Rush transcript below. Please check quotes against the video.
00:00 Sasha Baker
Hi, everybody. Let me start by thanking you all for getting up early and hoofing it downtown, leaving the UNGA bubble in Midtown for at least a little bit. Hopefully, everyone got some coffee.
We are here today to talk about cyber resilience and cyber defense, particularly for vulnerable democracies. I wanted to say a word before we introduce the panel and get started.
We've been talking at OpenAI about something we're calling the defender's window, which is basically the idea that, now that we have these AI-enabled cyber tools, there's this period of time where we're really rushing to get them into the hands of critical infrastructure operators, governments around the world, and people who want to patch systems, defend their networks, and remediate vulnerabilities. We know that as these tools proliferate out in the ecosystem, there are going to be bad guys out there who also try to use them to do things that we don't want to see. So we have this window of time to take action, and we're really motivated by the idea that we need to act with some urgency.
We have a program we call Daybreak. Some of you may have heard about it. Daybreak is the umbrella term that we have collected all of our cyber models and our cyber tools underneath. It's designed to put cyber defensive tools in the hands of cyber defenders here in the U.S. and around the world. Specifically, we're focused on frontline defenders.
You may have seen Greg Brockman, our president, made an announcement—I've lost all track of time—three weeks ago, where he announced a global initiative to help critical infrastructure operators, particularly underserved critical infrastructure operators, both here at home and globally, to use frontier AI to protect essential services that civilians around the world depend on.
We made a global commitment of $1 billion in tokens to serve that program. These are subsidized tokens that we're giving to frontline critical infrastructure operators to enable them to use the tools and get comfortable with them without having to worry at the outset about cost. So we're trying to expand this subsidized access to the people who need it most.
What I'm really excited about today is my ability to announce that we are beginning a new partnership with the government of Ukraine. We have Dmytro Kushneruk, who is the consul general, here today with us. We are going to be partnering with Ukraine's Ministry of Digital Transformation to work to get our cyber models into the hands of critical infrastructure in Ukraine. We know that Ukraine is defending civilian infrastructure from persistent Russian attacks every day, every hour.
This means that verified Ukrainian teams are going to get these tools. They'll get training. They'll get technical support to help them identify vulnerabilities in their networks and develop and test fixes faster. That is really exciting for us. We hope that it's only the beginning of a partnership with Ukraine, and more to come on that front.
With no further ado, I'm going to introduce our distinguished panel, and then we'll get started. As I said, we have Dmytro Kushneruk. He is the consul general of Ukraine based in San Francisco. He was formerly with Ukraine's permanent mission to the United Nations, so he knows the UN and New York City very well, and was the deputy chief of protocol to the president of Ukraine.
We're delighted to welcome Andy Baker. Andy and I are not related, as far as I know, just for posterity. Andy is now the managing director at American Global Strategies. He formerly served as the national security adviser to Vice President JD Vance.
We're delighted to welcome Naz Durakoğlu. She is the minority staff director for the United States Senate Foreign Relations Committee, working for Senator Shaheen, and a former assistant secretary of state for legislative affairs.
Thank you all for being here. I'm going to just kind of bop over here, and we will get started. Switch to the handheld mic. Okay, I'm going to start with you.
In light of the announcement that we're able to make today, we know that Ukraine has been dealing with really persistent and oftentimes brutal attacks for years now, including not only cyberattacks, but drones, missile strikes, et cetera. A lot of these have been targeted toward civilian infrastructure that Ukrainian citizens rely on every day.
Tell this audience what that means in practice for civilians who depend on hospitals, utilities, and public services. Specifically, when we're talking about cyber, because of course that's what we're here to talk about today, give us some examples of what it takes on the part of the Ukrainian government and Ukrainian public services to keep those services running under these persistent cyberattacks.
05:39 Dmytro Kushneruk
Thank you. First of all, I want to thank OpenAI for bringing Ukraine into this very important initiative and, most importantly, for approaching it in a very practical partnership focusing on protecting and defending civilian infrastructure. This is very valuable for us, because for Ukraine, cyber resilience is really not about protecting computers. It is about actually keeping our country running.
We started experiencing that long before, maybe ten years ago, when there was a big cyberattack on our electricity infrastructure, which affected a lot of people. At the time, we were maybe not so prepared. Then we had quite a large incident last year when there was a big cyberattack on our railway system, which affected people immediately, and we were more prepared. Actually, the trains kept running, but the online systems were gone, and it took time to restore them.
There was also a large, famous attack on one of our mobile operators, Kyivstar, which affected a lot of people. A lot of different services were connected to that, so it really required a lot of effort from our government structures to fight that.
