Search

Search bills, members, committees and pages...

“Artificial Intelligence and Criminal Exploitation: A New Era of Risk”

HearingHouse Judiciary Subcommittee on Crime and Federal Government SurveillanceJul 16, 2025 · 10:00 AM

Summary

House Judiciary Subcommittee on Crime and Federal Government Surveillance held a hearing on Jul 16, 2025 at 10:00 AM in Rayburn House Office Building, Room 2141, rescheduled. 4 witnesses appeared.


Record

The meeting has its video, its transcript, witnesses and documents on the record.

Video

The proceedings, as the committee streamed them.

Transcript

The transcript runs to 1,585 lines and 84,160 characters, as the Government Publishing Office printed it.

house-hearing-61182.txt
1[House Hearing, 119 Congress]2[From the U.S. Government Publishing Office]34                  ARTIFICIAL INTELLIGENCE AND CRIMINAL5                    EXPLOITATION: A NEW ERA OF RISK67=======================================================================89                                HEARING1011                               BEFORE THE1213                    SUBCOMMITTEE ON CRIME AND FEDERAL14                         GOVERNMENT SURVEILLANCE1516                                 OF THE1718                       COMMITTEE ON THE JUDICIARY1920                     U.S. HOUSE OF REPRESENTATIVES2122                    ONE HUNDRED NINETEENTH CONGRESS2324                             FIRST SESSION2526                               __________2728                        WEDNESDAY, JULY 16, 20252930                               __________3132                           Serial No. 119-313334                               __________3536         Printed for the use of the Committee on the Judiciary3738                 [GRAPHIC NOT AVAILABLE IN TIFF FORMAT]3940               Available via: http://judiciary.house.gov4142                               ______4344                 U.S. GOVERNMENT PUBLISHING OFFICE454661-182                    WASHINGTON : 20254748                       COMMITTEE ON THE JUDICIARY4950                        JIM JORDAN, Ohio, Chair5152DARRELL ISSA, California             JAMIE RASKIN, Maryland, Ranking53ANDY BIGGS, Arizona                      Member54TOM McCLINTOCK, California           JERROLD NADLER, New York55THOMAS P. TIFFANY, Wisconsin         ZOE LOFGREN, California56THOMAS MASSIE, Kentucky              STEVE COHEN, Tennessee57CHIP ROY, Texas                      HENRY C. ``HANK'' JOHNSON, Jr.,58SCOTT FITZGERALD, Wisconsin              Georgia59BEN CLINE, Virginia                  ERIC SWALWELL, California60LANCE GOODEN, Texas                  TED LIEU, California61JEFFERSON VAN DREW, New Jersey       PRAMILA JAYAPAL, Washington62TROY E. NEHLS, Texas                 J. LUIS CORREA, California63BARRY MOORE, Alabama                 MARY GAY SCANLON, Pennsylvania64KEVIN KILEY, California              JOE NEGUSE, Colorado65HARRIET M. HAGEMAN, Wyoming          LUCY McBATH, Georgia66LAUREL M. LEE, Florida               DEBORAH K. ROSS, North Carolina67WESLEY HUNT, Texas                   BECCA BALINT, Vermont68RUSSELL FRY, South Carolina          JESUS G. ``CHUY'' GARCIA, Illinois69GLENN GROTHMAN, Wisconsin            SYDNEY KAMLAGER-DOVE, California70BRAD KNOTT, North Carolina           JARED MOSKOWITZ, Florida71MARK HARRIS, North Carolina          DANIEL S. GOLDMAN, New York72ROBERT F. ONDER, Jr., Missouri       JASMINE CROCKETT, Texas73DEREK SCHMIDT, Kansas74BRANDON GILL, Texas75MICHAEL BAUMGARTNER, Washington7677                                 ------7879                   SUBCOMMITTEE ON CRIME AND FEDERAL80                        GOVERNMENT SURVEILLANCE8182                       ANDY BIGGS, Arizona, Chair8384TOM TIFFANY, Wisconsin               LUCY McBATH, Georgia, Ranking85TROY NEHLS, Texas                        Member86BARRY MOORE, Alabama                 JARED MOSKOWITZ, Florida87KEVIN KILEY, California              DAN GOLDMAN, New York88LAUREL LEE, Florida                  STEVE COHEN, Tennessee89BRAD KNOTT, North Carolina           ERIC SWALWELL, California9091               CHRISTOPHER HIXON, Majority Staff Director92                  JULIE TAGEN, Minority Staff Director9394                            C O N T E N T S9596                              ----------9798                        Wednesday, July 16, 202599100                           OPENING STATEMENTS101102                                                                   Page103The Honorable Andy Biggs, Chair of the Subcommittee on Crime and104  Federal Government Surveillance from the State of Arizona......     1105The Honorable Lucy McBath, Ranking Member of the Subcommittee on106  Crime and Federal Government Surveillance from the State of107  Georgia........................................................     3108109                               WITNESSES110111Dr. Andrew S. Bowne, Professor, George Washington University112  Oral Testimony.................................................     5113  Prepared Testimony.............................................     8114Zara Perumal, Chief Technology Officer, Overwatch Data115  Oral Testimony.................................................    24116  Prepared Testimony.............................................    26117Cody Venzke, Senior Policy Counsel, National Political Advocacy118  Division, American Civil Liberties Union119  Oral Testimony.................................................    40120  Prepared Testimony.............................................    42121Ari Redbord, Global Head of Policy, TRM Labs122  Oral Testimony.................................................    72123  Prepared Testimony.............................................    74124125          LETTERS, STATEMENTS, ETC. SUBMITTED FOR THE HEARING126127All materials submitted by the Subcommittee on Crime and Federal128  Government Surveillance, for the record........................   104129130Materials submitted by the Honorable Lucy McBath, a Member of the131  Committee on the Judiciary from the State of Georgia, for the132  record133    A letter to Speaker Mike Johnson, Minority Leader Hakeem134        Jeffries, Majority Leader John Thune, and Minority Leader135        Chuck Schumer, from the National Association of Attorneys136        General, May 16, 2025137    An article entitled, ``Inside Congress Live,'' Jun. 27, 2025,138        Politico139    A testimony from Barry Friedman, Jacob D. Fuchsberg Professor140        of Law and Affiliated Professor of Politics, Faculty141        Director, Policing Project, New York University School of142        Law, Jul. 16, 2025143    A letter to the Honorable Andy Biggs, Chair of the144        Subcommittee on Crime and Federal Government Surveillance145        from the State of Arizona, and the Honorable Lucy McBath,146        Ranking Member of the Subcommittee on Crime and Federal147        Government Surveillance from the State of Georgia, from148        PublicCitizen, Jul. 16, 2025149    A testimony from Keith Kupferschmid, Chief Executive Officer,150        Copyright Alliance, Jul. 16, 2025151An article entitled, ``The countdown to artificial152  superintelligence begins: Grok 4 just took us several steps153  closer to the point of no return,'' Jul. 12, 2025, The Blaze,154  submitted by the Honorable Andy Biggs, Chair of the155  Subcommittee on Crime and Federal Government Surveillance from156  the State of Arizona, for the record157158                                APPENDIX159160A statement from the Honorable Jamie Raskin, Ranking Member of161  the Committee on the Judiciary from the State of Maryland, Jul.162  16, 2025, for the record163164                  ARTIFICIAL INTELLIGENCE AND CRIMINAL165                    EXPLOITATION: A NEW ERA OF RISK166167                              ----------168169                        Wednesday, July 16, 2025170171                        House of Representatives172173       Subcommittee on Crime and Federal Government Surveillance174175                       Committee on the Judiciary176177                             Washington, DC178179    The Subcommittee met, pursuant to notice, at 10 a.m., in180Room 2141, Rayburn House Office Building, the Hon. Andy Biggs181[Chair of the Subcommittee] presiding.182    Members present: Representatives Biggs, Kiley, Lee, Knott,183and McBath.184    Also present: Representative Raskin.185    Mr. Biggs. The Subcommittee will come to order. Without186objection, the Chair is authorized to declare a recess at any187time. We welcome everyone to today's hearing on Artificial188Intelligence and Criminal Exploitation.189    I now recognize the gentlewoman from Florida, Ms. Lee, to190lead us in the Pledge of Allegiance.191    All. I pledge allegiance to the Flag of the United States192of America, and to the Republic for which it stands, one193Nation, under God, indivisible, with liberty and justice for194all.195    Mr. Biggs. Thank you. I now recognize myself for an opening196statement. I appreciate everyone being here today, our197witnesses, and those in the audience. This is an important198hearing which focuses on artificial intelligence and how it is199being exploited by criminals. The conceptual roots of AI can be200traced to British mathematician Alan Turing when the 1930s201theorized about a machine being capable of performing any202computable task. Today, AI is best understood as a branch of203computer science that leverages large scale data processing,204algorithmic modeling, and modern hardware to enable machines to205perform tasks typically requiring human cognition.206    Unfortunately, like most technical innovations, the207criminal element has begun to use AI to enhance their elicit208activities. The AI-enabled threats continue to evolve as bad209actors use AI technology in a wide spectrum of criminal210enterprises. From deepfake scams and synthetic identity fraud211to financial crimes and child sexual abuse material, CSAM, the212landscape continues to evolve at a rapid pace as AI provides213users with enhanced capabilities. The AI-based or AI-driven214threats and schemes can cost businesses millions of dollars a215year including both prevention and falling prey to them. In one216case, fraudsters used AI to clone a CEO's voice and authorized217a wire transfer. Among corporations that experienced a rise in218deepfake incidents, 75 percent of deepfakes impersonated a CEO219or another C suite executive.220    Generative AI enables the criminal exploitation of victims'221emotional vulnerabilities through tactics such as sextortion,222pig-butchering scams, phishing, and elder fraud. Senior223citizens are increasingly targeted through voice phishing scams224where an AI-generated replica of a grandchild or military225officer claims to need urgent funds. In one case, a Colorado226mother received a call from what sounded like her daughter227pleading for help. The voice was AI generated, closed from a228short, online clip and used to demand ransom. The voice was229indiscernible to the mother who wired $1,000 to scammers in230Mexico.231    AI is also fueling a rise in sextortion