What's in America's Code? Reaganism with Horacio Rozanski

Ronald Reagan Presidential Foundation & Institute
Loading transcript... Click for full transcript
About this episode Booz Allen Hamilton's report reveals that Chinese LLMs introduce significantly more code vulnerabilities than … AI summary

Booz Allen Hamilton's report reveals that Chinese LLMs introduce significantly more code vulnerabilities than American models, particularly when used for national security applications, and inject political bias into generated code. The discussion highlights a critical 'global adoption race' where cost advantages of Chinese AI threaten US trust and security standards, necessitating policy interventions like supply chain certification and accelerated development of trusted American open-source alternatives.

Key takeaways 7
  • Chinese LLMs introduce more vulnerabilities than American models, especially when coding for national security applications; however, these are not intentional backdoors but rather systemic differences in secure coding practices and political alignment.
  • The primary driver for Chinese AI adoption in the US software supply chain is cost, with models like DeepSeek being 10-20 times cheaper than US alternatives like Anthropic or OpenAI, creating a financial incentive for startups to use them despite security risks.
  • Chinese models exhibit political bias by refusing to generate code for sensitive topics (e.g., Taiwan Navy, missile fleet management) or providing non-secure URL formatting for US applications compared to Chinese ones, effectively embedding PRC-aligned principles into global software.
  • The 'Huawei moment' for AI is not about hardware backdoors but about the pervasive adoption of Chinese-trained models becoming the global standard, which would shape global information and application logic through propaganda-aligned training data.
  • US trust in AI is eroding among younger demographics, with surveys showing young Americans view AI as a greater threat than the PRC, which undermines the US competitive advantage in the 'trust' pillar of the AI race.
  • The government's pause on certain AI models (like Mistral) was a necessary response to unexpected vulnerability leaps, but slowing innovation entirely is dangerous because the adversary (China) continues to advance without such constraints.
  • Cybersecurity is shifting towards AI-driven attacks where LLMs can control thousands of attack vectors simultaneously (e.g., drone swarms), requiring defense mechanisms that specifically counter AI behaviors rather than just human-like attack patterns.
Notable quotes 5 AI-generated: wording and quote attribution may be wrong. Use the play link to verify.
  • “The first link in the software supply chain is no longer the code, it's the AI models behind it.”
    ▶ 4:15 Roger Zachim introducing the core premise of the Booz Allen report regarding the shift in supply chain risk.
  • “We tested for back doors. We found none. But what in fact we did find... is that when they're coding for American use... they'll introduce more vulnerabilities still.”
    ▶ 8:21 Harasio Rosansski clarifying that the risk from Chinese LLMs is systemic vulnerability and bias rather than intentional malicious backdoors.
  • “This is the Huawei situation all over again... people all over the world will essentially be asking questions of models that are trained on Chinese propaganda.”
    Rosansski explaining the long-term geopolitical risk of Chinese AI adoption becoming the global standard.
  • “The adversary gets a vote. So it's not just what we want to do but what do we want to do again in this race in comparison to... China.”
    ▶ 22:29 Rosansski arguing against unilaterally slowing down US AI development while China continues to advance.
  • “2026 is going to be the year of cyber AI... 26 has played out at the thematic level exactly as we expected.”
    ▶ 31:23 Rosansski confirming his previous prediction about the acceleration of AI-driven cybersecurity threats.

Chapters & Sections (16)

0:00 Chinese AI Models in US Software Supply Chain chapter 1
3:36 Chinese LLMs Software Vulnerabilities
7:55 LLM Supply Chain Security Risks chapter 2
11:24 Supply Chain Certification Challenges
12:52 Government Procurement Impact on AI Security
14:33 Chinese AI Bias and Global Adoption Race chapter 2
16:25 AI Code Refusals and Global Adoption Race
18:10 Three Pillars of AI Adoption
19:59 US AI Trust and Global Competition chapter 1
21:55 Balancing AI Speed and Safety
25:49 AI Cybersecurity Risks and Policy Balance chapter 2
28:20 Balancing AI Safety and Economic Growth
31:07 2026 Cyber AI Threats and Defense
33:29 AI Drone Swarms and Reagan Legacy chapter 2
35:49 US Drone Swarm Investment and AI Warfare
37:55 Reagan's Shining City on Hill

Transcript

Loading transcript...