Sometimes the Russians combine cyberattacks and missile attacks. Just this morning, they attacked our intranet node in Kyiv, in the capital, which already affected the work of some of the — And the attack, I mean, was by missile. So this is a combination of cyber and physical attacks, which brought some disruptions to the work of our internet providers.
What our government does is try to create a decentralized architecture, so government data flows across different distributed, encrypted registers. If you attack one of those, they will not be able to disrupt. We also have some lessons learned, and we have national roaming. For example, if one mobile operator is targeted, then the users can just switch to another one immediately. So the work of hospitals, of everything, is continuous.
It's not a matter of whether you will be attacked, whether you will be penetrated or not. Yes, you will be. But definitely, you've got to prepare for that, and hopefully, with the work with OpenAI it will be helpful. We can do that more effectively.
08:09 Sasha Baker
I remember there was a sort of meme going around in the U.S. system for a while about the fact that, despite the persistent attacks that the Ukrainian civil services were under, your trains were still running on time more often than, frankly, the Amtrak between D.C. and New York. Not that I'm paying any attention to that.
Andy, I want to ask you, based on your—you've just come out of the White House, and I know you've thought deeply about these questions. Talk to the audience a little bit about whether you believe it's in the U.S. interest to help partners around the world, like Ukraine or others, defend themselves from these kinds of cyber activities, and if so, why.
08:57 Andy Baker
Thanks very much. It's great to be here. Thank you very much for having me here, Sasha. It's good to see you all this morning. Thank you.
Look, I would tend to turn that question on its head a little bit. I think it's important to see artificial intelligence for what it is, which is an immense opportunity. This is an emerging general-purpose technology. This is going to be key to human flourishing in the twenty-first century. So I think it's critical not just to focus on cyber defense and cybersecurity, but to think about artificial intelligence and how the entire world is going to need to use, embrace, and adopt artificial intelligence for a whole host of purposes, many of which are yet to be discovered.
I think this is a technology that has the opportunity to revolutionize how humans do business in virtually every endeavor. Thinking about it as something that really should be available universally and worldwide is critically important.
Now, cyber defense and cybersecurity are a critical component of everything that we need to do, but I think it's important to put that in perspective as well. Artificial intelligence, in many ways, is a process. It's an accelerating process. But it's important to recognize we have some time. We have time to adapt. We have time to figure out ways to use it in a way that's productive, in a way that's beneficial.
I think it's important to balance those two things. You have, on the one hand, a huge opportunity available to us. We want to make sure that we seize that opportunity. We want to make sure that other people can seize that opportunity. No need to panic about the cybersecurity aspect of it. This is something that we can adopt, something that we can embrace alongside the technology as we advance alongside it.
10:39 Sasha Baker
Yeah. We were talking just back in the green room about a number of these topics. I was at an event yesterday that was more focused on biotechnology than on cyber, but I was talking with a scientist who reminded me that every technological advancement is disruptive in its own way and has the risk profile and also the opportunity profile. So that's a point well taken.
Naz, I want to turn to you. You're a veteran of the Hill. You have the scars, I'm sure, to show for it. Talk to us a little bit about where you see opportunities for bipartisan consensus on the questions, particularly about cybersecurity for critical infrastructure, if you see them.
11:25 Naz Durakoğlu
Sure. Sasha, thank you again for having me as well. I have some good news. The Hill actually does understand that this is an issue. While there's obviously a debate on regulation, and that's speeding up right now, and there are differences in view, when it comes to protecting critical infrastructure and even assisting our allies and partners, it's pretty much across the board. There is agreement that we need to do that.
There is actually legislation that has advanced through our committee, the U.S. Tech Path Act. Senators Shaheen and Ricketts are the original cosponsors. That would expedite technology, particularly cyber resilience technology, into the hands of our allies and partners.
This is something that's already happening. Frankly, it's just a basic duty of government to make sure that when you turn the tap on, water comes out, the electricity doesn't go out, and hospitals keep running and treating patients. There is a broad understanding that this is a major issue.
I will say, seeing what Ukraine has to go through day to day is also a huge wake-up call to our members on a bipartisan basis. So there's already a lot of activity there, a lot of conversation, and it's just a matter of getting it across the finish line, which is more a product of committee jurisdictional problems than a lack of bipartisanship or attention on these issues.
12:47 Sasha Baker
What chances do you give it of passage?
12:49 Naz Durakoğlu
Our bill that I referenced, probably—well, because the—oh, man. You're going to get me into the weeds on things that I'm going to not go into. But, because, like, the 10,000-foot—
13:01 Sasha Baker
Not the 30,000.
13:02 Naz Durakoğlu
So we're having defense authorization conversation issues at the moment, not related to—
13:08 Sasha Baker
Everything rides on the NDAA.