and synthetic CSAM.232New AI tools can generate highly realistic, but entirely233fabricated explicit images often used to extort minors or234damage reputations. Some sextortion scams exploit the trust235associated with platforms like Apple's iMessage by236impersonating classmates or romantic interests via recognizable237blue bubble interfaces. Criminals now deploy apps like Muah to238fabricate child abuse images at scale. Stanford University239researchers have uncovered evidence that generative models were240trained on real exploitative content.241    Terrorist groups now utilize AI to target, recruit, and242indoctrinate vulnerable individuals. Generative AI provides a243degree of separation, allowing actual terrorists to maintain244anonymity in their public facing recruiting practices.245Generative AI also allows terrorists to produce propaganda,246fake news stories, and emotionally resonant messages tailored247to specific psychological profiles.248    Reports of generative artificial intelligence enabled scams249between May 2024-May 2025 rose by 456 percent. The use of250exploi-251tive generative AI allows criminals to produce human-like text,252code, images, and videos allowing criminals to use the253technology for further criminal activity such as creating more254realistic phishing lures or generating deepfakes for extortion.255    On average, phishing attacks cost $4.9 million per breach.256On the other hand, AI is increasingly integrated into police257investigations offering new tools and capabilities for law258enforcement agencies into the backdrop of rapidly expanding259digital data sources and increasing demands on law enforcement260agencies. AI provides a more adaptable and comprehensible261approach to solving crimes, compared to traditional methods262leveraging data analytics, machine learning, and pattern263recognition to enhance investigations and assist with264administrative tasks. This is also potentially a problem, as265well, as we seek to balance curbing AI with our civil rights.266    AI can also help process large volumes of data, identify267patterns, and generate actionable insights, and in turn, these268applications can improve efficiency, accuracy, and resource269allocation with investigative processes. However, to fully270benefit from AI applications, law enforcement entities need271reliable data, human oversight, while also tackling issues272related to privacy, bias, and ethical considerations.273Addressing the continued misuse of AI will require a varied274approach while also raising public awareness about the risks275associated with AI-generated content.276    Law enforcement agencies must engage openly with community277stakeholders, legal experts, and the public to communicate the278intended uses, benefits, and limitations of AI technologies.279The collaborative effort to both prevents the misuse of AI280while encouraging lawful application is required to effectively281navigate this evolving landscape.282    I am excited about today's hearing. I think this is the283first of its kind. I believe it will be only the first of its284kind as we consider AI and its continued expansion of influence285on our lives. I am looking for a very substantive discussion--I286anticipate a substantive discussion that we are going to have287today and with that, I yield back and recognize now our Ranking288Member, Ms. McBath, for her opening statement.289    Ms. McBath. Well, thank you so much, Mr. Chair, and thank290you to our witnesses today. Thank you so much for taking291moments out of your day to come before us. Thank you for292convening this hearing to discuss AI-enabled crime, efforts to293detect and combat such crime, and how law enforcement deploys294AI tools.295    Like so many new technologies, AI is not inherently good or296bad. The AI-enabled tools can find patterns, sort through vast297amounts of information, and may even help law enforcement solve298their crimes. In the wrong hands, the same tools can be used to299commit financial fraud, breach national security systems, and300to harm our children. When used by law enforcement, this301technology has the potential to empower our investigators,302while also carrying the risk of serious errors with life-303changing consequences. That is why it is critical that we304proceed thoughtfully and put appropriate guardrails in place so305that everyone in our criminal justice system that is using AI-306enabled tools, they are using them responsibly, not to the307detriment of law-abiding members of our community.308    You have already seen what can go wrong when those309safeguards are missing. A woman and her family experienced the310dangers of using AI enabled facial recognition technology.311Detroit police used a facial recognition tool in an attempt to312identify a carjacking suspect using an image from a313surveillance camera. The tool matched the surveillance image314with a picture of Porcha Woodruff, a nursing school student.315One morning, as Ms. Woodruff was getting her two children ready316for school, the police knocked on her door and they told her317that she was under arrest for carjacking. She knew right away318there must be some kind of mistake, and she gestured at her319body as she spoke to law enforcement to point out the obvious,320she hoped, to law enforcement that she was eight months321pregnant. Though the police had not been looking for a visibly322pregnant woman, they still handcuffed Ms. Woodruff, took her323away from her crying children, held her for 11 hours, searched324her phone, and they charged her. After her release, she went325straight to the hospital and was treated for dehydration. The326charges were dismissed a month later.327    This case is especially troubling because facial328recognition tools have been shown to perform worse on Black329individuals, increasing the risk of misidentification and330contributing to over criminalization. AI is only as good as the331data is it trained on and when that data is biased, it332exacerbates racial disparity, long embedded in our criminal333justice system, and an inaccurate tool is dangerous for every334single one of us. Not one of us is immune to these mistakes.335    Thankfully, and in due part to cases like this one, the336city of Detroit has adopted new rules to direct the use of337facial recognition technology within its police department, and338they are simply not alone. Many cities and states have put339sensible guardrails in place to limit potentially harmful uses340of AI. That is why it was alarming when some of my Republican341colleagues recently attempted to pass a moratorium on State and342local AI regulations in the big ugly bill, a move that343generated bipartisan opposition so much that 40 State Attorney344Generals and 17 Republican Governors, including the Governor of345my State, Georgia, wrote letters to the Senate in opposition to346the proposed moratorium. The Governors warned that, and I am347quoting them, ``People will be at risk until basic rules348ensuring safety and fairness can go into effect.''349    As you will see behind me, Sarah Huckabee Sanders, the350Republican Governor of Arkansas and former press secretary to351President Trump, took to Twitter to quote,352353        I stand with the Majority of GOP Governors against stripping354        States of the right to protect our people from the worst abuses355        of AI. The U.S. must win the fight against China on AI and356        everything else, but we won't if we sacrifice the health,357        safety, and prosperity of our people.358359    While this most recent proposal was ultimately stripped360from the bill by a 99 to one vote of the Senate, the Republican361Chair of the House Energy and Commerce Committee has already362vowed to continue to pursue a moratorium, even while363acknowledging that Federal regulations on AI are still light364years away.365    I stand with those seeking to protect the health and the366safety and civil rights of our communities from the abuses of367AI and I hope that we can come together and follow the lead of368the States to explore what those guardrails should look like369and put them in place.370    I look forward to learning more from our experts here371today. Hearing from you is going to be extremely critical for372us on this very important issue.373    Before I yield, Mr. Chair, I ask unanimous consent to enter374into the record two letters. The first is a letter from 17375Republican Governors in opposition to a moratorium on State and376local regulation on AI; and the second, a letter from 40 State377Attorneys General, both Republicans and Democrats, in378opposition to a moratorium on State and local regulation of AI.379    Mr. Biggs. Without objection.380    Ms. McBath. I yield.381    Mr. Biggs. The gentlelady yields. Without objection, all382other opening statements will be included in the record. We383will now introduce today's witnesses, and we are very grateful384for our witnesses.385    Dr. Andrew Bowne.386    Dr. Bowne. Bowne.387    Mr. Biggs. Bowne, OK. Dr. Bowne is a Professorial Lecturer388in Law at the George Washington University Law School where he389teaches courses on artificial intelligence law and policy. He390has served in the United States Air Force Judge Advocate391General Corps since 2010 and previously serves as the Chief392Legal Counsel of the Department of the Air Force Artificial393Intelligence Accelerator at the Massachusetts Institute of394Technology.395    Thank you, Doctor, for being with us today.396    Ms. Zara Perumal is the Co-Founder and Chief Technology397Officer of Overwatch Data, an artificial intelligence company398focused on threat intelligence and cybercrime tactics on the399dark web. Prior to founding Overwatch Data, she worked at400Google on matters involving machine learning and cyber security401threats.402    Thank you for you being us today, Ms. Perumal.403    Mr. Ari Redbord is the Global Head of Policy at TRM Labs, a404company focused on preventing illicit financial activity. He405previously served as Senior Advisor to the Deputy Secretary and406Under Secretary for Terrorism and Financial Intelligence at the407U.S. Treasury. Prior to Treasury, he was an Assistant U.S.408Attorney where he focused on terrorism, espionage, financial,409child exploitation, and human trafficking cases.410    Thank you, Mr. Redbord, for being with us today.411    Mr. Cody Venzke is a Senior Policy Counsel in ACLU's412National Political Advocacy Department where his work focuses413on surveillance, privacy, and technology. Specifically, he414works on matters related to artificial intelligence, privacy,415children's privacy, and civic uses of data.416    Thanks, Mr. Venzke, for being with us today.417    We appreciate all of you being here and now ask that you418please rise so you can be sworn in.419    Would you please raise your right hand? Do you swear or420affirm under penalty of perjury that the testimony that you are421about to give is true and correct to the best of your422knowledge, information, and belief so help you God?423    Let the record reflect