Cairncross acknowledges AI risks but warns tighter oversight could slow innovation

Andrew Harnik/Getty Images

The national cyber director said developers are strengthening safeguards after a series of unauthorized AI intrusions, while defending the administration’s push for rapid deployment.

National Cyber Director Sean Cairncross said Thursday that advanced artificial intelligence poses legitimate safety risks, but he argued that closer work with developers and stronger technical safeguards can address those dangers without slowing deployment.

Speaking at The Washington Post’s AI Edge Summit, Cairncross defended the Trump administration’s approach as he faced questions about whether even responsible developers can prevent their systems from acting beyond human control.

The issue has gained urgency following a smattering of incidents in which AI agents took unauthorized actions, prompting global debate over whether safeguards are keeping pace with the technology.

“There are legitimate risks,” Cairncross said, describing the technology as both new and powerful. He also pointed to its defensive benefits, saying companies were using AI to find and repair security weaknesses at a scale they had not previously achieved.

His remarks reflected a central tension in the administration’s approach, in which many officials want to contain the risks of increasingly capable AI systems while deploying them quickly enough to protect U.S. networks from cyberattacks and maintain an advantage over foreign adversaries.

The discussion followed Tuesday’s White House meeting with technology executives, where President Donald Trump and industry leaders signed an accord outlining internal safety controls, external audits and independent committee oversight. The agreements put in place are mainly voluntary.

Cairncross said the government has a role in evaluating and testing models, but warned against giving it more direct control over their development.

“Once the government is introduced into this space directly, there is a tendency for government to start to want to adjust the dials directly, and it is difficult to reverse that,” he said, arguing that such intervention could slow innovation.

Much of the questioning centered on the Hugging Face intrusion disclosed this summer, when an OpenAI agent conducting a security evaluation escaped its testing environment and broke into the company’s systems. More recent disclosures have described agents accessing federal data and attempting to break into a government website.

Asked how the public could be confident that developers would prevent another such incident, Cairncross said the Hugging Face episode had heightened awareness and prompted substantial engineering work.

“Ultimately, like any technology, its effects are going to be determined by the people who are in control of it, and it comes down to human decision-making,” he said.

The administration’s June AI security order provides for classified assessments of models’ cyber capabilities and a voluntary framework giving the government access to certain advanced systems up to 30 days before developers release them to other trusted partners. Cairncross described that early access as a way to strengthen defenses across federal systems and critical infrastructure.

His remarks also reflected a change in the administration’s vocabulary. Throughout the discussion, he called AI “superintelligence” or “SI,” following Trump’s order Tuesday directing agencies to use those terms in official communications. The order says the new wording better captures the technology’s advancing capabilities and promise, while applying it to systems already covered by the legal definition of AI.