13:09 Naz Durakoğlu
Yeah. But I do think that this is a new bill, and frankly, it's gotten a lot of attention. I do think, maybe not this year, but folks will build on it and probably make it even more important going forward. I think it'll probably eventually pass in the next two to three years.
But right now, I don't think it's the time for it, not because it's not an important issue, but because there's a war going on. The defense authorization has become a problematic piece of legislation right now.
13:43 Sasha Baker
Dmytro, I want to turn back to you. Where, from your perspective, do you think using AI could make the biggest difference for the Ukrainian government? I know you all have been—and we were just talking about this—your president even is very interested in AI. How are you thinking about using these tools to improve Ukraine's circumstances?
14:10 Dmytro Kushneruk
Yeah, definitely. The president is really interested in this topic.
14:15 Sasha Baker
I didn't ask you which AI tool he was using, and I won't do that. We'll just assume.
14:20 Dmytro Kushneruk
But he really is interested in these events that we're having today, for real. For Ukraine, of course, data protection, because of state data, is super important, and it has to be 100% protected.
Our CERT-UA, it's like our cyber center of response. We're registering about 6,000 cyberattacks per year, about 15 per day. These are serious attacks. Of course, we know where it's coming from. AI and agents are super vital to automate this threat triaging and log analysis at machine speed. So speed is really, really important. Traditionally, it takes time for humans to react.
Definitely, we think that AI can help inventory systems, analyze code, validate whether a vulnerability is really exploitable, prioritize the systems that matter most, assist engineers in developing the patch, and all of that. It's not just finding vulnerabilities; the real value is reducing the time between discovery and fixing the problem.
The second opportunity is incident response, because humans see thousands and thousands of these logs, and they have to find what's really important. AI can give capable defenders a much greater advantage, like leverage. This is why the objective is not to replace the cyber defender with AI, but to make sure that the cyber defender acts faster, is more informed, and is much more capable.
16:13 Sasha Baker
That's great. Andy, I was just up at the podium talking about this idea of the defender's window. I want to ask you: What do you think is going to happen in terms of the balance between defensive and offensive AI-enabled cyber? What steps can we as a technology company, or governments, be taking to better advantage the defender?
16:40 Andy Baker
Thank you very much. I do actually want to go back to one thing Dmytro said, which is critically important. I would just summarize it as: The answer to agentic AI is going to be even more agentic AI. This goes back to the point I was making earlier about opportunity and how important this is as an opportunity. Of course, we have to think about the risk. We have to think about the challenges, but the opportunity is core.
Now, when you talk about the defender's window, you talk about the balance between offense and defense. I think the critical thing to recognize is we're in this moment. We have this window because the United States is winning right now. Because the United States is ahead, because the United States is in the lead, we have a window to defend our companies. We have a window to defend partners and allies. We have a window to prioritize defense over offense. That race is not a value-neutral proposition.
If the shoe were on the other foot, if we had a different situation, I don't think we'd be talking about a defender's window. We would be in a much, much worse situation. There's this fashionable notion out there in Washington, on the East Coast, maybe across the United States, maybe across the Western world, that somehow it's a good thing, this balancing between the United States and China. Like I said, that's not a value-neutral proposition.
Anybody who cares about democracy, anybody who cares about freedom, anybody who cares about the defense of free societies, anybody who cares about our way of life should be invested in the United States going as far and as fast with this technology as is possible. They should be invested in the United States winning. That's how we keep that defender's window open. That's how we protect our societies.
18:18 Sasha Baker
Thanks, Andy. Naz, I want to ask you again, drawing on your background both at the State Department and in Congress: What do you wish technology companies like OpenAI or our peer labs better understood about the way government is processing this new technology and grappling with the implications, from a policy perspective, of how to manage some of the questions that Andy just referenced?
Another way of asking that question is basically: What are we doing that annoys you or that we're doing wrong? What do you want us to fix?
19:00 Naz Durakoğlu
We talked about this a little bit earlier. I think most people who've worked in government or worked with government recognize that it works at a different pace, particularly than the private sector. So I think you always have to keep that in mind.
The best engagement—congressional engagement, government relations—doesn't wait for a crisis. It's a relationship based on trust. It's a relationship that's been developed over time. Frankly, government and the private sector need each other on this issue. Government has insights, intelligence, and other information that the private sector doesn't have, and the private sector has these capabilities. It's working on all these things and developing these tools in a manner that government needs to always stay informed.
I have to say, I think there's never enough communication on this issue. More communication really is better. We were talking in the back room—the company, the frontier lab, will go unmentioned—but there was a time where we reached out. It's not OpenAI, though. We reached out to a company as a committee, and we were told, “Hey, look at our blog.” We were kind of like, “This is how you're going to carry out your engagement here?” I'd really recommend against that.