the witnesses have answered in the424affirmative and thank you, you may be seated. Please know that425your written testimony will be entered into the record in its426entirety. Accordingly, we ask that your testimony be summarized427in five minutes and what is going to happen, just so you know,428is about 15 seconds before the end, you will start hearing429this, something like that, and then at the magic moment, I will430start getting a little bit louder, but it will kind of help you431wrap up on time, so we can work this out. We are so grateful432that you are here.433    Mr. Bowne, you may begin with your five minutes.434435                  STATEMENT OF ANDREW S. BOWNE436437    Dr. Bowne. Thank you, Mr. Chair, Ranking Member, and the438distinguished Members of the Subcommittee. Thank you for the439opportunity to testify to the intersection of artificial440intelligence and criminal exploitation.441    My name is Andrew Bowne. I serve as a Professorial Lecturer442at the George Washington University Law School where I teach443courses on AI law and policy. I have served in the United444States Air Force Judge Advocate Generals Corps since 2010445including assignments as a prosecutor, a staff Judge Advocate446General Counsel Air Force installation, and as you heard, a447Chief Legal Counsel for the Air Force's AI Accelerator at MIT.448    I do appear today in my personal capacity. The views I449present are my own and do not necessarily reflect those of the450Department of Defense, the Department of the Air Force, or the451Judge Advocate Generals Corps.452    AI is both a catalyzing and transformative technology453enabler, a solver of traditional processes, but also creates454entirely new ones. When a task AI is used for is criminal or455harmful, the nature of AI becomes a threat multiplier. The AI456systems now automate decisions, model environments, and infer457actions of unprecedented speed, and scale. While they are458designed to benefit society, their dual-use nature means they459could also facilitate exploitation, fraud, and abuse. Even AI460systems designed with legitimate use in mind can create harm if461not carefully designed and deployed with safety, ethics, and462accountability built in.463    Today, I would like to briefly highlight how AI enables464criminal activity, the gaps in current criminal law, and465proactive steps Congress might take. First, how AI enables466criminal activity. I am seeing really three categories of AI467developments that are of particular concern in this area:468Computer vision, generative adversarial networks, or GANS, and469large language models, or LLMS.470    Computer vision systems which interpret visual data are471used to automate surveillance, identify targets, and even472harvest personal data from breached documents for identity473threat and fraud or enable real time threat detection for474public safety that can be repurposed to stalk or blackmail475individuals with chilling efficiency. GANs are capable of476generating synthetic images, videos, and audio that are known477in public discourse as deepfakes. These tools allow the478impersonation of public officials and private citizens alike.479Multiple watchdogs and law enforcement agencies that have been480conducted longitudinal analysis on AI generated child sexual481abuse material or CSAM are reporting rapid rises in the number482of generated images shared online. Perhaps more concerning is483that the increased capabilities of sophistication of generative484AI models enable them to produce very realistic images.485    Generative AI tools are also used for sextortion, grooming,486and emotional coercion, often targeting children. Large487language models like those powering chatbots revolutionizing488phishing, fraud, and social engineering involve misinformation.489They engage victims and extend realistic conversations, target490elderly people and vulnerable people in scams or overwhelming491financial institutions of thousands of tailored loan492applications. They are also used to generate malicious code,493making cybercrime accessible to individuals with no technical494background. In short, deepfakes, AI generated CSAM, and495automated fraud are not theoretical threats. They are real,496growing, and causing harm now. The barrier to entry to using AI497to perpetuate or perpetrate is low. Anyone with a few seconds498of your voice or image can create convincing synthetic content499without coding or expensive hardware. The tools are cheap,500accessible, and often unregulated.501    Tragically, gaps in current Federal criminal law allow bad502actors to use AI to profit at the expense of others, prey on503the vulnerable or create mistrust with impunity. While there504are statutes for wire fraud and child sexual abuse material,505they do apply to many of the AI-enabled crimes, there are506several significant gaps.507    More alarming still are emerging threats such as autonomous508criminal activity, cross-board AI enabled crime, and509algorithmic market manipulation in which criminal liability is510unclear or altogether absent.511    There are a variety of strategies that the Committee, as512well as Congress, can consider, including criminal law reform.513They could define new offenses from malicious use of AI,514particularly deepfakes and AI CSAM. They could also provide515sentencing enhancements for crimes aggravated by the use of AI516tools when those tools augment the scale or impact of the harm517or make it more resource intensive to investigate and518prosecute.519    You could also look at enabling AI safety and transparency520requirements and in conclusion AI is a revolutionary enabler521but does not self-regulate. The bad actors who choose to522exploit the law must be ready. Thank you, Mr. Chair, for the523time.524    [The prepared statement of Mr. Bowne follows:]525526[GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]527528    Mr. Biggs. Thank you, Dr. Bowne, and we have your written529testimony, which is more expansive, so I remind everybody we530have that, so appreciate that.531    Ms. Perumal, we give you your five minutes now.532533                   STATEMENT OF ZARA PERUMAL534535    Ms. Perumal. Chair Biggs, Ranking Member McBath, and the536Members of the Committee, thank you so much for the opportunity537to testify today and for creating this forum to discuss how AI538is changing the landscape of cybercrime. I am honored to share539my perspective on how technology is making these threats more540accessible, more personalized, and more difficult to detect.541    My name is Zara Perumal. I am the Co-Founder and CTO of542OverWatch Data, a cyber threat intelligence company that use AI543to identify and analyze emerging threats in the cybercrime and544fraud ecosystems. Through our work, we see every day how AI is545used to both prevent and also to facilitate criminal activity.546    I would like to focus my remarks today on how we see AI547changing the threat landscape and what we can do about it548through both education and innovation. AI is a powerful,549general-purpose tool with a broad range of applications for550criminal activity and for a broad range of threat actors. It551can be used to learn how to commit crimes, to write code and552craft realistic scam text messages, generate audio or voice553clones, and of course, create deepfake images or videos.554    Across this wide range of malicious use, three trends stand555out.556    First, AI is reducing the barriers to entry for557cybercrimes. Users can ask a chatbot including ones explicitly558designed for fraud how to commit crimes. They can learn the559technical skills they need to carry them out and they can also560use it to make their attacks more convincing and more561effective.562    Second, it is challenging businesses by subverting identity563verification systems. AI can be used to generate a photo for a564fake persona or profile. It can then be used to generate high565quality synthetic fake IDs and then if they are asked to verify566their identity, they can join a video called swap bare face567with their fake photo and verify their access to that business.568This is a problem not just for the specific business that is569being targeted, but it is a problem because it gives them a570foothold from which they can hide their identity for the future571next online crime that they will carry out.572    Third, we see is the crimes that are becoming far more573personalized. For example, voice clones are used to target the574elderly by calling a grandparent and what sounds like their575grandchild's voice and claiming to be in the hospital and in576need and in need of money. Employment scams prey on young577adults who are looking for their first job. One of the most578disturbing cases is the nudifying apps which often target579children. They turn ordinary photos into fake sexually explicit580images which are then used to bully, harass, and extort581victims, in some cases driving them to suicide. This abuse is582carried out to children, both by their classmates and by remote583criminals.584    There is a lot of harm. There is a lot that is changing,585but there is also a lot we can do.586    First, education awareness can prevent and deter many of587these harms. These crimes work because people don't expect588them. If we invest in education across schools, workplaces, and589communities, we can make these crimes less effective and more590costly to carry out.591    Second, we have an opportunity to combat this with592innovation. The same technology that is enabling these crimes,593can also be used to detect scams, find malware, and destruct594cybercrimes. By supporting innovation and strengthening public/595private partnerships, we can shift the technical advantage to596the defenders.597    While AI enables crime to be more accessible, more598personalized, and harder to detect, I remain optimistic. With599the right investment in education and innovation, we can engage600our whole society in building a future where AI expands access601to opportunities, strengthens safety, and helps people spend602more time on what matters.603    On a personal note, it is very exciting to me to see that604Congress is addressing this issue and putting a spotlight on605it. Thank you and I look forward to your questions.606    [The prepared statement of Ms. Perumal follows:]607608[GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]609610    Mr. Biggs. Thank you very much.611    Mr. Venske, you are recognized for your five minutes.612613                    STATEMENT OF CODY VENZKE614615    Mr. Venzke. Chair Biggs, Ranking Member McBath, and the616Members of the Subcommittee, thank you for the opportunity to617testify today on behalf of the American Civil Liberties Union.618    I will address two issues this morning: First, it is619crucial that our response to criminal uses of artificial620intelligence adhere to the Constitution, civil rights, and621civil liberties. Second, efforts by Congress and the622administration must not inadvertently open the door for AI623abuses such as through a moratorium on