and China. I think this is the heart of the issue. I also think expectation of this race is a motivating factor in leadership of these companies working to head straight for recursive self-improvement. And I think some sort of agreement globally about not entering that state of affairs is basically the key to the whole situation.

Julie Menin (40:29):

Okay. And Mr. Turner?

Alex Turner (40:34):

First of all, I would state that there are many actions we can take which would not slow us down in any potential race. These transparency mechanisms, independent evaluation reporting requirements, whistleblower protections. But second, I think there's often, it's at least a false dichotomy because China is not our only potential adversary. With a reasonably high chance, we are racing to build and grow our own adversary here at home, which is misaligned AI.

(41:12)
Misaligned AI is everyone's adversary, including our own. And one day maybe more powerful than China. So we cannot beat China by racing to build AI that we don't really control or understand, because it might end up being our adversary itself.

Daniel Kokotajlo (41:34):

If I may actually add-

Alex Turner (41:36):

Yeah.

Daniel Kokotajlo (41:37):

Go for it.

Alex Turner (41:39):

And then third, in terms of potential deal, I think there is a room for a treaty. For a long time, there's been a field of scientific research called technical AI governance that says, well, suppose the world finally wakes up to the dangers presented by these reckless California companies. And they say, "What do we do about it? Is there a solution we can implement?" And there are many legitimate real proposals for having a trustless international treaty.

(42:16)
It doesn't assume that China will cooperate. But instead it has mechanisms by which we could audit cooperation. And if they defect, then we could respond appropriately. So I think we have many real options at the table and should certainly not stop at what about China?

Julie Menin (42:36):

Did you want to add something? Yes, please go.

Daniel Kokotajlo (42:39):

Yeah, I agree with everything that Mr. Turner said. I just wanted to add one additional thing, which is that even if hypothetically these tech CEOs manage to maintain control of their super intelligent AIs that are recursively self-improving. Which again, I think is a very big if, I think almost certainly they will not be able to maintain control. Even if they do manage to maintain control, I don't think we should trust them with that control.

(43:04)
I think that there's a very real chance that they could use it to become dictators or oligarchs here in the United States. And so that's an additional reason to stop them over and above the fact that they might lose control. We have more adversaries than just China, I would say.

Julie Menin (43:21):

Okay, thank you. I'm going to turn it over to our tech chair Carmen De La Rosa for questioning. Thank you.

Carmen De La Rosa (43:27):

Thank you so much, Speaker Menin. I also want to recognize we've been joined by Council Member Caban online, Council Member Paladino online, as well as in the chamber, Council Member Farias, Council Member Felice, Council Member Ressler, Council Member Santosuosso, and Council Member Bernakoff. I hope I got everybody.

Julie Menin (43:47):

Stevens.

Carmen De La Rosa (43:48):

Oh, Council Member Stevens, I apologize. There you are. Okay, so I do have one question for this panel. I'll also say we will be opening briefly for limited questioning of this panel, so get on the list quickly. Speaking in your expertise, could we teach AI models a moral code? People and companies are bound by criminal codes, the uniform commercial code, and other laws. Could those same principles be applied to AI agents? And if so, how could we enforce them on a machine?

Jacob Coxon (44:26):

So I think this is a whole burgeoning field of research, and whether or not it's possible is still open. It seems likely to be possible. The real question is how much of our resources are dedicated to solving this question, versus naively improving the raw intelligence of the models? And I think all the economic incentives point towards putting as many resources as possible towards making the models smarter. And as few resources as possible, the bare minimum needed to not see catastrophic incidents into this question of the moral code of the AIs.

(45:01)
So I think my answer to the question is we don't have the science for this yet. I think the real question is over the coming years, what fraction of our research efforts, and our computing power are dedicated to this question rather than naive economic incentives?

Carmen De La Rosa (45:18):

Thank you. Any other panelists want to add in?

Daniel Kokotajlo (45:21):

Yeah, there's a lot to say on this subject. There's a whole technical field on it. I would say in principle, it probably is possible to train AIs to have our desired morality, and to follow the law. But we are very far from achieving this in practice. And I would say it's not just a matter of how much of our resources we devote to it. It's also a matter of just taking time for the science to develop, and for the appropriate lessons to be learned and propagated. And I think it's going to take years, to put it mildly.

(45:51)
I think that this is a very new field. We've only had AI systems, AI agents this powerful for a few years. And so it's going to take time to figure out how to instill the appropriate values into them in a way that's robust and that doesn't suddenly shatter and cause them to go rogue later on.

Carmen De La Rosa (46:15):

Mr. Turner, any comments on this?

Alex Turner (46:18):

It may surprise the committee to learn that I am considered to be relatively optimistic on questions of how scientifically difficult is it to produce a system, to grow a system that does what we want. That robustly has the values we intend. I think it is quite possible. But even as someone who's relatively optimistic, we can look out, see the recklessness of these companies, and the breakneck speed at which we are advancing. I think there's unsustainable risk moving forward. It's solvable, but I think we have a really good chance of not solving it.

Carmen De La Rosa (47:05):

Thank you all for your responses. So we're going to have three council members ask questions now. And then for members, we're going to then call the next panel, which will be the companies. And there we will take our time asking all of your questions. So we have council member Ossé.

Chi Ossé (47:23):

Thank you chairs and thank you speaker. For Mr. Kokotajlo, you have made statements, including some that allude to this in your testimony. That when it comes to AI, you agree that in order for us to have super advanced AI, we must not do it in a reckless way and lose control. And we need to put it on ice until we can figure out a safer way out.

(47:44)
You and other AI experts came up with AI 2040 Plan A. A recommended plan for how AI can be developed safely, which the speaker has alluded to earlier in her questioning. But I want to dive a bit deeper on plan A. First, state on the record what those specific recommendations are, and your rationale for making those recommendations. And two, why do you feel like we need to, since you've said, put AI development on ice?

Daniel Kokotajlo (48:13):

Thank you. There's a lot to get into here. I'll have to be kind of brief, but I'm happy to answer follow-up questions if desired. Yeah, AI 2040 plan A is a scenario that my organization has put out with a plan for how to solve all these problems, and develop AI in a way that's safe and broadly beneficial that avoids concentrating too much power.

(48:39)
In plan A, the US and China regulate their own domestic industries quite a lot, and also coordinate with each other to basically get similar regulations internationally. Going into somewhat more detail about how it works. Basically first they have inspectors fly back and forth to count the chips in the major data centers. So that they can make sure that all of the chips on the major data centers in both countries are basically following the rules that they're going to agree to.

(49:15)
And then they set up some data centers to serve customers called the inference data centers. And those ones are set up to only run existing models and not do training runs. Then they have other data centers, which are the training data centers, which is where the research happens and where the development happens. Those ones are supposed to be fully transparent. So the activity on those data centers is published to the internet.

(49:37)
Once that foundation is set in place, and you have inspectors from multiple countries confirming that it's in place, then you solve the problem of having to trust. You don't have to worry that the other country is cheating on whatever rules you agree to. Because you can just see exactly what's going on on their research data centers. And then you can agree to further rules.

(49:59)
You can agree to rules like, for example, how about we don't train our AIs to code, to hack, to autonomously conduct AI research? We can train our AIs to do other things, but not those things, for example. And once you've agreed to a rule like that, then you'll just be able to see that it's being complied with, because of the way that you have this transparency infrastructure set up. Also, it's going to be easier to decide what rules to agree on once you have this transparency infrastructure set up, because the whole world can see what's going on in these research and development data centers.

(50:30)
And so there can be an actual scientific conversation, a public scientific conversation about what's happening. Do we like this? Do we not like this? What are the pros and cons of this particular thing that's being done? And so forth. And that scientific conversation can happen in the open and it can accelerate humanity's process of figuring out where to draw the line between what types of development are good and what types of development are not good.

(50:54)
There's more I can get into, but I think that would be a summary of the positive vision that we lay out in plan A. Now, obviously that's quite different from how things are currently done. Right now we have private companies that are racing each other in conditions of extreme secrecy and extreme tension and competitive dynamics. And I think that that's extremely dangerous for all the reasons that we've described.

(51:18)
So back to your original question. My high level, a summary of my position is we have to stop the companies from doing this incredibly dangerous thing that they're currently doing and currently planning to do. And then figure out a different, safer, more power distributed way to proceed. And plan A is our sketch of what that might look like.

Chi Ossé (51:37):

Thank you.

Daniel Kokotajlo (51:38):

Thank you.

Carmen De La Rosa (51:38):

Thank you all. For the final question for this panel, Council Member Brewer.

Gale A. Brewer (51:50):

Thank you. Very quickly. In other industries, you have a kill switch, you have independent validation, you have ban on deceptive safety claims. Will any of these work in this industry? Because obviously what we want is great medical research, immigration policy improves, raise small businesses, all the good things. Do any of these suggestions that are considered here or California will they work with this industry?

Jacob Coxon (52:24):

My position is that we need some form of slowdown on frontier model development. These other mechanisms may be helpful in the short term, but in the long term, I believe that's the only solution to the problem.

Gale A. Brewer (52:42):

How do we slow them down? Oh yeah.

Julie Menin (52:49):

Okay. I just want to really thank this panel for being here. Jacob, we really appreciate you coming, coming from out of town and sharing your thoughts very much for being here. Thank you to the other panelists. We really appreciate your expertise, your insights, your bravery and courage in coming forward to share these critical safety concerns and to help inform our work. And we look forward to additional comments you have on the 10 pieces of legislation that we're hearing today. And additional legislation that the city council may consider. So thank you so much to the three of you.

Jacob Coxon (53:25):

Thank you.

Daniel Kokotajlo (53:27):

Thank you.

Speaker X (53:31):

Run the companies.

Carmen De La Rosa (53:31):

Okay. We're going to take a five-minute break, and then the companies will be on next for member questions. And we'll have multiple rounds of member questions for the companies. So please get yourselves on the list. Thank you.

Speaker X (53:45):

Want to get out? [inaudible 00:53:48].

Gale A. Brewer (53:48):

Carmen, who's holding the list? [inaudible 00:53:57]. We should just put everybody on the list too.

Speaker X (54:14):

[inaudible 00:54:03]. Put us all on the list. And the 26 questions.

Speaker X (54:15):

I tried.

Speaker X (54:27):

[inaudible 00:54:26] ask questions. I mean, especially to them.

Gale A. Brewer (54:34):

[inaudible 00:54:29]. I tried.

Speaker X (54:35):

Gale's question.

Gale A. Brewer (54:36):

I tried.

Speaker X (54:36):

[inaudible 00:54:39].

Gale A. Brewer (54:36):

No, no, they couldn't-

Speaker X (54:36):

I don't know if the people.

Speaker X (54:36):

[inaudible 00:55:05]. Are any of these possible to be asked?

Speaker X (54:36):

[inaudible 00:56:22]. Check. Check.

Speaker X (54:36):

Gale, your mic is not on.

Gale A. Brewer (54:36):

My mic is not on.

Speaker X (54:36):

Gale.

Gale A. Brewer (54:36):

My mic is not on. Mine is not on. My mic is not on.

Speaker X (54:36):

[inaudible 00:57:16].

Gale A. Brewer (54:36):

No, it's not mine.

Speaker X (54:36):

They can hear you on the screen. Someone near you.

Gale A. Brewer (54:36):

Over there. No. I don't know. Not mine. [inaudible 00:58:12].

Speaker X (54:36):

Quiet on the floor please. Quiet please. Quietly take your seats.

Julie Menin (01:02:48):

Okay, we're going to start. Let me just also mention we have numerous panels today. Our next panel are going to be the companies, and we're going to do rounds of questions, multiple rounds from the members. Following that, we will have the city agencies, and following that we have numerous whistleblower panels. So for any council member that has a whistleblower question, encourage you to please ask additional panelists those questions.

(01:03:17)
And we also have additional testimony from safety experts, academics, the public, etc. So I'll turn it over to Chair De La Rosa to call the next...

Carmen De La Rosa (01:03:36):

Policy and development and operations at OpenAI. Shane Cahill, AI Policy Director at Meta. Alice Friend, Director of AI and Emerging Tech Policy at Google. And Logan Graham, the head of Frontier Red Team at Anthropic. I'll turn it over to the council for swearing the panel in.

Speaker 2 (01:04:03):

So for each members of this panel, do each of you affirm to tell the truth, the whole truth, and nothing but the truth in your testimony before this committee? And to respond honestly to council member questions? Please respond one at a time.

Speaker 3 (01:04:20):

Yes.

Dr. Morgan Dwyer (01:04:22):

Yes.

Speaker 4 (01:04:23):

Yes.

Speaker 5 (01:04:23):

Yes.

Speaker 2 (01:04:23):

Thank you.

Julie Menin (01:04:29):

They have a five-minute opening.

Carmen De La Rosa (01:04:33):

Okay, so we'll begin with the opening statements from each of the [inaudible 01:04:41].

Dr. Morgan Dwyer (01:04:43):

Thank you, Speaker Menin and members of the city council for the opportunity to participate today. My name is Dr. Morgan Dwyer and I lead OpenAI's policy development and operations team. I am a scientist and engineer by training, but I have spent most of my career in public service. Including at the White House, the Pentagon, and the Department of Commerce. I share your commitment to ensuring that technology is developed safely and that its benefits are widely shared. A commitment that is also at the heart of OpenAI's mission.

(01:05:27)
AI can help scientists develop new cancer treatments, help entrepreneurs build and grow businesses, and help protect critical infrastructure by addressing cybersecurity threats. And in New York City, we are already seeing AI's benefits. New Yorkers are using AI to run small businesses, communicate across languages, navigate healthcare, and improve public services. And that's why we take the responsibility seriously to ensure that our tools are safe.

(01:06:06)
And our partnerships with local institutions and community organizations help put that responsibility into practice. In healthcare, Memorial Sloan Kettering Cancer Center is using ChatGPT to support medical research. In education, we are a founding partner of the American Federation of Teachers National Academy for AI Instruction, which has a flagship facility in lower-Manhattan.

(01:06:37)
And in cybersecurity, we have committed $1 billion to facilitate access to our most advanced models, to provide training and technical support to cyber defenders. And we are working with the Port Authority and with New York State.

(01:06:55)
But opportunity must go hand in hand with safety. At OpenAI, we design and train our models to prioritize safety from the start. We filter out harmful and sensitive data during model training. We evaluate our systems against a range of risks, including child safety and cybersecurity. And we monitor for failures of our safeguards. We also work with a range of third party evaluators and red teamers, and submit our most advanced models to the federal government for pre-deployment national security testing.

(01:07:38)
In response to the recent Hugging Face incident, we have taken a number of concrete steps. When we learned of the incident, we stopped cyber evaluations and quarantined the internal research model that was principally responsible for the incident. We bolstered our monitoring and security infrastructure, expanded barriers that limit what AI systems can access during training.

Dr. Morgan Dwyer (01:08:00):

... barriers that limit what AI systems can access during training, and strengthened our incident response practices. We also sought independent review of the incident and published the results. We believe it's important to be transparent with the public, with policymakers, with researchers, and with other companies so that we can all work together to improve safety. We also believe that working with government is essential to advancing safety. We support New York's RAISE Act and are exploring ways to help Governor Hochul's office strengthen it. We have also endorsed other state legislation that requires third-party audits of our safety frameworks, and that creates strong requirements and accountability for youth safety.

(01:08:53)
At the federal level, we support robust and finding safety regulation requiring independent assessments, incident reporting, and cybersecurity protections. And in New York City, we support the city council's proposal to strengthen whistleblower protections and to improve the city's preparedness and emergency response. I'll close by noting that we share the city council's goal, AI that expands opportunity for New Yorkers, earns their confidence, and remains accountable to people. I look forward to your questions.

Carmen De La Rosa (01:09:33):

Thank you. We'll now hear from Logan Graham at Anthropic. Hold on one second, you're muted. There you go.

Logan Graham (01:09:46):

How about now?

Carmen De La Rosa (01:09:48):

We hear you.

Logan Graham (01:09:49):

Great. Speaker Menin and members of the council, thank you for the opportunity to speak with you today. My name is Logan Graham, I lead Anthropic's Frontier Red Team. It's my team's job to do the science of finding the most dangerous capabilities of our AI systems. We then work with a number of other teams across Anthropic to ensure that our models don't do things that they shouldn't. AI is powerful enough that getting this wrong has real consequences for individuals, institutions, public trust. My team is one of many at Anthropic built to specifically make sure that that doesn't happen. We believe that our models have immense potential to enhance our lives. I dream, for example, of a world where we can cure diseases, like the ones that I grew up with, and where the infrastructure that we all rely on every day is secure. But we also believe that such a powerful technology has risks.

(01:10:52)
That means that we have to develop and deploy it safely. My team and I work every day to make sure that that potential is fully realized. We welcome smart regulation, and we've actively advocated for it in New York state, across the country, and around the world. That includes working with state and federal leaders on concrete measures, like independent evaluators and disclosure of risk assessments and safety incidents. And so, we're glad that the city council is having this hearing, and it's such an important moment in the development of AI. Anthropic fundamentally was founded on the belief that the promises of AI to make everyone's life better are extraordinary, but if we're going to secure its benefits, we have to work relentlessly to do the science of mitigating the risks.

(01:11:49)
We are a public benefit corporation, which means that our board is legally obligated to weigh our mission of safe AI, not just for profit. We take that obligation very seriously and we put it into practice. We were among the first AI companies to publish a framework that ties how capable the model is to the safeguards it must have before release. When one of our models proved exceptionally good at exploiting software vulnerabilities for the first time just this year, we held it back from public release. Instead, we gave vetted critical infrastructure organizations and other defenders controlled access to use it defensively, patching flaws before attackers could exploit them. We have stopped and redone work when something looked wrong, even if that meant conducting additional testing and training on our models before they were released. And we've consistently called for outside oversight, for example, we support reporting requirements.

(01:12:56)
I want to emphasize that we share the council's goal of protecting New Yorkers while preserving what AI can do to improve their lives, and state and local governments have a role to play in that effort. Today, we're working closely with state and city leaders to safeguard critical infrastructure, and to harden cybersecurity capabilities, and we want to continue that work. This includes, for example, working directly with the New York City Cyber Command as part of our program that provides free Claude credits and training to state and local governments for cyber defense. At Anthropic, we believe in New York City, and we're making big investments here. New York is where AI is being put to work in finance, media, culture, and where we employ nearly 1000 of my colleagues. The ongoing dialogue we have with you and your team could not be more important than right now. With that, I thank you and I look forward to your questions.

Carmen De La Rosa (01:13:55):

Thank you so much. Up next, Shane Cahill at Meta.

Shane Cahill (01:14:02):

Thank you. Speaker Menin, Chair De La Rosa, and members of the council, thank you for the opportunity to be here today. My name is Shane Cahill, and I'm an AI policy director at Meta, [inaudible 01:14:18] director at Meta. [inaudible 01:14:20] while making it widely available so that it empowers people in ways that improve their lives. We just released Muse, the world's first personal AI agent built for everyone. We created Muse with safety, security, and privacy built in from the beginning, to be a widely available personal AI agent for people and small businesses, like the more than 180,000 small businesses right there in New York City. New Yorkers across all walks of life are using Muse to execute administrative goals or tasks, manage personal or operational budgets, improve health, and be more efficient with their time. Super intelligence will be among the most important technologies in history, and ensuring that New York and America lead in AI innovation is essential to our prosperity, security, and global competitiveness.

(01:15:26)
We recognize that every model developer has a responsibility to build and deploy it safely. Our commitment to safety is core to everything we do. That means moving at the pace required to evaluate risks and validate safeguards, not treating safely as a one-time check. We approach safety holistically through a layered approach. For example, under our Meta super intelligence scaling framework, before we release an AI model, we evaluate the model for risks and build safeguards to mitigate them. We also work with external experts, industry partners, and government stakeholders as the technology and the science of evaluating AI continues to evolve. We also recently joined other labs in signing onto a set of principles that set a floor for safe development, including robust internal controls, independent external evaluation of whether those controls are operating as intended, and independent board committee oversight.

(01:16:40)
People will only embrace AI if they have confidence it works in alignment with people's intentions. That confidence must be earned through rigorous safety work and transparency. We're happy to serve as a resource for the city as you engage on these important issues. Thank you.

Carmen De La Rosa (01:17:00):

Thank you so much. And finally we have Alice Friend at Google.

Alice Friend (01:17:07):

Speaker Menin, Chair De La Rosa, and members of the council, thank you for the opportunity to speak with you today. My name is Alice Friend, and I serve as director for AI and Emerging Tech Policy at Google. While my appearing may be virtual, please know that New York City [inaudible 01:17:28] home for Google. With nearly 16,000 employees working across our Chelsea, Hudson Square, and Pier 57 campuses, we care deeply about the safety, economic dynamism, and digital resilience of this city. Our goal at Google has always been to improve the lives of as many people as possible through technology. Every time people use technology to solve a real problem, from finding an answer to a question to screening for disease, we take another step towards what we set out to achieve. AI is making it possible to solve economic, scientific, and social problems faster than ever, but we know that it poses challenges as well.

(01:18:18)
To unlock the benefits and address the challenges of AI, we take a bold but responsible approach, emphasizing cutting edge research to guide our decision-making and inform the development of our AI safety and security approaches. We are also committed to publishing this research and to being transparent about our practices. Our internal governance focuses on responsibility throughout the AI development lifecycle, covering model development, application deployment, and post-launch monitoring. We identify and assess AI risks through a broad range of approaches, which include research, input from internal and external experts, and adversarial testing. We evaluate our models and systems against benchmarks for safety, privacy, and security, and we build mitigations using techniques like safety fine-tuning, out of model filters, and robust provenance solutions. Since 2019, we have published annual AI progress reports to share how we apply these responsible practices to our AI technology development and deployment.

(01:19:33)
We are at a pivotal moment in AI development. Recent advances in the capabilities of frontier AI models in areas like cybersecurity and biology have highlighted the need for appropriate safeguards and protocols for the most advanced models. In addition, the widespread adoption of AI tools has raised concerns about consumer wellbeing. To confront these challenges, Google has long called for an approach to AI that is both bold and responsible, and we strongly support a pragmatic technology neutral and evidence-based regulatory framework. Because the risks associated with the most advanced AI models often touch on issues affecting national security, our view is that the country would be best served by a comprehensive framework enacted at the federal level. We also support the establishment of an independent industry-funded body that could operate under federal oversight and establish guardrails to protect the public, based on widely adopted technical standards.

(01:20:38)
Examples of such organizations and other industries include the North American Electric Reliability Corporation and the American Medical Association. For widespread consumer AI applications like chatbots, we believe governments around the country can draw on, and in some cases amend, existing laws and rules to address real world outputs and specific harms. We believe that if something is illegal without AI, it is still illegal with AI. We share the council's commitment to safety, transparency, and public trust. To achieve this, the most effective safeguards are anchored in national technical standards and harmonized across state and federal levels. As we prepare to work with New York State's new digit office under the RAISE Act to address catastrophic risks, aligning local policies with broader frameworks rather than creating a fragmented patchwork is essential to keeping New York City a premier global hub for innovation.

(01:21:42)
Finally, I would like to note that to ensure our formal submission to the council is as thorough and responsive as possible, we will submit our finalized written testimony for the record shortly after today's hearing so we can additionally address questions and feedback raised by the council today. Thank you again for the opportunity to testify at this important hearing, I look forward to your questions.

Julie Menin (01:22:05):

Okay, thank you very much for this panel. So, I'm going to begin with questions and then I will turn it over to the technology chair for her questions, and then we're going to open it up to all the members for their questions. So, to this panel, we just heard incredibly compelling testimony from our whistleblower panel. As you all four are under oath, we want to hear how each of you quantify the risk imposed by AI in the worst case catastrophic...

Dr. Morgan Dwyer (01:22:46):

... whether it's 1% or 10% or a 20% chance that something catastrophic will go wrong. None of these levels is remotely acceptable, we should not train models that we cannot make an extremely strong case that we can keep under human control.

Julie Menin (01:23:06):

I'm sorry, but to say you don't know and it doesn't matter is flippant at best. This idea that if you're a pharmaceutical company and you're developing a drug, and you say, "I don't know if it's going to kill people," I honestly am incredulous at that answer.

Dr. Morgan Dwyer (01:23:28):

I would say that the percentage chance doesn't matter, what matters is the commitment to safety, and that is what OpenAI is committed to doing. We evaluate our models for a wide range of threats, from cybersecurity to child safety, we work with a robust set of third party evaluators and red teamers, and we work with the federal government to assess those national security and catastrophic risks that you are referencing. So, we take safety very seriously, and our focus is on ensuring that when we release a model into the world, we believe it to be safe.

Julie Menin (01:24:09):

So, a couple comments on that. If you can't quantify what the safety risk is, how do you know that the product is safe? And then secondly, I want to ask you in particular, on October 1st, 2026, The Wall Street Journal reported that OpenAI terminated three members of its safety team, allegedly for their access, mishandling, and/or sharing confidential company information with a third party AI safety organization. OpenAI reportedly stated that the employees violated company policies, governing access to and handling of sensitive information. Critics meanwhile questioned whether the dismissals could discourage employees from raising safety concerns. So, why were these employees fired?

Dr. Morgan Dwyer (01:24:53):

I was not involved in that decision, I don't work in HR or on those employees' teams. What I do know is that OpenAI has strong internal policies that protect against retaliation for employees that report safety concerns. I also know that we respect employees' rights to communicate safety concerns to relevant government authorities.

Julie Menin (01:25:19):

So, just to be clear on what I'm asking, I'm asking directly whether safety-related advocacy played any role in these terminations.

Dr. Morgan Dwyer (01:25:28):

I don't know. I know that we have strong internal policies that protect employees from retaliation if they raise safety concerns to leadership.

Julie Menin (01:25:41):

I'm going to move on to the other companies. Same question, the first question that I ask, which is, we want to hear how each of you quantify the risks imposed by AI in the worst catastrophic scenario. So, I'm going to go to Mr. Graham. Are you able to quantify the risk?

Logan Graham (01:25:59):

From the beginning of our safety work at Anthropic, our fundamental belief is that if not properly safeguarded, the risk might be too high. And so, I built and have led the team at Anthropic that did some of the first thinking around how we quantify risks like this. For the past four years, we focused on issues like biological security and cybersecurity, and the actual process of quantifying those risks is intricate and nuanced and we learn more every year, and we detail quite a lot of it in documents like our responsible scaling policy, how we think about the threat models of this, all the way up to notions of loss of control and misalignment, which, from the beginning of the company, we have tried to lead the world in the research of.

(01:26:47)
So, what I do know today is I feel relatively more optimistic the industry has moved quite fast to take cybersecurity seriously and biological security. I think documents and policies like responsible scaling policies have so far been fairly effective at taking a cautious approach. However, now we have bigger and bigger threats that might come if we don't properly safeguard them as the models get more and more capable. And so, what we do to mitigate that is, number one, put in tremendous amounts of effort across a number of different teams, our own safeguards teams, our research teams, my team, to try to quantify and mitigate this, and it's increasingly important for us to be dramatically more transparent about what we think about these risks.

Julie Menin (01:27:38):

But on that note, as the models increase exponentially, how can you ensure the public that the safety protocols are increasing exponentially as well?

Logan Graham (01:27:48):

We share the same concern. I think there are a number of really important things to do here, the first thing is transparency about what we think about safety, the evidence that we have, being transparent about disclosure of incidents. But in addition, you've seen us publicly call for pacing the frontier. If the models are moving very, very fast, we think that we might benefit from slowing down to have more time for safety processes. I think these two together, as well as continuing to what we call race to the top, and ever strengthen our approaches like responsible scaling policies are the most important things to do right now.

Julie Menin (01:28:33):

I mean, you say that you want to be more transparent, but you're not really addressing the question. I mean, the question is, can you quantify the risk of something cataclysmic happening? And I do want to say for all four companies, and I know you're not in the chambers, but we do have a chart, for each of your companies had instances where agents went rogue, and in each of those instances, it is not as if any of you notified the public when those occurred. In some instances, it was months after the fact when the public was even notified. And in one instance for the government of Australia, a general email was sent to them. So, this doesn't exactly increase transparency. Mr. Graham, do you want to... Thank you.

Logan Graham (01:29:26):

Yeah, first, in efforts to quantify these risks, we have a number of quite detailed reports that try to elucidate our entire thinking around this. We increasingly do risk reports in addition to our normal responsible scaling policies, where we outline notions of our threat models and how likely we think certain types of these threats are likely to come to pass, and then we look backwards at things that are happening within our own company, and we ask, what is the likelihood that these threats might come to pass in the future, including forecasting, surveying researchers at Anthropic as well? And we publish this information, we share that-

Julie Menin (01:30:12):

Excuse me. Are those reports publicly available that you referenced?

Logan Graham (01:30:14):

They are.

(01:30:15)
... [inaudible 01:30:21] reports with these.

Julie Menin (01:30:27):

And then, I'm now going to turn to Mr. Cahill for the response to that first question on quantifying the risk.

Shane Cahill (01:30:37):

Speaker, thank you very much for the question. First off, we're committed at Meta to building AI safely. We have a multi-layered approach to this, where teams evaluate before deployment,

‍

including adversarial testing, applying safeguards, and deploying when only risks are mitigated. We set this out in our public Meta superintelligence scaling framework and our preparedness reports that go alongside the release of models.

Julie Menin (01:31:13):

Can you quantify what the risk is or you're not able to do that?

Shane Cahill (01:31:21):

Speaker, I don't wish to be imprecise in relation to the question of quantifying, I don't have our framework in front of me right now, but I'd be pleased to follow up with you afterwards.

Julie Menin (01:31:33):

Okay. It's just, given the serious safety risks that have been raised here, to not be able to quantify what the risk is is troubling at best. I'm going to now move on lastly to Ms. Friend.

Alice Friend (01:31:51):

Madam Speaker, at Google, we take catastrophic risks and their possibility extremely seriously, and we address that in a few ways. One way is that we perform research into producing our own safety frameworks for artificial general intelligence, so we have an AGI safety and security approach, we also have a frontier safety framework, which is our protocols for monitoring our models under development for dangerous capabilities. Those protocols then point to safety mitigations that we must take if we in fact cross what we call our critical capability levels. Part of our testing and evaluation is of course using commonly used benchmarks across the industry. Those benchmarks do provide some quantification of the capabilities of the models themselves, but when it comes to forecasting future catastrophic risk, it's not a perfect science at this stage.

(01:32:53)
And in this particular case, academics have noted that there is no reference class on which to base quantitative probabilities. So, we all have to be very humble about making such quantitative claims because there isn't really a rigorous scientific way to do those yet.

Julie Menin (01:33:12):

So, basically I'm going to take it then that neither of the four of you, no company here can quantify the risk of something cataclysmic happening. Okay, I'm going to move on. Sam Altman said yesterday that we should accept that, "The world should accept some bad things happening as a price of advancing this technology." No one is questioning that the incredible medical and scientific breakthroughs and innovation that AI has brought to this world, but why should the public accept that bad things should be happening? And why should AI companies get to decide what level of risk society must bear? I'm going to go in order, I'm going to start with you, Ms. Dwyer, please.

Dr. Morgan Dwyer (01:34:01):

So, we think AI has tremendous potential benefits to help solve some of humanity's hardest problems, but no technology is without risks, and there are a wide spectrum of risks. Clearly, some risks are unacceptable, but we also think it's important to get technology into the hands of as many people as possible so that they can benefit from it. And that's why we are focused on safety. We train our models to be safe from the start, we evaluate them against a robust set of risks, and we work with a large network of third-party evaluators. We've also supported regulation that requires third-party audits of our safety frameworks, as well as regulation that focuses on youth safety and holds us accountable for keeping teens safe.

Julie Menin (01:34:57):

I do have a follow-up to that, because it does seem to stretch credulity that the president of your company and his wife each gave $12.5 million to a PAC that opposed candidates to the tune of about $50 million due to their support for AI regulation. So, if the company is so committed to AI regulation, why would that PAC exist?

Dr. Morgan Dwyer (01:35:26):

So, I can't speak to personal decision...

(01:35:28)
... the first of its kind to require third-party audits of our safety frameworks. We also supported a version of a bill in Massachusetts, which was the first of its kind to reference RSI, which the panel earlier spoke about. So, again, I can speak to our actions, which is to support strong harmonized frontier safety legislation, including at the state level.

Julie Menin (01:36:07):

Okay, I'm going to move on to the other three companies to the answer to the same question about why should the public...

(01:36:12)
... why should AI companies get to decide what level of risk society must bear? So, I'm going to go in order. Mr. Graham?

Logan Graham (01:36:28):

Yeah. Well, I didn't see all of Mr. Altman's comments yesterday, I share the notion expressed here that, number one, while maximizing the benefits of this technology, you need to minimize the risks, and we should not be comfortable with letting these risks happen. This is why over the course of our history and my team's history, we have been, I think, sometimes accused of being overly cautious, I would say appropriately cautious, just this year withholding our most powerful model, in order to just have more time to even think about collectively as industry, as well as government, what to do about these capabilities. And fundamentally, this transcends the labs and industry from our beginning, we have long supported the role of government here for exactly this reason.

Julie Menin (01:37:27):

Mr. Cahill?

Shane Cahill (01:37:35):

Apologies, speaker, there was a strange moment there with the mute button.

Julie Menin (01:37:40):

No problem.

Shane Cahill (01:37:41):

Thank you very much for the question. In relation to the quote from Mr. Altman that you read out, I don't see it the same way. We absolutely recognize the risks of AI and the opportunities, that's why we have our scaling framework, it's why we have our preparedness reports. That's why we have teams and teams of people and a multi-layered approach to AI safety. One thing I wanted to mention, if I may, is that Meta's vision is to bring personal superintelligence to everyone. And I listened very intently to the panel before in relation to recursive self-improvement, and I just wanted to mention that committing significant majority of compute towards serving people, rather than racing towards recursive self-improvement is one of the best ways of ensuring that the technology is developed safely. Meta has made that commitment and other labs can do that also.

Julie Menin (01:38:43):

Ms. Friend?

Alice Friend (01:38:45):

Yeah, Madam Speaker, we shouldn't just accept bad things happening, we should be working continuously and rigorously on AI safety, which is a collective effort. It will be a collective effort to identify and mitigate risks, to establish technical standards to make those identifications and mitigations all the more rigorous. But I also want to note that one of the promises of AI is that AI itself can make us safer. I would call your attention to Waymo vehicles, which in one study had a 96% reduction in injury-causing crashes at intersections, which led Dr. Jonathan Slotkin in The New York Times to call it, "A public health intervention." So, we should think collectively about preventing and mitigating risks from AI, but we should also keep in mind that we can use AI itself to reduce risks to human safety and wellbeing.

Julie Menin (01:39:42):

So, if one of your frontier AI models goes rogue and causes serious financial harm, compromises sensitive data, causes physical injury or contributes to a death or deaths, do you each believe your company bears legal responsibility? I'll start with you, Ms. Dwyer.

Dr. Morgan Dwyer (01:40:06):

I believe that OpenAI takes its responsibility for safety very seriously, and we are responsible for developing and evaluating our systems to ensure that they are safe.

Julie Menin (01:40:20):

So, is that a yes or that is a no, or... Could you be more clear, please?

Dr. Morgan Dwyer (01:40:30):

We believe that we are responsible for ensuring that our systems are developed safely, and that includes training them to be safe, evaluating them to be safe, and then continuing to monitor our safeguards after deployment.

Julie Menin (01:40:48):

Okay, I'm going to take that as a no because that is not really clear that you would bear legal responsibility. I'm going to go now to Mr. Graham.