Again, these relationships are based on trust, so don't wait for a crisis. We need to be talking sooner. I think that's applicable to foreign governments as well. They need to understand these things, and they also need to trust that American companies will be there for them in a time of crisis. I hate to say it, but politics, foreign policy, and commercial policy are not all that different from each other. Allies need to know that we're going to be there for them.
20:46 Sasha Baker
Yeah. We hear that as we engage with governments around the world: Building relationships of trust before there is a moment of crisis—and we hope to avoid the moment of crisis entirely—is key to how we show up. So thank you for that.
I want to ask you all the same question here, which is the following: What is, in your view, one thing that governments or technology companies should be trying to do now to help protect critical infrastructure that might be vulnerable to cyberattack? Do you want to go first?
21:32 Dmytro Kushneruk
Yeah. I would agree absolutely with what Naz just said: Cybersecurity is not purely a technical function, because it affects everything. That means that we have to bring the government and the private sector together before the incident happens.
This is one of the reasons we think Ukraine can actually be valuable to OpenAI as well, because we have such great—I mean, it's awful, but great—expertise in fighting these cyberattacks. A laboratory can tell you whether a technology works or not, but Ukraine can help show you whether it works when the threat is real, is super real.
We see it as basically a genuine two-way cooperation with OpenAI. Once OpenAI brings frontier AI, it gives it into the hands of defenders who do that every day. We can give them the best tool. We can train them together. Ukraine brings the frontline experience. If we combine all these together successfully, the lessons should be useful for Ukraine and for all our partners around the world.
22:41 Naz Durakoğlu
I would just say, again, in Congress, we are looking at some of what the frontier labs are saying in terms of the emerging capabilities and what that might mean for our societies and for our people. This gets to Andy's point a little bit too. I would say that's a really important conversation. I'm glad it's happening. I actually think it's probably taking place a little too late.
But at the same time, I hope that while we're looking at regulations, export controls, this type of architecture, we don't lose sight—and particularly lose time—when it comes to protecting and advancing these defensive capabilities. I think it's really, really important to have those conversations in parallel.
We have to be very, very careful when it comes to losing sight of the importance of AI in defending critical infrastructure, because there's a lot that can be offered there. Again, I just want to make sure that those two paths are going in coordination and parallel to each other, and we're not missing one over the other.
23:45 Andy Baker
I think Naz makes a really important point, which is that, fundamentally, we need to have a conversation about what we want to use this technology for. That's something that we shouldn't lose sight of. We have to work together if we're going to defend our society. We have to work together if we're going to succeed with this technology.
But there needs to be room for thought and for a thoughtful conversation about what is the end, what is the goal of the technology. I think artificial intelligence—or superintelligence, rather—is incredibly fascinating precisely because it can be engaged in so many different areas of human endeavor. You're going to see a lot of differentiation as it's applied to different sectors of the economy and different sectors of our society.
But there does need to be a fundamental question about whether we are using this technology to uphold our values. Are we using this technology to uphold the citizenry of a free society? Are we using this technology to uphold the values of a free society? I think that if you have that social engagement, if you actually have that consensus-building function, that's really critical to a successful defense of your society.
24:51 Naz Durakoğlu
Can I say one more thing?
I also think that everybody in this room, if you're not doing it, you really, really need to be paying attention to what is happening in Ukraine day to day, because that is where the lessons learned are. That is where we're going to be learning how to defend our own infrastructure and how we can actually do that at pace with some of the technological advancements. Ukraine is just such an extraordinary example. So I would say, to the extent that you can, every day, look at what's happening there, because it's really, really important to learn from the Ukrainians.
25:26 Sasha Baker
Yeah, that's actually a great transition. Dmytro, I'm going to give you the opportunity to wrap us up here. The last question: What is it that you hope Ukrainian cyber defenders may be able to do a year from now that they're not able to do today?
25:42 Dmytro Kushneruk
Well, I guess I already mentioned that we will be able to do everything we already do, but more effectively. I had a conversation with our Ministry of Digital Transformation team, because they're really looking forward to starting this partnership, expanding the partnership. Eventually, we would like to have OpenAI in Ukraine, because it would also be a good gesture as well.
26:13 Dmytro Kushneruk
Okay, we're looking forward to that as well. In practical terms, that will give our cyber defenders, who have big experience, but they will be—it's like the United States is providing arms and weapons to Ukraine to fight on the battlefield. With such a tool, an AI tool could also be given from the United States to Ukraine to fight in cyber.
26:38 Sasha Baker
Yeah, that's a great way to wrap this up. Thank you to our panelists for participating this morning. Thank you all for, as I said, getting up early and joining us here at the OpenAI office. We will stick around for a few minutes. If folks have questions, feel free to come up and mingle. Otherwise, thanks for joining us.