State regulation of AI624or continuing consolidation of Federal data. With appropriate625measures, Congress can ensure that AI is safe, effective, and626consistent with our rights and liberties.627    First, Congress' measures to address criminal AI must628comport with the Constitution, civil liberties, civil rights,629and privacy. For example, traditional First Amendment630activities do not lose their protection simply because631artificial intelligence was used. Editorial content moderation632using AI is not categorically exempted from the First633Amendment's protections. Neither is commentary on politicians634or candidates for office. Speech about politicians and635candidates, in particular, lies at the heart of the First636Amendment and enjoys special protection. Consequently, courts637have readily and correctly overturned laws prescribing false638speech about politicians and candidates. The emergence and use639of AI does not change the core foundational Constitutional640precepts.641    Likewise, privacy concerns may arise from obligations642imposed on platforms that host and distribute AI systems.643Requirements or incentives to search users' communications, to644restrict their publication of models, code, and data, to645monitor a report their online activity or to prohibit or646undermine encryption, all increase governmental surveillance647and, in some circumstances may violate the Fourth Amendment. As648the Committee considers legislation addressing criminal uses of649AI, we urge you to ensure that speech, privacy, and other650important civil liberties are protected.651    Second, the recently rejected AI moratorium would have652dramatically increased the risk of AI harms including criminal653and fraudulent activity. Similarly, the consolidation of654Federal data is creating enormous risk of AI harms. The655moratorium that was included in versions of the reconciliation656package was sweeping, preempting State laws and local657regulations that regulate AI for 10 years. Although the658moratorium included limited exemptions for some generally659applicable laws, serious questions about the scope and660workability of those exemptions remain. For example, dozens of661States have passed laws regulating deepfake, nonconsensual662intimate imagery often by amending existing statutes to clarify663their application to generative AI.664    Similarly, Tennessee's ELVIS Act extends legal protection665to a person's voice including a simulation of the voice. It is666not clear if such laws with their express application or clear667intent to apply to AI qualify as generally applicable.668Moreover, in many instances addressing AI's harm requires669legislating specifically on AI. Establishment of an AI670moratorium will jeopardize these efforts giving bad actors a671blank check. As Ranking Member McBath recognized, 17 Republican672Governors and members of both parties in both chambers of673Congress oppose the moratorium before Congress stripped it from674the reconciliation package in a 99 to one vote in the Senate.675    The more immediate concern, consolidation of Federal data676creates a platform for super charged AI driven surveillance.677While data consolidation sharing could potentially improve678governmental operations and limited circumstances, efficiency679should not be elevated over robust protection of our privacy,680otherwise consolidation could risk the creation of vast and681unaccountable surveillance platform, capable of tracking682citizens' activities, movements, and associations. Such a683platform would be readily analyzable by large language models,684machine learning, and other AI systems such as black box685fleecing algorithms used by Federal law enforcement to ingest686governmental data and predict who is likely to commit crimes.687    Data consolidation could lead to biometric information688gathered by Federal law enforcement or during air travel, being689readily accessible by other agencies. Records related to690firearms might be accessible across the Federal Government and691IRS data reflecting contributions to organizations like the692ACLU, the NAACP, the NRA, or The Heritage Foundation could be693accessible to Federal law enforcement without meaningful694process. It is essential for Congress to block the reaction of695centralized government dossiers on each of us.696    Thank you for the opportunity to testify before this697Subcommittee and I look forward to your questions.698    [The prepared statement of Mr. Venzke follows:]699700[GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]701702    Mr. Biggs. Thank you, Mr. Venzke.703    Now, Mr. Redbord, you are recognized for five minutes.704705                    STATEMENT OF ARI REDBORD706707    Mr. Redbord. Chair Biggs, Ranking Member McBath, the708Members of the Subcommittee, my name is Ari Redbord and it is709an honor to appear before you today on behalf of TRM Labs,710where we work every day with law enforcement, financial711institutions, and national security agencies to detect,712investigate, and prevent illicit activity in the digital asset713ecosystem.714    Before joining TRM I spent about 11 years as a Federal715prosecutor at the U.S. Department of Justice and later as an716official in the U.S. Treasury Department's Office of Terrorism717and Financial Intelligence.718    In those roles and now at TRM I've seen one truth borne out719time and time again: Criminals are often the earliest adopters720of transformative technology. They were among the first to721weaponize automobiles to move illicit goods across State lines,722adopt pagers and cell phones to coordinate narcotics networks,723utilize encrypted messaging apps to evade surveillance, and724exploit cryptocurrencies to steal and transfer illicit proceeds725at the speed of the internet. Now they are embracing artificial726intelligence.727    We are rapidly approaching a world in which the bottleneck728for crime is no longer human coordination, but computational729power. When the marginal cost of launching a scam, phishing730campaign, or extortion attempt approaches zero, the volume of731attacks, and their complexity will increase exponentially.732    We are not just seeing more of the same. We are seeing new733types of threats that weren't possible before AI, novel fraud734typologies, hyper-personalized scams, deepfake extortion, and735autonomous laundering. The entire criminal ecosystem is736shifting. That is why today's hearing matters.737    We must recognize that in the same way criminals are738leveraging AI to disrupt and deceive law enforcement and739national security agencies must be empowered to use AI to740defend and respond. This is not optional. It is foundational to741preserve public trust and the social contract itself. If742adversaries are deploying large-scale AI-enabled crime with743impunity, and if the public no longer feels that government can744protect them, we risk a breakdown of that trust. The745consequences are not just individual harms; they are systemic746national security-level threats to our institutions and civic747cohesion.748    At TRM we see this shift every day. Through Chainabuse, our749public scam reporting platform, we've tracked a 456-percent750rise in AI-enabled scams, which often use deepfake technology,751just in the last year. Ransomware actors are using AI to draft752realistic phishing emails, identify vulnerable targets, and753deploy malware that adapts to evade detection.754    On the laundering side we are seeing bad actors use AI to755automate and accelerate illicit money flows. We are also seeing756fully autonomous fraud agents scraping personal data, launching757scam campaigns, and even coordinating laundering operations.758The most disturbing, we're seeing AI used to generate synthetic759child sexual abuse material, fake, but deeply harmful content760traded online and weaponized in sextortion schemes.761    The solution to the criminal abuse of AI is not to ban or762stifle the technology; it is to use it and use it wisely. We763must stay a step ahead of illicit actors by leveraging the same764innovations they use for bad, for good.765    At TRM we integrate AI at every layer of our platform to766combat crime using machine learning models and behavioral767analytics to flag complex obfuscation techniques, trace illicit768cryptocurrency transactions in real time, and identify emerging769criminal typologies.770    We are developing and deploying AI-powered defense agents771at scale to map illicit networks, triage threats, and surface772early warning signs. These operational tools are already being773used in the field to help global law enforcement agencies move774faster, trace complex laundering schemes, and target the775highest-risk activity, often stopping criminal networks in776their tracks before they can cause further harm.777    The future of crime will be defined by AI, but so will the778future of enforcement. With the right investment,779collaboration, and technology we can meet this moment. Thank780you again for the opportunity to testify and I look forward to781your questions.782    [The prepared statement of Mr. Redbord follows:]783784[GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]785786    Mr. Biggs. Thank you so much. I appreciate all of you and787your testimony and very, very interesting. I hope we can get to788some deep substance on it today.789    I now recognize the gentleman from North Carolina, Mr.790Knott, for five minutes.791    Mr. Knott. Thank you, Mr. Chair.792    To the witnesses, thank you for coming to testify today.793This is sort of a novel topic, but as each of you have stated794clearly, this is a very important topic and development around795the blockchain technology, AI technology, it is something that796it is only going to become more prevalent and more dominant in797just about every area of our life. That is true here in798America; that is true overseas. It is going to be one of those799paramount moments that is going to be formative. Where were you800before? Where were you after?801    To that end, as a former prosecutor myself, when I was802prosecuting, I came on at the very end of the AI-free crime. I803started to see how blockchain and cryptocurrencies and804artificial intelligence was infiltrating every area of the805criminal world.806    To that end, Mr. Redbord, as the use of AI and blockchain807technology becomes more common and it becomes more integrated808in every avenue, there is obviously access from domestic actors809that are criminal and international actors. There is really no810border that is recognized. How does that impact the criminal811infrastructure as it were when you look at domestic versus812international crime and that relationship?813    Mr. Redbord. Thank you so much for the question. Yes, I814feel like you would uniquely understand this as a former AUSA815as well. We both prosecuted cases in a world where there were816networks of shell companies and hawalas in high-value art and817real eState used to launder funds. Today, as criminal actors818are looking to blockchains and cryptocurrencies