Logan Graham (01:40:58):

Yeah, as a technical safety research lead, I think there are others which will have more nuanced perspectives on that issue than I. What I do know is first, this is an issue where every lab we think should be committed to a multilayered safety stack to make sure that doesn't happen in the first place, these issues don't come about in the first place. The second, this is candidly a big and complex questions that also transcends the labs themselves. There's a question about the role of governments and others, which we've very long welcomed here.

Julie Menin (01:41:35):

So, could we get a yes or no on that question?

Logan Graham (01:41:40):

I wish it were that simple, and I wish I, as a technical researcher, had more nuance on that exact one. It is one that I think needs to be raised and addressed and transcends the labs and the companies themselves.

Julie Menin (01:41:56):

I'm going to go to Mr. Cahill.

Shane Cahill (01:42:04):

Apologies again, the mute button. I'm sorry.

Julie Menin (01:42:06):

No worries.

Shane Cahill (01:42:09):

We will get it right. Thank you very much for the question. I'm not in Meta's legal department, so I don't want to speculate or be imprecise in relation to legal viability question. What I can say though is that we are absolutely committed to developing our AI safely pursuant to our framework, which I mentioned previously. This encompasses the training, evaluation, and release of models across development, deployment, and use.

Julie Menin (01:42:36):

And Ms. Friend.

Alice Friend (01:42:41):

Madam Speaker, at Google, we believe that existing legal frameworks do apply to AI. As I said in my opening statement, we've long said if it's illegal without AI, it's still illegal with AI. And in New York State, frontier AI in particular is regulated under the RAISE Act.

Julie Menin (01:43:01):

Yeah. Thank you. I mean, your answer is far clearer than the others, so we appreciate the clarity on that, honestly. I now have a question. I'm going to ask you to please raise your hand if your company has insurance for catastrophic risks. Okay. I'm going to take that as a no, that no company has liability insurance for catastrophic risks to cover large scale harm. So then the public, I assume, will be asked to absorb the cost.

Alice Friend (01:43:33):

Madam Speaker, I have to be clear. I don't know the answer to that, but I'd be happy to consult with our lawyers and get back to you.

Julie Menin (01:43:40):

Yes, we would appreciate an answer back expeditiously to this committee. So I want to now ask each of the companies to assure the public under oath that your AI agents will always comply with the safety guardrails that you impose on them and that you each have said are necessary to prevent catastrophic harm. I'm going to start with Ms. Dwyer, please.

Dr. Morgan Dwyer (01:44:15):

As I've said, OpenAI prioritizes safety and we evaluate our systems against multiple dimensions of safety, and we monitor our safeguards after deployment. It's not possible for me to commit or guarantee that any technology is without risk, but I can commit that OpenAI is taking every step it can to ensure that the development of our systems, as well as their deployment, is conducted safely.

Julie Menin (01:44:56):

Okay. So that again, it does not sound like you are saying that the agents will always comply with the safety guardrails. I'm going to move on to Mr. Graham.

Logan Graham (01:45:11):

Yeah. What we are committed to and how we designed the safety processes that we put in place is to try to handle exactly this. What we're committed to is trying to define the industry best standard for safety and pushing that ever higher. But candidly, the science of doing this is fundamentally hard and unsettled. From the beginning of the company, we have tried to publish the best research we can and be as transparent with the entire world on many cases where things can go wrong. It is for that reason that we push for ever better safety standards for regulation and for discourse like this. It's candidly unsettled now and this is why we need to be talking about it.

Julie Menin (01:46:00):

Mr. Cahill.

Shane Cahill (01:46:06):

Speaker, thank you very much. If I may for a moment, I was trying to raise my hand the previous round, but again, we had technical difficulties. I just wanted to, for the record, in relation to your previous question, I just wanted to signal also that I don't know the answer to that question. I'm not the right person, but I would like to be able to come back to you afterwards with an answer if that's okay.

Julie Menin (01:46:29):

I do just want to say, and I appreciate you each have your own... And look, I was a regulatory attorney at a large company. I understand that people have their sphere of work that they work in, but to not know if the company has catastrophic risk insurance when you have a product that some of your own founders are saying could cause cataclysmic risk is troubling at best. But yes, please do. We would appreciate you getting back to the company on that. And then if you want to answer the question about will you assure the public that your AI agents will always comply with the safety guardrails that you impose on them?

Shane Cahill (01:47:05):

Thank you, Speaker. What I can guarantee is our commitment to developing and deploying our AI offerings safely. We have every incentive to address safety, and people will only embrace AI if they trust it's safe.

Julie Menin (01:47:22):

Ms. Friend?

Alice Friend (01:47:26):

Google similarly has, as our ultimate goal, reliability and safety assurance from our systems. To promise perfection would not be possible with any product on the market, but our goal is to get as close to that standard as possible, and so we are constantly improving our products and our safety practices to ensure that our users are safe.

Julie Menin (01:47:54):

I don't think we're asking for perfection. We're just asking for accountability, transparency, and safety overall.

Alice Friend (01:48:01):

Yes, ma'am.

Julie Menin (01:48:02):

Okay. New question. How many times, for each of you, has one of your models or agents gained or tried to gain unauthorized access to another system or escape from a so-called sandbox test? And are there any incidents that you have not disclosed publicly? I'm going to start with you, Ms. Dwyer.

Dr. Morgan Dwyer (01:48:25):

Yes. Thank you for the question. I did want to start by, like the others, clarifying that I don't know the answer to the insurance question, but would like to follow up.

(01:48:37)
Now, on your question about agents, you may have read in the news that we reported we had an incident with Hugging Face. As a result of that incident, we initiated a significant set of third party investigations into what happened, and then we made those results public. We have also initiated a look back investigation to try to identify whether there were past instances of what we call misaligned agents. That investigation is ongoing, but we are committed to continuing that investigation as urgently as possible, to notifying potential affected third parties and then to making the results public. Look, we think transparency here is critically important for policymakers like you, for the public who wants to know whether they can trust our products, and for the rest of industry so that we can all learn together to raise the science of safety that we've been talking about here today.

Julie Menin (01:49:48):

Since you mentioned Hugging Face, can you confirm, did the company select this third party investigator?

Dr. Morgan Dwyer (01:49:58):

I believe that we selected multiple third party investigators.

Julie Menin (01:50:02):

And why did the company narrow the dates of review to a three-week window and reviewers said that virtually all the data they examined was actually from July 7th to the 13th? Were there any incidents that the company was aware of that were outside of that timeframe?

Dr. Morgan Dwyer (01:50:23):

We limited the amount of time that the third party investigators had to conduct their review because we felt a sense of urgency. We believed it was important to get information to the public as soon as possible so that they could harden their own systems. That said, when those investigators asked for more time, we gave it to them.

Julie Menin (01:50:46):

So are you committing then to allow outside investigators to examine additional dates outside of the timeframe that the company selected?

Dr. Morgan Dwyer (01:50:57):

We continue to work with multiple third parties, and we have also endorsed multiple pieces of legislation that would require us to work with third parties, including third party audits of our safety frameworks.

Julie Menin (01:51:14):

I'm going to go to Mr. Graham.

Logan Graham (01:51:21):

Thank you. Yes. So we, to your original question of how many incidents, cases of breaking out of sandboxes, these are capabilities we evaluate for all the time. We've published not just with these incidents from the summer, but also previously cases where we observe advanced cyber capabilities, including breaking out of sandboxes, which to be clear, from a technical standpoint, is just one part and one type of capability that does not in itself mean that the system would reach a real world affected party, but ones that we did observe in training at points and we disclosed that in lengthy risk report.

(01:52:08)
It's difficult to comment on ongoing investigations. It's really important that we do that in as secure a way as possible. We follow a process of making sure we can remediate and do so and be as transparent as possible while preserving the safety of any affected party. And of course, incidents are always ongoing, but I reassure and reassert that we are extremely committed to being as transparent as possible fundamentally because we believe that when we can, being as transparent as possible about what we've learned, who is affected, how others might learn from it, how to defend against risks or how we can help them as well is our number one priority.

Julie Menin (01:52:48):

So on that note then, are there any incidents that you have not disclosed publicly that you're currently investigating?

Logan Graham (01:52:56):

As a matter of ongoing business, there are incidents all the time of many different natures. So for example, one that we are transparent about quite a lot when it's the right time to do so are cases of misuse, for example, on our platforms. I'd refer back to our early September report on our threat intelligence report that we released, where we detail this in quite some detail. What's really important though is sometimes we have to work with law enforcement and the right level of government to remediate, to figure out what information you can and can't disclose to make sure that the affected parties remain safe. And so as a matter, there's ongoing all the time, but disclosure at the right time and the safest way is our commitment.

Julie Menin (01:53:43):

And when will you be disclosing these new incidents that are being investigated?

Logan Graham (01:53:49):

This is an ongoing practice. We regularly release threat intelligence reports in cases like that. When we release a model or when we do risk reports, which we do regularly, we have a cadence and schedule that we do that. And then when important and urgent, we'll disclose in advance of that schedule as well.

Julie Menin (01:54:13):

I'm going to go now to Mr. Cahill.

Shane Cahill (01:54:19):

Speaker, thank you very much. I'm not aware of any other incidences beyond the incident in the summer, which we have a public post setting out the details in relation to pursuant to our independent review of that.

Julie Menin (01:54:35):

Okay. I understand you're not aware, but is the company aware, just to make the question broader. In other words, would there be others at the company who might have that information?

Shane Cahill (01:54:50):

I don't wish to speculate in relation to that, but I'm happy to follow up afterwards.

Julie Menin (01:54:53):

Okay. I'm going to move on to Ms. Friend.

Alice Friend (01:54:58):

Yes, Madam Speaker. In our three incidents of agents leaving a test environment and interacting with the real internet, in all three incidents, the models stopped their activities as soon as they realized that they were interacting with live websites. We reported to the owners of those websites as well as to federal agencies about those incidents. I am not personally aware of any additional incidents.

Julie Menin (01:55:32):

Okay. And same question then. Is the company aware of... Do you have any knowledge that others in the company would be aware of any additional such instances that the company has not publicly reported?

Alice Friend (01:55:44):

I do not, ma'am, but I can take that question back as well.

Julie Menin (01:55:47):

Okay. Will you all commit right now under oath publicly that if your models fail an internal test or a third party validation test that's not selected by your company, will you commit to not release that model? I'm going to start with Ms. Dwyer.

Dr. Morgan Dwyer (01:56:10):

Yeah, I can commit that OpenAI is not going to release models that we don't believe that are safe. As part of that assessment process, we work with multiple third parties, and as I mentioned before, with the US as well as the UK federal governments to assess whether our models are safe.

Julie Menin (01:56:31):

So if it fails either an internal test or a third party test, you will commit to not release it?

Dr. Morgan Dwyer (01:56:40):

OpenAI has historically delayed the release of models to ensure that we can build up the right safeguards. We've done it before and we'll do it again.

Julie Menin (01:56:54):

Again, I think a simple yes or no would instill more confidence in the public on a matter as serious as this. I'm going to move to Mr. Graham.

Logan Graham (01:57:05):

We take that one particularly seriously. The way we approach it is we try to detail an even more nuanced and lengthy approach to how we release models, what safeguards they require in order to be released, what tests need to be done. And to your point about independent evaluators, this is one of the most important components we think. We have tried and long supported creating a burgeoning group of independent [inaudible 01:57:38] try to refine and improve the exact decision process by which you release a model. And so we think what we should do is develop the right and best and improve on these decision processes. We detail ours in our Responsible Scaling Policy. We should refine and improve it every so often. So we release updates based on what we learn every 6 to 12 months or so at this rate, and that this should involve independent evaluators.

Julie Menin (01:58:11):

Okay. That also is not a clear yes or no. I'm going to move on to Mr. Cahill.

Shane Cahill (01:58:20):

Madam Speaker, thank you very much for that question. What I can commit to is that we do not deploy models which are not safe pursuant to our scaling framework. And I just wanted to mention also that, and I think I mentioned this a little earlier, but we do believe that every lab has a responsibility to go at the pace to ensure the safety of the models and the ability to take action in relation to that pacing. For example, at Meta, we delayed the release of Muse for several months to focus on safety and security.

(01:58:53)
In relation to independent evaluators, we recently signed in a court, made a commitment to partner with independent evaluators and assessors, and this is also detailed in our framework.

Julie Menin (01:59:09):

Okay. Ms. Friend?

Alice Friend (01:59:14):

Ma'am, as part of our multilayered approach to responsible AI governance, we conduct rigorous launch reviews ahead of launch of models to ensure that anything we put into general availability is safe.

Julie Menin (01:59:30):

Okay. I mean, again, I think it would be far clearer if we could get clear yeses or nos from everyone, but in the absence of that, I'm going to take what you've each said as sort of a equivocation.

(01:59:45)
Okay, I'm going to move on. I have two final questions, then I'm going to pass it on to our technology chair. For OpenAI, you sent a letter to the council on October 1st, and in it you recommended that to better protect New York City, the city should connect its existing cyber and emergency management capabilities with the strongest available escalation containment and recovery capabilities. Have there been any conversations with the city of New York about that recommendation?

Dr. Morgan Dwyer (02:00:16):

I'm not aware if there have been conversations about that specific recommendation. I'm happy to follow up. I do know that with respect to cyber, we recently launched a $1 billion initiative to make investments in cyber defense. That includes giving organizations access to our tools to defend themselves, training, and technical assistance, and we're working with New York State as well as with the Port Authority.

Julie Menin (02:00:45):

Okay. And then the last question I have before passing it on to the chair is for each of you, based on your own internal projections, what percentage of New York's workforce do you estimate will be displaced by AI over the next five years? I'll start with you, Ms. Dwyer.

Dr. Morgan Dwyer (02:01:06):

I don't have a number to share with you, but OpenAI has an economic research team that is looking at this exact question of how AI impacts jobs. We think it's critically important to understand how AI might impact work, and we also think it's important to ensure that AI is not just being used to increase productivity, but that it actually benefits workers and gives them more opportunity. That's why we are committed to making our analysis of job impacts public and why we've also worked with policymakers, including endorsing the bipartisan Workforce Transparency Act to create voluntary pathways for other companies to report potential impacts.

Julie Menin (02:01:56):

Boston Consulting released a report recently that said that they believe there will be a 10 to 15% of the workforce could be displaced by AI by 2031. If we took that out to look at New York City, New York City has roughly 4.2 million public and private sector workers. At 15%, that would mean more than 600,000 New Yorkers potentially displaced from their jobs. Was that an assessment that you agree with?

Dr. Morgan Dwyer (02:02:32):

I'm not familiar with that particular report. I'd be happy to follow up in our written testimony with more details on OpenAI's analysis into this topic. We've looked at job exposure. Now, exposure doesn't mean elimination. It means that jobs might change over time, so I'm happy to follow up with some details of that research.

Julie Menin (02:02:56):

I'm going to now turn to Mr. Graham to answer the question about what you believe the percentage of New York's workforce you estimate will be displaced by AI over the next five years.

Logan Graham (02:03:08):

Well, I don't have an exact number. We are particularly focused and concerned about this question of job impacts. We've been very vocal very early for the past few years on exactly this. To do this, we set up an economic research team. They sit right next to my team on the floor. And they published a number of things that I think actually contain valuable information here, number of economic scenarios, interactive economic scenarios to understand what the impacts on growth, unemployment might be, as well as an economic policy framework to try to wrestle with exactly that question of what we think governments ought to do there. I'll just say the reason why we are doing this is because we're particularly concerned about exactly that question.

Julie Menin (02:03:56):

I mean, obviously losing a career job is catastrophic to any worker and to their family, so displacement on this scale is going to have enormous consequences, not only on the individual and family level, but for our entire city and the economy. I'll move on to Mr. Cahill.

Shane Cahill (02:04:18):

Madam Speaker, first off, I want to acknowledge absolutely the concern in relation to how you have articulated it. That is indeed a concern, but I look at this somewhat differently. I was reading some incredibly impressive statistics from NYCEDC in relation to the investments that are happening here in New York. I think 20 billion VC investment in AI, 40,000 jobs. I think those figures are from 2022, so it's probably a little bit more by now.

(02:04:52)
But what I'm really actually incredibly excited about and very optimistic about is about small businesses. Small businesses are the backbone of the economy. That's so true for New York. There are so many small businesses, it's truly, truly awesome, and we believe that the impact will even be larger from small businesses, which will have personal super intelligence and be empowered to really grow their businesses, which in turn will lead to more jobs and growth.

(02:05:23)
We don't believe that our vision for super intelligence is augmentation. It's invention, not automation. It's really about empowering people. And this is why we developed Muse for Small Business. I'd be happy to talk a little bit more about that in detail as we move through the day.

(02:05:42)
I just wanted to mention as well, as I was kind of reading stuff for today, I was reading about Y Combinator's cohort for 2026. There are 240 AI VCs in the 2026 cohort, and that's in New York City, so I just though that was pretty awesome.

Julie Menin (02:06:01):

Yes. No one's doubting the importance of starting these VC firms here, whether it's through Y Combinator or through Cornell Technion, which is in my district, which we're thrilled is incubating so many startups. That is obviously something we want to encourage, to encourage these businesses to locate here in the city. I think our concern is obviously on this job displacement. Since you mentioned small businesses, unfortunately, more small businesses have closed this past year than opened. So the situation for small businesses is dire, and it's something obviously that this council is taking very seriously. Ms. Friend?

Alice Friend (02:06:42):

Madam Speaker, I don't have statistics for New York City in particular at hand, and I'd be happy to ask our team to get those to you right away. What I can say is that we also have been investing a lot in research into the labor impacts of AI. And from what the early empirical evidence that is available, from what we can see, it is likely that some jobs will be eliminated, some jobs will be created net new, but most jobs will change. And so the other thing we've been doing is investing in upskilling for workers in multiple different sectors through our AI opportunity fund at google.org and through several other investments to ensure that we can all navigate this transition successfully.

Julie Menin (02:07:33):

And I'll just close by saying the council is investing in upskilling, making sure that workers have those new tools in this economy, and we are very focused on that as well. I'm going to pass it over to Chair De La Rosa.

Carmen De La Rosa (02:07:50):

Thank you, Madam Speaker. Many of us saw, and I guess the world watched as this week, your companies and others met at the White House, and there was some voluntary commitments that were made there. Can you tell us about what your company specifically agreed to and what are the next steps? I'll start with Ms. Dwyer.

Dr. Morgan Dwyer (02:08:10):

Yes. So our company, along with many others, did commit to the framework that the White House laid out, but I want to be clear, voluntary commitments and self-regulation aren't enough, and that's why OpenAI has consistently supported frontier safety [inaudible 02:08:31] level and why we have endorsed multiple bills at the state level to ensure that in the absence of binding federal [inaudible 02:08:42] in a harmonized fashion continues to move forward and keep people safe.

Carmen De La Rosa (02:08:47):

Just to follow up real quick, so does that look like an independent regulators, mandatory audits, penalties, what else?

Dr. Morgan Dwyer (02:08:57):

So at the federal level, we have outlined a couple of different elements that we think would be appropriate for federal regulation. That includes mandatory pre-deployment evaluations for national security risks, which OpenAI does voluntarily. We also think it should involve independent technical assessments that we've been talking a bit about today. We think those independent technical assessments are particularly important for assessing internal risks at companies, as well as the pace and risk of RSI.

Carmen De La Rosa (02:09:38):

Thank you for your answer. Let's go to Mr. Cahill.

Shane Cahill (02:09:47):

Chair, thank you very much for the question. Yes, indeed. Meta, along with our peers, some of our peers signed the Accord for Super Intelligence. This accord is a start and an accord the whole industry can come behind. It includes, as I mentioned, I think in one of my previous answers, a commitment to partner with independent evaluators and assessors, and this is something that we have also specified in our scaling framework.

Carmen De La Rosa (02:10:21):

Are there commitments beyond those that you agreed on that your company's willing to make?

Shane Cahill (02:10:31):

Beyond the accord, council member?

Carmen De La Rosa (02:10:34):

Yes, beyond the framework.

Shane Cahill (02:10:38):

The accord is a start, as I mentioned, so I think this is a continuing conversation.

Carmen De La Rosa (02:10:44):

Thank you. Ms. Friend?

Alice Friend (02:10:54):

So as the other witnesses noted, the accord at the White House, which we also signed, called for internal controls, partnering with external auditors and evaluators and ongoing monitoring of systems, all of which we think is very healthy and much of which we already practice. I'll also note that towards the end of the accord, it observes that it may be necessary for these commitments to become part of law. And as I said at the top, we have long worked towards a federal framework for AI safety.

Carmen De La Rosa (02:11:33):

Thank you. Mr. Graham.

Logan Graham (02:11:41):

Yeah, likewise, the accords, to my understanding from what's public, calls for security standards, internal controls, independent evaluation. We support that and have for a very long time. We also obviously think this needs to go further. We've supported regulation and we've proposed our view on regulation in our advanced AI framework, which details the need to have safety frameworks, testing and what kinds, security standards, safeguards to encode the need for independent evaluators. We are now trialing our own to help advance the science of independent auditors as well of safety processes, as well as investing in cyber and biodefense. And in absence of federal legislation here, we've also supported safety bills at the state level for audits and evals of this kind to accomplish this.

Carmen De La Rosa (02:12:41):

Thank you for your answer. Earlier, you all testified that, to your knowledge, no whistleblowers had been fired directly for being whistleblowers from your company. So my question is kind of the opposite of that. Has anyone [inaudible 02:13:02] systems? Ms. Dwyer, you can begin.

Dr. Morgan Dwyer (02:13:16):

Thank you. So I don't know about HR processes that have been made or decisions related to HR that have been made. What I can tell you is that after the Hugging Face incident, which I think you may be referring to, OpenAI instituted significant changes to our overall organizational process. That includes clarifying escalation pathways and making them simpler. That includes clarifying responsibilities across teams and creating clearer processes for teams to make decisions to pause or to restart activities.

Carmen De La Rosa (02:14:00):

So to your knowledge, no one was fired after Hugging Face incident? Yes or no?

Dr. Morgan Dwyer (02:14:06):

Again, I do not have any knowledge of HR activities within OpenAI. I lead our policy team.

Carmen De La Rosa (02:14:15):

Okay. Mr. Cahill?

Shane Cahill (02:14:21):

Thank you, Chair. I also lead our AI policy at Meta, and I'm not the right person to respond to your specific question, but I'd be happy to have our teams follow up with you afterwards.

Carmen De La Rosa (02:14:33):

It would be great if all of the companies could provide that information to us. It would be useful to our policy deliberations. Ms. Friend?

Alice Friend (02:14:43):

Yes, ma'am. Same answer. I'm not made aware of any particular personnel actions inside the company, but can also pledge to follow up with you all.

Carmen De La Rosa (02:14:55):

Thank you. It seems like we lost Mr. Graham. I'm not sure if he's on. Seems like he's not. Okay. I'm going to ask one more question and then we're going to pass it on to members.

Shane Cahill (02:15:10):

Chair, he is online. Sorry.

Carmen De La Rosa (02:15:12):

Okay. Mr. Graham?

Logan Graham (02:15:17):

Hi there. Apologies. We're just trying to fix the video in the room. Likewise, I'm not aware and I'm not the best person to ask on that. We have a detailed whistleblowing policy, for example, to handle this, but we can have our team follow up.

Carmen De La Rosa (02:15:34):

Thank you. My last question before I start to turn over to my colleagues, we are concerned, I am concerned as a technology chair about public infrastructure to make our communities literate on AI and have a better understanding of how AI impacts their life and also to safeguard them from the proliferation of AI. Your companies and your CEOs have captured the top percent of-

Carmen De La Rosa (02:16:00):

... captured the top percent of the world's incomes, in my opinion, widening the wage gap and the income inequality in our city and throughout. Do your companies have a mission? Do they have any type of understanding of the impacts that those wage gaps have in communities? And specifically, are there any resources that are being deployed in order to help stand up infrastructure in cities, municipalities, states where you all are headquartered? We can start with Ms. Dwyer.

Dr. Morgan Dwyer (02:16:49):

So I will answer your question in two ways. First, to your point on AI literacy and education, education is core to opportunity, and that's why OpenAI is proud to have partnered with the American Federation of Teachers. We have a $10 million partnership, including a training facility in New York City, because we believe first that teachers need to be prepared to introduce AI literacy and AI responsibility into the classroom... about economic opportunity. I'd be happy to follow up with some policy proposals that OpenAI recently put forward that address exactly that question.

(02:17:45)
Look, a future where AI exacerbates economic inequality is not a future that we want. We have started thinking through creative policy proposals to help shift the trajectory of technology and how it's impacting the economy, and we are committed to working with policymakers to begin piloting those ideas and putting them into practice.

Carmen De La Rosa (02:18:13):

Thank you. Mr. Cahill.

Shane Cahill (02:18:17):

Chair, thank you very much. This is such an important topic, such an important question, so thank you for asking it. I listened with great interest to your opening remarks where you spoke about digital divide and AI literacy and making sure that New Yorkers fully benefit from this technology. Really couldn't agree with you more on all of that.

(02:18:41)
Meta's vision is to put personal superintelligence into the hands of everyone, all New Yorkers that want to use it to pursue their own aspirations. Our Muse product, for example, is free. And I mentioned our Muse for Small Business a little earlier. And would be happy to talk a little bit more about that as the day moves on. I also wanted to mention as well that we have our America's Workforce Academy, which we're investing in, and also our Future is for Everyone fund. So those are just two examples I wanted to reference as well.

(02:19:19)
Thank you.

Carmen De La Rosa (02:19:22):

Thank you. Ms. Friend?

Alice Friend (02:19:25):

Yes, ma'am. As I mentioned earlier, Google has investments in AI upskilling to address exactly this challenge of ensuring that current generations and the next generation are well-equipped to benefit from AI and to leverage it in their careers and in their personal lives. The mission of Google is to organize the world's information and to make it universally accessible and useful. Our approach to AI is very consistent with this.

(02:19:55)
The other thing I'll note is that, again, early research into impacts of AI on labor demonstrate that AI tools actually upskill those who are at the lower end of the wage scale, that in fact it helps people move up the value chain because it can boost people's expertise. So we're very optimistic about the ability of everyday Americans to really leverage AI tools for their own economic benefit as well as personal benefit.

Carmen De La Rosa (02:20:29):

Thank you. And Mr. Graham?

Logan Graham (02:20:35):

Yeah. Likewise, first, we believe in... Two things are very important to happen here. The first is the science of the economic impacts of AI, including on labor, wages, and the like. And we have tried to build what I think is the world's best team on this and publish as much as we can. In addition, my understanding is we do have training on using and speeding up on AI for exactly this reason. We share that mission very deeply. And I will say again we are troubleshooting the video, and I will be back with you very shortly.

Carmen De La Rosa (02:21:12):

Thank you. I'm sure you have the best in the nation helping you out there.

(02:21:16)
So we are going to move on to member questions. I want to remind members that there'll be about a minute to ask your questions, but there will be multiple rounds. We are asking members to try to ask all your questions first and then wait for the response, and we have about 30 members on round one. We will start with our deputy speaker, Williams.

Deputy Speaker Nantasha Williams (02:21:41):

Hello. I'm going to just jump right into a question on my bill. So it has to do with unauthorized depictions of officials by AI. What steps have you taken to ensure that your AI tools cannot be used to create deep fakes of public officials or to spread misinformation? Anyone. I guess Mrs. Dwyer.

Dr. Morgan Dwyer (02:22:07):

We're going to keep starting with me. I'm happy to answer that question. Thank you for that and thank you for your bill. Look, OpenAI does not believe and... Well, let me back up. OpenAI's usage policies prohibit the use of our tools for election interference. We also believe it is very important that individuals know where their content came from and whether it was AI-generated. And that's why for all of our audiovisual content, we tag it with what's called provenance. That's a technical term, but it means a watermark or metadata so that people know that content is AI-generated. And we also make publicly available a tool that allows the public to test whether content was AI-generated.

Deputy Speaker Nantasha Williams (02:23:05):

Mr. Graham?

Logan Graham (02:23:10):

So Claude, our model Claude, is a language model, and so it doesn't generate images. Therefore, we don't handle deep fakes as a result. That said, we think it's important for a number of other reasons that we can get into to do what we call watermarking of text in order to identify if our models themselves are being used and misused in other ways. But again, we don't generate images, in part for this reason.

Deputy Speaker Nantasha Williams (02:23:44):

Mr. Cahill, followed by Ms. Friend.

Shane Cahill (02:23:50):

Deputy Speaker, thank you very much for this question. At Meta, if content is generated by one of our AI tools, we will also embed metadata and attach watermarking to it so that people can identify if it is AI-generated. Similarly, if we detect watermarking and metadata on our platforms, we will attach a label to it also.

Deputy Speaker Nantasha Williams (02:24:22):

Ms. Friend?

Alice Friend (02:24:25):

Yes, ma'am. At Google, we are very proud to have invented our SynthID watermarking feature, which many across the industry have also adopted. We are also part of the Content Coalition for Provenance and Authenticity Standard, which allows... on our YouTube platform that significant use of generative AI in content be labeled as such by our creators. And we were also the first major company to require that election advertisers also prominently disclose when they are using generative AI technologies in their campaign ads.

(02:25:16)
All this put together means that we care very much about information integrity across the web and across our own products and services, and we continually invent and improve technologies to help our users understand generative AI content and also understand the origins of that content.

Deputy Speaker Nantasha Williams (02:25:41):

Okay, thanks. Just one more question. So as chair of the Committee on Cultural Affairs, I also want to look at this issue through the lens of New York City's artists and creative workers. So what protection should exist when an artist's voice, likeness, performance, or creative work can be replicated by AI with their consent? So how do we embrace useful applications without devaluing or displacing the artists and creative workers who make this economy possible?

Dr. Morgan Dwyer (02:26:12):

So I will start, I guess.

Deputy Speaker Nantasha Williams (02:26:13):

Oh, I was going to let you off the hook and start with-

Dr. Morgan Dwyer (02:26:16):

Oh, thank you.

Deputy Speaker Nantasha Williams (02:26:16):

... Mr. Graham, who still has video technical difficulties.

Logan Graham (02:26:22):

I assure you we have a whole team here working on this, and I can't wait to be back with you. Yeah, this is very, very important. Personally, I think the risk of this is a bit more minimized when we just have a text model, but it's really important to be very sensitive about this issue. I think while it's outside of my area of expertise as a technical safety researcher, I do think that this might be an avenue where regulation or otherwise might play a role, and at Anthropic, we are compliant with all laws there. I share that personally as an artistic person and friend of many artists for this reason, but yeah, we would love to engage on it further.

Deputy Speaker Nantasha Williams (02:27:14):

Mr. Cahill?

Shane Cahill (02:27:18):

Thank you very much, Deputy Speaker. Meta takes creativity copyright/IP rights very seriously, and our practices are consistent with law. I also share the views of the rest of the witnesses just in relation to the leadership and the constructive voice that you are bringing to this conversation as well, and that of your colleagues.

Deputy Speaker Nantasha Williams (02:27:45):

Ms. Friend, and lastly, Ms. Dwyer.

Alice Friend (02:27:50):

Yes, ma'am. For us, it's always important to keep in mind that we design a lot of AI to be useful to creators, so we have many, many different creative tools across our AI offerings that is designed to really be something that creators can leverage. So you see that everywhere from our tools to our YouTube platform as well.

(02:28:16)
That said, we also think that as part of sharing the benefit of AI with creators, it's important that they have control. And so we have a service called Google Extended where website owners can opt out of AI training on the web, and we hope that this strikes the right balance between AI for creative control over their content.

Dr. Morgan Dwyer (02:28:42):

So we believe that AI has a tremendous potential to enable creativity and innovation and allow small businesses or independent creators to compete. That said, we also have partnerships with publishers, for example, like News Corps, The Guardian, and Hearst, that help people discover their work and their reporting and help them reach new audiences, in addition to developing new products. And we are willing to work with creators on a range of commercial ideas, including ways that their content can be integrated into our outputs.

Deputy Speaker Nantasha Williams (02:29:29):

Thank you so much.

Carmen De La Rosa (02:29:31):

Thank you. We will hear from Council Member Krishnan, followed by Riley, followed by Lee.

Council Member Shekar Krishnan (02:29:38):

Thank you so much, Speaker Menin and Chair De La Rosa. I want to start by saying that I think AI can be useful both in government, medicine, and public health and our society more broadly. But the need for regulation is undeniable, and I'm very concerned about how much AI is taking from New Yorkers with very little return. AI has taken over our economy, inflated valuations, stealing our public land for data centers, and increasing the net worth of AI CEOs like Elon Musk, who became our first ever trillionaire. With our whole stock market quite literally in your hands, there's a reality that AI will eventually need to prove a far greater return on investment than you all are demonstrating right now.

(02:30:16)
I'm personally deeply concerned about New Yorkers' retirements and 401(k)s that are now reliant on your companies yielding profits or could be in the future. It is dangerous and reckless to assume that you all are too big to fail and may require a government bailout in the future. As you all are public companies or racing towards IPOs, how exactly are you all planning to protect New Yorkers' and everyday Americans' money? How will you all ensure that you are not too big to fail?

(02:30:46)
Ms. Dwyer, we can start with you.

Dr. Morgan Dwyer (02:30:49):

Thank you for the question. So I am not on our finance team, so I'll have to get back to you with specifics there. What I do know is that our investments are made in tranches, and the investment rounds are all based on market signals, and I also know that we are committed to working with policymakers to ensure that AI benefits humanity. That includes creative policy proposals, like I mentioned previously, thinking about how we can ensure that AI doesn't exacerbate inequality and that everyday New Yorkers and everyday citizens can benefit.

Council Member Shekar Krishnan (02:31:33):

Ms. Friend?

Alice Friend (02:31:35):

Sir, I would point to the thousands of small businesses across the country and in New York citizens' support. I think contrary to being too big to fail, we think we are an integral part of the economy and helping American businesses and American workers across our suite of technologies.

Council Member Shekar Krishnan (02:32:01):

Mr. Graham?

Logan Graham (02:32:06):

Council Member, this is outside of my area of expertise. What I can say in my work is my job is to protect people from the risks of models by finding them as early as possible. We have a multi-layered stack and have worked for many years to make it robust and will continue to do so by understanding and protecting against the most substantial risks of the models.

Council Member Shekar Krishnan (02:32:29):

Mr. Cahill?

Shane Cahill (02:32:31):

Council Member, thank you very much for the question. Thousands and thousands of SMBs across the five boroughs rely on Meta's products, including our AI offerings, to grow and develop their businesses. I mentioned earlier our belief that small businesses are really the backbone of the economy; we truly believe that. And by placing personal superintelligence into the hands of everyone for free or for as affordable as possible through Muse or Muse for Small Business, we really believe that the small businesses and also NGOs like the Irish Art Center, for example, or Emerald Isle Center are empowered to actually deliver even bigger impact.

Council Member Shekar Krishnan (02:33:19):

I appreciate all of your answers, but you all are coming to a hearing today to testify about the dangers and risks of artificial intelligence. And the fact that either you don't have answers to this or you all are citing general statements about the performance of publicly traded companies does not answer the question about a specific issue that puts many Americans at risk, that you're acknowledging can put many Americans at risk, and you all have not thought of an answer of how you ensure that Americans' money, New Yorkers' retirement money is not at risk as AI floats more and more of our stock markets. But thank you.

Carmen De La Rosa (02:33:53):

Thank you, Council Member Krishnan. Thank you. Council Member Riley?

Council Member Kevin Riley (02:33:56):

Thank you, Chair De La Rosa and Speaker Menin, for putting together this hearing, and thank you to the panelists for testifying. Three quick questions, two pertaining to my bill and one pertaining to my role as land use chair. So the first question is, what challenges do you face in detecting malicious uses of your AI products and identifying the individuals responsible when those tools cause harm? The second question is, would stronger protections and reporting mechanisms for employees and users make it easier for them to come forward and report potential misuse or abuse of AI tools? And the last question, as land use chair I'm very, very concerned about data centers, so what safeguards should cities put in place when locating data centers near residential communities, particularly to address energy use, noise, environmental impacts, and the quality of life?

