Amazon (AMZN) CSO on AI Shaping Cyber Threats, Safety Tools & Frontier Models
Show transcript
Nicole Petallides, live on the floor of the New York Stockchand now by Steven Schmidt, chief secu officer of Amazon. Let's talk about Amazon's colliding now at scale. Yout noted that the volume velocity of threats are on the rise, 750 million threats daily. Can we talk about what's going on here, Nicole? AI is really cyber security question equally. It's giving the attackers and defenders both speed and scale. But one thing that's really important AI has not created superhuman adversaries. What it has done is madery actor with access to these tools, capable of operating at ale that used to require nation state resources. For examp the time window between something being disclosed as a vulnerab to when it can be exploited by an actor, it's compressing towards single t houe velocity of threats. They're both increasing. And the old world that we used to live in, it used to be that we had or weeks or months to fix vulnerable systems. It's not down to minutes and hours. And more importantly, AI is also lowering the skill level needed to launch sophisticated attacks andom more of each step, which as a result, increases both the volume of s and the speed at which attackers can adapt. S what is Amazon doing internally? Since everything picking up for the attackers and the defenders, the speed is faster. AI is making it happen more often. It's even making it m simplistic for attackers to have a high advort of attack. What are you doing internally at the company? So the first thing that we do internally is we make sure we've got vity into everything we have. Sounds deceptively simple. But for any large company and we qualify as a large company, I think you've got it. That's everywhere. In many cases, a lot of people don't even know what they have. Song that good inventory to begin with is a critical foundation. The second thinggot. How quickly can you fix ing? How quickly can you patch something? And third, we've got t change the way we think about building applications. They have to be reviewed from a security perspective at the time they're written, rathe than going back to the old way, where we used to review them once a year or one time and then let things sit. You've got to constantly review,ecause the models that drive the AI engines are changing about every 3 to 4 months, their capabilities rising. So we have tack and look again. Is there something new that we haven't seen before? I don't know how much regulatory programs can actu you know, sort of slow this down to a certain extent because it's moving faster than we're going to talk about the accord today. But overall, right, there's regulation, but all of this is moving so much faste the meantime, you talked about engineering product development. Where does Amazon stand in that competitively to have cyber security to as it evolves and have that stronghold and sort of kac with AI at the same time? Well, from our ctiv as defenders have to adopt AI rapidly because it fntally is required for us to be able to beat the attackers at the game that we have to play. And it's a situation where a lot of people talk about, well, should wew down development or is this something that we should beor careful about? We don't see this as a choice, really between progress and safety. Models should be released when they're ready and safe to use, which really from rigorous testing and strong safeguards. And there risks that if this doesn't happen collectively,ng the industry, working with the government, working with all of our civ customers, we believe as an industry in partnership with the government, weing to get the right protection that way. AI is alreadyevel and delivering real value to customers, so getting thisnsion. And it's interesting too, because now people are now having the adoption of AI.s no longer something for governments or, you know, war fighters or things like that in those special control rooms. everybody's starting to use AI in their businesses in daily life. What d think of the meeting that happened in takeaways? Because a week ago, we were worried about catast existential risk to humanity overall. And it seems like some of the language from the likes of Jensen Wong and even Altman, that they can control this, that it's not as scary or, you know, dangerous as it may have seemed a week ago. What did you think about the accord that they signed, or how you feel about the big picture on this? I think if we look at the accord, fundamentally, it has sound foundations. If you look at the few things that are in there right now, you doing evaluations of what you have before you ship, it just makes sense. It's som we've been doing for a long time. We help others evaluate their own models as w And it's an area where I think with the right application of skill, the indust get much better at catching these problems before they escape. The second part is ensuring that we're doing the development work as an industry on foundations, which themselves are secure. A lot of the problems the industry has seen has b the containers, which is the sort of that models sit in, haven't really been designed from the was appropriate for containing a model that has a level of that the models we're seeing now come out. Have. We hear over and over again that we're just in the third inning of the AI build out. And you noted something some of the myths and AI tools that you can't just have an AI tool and expect them to work. You need to have the pros or folks, strong teams, the operational rigor. There are maybe some myths and facts that areoingon I conversations you have. Can you ten us with that? Sure, Nicole, you're so right. There is a huge gapen the narrative around frontier models and the reality of operating them atca I'd say the number one myth is that frontier models are going to find all theulnerabilities in your software and systems, and everything will go back to normal We are now operating at a permanently different velocity. This is not somethinge environment and will go away. Each future generf models is going to improve, and that's going to change the nes that we as defenders have to operate under. The second myth is that AI is creating new classes of security threats. It is not. AI has really made everyone with access to the reallyoo models capable of causing problems at scale. But the most advanced adversaries are using it as automation of what they already do. You know, I think there wasrd one. I may have interrupted you, but I'll leave you with this. Yeah. I mean, and you can add, please, what do you want peoplen to know? And the takeaway from this conioo they are confident in the capabilities and or the ethical part of this story too. And just some final thoughts, please,en Sure. I think the most important thing here is as business ow we cannot let AI decide what it's allowed to do. We have to build guardrails around it. We have to build the right environment for containment. And more importantly, we have to enable our teams within our organizati to use AI safely with the right harnesses around it. And that, by the way, was the sort of the third point that I was thinking about earlier. You cannot match AI tools with systems and expect them to work without really strong teams and operational rigor. AI is amplifier. It takes whatever foundation you already have, whether it's good or bad and changes it makes it louder. But it is not. Stephen, I want you to come on all the time because I think this is a great conversation for folks as they start to, you know, wheney0 million threats or over that ayd handling that with engineering and product development and, you know, have a grasp on that. I think it's a really interestingvers one that continues to evolve on the know you're very busy. Stephen Schmitz, Chief Security Officer at Amazon