we can trace819every transaction on an open public ledger, right? There's no820more bulk cash smuggling. There's TRM to track and trace the821flow of funds.822    I think what we see right now is this really interesting823convergence between AI crime, as we're going to discuss today,824and crypto. Really primarily crypto is often the means of value825transfer in these different crimes, right? You see these826deepfake scams where they are scams trying to get827cryptocurrency from investors or users. They are ransomware828actors who are supercharging attacks where cryptocurrency is829the payment.830    The significant difference now as we're investigating831crimes as prosecutors and law enforcement is that we can trace832and track every one of those payments on open public ledgers833which allow us to do financial crime investigation, really,834better than we've ever done it before.835    Mr. Knott. Is there the ability as you see it to pinpoint836with specificity criminal activity and, I would say more837importantly, going back to the trust that we need in law838enforcement, pinpointing criminal actors? Because it is such a839foggy space for many people. Can you pinpoint the actual840criminal as opposed to just criminal activity?841    Mr. Redbord. It's a great question, and absolutely in many842circumstances. What we're doing essentially at TRM is we're843taking that raw blockchain data, right, those alphanumeric844addresses, those crypto wallets, and we're associating them845with real world entities. Oftentimes it's terrorist financiers,846ransomware actors, and sanctions, for example. That allows law847enforcement to then take that data and track and trace the flow848of funds to build out networks.849    Mr. Knott. Is there--850    Mr. Redbord. Cartels are a great example of that today. I'm851sorry.852    Mr. Knott. Is there a risk that cartels, terrorist states853could use legitimate constructs on the blockchain that are854developed here in the United States for their own benefit,855therefore taking advantage of a legitimate structure or a856legitimate software that is developed here?857    Mr. Redbord. Absolutely. The real challenge for regulators858and policymakers is how to ensure that lawful users have access859to those types of tools and yet stop bad actors from using860them. To me the answer the U.S. Treasury Department over the861last few years has done a pretty good job on this--target the862bad actors: The North Korean cyber criminals, the ransomware863actors, and the scammers, as opposed to necessarily the lawful864services that they're using.865    Mr. Knott. Is there a risk if we are too zealous in the866prosecution? As a prosecutor I am all for strong law867enforcement, but if we are too aggressive on the front end as868this technology is developing, could we stifle domestic869innovation here at home if we are too aggressive in870prosecuting?871    Mr. Redbord. Absolutely. It is critical that we continue to872focus on the bad actors in this space which will allow the873lawful ecosystem to grow as opposed to the lawful services that874are being used by bad actors. Absolutely, really the key to all875of this is to stop bad actors from leveraging the technology to876allow this industry and this technology to grow.877    Mr. Knott. Then briefly, what can we do in Congress to878ensure that law enforcement has the resources to target the bad879actors with specificity?880    Mr. Redbord. That's exactly right. Today what we really881have across the U.S. Government is a cadre of law enforcement882agents that are really true experts, power users of blockchain883intelligence tools. What we really need is that cadre to grow884significantly. As bad actors are leveraging AI, as they're885leveraging blockchain technology, every Federal agent should886have access to tools and the training necessary to sort of meet887this new moment from a technology perspective.888    Mr. Knott. Sir, thank you.889    Mr. Redbord. Thank you.890    Mr. Knott. Other Members, I ran out of time, Mr. Chair. I891yield back.892    Mr. Biggs. Thank you. Without objection, I propose that we893have a second round of questions. Seeing none, we will proceed894in that fashion.895    Now, I recognize the Ranking Member, Ms. McBath.896    Ms. McBath. Thank you, Mr. Chair. I just have to say that--897and just in listening to each and every one of the witnesses, I898am just really amazed at the depth of the use, criminal usage899of AI. Really thank you so much for what you brought to the900table today, but I do want to talk a little bit about facial901recognition.902    The Detroit Police Department reportedly conducted 129903facial recognition searches in 2020, and all on African904American people. The following year 95.6 percent of the905searches targeted Black people.906    Mr. Venzke, how does the use of AI-enabled facial907recognition comply with the Fourth Amendment's equal protection908principles?909    Mr. Venzke. It raises serious concerns. As far as I know910there's not been a clear holding that equal protection911principles are violated by the use of facial recognition912technology, but it certainly raises those concerns because of913the disproportionate impact we've seen that technology have on914protected classes, particularly as you said, Black people, and915in particular Black men.916    We've also engaged in civil rights litigation to defend917individuals who have been wrongly identified by facial918recognition technology. To a large extent this is a matter of919process, ensuring that police departments have appropriate920processes in place so that there isn't reliance solely on an921identification made by facial recognition technology to bring922in a suspect that there isn't bias in lineups and things of923that nature.924    Because of the certain threats that we've seen here and the925ways that the technology can struggle in real world conditions926we have long stood by that there needs to be a moratorium for927law enforcement uses of facial recognition Thank you.928    Ms. McBath. Thank you for that. This is just so interesting929you should say that because even on my phone I have facial930recognition and sometimes it says I don't recognize you and I931am like, well, you know who I am. Of course, there are still932problems with AI and the technology still needs to be advanced.933    Mr. Venzke, I am going to ask you another question: What934warrant requirements and limitations should be applied for935facial recognition tools when they are used by law enforcement?936    Mr. Venzke. Well, as I said, our overall stance is that law937enforcement should not be deploying the technology at all938because of the underlying foundational issues of how it can939struggle with a variety of protected classes and correctly940identifying people, especially in real world conditions where941lighting may not be ideal or the surveillance footage may be942grainy. That can result in someone who's 8 months pregnant943being apprehended for a crime where there clearly was not a944pregnant person involved.945    The use of facial recognition technology may not946necessarily implicate the Fourth Amendment, but as I said, it947raises very serious concerns about perpetual surveillance, the948ability of the Federal Government to identify individuals in949public spaces going about their daily lives without any950recourse, without any judicial oversight. That is ultimately a951policy question for legislators, city councils, and Congress to952step up and regulate.953    Ms. McBath. Thank you for that. Dr. Bowne, in your954experience have you find that AI-enabled tools used by law955enforcement are tested and evaluated before they are deployed956to ensure that they are safe and effective?957    Dr. Bowne. In my experience in law enforcement, as a958prosecutor, recently as a supervising prosector the tools that959are being used are certainly going to depend on the960jurisdiction that's using them. States, counties, certainly961Federal Government, from my experience in the Department of the962Air Force, law enforcement organizations that are starting to963use these tools are relatively new users.964    In the Air Force any AI tool is supposed to go through965rigorous testing and evaluation standards to ensure that it966results in a certain quantified reliability. That's very967challenging to do with some of these tools, particularly when968you're talking about edge cases like African American men when969they are not found frequently in data sets. Those questions are970being asked.971    I don't see in my experience the type of rigorous standards972established across the board by regulators. Until that happens973law enforcement is going to try to keep up. It's tempting to do974that, but there's likely to be some gaps there.975    Ms. McBath. Thank you.976    Mr. Biggs. Thank you. The gentlelady yields. I now977recognize the gentlelady from Florida, Ms. Lee, for five978minutes.979    Ms. Lee. Thank you, Mr. Chair.980    Welcome to our witnesses today. As a Member of the House's981Bipartisan Task Force on Artificial Intelligence I had the982opportunity to work with Members on both sides of the aisle to983discuss a national approach to artificial intelligence that984would encourage innovation, strengthen our global leadership,985and also confront serious threats including those like you have986been discussing here today that involve criminal misuse of this987technology.988    Today's hearing, among other things, highlights one of the989most urgent of those threats, which is the exploitation of990children through AI, from synthetic child abuse materials to991predatory chatbots, to real time location spoofing, we are992seeing criminals use AI to expand both the scale and993sophistication of their crimes. AI can also, we know, be part994of the solution. In cases like Operation Renewed Hope AI helped995Federal agents identify and rescue minor victims who might996otherwise have never been found.997    One of the things that we are interested in doing is998ensuring that law enforcement, child protection, nonprofits,999and trusted partners in the private sector have access to1000effective responsible AI tools and the legal clarity to use1001them. It is about stopping criminals, saving lives, protecting1002children, and ensuring that we are doing our part to help1003technology be a force for good.1004    On that subject, Ms. Perumal, I would like to followup with1005you. I would like to know what would you recommend Congress1006prioritize, to better equip law enforcement with the tools they1007need to stay ahead of AI-enabled threats?1008    Ms. Perumal. Thank you so much for the question. I think a1009few things come to mind. One is strengthening public and1010private partnerships. The more that we have the opportunity to1011share information across industry and government, and the1012threats we're seeing, it is incredibly helpful.1013    Making it easier to share technology and share the1014innovation--frankly, it can sometimes be difficult, especially1015as small business are trying to