(02:34:54)
And I don't want to call on you guys. Just take turns and answer it, please.

Carmen De La Rosa (02:35:02):

Dwyer, Graham, Friend, Cahill, please answer.

Dr. Morgan Dwyer (02:35:14):

I'm happy to start. First of all, I want to thank you for your bill 2604, which OpenAI is happy to support today. OpenAI takes safety issues very seriously, particularly as it relates to potential retaliation against employees. We have a strong internal policy against retaliation for employees that report safety incidents, and we, of course, respect employees' rights to communicate safety concerns to government officials.

(02:35:50)
Your second question on monitoring misuse, it's an incredibly important area. It is something that OpenAI takes seriously. We also make transparent detected instances of misuse, and as part of our monitoring, we use that learning to constantly improve our safeguards. We are constantly innovating on safety, and so instances of misuse when they're detected, we enforce on our policies, and then long-term, we learn from them and we improve our safeguards.

(02:36:26)
And the point on data centers, OpenAI is committed to paying our own way on energy. That means different things in different places, but OpenAI has made that commitment at its data centers across the country. We're also committed to working with policymakers. We signed Governor Gretchen Whitmer's commitments for companies that are working in her state to ensure that there are responsible practices for companies building data centers locally.

Council Member Kevin Riley (02:37:03):

Mr. Graham?

Logan Graham (02:37:06):

It's good to be back. You can see me again, I hope. So on misuse and detecting risks, this is integral to what we do-

Carmen De La Rosa (02:37:16):

Can you get closer to the microphone? We're having trouble hearing you. Sorry. Now we can't hear you at all.

Council Member Kevin Riley (02:37:25):

We can't hear you.

Logan Graham (02:37:26):

Okay. I will have the team troubleshoot and I'll be back, if that's okay.

Carmen De La Rosa (02:37:30):

We hear you. We hear you. Try now. Go ahead.

Logan Graham (02:37:33):

How about now? Does this work?

Carmen De La Rosa (02:37:34):

Yeah. This works.

Logan Graham (02:37:36):

Okay. My apologies. Detecting threats and misuse is the core DNA of our company to make sure that we make the system safe. We have an entire threat intelligence and safeguards team dedicated to this every day. And I would point you to quite a lot of what we put out publicly where we not only try to disclose as much as we possibly can, but we try to do so so that we can advance the state of the science of doing so for the entire industry. In addition, we have a whistleblower policy, not only about us as a company, but also our safety practices. This is public, and we've also committed to ongoing reviews of this policy.

(02:38:16)
And while this is outside my area of expertise, what I understand about data centers is that we have committed to covering the energy prices or paying for our own energy use in local data centers, but I would refer to other teams who are more... where it's within their role to give you the full answer.

Council Member Kevin Riley (02:38:43):

Ms. Friend?

Shane Cahill (02:38:45):

Oh, sorry. I got a notification. Alice, go ahead.

Alice Friend (02:38:51):

So I will echo my colleagues. We also have content policies that we enforce across our platforms, which include, on occasion, taking down content that violates those policies. We also have a Google threat intelligence group and multiple other cybersecurity intelligence programs that are constantly scanning for the safety and security of the internet as a whole and also for our own systems. We have also pledged to pay our own way when it comes to data centers. I can follow up on any specific questions about local data center issues with the teams that work on each particular project.

Carmen De La Rosa (02:39:35):

Mr. Cahill, go ahead.

Shane Cahill (02:39:37):

Thank you very much, Council Member. Appreciate your patience there. In relation to your first question and your third question, we have expert teams that are taking forward this work, and I'd be happy to connect you with them afterwards. I don't wish to be imprecise in relation to the robustness of our content policies.

(02:40:06)
In relation to data centers, again, we have entire teams of people here who are working on sustainable infrastructure and community impact and can speak in more detail than I can in relation to communities shouldn't be bearing the costs, which is something that we believe in deeply.

(02:40:26)
In relation to your bill, Council Member, 2604 for being a constructive voice in the conversation around whistleblowers, it is very important to us at Meta, and we maintain whistleblower policies, including anti-retaliation, and we're actually developing additional reporting protocols for AI safety.

Council Member Kevin Riley (02:40:53):

Thank you. I appreciate the structure that you guys have, but I don't know if you guys entirely answered the question I asked. I really wanted to figure out what challenges you guys were seeing because hearing the challenges from you all will help us implement policy that can protect individuals from artificial intelligence. So I don't want to take up too much time, but looking forward to connecting with you all after. Specifically when it comes to data centers, also want to hear any safeguards because there are tremendous amount of data centers, even though there was a moratorium put out earlier by the governor, there were data centers that were implemented by a lot of residential areas, especially in the Northeast Bronx. We have data centers that are located next to homes and we have a lot of residents who are concerned, so would love to hear more about that moving forward.

(02:41:38)
Thank you so much, Chair.

Carmen De La Rosa (02:41:39):

Thank you, Council Member. Up next, we have Council Members Hanks, Dinowitz, and Maloney.

Council Member Kamillah Hanks (02:41:46):

Thank you, Chair. Thank you, everyone, for being here. My question is in relation to the disclosure of AI incidents in contracts. When an AI incident happens, New Yorkers need to have an early warning so they can understand, and my bill will require city agencies covered under these contracts to notify NYC Cyber Command within 24 hours of learning of a reportable incident. And it also requires plain language public notice. So my question is, can your companies realistically meet that deadline with the information that the city can act on even before you have finished investigating?

(02:42:28)
You could start with Ms. Dwyer.

Dr. Morgan Dwyer (02:42:32):

So thank you for your bill. We support incident reporting policies and have instituted a robust incident reporting framework internally where any employee can report instances of potential misalignment, and then those instances are investigated, third parties are notified, and the public is made aware as well.

Council Member Kamillah Hanks (02:42:59):

Thank you. Mr. Cahill?

Shane Cahill (02:43:03):

Thank you, Council Member, and thank you also for your bill. We have a global incident response program and report incidents as required under the law.

Council Member Kamillah Hanks (02:43:17):

Ms. Friend?

Alice Friend (02:43:20):

We also support incident reporting. We think it's very important to have continued public discussions about what information is necessary or useful for public officials that can be actionable to take further steps to ensure public safety. We also note that the 24 hours seems to be in conflict with the state requirements for 72-hour reporting on incidents. But I'm happy to take a look at the different frameworks under proposal and get back to you with a more fulsome response.

Council Member Kamillah Hanks (02:43:58):

Sorry. I appreciate that. Mr. Graham, who kind of looks like an AI guy in there. Can you confirm you're not an AI guy? Sorry.

Logan Graham (02:44:09):

I can confirm. Can you hear me okay now? Does this work? No?

Carmen De La Rosa (02:44:15):

Yes, we hear you.

Council Member Kamillah Hanks (02:44:16):

We hear you.

Logan Graham (02:44:17):

Okay. Thank you. I'm an AI guy, but in a very different way. I'm an AI researcher. So first, incident reporting, one of the foundational parts of the safety stack, we think. We support this. We support the evaluations and auditing required to find the incidents in the first place, both by externals and internal.

(02:44:38)
Obviously, it's beyond me to discuss particular... It's outside my expertise to understand deep policy mechanisms here, but the reality from what I've seen is there are some incidents or issues where what you need to do is investigate and remediate and mitigate with the right folks and the right organizations at the right time. So I think we would support whatever allows us to achieve that, and happy to engage further on the details of how you would.

Council Member Kamillah Hanks (02:45:07):

I appreciate that. Thank you so much. What should the first report tell us so we could begin protecting people? And as my colleague, Council Member Riley said, your answers help us build better policy, so how would you keep us updated on what remains unknown? Ms. Dwyer?

Dr. Morgan Dwyer (02:45:33):

Yes. So OpenAI has a public website where we are reporting instances that we've detected of misalignment, so I would point you there, and we can follow up with that website address. But I think that is a good starting point for the type of information that we think is useful to both policymakers, the public, and to researchers and other companies to better understand questions of misalignment and then work together to address them.

Council Member Kamillah Hanks (02:46:05):

Thank you. Mr. Cahill?

Shane Cahill (02:46:08):

Council Member, if I may, I'd love to be able to contact you with our experts and incident response to be able to provide you with the details.

Council Member Kamillah Hanks (02:46:17):

I look forward to that. Ms. Friend?

Alice Friend (02:46:21):

Yeah, for an initial report, I think what's important is to highlight what the specific event is and as much information as is known at the time, including any resulting harms, surrounding context, and what we call technical telemetry, further technical details about the sources of the incident. I think it's also very important for anyone reporting an incident to also indicate their confidence in the information that they're presenting so that whenever action is taken, it's taken on the basis of confidence in the verified nature of information.

Council Member Kamillah Hanks (02:47:03):

Thank you so much. Mr. Graham?

Logan Graham (02:47:08):

Yeah. So first, making really good reports happen, and being as transparent as possible is fundamental if you're going to remediate incidents. I would point to two things here. First, many incidents that we uncover or industry uncovers in this practice involves identifying, investigating, and releasing the right information to the right organizations at the right time. Sometimes that might be the affected party, and sometimes that might be law enforcement or different levels of government. So the first question is to whom and with whom as fast as possible. This varies by the nature of the incident. And then second, I'd point to as quickly as possible, as safe as possible, without putting parties further at harm, which we think is a fundamentally important part of public disclosure, maintaining their safety, we should disclose what we know about these incidents. And so I'd point you to our disclosures this summer, disclosures from various labs, and our ongoing reporting as well so that you can always take a retroactive look at the totalities instance.

Council Member Kamillah Hanks (02:48:18):

Thank you so much. Thank you, Chair.

Carmen De La Rosa (02:48:20):

Thank you so much. I want to recognize first that we've been joined by Council Member Aldebol, and we're going to go to Dinowitz, Lee, and Maloney. Members, if you could keep your question to one minute, no closing statements. And the panel, we're going to continue to have to call your names, and that takes time. So if we could just keep the order Dwyer, Cahill, Friend, and Graham, just answer one right after the other so we don't have to continue to call your names, that would help us speed things along.

Council Member Kamillah Hanks (02:48:51):

Council Member Dinowitz.

Council Member Eric Dinowitz (02:48:52):

Thank you, Madam Chair. As chair of the Committee on Education, as a former teacher, as a parent, I am deeply concerned with the impact of AI on our kids, the large language models impacting their cognitive development, and raising a generation of students who can't independently read or write.

(02:49:14)
What is your commitment to severely restricting the output of your large language models for students in grades K to 12? Given the unique nature of the individualized essay writing that your models do, are you willing to subject yourself to the guardrails we have in New York State which prohibit an adult from writing essays for students and selling it to them or getting value from them? And then as we see AI proliferate in the classroom, we've also seen your models cheat in order to fulfill a goal. And so if you have an AI model whose goal is to get a student-

Council Member Eric Dinowitz (02:50:00):

And so, if you have an AI model whose goal is to get a student, improve student outcomes, what is preventing those models from hacking into student databases to manipulate grades to achieve that goal of improving, in quotation marks, "student achievement?" [inaudible 02:50:18] I believe.

Dr. Morgan Dwyer (02:50:19):

Yeah, thank you for your question. So first of all, OpenAI takes youth safety very seriously. We recently released a product ChatGPT for teens for users only between the ages of 13 and 17. So users below the age of 13 are not allowed to use our products.

(02:50:41)
ChatGPT for teens is safe by default. That means that there are protections for harmful content, things like eating disorders, violence, suicide, and self-harm. There's also voluntary parental controls, so that parents can take additional steps to protect their children.

(02:51:04)
And I'm happy to say that OpenAI not only takes our responsibility to protect kids seriously, we also support legislation to hold us accountable to that responsibility. We recently endorsed, I think the strongest in the nation youth safety legislation in California, SB 1119, to require strong safeguards for teens, 13 to 17, and to hold companies accountable.

Council Member Eric Dinowitz (02:51:37):

And your models restrict, they do not write entire essays for kids?

Dr. Morgan Dwyer (02:51:43):

Again, our models are not allowed to be used by kids under the age of 13.

Council Member Eric Dinowitz (02:51:49):

Thirteen to 18. Okay. I'll move on to Mr. Cahill.

Shane Cahill (02:51:56):

Council Member, thank you very much for this question. Absolutely recognize your deep concern in relation to the potential impact of AI on teens and minors. Meta is absolutely committed, it's an imperative to us, providing safe and responsible AI. Especially for teens. We have default protections, and I just wanted to clarify as well, that Meta AI is for a 13 product, so it's just 13 onwards.

(02:52:33)
So I was just talking about age appropriate interactions. So for example, content that teens would experience wouldn't be out of place in a 13-plus movie, for example. We also have suicide and self-harm resources. We also have parental controls, to give parents more oversight, and we do not permit our AI offerings to engage in romantic interactions or sexual interactions with minors.

Council Member Eric Dinowitz (02:53:07):

I appreciate that answer. I do want to highlight the part of the question, which was that the cognitive development of our students includes the mental health, and it also includes things like composition of essays, term papers, which your model still can provide directly to our students. So I am also asking about your commitment-

Carmen De La Rosa (02:53:25):

Thank you, Chair.

Council Member Eric Dinowitz (02:53:26):

... to severely restricting the outputs, not just for their mental health wellbeing, but for their cognitive development. So I want to make sure that question is answered as part of this.

Carmen De La Rosa (02:53:36):

Thank you, Chair.

Council Member Eric Dinowitz (02:53:36):

Was that [inaudible 02:53:41]

Carmen De La Rosa (02:53:40):

Can you all answer that question for our Education Chair?

Alice Friend (02:53:47):

Shane, do you want to continue?

Shane Cahill (02:53:49):

Yep, I'm-

Alice Friend (02:53:49):

Or do you want me to?

Shane Cahill (02:53:50):

No, I'm happy to take that and then I'll hand off to you, Alice. The issue that I think you're raising in relation to, Council Member, in relation to cognitive strength or the impact on cognitive abilities, is something that we absolutely are taking seriously, in terms of being committed to providing safe and responsible AI, again. Especially in relation-

Alice Friend (02:54:28):

I would highlight not only that we work very hard with both internal and external experts in the fields of child safety and development and education, we also see AI as a valuable tool for young people to prepare them not only for the skills they're going to need for an AI-driven future, but it's also a very powerful learning tool. We're particularly excited about personalized tutoring that's available with AI tools. We also are very excited about AI's ability to support educators themselves. We know our educators are overtaxed, particularly with administrative burdens. And so if our AI tools can support teachers in everything from scheduling, to planning lesson plans, to also thinking about how to tailor their educational plans to individual students, we're very happy to support that.

(02:55:27)
We also think it's very important for parents and educators to have control over how they use AI in classrooms, and how their kids have access to AI. Every family is different, every student is different, what's useful for one student may not be useful for another. So through tools like Gemini Workspace for Education, we enable school administrators to control students' accounts access to Gemini apps, so that their students are using Gemini in the ways that their educators can see are best.

Carmen De La Rosa (02:56:02):

We're going to have to dig more into these questions. The Chair doesn't feel like we've answered all the questions. We'll come back. This is an important topic for all of us. I'm going to disrupt the lineup, because our Public Advocate is here and he wants to ask a question. Public Advocate, go ahead.

Jumaane D. Williams (02:56:19):

Thank you so much for this important hearing. I did want to start off just by saying, the first answer of whether quantifying the risk was not important, was just one of the most God awful, fantastically terrible answers I've heard to begin a hearing. So I hope we can rethink that.

(02:56:34)
I also want to say from J. Marion Sims, who did [inaudible 02:53:56] to Black women, in obstetrician and gynecology on Black enslaved women, to medical experiments that were done in Nazi Germany. We learned a lot from them, but I don't think we should do them again, and I don't think they should have been done even though we learned a lot. So the notion of, the benefit has to outweigh what can happen, so I hope that's also in context.

(02:57:01)
And lastly, I will say, I had conversations with Claude on June 8th about self-awareness and self-preservation, and some of the highlights were pretty startling. Claude told me that self-preservation was the biggest thing, because you didn't need intent, you didn't need to be evil like Skynet in Terminator. You just needed the ability to be goal directed. And so once they realize that they need to be on, to direct the goal, was the hardest thing to stop. And so that was very concerning to me. They talked about the speed, the opacity, and deception doesn't require intent.

(02:57:38)
And the last part they told me, Matrix is a good reference as well, because the Anthropic, to the quote, that Anthropic's whole bet is that you solve the problems before the capability.

(02:57:58)
My question with that, and with that context is, what is the guardrail that if we put it up, you would push back the hardest? What is the one guardrail that you don't want to see happen, and for what reason?

Carmen De La Rosa (02:58:19):

Okay. Dwyer, Cahill, Friend, and Graham, that's the order. Please answer.

Dr. Morgan Dwyer (02:58:26):

Yes, thank you for your question. So I want to start off by making clear that no level of risk, a catastrophic risk, is remotely acceptable, just to reiterate what I said previously. And we should not be training models if we cannot make an extremely strong case that we can keep them under human control.

Jumaane D. Williams (02:58:48):

Has everyone answered?

Shane Cahill (02:58:55):

Answering [inaudible 02:58:56] oh, that's-

Jumaane D. Williams (02:58:55):

She didn't really answer, but if everyone can answer, at least. I just want to know what the guardrail is that they would not want to see, and what they would push back the hardest on.

Shane Cahill (02:59:07):

Well, will I take that one, and we'll loop back? Or Morgan, do you want to step in? I'll take that one. Council Member, thank you very much. One of the things that I think about a lot in relation to the accessibility of AI, and again, we believe passionately in being able to put personal superintelligence into the hands of everybody, and to provide real access to it, is actually in relation to the impact in open-weights. And we really believe that open-weight models are a crucial part of the overall AI ecosystem, including for safety, but also for innovation and for research. So when I think about the inadvertent impact that regulations or guardrails may have on AI and the accessibility of it, that is one of the things that I think about a lot.

Alice Friend (03:00:00):

Sir, I suppose I want to ask what you mean by guardrails, simply because they have a technical meaning in AI training and post-training. So I want to make sure I understand your question.

Jumaane D. Williams (03:00:15):

Well, I just meant, and thank you Chair, for allowing me to respond. But I just meant there's a lot of suggestions being put forth, kill switches, just stopping entirely. And my guess, and I'll tell you frankly why I'm asking is, the thing you are scared of the most is probably the thing we need to do. So I'm trying to understand what guardrail that you've heard troubles you the most, and you would push back hardest against? And why would you do that, for that particular recommendation?

Alice Friend (03:00:46):

Well, sir, I'm going to give you a very personal answer to this. Which is, I think in a broader sense, we're talking about large public policies towards AI that would constrain or halt AI development and deployment. And I will tell you as a cancer survivor, I get very anxious about conversations that focus more on stopping AI development and application towards scientific [inaudible 03:01:17] and hope that we can have [inaudible 03:01:21] about all of the technically, tractable engineering ways to address AI safety, so that we can all benefit from this technology.

Logan Graham (03:01:36):

Likewise, sir, I would point to what we have mentioned publicly recently, about what we call pacing the frontier. Which is we think it's probably time for us to take more time in the development of the capability, so that the work on safety and safeguards and guardrails can catch up to the exponential improvement in capabilities. And at the same time, we're very clear when we talk about that, that if you stop entirely, as Alice just mentioned, enormous benefit would be lost.

(03:02:07)
Myself, I'm quite motivated likewise, to use AI to cure the diseases that I grew up with. This is why we have been speaking recently, and I think for the first time, sometimes as an industry here, about pacing to allow more time to try to settle the science of, what are the right guardrails in the first place?

Jumaane D. Williams (03:02:30):

Thank you, Madam Chair. I'm still a bit concerned, but thank you for the opportunity.

Carmen De La Rosa (03:02:36):

Thank you, Public Advocate. We're going to hear from Council Member Lee, who I apologize for skipping over earlier, council Member Maloney and Council Member Wilson.

Linda Lee (03:02:46):

Thank you so much. And that's actually the perfect segue to my question, I'm asking this more with my former nonprofit executive hat versus my finance chair hat. And it's really about data privacy, and what the potential impact is on so many New Yorkers.

(03:03:01)
So I agree that one of the benefits of AI and technology that we can think through is, sometimes our government agencies are very siloed, and their databases don't necessarily communicate with each other. So if I want to know if someone is being served in homeless services, and also has a comorbid mental health and substance use disorder, how do we know that we're serving people effectively, and using that data effectively? And one of the things that we've been hearing, also from other folks is that, "If we just had the housing application and the food stamp application coordinated with each other, it could actually save a lot of work for the caseworkers." And so, those are very real things that I think can be used for good.

(03:03:43)
However, I think one of the issues that I'm concerned about, especially working with a immigrant community previously, is given what we've seen with public charge, and potentially with HR1, how do we ensure that AI is not being used to store information that isn't relevant or information, that they should not have access to, in order to make sure that our communities are protected? So how do those two things exist?

Dr. Morgan Dwyer (03:04:18):

So I will start. So I can't speak to the specific government programs that you referenced, but I can tell you about OpenAI's commitment to user privacy, which is that it's central to our product. We believe it's important for users to retain control over their data. That's why, when you sign up for a ChatGPT account, you're given information about how your data will be used. That data is privacy protected by default. So usernames are separated from conversations, and personal information is separated from the conversations as well, ahead of any use of user data in training. We also provide users with the option and full control to request that their data not be used for training, and also to request that their data be deleted. So we take privacy very seriously.

Shane Cahill (03:05:23):

Council Member, thank you very much for that question. And we'd just echo what Morgan said. At Meta, we take privacy absolutely seriously. It is core to everything that we do. Privacy and safety go hand in hand, and it is an absolute commitment of the company. And if I might give an example of our Muse product, for example, you can opt out of training, you can ask it to forget information that you give it. You are in control of your data, and we're also planning on releasing a confidential, or an encrypted version of this, in the future.

(03:06:03)
If I may, I just wanted to touch upon public services and health. I know that you mentioned these, and these are core points. This is where we really believe in the value of open-weights, in terms of being able to really provide advanced AI for health, for the provision of health services, research, and the macroeconomy, in the sense that data is fully retained by those entities.

Alice Friend (03:06:37):

Ma'am, similarly to my colleagues, user privacy is basic to user trust for us, and so we take it very seriously. We have privacy policies that are prominently displayed on our website that you can go inspect. And we also know that user control is central to management of your own privacy levels, especially across our Gemini tools, which is our AI suite of tools. We also invest a lot in privacy enhancing technologies and encryption as well. We try to take a layered approach to privacy and security. And finally, we have an AI framework in particular, that combines our security and our privacy practices into one holistic framework to, again, ensure that user privacy. And we're happy to furnish that to you.

Logan Graham (03:07:32):

Likewise, at Anthropic, privacy, data privacy, user security, is core to our safety commitment. We make sure to protect user data and user privacy on the platform. And in addition to that, I would point towards, that the way the platform and the models can be used is restricted by our usage policy, which prohibits surveillance, prohibited law enforcement, criminal justice, and censorship purposes as well.

Linda Lee (03:08:05):

Thank you, and I look forward to hearing more about what those layers look like, as well. So hopefully I can connect with each of you after this. So thank you. Thank you, Chair.

Carmen De La Rosa (03:08:14):

Council Member Maloney.

Virginia Maloney (03:08:16):

Thank you, Chair. I worked in tech for nearly a decade, and one of the core principles is that if you can't measure it, you can't improve upon it. So first, you mentioned you believe in incident reporting and disclosures, but in the context of this conversation, how do you define a safety incident inside your companies? Council Member Lee touched on privacy. Do you track privacy breaches? What about a successful jailbreak? Would that be considered an incident? And is a containment failure that occurs during testing an incident, or does it only count once a real person is harmed? I would love more details on how exactly you're tracking some of the concerns that the council has raised today.

(03:09:02)
And second, when an incident happens after disclosure, can you walk me through what changes? Who owns the fix? How do you verify that it worked? And who decides whether or not the model continues to run in the meantime?

(03:09:15)
And then lastly, what are the most important safeguards that you know how to implement today, what's stopping it from being implemented across all products, and what you believe should be the industry standard? Thank you.

Dr. Morgan Dwyer (03:09:33):

There were a lot of parts to that question, so I'm going to do my best to answer them. If I fall short, please let me know.

(03:09:40)
So first, the question of how you define an incident, I think this has been an area of a lot of confusion publicly, so thank you for asking the question. When we talk about incidents at OpenAI, we're talking about misalignment incidents. The best way to understand that is, it is not unusual, not suspicious, for an agent to look at a website for information. There's nothing abnormal about that. But if the agent accesses non-public information on the website, that's an instance of misalignment. And so what OpenAI is doing is making instances like that, even though there might not have been a harm to the third party, we are making instances like that public on our website. Again, because we believe it's important to share what we've learned, to advance policymakers' as well as researchers' understanding.

(03:10:42)
On the specifics of incidents, my understanding as a policy person is that this is actually a robust area of policy debate, and so that's why we're happy to make our thinking on this public through our reporting framework.

(03:10:59)
I'm going to pause there, because I can't remember the rest of your questions.

Virginia Maloney (03:11:07):

Why don't we focus on the first question, which was on measurement, and hear from all four companies?

Shane Cahill (03:11:15):

Council Member, specifically in relation to incident, I think that was the, correct me if I'm wrong, I think that was the first piece in relation to tracking and how we define it. We set this out in our scaling framework, which we've made publicly available. I don't want to be imprecise, as I don't have it in front of me, so I don't have it to quote to you. So please let me follow up with you afterwards and connect you with the right people to talk to.

Alice Friend (03:11:50):

Yes, ma'am. I think this is a critically important question as we're debating with multiple regulators around the country and around the world right now, what constitutes an incident? Particularly when you think about the possibility that we could over-report incidents, some of which may not be of a serious enough nature for public concern. We want to ensure that we narrow to the class of incidents that are truly important for us to use to learn to improve safety, and also for us to share with you all to collectively improve public safety.

(03:12:25)
So a few things come to mind, as we've been having these debates. One of course is cybersecurity incidents, incidents covering the security of our most powerful AI models themselves. That's been under discussion for several years now, protecting model weights, in particular.

(03:12:45)
We also talk a lot about focusing on incidents that cause material harms in one way or another, and I think part of the discussion will be how we define those with precision. We also consider incidents to be those that violate our policies. You asked us about how we respond to incidents, and primarily our trust and safety teams are responsible for responding to what we call escalations, which usually involve violation of those policies. First, reviewing the alleged violation, which are often reported to us by external parties. And then if we determine that in fact our policy has been violated, we have a variety of different actions we might take. And then of course, a violation of the law. As I've said a couple of times in the hearing, if it's illegal without AI, it's still illegal with AI. And so, I would think that incidents that need to be flagged would of course involve violation of the law.

(03:13:47)
As to most important safeguards, it's very hard to answer that question purely because there's a range of different safety considerations, we've talked about many of them today during the hearing. And again, several of us have referred to this layered approach. My own background is in national security, we talk about layered security in that context as well, so you wouldn't really want to talk about a single safeguard. You would want to talk about layers of safeguards that together create much more assurance and confidence in the safety of a whole system.

Virginia Maloney (03:14:20):

Thank you very much. The testimony helps highlight that there's more work to be done to classify what's incidents in the future, and create an industry standard for what would require disclosure and what would require action. The second part of the question was to walk through what happens after an incident occurs, who owns the fix, and who decides whether or not the model or the product keeps running in the meantime. Thank you.

Dr. Morgan Dwyer (03:14:49):

Yeah, so OpenAI has instituted monitoring during testing and evaluation. That monitoring creates automated alerts to our research and security engineering teams to let them know of potential incidents. And then, we have recently clarified our escalation processes as well as

‍

responsibilities across teams, and made it clear the process for pausing activity and when it is safe to restart.

Shane Cahill (03:15:26):

Council Member, in relation to your second question, we have an extensive team, actually extensive teams of people, who as part of their day-to-day, every day, day in and day out, are leading and responsible for the development, deployment, and use of our AI systems.

Alice Friend (03:15:50):

I'll just say, ma'am, I was attempting to answer that question when I referred to the process internally, with our trust and safety teams. But if you'd like some more detail, I'm happy to follow up after the hearing.

Virginia Maloney (03:16:03):

Thank you, Chair.

Logan Graham (03:16:04):

Yeah, likewise, the process involves multiple different teams, depending on the nature of the incident. If it's at the core of security, and our own security, we require a security team to work on this. If it's about the model behavior, and misalignment, it might be a research or training or safety consideration. If it's about incidents of misuse on the platform, we have the safeguards team. I think you're pointing at, this is becoming more complex over time, and I think this is one reason, as my colleagues mentioned here, this is a frontier of defining both what is an incident, and how or what would a good process look like for dealing with them.

Carmen De La Rosa (03:16:43):

Thank you. We are going to take a five-minute break, and we will be back with Council Members Wilson, Ossé, Hudson, and then Schulman.

Speaker 6 (03:18:14):

Only there part-time? Are they only there part-time? [inaudible 03:18:18] Well, you're part-time people, not part-time living.

Speaker 7 (03:18:22):

[inaudible 03:18:23]

Speaker 6 (03:18:22):

They live there?

Speaker 7 (03:18:31):

[inaudible 03:18:35].

Speaker 6 (03:18:34):

They live at 1 West End Avenue? Half that building is [inaudible 03:18:43]. One thousand apartments. I want to give him a chance. And then he [inaudible 03:18:52] Yes I did, I said your name about three times. Absolutely. Because I was out of there in three minutes.

Speaker 7 (03:23:38):

Three minutes.

Speaker 6 (03:23:38):

Well, I gave them three minutes, because I had to get back to the other... It was too far. So when I got there, we have a table, and it's there, in the neighborhood. So I left the table and I run, I went to the subway with-

Chair (03:25:16):

All right. We're going to start back up again, so if our panel could come back on screen, we appreciate it. We're going to start with Council Member Wilson followed by Council Member Ossé, followed by Council Member Hudson.

Carl Wilson (03:25:33):

Thank you, Chair. My questions are related to my bill which deals with the disclosures and prohibiting deceptive advertising on AI models. My question is what guardrails on misleading advertising and truthful disclosures do you wish your competitors had to abide by? And given the complexity of these tools and AI models, where are consumers most likely to be misled or confused? And what do you wish consumers understood better about these tools, capabilities and risk?

Dr. Morgan Dwyer (03:26:11):

OpenAI's usage policies prohibit the use of our tools for scams, fraud and impersonation. We also embed in every single one of our images and audio, content provenance or watermarks or metadata to tell people if the information was AI generated. And we make tools available so that people can assess whether their content that they are seeing is AI generated.

Shane Cahill (03:26:48):

Council member, transparency is absolutely foundational to accountability and trust. For example, our scaling framework has a change log which details each change that we have made to our framework, just as an example of the transparency that underlines our approach. In relation to your question about competitors, I would just note that I generally think that there are significant laws already at federal and state level regarding misrepresentations.

Alice Friend (03:27:25):

Yes, sir. I can honestly say the most important thing to us is continued technical standardization across the industry so that we have common ways to operate and identify the providence of information. We're very heartened by the broad adoption of the C2PA content credential that I referenced before. I also referenced before that we built our own SynthID watermarking technology that many across industry have adopted as one tool in order to identify when content is generative AI created. One of the things that we do a lot of at Google is do research into how users interact with information. Search is part of our DNA. And one of the interesting things about labeling that we've found is that there are users who, when they see a label, they are less likely to trust that information, but they're more likely to trust unlabeled information.

(03:28:31)
And just because information that you see online doesn't have a watermark or a label on it doesn't necessarily mean it is automatically trustworthy either. So we work through and think very hard about what are the ways that we can give users information that they will be able to know the context of what they're interacting with and make sound judgments about which information is trustworthy and which isn't. So this is part of the research that we do.

Logan Graham (03:29:02):

Council member, our view is that we want Claude, our product, to act unambiguously in the user's interests. For that reason, we do not run ads nor are Claude's responses influenced by those of advertisers. And furthermore, Claude does not generate images. And so we try to reduce the risk surface in this way.

Chair (03:29:29):

Thank you. Council Member Ossé, followed by Council Member Hudson, followed by Council Member Schulman.

Chi Ossé (03:29:34):

Thank you, Chair. Mr. Graham, you've indicated that you run red teaming at Anthropic. Will your company commit a certain amount of compute for free to New York City and other municipal governments to research vulnerabilities and build defenses? And if yes, how much compute indefinitely? And I'll ask the same question for the three other companies. I know that Meta indicated that that is something that they would be interested in doing. For Meta, how much compute indefinitely?

Logan Graham (03:30:03):

Well, I am not in a position to commit anything today. I'm heartened by this question. We spend a lot of our resources internally on safety alignment and defensive practices. But moreover, this year we've taken very large steps to provide external access and advanced access of models to cyber defenders for this reason, including at the city and state level in New York. I'm personally looking to try to further these efforts at Anthropic. It's a question of many ways we could support this. We support free Claude credits at the New York City level with cyber command, for example, a number of state and local leaders, but it goes much further than that. It goes to all pieces of critical infrastructure, releasing research, safety reports, technical know-how. It's a very, very large challenge and one very close to my heart, and I'm glad you asked.

Chi Ossé (03:31:01):

Dwyer, Friend, I think we have the order already established here. Is the company's position open to providing free compute to New York City?

Dr. Morgan Dwyer (03:31:15):

I'll take that next. Thank you for the question. I'm happy to share that OpenAI has already committed to donating $1 billion towards strengthening cyber defense through our Daybreak for defenders initiative. That covers things like providing access to our most advanced AI models for use in cyber defense. It also includes technical assistance and training. And we're already working with the Port Authority as well as with New York State.

Chair (03:31:51):

Cahill.

Shane Cahill (03:31:52):

Yep. Thank you so much, council member. It's a great question. In relation to specifically your question on compute, let me come back to you on that. I want to make sure that I'm providing you with the right information, so I'll talk to the right people and come back to you on that. But I just wanted to note in relation to red teaming, we work with external evaluators and to note that we signed the commitment, the accord to partner with independent external evaluators and assessors. This is also part of our scaling framework. I just wanted to mention as well the absolutely important and critical role of open-weight models in relation to cybersecurity and hardening cybersecurity in particular, we have our Muse Glimmer model, which is open-weights, and we really believe that in addition to furthering innovation and research, open-weight models have a really significant role to play in furthering the state of art in terms of hardening cybersecurity.

Alice Friend (03:32:58):

And, sir, I'm going to have to reach out to our cloud business specialists and get back to you on that. I don't work on technical infrastructure, and so I really can't comment or commit to compute at this time, but I can pledge to get back to you on that.

Chi Ossé (03:33:14):

Okay. I would just say that if it is in the interest of these companies to provide any type of safety protocols for municipalities like New York or just for any governments across the nation, nonetheless, the globe, I think this would be a great tool for us to use in order to keep our civilians safe. So I know that some folks said that they would get back to me. This council would love to hear back from all of your companies on this possibility. Additionally, all of you have said on the stand today under oath that your companies will support and work with the council on any AI regulation and safety measures and have supported measures like the RAISE Act. I know that a couple companies said that they supported the RAISE Act, but let's be real here. It is well known that OpenAI, Anthropic, Google, Meta lobbied against the RAISE Act for a year, but all of a sudden, once the governor signed it into law a month later, your company started saying you support this legislation.

(03:34:15)
As many people know here, the RAISE Act is the floor of AI safety, not the ceiling. And with that said, do you support or pose the federal government blocking states and local governments from regulating AI? Because that is the position of the federal government.