figure out how to share that1016technology, which makes a delay. As you have a new way that we1017can maybe find something like trafficking or better detect AI-1018generated harm, it can be difficult to then deploy that. I1019think anything that is to improve that public-private1020partnership would be incredibly helpful.1021    Ms. Lee. Are there specific legislative or funding1022priorities that you or your clients have identified that you1023think would be impactful?1024    Ms. Perumal. Yes, few things that we see with our clients.1025One is there's a big challenge to identity in terms of online1026identity. The AI-generated agents can more explicitly scrape,1027use websites for fraud. Then on the other side you also see1028things like ID fraud where people are using this to hide their1029identity and commit online crimes.1030    That's an area that the industry is generally trying to1031adapt and respond to because that's how so much of fraud and1032scams and extortion has been carried out.1033    Another thing that comes to mind is to the earlier point on1034innovation, if it's easier to share and collaborate, that would1035be incredibly helpful for us in the private sector.1036    Ms. Lee. I would like to go back to you, Mr. Redbord. You1037said something in your remarks that I thought was really1038interesting, that AI is also the future of enforcement. I1039believe your words were invest, collaborate, and we can be more1040effective.1041    I would like to hear in your view what are the most urgent1042risks posed by AI to national security and public safety and1043what would you like to add about what we can be doing in1044Congress?1045    Mr. Redbord. Absolutely. Thank you for the question. Really1046what we see AI doing today is supercharging criminal activity1047that we've seen exist for some time. Now, you don't need1048ransomware affiliates because you can have AI agents that are1049automatically deploying malware. We're seeing cyber-attacks at1050scale by Norther Korea and other types of cyber actors. Then1051we're seeing the laundering of the funds that are stolen move1052faster than ever before.1053    As I mentioned in my testimony we've seen a 456-percent1054increase from last year in scam activity involving AI. We have1055to move as fast as the criminals. When we think about these1056issues at TRM, it's how can we move faster? How can we us AI1057the same way they're moving funds to track and trace those1058funds to ultimately seize them back?1059    It's--when you ask, it's the tools and the training to1060ensure that every single law enforcement and national security1061professional have access to the same tools that many cyber1062criminals are using today, and obviously the funding necessary1063to support that as well as the training.1064    Ms. Lee. Thank you. Mr. Chair, I yield back.1065    Mr. Biggs. The gentlelady yields back. I recognize myself1066for five minutes. I appreciate the testimony that we have had.1067    I had a different line of questions for the next round, but1068things you have said in your testimony and what I have heard in1069the first round makes me want to ask some specific areas.1070    You don't have a lot of time to respond, so I am going to1071ask because I want a quick response from every one of you.1072    One of you mentioned the ELVIS Act in Tennessee, which1073prohibits the simulation of Elvis' voice, basically. That is1074how that generated. What about any other person? I am thinking1075what if there is a deepfake of any other public figure and you1076have that person say something that is pernicious, something1077that is bad, something that is politically inflammatory,1078whatever, do we have laws in place that would prohibit that or1079it's just the Wild, Wild West?1080    We will start with you, Mr. Redbord.1081    Mr. Redbord. Slightly more broadly, I would say that we1082have laws in place that absolutely cover a lot of these areas,1083but we are going to need to add AI to a lot of them. When I1084think about these issues, for example, when you talk about1085these types of scam activity that are being supercharged by AI,1086we have wire fraud statutes to address them.1087    Mr. Biggs. Right, right. We will get into that, too, but I1088am talking specific. This is a specific case. Let's say you1089have a public figure and you have them say something that is1090totally outrageous, it is totally deepfaked. You can't tell.1091The average person can't tell. If that person was--if that1092language is attributed to that person elsewhere, you might have1093libel. You might have civil claim of libel or defamation of1094character, something like that. Does that in your opinion exist1095when someone manipulates a deepfake to do something like that?1096    Mr. Redbord. It would require adding additive measures to1097what we have today.1098    Mr. Biggs. Mr. Venzke?1099    Mr. Venzke. That sort of speech lies at the core of the1100First Amendment's protections. It's a commentary on1101politicians. For example, when the--1102    Mr. Biggs. If it is not commentary on politicians. Let's1103say with maliciousness. Maliciousness? With malice. That is the1104word I am looking for. With malice you say that Andy Biggs said1105X, Y, this. It is just horrible. You put it in The New York1106Times and you did it because you wanted to harm me.1107    Mr. Venzke. If you take, for example, the Republican1108National Committee's deepfake about President Biden announcing1109a draft for Ukraine, that is commentary on public events. Of1110course, existing exceptions to the First Amendment still apply1111to AI. That means--1112    Mr. Biggs. That is what I want to get at. That is what I1113wanted to hear from you, whether something like a defamation,1114like--1115    Mr. Venzke. Yes, defamation is subject to--1116    Mr. Biggs. --which is why I specifically used The New1117York Times.1118    Mr. Venzke. That's exactly right.1119    Mr. Biggs. Ms. Perumal, same question?1120    Ms. Perumal. Yes, I am not super familiar with the legal1121side, so I can talk more the technology, but I do see that it1122is challenging, detection on it.1123    Mr. Biggs. Right. Thanks. Dr. Bowne?1124    Dr. Bowne. There's this inherent friction that we see. I1125agree with both Mr. Redbord and Mr. Venzke, that what you1126described, sir, is likely protected under the First Amendment.1127You have--1128    Mr. Biggs. Unless there is malice.1129    Dr. Bowne. With malice. Now, there's legal protection1130certainly from a civil right of action if it were to be--1131    Mr. Biggs. Let's not to interrupt. I don't want to be rude1132to interrupt, but I do want to interrupt. What my question is--1133let's expand it. A true deepfake is so persuasive you can't1134tell the difference side-by-side of me over here and the1135deepfake. We have had examples of parents and grandparents.1136They can't tell the difference between the deepfake and the1137voice of the kid. They look the same. They act the same. They1138are remarkable. Now, do I have protection, for instance, from1139someone doing that?1140    This is going to lead into the CSAM, which I was hoping I1141would have enough time to get to that, because it is the same1142type of deal where you see CSAM, which is so persuasive and1143sick and disgusting. That is all AI-generated. You mentioned1144the one of the Ukraine thing. What remedy does someone have1145when they are a victim of this kind of generative AI?1146    Dr. Bowne. Mr. Chair, if it were to fall under the statute1147of like wire fraud--so you look at the intent of what's behind1148it. Those are protections there. If it's to create1149misinformation, you certainly articulated the challenge and the1150potential harm, that may not be outside of the law. There are1151gaps in protection when you're facilitating particularly1152harmful activity using deepfakes.1153    Mr. Biggs. Yes, thank you. We will be talking about that in1154the future.1155    That ends the first round of questioning and now for the1156second round of questioning I recognize the gentleman from1157North Carolina, Mr. Knott.1158    Mr. Knott. Thank you, Mr. Chair. I have got to say I am1159happy to have a second round so soon. I wished more Members1160would show up because this is important, but selfishly I am1161enjoying the conversation.1162    All of you have basically indicated what was stated either1163directly or indirectly that computational power and ability1164will dictate sort of the new criminal landscape. Obviously, AI1165will supercharge this. The landscape is going to be forever1166changed. I want to ask each of you, how far are we from having1167autonomous criminal behavior?1168    Doctor, start with you. Go in order down the line.1169    Dr. Bowne. Those are fantastic questions.1170    Mr. Knott. Thank you.1171    Dr. Bowne. My assessment is we're there. We have plenty of1172autonomously certainly, from a bad actor that is using AI and1173using the autonomous features of those models to perpetuate1174crimes we're certainly there. The scale, the sophistication,1175and the speed that are created by using AI-enabled models,1176certainly, from committing scams at scale, targeting1177personally, finding cyber vulnerabilities, that is all1178happening already.1179    Ms. Perumal. Yes, I agree. We're definitely seeing that1180now. It's the beginning of what's happening. It's being used1181for more simple crimes. We see different uses. You might think1182of simple bots that text people and send us these annoying scam1183text messages. Those are using AI and automate by pulling1184breached or leaked data about you. Then, similarly with1185computer-use agents, they're starting to be filling out forms.1186There's a large opportunity for those to get much more1187sophisticated.1188    Mr. Venzke. Relatedly on the civil side, we're seeing rapid1189advancement of artificial intelligence that's used to make1190decisions about who can get a loan, who has access to house,1191and things of that nature. Often in many cases that will output1192a score that humans are largely deferring to. Artificial1193intelligence has reached the point where it is having an1194outsized effect on our lives, not just because of criminal1195activity, but because it affects so many important sectors as1196well.1197    Mr. Knott. Yes.1198    Mr. Redbord. Thank you for the question. We are there1199today, but AI is not dominating criminal activity. That's in1200large part why this hearing is so important at this moment, to1201start having this conversation. This is really why at TRM over1202the last year or so we have focused a lot of our attention.1203Particularly how can we build AI tools that enable us to move1204faster? Because while we're not there yet, we're getting very,1205very close.1206    Mr. Knott. What is going to be required to make it1207responsive to the threat?1208    Mr. Redbord. That's exactly right.1209    Mr. Knott. What will be required? I am asking, like--1210    Mr. Redbord. Oh, sorry.1211    Mr. Knott. --in terms of capacity, in terms of private1212sector investment, in terms of public investment? Give me a1213broad picture of what's going to be needed.1214    Mr. Redbord. It's all of it. I know public-private1215partnerships were talked about. It's often this sort of this1216right way as something to discuss. Really what it has to be is1217the private sector building the tools that government can1218ultimately leverage to move as fast as the cyber criminals.1219    Mr. Knott. In your opinion is the law lagging this new1220frontier or are the existing criminal laws sufficient to1221protect the marketplace and victims like Mr. Biggs talked1222about?1223    Mr. Redbord. It'll absolutely be a combination of both. It1224will be important when you talk about CSAM, which I know we'll1225focus on, on ensuring that the Federal sentencing guidelines1226meet the AI moment for that. We will have a need for AI-1227specific laws, but I will say that a lot of the laws we have1228today: Wire fraud, bank fraud, those types of laws, these types1229of disinformation investigations, certainly will include AI.1230    Mr. Knott. Jurisdictionally how do you see AI factoring1231into content actions, vehicles designed overseas that penetrate1232into the American market? How do we protect against that in a1233jurisprudence sense?1234    Mr. Redbord. It's a challenge. The nature of crypto, the1235nature of AI, and the nature of technology, is global and1236cross-border. In large part we want to make sure that the1237innovation is happening here. That's why it's so important that1238as we have these conversations we're walking that line between1239stopping bad actors but not stifling innovation in this1240critical moment. Just like the internet was born and created in1241the United States we need to ensure that is true for AI1242technology as well.1243    Mr. Venzke. If I may add to that representative, as we1244think about ways that existing legal frameworks need to adapt1245to this rapidly evolving challenge, a multijurisdictional1246approach is the right approach, not just at the Federal level,1247but also internationally, and of course with States. We've1248talked a little bit about the moratorium that was included in1249versions of the reconciliation package. The House did exempt1250criminal laws. Often, in many cases, civil penalties will be a1251necessary complement, for example, in addressing nonconsensual1252imagery at high schools--1253    Mr. Knott. One more question for the panel really quick.1254What can parents do to protect their children from this type of1255landscape?1256    Dr. Bowne. As a parent myself, education on the risk is1257certainly important. That's something that the public sector1258can lead on, law enforcement can lead on, similar to drugs and1259tobacco. The risk of AI, whether it's for scams, whether it's1260for CSAM, whatever harms, they really impact children as well.1261    Ms. Perumal. I definitely agree. Especially for the CSAM1262harms, giving their children awareness that something like this1263might happen to you, it might have nothing to do with anything1264you did and here's how you can reach out. Sharing that1265awareness because they target the fact that people feel shame1266when they have no reason to. I think that would be really1267helpful.1268    Mr. Knott. Thank you.1269    Mr. Venzke. As a former teacher parents are an integral1270part in helping kids navigate the world, and education and1271talking with kids about the new risks that are emerging are1272critical.1273    Mr. Knott. Thank you.1274    Mr. Redbord. Education is absolutely critical. As a parent1275of middle school and high school-aged kids I appreciate this.1276One more point that I do think is important here though is that1277we need to ensure that they also know how to leverage it, not1278that they're just afraid of it.1279    Mr. Knott. Sure.1280    Mr. Redbord. Their success in large part and in the rest of1281their life will depend on their ability to leverage and engage1282with this technology. It's absolutely so critical that on the1283one hand we protect them against the bad harms, but also ensure1284that they're really able to use it and leverage it.1285    Mr. Knott. Absolutely. Thank you. Mr. Chair, I yield back.1286    Mr. Biggs. Thank you. The gentleman yields. We now1287recognize now the Ranking Member, Ms. McBath.1288    Ms. McBath. Thank you, Mr. Chair. Once again, as you can1289see, we are quite alarmed as to what we are hearing today, so1290thank you very much.1291    I want to go back and touch on what the Chair was just1292asking, the question that he asked about. In specific, I would1293just--each of you, if you can just tell us in a nutshell that1294you are expressing to us that there are gaps. There are gaps in1295legislation. There are gaps in things that we need to do here1296in Congress to make sure that there are protections that are1297enforcing and preventing these kinds of deepfakes and all that1298we are talking about today.1299    Can you give us an idea? Tell us what kinds of legislation1300are going to be extremely important for us to put in place to1301prevent these kinds of gaps that you just expressed to us that1302there are today?1303    Dr. Bowne, could you start, please?1304    Dr. Bowne. Yes, ma'am. One of the gaps may be closed soon.1305H.R. 1283, which was introduced by this Committee would amend1306Title 18 of the U.S.C. 2252(a), which is the statute that1307covers child pornography and CSAM. The bill is intended to1308amend that statute to include AI-generated CSAM within the1309definition and coverage under that criminal statute. There is1310the Title 18, the criminal statutes that may need to be amended1311both in content on what is covered, what is criminalized, but1312also potentially in the sentencing guidelines, as Mr. Redbord1313mentioned.1314    Then, as the Chair explained and in his question there is a1315gap as well on the civil side that there might not be a cause1316of action for that noncriminal, because even that amendment1317that's proposed in H.R. 1283 still has to be constitutional.1318There are First Amendment protections even on things that would1319normally be objectionable.1320    Ms. McBath. OK. Thank you. Mr. Redbord, please?1321    Mr. Redbord. Thank you very much. I provided about five1322suggestions in my written testimony, but I'll just focus on one1323for purposes of this answer.1324    It is absolutely critical that agencies at every level have1325access to modern investigative capabilities including the1326blockchain analytics platforms integrated with AI, media1327authentication tools, as we talked about, and AI-enabled1328investigative tools. Congress should allocate dedicated funding1329to these tools along with specialized training programs.1330    Ms. McBath. Thank you. Mr. Venzke?1331    Mr. Venzke. I think awareness of, first, where existing law1332can apply to criminal activity is critical in navigating this1333space. For example, 2258(a) has been extended and prosecutions1334have been brought for simulated CSAM material created regarding1335a specific identifiable child using AI technology. I agree with1336Mr. Redbord that education, providing training, defense, and1337funding for critical infrastructure for schools and others to1338educate students and other vulnerable populations about the1339threats of AI will be key, and to shore up their own1340cybersecurity infrastructure.1341    Ms. McBath. Mr. Venzke, I want to go back to something that1342you did touch on though. You did touch on the moratorium on1343State and local AI, which actually failed. That last attempt1344failed. The Republican Chair of the House Energy and Commerce1345Committee has already vowed to continue to pursue it even as1346they acknowledge that Federal legislation setting standards on1347AI is still years away.1348    As we work to develop that legislation what principles or1349proposals should we consider?1350    Mr. Venzke. One thing I would look to, and Representative1351Lee already referenced it, was the House AI Task Force final1352report from the last Congress. That was a thoughtful sort of1353compendium of the various issues around AI regulation at the1354Federal level. It recognized that preemption particularly is a1355sensitive issue. It doesn't need to be all or nothing, that1356there is a range of tools that can be used in adjusting what is1357the appropriate area for preemption? What is the program amount1358of preemption to ensure that States have significant latitude1359to address these harms in a timely manner, which of course is1360beneficial for Congress as this Committee looks at what works1361and what does not.1362    Ms. McBath. OK. Thank you. One last question. Dr. Bowne,1363how can public agencies use the procurement process to ensure1364that the AI systems they want to acquire are safe and1365effective?1366    Dr. Bowne. They certainly articulate what the problem is1367and what the need to create a demand signal for private1368industries, for R&D, for academia to do the research that is1369needed. The procurement system is a fantastic way for Federal1370agencies or State agencies to ensure that the standards are1371being met and that the capabilities are there and are being1372focused on in the development and the research in the public1373sector--or in the private sector and in academia.1374    Ms. McBath. Thank you. Mr. Chair, I have a unanimous1375consent request to enter into the record, a statement from1376Barry Friedman, Faculty Director of the Policing Project at New1377York University School of Law, dated July 16, 2025. Also,1378entering into the record a statement for record dated July 16,13792025, from Public Citizen regarding the growing threat of1380criminal exploitation through AI. Last, but not least, a1381unanimous consent to enter into the record a statement from1382Keith Kupferschmid, Chief Executive Officer of the Copyright1383Alliance, dated June 13, 2025.1384    [The information referred to follows:]1385    Mr. Biggs. Without objection.1386    Ms. McBath. Thank you. I yield.1387    Mr. Biggs. Thank you. The Chair now recognizes the1388gentleman from California, Mr. Kiley, for his five minutes.1389    Mr. Kiley. Thank you, Mr. Chair, for calling this hearing.1390It is a hugely important topic. We have often seen this arms1391race develop between criminals and law enforcement when it1392comes to the use of technology where criminals innovate and law1393enforcement has to innovate in turn. It is a matter of just1394trying to sort of keep up.1395    With AI it is a totally different ball game in the sense1396that the development of new capabilities is happening so1397quickly, and the nature of those capabilities is often emergent1398and surprises even the people who train the systems. The ways1399in which they are being applied is equally unpredictable.1400    To me it seems that integrating AI into law enforcement1401operations, is not just a tool at this point; it is absolutely1402essential. It is a tremendous challenge and requires a lot of1403expertise. It seems to me that we need to be