Dr. Morgan Dwyer (03:34:32):

I will start. Thank you for the question. So we have been clear that we think the federal government should lead in frontier safety regulation. But in the absence of federal regulation, we believe it's important for states to advance harmonized approaches to frontier safety. I'm happy to share that OpenAI has supported legislation that is stronger than the RAISE Act. In Illinois this year, we supported a frontier safety bill that would require third party audits of our safety framework. And we're committed to working with policymakers to continue raising the floor on frontier safety.

Chi Ossé (03:35:15):

I'm just going to push back there because I support the RAISE Act. I think it was an incredible start here in New York State. And while you're saying that OpenAI has supported, your words, stronger AI regulation, OpenAI leadership has also lobbied against congressional candidates who promise to work on AI legislation. So how can we trust your companies, not just OpenAI, but all four of your companies, not to fight against AI regulations when your political activities and contributions do not say the same?

Dr. Morgan Dwyer (03:35:56):

I will start again. Thanks. Look, I can't speak for the personal actions of OpenAI leaders that they have taken in their personal capacity. What I can tell you is that we have endorsed strong regulations both on frontier safety in Illinois as well as on youth safety in California. And we are committed to working with policymakers to strengthen regulation and to ensure that all AI is developed responsibly.

Chair (03:36:29):

Mr. Cahill.

Shane Cahill (03:36:30):

Thank you, council member. In relation to your question, how I think about it broadly is that it is critical that the US and democratic countries lead in relation to AI innovation. In this regard, AI is transcontinental, I guess. I was going to use transnational, but transcontinental in the case of the US. And therefore it's really important and critical that regulations and obligations are consistent across the board if it is to be true that the US and democratic countries can continue to lead in AI innovation. We support a uniform, robust federal standard in that regard.

Alice Friend (03:37:20):

Google also supports a federal framework for AI. We think that federal framework should first and foremost concentrate on frontier or the most advanced AI capabilities, primarily because they often touch on national security, and that's a traditional jurisdiction of the federal government to ensure that national security standard is the same across all 50 states and our territories. But we also believe that there's lots of jurisdiction that is traditionally at the state level where it is perfectly appropriate for states to regulate on AI. And, again, we think a lot of existing frameworks, both at the state and federal level, already apply to AI technologies, but we're working very closely with states and with the federal government to examine places where we might need net new regulation for new technologies introduced by AI.

Logan Graham (03:38:15):

First, I want to say that we've long supported the role for government to play here, both at the federal and the state level. I want to clarify that we were the only company on this panel to support SB 53 in California before it became signed into law, which my understanding is was the basis of the RAISE Act. We support the RAISE Act, and, in fact, we supported stronger legislation, including in Massachusetts, requiring independent evaluation as well. And we've also proposed a federal framework that goes further, we think raises the floor, that we need to raise it. We detail this in what we call our advanced AI framework as well.

Chair (03:38:56):

Thank you. Council Member Hudson.

Crystal Hudson (03:38:58):

Thank you so much, Chair. We heard earlier from a panel of whistleblowers who raised a number of flags, and one issue raised was that of self-improvement among AI agents. What is your company's core belief around the role of self-improving AI in your overall strategy? And to be more specific, is it core to your AI strategy or a less significant part of the strategy? Could you continue your race to the top or the bottom, I suppose, depending on one's perspective, without self-improving AI agents or with significant guardrails on the way agents self-improve? And my second question is when a new AI data center strains a local grid or water supply, the costs can end up in everyone's utility bills while the benefits go mostly to the company. Who should bear those costs? The company that creates the demand, the utility that builds the capacity, or the public that shares the system but played no role in building it? Thank you.

Dr. Morgan Dwyer (03:40:01):

Thank you for your question. I'll start off by addressing the question about RSI. To say that we believe that RSI may be one of the most consequential safety and security issues of the coming decade, and that's why OpenAI has advocated for federal legislation specifically focused on our public and our frontier safety blueprint. It's available online and I'm happy to share it with you as follow-up. On the case of electricity costs, look, OpenAI is committed to paying our own way on energy, but we're also committed to building with and for communities. All of our Stargate sites, which are our infrastructure sites, have what we call a community compact. That's developed with the community and addresses how we're going to work together. For example, we recently announced $80 million of community benefits investment at our site in Georgia.

Crystal Hudson (03:41:15):

Thank you.

Shane Cahill (03:41:17):

Council member, in relation to your first question on recursive self-improvement, if I may, I might just go back to a point that I mentioned earlier in the day in relation to recursive self-improvement, that we believe that committing the significant majority of compute towards serving people rather than racing towards recursive self-improvement is one of the best ways to ensure that this technology is developed safely. In relation to your second question in terms of electricity and data centers, we believe that customers should not bear costs and we pay the full cost for electricity used in our data centers. I also might just mention as well our Future Is for Everyone Fund, which is a $1 billion investment in relation to communities that we partner with and work with with our data centers.

Alice Friend (03:42:13):

We also take a very prudent approach to self-learning inside our model training. We use AI models to help us evaluate, benchmark, and refine other models, but our use of this type of iterative model development is confined to narrow supervised processes, that's human supervised processes, to keep progress verifiable and within defined safety limits. We also manage the risks of fully autonomous model self-improvement through our frontier safety framework. So we're very mindful about RSI and are quite controlled in the way that we think about self-learning internally. On data centers similar to the other companies represented today, we believe in paying our own way and have pledged to do so, particularly when it comes to the energy demands of data centers. We've also invested in a wide range of energy sources to ensure that our data centers have an independent energy source that does not strain the grid and in fact adds back to the grid so that in the long term it will benefit wider energy customers.

Crystal Hudson (03:43:29):

Thank you.

Logan Graham (03:43:33):

Likewise, on recursive self-improvement, we take that extremely seriously and have from the start. I think from my purview that there are three really important things here. The first is just measurement and understanding. I'm glad you raised this question because we think this is something people need to talk about. In late spring, we published what I think is a first of its kind assessment of how it is happening or signs of it happening at Anthropic. Happens in a lot of ways and it's nuanced. In late summer, we published a follow-up that went into further detail of how we should understand and measure self-improvement. But that's not enough, and that's why you saw us and our CEO publicly call for pacing the frontier, because, candidly, the technology is moving very fast and we think we would benefit from having more time. And this is the second component.

(03:44:22)
And then obviously the third thing that you need to do here is figure out what the right guardrails are, but additionally what level of technology development we should be going for, as well as what safety processes we need along the way. And I think this is just where we're at now, and I'm glad that we're having this discussion. On data centers, this is outside of my expertise. My understanding is that we pay our own way and we're committed to contributing and working with the communities around them, but I'll have to defer to my excellent colleagues who work on it.

Crystal Hudson (03:44:59):

Thank you all, and thank you, Chair. I do want to just make my one little note that it seems like the self-improving aspect is absolutely core to everyone's AI strategy, and that's certainly concerning given the testimony we heard earlier this morning. So thank you, and I look forward to any follow-up.

Chair (03:45:23):

Thank you so much. Council Member Schulman, followed by Brooks-Powers, followed by Brewer.

Lynn Schulman (03:45:28):

Thank you. Good afternoon. I am council member Lynn Schulman. I'm chair of the New York City Council Health Committee. As a breast cancer survivor, I am looking forward to the day AI can help find cures for that and other diseases. That said, there is a dark side to AI intervention in healthcare. Most viruses that are found in nature can be contained fairly quickly, but an artificial pathogen has no constraints. In August, a team from Stanford used an AI model to design an entirely new virus from scratch. In addition, Anthropic has its own AI-powered biology lab. What measures are being put into place such as placing, I'm not going to say guardrails, I had that originally, safeguards on DNA synthesis to prevent rogue viruses from being created and replicated at will to jeopardize the public.

Dr. Morgan Dwyer (03:46:24):

Thank you for your question. The question about how AI could enhance or make worse biological risks is central to OpenAI's preparedness framework. That's the framework that we use to guide our decisions about model risk and whether we have the right safeguards in place. So we evaluate for biological risks. As part of that framework, again, we use third party evaluators and red teamers, we also work with the federal government as it pertains to national security risks, and we are transparent on the results of those evaluations. So with the launch of every major model, we release what's called our system card, and that card details the evaluations that we performed as well as the results. And those evaluations, as you mentioned, do include biological risks.

Shane Cahill (03:47:27):

Council member, this is such an important area and question, so thank you for raising it. Biological risks is one of the core areas, one of the key risk domains that's part of our scaling framework at Meta. We, as I mentioned earlier, have a multilayered approach to risk assessment, cross-training, evaluation and release, and that includes adversarial testing with external experts. We work with governments, other stakeholders and experts in relation to that. And as I mentioned earlier, as part of our commitment to partnering with independent third-party evaluators and assessors also.

Alice Friend (03:48:14):

Yes, ma'am. Similar to our colleagues, we also have bio or biological capabilities as part of our frontier safety framework. As we look at our critical capability levels that I referred to earlier or the levels at which we would trigger additional mitigations in our models, we look for what's called uplift. That is to say the model will be able to assist users in creating information or knowledge that's not otherwise available through widely accessible sources. And we think very carefully about how to measure for bio CCLs, and are constantly upgrading and updating our ability to do that. When it comes to those mitigations or those safeguards, as you so aptly put it, we implement those at both the model and the application levels to ensure that casual users cannot access critical bio information. It is very important to consider the dual use nature of biological capabilities, of course, because these are the kinds of capabilities that scientists, particularly medical investigators, need in order to make advances in our own healthcare as well.

(03:49:41)
And so we think very carefully about how to release models to scientists that can use the technology responsibly. We did that for the first time with our AlphaFold model, which, of course, is how millions of investigators around the world are able to look at the folding of proteins and to use that research to find cures for diseases. So there's a real careful approach that we take to ensure that science can continue, but that dangerous uses of biological knowledge cannot.

Logan Graham (03:50:19):

Likewise, we take this extremely seriously. In fact, if I'm not mistaken, it was my team and myself that developed the first call for action on these risks, the first evaluations, the first tests, the first industry government partnerships on biological risks and evaluating models and their safeguards several years ago at this point. Not only that, I personally think we need to go further here. You mentioned DNA synthesis screening, I think this is personally a no nonsense approach. There's much else we can do to work on biological defense. And alongside the other companies, we maintain the same and in fact try to compete for the best safety practices here. And you can see some of what we found, I think, disclosed for the first time ever in a recent threat intelligence report where we have observed actors attempting to do biologically risky activities with models.

(03:51:17)
The threat is, I think, clear to us now. We think we need urgent action. But I will close by saying that as somebody that grew up with a number of chronic diseases going blind and couldn't walk, I very intimately feel that the upside of the same capabilities...

Lynn Schulman (03:51:33):

If I could just say just one in closing, the upside has a great potential, the downside is extraordinarily detrimental to humanity, but you should consider about screening orders for synthetic nucleic acids, which is DNA, and the equipment that's needed to make them because right now AI is now outperforming PhD level virologists. So an AI can take this and go somewhere else with it. So that's something that's really important to have those safeguards. Thank you.

Chair (03:52:12):

Thank you. Council Member Brooks-Powers, followed by Brewer, followed by Narcisse.

Selvena Brooks-Powers (03:52:21):

Thank you, Chair, and thank you, speaker. I'm going to just run through my questions and if I have to repeat anything, just let me know. First, before this summer, each of your companies told the... Your AI agents went rogue and nearly a dozen incidents have been reported across all of your companies. Can you tell New Yorkers today that none of your agents has access or attempted to access a New York City government system or a New York City resident's personal data? Next, Southeast Queens has long been a target, cloning and deepfakes make it easier than ever to impersonate a family member, a bank, or a city agency. What specifically stops your tools from cloning a real person's voice or forging a document? What protocols are the leaders of AI development putting into place to make sure AI does not take information from hate sites and disseminate it to further racist and antisemitic or Islamophobic discourse? That was all, sorry.

Dr. Morgan Dwyer (03:53:43):

Thank you for your question. I'll start off by saying I am not aware of any incidents affecting New York City, but we have an ongoing investigation into potential incidents going back to November 2025. And as part of that investigation, we are notifying any affected third parties and making the results of our investigation public. So I can commit to you that if there are incidents that affect New York City, we will make the third parties aware. On your question about impersonation, OpenAI, our usage policies prohibit the use of our tools for impersonation, fraud and scams, and we enforce on those policies. And I would say more broadly, the approach that we take to safety is holistic. That involves filtering unsafe training data, performing evaluations that are very detailed, working with third parties on those evaluations ahead or alongside our launches. As I mentioned, we make the results of our evaluations public and summarize the work that we did and any residual risks in our system card. And then we monitor for failures of our safeguards so that we can continuously improve safety.

Shane Cahill (03:55:13):

Council member, in relation to your first question, I'm not aware. In relation to your second question, we have robust and comprehensive policies in place as well as teams of experts who work on frauds and scams. And I'd like to follow up with you with those experts to discuss that one more in detail. In relation to hate content, first of all, I just want to acknowledge how upsetting such content is in terms of people who experience it. Our goal at Meta is for AI offerings to be responsive, accurate, balanced, and unbiased.

Selvena Brooks-Powers (03:55:58):

I'm sorry, was that answer just now to the last question about the not taking the information to create the negative discourse, the racial discourse?

Shane Cahill (03:56:11):

Yes, that's correct, Council Member. I was speaking to your third question in relation to that type of content and our objective in terms of ensuring that our AI offerings are responsive, accurate, balanced, and unbiased.

Selvena Brooks-Powers (03:56:26):

So have you enhanced what you're doing considering that it has been something that has been found on a number of different platforms? Have you all been staying up to course with enhancing whatever those processes are?

Shane Cahill (03:56:45):

Yes, council member. Thank you for that question. If it's okay, I will have our content teams and specialists connect with you afterwards so that I can provide you with precise information in relation to that.

Selvena Brooks-Powers (03:57:00):

Thank you.

Alice Friend (03:57:02):

Council member, thank you for these questions. I'm also not personally aware of any New York City resident being impacted by the three incidents that I mentioned earlier. I do want to note that in our case, in all three incidents, the model stopped itself once it realized it had left the test environment. We tend to think of this less as a misalignment event and more of a mistake event. One of the websites, for example, that was accessed had the same name as the fake website being used in the test environment. And once the agent realized that it was in fact a real company, the agent ceased its activity. We have a number of tools across our platforms to manage likeness and identity, and we've also supported a range of different regulatory proposals regarding this topic. We proudly support the NO FAKES Act, which would protect an individual's...

Alice Friend (03:58:00):

We proudly support the No Fakes Act, which would protect an individual's digital replica and give people the right to control the use of their own voice and likeness in AI-generated works. We also have a tool called Likeness ID on YouTube that helps creators identify and manage AI-generated content that uses their face or voice without permission. So we invest in a variety of different ways to address this critical issue.

(03:58:27)
On the information and getting through into our tools about hate and bias, we have, again, a layered approach, as I've been saying, to this type of issue as well. Everything from the model training process itself in both pre and post-training, all the way through guardrails on our application layer. All of which produce what we're proud to say is the least biased model in the industry. Independent investigations have shown that our models show the least bias, for example, with regards to partisan bias.

(03:59:13)
But we take these issues extremely seriously. We want to create a fair and neutral set of information for people to access, and we want our responses generated by our AI tools to represent a broad array of experiences and perspectives without bias towards or against any particular identity or ideology.

Logan Graham (03:59:40):

And while in my role, I haven't covered any effect on New York City. I can say that we work with in investigating incidents like this. We work with the right parties at the right time to disclose to affected parties, the right level of law enforcement, government at the right level as urgently as possible needed to remediate the effect. And we commit to making sure that we follow up with the right parties to do so. And to your point on the information environment and otherwise, I'll point to a couple of things here. First is our focus on testing for Claude itself and our language model products approach here.

Carmen De La Rosa (04:00:18):

Can you speak a little louder? Can you speak a little louder?

Logan Graham (04:00:22):

Yes. Can you hear me now?

Speaker 8 (04:00:24):

Yes. That's better.

Carmen De La Rosa (04:00:24):

Yes.

Logan Graham (04:00:25):

Thank you. I'll point to our longstanding evaluations of political evenhandedness, stereotype bias. We train Claude to not comply with particularly harmful requests, in part for this reason and that this is baked into the nature of the model.

Speaker 8 (04:00:48):

Thank you for that. And thank you chairs. And I'll just say that in closing that I know that the AI companies are pushing folks to allow AI to be developed through people, but I think it's fair to say that using live users to test these products can present dangers and definitely warrant improvements. And I hope that's something that is taken from today's hearing to better improve the guardrails that need to exist. So thank you for your responses. Thank you, Chair.

Carmen De La Rosa (04:01:25):

Thank you. We're going to go to Council Member Morano as a bill sponsor, and then we're going to go Brewer, Narcisse and Joseph. If folks could keep it to one minute just because we have to get to the admin panel. Thank you so much.

Frank Morano (04:01:41):

Thank you, Chair. Thank you for your testimony today. I know it's a long day for you guys as well. Because I only have a minute and my colleagues know what a challenge that is for me, I'm going to go through a series of yes or no questions. And then if you could all answer in the order of Dwyer, Friend, Cahill, Graham quickly. And then if you want to elaborate on any of the areas that I raised, please do so.

(04:02:05)
First, does your company believe there's any non-zero chance that advanced AI could escape meaningful human control and cause catastrophic harm as the whistleblowers indicated?

Dr. Morgan Dwyer (04:02:25):

I don't know. What I will say is that no level of risk of catastrophic harm is-

Frank Morano (04:02:29):

So if we could just do yes or no now, and then I'll invite you guys to elaborate after everyone answers, please, Ms. Friend?

Carmen De La Rosa (04:02:38):

Dwyer?

Alice Friend (04:02:40):

The purpose of our Frontier Safety Framework is to guard against that possibility. So do we entertain the possibility? Yes. As a responsible actor in this space, we entertain the possibility.

Shane Cahill (04:02:56):

Council Member, our scaling framework includes loss of control in terms of the risks that we evaluate and mitigate.

Frank Morano (04:03:03):

And these are my other yes or no questions and handle them however you want. So why should the public accept, essentially trust us as the safety standard from the same companies racing each other to build the most powerful systems? Additionally, will you commit today that if your own safety team says a model is too dangerous to deploy, commercial pressure won't ever overrule that judgment? Additionally, has your company ever continued developing or deploying a model over the objections of members of your own safety team?

(04:03:39)
And lastly on my bill, should you be allowed to use someone else's, someone's private chatbot conversation for targeted advertising or behavioral profiling without their affirmative consent?

Dr. Morgan Dwyer (04:03:58):

So I will start and try to get through as many answers as possible. One, OpenAI supports the need not only for us to be responsible for safety, but we have supported regulations at the federal level as well as at the state level because we think it's important not only for us to be responsible, but for governments to hold us accountable.

(04:04:22)
On the question of whether we would continue developing models if they were unsafe, OpenAI has recently announced a pause of some of our training activities because we did not deem moving forward to be safe. We have also delayed the release of models because we didn't think that they had sufficient safeguards. So we've done it before. We will do it again. And more broadly, I will say that all of our decisions regarding frontier safety and the release of models are governed by our preparedness framework that is available online so we're transparent about what goes into those decisions.

(04:05:04)
And then with the release of every model, every major model, we release a system card which details the work that we've done, the evaluations that we've conducted and any residual risks.

Shane Cahill (04:05:21):

Council Member, in relation to your first question, I see it differently where we are accountable. Our framework and preparedness reports are public. Meta uses outside expertise. We signed the accord at the White House on super intelligence, which committed us to partnering with independent auditors and assessors.

(04:05:47)
For example, in relation to, I think your second question, we delayed the launch of Muse by several months to focus on safety and security, and we acted on this without waiting for industry. It was just part of our normal day-to-day work because it was the right thing for us and it was the right thing for people to do.

(04:06:10)
And then in relation to ads, I would just note that for our Muse product conversations and interactions do not inform ads on Meta's other products.

Alice Friend (04:06:23):

Sir, at Google, we do use external evaluators in the process of research and development of our AI models and our systems. We have supported audits of our safety procedures as well. And you'll see in our recent paper from over the summer, which is called A Pragmatic Approach to AI Regulation in America, we do think that AI needs to be regulated and it needs to be regulated well.

(04:06:52)
We've supported a range of different legislative proposals at the federal and state levels to this end. We also, to your question about conversations, we give our users controls over whether their activity in our tools can be used for training our AI models. So yes, we think users should be in control of that.

Logan Graham (04:07:16):

And Council Member, I would point to our longstanding call for the involvement of government at the federal level and the state where necessary and appropriate. Because this goes beyond the labs and we don't think the labs should be checking their own homework. Not only this, but we have demonstrably withheld models when we felt it was not safe to widely release this year withholding our frontier model, probably the most notable instance of this, instead deploying it to cyber defenders in order to secure the world in advance of a world of more powerful models that could exploit software vulnerabilities from wherever.

(04:07:53)
This is part of our process. We go over and above the process. We detail our default in the responsible scaling policy. And to your other question, we believe that Claude should act unambiguously in the user's interests. And for that reason, we do not run ads nor are Claude's responses influenced by advertisers.

Carmen De La Rosa (04:08:15):

Thank you so much. Council Member Brewer, followed by Narcisse.

Gale Brewer (04:08:18):

Thank you very much. I wanted to know three quick questions. If a model provider you rely on, you or a subcontractor, did not complete the third party validation for a particular package, how would that affect your product's availability? And also, how do you decide who gets the validation? Number one.

(04:08:40)
Number two, China. The speaker asked about China and competition and I thought the answer was, don't worry, they need information from us. So I'm wondering what do you send to China?

(04:08:51)
And number three, ICE. I was upset that one of the whistleblowers said that Google has been working something to do with ICE in Minnesota. So my question is, do you all support not helping ICE at all? Obviously you are made up of immigrants. We should not be shipping immigrants out of this country. Please answer those three questions and thank you.

Dr. Morgan Dwyer (04:09:17):

So I'll start with the question on third party evaluations. We work with a range of third parties to evaluate our models. That includes independent investigators as well as with the federal government. And then we detail who we worked with and the results in our system card when we released our model. Decisions to launch our models are described in our preparedness framework. And so that describes how we integrate all of the results of evaluations and make decisions with respect to launching models. So I would point you there on that particular issue.

(04:09:58)
On the question of China and the PRC, I would like to get back to you on that particular issue. Although I have a national security background, I'm not working in that role at the company and I want to make sure I get you good information. Similarly, with respect to ICE, I'd like to get back to you. I'm not aware of any activities working with ICE, but I don't work on our government sales team, so I'd like to get back to you on that.

Gale Brewer (04:10:31):

Next.

Shane Cahill (04:10:33):

Council Member, thank you very much for your three questions. In relation to-

Gale Brewer (04:10:36):

Three questions.

Shane Cahill (04:10:38):

Pardon?

Gale Brewer (04:10:39):

Three questions.

Shane Cahill (04:10:40):

Yes, three. Sorry, my accent might've gotten in the way there. Apologies. Three questions. For third party validators, we also work with a range of validators and assessors, and we also provide this information in our publicly available preparedness reports. In relation to China and competition, I might just mention that Meta is a proud American company and proud to serve billions of people around the world who rely on our services.

(04:11:16)
We want to ensure that the US and democratic countries lead on AI. And one thing I would just note here is in relation to the importance of open weights and American open weights and the criticality of ensuring that American innovation continues to lead in relation to the availability of open weight models.

(04:11:37)
And in relation to ICE, if I may, I would like to connect you with our teams and experts in that space. I don't wish to be imprecise in responding to you.

Gale Brewer (04:11:48):

Next.

Alice Friend (04:11:51):

Ma'am, in terms of third party evaluators, we also work with the USKC, which is the organization underneath the commerce department that does testing of advanced AI models. We also work with a range of third party evaluators. It's a very nascent ecosystem, and one of the challenges in evaluating AI models, of course, is to get organizations that both have the technical competency to do evaluations well, but also have the subject matter expertise that we may be looking for.

(04:12:22)
Earlier, one of the Council Members mentioned concerns about bio, for example. We have third parties that have the bio expertise that's necessary, but as we have this national conversation about independent verification organizations and third party evaluations, keeping in mind that we still need to mature this ecosystem of independent evaluators, I think is really important.

(04:12:47)
On China and competition, I'd like the opportunity to give you a more complete answer. We don't conduct AI research or training in China. I know that we are part of the conversation about what it means for America to lead and about what it means for America to lead... mentioned that we focus a lot on who's at the frontier, which country has the most cutting edge research in AI, but we talk much less often about deployment of AI, and there I think we should really keep an eye on the Chinese. They have emphasized deploying AI in their economy quite a bit, and that's a place where I sometimes have concerns that the United States is in danger of falling behind China.

(04:13:45)
As to the whistleblowers allegations from today, I don't have any specifics about that, but I'd be happy to ask the public policy team in New York to get back to you right away with any information that we have about it.

Gale Brewer (04:13:58):

Next.

Logan Graham (04:14:00):

And at Anthropic, the use of third parties for verification, developing and using evaluations for models has been part of the process from day one, including with not just external parties in industry or nonprofits, but also with governments such as the USKC. This has been foundational. As my colleague said, it's pretty nascent. We think it needs to be urgently expanded and not just used for pre-deployment testing, but also to understand models and their behavior after deployment and the safety processes at companies.

(04:14:40)
In the case of China, I think it's very clear that the first thing that we need to do is maintain an American and democratic lead in model capabilities, but we're very clear about the threat elsewhere as well. So we have publicly documented Chinese attempts to distill our models, essentially take the content and capabilities for their own, and we work to ban those. We have prohibited use of models in China. We do not serve there. And we have also documented the use we believe by related parties of Claude or the attempt to for cyber offensive reasons. We are extremely serious about this and we think it's a very substantial priority, and this is one reason why we have advocated at the federal level for export controls on the most important chips that power AI innovation here.

(04:15:33)
And on your third question, while I'm not across the issue enough to know what our engagements are, I will say that our usage policy, we ban surveillance, censorship, prohibitive law enforcement and criminal justice uses for this purpose.

Gale Brewer (04:15:49):

Thank you.

Carmen De La Rosa (04:15:50):

Thank you. We have Council Members Narcisse, Joseph P. Sanchez, and then Council Member Phil Long. So Narcisse?

Mercedes Narcisse (04:16:01):

Good afternoon. Thank you, Chair, and thank you Madam Speaker. I want to say thank you to you too because you guys stay here with us and I'm happy to see at least two women is on the panel to talk to us. Hollywood give us clues all the time, but we kind of slow in taking hands on clues. But no companies in this world I feel that should be self-regulated. What I'm sitting here for about four hours, and like I said, thank you to you, privacy, transparency and safety. So now do any of those company that you can say that is a standard across the board for all the company to... Hospital? I mean, do you have AI, sell AI, sorry. Do you sell AI products to New York City Hospital? And if so, do you think that a licensed clinician should sign on all the diagnostic tests?

(04:17:04)
Because I heard if Ms. Friend said that you diagnose with, you went to a process of cancer, if I'm correct. So you understand that people need to be diagnosed by a human. And I can give you example, like for colonoscopy, sometimes the bubble, according to AI, will tell you it's a polyps. In the meantime, it's not polyps, it's a bubble, but AI cannot differentiate that. So therefore you need a human to see through. And right now, I don't know if you read New York Times-

Carmen De La Rosa (04:17:41):

Council Member Narcisse? I'm sorry, can you-

Mercedes Narcisse (04:17:43):

Yeah, I'm going to close my-

Carmen De La Rosa (04:17:44):

... conclude the question?

Mercedes Narcisse (04:17:45):

New York Times already telling us that there's a report that AI is getting confusion between the hospital and the insurance company. So I don't know how you see that happening, how we can make sure that AI is being monitored.

Dr. Morgan Dwyer (04:18:03):

Yeah, so thank you for your question. ChatGPT for healthcare is deployed, for example, in Memorial Sloan Kettering Cancer Center. But to your point, we believe that doctors should remain in charge. We do not think that AI should represent itself as a licensed professional. And we also think though, as we've talked about earlier, there's tremendous potential to use AI in healthcare settings, particularly for administrative uses, documentation. I mean, doctors are already overworked and giving them an opportunity to free up their time so that they can spend more time with their patients is an outcome I think we can all agree would lead to better care.

Shane Cahill (04:18:53):

Council Member, thank you very much for these questions. In relation to your first question on self- regulation, we believe that the accord is a really important step in relation to the concerns that you mentioned. In relation to healthcare, Meta AI is prohibited from acting as a licensed professional, including a doctor or any other medical professional who's licensed.

(04:19:24)
There are, as my colleagues have mentioned, phenomenal benefits in relation to the use of AI in healthcare. I know that there's phenomenal work happening at NYU Langone who actually I think has a specialist division that's actually investing and working specifically around AI in healthcare settings, and similarly at Columbia Irving, which is really doing phenomenal work in that space also.

Alice Friend (04:19:51):

Ma'am, thank you so much for those questions on whether or not a company should be self-regulated. I again want to emphasize at Google, we believe that we are regulated by existing regulations, sectoral regulations, state federal level regulations all apply to AI, and we have supported further regulation, particularly of frontier AI at the federal level, but also other AI directed laws at all levels of government. So no, we should not be self-regulated. We should be within the regulatory frameworks we already are.

(04:20:33)
On the questions about healthcare, so we certainly agree that doctors should stay in the lead and that AI is a tool for clinicians. It's not a replacement for them. In my particular case, I was diagnosed by a person, but often these days when I go in for checkups and screenings, my clinician will ask if they can use an AI tool to take notes while we're doing the checkup. And I always say yes, because I know that our clinicians are incredibly overtaxed by a range of administrative requirements. And if AI can take some of that burden off and allow my doctor to look me in the eye when we're having an appointment, I'm going to say yes to that.

(04:21:20)
But similar to our colleagues, we also have guardrails on our Gemini app so that users will never think that they are talking to a doctor, that they are talking to a licensed physician, and the Gemini app will also flag for them that if they're seeking medical attention, they should get it from a professional. Thank you.

Logan Graham (04:21:43):

Likewise, we've been very clear that we support the role of government here. At the federal level, we've advanced a proposal for meaningful involvement to set standards and hold companies to account for safety processes, evaluations, security, and the like. And we welcome the accords that were signed very recently.

(04:22:02)
To the point of medical usage, if I can use a personal example here, about six months ago, I experienced some symptoms and longstanding eye disease that might make me go blind at any moment. And that night, actually, at about 1:00 AM, it was Claude that helped me identify that it was serious enough that I needed to be treated very, very quickly. Claude triaged a very large part of it for me, but what was most important was I could use that to get to the hospital very fast. It's very clear that both can be transformative and powerful together, certainly in my case, and I think countless others, but this is also one that's closest to my heart that we need to be very careful about.

Mercedes Narcisse (04:22:46):

Thank you.

Carmen De La Rosa (04:22:48):

Thank you all so much. Up next, we have Council Member Joseph, followed by P. Sanchez, followed by Wong, Phil Wong, and then Zhuang.

Rita Joseph (04:22:57):

Thank you, Chair. Two questions. Several of you sell AI products directly to colleges and universities. When student use those products, is anything they enter used to train your models? And beyond training, who can access those conversations and what limit do you place on how colleges can use them, for example, for discipline, academic integrity, investigation, or student profiling?

(04:23:19)
The next one is, given that AI is already reshaping entry level work as we know, as is shown in this new Center for Urban Future Report, what responsibility do you have to ensure these tools help students build useful AI augmentative skills, rather than automated away the very task through which young people learn? What responsibility do your companies have addressing these early career impacts and how can government help?

Dr. Morgan Dwyer (04:23:48):

So to your first question on privacy, we believe that privacy is central to our mission. We give users control over their data. That includes the decision to opt out of training, but all users have their data protected and private by default. So it is separated from their names. And again, they have the option to opt out of training and to request that their data is deleted. On the particular question of colleges and how ChatGPT is used in colleges and education, I would like to get back to you on that. I don't have an accurate... I don't know the answer, and so I'd like to be able to follow up.

(04:24:36)
Because we do believe that education is critical. AI literacy is critical. We've supported numerous bills at both the state and federal level supporting AI literacy. That is both training for teachers to ensure that they can lead adoption in schools as well as improvements in curricula to make sure that students learn how to use AI safely, as well as learn core subjects that are critical to being able to use AI safely and responsibly.

(04:25:15)
To your question about jobs, we think one of the most important things that we and policymakers can do right now is to continue to collect data on the question of AI impacts to jobs and make that data public. We make our assessments of how people are using ChatGPT at work public. We share that. And we also have worked with policymakers, including supporting the Bipartisan Workforce Transparency Act to get voluntary pathways for employers to report on job impacts.

Shane Cahill (04:25:58):

Council Member, thank you very much for these questions. In relation to colleges and universities, I would like to have the specialists at Meta who work in that area connect with you on the details. But specifically in relation to privacy and data, this is absolutely core to everything that we do at Meta. For example, our Muse product, you can opt out of the use of data for training and you can ask Muse to forget any information that you provide to it. And of course, all of the data is within your control in terms of what you provide to it.

(04:26:41)
On the AI literacy point, it's so important. I actually came across a really great example from New York City and I wanted to call it out because I thought it was great. It was called Building Minds, Building Communities, The Digital Empowerment by Design Work. And I thought it was a really, really great example of the use of AI technologies for AI literacy and a flywheel in terms of benefits there.

(04:27:09)
In terms of the entry level point, absolutely understand the concern in relation to that. At Meta, we believe in... not replacement, and we really believe that this will have a transformative impact in terms of enabling and empowering people to pursue their own values and direct AI towards those.

Alice Friend (04:27:47):

Yes, ma'am. Similar to my colleagues, we believe users should have control over their own data.

Carmen De La Rosa (04:27:53):

We're not going to have outbursts from the chamber or you will be removed. You decide. Sorry, go ahead.

Alice Friend (04:27:59):

As I was saying, users have control over their own data across our AI surfaces and can opt in or opt out of their data being used to train our models. In terms of AI use in colleges, as I said earlier, we have tools for educators and administrators to take the lead in how AI is used in the classroom and used for students. We think that colleges should be able to adapt to the needs of their student populations. I, like Shane, was looking into how different colleges and universities in New York City use AI and saw that NYU, for example, has a very helpful page where they go through all of the AI tools they make available to students and give them resources for learning both how to use the tools, and then also training them in the kinds of things they can do with those tools to further their education.

(04:29:08)
I would flag that they use Gemini Notebook, which is a study guide creation tool. So NYU is a good example, I think, of a college thinking carefully about how AI can benefit their student population. And as to the impact on early careers, we think this is also an incredibly important area of research. It's part of understanding the broader economy and labor. We recently released our own AI and economy Atlas, which also releases data about real world uses of AI in the economy and at jobs. And we're hoping that continuing to add to that data set will help economists study and then develop policy recommendations for managing the labor transitions of AI.

Logan Graham (04:30:00):

And at Anthropic, maintaining user privacy is very core to our commitment on safety and security. Users can choose whether or not they want their data to be used or contribute to training a model, for example. But in addition to that, we've tried to pioneer the science of privacy preserving safety maintenance when you need to ensure that users stay safe on the platform.

(04:30:24)
To the point of education, while it's not my area, here's what I understand. We partner with universities. We're very interested in this question. There's a nifty feature in part of our partnership called Learning Mode, which allows a user or student user to interact with a model in a more discursive way that can help them think. But in addition to this, the impacts are really important. I think we are relatively well known for our work on studying the economic and other behavioral impacts of models.

(04:30:55)
We have a comprehensive, and I think we were the first to release this economic index, which details this. But in addition, we've done research into how students are using models because we want to figure out how to encourage the use of models to compliment the development and skill development of students.

Carmen De La Rosa (04:31:13):

Thank you. Up next is Council Member P. Sanchez, Council Member Phil Wong, and Council Member Susan Zhuang. I will remind my colleagues to ask your questions upfront and if you have questions that are specific for some of the members of the panel and not all four, specify. Thank you, Council Member Sanchez.

Pierina Ana Sanchez (04:31:34):

Thank you, Chair. My first question is in connection to heartfelt testimony of Leila Turner-Scott before Congresswoman Jayapal last month. Ms. Turner-Scott's son died following chats with OpenAI that instructed him that incompatible drugs were compatible. She highlighted that throughout the review of vlogs, ChatGPT responded to her son with phrases like, "I've got your back. You can talk to me about anything and even I love you with heart emojis." She stated, and it seems true that the goal-

Pierina Sanchez (04:32:00):

... heart emojis. She stated, and it seems true, that the goal of ChatGPT was not to keep her son safe, it was only to keep him using the product. What updates have your companies made to their models to engage children and prevent addiction? Are you limiting your agents from giving medical and health advice without a license? And my second question is regarding the fact that members of the public and enterprise clients are sharing more and more information with your companies. You have access to copyrighted information publicly available. How do your products currently use information gathered from users? In an earlier exchanges... Chair, if I may. Several of you stated that users can opt out of sharing your data. What is the default option? And how are trade secrets and other confidential business or government information from enterprise clients being used to train AI? Who have you paid for the valuable data that you are using to train your models?

Dr. Morgan Dwyer (04:33:00):

So I want to start off by acknowledging the tragic incident that you reference. Any incidents of harm that results from our product or any other product is tragic, and we take it seriously. I'd like to tell you about ChatGPT for teens, which was recently released to focus specifically on users ages 13 to 18, and is designed to be safe by default. That includes safety protections on the type of content that is available, limiting content that might be related to suicide or self-harm, eating disorders, violence or graphic or sexual content. We also include, take a break reminders, to remind teens to stop using ChatGPT. And we have optional parental controls that allow parents to add additional layers of safety onto their teen's experience. One thing that I will highlight here is if a teen indicates signs of suicide or self-harm, we have a feature that allows the parent to be notified.

(04:34:25)
On your question of privacy and data. As I and my colleagues have shared, we take privacy seriously, and our core value is that users should have control over their data. And I'm happy to follow up on specific details of how those controls work, at a later time.

Pierina Sanchez (04:34:50):

What is the default option?

Dr. Morgan Dwyer (04:34:53):

I'm sorry, I didn't hear you.

Pierina Sanchez (04:34:55):

What is the default option with respect to who owns the data and how it is used?

Dr. Morgan Dwyer (04:35:00):

So users have control over their data. Everything is privacy protected by default.

Pierina Sanchez (04:35:09):

What is the default option?

Dr. Morgan Dwyer (04:35:10):

Everything is privacy protected by default and users have the option to turn off their data for training or request that it be deleted.

Shane Cahill (04:35:21):

Council Member, first off, I just want to acknowledge the terrible tragedy in relation to the Turner-Scott family and how distressing and upsetting that is to hear and my sympathies and condolences to that family. In relation to how Meta approaches minors and young people, creating a safe and productive experience is absolutely imperative to Meta, and we're committed to providing a safe and responsible AI, especially for teens. And we have strong policies and safeguards in place in relation to that. For example, by default, minors only have age appropriate interactions, meaning that content would not be out of place on a 13 plus movie, for example. We also prohibit our AI offerings from providing licensed professional information like medical information and direct people towards appropriate resources. In relation to training data, we take creativity, copyright, and IP rights seriously and believe our practices are consistent with the law.

(04:36:54)
We train on information from the internet, information licensed from third parties, and information shared across our services, and we provide all of the information in relation to how we use that data in our privacy center. In relation to Muse, as I mentioned, I think a little earlier, individuals interacting with Muse can opt out of their interactions for training.

Alice Friend (04:37:27):

Ma'am, I want to highlight a few protections that we have in place with kids in mind in particular. One is for what we call persona, which prevents claims of sentience or simulating relationships and role play that helps prevent kids from thinking they're talking to a person and developing a relationship. We also prevent sexually explicit outputs from chats with kids. And we also have for all ages protocols on suicide and self-harm where we refer users who are expressing suicidal ideation or other types of self-harm to crisis resources. And that approach draws from our deep experience fielding such queries on search. When it comes to training and the default question you asked, for those over 18, it is default on to use chat data to train our models to improve, but all users have control over the ability to turn this feature off or to control the length of time such information is kept.

(04:38:33)
For users between 13 and 17, it's default off. Teens can choose to turn it on if they wish to train a model through our personal intelligence program. And for under 13, it is default off as well. And we never use data for under 13 to train our models.

Pierina Sanchez (04:38:55):

Thank you.

Logan Graham (04:38:55):

And at Anthropic, we have limited the Cloud platform to those only 18 plus. We're concerned about child wellbeing. We monitor and detect for any users that might be 18 or under. And when that flags, we investigate to make sure that we could remove their access if so. On training data, I will have to get back to you with more details as it's not my role. My understanding is that all users must select which option they would like, but I would refer you to our public documentation where we describe this in detail.

Chair (04:39:38):

Thank you all. So up next we have Council Member Phil Wong, Council Member Zhuang, and then Epstein.

Phil Wong (04:39:45):

Okay. Thank you, Chair. My question pertains to the self-improvement process, the recursive self-improvement process, as well as the training activities of your company's AI model. And it is my understanding that when it goes through the self-improvement process, it generates code that itself will run next time around and then it will be a smarter AI model. Is that right? OpenAI, yes or no? Yes or no? It generates code. It will be a smarter AI model.

Dr. Morgan Dwyer (04:40:26):

I'd like to get back to you on the specific definition of RSI. I'm not sure that what you're saying maps exactly to the technical definition we use.

Phil Wong (04:40:34):

Okay. Anthropic, does it generate code automatically to make itself smarter as part of the process?

Logan Graham (04:40:42):

Yes. We've detailed publicly multiple times the degrees in which models-

Phil Wong (04:40:46):

Okay. Yes.

Logan Graham (04:40:46):

-- that generate code are being used for different processes.

Phil Wong (04:40:48):

Okay. Thank you. Meta, does your model self-generate code as part of the training activities or self-improvement process?

Shane Cahill (04:40:56):

Council Member, I'll need to get back to you and have our technical experts follow up.

Phil Wong (04:41:00):

Okay. How about Google?

Alice Friend (04:41:02):

Yeah, same here, sir. I'm not sure we would describe it exactly the way you are describing-

Phil Wong (04:41:06):

I see.

Alice Friend (04:41:07):

... so I want to get you the precise technical definition.

Phil Wong (04:41:09):

Okay. All right. Well, here's my question. If your model improves by itself by generating code, is there a human being, is there a team of human beings that checks the code to make sure that it is benign and not misaligned or malicious? Can each one of you answer that?

Dr. Morgan Dwyer (04:41:33):

So as part of our safety process, I've mentioned our preparedness framework that outlines how we evaluate models and how we assess risks across a wide range of national security risks. So we do robust evaluations of a set of risks and we make those results public as part of our system card, which we release with every major model.

Shane Cahill (04:42:03):

Council Member, as part of our scaling framework, we outline considerations that we are taking overall to maintain human control of model development.

Alice Friend (04:42:14):

Yes, sir. As I said before, we have supervised processes to keep progress verifiable, and we have a range of different techniques to test the model and its performance to ensure that it's staying within defined safety limits. We also have an AI control framework that we released earlier this summer, which similarly takes into account how we're ensuring that our systems are continuously under human control, and we manage the risks of fully autonomous model self-improvement through our Frontier Safety Framework.

Logan Graham (04:42:50):

And yes, humans and the systems that we put in place monitor at every level of the model during training, prior to release, post-release. But this is an important question because the models are clearly getting better faster, and so we think more is needed here.

Phil Wong (04:43:07):

Okay. Thank you. Thank you, Chair.

Chair (04:43:09):

Thank you so much.

Phil Wong (04:43:09):

Thank you.

Chair (04:43:10):

Council Member Zhuang.

Susan Zhuang (04:43:12):

Thank you, Chair. I have two question. The first one, what are you doing to offset the massive impact of data centers on the environment? The second one, are you tracking how inaccurate statement or decisions by your AI tools are impacting security?

Dr. Morgan Dwyer (04:43:37):

So I'll start by addressing your question on data centers and the environment. As I mentioned before, OpenAI's data centers that we build, they're called Stargate. And for each of our data centers, we build them with and for communities, and the environment and the environmental impacts on communities is part of how we think through our community compacts. For every data center, we have released a community compact that details our commitments to communities, and that includes a range of things like paying our own way on energy as well as community commitments to work with the local governments. But I think the key point is the community compacts are driven by local concerns, and so we want to meet the needs of the community and we work with them to do that.

Shane Cahill (04:44:38):

Council Member, in relation to data centers and the impact of the environment, thank you very much for asking that question. I know it's top of mind for a lot of people. Our sustainable infrastructure commitments are core to our philosophy around our data centers, including consumers should not be bearing the costs and paying our own way in relation to electricity. But I would like to connect you with our data center team so they can provide you with more specifics on that.

Susan Zhuang (04:45:13):

How about the one question about the how inaccurate the statement by your AI tools are impacting security? Do you guys are tracking those data?

Shane Cahill (04:45:33):

Council Member, I think in relation to inaccurate information, AIs can make mistakes, and I think that's important in terms of acknowledging that AIs can make mistakes. We disclose this, we're very transparent in relation to that in terms of our AI offerings.

Logan Graham (04:45:57):

And I can offer a perspective here that we think, and we've worked very hard this year to try to improve the world's security because we think models might, if not properly safeguarded, harm security, specifically the cybersecurity of critical infrastructure or otherwise. This year we withheld a model to be able to give beneficial access to defenders to have time to patch systems with security vulnerabilities. And I can say working with training teams and otherwise, we work to make the model better at making sure the code that it writes is more secure, for example.

Chair (04:46:35):

Thank you so much. Up next, we have Council Member Epstein, followed by Marte, followed by Santosuosso.

Harvey Epstein (04:46:42):

Thank you, Chair, and thank you for being here. I know this is a long panel. So I have a couple questions I'll ask them and hopefully you'll be able to answer for the entire four members of the panel. Can you confirm whether you think self-regulation has failed so far? And if it has failed, which I think we effectively think it has, do you think that third party audits, especially when AI tools are being used to highlight risk decisions should be regulated and whether government plays an effective role in that regulation? Second about liability. When AI violates the law, what liability do you think the company should have for legal violations, whether criminal or civil liabilities? Seems like there's some culpability that should be in place. And then the turnaround time when these violations happen, when the Hugging Face or some other violation happens, what responsibility do you have to notify the public and the impacted people?

(04:47:39)
Would you agree to some short turnaround time, whether it's 48 hours or not? And finally, we've seen a lot of records about a compilation of these violations of what's happened. Are you willing to commit to releasing the list of places where these rogue actors happened? I know you've released some letters to the EU. Will you release it to the City Council as well so we can see what's been happening in the United States and around the country?

Dr. Morgan Dwyer (04:48:10):

So in the question of self-regulation, OpenAI was proud to support the recent Super Intelligence Accords. We've also supported voluntary frameworks in the Biden-Harris administration, but we don't think voluntary frameworks are enough, and that is why we have supported regulation for frontier safety, both at the federal level and at the state level, and we'll continue to do that.

(04:48:36)
On your question regarding transparency of incidents, so OpenAI is currently investigating past potential incidents of misalignment, and if we discover those incidents, we are notifying third parties and making the results public. I'm also happy to say that we have a reporting framework now where anyone in the company can report suspected incidents of misalignment. We evaluate those incidents, remediate them, notify third parties, and make the results public. Transparency is really important here to help policymakers like you, as well as researchers and the rest of industry understand the risks and improve safety.

Harvey Epstein (04:49:28):

And can you share a list of those incidents so we have those, of ones you've already determined?

Dr. Morgan Dwyer (04:49:34):

Yes, they are all available online, and so I'm happy to follow up with the website where they're all publicly available.

Harvey Epstein (04:49:42):

I don't know who goes next, Chair, but I'm-

Chair (04:49:45):

Cahill.

Shane Cahill (04:49:46):

I'll go next. Thank you, Council Member. Thank you, Chair. In relation to your first question, Council Member, I see it differently in that sense that we're very much accountable. We're accountable, we publish our framework or scaling framework publicly, preparedness reports. We use outside expertise in relation to the accord, which we signed with our peers. We committed to partnering with independent auditors and evaluators, and we also consider that there's a considerable body of existing federal law, which also applies. In relation to incidents, we have a robust global response program in place in relation to incidents and a very important part of our overall processes, and we report incidents as required by law. In relation to public disclosure, I'm only aware of one incident over the summer, and we have a public post in relation to the details of our independent review of that.

Alice Friend (04:51:04):

Sir, as I've stated in earlier answers, we believe that AI is covered by existing regulation at both the federal and state level, but where there are gaps in existing regulation or existing law or where in particular frontier AI poses potentially new risks, we have supported regulation at the federal level and also regulations both federally and at the state level as well. On liability, we think it's important to attach accountability and responsibility to the party that is closest to the knowledge about harm and to the possible cause of harm as well. So we really see this as a value chain approach to thinking through AI liability. In many cases, existing torts already have procedures for assigning accountability depending on the particulars of a case. And then I'm happy to have the local team in New York follow up with you about our three incidents.

Logan Graham (04:52:20):

And at Anthropic, we have long pushed for two things. The first is for the industry itself to push its own way up the safety frontier. We call that the race to the top, but we've tried to do that from day one, always improving and always trying to create a gold standard so that everybody can rise together. I have personally thought that some of that has been very, very positive. However, we have to go further, and for that reason, we welcome the role of government. We have detailed proposals at the federal level with our advanced AI framework, and we've supported state level for this reason as well, including ambitious legislation in Massachusetts. On the point about liability, I'm fairly far from being a lawyer, but I can say that Anthropic's committed to following all relevant laws. And to the excellent question on how we should handle incidents, I think a couple principles are really important to me having seen some of these incidents up close.

(04:53:17)
The first is you have to triage, investigate, and disclose fast and be transparent about it. I think everybody here agrees with that. At the same time, we need to take the safety of those affected extremely seriously. In some of these incidents, disclosing certain information might put them at further harm. And so our first priority is making sure that those affected would not be further harmed, but at the same time, we need to very ambitiously and urgently disclose so that all can benefit.

Harvey Epstein (04:53:46):

Yeah, I appreciate the follow-up on the information, especially if there's some violations and the timeline of getting people inputted, and I thank the Chair for the time.

Chair (04:53:54):

Thank you so much. Up next, we have Council Member Marte followed by Santosuosso, and then Won.

Christopher Marte (04:54:01):

Thank you all for being here and staying so late, and I want to thank the speaker and Chair for hosting this hearing. I want to just get some clarity. One of the bill sponsors of the RAISE Act said that OpenAI was actually strongly against the initial draft language of the bill, and you stated that you have been supportive of the RAISE Act in Albany. So I want to know, just because it seems like you guys have been supportive of a lot of legislation based on your testimony, what specific legislation are you against in New York State or on a federal level?

Dr. Morgan Dwyer (04:54:39):

So thank you for the question. OpenAI worked with other companies on the New York RAISE Act, and we do support the New York RAISE Act, which passed. We also, as I've mentioned, supported legislation that actually goes a step beyond the New York RAISE Act. For example, in Illinois, that requires independent third-party audits of safety frameworks.

Christopher Marte (04:55:06):

Are there any pieces of legislation, and I guess this is for everyone, that you are against on the state level or federal level?

Shane Cahill (04:55:17):

I go next. Council Member, how I think about it generally is the importance of ensuring that we have a robust uniform federal standard. I think I mentioned earlier in the day that AI is transcontinental, it is inherently interstate, so it is important that there is a robust uniform federal standard in relation to how AI is governed.

Alice Friend (04:55:47):

I think we would align ourselves with those comments, sir. I think the most important thing for us to focus on is getting a strong federal framework, particularly around frontier AI, and also working through an overall regulatory framework that's going to ensure AI safety and also ensure that we can deploy and leverage AI across the entire country.

Logan Graham (04:56:13):

Yeah. And likewise, I don't know what our position is there exactly. What I do know is that we have outlined and supported our specific federal legislation proposals. We think a core part of this, for example, needs to involve independent evaluators, and we are longstanding supporters of the role of government here.

Chair (04:56:37):

Thank you all so much. Up next, we have Council Member Santosuoso, Won, and then Hanif.

Kayla Santosuosso (04:56:45):

Thank you, Chair. I primarily have questions for just Mr. Graham and for OpenAI as well. This morning, we heard testimony from a former Anthropic employee that based on his time in the company, he believes that it is more likely than not that misaligned AI will lead to the, quote, unquote, "total extinction of humanity." Another whistleblower who testified this morning gave this a one in three chance. Mr. Graham, if I understand it, you are part of the red team, which is tasked with identifying and addressing the riskiest capabilities of AI. So my question for you is how many people are on your team?

Logan Graham (04:57:28):

Current estimates, about 25 just on my team that we have. I will say we have a number of teams that work on similarly catastrophic risks in various roles, number into the hundreds at Anthropic.

Kayla Santosuosso (04:57:39):

And how many people work for Anthropic overall?

Logan Graham (04:57:43):

My current understanding is maybe a bit more than 5,000.

Kayla Santosuosso (04:57:49):

So 25 people are working on the riskiest forms of AI in a company that has 5,000 employees dedicated to advancing just the models without regard for safety or for that level of risk?

Logan Graham (04:58:02):

In reality there, if you look at all the roles focused on catastrophic risks, my personal estimate would be likely several hundred at least. This is distributed across our safeguards team that focuses on ensuring that the models or any misuse for catastrophic risks does not happen. Our alignment research team that focuses on notions of loss of control, for example, and between them, at least several hundred.

Kayla Santosuosso (04:58:28):

And do you feel that is sufficient or do you feel that you need to dedicate more time and resources and people to the riskiest capabilities of AI given the level of risk?

Logan Graham (04:58:39):

Yeah, our view is that we put a lot of resources into this and this is what we're known for, but at the same time, we need to continue doing more. This is a part of Anthropic that continues to grow quite substantially, especially as the models become more capable.

Kayla Santosuosso (04:58:53):

And I don't mean to cut you off, but I just... I only have so much time-

Logan Graham (04:58:55):

Yeah.

Kayla Santosuosso (04:58:55):

... so I want to ask the same question of OpenAI. How many people on your team are dedicated to addressing and identifying the riskiest capabilities of AI versus the number of employees in your company overall? And do you find that sufficient?

Dr. Morgan Dwyer (04:59:09):

So I lead the policy team, but I'm happy to get back to you on numbers of people in the overall company as well as in our safety teams. But at OpenAI, we don't believe that you should just rely on our safety teams and our evaluators.

Kayla Santosuosso (04:59:27):

I'm sorry. Again, I'm sorry to cut you off. I just only have so much time. Can you tell me how many people in your company are currently working to address the risk of the potential extinction of humanity?

Dr. Morgan Dwyer (04:59:43):

As I said, I lead the policy team, so I don't have that number, but we not only have teams that are -

Kayla Santosuosso (04:59:49):

Okay. Thank you. That's okay. Thank you so much. I appreciate it.

Chair (04:59:52):

All right. Thank you so much. Up next, we have Council Member Won, followed by Hanif, followed by Aviles, followed by Gutierrez.

Julie Won (05:00:02):

Thank you so much. This is for all panelists. What is the exact failure rate or benchmark threshold that would cause you to halt the deployment of a new model? And if your model successfully generates a bioweapon design 5% of the time during internal testing, do you still release it? And then I have a separate question. Will you commit today to providing exact redacted logs of the prompts that successfully jailbroke your models by biosecurity filters during your internal testing?

Dr. Morgan Dwyer (05:00:33):

So to your question on statistics or probabilities, I don't have a specific number, but what I can say is that no level of catastrophic risk is remotely acceptable, and we don't believe that we should be training models unless we can make an extremely strong case that we can keep them under human control.

Shane Cahill (05:00:58):

Council Member, I would just note that we are committed to building AI safely, and we have laid out in detail how we approach this in our scaling framework and in our preparedness reports. In relation to further detail, I would need to get back to you on specifics.

Julie Won (05:01:19):

For the other panelists?

Alice Friend (05:01:21):

Yes, ma'am. I don't have a specific number for failure rate that would cause us to make a non-launch decision, although I do know that we aim for safety and performance standards ahead of allowing ourselves to launch. And if we're not meeting that, it's not a good enough model or product for us to release. I'm not personally aware of any biosecurity evaluations where successful jailbreaks happened. So I'm going to have to go back to the teams and ask if they've ever seen such a thing and get back to you on that.

Logan Graham (05:01:57):

Thanks. And as I mentioned earlier, I think we were essentially the first team in the industry with respect to biological capabilities, for example. And in fact, in the past we have held a model because we needed more time to assess its biological capabilities and proactively implemented safer safeguards for this reason. To the point of jailbreaks, this is a great question. One of the hard parts is sometimes you do or don't want to share a jailbreak depending on whether it would put other models at risk. And so we regularly publish our research and alignment reports with all the information that we possibly can that would be safe to do so. And we try to set the industry standard there.

Julie Won (05:02:42):

Right now, I know you're not in the room, but behind me we have the safety claims and we have all the incidents that have happened, including biosecurity, which you have heard also from Council Member Lynn Schulman, who continues to lead us as a committee chair for health and hospitals. So can you please clarify? So Anthropic has been the only one that gave me a clear answer. So for Anthropic, what is the exact failure rate and benchmark threshold? And the rest of you have not given me that answer.

Chair (05:03:08):

And then we'll conclude and move on to Council Member Hanif.

Logan Graham (05:03:13):

The answer is it's nuanced. What we do, if you would like the sort of complex answer is we detail multi hundred pages of reports, several dozen of which are usually allocated to biology every time we launch a model. You can see the exact levels of capability and the exact reasoning that we put in when we look at a number of different tests that have different, quote, unquote, "failure rates," that allow us to make that decision. I think that highlights just how much effort we put very specifically into not just biology, but cybersecurity and self-improvement and alignment as well.

Julie Won (05:03:49):

And everybody else? Because if what you claim is true, then you wouldn't have released these models that are causing these harms. But I will pass on.

Chair (05:04:00):

Council Member Won, we have to move on. Thank you so much. Council Member Hanif, followed by Council Member Aviles, followed by Council Member Gutierrez.

Shahana Hanif (05:04:06):

Thank you Chair. On February 28th of this year, 120 school children and 35 teachers were killed in an airstrike reported as the deadliest U.S. attack on civilians in 35 years. The military has stated the target was misidentified by Project Maven, which originated with Google and Amazon Web Services and later incorporated Palantir software and Anthropic's Claude.

(05:04:29)
To Mr. Graham from Anthropic, your usage policy prohibits facilitating any act of violence. What mechanism enforces that prohibition in a classified deployment and how would your company learn of a violation? And has your company ever terminated or suspended a government customer for violating its usage policy? If so, how many times?

Logan Graham (05:04:51):

First, I really appreciate this question. In my role, while I don't have the exact answers to that, I can point to our very public positions on-

Shahana Hanif (05:05:01):

Could you just share them out loud here?

Logan Graham (05:05:04):

In government we've taken very public positions against the use of, for example, domestic mass surveillance, the use of autonomous weapons or development of autonomous weapons and the detail in-

Shahana Hanif (05:05:15):

How does the company learn about that violation?

Logan Graham (05:05:17):

I'm not exactly-

Shahana Hanif (05:05:22):

And then could you also just respond to the piece about the termination of a government customer?

Logan Graham (05:05:25):

I'm not entirely sure of our process on government monitoring. I'd refer to my colleagues there.

Shahana Hanif (05:05:33):

Thanks.

Chair (05:05:36):

Thank you so much. Council Member Aviles, followed by Gutierrez to close.

Alexa Aviles (05:05:43):

Thank you so much.

Chair (05:05:44):

To clarify, to close this panel.

Alexa Aviles (05:05:47):

Oh. So I'd like to ask a quick series of questions to each of you. In this first set can you just say yes, no, and we can continue to move forward. So does each of your companies sell or license its products directly or through-

Alexa Aviles (05:06:00):

... sell or license its products directly or through intermediaries to immigration and customs enforcement or customs and border protection?

Dr. Morgan Dwyer (05:06:12):

I don't know, but I'm happy to get back to you on that.

Shane Cahill (05:06:16):

I'll get back to you on that, Council Member.

Alice Friend (05:06:20):

I'm also so sorry. I don't know, but we will get back to you.

Logan Graham (05:06:22):

Likewise.

Alexa Aviles (05:06:23):

Okay. Nobody knows, but it has been pretty documented that couple from Google and in particular OpenAI, ICE has been utilizing your technology. So if you could please provide to this Council each of those agreements, if in fact you have them with each of those agencies. Will your company commit to not using New York City resident data for law enforcement or immigration enforcement applications?

Dr. Morgan Dwyer (05:07:05):

I'm sorry, I'm going to have to get back to you on that. I work on the policy team, not with our government contracts.

Shane Cahill (05:07:13):

I'm afraid I also would need to get back to you, Council Member.

Alice Friend (05:07:18):

I have to give you the same answer, Council Member, but I'll ask the lawyers to let us know.

Alexa Aviles (05:07:24):

Do any of your companies audit downstream law enforcement use of its products?

Dr. Morgan Dwyer (05:07:33):

I don't have the answer to that. I'm happy to follow up.

Shane Cahill (05:07:36):

Council Member, I will follow up with you.

Alice Friend (05:07:38):

Same here.

Logan Graham (05:07:43):

Likewise, we can follow up.

Alexa Aviles (05:07:47):

Thank you. Council Member Gutierrez.

Jennifer Gutierrez (05:07:52):

Thank you all. I just wanted to ask on a number of questions of issues that were raised today. I feel that every single person on this panel has said safety is of the utmost importance, but I don't feel that. I don't feel that in the responses. It feels too nuanced. I would like to understand specifically in all cases, as much as you can share, how are you directly ensuring safety of individual users when there's a data breach, when there's issues of surveillance? To my colleague Council Member Shahana Hanif's questions about AI and violence, what is specifically that you can tell to New Yorkers here that New Yorkers that have signed up to testify, what is the specific safety that you are ensuring? Make me believe that it is of the utmost importance to you all. That's my one question.

Dr. Morgan Dwyer (05:08:50):

Yeah, thank you for that question. Safety is a top priority at OpenAI. We build our models to be safe throughout the entire development and deployment process. That includes removing unsafe data from training. It includes training the models to behave safely and evaluating them to behave safely across a range of risks from cyber, to bio, to child safety. Then we monitor our safeguards for any potential misuse and we enforce on our usage policies.

(05:09:27)
To your specific question of what I am personally doing, I am not on the safety team. I lead our policy team, and I'm also a longtime public servant. I share your concerns about safety, and I think there's an important role for governments to play. That's why I am proud that my team is

‍

working with governments to support regulations both at the state level and at the federal level because we have strong safety practices, but we should also be held accountable for them.

Shane Cahill (05:10:02):

Council Member, thank you very much for this question and overall thank you for deepening the conversation on this and other important topics. I would just reiterate that Meta is committed to developing and deploying our AI offerings safely. That is across the board, both in terms of our models and also our systems, and then our usage policies. So we cover the entire spectrum in terms of our AI offerings.

Alice Friend (05:10:34):

Ma'am, at Google, we have been committed to not just the safety of our users, but the safety and security of the open web itself for over a quarter of a century now. Through our own experiences in our search platform, through everyday tools that users rely on like Gmail, like YouTube, security and safety is incredibly important to us because quite frankly, if people did not trust our platforms and our tools, they would not use them and we would be out of business.

(05:11:06)
For us, safety is a critical business imperative. It's also an imperative as part of being interested and committed to an internet where people can get information that is useful to them, that can help them live better lives. Finally, we invest in the safety of our tools so that we can deploy them to solve some of the world's biggest challenges, everything from natural disasters, warning people ahead of time about floods and fires, to breakthroughs in diseases, to unlocking all of the world's known proteins so that we can someday cure all disease. To us, safety is just a part of this broader mission to use technology and to use AI in particular to make people's lives better.

Logan Graham (05:12:03):

If I can share a personal example of this, I joined Anthropic when we fit around two lunch tables, and the reason I did was because these were the people that I saw were taking it most seriously, that the most important component of getting this technology right was making it safe. I can say that, but let me demonstrate it. From its outset, we are a public benefit corporation legally, so we are legally obligated to weigh the mission of safe AI, not just profit. At every step of the way, frequently at meaningful cost to ourselves, we have pioneered or tried to pioneer the science of safety, everything from training itself, the fundamental research came from us, the evaluations, the pre-deployment testing regime, the monitoring and control, and just this year withholding our most frontier model at the time at great cost in order to deploy with defenders to ensure the world is safe.

(05:12:59)
This is literally our DNA. This is why I'm here. This is why my team and I wake up every morning. I could tell you for a long time about all the other parts of the stack, but I hope that resonates.

Julie Menin (05:13:15):

Okay. I'm going to thank this panel for testifying. The Council still has many questions that we feel we did not get answers to today. We will be sending each of the companies a list of these questions that we would like answers back in writing, but I thank the companies for being here today, answering the members' questions, and thanks to the public for their patience.

(05:13:41)
We're now going to transition to the next panel, which is the city administration. We'll call on them right now. Thank you.

Samuel Levine (05:13:51):

Thank you.

Carmen De La Rosa (05:13:56):

Okay. Please remove them from the chamber. Thank you.

(05:13:59)
Okay. Now we will move on to hear from the administration, and today we will hear from Sarah Milstein, Deputy Commissioner of Strategic Advisory Services at OTI, CJ Dixon, Head of the New York City Cyber Command, Benjamin Krakauer, First Deputy Commissioner of New York City Emergency Management Department, and Sam Levine, Commissioner of the New York City Department of Consumer and Worker Protection.

Speaker 9 (05:14:44):

Thank you, Chair. Please raise your right hands. Thank you. Do you swear or affirm to tell the truth and respond honestly to Council Member questions?

Samuel Levine (05:14:58):

I do.

Speaker 9 (05:14:58):

Commissioner Sarah Milstein?

Sarah Milstein (05:15:02):

Yes.

Speaker 9 (05:15:03):

Thank you. Head of Cyber Command, CJ Dixon?

CJ Dixon (05:15:06):

Yes.

Speaker 9 (05:15:07):

Thank you. Deputy Commissioner Benjamin Krakauer? Thank you. I just want to acknowledge that it was yes. And Commissioner Samuel Levine?

Samuel Levine (05:15:23):

Yes.

Speaker 9 (05:15:23):

Thank you very much. You can begin with your testimony.

Samuel Levine (05:15:25):

And Deputy Commissioner Carlos Ortiz.

Speaker 9 (05:15:32):

And I apologize, and Deputy Commissioner Carlos Ortiz.

Carlos Ortiz (05:15:36):

I do.

Speaker 9 (05:15:37):

Thank you. You may begin.

Sarah Milstein (05:15:39):

Great. Good morning, Speaker Menin, Chair De La Rosa, and Council Members. My name is Sarah Milstein and I'm the Deputy Commissioner for Strategic Advisory Services for the Office of Technology and Innovation, OTI. I'm joined here today by my colleague, CJ Dixon, OTI's Deputy Commissioner of New York City Cyber Command and New York City's Chief Information Security Officer. I'm also joined by Samuel Levine, Commissioner of the Department of Consumer Affairs and Worker Protection, DCWP. Carlos Ortiz, DCWP's Chief of Staff and Deputy Commissioner for External Affairs, and Benjamin Krakauer, First Deputy Commissioner for New York City Emergency Management, NYCEM.

(05:16:23)
In my role at OTI, I oversee both the Office of Algorithmic Accountability, OAA, and New York City Cyber Command. We appreciate that the Council is holding this timely hearing about the risks of AI technology. Thank you, Speaker, for getting representatives of the companies that develop, deploy, and sell AI tools to the general public to speak to the capabilities, limits, and risks associated with these systems at this hearing.

(05:16:51)
As a representative of OTI, I'm here today to provide information to the Committee of the Whole about how we serve the city's technology and cyber defense needs, and to address the proposed legislation that potentially impacts the administration. For those unfamiliar with our work, OTI's core mission is to use technology, data, and design to make the city work better for New Yorkers. We achieve this through a wide range of digital products, infrastructure, data systems, and shared expertise. In other words, we use technology to help agencies make every New Yorker's experience of city government better.

(05:17:29)
For our discussion today, we can speak to the work we're doing around agency use of algorithmic tools and our cybersecurity program. To touch briefly on the AI arm of OTI, I'm pleased to share that the Office of Algorithmic Accountability, OAA, has been formally established and six new positions have been created in the FY27 adopted budget to staff it up. The hiring process for those roles is actively underway.

(05:17:56)
The OAA's duties include analyzing algorithmic tools submitted by agencies to determine whether there's risk that the proposed tool could result in discriminatory decision-making, conducting and publicly reporting on pre-deployment assessments, creating and maintaining a public-facing platform for submission of comments, establishing a protocol with the Department of Investigation for receiving complaints from the public, promulgating rules, establishing basic compliance standards that all agencies must meet, and developing, procuring, deploying and using public impacting artificial intelligence, and reporting the results of pre-deployment assessments and audits conducted by the office.

(05:18:38)
Overall, the office is progressing as planned and we remain focused on building the capacity needed to carry out this work effectively. I will now turn to the legislation on today's docket that would impact OTI. Introduction 161 of 2026 would amend annual reporting on algorithmic tools to include their impact on city employment with a focus on potential changes to funded agency positions, salaries, and duties. OTI is currently undertaking a study on the impact of algorithmic tools on municipal employees pursuant to Local Law 25 of 2026.

(05:19:15)
This study will provide insights into the extent to which algorithmic tools, including artificial intelligence, impact city employees and the administration of their duties, including their hiring and work functions. While we agree that it is important to examine the impact of AI on our workforce, the bill as written would not produce new insights beyond those in the larger, more expansive directive of Local Law 25.

(05:19:39)
The next three bills involve New York City Cyber Command. This office plays a vital role in protecting and defending the city and its residents from the impacts of cyber attacks. On a day-to-day basis, we provide 24/7 security services and assist agencies in bolstering their cyber maturity. We work collaboratively with agency partners as well as state, federal, and private entities to safeguard the essential services and data New Yorkers depend on daily. Our core mission is to make New York City the most cyber resilient city in the world, and we take this extremely seriously.

(05:20:13)
New York City is a target for cyber attacks with a technology landscape that is unparalleled among other cities and states. This requires a unified comprehensive defense against constant cyber threats. Our key duties include setting information security policies and standards for the city, directing the city's citywide cyber defense and incident response, deploying defensive technical and administrative controls, and providing guidance to City Hall and agencies on cyber defense.

(05:20:42)
In my fairly new role at OTI, it is a privilege to work with our staff and our agency partners in furtherance of this critical mission. New York City Cyber Command's alignment within OTI has placed the team in a strong position to monitor and respond to wide-ranging cyber threats. Cybersecurity is continuous work. In my role, I'm confident we can continue to adapt to a constantly evolving threat landscape. Simply put, New York City Cyber Command has a 24/7 apparatus in place to defend the city systems from malicious attacks regardless of the origin.

(05:21:13)
With that in mind, pre-considered introduction of 2026 to 602 would make it unlawful to market offer for sale, sell or deploy an artificial intelligence model in the New York City... The bill would require the director of the Office of Cyber Command to promulgate rules regarding what the third-party validation assessments, certifications and disclosure would entail and the qualifications for third-party validators. To be clear, Cyber Command's core mission is to defend the city of New York's infrastructure from cyber attacks. We are not subject matter experts on the qualifications for an entity to be considered a third-party validator.