thinking very1404seriously about how we can have coordination and how we can1405make cutting-edge tools available to law enforcement across the1406country.1407    I wanted to ask both Mr. Redbord and Ms. Perumal, if I am1408saying that correctly, about your thoughts on this. I know that1409you have a law enforcement background. I know that you actually1410worked at Google, and I believe it was just a couple days ago1411that Google announced that its cybersecurity AI platform for1412the first time detected and defeated a software vulnerability1413in the wild that was known to malevolent actors. Maybe if you1414could both address the role of the public and private sector in1415meeting this challenge.1416    Mr. Redbord. Thank you so much for the question. It's1417absolutely critical that the public and private sector work1418together on this as the question noted.1419    Look, every Federal law enforcement agency in the U.S.1420today is using tools like TRM to track and trace the flow of1421funds, to automate tracing when it comes to cryptocurrency, to1422leverage AI tools in that respect. The reality is that it's1423still a handful of investigators that have this expertise and1424training.1425    As we move from crime on city streets to crime on1426blockchains and in cyberspace we're going to need every agent1427and investigator, not just Federal, but State and local to have1428access to these types of tools and training. As you mentioned,1429cyber criminals are now using this more and more and will1430eventually be using this at scale. Every agent investigator who1431is investigating these cases, tracking them, needs to be moving1432as quickly. I would say tools and training primarily.1433    Then the other piece is really true public-private1434partnership where FBI and IRS-CI and HSI and others are working1435closely with the private sector to share information to move as1436quickly as possible.1437    Mr. Kiley. Thanks very much.1438    Ms. Perumal. Thank you for the question. I love that you're1439following the vulnerability discovery. That's awesome.1440    To your point the criminal ecosystem is using this to scale1441their offense. We have to use it to scale our defense and make1442that more effective if we're going to keep up. There's a lot of1443ways we can do that, from better detecting malware, to better1444understanding the tools and tactics they're using, better1445detecting the scam messages. If we can enable, as I said, the1446public-private partnerships, which we keep repeating and if we1447can make it easier and much faster to adapt as the criminal1448ecosystems adapts, that makes us a lot more effective.1449    There are so many opportunities. Even if you think about1450all the reports of scams that maybe we already have access to1451or law enforcement has access to, if we can just go through1452that data and find the trends, using AI to speed up and scale1453investigations is a way that we can really keep pace with the1454criminal ecosystem.1455    Mr. Redbord. One more thing I would add to that,1456historically, I was a prosecutor for a long time, we1457investigate specific cases, right? There's an instance of crime1458and we need to investigate that specific case. What this1459technology really allows us to do is build out networks, to1460understand crime typologies, to understand where the threat1461actors are, and how they are engaging and what they would1462potentially do next. Really, it's an extraordinary moment when1463it comes to not just law enforcement, but how to disrupt1464adversaries from a national security perspective.1465    What this technology--and I think you got to this in your1466question--really enables is not just the one-off harm that's1467been done to an individual, but how do we build out networks of1468cartels, fentanyl dealers, and scam networks in Southeast Asia1469and elsewhere? This technology I guess connected to blockchain1470intelligence, really allows us to do a lot of that today.1471    Mr. Kiley. Interesting. You can address crime much more1472systematically in a more efficient way and more preemptively?1473    Mr. Redbord. We even see that today in the actions that are1474coming from the U.S. Treasury and Department of Justice where1475they're going after networks. They're doing civil forfeitures.1476There was a very large civil forfeiture complaint filed about 21477weeks by the U.S. Attorney's Office in D.C., against $2251478million involved in pig butchering scams. It was a network.1479We're seeing them use it today.1480    Mr. Kiley. Very interesting. Thanks very much. Mr. Chair,1481it seems there is a role perhaps for us to play in supporting1482these public-private partnerships and in facilitating the1483training and access to this knowledge and these resources in1484law enforcement across the country. I yield back.1485    Mr. Biggs. Thank you. The gentleman yields back. I am going1486to recognize myself for my last five minutes here. I would1487suggest that as we started off, I said this would be the first1488of its kind. I meant that we are going to have to keep pushing1489this.1490    A week--let's see, maybe a week ago Elon Musk announced1491Grok 4. He talked about artificial intelligence and Grok 4 is1492going to have the intelligence--it already has beyond a Ph.D.,1493engineering, science, genius, et cetera, an artificial super1494intelligence.1495    We've touched on it lightly here today using different1496terms, but my question is at what point do we no longer see1497computational decisionmaking with a human first mover and you1498have an algorithmically iterative process that essentially--and1499we are there in some extent now, but we are not totally there1500because human interaction is still the first mover. At some1501point it won't be a human that is the first mover anymore; it1502will be the algorithm itself.1503    How long before we get there? How do we get there and1504prevent the crime and provide the deterrence that is necessary?1505For the hypothetical I give you, how long before adjudicating1506whether there is probable cause or not for a search warrant or1507an arrest warrant is merely algorithmically sustained as1508opposed to having a human make that determination?1509    With that bizarre question but acknowledging that we are1510actually moving so rapidly that we probably thought by 2050 you1511would be getting to artificial super intelligence, but it looks1512like maybe before 2030 you are going to be in artificial super1513intelligence.1514    Dr. Bowne? Then we will go down the whole panel.1515    Dr. Bowne. Thank you, Mr. Chair. Certainly, a thought-1516provoking exercise. I am glad we are still at the point where1517it is an exercise, and not reality, but I recognize that we may1518not be far from there.1519    Before we get to artificial general intelligence, or before1520we get to certainly artificial super intelligence--and those1521are still theoretical and not a foregone conclusion--there is1522this very powerful and very rapidly increasing agentic AI.1523    Mr. Biggs. Yes.1524    Dr. Bowne. We start to see some of what you describe1525already taking place at, admittedly, lesser extent than what we1526would if it were true AGI or ASI. We still have algorithms that1527are making decisions on behalf of humans that are able to do so1528at speed and often at a skill that it certainly makes it1529difficult for the human agent to observe and to be a part of.1530It really depends on how much trust, how much authority we1531provide those agents, and what those models are; they fine-1532tuned to limit that?1533    I do believe, as you said, Mr. Chair, this is the first of1534hopefully many having some of those industries, some of those1535private sector companies describe that so that this1536Subcommittee and Congress can ensure that they are able to1537predict and know, and set up those guard rails if necessary to1538limit what you're concerned about.1539    Mr. Biggs. Ms. Perumal? Since we only have a minute left,1540each of you get 20 seconds.1541    Ms. Perumal. Thank you. Very interesting question. We see1542AI agents making simple decisions today. For more complex1543decisions, as the models can do more complex reasoning in the1544next few years, it really should come down to how important is1545the decision, and then what transparency and explainability we1546can get from the model and how much human oversight is1547necessary? It really depends on how risky that individual1548decision is where we should hopefully see it overlap on these1549autonomous decisions.1550    Mr. Venzke. I'm going to build directly on that. The role1551of AI is a choice. Laws passed in Texas, the National Security1552Memorandum that governs national security uses AI, say that1553certain things are off limits for artificial intelligence.1554    You mentioned probable cause. That strikes me as a core1555foundational tenet of due process that should probably be truly1556a human activity. That is the choice that we make of who will1557be--what will be human, what will be AI, and where will humans1558be in the loop?1559    Mr. Redbord. I've never seen anything move as fast as this1560moved in my lifetime. While I don't have a great answer for how1561long, it's certainly coming. If I could leave this Committee1562with anything today, it's that we need to move as quickly1563building the tools, working with this body to provide the right1564laws there. As an old school prosecutor, I'm happy with judges1565still making decisions around probable cause, but I do think we1566really need to ensure that we are using the tools defensively1567to meet this moment.1568    Mr. Biggs. Great. Thank you all for being here. My time is1569expired. There is so much more to cover about this. Like I say1570it is just the first, and hopefully we will get back together1571soon and continue this.1572    Please feel free to contact me or the Ranking Member. I1573assume that is OK. She says that is OK. Because we want to have1574a dialog and see where there are holes, where there are gaps.1575Let us know. We want to do stuff that is preventive without1576being constrained, if that is possible. Thank you.1577    With that, we are adjourned.1578    [Whereupon, at 11:30 a.m., the Subcommittee was adjourned.]15791580    All materials submitted for the record by Members of the1581Subcommittee on Crime and Federal Government Surveillance can1582be found at: https://docs.house.gov/Committee/Calendar/ByEvent1583.aspx?EventID=118467.15841585                             [all]

Witnesses

4 witnesses appeared, with 12 papers on file.

NamePositionPapers
Ms. Zara PerumalChief Technology Officer, Overwatch DataBiography · Testimony · Biography
Mr. Ari RedbordGlobal Head of Policy, TRM LabsTruth in Testimony · Testimony · Biography
Dr. Andrew BowneProfessor, George Washington UniversityBiography · Testimony · Truth in Testimony
Mr. Cody VenzkeSenior Policy Counsel, National Political Advocacy DivisionBiography · Testimony · Truth in Testimony

Documents

The committee filed 7 documents for the meeting.