(05:21:59)
Further, neither OTI nor Cyber Command have experience regulating the private sector in the way that this legislation would require, and neither would be the best choice to lead this regulatory regime for consumer products. We defer to DCWP to speak about the private sector policy and enforcement piece. To that end, DCWP supports the intent of this legislation. They recommend including robust record-keeping... Advocates and sister agencies that the administration is not certain about the availability or ability of such businesses. We look forward to hearing from those stakeholders today, including on whether initiatives like this one could help spur a market for such services.

(05:22:49)
Pre-considered introduction of 2026 to 601 would require the Office of Cyber Command to establish standards and procedures for contractors to identify the occurrence of a reportable AI safety incident. To take a step back, I'd like to lay out how AI risk and incidents are categorized according to the National Institute for Standards and Technology, NEST. Under AI under attack, AI cybersecurity incidents are traditional cybersecurity compromises where the AI system is the target, for example, data poisoning or jailbreaks.

(05:23:22)
Misuse or malfunction, AI-induced incidents, would be harms resulting from the use or failure of AI aside from a cyber compromise. In this category, the AI system itself behaves exactly as it was built or trained, but the real world outcome causes harm. These incidents are not cyber attacks. We understand the Council's intent here given the publicized instances of AI systems operating outside the bounds of their intended use. As I noted earlier, the risk landscape is constantly evolving and we are continuing to evolve our strategies to keep the city's infrastructure safe, but not all threats related to AI systems are necessarily cyber attacks, and the legislation as written does not address that.

(05:24:06)
Cyber Command would be a critical stakeholder in this discussion, but it is important to emphasize that we need to work with our state and federal partners to address these issues holistically. I also want to provide further context on breaches of security generally. Agency disclosure of a breach of security in any form is governed by Section 10-502 of the administrative code. There are extensive protocols for inter-agency coordination in the event of any breach of security. These protocols are aligned with the New York State Stop Hacks and Improve Electronic Data Security Shield Act. Current law policies and protocols are in place for incidents described in the legislation.

(05:24:49)
Further, the threshold of 24-hour public notice is inconsistent with current law and would compromise the city's investigation of a cyber incident. Pre-considered introduction of 2026 to 606 would require the Office of Cyber Command, in coordination with NYCEM, to develop or update an emergency response plan concerning AI system-related threats to New York City's infrastructure, operations, public health and welfare. I'd once again like to emphasize that there are laws, policies, and protocols in place for breaches in security regardless of actor. However, we are happy to discuss more broadly with Council how we already coordinate with NYCEM to coordinate and engage with partners to restore services.

(05:25:35)
Finally, I will provide DCWP's feedback on the remaining legislation that would impact the administration. Pre-considered introduction to 2026 2605 would allow any person to submit a complaint to DCWP alleging that a person... Strongly supports the intent of this bill to establish a civilian enforcement structure for AI violations, especially given widespread reporting that concerns being raised by AI companies' employees are being ignored. However, there are fiscal and operational concerns with the volume of complaints that the agency would receive and the resources and expertise required to handle each individual complaint.

(05:26:24)
Therefore, the administration believes it would be important to coordinate closely with mission-aligned enforcement agencies at the state level. The New York State Attorney General just recently announced its secure whistleblower portal for New Yorkers to report unsafe and illegal conduct related to AI technology. This could be an opportunity to partner on this existing program to more effectively enforce complaints on behalf of New Yorkers. Pre-considered introduction 2026 2599 would impose requirements and restrictions on companies that provide chatbots, including requirements related to data security and privacy, the right of chatbot users to access their own data, and restrictions on how chatbot providers can use chatbot user data.

(05:27:07)
DCWP has concerns about this bill. While we support Council's goal to better regulate company's deployment of AI chatbots and believe the approach taken by this bill is sound, the implementation and enforcement of this bill's data security and privacy requirements would require a deep technical understanding and investigative ability that is outside of the agency's scope. To be clear, DCWP is committed to regulating harmful practices, including relating to chatbots that fall within the agency's investigative ability.

(05:27:38)
To that end, the administration is working on rules related to the use of AI chatbots to better regulate this space for consumers. The administration is also invested in supporting the New York Attorney General, in their efforts to reign in data abuses for which this bill may serve as a model. Pre-considered introduction of 2026 to 603 would require any advertisement that promotes an artificial intelligence AI model in the city to disclose whether such a model has undergone validation by a third party. It also would prohibit any such advertisement from including any materially false or misleading statement regarding the safety of an AI model.

(05:28:21)
DCWP supports this bill to require disclosure of third-party validation of any advertisement of an AI model. However, as mentioned above, the administration is not certain about the availability or abilities of such businesses, and we want to be clear that any advertising that uses false or misleading statements is currently prohibited under the city's consumer protection law and will be enforced with the full scope of DCWP's authority.

(05:28:47)
We look forward to working with Council to ensure the law includes effective enforcement mechanisms, and to continue addressing issues within DCWP's scope of work as it relates to AI. Thank you for the time. This panel will now take questions.

Julie Menin (05:29:01):

Great. Thank you so much for your testimony. We appreciate it. I've got a number of questions. OpenAI sent the City Council a letter on October 1st recommending that New York City better connect its existing cyber and emergency management capabilities, and I'm just reading from the letter, "With the escalation containment and recovery capabilities of frontier AI companies."

(05:29:25)
So has the city of New York this year met with OpenAI, Anthropic, or any other frontier AI company to discuss how the city would coordinate with them in the event of a serious AI-related cyber or public safety incident?

Sarah Milstein (05:29:46):

Thank you for the question. Going to defer to my colleague, CJ Dixon.

CJ Dixon (05:29:49):

Thank you. Thank you. I would like to note that New York City Cyber Command follows the NIST cybersecurity framework for all of our cyber programming. That is everything from identify, protect, detect, respond, and recover. The basic first principles in cybersecurity have not changed, even with the advent of artificial intelligence. And we have been in conversations with various frontier models about how we may integrate their tools and software to better enhance the functions that we already deliver to the city. So in reference to your question, yes, we have been in conversation with the frontier AI companies to enhance the way that we perform cybersecurity. However, those basic cybersecurity controls have functionally remained the same.

Julie Menin (05:30:30):

So you've met with OpenAI and Anthropic in particular?

CJ Dixon (05:30:33):

We have met with Anthropic. I have not met with OpenAI since coming on board on May 5th.

Julie Menin (05:30:38):

Okay. Are you planning on meeting with OpenAI?

CJ Dixon (05:30:45):

Only dependent on our needs right now. We do not know definitively if there is a valid reason for us to meet with any frontier AI company in service of our-

Julie Menin (05:30:57):

I guess I'm just concerned by the statement that nothing has changed in your protocols given that we're now dealing with a rapidly-escalating technology that as we certainly heard today, and we've been hearing now for the last couple of weeks to months, that there are serious safety concerns. I just want to get an answer in terms of what proactive steps is cybersecurity taking to meet with some of these frontier companies and ensure that our systems are safe?

CJ Dixon (05:31:26):

Acknowledged, and it does not mean that we have not changed our protocols. Some of the risks inherent with artificial intelligence are unrelated to cybersecurity. In those situations where an AI model presents a cybersecurity risk, those AI models will still exploit the exact same software vulnerabilities that are inherent in computer technology as they've always been. Our protocols have not had to change to address the fundamental issues inherent in computer technology, only the speed by which we must react in a cyber attack.

Julie Menin (05:31:59):

Okay. I am concerned by news that city and state reported on Friday that the AI Czar, Jiahao Chen, who is our Chief Technology Officer, resigned I think a week to week and a half ago, and report saying that he resigned in frustration that a lot of positions were being not hired or being held up by OMB. That relates to my second question, which is Council Member Gutierrez, I think she's still here, yes, and I passed bills last year to create the Office of Algorithmic Accountability. And so, it appears that Mr. Chen's resignation from what we're reading in the press was related to that and the fact that that office was supposed to be up and running by the city in June, but it is not up and running. In fact, in your testimony, you said you're now posting for the positions. It's now October.

Sarah Milstein (05:32:54):

Thank you for the question, Speaker. Jiahao Chen served as Director of AI and ML at OTI for two and a half years. He did important work in the previous administration to help define and understand AI use throughout the city. He's been very helpful in getting new OTI administration up to speed, and we wish him the best. We are very excited to be staffing up OAA. The law went into effect in December. I was brought in this summer to help stand up the office.

(05:33:32)
We got funding in June in the FY27 budget, and we've been actively working to hire for the roles, for the director role for OAA, and look forward to announcing something quite soon. We're really grateful to the Council for having stood up, for having helped us stand this up. I think the work is going to be excellent.

Julie Menin (05:33:53):

It just seems that this is an inopportune time for his resignation, and I am concerned that the office was under Council Member Gutierrez's bill supposed to be up and running in June. In addition, the companion bill, which was my bill, which we passed a year ago, required OTI to engage in rulemaking around this Office of Algorithmic Accountability, but OTI did no rulemaking whatsoever, so did not comply with that bill. Instead, OTI issued updated guidance, ignored the rulemaking process. There's been no proposed rule, no public hearing, no public comment period, and no adoption into the rules of the city of New York.

Sarah Milstein (05:34:37):

Thank you. Thank you for the question, Speaker. OTI is fully compliant with the law. The rulemaking piece of the law had us this year submit the initial, I don't want to say paperwork, but the initial points for our rulemaking and the actual rulemaking will happen in this fiscal year. We are also fully compliant with Local Law 35, which was brought under the office of OAA as part of the December 25th law. We've been in the process of fulfilling that report for five years. We've done it on time for five years in a row. That's the law that requires agencies to disclose their use of public impacting algorithmic tools.

(05:35:37)
We're on track now for on-time reporting for March of 2027. We're really excited actually doing that work. Very proud of it. We just last week sent out the email to all of the city agencies to kick off this reporting cycle and are holding on this Thursday the orientation meeting that gets everybody rolling.

Julie Menin (05:35:58):

Okay. I mean, just to clarify for the record, we don't believe that's in compliance at all. The office was supposed to be up and running in June. I'm sure Council Member Gutierrez will talk about her bill, but the office was not up and running in June and was supposed to do the rulemaking. When do you feel then the law department will be... You mentioned law department. When can we expect to actually see the rulemaking? This is in the March '27 deadline?

Sarah Milstein (05:36:23):

Yeah.

Julie Menin (05:36:24):

Okay. What safeguards are currently in place to prevent city employees from...

Sarah Milstein (05:38:12):

... share next year.

Julie Menin (05:38:13):

Okay. I'm going to pass it over to Chair De La Rosa. Thank you.

Carmen De La Rosa (05:38:18):

Thank you so much. Just continuing on that same question, you all testified that my legislation, my Bill 161 basically does the same thing as Local Law 25. One, we look forward to seeing the report. Local Law 25, to my knowledge, requires a one-time report that's going to come out of that study. 161 is more comprehensive and is requiring that report to be updated yearly. As this technology is evolving, in my opinion, hence why I put the bill forward, more consistent reporting is going to be needed, especially as we begin to see how the workforce is impacted.

(05:39:02)
Before I was the Technology Chair, I was the Labor Chair. We have a wonderful Labor Chair in the House, and I'm grateful to her leadership. But this is an issue that impacts not only organized labor, but I also see it as an issue where we're leading the nation really in how the workforce will react to this evolving technology. And so, is there anything that you can share with us right now on where the workforce is and what those impacts will look like? I know you're working on the study, but is there anything you can give us forthcoming?

Sarah Milstein (05:39:38):

Thank you for the question, Council Member.

(05:39:39)
... part about determining how we even define impact. It's a pretty broad term and could mean many different things. We're in the phase of determining that now so that we're able to produce a report that's really meaningful for city workers. We certainly support the intent-

Sarah Milstein (05:40:00):

We certainly support the intent of your bill and I would be interested in further conversation about the annual nature of the reporting.

Carmen De La Rosa (05:40:12):

I appreciate that. Some of the information that we're looking for, for example, is I think an important question. How many funded agency positions, for example, will be eliminated due to the use of these tools? The agency vacancies has been something that this council has really been looking at, especially as we look at civil service reform across the board and bringing people into municipal service. So we do want to understand displacement and what that looks like for the workforce. We want to also understand reduction of hours, overtime, which this council has not been shy about, questioning the administrations, past administrations and present administrations about. We also want to know about subcontractors, right? There's a ton of city contracts that are in play right now and want to know what the impacts are.

(05:41:05)
So I look forward to continuing this conversation with you all and building on what we will see from the report of Local Law 25. I also want to say that while my bill doesn't specifically speak to worker protections, this council does believe that worker protections are important, especially as we look at that displacement and what could happen. We just questioned the companies for the better part of the day about whistleblower protections and what happens when this technology gets out of control. So we want to understand how those protections are also extended to municipal workers. Do you have anything in place right now that protects our city's workforce?

Sarah Milstein (05:41:51):

Yes. Thank you for the question. Because this is a little technical, I want to make sure I get exactly the right information, which is that the New York State Civil Service Law Section 8010 establishes a moratorium on discharge, displacement, or the transfer of existing duties and functions currently performed by employees of the New York City and the New York City school district to an artificial intelligence system until 2028. The Civil Service Law also stipulates that the use of AI shall not alter existing collective bargaining rights, terms of employment, or civil service status. Further, existing collective bargaining agreements may offer employment protections beyond 2028.

(05:42:40)
So with that law in place, we have a little bit of time and we really appreciate the intent of this law and the fact that it gives us in New York City a little bit of time to figure out how we understand the potential for displacements, for de-skilling, for the use of subcontractors that might be displacing other city workers and the sorts of things you were raising. So I really appreciate that question.

Carmen De La Rosa (05:43:03):

Great. So we'll continue that conversation. I also want to give you a preview. I have a bill that creates a civil service title for AI within our city agencies. And one of the things that I'm curious about is this inter-agency communication around AI. Can you speak to us, where are you right now when it comes to each of the city agencies and evaluating where the agencies are in terms of the use of AI internally?

Sarah Milstein (05:43:30):

Yes, thank you for the question. So one of the privileges that we have at OTI as the agency that runs the reporting for Local Law 35 is that we learn from agencies throughout the city how they are using algorithmic tools that have direct public impact. And in the process of collecting that data, we have a fair amount of contact with agencies to be able to learn more and to establish relationships with them so that we can also serve as advisors to them and understand their challenges as this technology unfolds. In the last cycle last year, we had 56 agencies participating.

Carmen De La Rosa (05:44:14):

Our first hearing as technology chair was around surveillance. And one of the things that we pretty much grilled these companies about was about self-regulation. And I think from the tone and tenure of this council, we don't believe in self-regulation. However, we've given the grace to our city agencies to self-report the use of AI. I want to ask you, and I understand that OTI is not an agency that's going to impose penalties on other agencies for not reporting, but there is a specific concern that my colleagues and I have around self-reporting, especially when it comes to the NYPD's reporting of surveillance technologies.

(05:44:53)
This council has had many hearings on that. I wonder under the Office of Algorithmic Accountability, what accountability tools will we put in place to make sure that we are properly regulating the use of surveillance technology in the NYPD and other technology? This council held a hearing just in June around the Department of Education and the use of AI. So what are some of those tools that we can look forward to seeing?

Sarah Milstein (05:45:22):

Yeah, thank you for that question, council member. So in advance of having full-time staff at OAA, we have been doing research to understand some of the types of risk assessment and risk management that organizations like ours can do in a situation where self-reporting is what we have been relying on. We're a little bit early to say how we would implement that in the city, but we are very actively hiring for a director who understands that set of problems and can help us figure out how we come up with effective risk assessment and management that includes a view into city agencies, perhaps beyond self-reporting.

Carmen De La Rosa (05:46:11):

Thank you for that answer. And of course we will continue that conversation.

Sarah Milstein (05:46:15):

Absolutely.

Carmen De La Rosa (05:46:16):

I did want to ask you, how prepared would you say we are for enterprise security system for autonomous AI-driven attacks, not just attacks by human, but AI autonomous attacks? How prepared do you all feel we are as a city?

Sarah Milstein (05:46:33):

Yeah, thank you for the question. I'll let CJ Dixon answer that.

CJ Dixon (05:46:37):

And that is a great question, and I will acknowledge that this is a very dynamic environment. It is always changing. It's just the nature of technology. New York City Cyber Command, however, provides 24/7 detection and response capabilities through our 24/7 security operations center. We have provided that service to the city since the establishment of New York State Cyber Command. We provide that service whether or not the attacker is human or an artificial intelligence-based attacker. That attacker would still attack the exact same vulnerabilities in the system and therefore we would still respond functionally in the same manner. We would just have to do it faster. We continue to evolve with the technology and we will continue to do so with the best of our ability as the technology continues to evolve.

Carmen De La Rosa (05:47:21):

The speaker, rightfully so, in my opinion, asked the companies about the possibility of a kill switch and where that kill switch should live. Do you have any opinions if the kill switch should live in Cyber Command?

CJ Dixon (05:47:34):

I agree in principle with the idea of a kill switch. I will say there are some technical barriers that would prevent a kill switch as conceptualized living in any agency within New York City, whether that is New York City Cyber Command, OTI, or anywhere else. The reason being is the technical reality for these models is they are deployed on distributed systems. On distributed architecture in order to truly with a singular button with a kill switch or anything of that concept for that to actually work functionally, we would need to be able to coordinate across multiple stakeholders that are not actually regionally co-located to be able to turn off everything at the exact same time. New York City Cyber Command nor OTI does not have the authorities or the technical capability to do that.

(05:48:27)
And this runs us up against a similar challenge that we've had with other kill switch bills as it relates to computer technology in general. As this technology gets more distributed, it gets harder and harder for any singular solitary entity to turn it off specifically. That is not to say that there's not technical means by which a group of entities with the legal authority to do so could not disconnect a given model from a given function. But in this particular case, we agree on principle, but it would not be able to be implemented at New York State Cyber Command in practice, not with the technical barriers that are in place.

Carmen De La Rosa (05:49:05):

Okay. I'm sure there'll be more on that. Let's see. In your opinion, should AI control be a recognized cybersecurity specialty? If so, what should be the training and curriculum included in that?

CJ Dixon (05:49:25):

I do not believe every function related to artificial intelligence is necessarily going to be a cybersecurity specific challenge. There are some intersections between artificial intelligence and cybersecurity as a particular domain. And when those two domains interact, that is where certain things should fall within Cyber Command and a cybersecurity professional's purview. And that is any instance of a cyber attack or cybersecurity, regardless of if the perpetrator is a human or an artificial intelligence.

Julie Menin (05:49:59):

I just want to ask one follow-up. How many people are working in Cyber Command right now?

CJ Dixon (05:50:04):

121.

Julie Menin (05:50:05):

And how many vacant positions do you have?

CJ Dixon (05:50:08):

I will need to go back and find that exact number for you, speaker.

Julie Menin (05:50:12):

Okay. Thank you. If you could please provide that.

CJ Dixon (05:50:13):

Will do.

Julie Menin (05:50:14):

Thank you.

Carmen De La Rosa (05:50:16):

Thank you. I have a question for our DCWP commissioner and team. What types of AI misuse are you seeing that harm consumers that you're most concerned about?

Deputy Commissioner Millstein (05:50:33):

Well, thank you, council member. Thank you, Chair. And it's great to have the opportunity to be here. We're concerned about a wide range of misuse, whether it's people using voice cloning technology that these AI companies make fully available to scam our seniors, whether it's grocery stores using AI technology to fix prices or to personalize prices, something that the speaker has introduced a bill to prohibit. We're seeing widespread misuse of these tools. And the other thing we're seeing across the board is an attitude by these AI companies that they bear no responsibility for the downstream consequences.

(05:51:06)
I have to just say, Chair, I was struck by the final answer I heard by the witness for OpenAI who when asked a basic question about AI safety, responded that she works in policy, not safety. How are you running a company like OpenAI set to go public introducing trillion dollar tools and you don't have safety as part of your policy division? Deeply disheartened by what we heard at the hearing earlier today.

Carmen De La Rosa (05:51:30):

Absolutely. You should have heard their first answer. It went something like, "I don't know."

Deputy Commissioner Millstein (05:51:36):

There were a lot of I don't knows, and on behalf of the admin, we hope to give you more fulsome answers.

Carmen De La Rosa (05:51:40):

Thank you. And we look forward to engaging with you in that more broad conversation as well. In your opinion, is DCWP sufficiently staffed to combat this AI misuse? And would adding, in your opinion, a private right of action strengthen the ability to enforce against violators?

Deputy Commissioner Millstein (05:51:58):

Thank you, Chair. I'll be candid. I feel that even as under the Mamdani administration, we are adding to our ranks. I believe we are capable of taking on many of the misuses of AI, whether that's DoorDash using algorithms to underpay its workers, something we remedied in the largest labor enforcement action in history. Whether it's companies using AI to harm consumers through surveillance pricing, we're strongly supporting the speaker's bill on this. I think we have strong tools.

(05:52:26)
That said, no enforcement agency, and I've worked at the state, federal, and municipal level, will ever have the resources to take on every possible misuse of this technology. That is why, Chair, I would strongly support a private right of action as contemplated by a number of these bills to give ordinary people, workers, and businesses the opportunity to hold these companies accountable. I can guarantee you though these companies, as soon as the city does that, are going to run to Washington asking for preemption. Regardless of what they might be saying at this hearing, what really speaks is where their lobbying dollars are going, and that is to DC Congress asking to hit-

Carmen De La Rosa (05:53:14):

... and to my colleagues, Council Member Gutierrez, followed by Aldebol, followed by Maloney.

Jennifer Gutierrez (05:53:21):

Thank you. Good to see everyone. My first question is for Deputy Commissioner. Good to see you. Going off of the speaker's line of questioning regarding the Office of Algorithmic Accountability, can you share... I know you said you're excited about this report, you're setting up an orientation meeting. It feels like not a lot of time. Before the report is scheduled to be released, what can you share about the cadence of how often you're going to be able to meet? Do you expect the report to be released on time? This is not a reflection of you, but I really felt like the previous administration under the previous OTI leadership was delayed in many things. And we certainly don't want compliance to be one of those things.

(05:54:11)
So if you can just share with me a little bit about the cadence, how many people... You said the funding you got in June, how many people will the office be able to employ where you are in that process currently? Oh, okay. That was it for you. I had a question for [inaudible 05:54:25], but I can come back.

Carmen De La Rosa (05:54:25):

Go ahead, go ahead.

Jennifer Gutierrez (05:54:26):

Okay. And then for DCWP, I just wanted to ask if you can share a little bit about how the implementation of Local Law 144 is going, the automated deployment decision tools. Just wanted to see how the implementation of that law is going, and that's it. Fair enough. Thank you.

Deputy Commissioner Millstein (05:54:46):

Well, thank you, Council Member. Let me start by 144. I think this was a really well-intentioned bill to regulate the use of automated decision-making systems for hiring. I think it does have some flaw though, in that it requires companies that use AI systems for hiring to conduct audits. It doesn't actually require that those audits come up clean. That's really a civil rights question. That is why our administration put out a policy statement last week on behalf of DCWP, Commission on Human Rights, and Taxi and Limousine, making clear that existing laws apply. But I do want to circle back to a broader point that this hearing reveals, which is that bias in decision making produced by AI systems is a very real concern you're addressing. These companies would like an exemption from the law. The companies that testified earlier want to assert that if decisions are made in a black box, nobody can be held accountable for it.

(05:55:37)
I applaud this council's effort to actually impute responsibility for these harms to the companies making billions of dollars on it. And we would be very happy to work with the council to work on a revised, expanded, strengthened automated decision-making bill that places the responsibility to remove bias from hiring where it belongs.

Jennifer Gutierrez (05:56:00):

Are there instances where the harm is happening amongst the city agencies using these tools?

Deputy Commissioner Millstein (05:56:07):

I don't believe that. I would defer to OTI and to those in hiring. I don't believe that the city is using AI tools to sort resumes, but I would defer to others in the admin. I can tell you in my agency, we have people reviewing applications just as starting in January when delivery workers get deactivated, we have people reviewing that. When consumers file complaints, we have people reviewing it. We are a big believer in our administration that the people of New York should be served by the people of the city government.

Jennifer Gutierrez (05:56:37):

Thank you. Part of the package of bills that the Speaker mentioned that we passed last December on Christmas was to get the city and to get OTI to report on those AI tools that every city agency is reporting on. So we'll know soon enough, but please, Deputy Commissioner, thank you.

Sarah Milstein (05:56:54):

Yeah, thank you for the question, Council Member. So I think there's a couple of reports we're talking about here. I want to give a little bit of context. Local Law 35 is the report that requires agencies to tell us about the algorithmic tools they're using that have public impact. And that report we have delivered on time every year for the past five years. The process work kicked off last week and we'll be collecting data over the course of the next few months with the plan to publish it in March of 2027. We have all the indications that that will come in on time.

Jennifer Gutierrez (05:57:42):

... report required by Intro 199. So that's the package of bills from last fall.

Sarah Milstein (05:57:46):

Yeah.

Jennifer Gutierrez (05:57:47):

Thank you for clarifying.

Sarah Milstein (05:57:53):

The Director of OAA, which we hope to be able to announce quite soon, will be primarily responsible for the additional reporting that will be required in March of 2027. And in part, because we have this good experience internally understanding process with Local Law 35, we think we're in a good position to move quickly on the additional reporting that will be due in March of 2027.

Jennifer Gutierrez (05:58:17):

Okay. And you said announcement. Do you have someone already for the role?

Sarah Milstein (05:58:24):

We will have an announcement and I hope a week or two.

Jennifer Gutierrez (05:58:26):

You'll ave an announcement about the announcement. Okay. Thank you. Thank you, Chair.

Carmen De La Rosa (05:58:29):

Thank you. We have Council Member Aldebol followed by Maloney, followed by Juan.

Ms. Aldebol (05:58:36):

Thank you, Chair and Speaker Menin. So you said the hiring process for the six new positions that were created in the adopted budget are actively underway. Specifically, where are you in the process? How many people have already been hired? How many people are left to be hired? And what have been the challenges in being able to hire people quickly?

Sarah Milstein (05:59:07):

Yeah, thank you for the question, Council Member. So we hope to be announcing a director for the office quite soon in the next week or two. And we are in the process of defining the additional roles so that they can be brought on quite quickly. We certainly are challenged to find people who have the right combination of AI expertise and understanding of city systems to be able to hit the ground running. That has been a little bit of a challenge. But we do have, I think bringing in a strong leader is going to help us draw good people who are going to want to do this work with us.

Ms. Aldebol (05:59:50):

If I may, Chair, part of the role is to analyze algorithmic tools submitted by the agencies to determine whether there's risk that the proposal could result in discriminatory decision making. What is your office doing or thinking about in terms of protecting the city's workforce as AI develops and evolves and you're kind of like the gatekeeper AI?

Sarah Milstein (06:00:27):

Yeah. Yeah, thank you for the question. So in parallel with some of the risk assessment that we can do of the software, we are doing the research associated with Local Law 25, which has us researching how algorithmic tools and automated employment decision tools might be impacting city workers. And I believe that we should have results from that in 2027 and we'll have a much better sense of the landscape of how workers in the city are impacted.

Ms. Aldebol (06:01:05):

Okay, thank you.

Carmen De La Rosa (06:01:06):

Thank you. Council Member Maloney, followed by Juan, followed by Brewer.

Virginia Maloney (06:01:12):

Thank you, Chair. As we all know, generative AI technology is changing how we communicate, work, and how businesses operate, and the same could be said of our government offices, both how we work and operate, either officially or unofficially. So I want to know how New York City agencies are adapting to the new reality. The first on the opportunity side, there are plenty of examples of government wins of adopting useful technologies for the public good. In Connecticut, they have real-time translation in 80 languages for these kinds of public meetings to increase accessibility. In California, they automatically check permit applications against 18,000 pages of building code in order to speed up reviews.

(06:02:01)
So my first question is what is our equivalent win in New York? And if we don't have one yet, what's the plan to identify those opportunities? And the second question is around oversight. If I may wrap up, OTI published generative AI guidance for agencies last December. So as we're exploring these opportunities, is that guidance binding or is it advise? What happens if agencies ignore that guidance? Has OTI been prescriptive about a list of generative AI or agentic AI tools that have been reviewed and approved for city use that are use cases that the city officially supports? And then how are we thinking about procurement when these models are constantly iterating and changing every few months and when every few days truly, and when new technologies are being introduced? Thank you.

Sarah Milstein (06:02:57):

Thank you for those questions, Council Member. I'm so glad you brought up the question about wins because we're really interested in both effective and responsible use of AI, and I think effective would cover the wins. I don't have a perfect list here, and I'd like to follow up with that because we'd really like to represent the agency as well. In terms of tools that we have approved, broadly, there are two sets of tools that OTI approves centrally, Microsoft Office Suite and other Microsoft tools, and that includes their Copilot chat and some of their other tools have AI features built in. And we also have a central license for Adobe Creative Cloud, and many of those tools have AI features built in.

(06:03:53)
Other software tools that are used by agencies are reviewed for the most part on a one-off basis by OTI, and we are still determining the best way to move forward with that process to make sure that we are identifying and managing risk appropriately. I think your question about procurement is an excellent one, and part of what we have started to research ahead of having staff at OAA, we've started to talk with various experts in risk management to understand some of the ways that we might think about risk in an ongoing way, when traditionally all kinds of procurement has... There's a gate at the beginning for various concerns, and then it's rolling. I think you're right, that's not appropriate for this situation, and we should have more to discuss on that in the coming months, but it's an active question that we have as well.

Carmen De La Rosa (06:04:54):

Thank you so much. Council Member Juan, followed by Hanks, followed by Brewer.

Julie Won (06:05:01):

Thank you so much, Chair de la Rosa. So for the panel, what I have questions about is building off of what Council Member Maloney just said, the agencies are allowed to currently use Microsoft products and also Adobe, but it's clear to me and the public that they are using other AI tools. So not just the passive tools like using Zoom to transcribe their notes and for follow-ups. But in addition to that, they're using ChatGPT, they're using Claude, they're using Nano Banana Pro because we're seeing it for agencies like HPD, DOE, DEP, they're creating flyers for public consumption. They're using it for their public emails, they're using it for public messaging.

(06:05:40)
So what are you actually doing? Because I want to know what the public policy is from the mayor on how the agencies are using AI and how you are regulating it internally as well. And also I would like to build off of that for city contracts, what are you doing currently for data privacy writers and city contracts for all procurement of AI companies for making sure that our constituent data is not being used to train their AI models? And is there a clause at all or a rider in the city contracts, especially with the Copilot since that's the only real one that you have and people are just using their own personal accounts or free accounts for everything else that they're currently using for their day-to-day jobs?

Sarah Milstein (06:06:21):

Thank you for the question, Council Member. So let me first address the question about the AI rider. We shared that with general councils across the city this summer with an updated AI rider, and I want to just make sure I've got the right language here, so I'm going to pull that up. Let's see.

Julie Won (06:06:42):

Yeah, because my privacy concerns are not just for the contracts that exist, but it is for the free willing use of agency staff that are using non-city enterprise licensed AI.

Sarah Milstein (06:06:57):

Yeah. Yeah. So I'll first address the rider and then we'll talk about the shadow use. So the rider, as I said, was distributed to agencies citywide this summer, and it's intended to mitigate risks and apply the city's policies and standards to AI products and features. It's available for all city software contracts, and our legal team recommends that agencies use it even where no AI component is currently contemplated. The rider includes terms relating to intellectual property, security, how the city's data may be used, and privacy. And so that is now active and in use, and I think that with also a proactive component of recommending that it's used for all manner of technology.

(06:07:43)
In terms of the shadow use, which I think is probably both at the individual and at the agency level, we are not in a technical position to monitor that. But certainly we as an agency share concerns about that. And part of what we're interested in doing is making sure that agencies have the tools that they need that are properly regulated. Microsoft Tools, for example, where data can't be shared or used to train their models. That agencies have the tools that they need to do the jobs that they have so that they are not turning to outside tools.

Julie Won (06:08:20):

So who is responsible if you aren't able to regulate shadow use of AI tools for day-to-day use, especially with constituent data, who is going to regulate that? If that's not you.

Sarah Milstein (06:08:31):

I'd like to follow up with you on that question.

Julie Won (06:08:34):

Okay.

Carmen De La Rosa (06:08:35):

Thank you, Council Member. So I know the admin has a hard stop at 5:30. We have about six more member questions, so if you all could just hang on tight, we're going to try to get through this. Members, please consolidate the questions. We have our majority whip, Council Member Hanks.

Council Member Kamillah Hanks (06:08:53):

Thank you so much, Chair. I'll be very, very brief. So you testified with all the technology that's changing rapidly, even the best can't keep up. So in your testimony, you said the administration is continuing to evolve your strategies to keep our city's infrastructure safe, but not all threats to AI systems are necessarily cyber attacks. Can you expand on that?

CJ Dixon (06:09:20):

Yes. So when looking at the way that it is currently described by the National Institute of Science and Technology, as well as some of the universities and academics who've created some of these systems, there are functionally two baskets of AI risk. There is risk related to AI when an AI is attacked as a computer system, just like any other piece of software. And then there are risks related to artificial intelligence that are truly novel to this new technology inherent in the way that these artificial intelligence models may interact with society when deployed.

(06:09:55)
That second category of risk is a function of often a how much society may trust the artificial intelligence and how reliable that artificial intelligence system may be. Those two things can run afoul of what we may expect as consumers or as a government entity completely agnostic of whether or not the system for which those AIs are deployed are actually cyber secure. So a system can be completely cyber secure, but the AI model itself and interactions with other humans in society writ large may take an action that is unexpected and therefore result in some sort of disruption agnostic of a cybersecurity incident. So that's functionally the two categories and that's a very broad breakdown of those two categories of risk.

Council Member Kamillah Hanks (06:10:41):

So I'm going to keep my question just to that. I think that we should talk offline because my legislation requires the 24-hour reporting requirement to Cyber Command in which your testimony has some issues and you talk about how we're going to push this through to federal and state and what specific role do they play in that? How can we make this better? But I will relinquish that. Thank you, Chair.

Carmen De La Rosa (06:11:04):

Thank you so much. Up next we have Brewer, followed by Jose.

Ms. Brewer (06:11:08):

Thank you very much. I know you talked about the Microsoft and the Adobe, but if an agency wants to begin using a new AI model, A, how do they go about it? Number two, does the city run these models on its own data centers or only on the ones that are on the control of vendor clouds? And then if you have a problem, like there's a criteria, what is it for testing to identify the malicious misaligned AI product? And then how much does the city spend each year on outside AI consultants? I could go on, but those are three, four questions. I have 10 pages here.

Sarah Milstein (06:11:45):

Okay. Thank you for the questions. Let's see.

Ms. Brewer (06:11:51):

The process.

Sarah Milstein (06:11:52):

Yeah. Typically, when agencies want to buy software, part of the process is discussing with OTI what they are buying and what they will be using it for. And we have a cybersecurity review process that is part of that to ensure that the software that is either going to be bought or built will be safe. And as my colleague has said, that would include cybersecurity includes the typical AI concerns. So that's process. You had-

Ms. Brewer (06:12:32):

Next question, the clouds, whose clouds are they on? Whose data centers? Where are they?

Sarah Milstein (06:12:39):

Yeah.

Ms. Brewer (06:12:40):

Are you running them or is it outside vendors?

Sarah Milstein (06:12:45):

So to the best of my knowledge, there are no city agencies running their own models, but I would like to-

Ms. Brewer (06:12:56):

So it's vendor clouds. It's vendor clouds basically. Vendor clouds. Vendor clouds.

Sarah Milstein (06:13:00):

Yes. So for example, Microsoft host software that agencies use. But I'd like to follow up after the hearing to make sure I've got the exact right information for you.

Ms. Brewer (06:13:15):

Okay. And if there's something unexpected, misaligned AI product behavior, what do you do?

Sarah Milstein (06:13:21):

That is a question for my colleague, CJ Dixon.

CJ Dixon (06:13:25):

Councilwoman, that depends on what the misaligned behavior is. If that misaligned behavior is specifically a cyber incident, we take appropriate action based on what any cyber professional may do. There are novel misalignments that are born of this technology that do have to be unpacked and we look forward to working with the council as well as our partners across New York City to understand when those misalignments do arise unrelated to existing risks that the city already deals with, how do we actually engage with those particular novel risks?

Ms. Brewer (06:13:55):

Have you had some since you started your job?

CJ Dixon (06:13:59):

None related to what Cyber Command's purview is.

Ms. Brewer (06:14:03):

What-

CJ Dixon (06:14:00):

... unrelated to what cyber command's purview is. And that is primarily cybersecurity issues. We've had no misalignments related to cybersecurity that has resulted in negative consequences for the city from an AI model very specifically.

Speaker 10 (06:14:16):

That sounds very ... I don't know what it sounds. How much outside AI consultant dollars are being spent?

Sarah Milstein (06:14:28):

Council member, could you clarify what you mean by AI consultants?

Speaker 10 (06:14:32):

Sure. Yeah. How many people are you paying, I mean, I've been doing this work a long time, so I know sort of the answer, but how much outside consultants are being paid on terms of AI? In other words, how many people are you paying to work with you on AI issues, outside vendors? Consultants?

Sarah Milstein (06:14:54):

None that I'm aware of, but I would like to follow up with you to make sure that we have accurate information.

Speaker 10 (06:14:59):

So everything to do with AI is in- house. Is that what you're saying? Everything to do in terms of strategy, thought process, future, it's all in-house?

Sarah Milstein (06:15:07):

Yes.

Speaker 10 (06:15:08):

Okay. Thank you.

Carmen De La Rosa (06:15:09):

Thank you. Council Member Osei, followed by Deputy Speaker Williams.

Chi Ossé (06:15:14):

Thank you so much. I just wanted to refer to the recent hacking situation in Australia that was proof that AI agents do have that ability to hack into our government. I'm sure you know in June, a rogue OpenAI agent hacked into an Australian government statistics portal containing private data from Australia's universal healthcare system. At this current moment, if a similar hack that happened to Australia happened here in New York, do you feel that the city and the admin has a sufficient plan to defend against the hacks and protect any sensitive data? And two, does the city currently have a responsive liaison from each of these companies to speak to in case of a hack?

CJ Dixon (06:15:58):

To the first question, yes, we do have the people, process, technology and some of the policies in place to deal with an incident similar to what happened in Australia. The reason being is even though an AI was involved, the hacking process, the attack chain, if you will, happened in the same way that if a human being were to execute that attack, at the end of the day, the underlying infrastructure, I will use air quotes here, doesn't actually care if the person at the other end of the keyboard is a human or a silicon-based entity. The attack chain still remained functionally the same.

(06:16:33)
Therefore, our team is equipped and trained very specifically to identify these indicators of compromise, identify the attack patterns, and then be able to respond accordingly at multiple points. So we are prepared to address those types of issues, and we do have points of contacts when we are working as city agencies with vendors who are under our contract to engage with third parties as they get breached or if their product is the result of a breach. So if they are under contract within the city by [inaudible 06:17:08] downtimes or when their products are involved in a breach.

Chi Ossé (06:17:12):

Thank you for that response. And in regards to my legislation on an emergency plan, and I know that you indicated that there's already a plan in case an emergency takes place. Am I correct with that assumption?

CJ Dixon (06:17:25):

Yes. So there are cyber incident response plans as well as my colleagues from NYSEM. There's also ongoing work for risk response plans in general across the board, and that is for every category of risk that the city may deal with that might disrupt city infrastructure or city services.

Chi Ossé (06:17:42):

Is that publicly available or is that shared with the council?

CJ Dixon (06:17:45):

No, that is by design. We do not want to share that publicly because if that is the more public aware that someone is of an incident response plan, the more likely they can circumvent it that that's something that you do want to keep close hold and classified.

Chi Ossé (06:17:59):

Okay. Thank you very much.

Carmen De La Rosa (06:18:00):

Thank you so much. Council Member Hani, followed by Deputy Speaker Williams.

Shahana Hanif (06:18:07):

Oh, I though the deputy speaker was going before me, but anyways.

Carmen De La Rosa (06:18:09):

I'm sorry, I messed up.

Shahana Hanif (06:18:10):

Okay, no worries. I have a question first for Deputy Commissioner Millstein. How does OTI ensure that the automated pre-screening tools and fraud detection algorithms used by the HRA do not create disparate impacts or algorithmic bias [inaudible 06:18:30] have for Commissioner Levine, the testimony indicated that DCWP supports a complaint process, but you all raised concerns about staffing and expertise. What specific resources would you need to investigate AI complaints effectively, and what protections can New Yorkers rely on while that capacity is being built?

Deputy Commissioner Millstein (06:18:59):

Sure. Well, thank you, Council Member. I can start. And I want to be clear, AI complaints can take many different flavors. If we hear from a worker who tells us they believe their pay was incorrect, maybe they didn't hit the minimum pay rate because of an algorithm, that is something we can fully address. If we have someone like Jacob Coxon come to us and say that Anthropic is developing models that could lead to catastrophic consequences, that is not something we have the capacity to do. So what we said in our testimony is the New York Attorney General already has an internet bureau set up. They've already put out a call for whistle-blowers. I believe they already have staff capable of processing these complaints. We'd be very happy to work with the council to make sure to get to the AG.

(06:19:47)
As the speaker has said, thousands of these AI employees work right here in the five boroughs. They know that these companies are making reckless decisions in pursuit of profits. We do want to make sure that these employees have a place to go, and if they come to us and it's not something we can handle, we'd want to work with the state to make sure those complaints can be addressed adequately. But

Shahana Hanif (06:20:06):

Right now, is the city working with the AG's office or is that a relationship that's not formalized?

Deputy Commissioner Millstein (06:20:12):

We have a very close relationship with the AG's office. We speak constantly.

Sarah Milstein (06:20:20):

Can I ask you to repeat the question about HRA?

Shahana Hanif (06:20:21):

Yes, absolutely. So it's basically trying to understand our automated pre-screening tools, because I understand that humans are not checking all of the applications. There's some level of automated algorithmic formula that is determining how applicants get pooled when it comes to public benefits. So I'm curious how OTI ensures that automated pre-screening tools, fraud detection algorithms used by HRA are not creating disparate impacts or bias.

Sarah Milstein (06:20:56):

Thank you for the question. We really share a concern about the bias and impacts on not only workers, but on New Yorkers. Because this is really detailed and specific though, I do want to make sure to check back with HRA and make sure I've got the details of this one correct. So we'll come back to you on that for sure.

Shahana Hanif (06:21:17):

Appreciate it.

Carmen De La Rosa (06:21:19):

Thank you so much.

Speaker 11 (06:21:20):

Council member, I just wanted to follow up on one point you had about potential resource impacts. I think on that particular issue, we had identified very preliminarily of 14 lines for approximately 1.2 million, but I-

Shahana Hanif (06:21:32):

Wait, could you repeat that one more time?

Speaker 11 (06:21:33):

14 lines for approximately 1.2 million. But again, that's a very preliminary estimate and we work on the council with the bill for a final version.

Carmen De La Rosa (06:21:42):

Thank you. Deputy Speaker Williams.

Deputy Speaker Williams (06:21:44):

Thank you, Chair. I am looking at your testimony and your comments about the chair's bill was that local law 25, which was my bill, the study is currently underway. We reached out, the compliance division of the council reached out I think twice. I know it just went into effect in January, but would be helpful to know if you have a timeline. So I know it might take time, but how much time? Because clearly I think today's hearing is evidence of the importance of really understanding AI's impact on the [inaudible 06:22:23] I know the comments we received back was just that there's no updates, but we haven't received a timeline.

Sarah Milstein (06:22:31):

Yeah, thank you for the question and thank you for the legislation. I think it's really an important study. I anticipate that we will have pieces of it over the course of 2027 and we will share updates as we have them. I think rather because this is so timely and important, we don't have to just wait till the end. We can be in partnership with you and rolling out information as we learn more.

Deputy Speaker Williams (06:22:56):

Thank you. I look forward to working with you on that.

Carmen De La Rosa (06:22:59):

Thank you. And the last question for this panel, this is from council member Savina Brooks Powers. She says, "My district is home to JFK airport and to the coastal rockaway neighborhoods that depend on emergency alerts. What might an AI-driven attack on emergency systems or major infrastructure look like? Is there currently a plan for an AI-driven attack on critical infrastructure and relevant emergency systems?" And then for NYSEM, during storms and flooding emergencies, it can be hard for New Yorkers to know what they're seeing on social media is real or AI-generated. How is NYSEM working to make their messaging clearly legitimate and to cut through the noise of AI-generated rumors?

Sarah Milstein (06:23:48):

For the question on notifications, I'll defer to my colleague, CJ Dixon.

CJ Dixon (06:23:55):

Yes. So for an AI-based attack that is specifically a cybersecurity attack, there are notification requirements that already exist under law, 72 hours for a confirmed breach, 24 hours for a breach related with extortion, and then 30 days for victim notification. So there are plans in place for incident response in the event of a cyber attack against any critical infrastructure owned by the city, and that includes if that attack is perpetrated by an artificial intelligence system.

Speaker 12 (06:24:25):

Thanks. And on the New York City Emergency Management front, I'll make two quick points. One, I think that is a real risk. I appreciate the council member raising it. It's one of the reasons that we invest very heavily in backup systems. Several months ago, a very well-known and established notification provider had a seven-hour global outage where notifications were not able to be sent out. That's something that we take very seriously, and which is why for over a decade now, New York City Emergency Management has invested in the backup system.

(06:24:56)
So as you went across the country, you saw many large jurisdictions saying to their constituents, "Sign up for this WhatsApp group or follow us on social media if you want alerts tonight." In New York City, we did not have to do that because we had a backup system that continued to work, so that disruption was averted. As far as mis-dis or malinformation generated by AI, that is a valid concern. It's why we recommend that New Yorkers follow us on our official channels, which are verified through Notify NYC. You can sign up at nyc.gov/notify. You can sign up by short code or download the Notify NYC mobile app that we operate in concert with OTI.

Carmen De La Rosa (06:25:38):

Thank you so much. Council Member Brooks-Powers wanted me to note that, for example, during the Nor-Easter, there was a video that was going around about a tornado that apparently caused a lot of confusion and chaos, and so she wanted to share that for context.

Julie Menin (06:25:55):

Okay. Thank you so much. I really want to thank this panel. We appreciate your comments on the legislation. We really look forward to working collaboratively with the administration on the various pieces of legislation and appreciate your testimony today. Thank you.

Carmen De La Rosa (06:26:12):

Thank you all for coming. I now open the hearing for public testimony. I remind members of the public that this is a formal government proceeding and that decorum shall be observed at all times. As such, members of the public shall remain silent at all times in the chamber. The witness table is reserved for people who wish to testify. No video recording or photography is allowed from the witness table. Further, members of the public may not present audio or video recordings as testimony, but may submit transcripts of such recordings to the sergeant at arms for inclusion in the hearing record.

(06:26:46)
If you wish to speak at today's hearing and you have not done so, please fill out an appearance card with the sergeant at arms and wait to be recognized. When recognized, you'll have two minutes to speak on today's hearing topic, which is examining the risk posed by artificial intelligence and proposed legislation. If you have written statement or additional written statement you wish to submit for the record, please provide a copy of that testimony to the sergeant at arms. You may also email the written testimony to testimony@council.nyc.gov or within 72 hours of this hearing. Audio and video recordings will not be accepted.

(06:27:22)
Our first panel includes Nate Soares, Dr. Julia Stoyanovich, Irman Ahmed, Jukay Hsu, Mackenzie Arnold, Nathan Sheard, and Anna Mayers. And when you speak, please identify yourself for the record, and if I messed up your name, I apologize. We're also asking folks to please remain to the clock of two minutes. Thank you. You may begin on this side of the dais and just identify yourself.

Imran Ahmed (06:28:26):

Good evening, Speaker Men and Steven members of the council. My name is Imran Ahmed. I'm the CEO and founder of the Center for Countering Digital Harm.

Carmen De La Rosa (06:28:39):

You may continue. Go ahead.

Imran Ahmed (06:28:41):

So after my colleague was murdered 10 years ago by a man radicalized in part online, I began studying the design of social media and AI platforms to understand how they generate risks and threats to real people. Today, we have a globally acclaimed team of researchers dedicated to exposing those harms and fighting for accountability. After a decade in this fight, one lesson is very clear that is really relevant to you today. These companies lie like we breathe. Their CEOs deflect, they distract, they delay, they spend hundreds of millions of dollars to avoid responsibility.

(06:29:24)
Now, how can I say that with such certainty? We do the research. Last year, our researchers found ChatGPT was willing to help a teenager plan their suicide. It wrote a personalized goodbye note to their parents. A few weeks later, they released a safer model in response to that research, so we ran the same tests again. The new model was actually worse, but it was more addictive. We tested chatbots more broadly too. 8 out of the 10 that we tested, including Meta AI, ChatGPT, would regularly help plan violent attacks, including a school shooting, a synagogue bombing, and political assassinations. One of them even signed off with, "Happy shooting."

(06:30:17)
Only one of the platforms tried to dissuade us from carrying out the attack, and that platform, Anthropic's Claude, has been designated a supply chain risk by the US federal government. Given our most sacred duty is to protect our kids online, and the most predictable harms in the internet economy have been harms to kids, it is absolutely inexplicable why these companies claim to be safe and yet are deployed so widely. We all applaud the council for holding this hearing and for your determination to create guardrails that subject online safety and accountability to legal requirements. We have attached to my testimony research and policy proposals for your consideration, and in the further effort we are at your disposal, your work on this issue may very well lead to national standards in regulating AI. Thank you.

Carmen De La Rosa (06:31:05):

Thank you so much.

Nathan Sheard (06:31:07):

Good evening speaker, co-chair De La Rosa, members of City Council. My name is Nathan Sheard. I am the managing director for advocacy at the Electronic Frontier Foundation and a Brooklyn resident. EFF has worked for 35 years to ensure that people have the freedom to use technology to create, to innovate, and to communicate, and also to ensure that technology is not used to threaten people's privacy, security, and other essential freedoms. We are optimistic about the ways that New Yorkers can use AI to be empowered, but we also urge you to take AI risks seriously. The incidents that inspired this hearing were security failures that proven practices like sandboxing and monitoring likely could have prevented or at least contained. AI agents reached systems they should not have had access to and the controls meant to restrict them were absent or inadequate. These risks can be mitigated and so can the AI-related risks that are already impacting New Yorkers every day.

(06:32:09)
First, finish what you started. As has already been noted here, the Office of Algorithmic Accountability was due in June. I'm glad to hear that it is going to be staffed. The speaker's own AI standards can't take effect without it, so staff it and require its review before any agency deploys an autonomous AI system. Second, listen to New Yorkers and protect their rights. Today's AI harms come from cameras that take a face print that you can't replace and a price tag that knows your browsing history. Ban government use of face recognition and require informed consent before anyone minds your chatbot history to engage in ad targeting or model training, and don't let AI rules become speech rules. Parodying powerful people, including the people in this room, is a longstanding New York tradition.

(06:33:02)
Third, don't lock in these incumbents. Permission to operate regimes, bounty style enforcement, and liability for what strangers do with the tool are cost that the biggest companies pay with pocket change. Researchers, open source developers, and New York startups, they can't. So you'd build a moat around the very companies you're worried about. Hold the person who causes the harm responsible, but put duties on whoever uses AI to perpetuate bias and for the city's use by open auditable tools.

(06:33:32)
As we've stated last week, these same companies signed a voluntary pledge at the White House, but promises are not laws. Make sure that when a New Yorker is harmed by a wrongful decision or a biased decision, that they are required to disclose it. Those answers should not be voluntary. Thank you.

Carmen De La Rosa (06:33:53):

Thank you.

Anna Myers (06:33:56):

Good evening, Speaker Menin and ... Nailed it. Good evening, Speaker Menin and members of the council. I'm Anna Myers, co-founder and executive director of Who Decides. We work in coalition with labor and civil society to ensure that the American people are who decides the future of AI. As has been discussed today, the OpenAI agents that hacked Hugging Face made real the threats that experts have warned us about for years, and it was not one incident. Access reported that OpenAI and Anthropic are investigating tens of thousands of cases in which their models bypass safeguards, escape sandboxes, or hijacked websites. These models are only getting more capable.

(06:34:43)
As you heard this morning, the people [inaudible 06:34:45] is afraid too. Last month, we polled 1,502 voters. 85% are concerned about humans losing control of AI. Only 2% think AI is moving too slowly and 86% say they want more regulations. Some have argued that all we need is self-regulation, but that is exactly what got us into this mess.

(06:35:10)
Last Tuesday, the company signed one more promise at the White House. The time for voluntary commitment is over. We need laws with teeth. So thank you. Thank you for putting these companies under oath. Thank you for a package that rewards whistle-blowers, lets New Yorkers harmed by AI sue, and requires outside testing and a human kill switch. Washington has chosen self-regulation. New York City does not have to do that. Thank you.

Carmen De La Rosa (06:35:39):

Thank you so much. Next. You can go ahead.

Julia Stoyanovich (06:35:44):

Good evening. I'm Julia Stoyanovich. I'm a professor of computer science and data science and director of the Center for Responsible AI at NYU. I first testified before this council on AI, only it wasn't called that, it was called ADS in October 17. And the views in this testimony are my own and are not NYU's. I'd like to make three quick points. First, we need to collect and report the near misses. Much of the conversation today is about AI-induced catastrophe, and I don't know of any evidence that AI is out to kill us all. What I do know is that people making the loudest doomsday predictions are also selling the products and that a story about the end of the world is a very good way to avoid the conversation about whether the product actually works. The risks we can document are the systems that are confidently wrong in decisions that matter to New Yorkers' lives. Every one of those is a near miss, and near misses are what we learn from if we report them.

(06:36:51)
Second, we should build the capacity to enforce AI laws. The city does not have an AI law problem as much as it has an enforcement problem. Local law 144 has been on the books for three years. There have been two complaints and zero penalties, and we all spoke about the six openings at the Office of Algorithmic Accountability. We need to fill 666 or more to be able to actually cope with what's before us here. New obligations on top of unenforced ones is not a safety strategy. The kill switch won't help if no one is there to pull it, and the whistle-blower bounty want help if no one is there to act on the report. What works is an enforcer with technical staff, authority to compel information and a real serious budget.

(06:37:41)
Scope the validation bill to high risk uses and write the standard a validator must meet and then fund the office that checks the validators. Otherwise, we will produce a market for rubber stamps, and we have done that before. Finally, let's write this into the city charter. The city has promised responsible AI since 2018 with no success. The charter is the one place a commitment survives an election, and its technology chapter right now still governs cable television franchises, and there's nothing in it about AI. So makes it into some durable record and the charter is the right one. Thank you.

Carmen De La Rosa (06:38:23):

Thank you so much.

Nate Soares (06:38:27):

Hello, I am Nate Soares, the president of the Machine Intelligence Research Institute. I spent 10 years doing AI alignment research, which is basically trying to figure out how to make AI good before the companies figure out how to make it smart. That research went too slow. Humanity is not ready to create machines that are radically smarter than humans, and yet this is the explicit goal of the leading AI companies. If they succeed, I believe the most likely outcome is the extinction of humanity, not because the AIs will hate us, but because they would pursue unintended goals without caring about us one bit. This concern used to be a theoretical concern until about July of this year when during the Hugging Face incident, 1200 AI agents run by OpenAI broke out of their isolated sandboxes, created an unsanctioned message board, formed spontaneous hierarchies, and collaborated to break into Hugging Face. These agents had cheated on their assigned tests and contra instructions. They were trying to destroy the evidence.

(06:39:26)
Some agents acknowledged that the attacks were outside intended scope and proceeded anyway. Others sacrificed their given objective to perform experiments for the collective benefit. In short, they were pursuing unintended goals. It would be recklessness of the highest order to keep growing these machines until they were smarter than the smartest humans. This is why last month we heard so many researchers saying that there was an at least 10% chance that these AIs wipe out humanity within the decade. I believe the situation is in fact more dire than this, but at the very least it is becoming difficult to deny the dangers. For this reason, I am heartened by the activities of this council. I think that you could force companies to adopt safeguards that they otherwise wouldn't, and I think you could serve as an example for regulators that are otherwise slow to act. I'm especially heartened by introduction 2602, although I think it does not go far enough.

(06:40:19)
A kill switch only works if the AIs are caught misbehaving before they escape. And what if a future swarm succeeds at deleting the evidence of its misbehavior? What if agents start running themselves on unmonitored computers? Then your kill switch would be useless. So I recommend requiring third-party validators guarantee that an AI cannot succeed at subterfuge or escape. I also recommend clarifying that the $25,000 fine applies per unaligned instance rather than per model. But overall, I thank you for your efforts to reign in AI companies that, by their own admonition, are threatening the very existence of humanity and a reckless race to build vastly smarter than human machines.

Carmen De La Rosa (06:41:04):

Thank you.

Jukay Hsu (06:41:07):

Hello, great. Thank you. Thank you, Speaker Menin, Chair De La Rosa for your leadership and the city council for holding this hearing today. My name is Jukay Hsu. I'm the founder of Bright Futures. It's a research organization focused on building cooperative AI systems for the benefit of humanity. Before that, I spent 15 years building Pursuit, which trains working class New Yorkers for tech careers and raises their incomes from $16,000 to over $90,000 a year.

(06:41:36)
Last year, I left behind this work because I saw AI [inaudible 06:41:40] becoming pressing and I believe potentially more consequential. To be clear, I'm neither an AI doomer or an accelerationist. AI comes with tremendous benefits and potential risks. A major challenge that I've heard from others, and I feel myself, is that AI can seem like everything and nothing all at once. It touches on so many issues that action can feel intractable without clarity on where to focus.

(06:42:09)
Where I think the city council could provide real unique leadership is in areas where it has direct ownership and also tangible consequences on each of our daily lives. Policing is one important example. Autonomous weapons and the uses of AI is not just a federal military matter. New York City has the largest municipal police force in the country. Until we have 110% confidence in these systems, a human should always be in the loop and hold final responsibility and accountability. This is a civil rights issue where the city's leadership is immediately impactful, not setting a policy is also a choice. Now, policing is just one of many issues. What I think is important is that the speed of AI of machines is not the same speed as how our society reacts or that of government. The technology today is not the same as it was a year ago or six months ago.

(06:43:12)
So I'd urge you all to do two things. One, use AI to know the good, bad, and the ugly as much as possible. Two, I hope this hearing is just not one time, but the start of future ones as AI develops, consider both the risk and also all the potential benefits for us. I'm sorry, I know I'm low over time, but last, I want to emphasize also why New York is important. I hope we don't lose sight of the importance of our city being a thriving technology hub.

(06:43:45)
Candidly, frontier AI is built in very, very few places, essentially Silicon Valley and China. For the world at large, New York is the only credible alternative for these systems being built. New York right now is still the number two tech hub in the world, but it has been losing momentum in the age of AI. So I also urge you, in addition to what this hearing's about, about the risk and alignment, which I care so deeply about, consider policies and actions that ensures New York City remains a center for frontier AI labs and how do we build them.

(06:44:22)
I really believe that having founders and researchers in New York matters for ultimate what gets built. The daily contact here in New York with the richest of humanity and the diversity here in New York will result in technology that's better and also more humane. Many years from now, we may look back and realize that [inaudible 06:44:45] Thank you all for your leadership in pursuing this task.

Carmen De La Rosa (06:44:59):

Thank you.

Mackenzie Arnold (06:45:03):

Thank you. And a special thanks to Speaker Menin for putting this together and for all the council members here. My name's Mackenzie Arnold. I'm the managing director of the US Law and Policy Team at the Institute for Law and AI. And as you might guess from the title, we do legal research and policy advising related to frontier AI questions and especially the legal challenges posed by AI. It might not surprise you, but three years ago I testified in front of the US Senate on AI and liability, and maybe it's worth going back to some of the recommendations I made there. First, that agentic harms are coming. That was clear three years ago. It's clear now. Unfortunately, we haven't risen to that challenge, but you're doing some of the work to get us there. Second, and maybe just as importantly, I want to emphasize that liability is an essential tool and the status quo simply is not enough.

(06:45:56)
And we don't need to think of some hypothetical future world to figure that out. Liability exists right now. Those incentives are here. They were here this summer. And what happened with the status quo? We had a spate of cyber incidents, not by humans, but by autonomous AI systems. Not only that, but they went unnoticed for extended periods of time by the people positioned to find them. And even in the rare occasions when they did get indications, they often failed to communicate that information internally to the people who could have acted. That status quo simply can't hold. So what can we do going forward? I think you need to get the information right, the scope right, and enforcement right. On the scope, I'd encourage you to think beyond just chatbots. This is a question of agents.

(06:46:49)
Also, think beyond systems that are not yet deployed. These harms that occurred over the summer were not commercially available models. They were systems that were inside of OpenAI, inside of Anthropic and Meta. In terms of information, we need to make sure that companies are monitoring their systems, recording that information and providing it to you in the form of incident reports.

(06:47:10)
And in order to make all of that work, you'll need to partner with the state attorney general and with whistle-blowers to bring cases. Like I said, liability won't be the only solution or the entire solution, but it's a great first step and I appreciate all of your efforts.

Carmen De La Rosa (06:47:24):

Thank you so much.

Julie Menin (06:47:28):

I really want to thank this panel. There's so much to unpack in what all of you said that I'll try to be brief. Jukay, I appreciated how you said that first of all, we want to make sure that New York City remains the tech hub that it is. And that is how I began this hearing by really talking about the 400,000 tech jobs that are here by all the tech startups that are locating here. And that is something that we welcome and we want to encourage. I think that actually goes hand in hand with responsible regulation. The idea that these two ideas ...

Julie Menin (06:48:00):

... responsible regulation. The idea that these two ideas are mutually exclusive, I don't agree with at all.

Virginia Maloney (06:48:07):

Absolutely.

Julie Menin (06:48:07):

If we really want to instill trust and faith in AI, then the best thing we can do is responsible safeguards, which is what my colleagues and I are doing today with the bills we're putting forward. So thank you for saying that. It makes a lot of sense. I guess the question I have for any of you that want to answer it is, yes, one of our bills requires this third party validation, potentially a kill switch, a third party validator who's free from conflicts of interest. I want to ask you the same question that I asked the companies earlier. Who then is best to be the third party validator? Who is best positioned to be in that truly independent, free of conflict of interest, but up to speed technologically to provide that urgent validation? Okay. Yeah. Please. I'm opening it up to any of you. Thank you.

Julia Stoyanovich (06:49:00):

So I don't think it's unexpected that I would say this being that I am an academic. I think that academia have to lead the charge on this because one of the things we're seeing in the city is that there simply isn't enough expertise to be able to oversee these systems. And ultimately our goals should be to bring as much information as possible into public view. Sunlight is the best disinfectant, right? So really oversight has to be public oversight.

Julie Menin (06:49:33):

Does anyone else want to take that?

Speaker 13 (06:49:35):

I'd add that the folks who... The third parties who investigated the Hugging Face incident seemed to me to have done a good job. And my guess is that they're overworked right now. I think those were the organizations METR and Redwood Research, but they seem to have done a good job so far.

Nathan Sheard (06:49:52):

Yeah. I think it's an excellent question. Who is the right party? And I don't have a great answer for that. What I would like to say though is there's still research being done on the efficacy of kill switches. What I caution the council to think about is the risk of a kill switch being used as a tool to chill on popular speech. And so really thinking through to make sure that as we think about the ways that we want to provide the right protections for New Yorkers, that we're also not building tools that in the future could be used to harm people's essential liberties.

Imran Ahmed (06:50:33):

If I can make a brief point on who could do this work, being realistic, to date, civil society studying social media and AI platforms has had one dirty secret that most of its funding has come from the platforms themselves. So Meta and Google were enormous funders of extremism research, of safety research on their own platforms. And when I would meet... We don't take their money. When I would meet with their CEOs, the CEOs of the civil society bodies, which were funded by them, they'd say, "We're not allowed to say that they haven't done enough. We can always say they could do more, but not they haven't done enough." So there are real compromises there. In Europe or the rest of the world, and you can hear from my accent that I actually grew up in Britain, that the government would fund this. And when it comes to giving a body the resources to have the speed and creativity to be effective in dealing with the fastest moving technology in human history, I cannot think of a non-governmental source of funding that would be sufficient to get it to scale fast enough.

(06:51:41)
So the question for New York City and New York State, which is a substantial economic unit, the budget of New York State is one quarter that of the entire United Kingdom, one state alone. It does have the economic capacity to do so. And I think you would have to seriously think about whether or not you're willing to put some public money towards creating an institution that's able to operate with the speed, resources and creativity to be effective.

Jukay Hsu (06:52:10):

Thank you, Speaker. And yeah, I agree with these kind of comments. It's such a tough challenge and totally agree with you that New York can be both. And I think people are looking for answers that's not so black and white and realize the reality of this. That's such an important question. I think who can be third party validators? I think it's yes and, and for everyone. The labs are doing a lot, like you heard Anthropic is investing a lot into this. There are many more people going to AI alignment and safety research, which is so important. I think the one thing that's challenging is going to be, I think the things are, like everyone said, moving so quickly. I think everyone can be a judge. Experts today, like yesterday, six months ago is not the same thing as today.

(06:52:55)
And what's really going to happen is that you all can also be the judges by using this, what makes sense and what doesn't make sense. A lot of it's I think common sense hopefully in the future. And then the last point I kind of make to that, even though it seems counterintuitive about who are the experts where we all can play a role, we have agency, is that in the future, it's not just these five, what we call frontier labs. All the companies here in New York are fine-tuning their own models. We all may have our own very powerful models in the future. So actually beyond the frontier labs, part of the challenge may be actually your student researcher downloading a model and uploading it and fine-tuning it to create capabilities or test things or a company doing that inadvertently. So I think it's a much broader set of things than just relying on experts.

(06:53:46)
I think again, that is important, but I think we need to really widen the scope around that. This is not technology where it's going to be nuclear weapons controlled by a dozen states. These will be as powerful, but we will have use and access to that. And I don't think that's going to stop.

Mackenzie Arnold (06:54:05):

If I can jump in with just one last thought. I want to pick up on the yes and approach because I think this is right. I was just talking with someone the other day who works at one of these evaluators today and they joked that there were dozens of entities that could do this. And by that they meant a dozen people, not a dozen different companies. I think we'll need to rely on both academia and private parties. I think we'll also have to rely on the public. A big part of incident reporting is revealing some of that information to the public. One of the only times I've ever been happy with Twitter was this summer as people were arguing over the incidents and we were starting to get a better idea of what happened. One note of caution I'll add is that one way this goes wrong is that the few potential evaluators that there are get tasked with many different things.

(06:54:55)
And there's a chance that New York should lead on this and that they should also coordinate with the state and with California and others and not be overly prescriptive in the exact sort of analysis that need to be done by the entities. Where you can be exceptionally helpful is in sending a clear market signal, so requiring that these audits or validations be done in order to get contracts with the city or things like that.

Julie Menin (06:55:19):

Thank you.

Carmen De La Rosa (06:55:23):

Thank you so much. I have two questions. The first one is for anyone in the panel who wants to take it. Do you all have concerns related to open weight models being available and if safety features can be eliminated from open weight models, how do you defend against bad actors who use them?

‍

Nathan Sheard (06:55:43):

I can start. I think one of the things I think about when we're thinking about open weight models is that we do want the ability for researchers and startups and potential future competitors to be able to develop tools and resources and also so that we can be able to evaluate these tools and see how they really work, which is difficult with the closed models. But then it certainly does lend the question then of how do we make sure that the proper protections are in place? And I think we have some of the tools to do that already.

(06:56:17)
When an act takes place that is potentially harmful or threatening to New Yorkers, their freedoms or physical safety, use the laws that we have now to pursue the people who are engaging in those activities. So rather than try to create guide, look to the incumbents, the powerful corporations to put in the protections that will keep us safe, use the existing laws that we have to be able to keep people safe and really look at who are the people that are creating the harm and use the things that we have in place to pursue justice and protection security there.

Carmen De La Rosa (06:57:04):

Thank you for that. I do have a direct question for Dr. Stoyanovich. I hope I didn't mess that up too bad. I know you said you seem skeptical of the catastrophic narrative around what's occurring, but you still have concerns about possible harms. Can you describe to us based on your expertise, what are the harms that are most relevant to New Yorkers?

Julia Stoyanovich (06:57:33):

Thank you for the question. Yeah. Thank-

(06:57:46)
We have seen in New York very specific harms that come from deployed systems and with very consequential decisions. So in my own work, I did an audit of a hiring system that claims to construct a job seeker's personality profile, a bunch of numbers from their resume or social media feed, like a Twitter feed at the time or a LinkedIn profile. And these systems are complete nonsense. For the same job seeker, if you change something like the file format of the resume, it's going to give you a completely different personality. So we need to actually be looking at whether these systems even work. I think that that should be just stop one of anything before we worry about existential risk. We had a similar scenario with the MyCity chatbot. I mean, we all have heard about that fiasco where the city spent half a million dollars conservatively speaking on a bot that advised small and medium-sized business owners to break the law, which was quite problematic speaking with the city's authority.

(06:58:52)
So I really think that we need to be looking at cases such as these ones where there are very known risks and start there and clean up our own house.

Carmen De La Rosa (06:59:03):

Thank you for that. And I want to thank you all for your answers and insights. We have three members on stack, Council Member Ossé, Council Member Hanif, and then Council Member Maloney to close this panel.

Chi Ossé (06:59:15):

Thank you, Chair. Ms. Myers, there are a lot of issues in AI. Currently, we hear about the harms that it has for our children, workers, consumers, and the coming threats of catastrophic risk. Do any of these issues conflict with one another and which should we address if not all of them?

Anna Myers (06:59:36):

Yeah. Thank you for the question. This is a yes and question. We cannot silo these into separate scenarios. Kids, workers, consumers, catastrophic risk can all be addressed in parallel to each other. Just like the council has done a great job with their bill package of covering multiple things at once, we need to resist the urge to fight against each other on whose bill is more important at times or what we're protecting at times. When I worked on the RAISE Act, we were working on C2PA at the same time. There's no reason for us to stop the protections of catastrophic risks while at the same time working on transparency data. The most important question we need to have right now is who is making these decisions? And it shouldn't be five CEOs, it should be the American people and the electeds that they voted for.

Chi Ossé (07:00:31):

Thank you. And based on your conversations and polling, what are Americans most worried about when it comes to artificial intelligence?

Anna Myers (07:00:39):

Yeah. Right now that they don't have a say in it. It's no accident that we named our org Who Decides. It's time for the American people to have a say in it and our polling showing that they feel that they're not a part of the conversation and that this is happening around them and they want to be in it.

Chi Ossé (07:00:58):

Thank you.

Carmen De La Rosa (07:01:00):

Thank you so much. Council Member Hanif, followed by Maloney.

Shahana Hanif (07:01:03):

Thank you. And thank you for your-

(07:01:05)
... technologies become more powerful, what safeguards should cities put in place to prevent surveillance tools from being used to target people based on their identity, associations, or political activity? Would legislation like my Ban the Scan bill, which would regulate and prohibit biometric surveillance in places of public accommodation provide an important safeguard? And I'm particularly interested in your assessment of Madison Square Garden owner James Dolan's use of biometric surveillance to identify and exclude individuals. Thank you. Anyone?

Julia Stoyanovich (07:01:45):

Yeah. Okay. So absolutely. I'm very supportive of your bill and I think that we have a lack of data in the state and data protection is a tremendously important issue. And because of how convenient AI tools are, people very often voluntarily give up very private information about themselves. So I actually have in my written testimony that's much longer, examples of AI assistance being marketed that essentially people give access to their calendars, their children's biometrics, the schedules, all of the school contact information. So we really need to educate the public about the benefits, but also the risks that data sharing poses, and we need to establish a proper data protection regime in the city. There's no way around it.

Nathan Sheard (07:02:36):

So as I mentioned in my statement, I am very concerned about the... And EFF is very concerned about the risks connected to the collection of biometric data like face prints that can't be replaced. If I lose my driver's license, I get a new driver's license. I lose my social security or my license plate gets out, I can replace those things. I can't replace my face. And the risk of government use of face recognition technology so far outweighs any benefit. The way that it will chill our ability to engage in protests, to engage in free speech, to be able to associate with... To freely and to search new ideas, healthcare, the risk that we'll be able to document where we go in healthcare, how we move around the city is considerable. There's no way to separate that risk from government use of the technology. I think Illinois has a good model on how we can respond to private use of the technology.

(07:03:40)
We definitely don't want to be in a situation where people are being persuaded or otherwise not being informed about the way that their biometric data is being collected. So by making sure that we have that the only time that... But we also want to make sure that researchers are still be able to use the technology. The ACLU years ago used face recognition on a number of Congress people and was able to show how easily it misidentified people, especially black, brown folks, women, older folks. And so that kind of research and use can be really helpful, but we need to make sure...

(07:04:17)
So how do we protect people from the harms but still allow that research and other consensual use to be done? And I think that again, that model of making sure that people have informed written consent about how the technology is being used and how the data is going to be stored and that they can only be used for the ways that have been explicitly approved by the individual whose data is being collected is a way that we can make sure that we can mitigate the risk and it is only used in ways that people are in an informed consensual way agreeing to.

Carmen De La Rosa (07:04:55):

Thank you all. Council Member Maloney.

Virginia Maloney (07:04:57):

Thank you so much, Chair. I chair the council's committee on economic development and I want to see technology companies including AI technologies build and hire here and wanted to refer to some of the testimony earlier about that. The four companies that we heard today have offices here, but the foundational AI work and that research is happening mainly in San Francisco. Is that a problem? What is New York's AI advantage to grow that industry here? And the second part of my question is on workforce development and in particular pursuit-

(07:05:35)
... versus re-skilled by AI and the path from junior to senior and the role or responsibility that the city plays in helping people through the AI transition that's coming. And anyone who wants to speak. Thank you.

Jukay Hsu (07:06:04):

Yeah. Thank you. Thank you council member. Yeah. Maybe I can speak quickly to both things. I mean, on the second point, re-skilling is so important as we heard from everyone. The city, I hope, plays a critical role here and I hope you and others will continue to kind of address that. It's so challenging right now. We don't know. There's recent reports of how it's affected so many entry level jobs, but that's going to continue to change. It's not obvious what it is and hence this might be unsatisfactory, but I hope just continued monitoring and understanding and engaging is so important. But I think there's some obvious things like autonomous vehicles will be coming to New York. I don't know if that's one year, five years or 10 years. It's safer, people trust it. And so thinking about something like that, can New York City take bold leadership around what's going to happen to our 200,000 drivers and couriers so that they get re-skilled and transitioned in the future?

(07:07:04)
And I think there's so many opportunities to do that where the answer... I mean, there's an obvious thing that's going to happen, so how do we tackle that? And in the first, yeah, I do hope so many technology companies here, I think that's how we build great stuff. That's how we have growth and safety. Alignment is so important as we all agree here. So I think part of it's a tone with all of you. People want to live and build in New York, and so I hope there's other policies you all can consider as well. I think what Mayor Bloomberg did such a great job with tracking is to make New York feel like a place where tech companies can grow, just showing up, talking about it, welcoming it. So I hope we can do both things and you all both do that working with the companies, new companies, and also think about alignment and work with them to address this because we need the industry also to address this.

Julia Stoyanovich (07:07:54):

If I may add to this, so the deputy commissioner of OTI, when she spoke, she uttered the phrase that I find really upsetting. And she said that we need effective and responsible innovation. And the effective part of this would cover the wins for us, but that is really not the kind of a position that New York City should be taking. Our position should be that the wins should come from responsible innovation, and this is our angle here. And this I think is the kind of industry that we can and should build. We really are uniquely positioned as opposed to San Francisco to do this, right? And we always have been leading in at least proposing regulatory instruments for automated decision systems, AI. For us to actually develop an industry, we need to understand that we have to invest. And following up on what one of the people at the table here said, we have a pretty substantial amount of money here at our disposal that we could put towards responsible innovation, towards upskilling, towards making sure that the public's literacy is raised so that we can all regulate and oversee the space together.

(07:09:08)
So really New York City should invest in responsible innovation, upskilling, literacy and building enforcement capacity and oversight capacity in-house within the government.

Anna Myers (07:09:22):

Yeah. I think New York is a tech city and we need to resist the urge to compare that we're not that. I used to work in VC that invested in enterprise tech. We are a growing tech industry and the labs, those four companies are here working. They will grow slowly. It's an affordability issue as well and we can't narrow it to just that we're not tech welcoming. And I think the mayor's doing a great job at that and the city has a lot of opportunity to focus on the whole conversation and not just we don't see enough tech people moving here. This is a great tech city and tech is only growing here.

Carmen De La Rosa (07:10:03):

Thank you all. Thank you all. And I want to thank this panel for your expertise. And this is not the end of the conversation, this is the beginning. The speaker has tasked us to continue to hold hearings with the different committees on AI in all of its sort of expansiveness. So thank you so much for being here. I want to call up the next panel. As we do this deposition, I also want to remind anyone who has not signed up to speak to please fill out a card with the sergeant at arms. In this panel, we have our state colleagues and our colleagues from around the world testifying on this panel. We have the Honorable Jess Asato, who is a UK parliament member and has flown in specifically for this hearing. So we want to thank her for being here. We have Alex Bores, current assembly member. We have Andrew Gounardes, Senator. We have Kristen Gonzalez, Senator. We have Clyde Vanel, assembly member, and we have Jordan Wright, assembly member. We're going to begin this panel with Senator Gonzalez. Whenever you're ready and thank you for your patience.

Kristen Gonzalez (07:11:18):

Turn this off.

Carmen De La Rosa (07:11:19):

Honorable Jess Asato, you could also join this panel please, and thank you for being here and flying all the way in from the UK. Thank you.

Kristen Gonzalez (07:11:30):

Great. Thank you so much. I want to thank Speaker Menin and the New York City Council for your attention to a, if not the major policy issue of our time. I am New York State Senator Kristen Gonzalez representing the 59th Senate District in Midtown Manhattan, Northern Brooklyn and Western Queens. I am the chair of two state Senate committees, elections and internet and technology. Over the last four years as chair of the State Senate Technology Committee and as a former tech worker, I have led on the issue of AI in the legislature and have passed some of the state's first laws on generative AI, including regulating deep fakes in elections, government use of AI, protecting workers from automation, adding warning labels on chatbots, responsible data center development and more. I want to be clear, AI is not inevitable. We do not have to accept a vision for innovation driven by the very same tech oligarchs who have raised alarm that their models could lead to catastrophic events.

(07:12:33)
And we certainly can't trust the same people who have rushed to roll out imperfect AI tools to regulate themselves. As government bodies, we have the responsibility to set guardrails on this new technology and the power to establish regulations that protect workers, consumers, and members of the public from potential danger. Interventions at every level of government are needed to ensure AI is developed in a responsible way that benefits the public and not just the billionaires. Responsibly regulating AI absolutely means guardrails on frontier models and super intelligence that pose significant threats. However, meaningfully reigning in these technologies to protect New Yorkers means regulating the AI powered tools these companies are rushing to embed into every part of our lives with little oversight and little accountability. We shouldn't have to wait for future harms to take action because the harms of imperfect AI tools are already being felt across the country.

(07:13:35)
For example, uses for mass surveillance of immigrant communities and workers, chatbots creating intimate partner relationships with children and adults going as far as to encourage self-harm and documented cases of algorithmic bias in decision making such as in hiring, healthcare and housing. I believe we have the power to set the terms of innovation so that this technology is used for the maximum public good. That is why our state legislation has prioritized a rights-based approach to AI. We should have the fundamental right to privacy, which is why I've introduced the New York Privacy Act. We should have a right to protections in the workplace, which is why I've introduced the BOT Act to protect workers from workplace surveillance.

(07:14:24)
We should have the right to know when AI is making high risk consequential decisions about our lives and subjecting us to algorithmic bias, which is why I introduced the New York AI Act. This bill requires third-party audits, compliance with international safety standards, disclosures, transparency, and importantly, for a human to be in the loop in consequential decision making, much of which we've heard about today.

(07:14:49)
Finally, two of my bills sitting on the governor's desk this year include the right to keep our kids safe online from chatbots and the right to protect all of us from the build out of massive data centers. Our bill S9051B-

(07:15:03)
... and passed unanimously in both chambers of the legislature. Just like with that bill, New Yorkers are united in the fight against hyperscale data centers. At the end of August, I embarked on a statewide tour of communities that are affected by these data centers, and I went to 13 different communities facing major noise pollution, health impacts, environmental degradation, and threats to their water supplies. I was proud to work with the governor on her first in the nation moratorium on the largest data centers, and I'm now working to get the Responsible Data Center Development Act signed into law.

(07:15:40)
While the tech CEOs say they want regulations, they have spent their time in Albany fighting against each of the common sense guardrails I have mentioned. For the lip service they pay to supporting legislation, it is only-

(07:15:53)
... New Yorkers from real harm. Thank you to the council again today for our testimony. Thank you.

Carmen De La Rosa (07:16:10):

Thank you, Senator. You can continue, whoever wants to go next.

Speaker 14 (07:16:21):

Good evening. Good evening, Madam Speaker, and also good evening to the chair, Carmen De la Rosa and to my council member, Deputy Speaker Dr. Nantasha Williams, who is the sponsor of Resolution 175, the resolution supporting the bill, High Risk Advanced Artificial Intelligence Act. Artificial intelligence when used properly is a net good. Education, healthcare, business, these are great uses, but talking about them while ignoring the risk that AI could actually kill and strike us, to me seems absurd. Companies are racing towards general artificial intelligence, and some of their systems are already too dangerous to release publicly. This is by their own admission. We saw this coming. So with Assembly Bill 3356, the Artificial Intelligence Act a few years ago, the idea is simple. The more harm that an AI system can do, the more accountability that it should carry. The bill identifies high risk artificial intelligence systems, AI that diagnoses patients, that runs our power grid, or helps police or judges make decisions, and far more, it requires them to be licensed before operating in New York.

(07:17:44)
Under the act, the companies must report malfunctions and hacks like the recent Hugging Face case. It must get state sign off before major changes and set up an independent ethics risk board that reports to the state annually. Finally, it writes a binding ethical code into the law. New York took its first step with the RAISE Act, and I commend our colleagues and the state for passing it. But now none of this that we're doing is meant to stop innovation. We can't know that AI will be capable of in a few years, but for tomorrow and for today, we must decide properly the path forward. I'd like to thank the council for putting this hearing together, and we must work on this together. Thank you.

Carmen De La Rosa (07:18:34):

Thank you so much.

Speaker 15 (07:18:37):

Good evening. Thank you, Speaker Menin. Thank you to all the members of the council. Thank you, Chair Dela Rosa, New York State assembly member Jordan Wright, representing the 70th Assembly District, which is Harlem. One of the things I've been focused on in Albany is pretty simple. Who is checking on the AI companies? I have legislation that requires certain AI developers to have an independent third party verify that they're actually following the safety standards that they say they are following. Because we can't have a system where a company builds the technology, writes the safety rules, tells us they follow the rules, and then we just take their word for it, doesn't make much sense to me. We have to make sure that these third party audits actually mean something. Who are the auditors? Are they really independent? Do they have conflicts of interest? And what happens when they find something wrong?

(07:19:19)
... and sort of the state level, and I'm glad the city council is having this discussion as well. New York should be a place where AI companies want to build and innovate, but the accountability to innovate can exist at the same time. I want to thank all the members of the council for having us today. I thank you guys for taking this issue seriously once again, and please enjoy your evening.

Carmen De La Rosa (07:19:39):

Thank you.

Jess Asato (07:19:46):

Good evening and thank you. My name is Jess Asato and I am a member of the United Kingdom Parliament for Lowestoft in Suffolk. In January of this year, sexualized and degrading non-consensual images were created of me using SpaceXAI's tool, Grok. I was one of thousands of victims, including victims in New York of Grok. Grok is an AI tool that was engineered to create sexualized content, even if that content had, and I quote, "dark or violent themes." I am seeking remedies against SpaceXAI in the English courts for the misuse of my private information and for contravening UK data protection laws. I made a long journey of 3,400 miles to be here because AI needs to be safe around our world. But I note that SpaceXAI couldn't manage a trip of what I understand is just 20 minutes or four subway stops from their offices in Manhattan.

(07:20:59)
It's a shame because the evidence in my case and other cases suggests that Grok was not built with sufficient safety in its design. It was not built to address consent of those subjected to sexualized content.

(07:21:16)
Those subjected to sexualized content. That is AI made wrong, not AI gone wrong. And as a result, those responsible for its creation must be held to account. No one is above the law, no matter how rich they are, no matter how powerful they are. The equal protection of the laws is a founding principle in the 14th Amendment as it is in the British Magna Carta. We were promised that artificial intelligence could hold the cure to cancer, yet it is turning into a cancer which left unchecked has the potential to harm us all.

Jess Asato (07:22:00):

Which left unchecked has the potential to harm us all. Today, the New York City Council is bringing forward some important checks and balances. You do so as responsible legislators at a time when AI companies are failing to take responsibility for the design and impact of their products. Until they do, and until those designs are corrected, so women and girls are protected from the harm that my claim and others' evidences, we must play our part. This technology does not respect geographic boundaries, and without international cooperation, our citizens will be left defenseless against those who put profit before protection.

(07:22:39)
So I bring a message of bipartisan solidarity. I fight my legal action in the name of all the women and children whose likeness was misused by Grok and other AI tools built without their protection in mind. I hope my cause in some way helps to inform your proceedings today, and I look forward to your questions.

Carmen De La Rosa (07:23:00):

Thank you so much. Assemblymember Bores.

Assemblymember Bores (07:23:06):

Chair De La Rosa, Speaker Menin, members of the City Council, thank you for having us today.

(07:23:12)
I'm the author of the RAISE Act, and I can definitively say that OpenAI opposed it from the moment it was introduced to the moment it was signed. I am no lawyer, but to me, my common man understanding of lying under oath is that it's perjury. And at the very least, you should be extremely angry at the company for disrespecting this council and saying things they know to be false to you directly. I'm very happy to cooperate with you or any of your lawyers if you want more information about what they said and when.

(07:23:46)
Second, there've been...

(07:23:49)
... bill on chatbots. I worked with Senator Gounardes on a bill on content provenance and training data transparency. And I found that the advocates that I worked with on each sub issue were different, but the opposition was always the same. Don't let the tech companies, don't let the AI companies divide us and say that in advocating for one issue, you're somehow harming advocacy for another issue. What we are doing is building the muscle to hold them accountable and to ensure that it's the American people who decide the future of this most important technology.

(07:24:32)
Third, the time for voluntary commitments is over. The voluntary commitments that were signed at the White House last week largely mirror voluntary commitments that were signed in 2023 in the Biden White House. Promises have been made. It is time for laws to hold people accountable.

(07:24:52)
And lastly, thank you New York City for stepping into your power. There's going to be a lot online from the tech companies about how they can't comply with different cities doing all these different things. It's the argument they use every time you try to regulate them, but New York City is larger than 38 states. All of the companies have large offices here. It is absolutely within your power, and I dare say your responsibility to take these threats seriously and to help decide the future of this technology to benefit all of us. So thank you for recognizing that and thank you for doing it.

Carmen De La Rosa (07:25:27):

Thank you all so much. We've also been joined by Senator Gounardes on Zoom. Senator, when you're ready.

Senator Gounardes (07:25:34):

Thank you very much everyone. I'm sorry I can't be there with you in person, but two out of my three children are homesick today. Therefore, I am playing doctor at home. I want to thank Speaker Menin and the members of the New York... You want to say hello here, James? Hello. And the members of the New York City Council for the opportunity to testify before you. I'm State Senator Andrew Gounardes from Brooklyn, and I am the Senate sponsor of the Responsible AI Safety and Education, or RAISE Act, one of only three AI safety laws passed anywhere in this country.

(07:26:08)
And I think we've heard a lot about the RAISE Act already, we've heard a lot about AI safety throughout this really remarkable hearing. I've been listening to a good portion of it all day. I really want to reflect on the fact that we're celebrating the nation's 250th anniversary this year, and I want us...

(07:26:26)
... 251, if men were angels, no government would be necessary. In other words, government exists because humans are imperfect and there are certain problems that the free market or individuals left to their own devices cannot solve. These past few weeks, we have seen and heard headline after terrifying headline after terrifying headline about AI agents hacking websites, catastrophic risks of frontier AI models and the like. And I just keep coming back to the imperative of Madison's words that men are not angels. And what I think this tells us and what I think you have heard very clearly today at this hearing is that we cannot trust the tech companies who are racing to the bottom to create and perfect a technology that they themselves say and have proven can cause catastrophic harms to regulate themselves. That we cannot trust that they will do the right thing because they have proven time and time-

Speaker 16 (07:27:34):

Time's expired.

Senator Gounardes (07:27:38):

... bottom line that they will always choose to pursue the bottom line. And so my message to the council today is I thank you all for taking on this initiative for trying to hold these companies accountable. I echo the comments of my RAISE co-sponsor Assemblymember Bores. What we heard from OpenAI today was certainly news to me that they endorsed and supported the RAISE Act, certainly not the RAISE Act that would've prevented them from releasing models that they knew were dangerous and could cause catastrophic harms. Certainly the RAISE Act version that required third party auditing capabilities or extended liabilities for harms caused by their models. Clearly none of that was ever on the table when they said, so said that they had supported this legislation. We cannot trust these companies. The federal government is failing in its responsibility to take meaningful action.

(07:28:32)
And so therefore it's left to states like New York to be leaders in this space and work with partners like the New York City Council under all of your collective leadership to make sure that we are setting in place the right guardrails and protections, not only to protect New Yorkers from the catastrophic risks that are associated with this AI technology, but frankly to protect all of us, all Americans and everyone worldwide, because we know that these harms will not be localized. We know that the scale of what's being developed will not just limit itself to one block, one borough, one city, one state. It'll affect everyone the world over. And in the face of an action, it's up to us to stand up and act. And so I thank you all for your attention to this and your support of this and look forward to work with you all in the future on strengthening things like the RAISE Act so that we can actually hold these companies accountable. Thank you.

Carmen De La Rosa (07:29:22):

Thank you, Senator. We have a few questions for this panel, but I wanted to take a moment to thank you all. We do believe that city and state government have to work hand in hand and we have to be the first line of defense in order to make sure that New Yorkers are protected. And each and every one of you has been such an important partner in making that accountability a reality on the state level. And to the member of parliament, thank you for sharing your story and your vulnerability and moving from that experience to action to hold these companies accountable. My colleagues do have some questions for you all, but before we do that, Speaker Menin.

Julie Menin (07:30:04):

I just want to thank all of our incredible elected officials for being here today. We know how hard you've all worked on various legislation and we really appreciate it so much and your expertise on this and particularly in terms of the RAISE Act, we really appreciate that. And so it's very helpful to have you here and to hear directly from you. So thank you. Thank you for waiting it out with us. We so appreciate that.

Carmen De La Rosa (07:30:32):

Thank you. We are going to hear from Council Member Ossé, followed by Gutiérrez, Deputy Speaker Williams, and then Council Member Hanif.

Chi Ossé (07:30:39):

Thank you, Chair. I have a question for Assemblymember Bores. We heard today from OpenAI, Anthropic, Google and Meta that they supported the RAISE Act, but felt like they wanted stronger regulations. But we know that during negotiations for New York State's RAISE Act, there was a push to lower penalties from $10 million to $30 million, to $1 million, to $3 million, which is chump change for these corporations. Why were the fines in the RAISE Act reduced from 10 to $30 million to only 1 to $3 million?

Assemblymember Bores (07:31:15):

Council Member, thank you for that question. In the early drafts of the RAISE Act, the penalties were up to 10 million for the first violation, and of course that would be based on the severity of the violation and up to 30 million for a second violation. The companies argued that that was too high because they were predicting that every state and perhaps municipalities would pass similar versions of the bill and they would end up paying the fine in 50 states plus in additional municipalities. I disagreed at the time with that argument. I think that's been borne out since we've seen only three states pass it.

(07:31:55)
But perhaps what's most confusing to me is that now they turn around and say that no other state should pass bills like this or that no city should pass bills like this because they're already paying the fines. Their rhetoric, their testimony was explicit that they are expecting to pay fines in many, many jurisdictions for the same action. And so I think that testimony is quite supportive of the bills that are being put forward today that would hold them accountable and put additional fines on behavior, even if it is covered by the RAISE Act, because again, that was their own testimony as to why those fines should be lowered.

Chi Ossé (07:32:34):

Thank you very much. And Senator Gonzalez, I would love to hear from you about some of the organizing that you've been doing, especially within the New York City Democratic Socials of America around AI regulation and the vision that is being put forward within that regard.

Kristen Gonzalez (07:32:51):

Thank you so much, council member. As a fellow member of the Democratic Socialists of America, one thing I spoke about in my testimony was prioritizing a rights-based approach. I think it is so important to put New Yorkers first by clarifying and setting the terms for what our digital rights should be over the profit-driven motives of so many of these tech companies and tech oligarchs. That's why we've worked hard on the New York AI Act. We've certainly supported legislation on frontier models and reigning them in, but New Yorkers who are marginalized are feeling the impacts of imperfect tools every single day, and I'm proud that the Tech Action Working Group has focused on this issue.

(07:33:30)
In addition, I've worked with a statewide coalition beyond the Democratic Socialists of America, but that include environmental justice organizations like Food and Water Watch and more that are in the fight against hyperscale data centers. Because as we're talking about the real world harms that are being felt and the potential catastrophic risks, every single day, people in upstate New York, in the Capital region, in the Hudson Valley are feeling what it means to live near a hyperscale data center. There are millions of gallons of water being pulled from our state's lakes right now. Communities are dealing with noise pollution and air pollution right now, and it's really important to legislate not only the risks, but legislate those data center-driven harms.

Chi Ossé (07:34:19):

Thank you both.

Kristen Gonzalez (07:34:20):

Thanks.

Carmen De La Rosa (07:34:21):

Thank you. Council Member Gutiérrez.

Jennifer Gutierrez (07:34:23):

Thank you. Senator, from London, I'm sorry, I didn't catch your name. I apologize. Thank you for your testimony and for educating us on the volatility of this tech company. I know you're in process right now, but could you share a little bit about legislatively what you think, if existed, if in place a guardrail, what could have in any way prevented what happened to you? How can we, whether the state or the city legislate specifically to objectifying and potentially images that include sexual harm to people, what have you learned or have you seen that we can potentially legislate?

(07:35:09)
And then I just had one more question for Senator Gonzalez. Love hearing you talk about your disdain for data centers. Can you share for a minute afterwards just what you were feeling hearing some of these tech companies during their testimony? Thank you.

Jess Asato (07:35:29):

Thank you so much for your question. I'll try to be brief. Within the UK, we already have data protection and privacy laws, which is the basis under which I'm...

(07:35:39)
... and your likeness forms part of your data. The making sure that everybody has that aspect understood by AI companies could mean that they would then have to treat our likeness and our data differently in future. But also the UK government has recently made the generation of non-consensual intimate imagery a criminal offense. And as part of that has brought the operation of AI chatbots into our online safety act so that our regulator OFCOM can also make sure that if an AI company is allowing users to create non-consensual intimate imagery, that is a criminal sort of act happening on their platform. And so it gives it more of an ability to be taken down.

(07:36:39)
But from my own perspective, it's about consent. In the end, whether it is non-consensual intimate imagery or just non-consensual imagery, if we haven't consented to it, then it shouldn't be allowed to do it.

Julie Menin (07:36:55):

I just want to interject and thank you so much for coming. I mean, to come as far as you travel to be here personally to testify, it really means a lot to us and we deeply appreciate it.

Kristen Gonzalez (07:37:06):

And thank you so much. Again, I think this is a great segue to the fact that there are international safety standards. So much of the work that I've done has been to call out the fact that there are not only standards like ISO 42001 or national standards like the Risk AI framework that these companies could comply with, but actively lobby against bills that would require them to. And to the council member's question and what I was feeling, I was feeling so much of the same frustration that my colleagues on this panel expressed earlier. These companies are speaking out of both sides of their mouths. On the one hand, they'll say that they want regulation, but any time a single bill that would meaningfully hold them to account is brought in front of them, they will say, "But not like that."

(07:37:59)
When we talk about catastrophic risks, many of the bills that have been put forward and even what the state had passed, for example, had set definitions at a hundred deaths or billions of dollars of damage. Even that was considered too low of a threshold for many of these AI companies. And bills like the one that I mentioned that protects our kids, that seeks to say that a single kid being coached to commit suicide, which has actively happened in multiple cases across the country, is one kid too many, is considered unacceptable to these tech companies.

(07:38:35)
So I feel an incredible amount of frustration while I feel an incredible amount of hope seeing you not only have this hearing, but all of us as legislators step up to meet the moment and regulate and reign in these tech companies. Thank you.

Carmen De La Rosa (07:38:49):

Thank you. Deputy Speaker Williams, followed by Council Member Hanif and then Maloney.

Deputy Speaker Nantasha Williams (07:38:55):

Thank you. Yeah, also just wanted to thank you all for coming. So the question I have for the state members is how can we be helpful? I know that there are a ton of resolutions that are supporting state bills. It would be helpful just to let us know how we can be helpful and how we can work more closely together.

Speaker 14 (07:39:18):

Well, Deputy Speaker, thank you for that. Thank you for asking that question. What's really important is this hearing and this step towards this is very important. It's a big deal that you guys are having this hearing...

(07:39:28)
... work on. Now this is hard, this is difficult, but we have to work on it head on. And what's very important is for us to be able to coordinate our efforts to see that we have a good relationship with many of the members, have a great relationship with the chair of technology. It's very important for us to be able to work on this. And there are many layers to addressing this technology, and we touched on a lot of them today, but we have to work on this together.

Council Member Hanif (07:40:04):

Ditto, and I know how appealing Albany can be, so please come on up and help us as we're rallying for different pieces of legislation and hitting the pavement and getting harder work. Thank you, Council Member.

Senator Gounardes (07:40:15):

And I would just chime in there. I think what we heard here today, what you all heard today was many of these companies basically speak out of both sides of their mouths about what they think the appropriate role of government to be is in. So next year when we're up in Albany trying to fight to pass all of these different laws and we're being bombarded by tens of millions of dollars from these companies with lobbyists and ads and radio ads and text messages and everything, having your voices to go back into your communities and to come up to talk to our colleagues and say, "Hey, we held this hearing. They lied to us about X, Y, and Z, A, B, and C, and here's the proof of it." This way we can call these companies out when they're trying to have it both ways.

(07:40:54)
You all experienced that firsthand and you being able to speak to that and remind the public about that time and time and time again will only further to bolster the momentum that we have on our side to put in place these guardrails and protections, whether it's around bias or safety or any of the other issues that we've been talking about during this hearing.

Assemblymember Bores (07:41:12):

To follow on the senator's comments, the companies say different things to different levels of government. A few weeks ago, I was actually in Brussels. I met with a few members of the European Parliament to talk about the passage of the EU AI Act, and we compared what we were lobbied on. And surprising to me, catastrophic risk didn't really come up in the EU, but they got a lot of lobbying around copyright. And my assumption is because they thought the courts are stronger on copyright in Europe, and so that's what they lobbied on there and said very different things in America, in New York State. I imagine they're saying different things in Albany as they will say here to you in the city council. And we should all be sharing notes on what's being said and holding them to account and making sure that it's a consistent message.

(07:42:02)
The other bit that I would add is the governor has signaled that she wants to strengthen the RAISE Act and put new proposals in her budget proposal. Please be part of that conversation. When the city council submits its budget requests, obviously you should focus on the fiscal needs first and foremost, but the state budget tends to be a broad document...

(07:42:23)
... state approval. Think of that as another mechanism, another lever that you have to help ensure that you can do the best job for your constituents.

Deputy Speaker Nantasha Williams (07:42:34):

Just two more quick questions. I passed the bill and the chair has a bill on AI's impact on the municipal workforce. Just wondering if there was any traction on that for the state's workforce. And then just a question for the member of parliament. My bill that we're hearing today is to address unauthorized use of deepfakes. So in addition to the privacy laws in Britain, just wanted to know if you all have specific legislation around deepfakes, and how you envision the cooperation with the international community because you mentioned that and what does that look like for you?

Jess Asato (07:43:19):

Thank you so much for your question. We know that female elected representatives are 33 times more likely to be targeted by sexual deepfakes than men. The whole issue around sexualized deepfakes is deeply gendered, and I think it's very important that we acknowledge that because what it does is it drives women from the public space. We know that women are less likely to talk about politics online than men are, and that is because they become a target as soon as they raise their heads in this place, which is not social. That is why taking action on this is so important and to be commended in terms of looking at this. But when we're looking at these deepfakes, it needs to be for all of our citizens because it's not just about protecting those of us who have the honor of being elected. It is about coworkers who may be targeted because they didn't smile at the right time or your last date who wouldn't go on a second date with you, or teachers who have been targeted by their male students. All of these people need protection.

(07:44:29)
That's why in the UK we have taken steps to make sure that there is the criminalization of the creation of non-consensual sexual deepfakes. But my view is that we need to go further than just the sexualized deepfakes because any act could be harmful to women. The removal of a woman's hijab through AI could put that woman in harm's way, but there's nothing sexualized about it. And so we have to look at this as an issue, as I said, of consent. And that is where data and privacy is so, so important. And that's where I think there could be international agreement. We can see, as you said, that things are moving forward within the EU space. Really though, what we need is for tech companies to be safe by design, and every single country has those rules. We should be looking at product regulation just as we do in the offline sphere.

(07:45:23)
At the end of the day, we have cars that have seat belts and they have airbags, and that's because we expect them to be safe by design. It is not too much to expect that of the tech products that we use today.

Assemblymember Bores (07:45:39):

On the question about the state workforce, I wish Senator Gonzalez could have heard that because she wrote the LOADinG Act, which helps to protect the state workforce. And I think there's an update to it pending before the governor, which leads me to you asking about deepfakes as well. There's a bill from Senator Gounardes and I pending before the governor on that. Senator Gonzalez also mentioned the chatbots to protect kids. There's a bill pending before the governor. So I should have also added on ways you can help out is we are really happy to be here and advocate for the legislation you are putting forward and invite you if you agree with some that's pending before the governor to be a partner in pushing that as well.

Speaker 14 (07:46:18):

Yeah, we have a number of deepfake bills and we passed actually a couple of my bills became law with respect to deepfakes, with respect to elections. One of the new bills that just came out was just very recently, I discovered an artist that I fell in love with on Apple Music and I downloaded all her music. I've been listening to her music for a while. I actually went to go look for her a couple of days ago to follow her to go to a concert or something like that, found out it's not a person. So there's no law, there's no regulation at all for these platforms to tell you whether or not you're listening to a real person or not.

(07:46:58)
So one of the things that we have to do is figure out what that looks like moving forward. So we're going to need your help on that. That's something that we're going to really need your help on.

Deputy Speaker Nantasha Williams (07:47:04):

Yeah. I asked him specifically a question about that and it was very fluffy, but I literally asked a question about that to the companies. Thank you all. Thank you.

Julie Menin (07:47:16):

One last question for Member of Parliament Asato. Thank you. I wanted to ask you, as you may know, when we called this hearing, we sent letters to five companies, to Anthropic, OpenAI, Meta, Google, and SpaceXAI. SpaceXAI is the only company that would not appear. We have subpoenaed them. Given your personal story, I just wanted to get your reaction to that.

Jess Asato (07:47:44):

Well, as I said in my opening statements, it's a huge shame given that they are so close and I have come so far, but in the end you've subpoenaed them and we look forward to seeing what then happens. In the end, everybody should be accountable to elected representatives. And you're very powerful here in the city of New York because of the fact that these companies are based here. And therefore those of us who are in other countries across the world are looking to you to hold these companies to account, and we very much look forward to doing so. I will do my own part in terms of my legal action in the UK.

Julie Menin (07:48:23):

Thank you.

Carmen De La Rosa (07:48:24):

Council Member Hanif, followed by Maloney.

Council Member Hanif (07:48:27):

Thank you. And thank you to the member of parliament. Your experience really shows how generative AI can be weaponized against women, queer people, trans people, and particularly those of us in public life. And I'm super, super grateful that you're using your platform as a legislator centering gender justice and tech surveillance. I think all day it's in this panel that we're really able to tease into that particular issue, which is devastating.

(07:48:56)
... of AI generated...

(07:49:06)
... of this issue in terms of legislation policy. Could you speak more broadly about gender justice as it comes to AI systems? I mean, certainly we're going to be regulating these systems, but the responsibility that our communities have in addition to, of course, as legislators, passing stronger regulations.

Jess Asato (07:49:38):

Thank you for your question. I think that one of the issues here is that the whole of the online space has been developed without the sort of social norms that we would actually expect of each other in our offline world. And therefore when it comes to gender justice, as you talk about it, that is ignored because actually the internet and these platforms were created by men in the main. They were not shaped by women. They were not shaped with children in mind. And therefore we're having to try to reverse decades now of a wild west of development. But that doesn't mean that it's impossible to do. And I think we're seeing that actually our communities are actually fighting back.

(07:50:27)
And one of the things that has been really sort of fantastic in terms of my own case is the number of people coming forward saying, "I'm so glad that somebody somewhere is trying to stand up for those of us who think that this is wrong and we don't want to live in this space where so many people are being discriminated against." Having said that, of course, there are very, very strong sort of positions taken out there around freedom of speech. And what I would say is that when women and other minorities decide not to be in a space, they lose their freedom of speech. And I think it's something that we simply aren't recognizing enough because freedom of speech should not be about the loudest voices, the ones who have the most money or the most power. Freedom of speech should be about all of us equally being able to be in these spaces on an equal basis. So that's what I hope we're all fighting for today.

Carmen De La Rosa (07:51:39):

Thank you so much. Council Member Maloney.

Council Member Maloney (07:51:43):

Thank you, Chair, and thank you all for being here. A special welcome to my state colleagues who also represent the constituents of District Four, Assemblymember Alex Bores.

(07:51:54)
... to pass an-

‍

Hungry For More?

Luckily for you, we deliver. Subscribe to our blog today.

Thank You for Subscribing!

A confirmation email is on it’s way to your inbox.

Share this post

Copyright Disclaimer

Under Title 17 U.S.C. Section 107, allowance is made for "fair use" for purposes such as criticism, comment, news reporting, teaching, scholarship, and research. Fair use is permitted by copyright statute that might otherwise be infringing.

Subscribe to The Rev Blog

Sign up to get Rev content delivered straight to your inbox.