Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity And Ai Training topic

No spam. Unsubscribe anytime.

House Energy committee receives training on AI, cybersecurity and information warfare

3296643 · May 15, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Members of the Vermont House Energy and Digital Infrastructure committee received a multi-part briefing May 14 on artificial intelligence, cybersecurity and information warfare from outside experts at Norwich University and private industry. Speakers urged stronger governance, testing and cross‑sector planning but no formal actions were taken.

Members of the Vermont House Energy and Digital Infrastructure committee on May 14 held a training session on artificial intelligence, cybersecurity and information warfare featuring presenters from Norwich University Applied Research Institutes and private-sector specialists.

The training, opened by Representative Kathleen James and led by Phil Sussman, president of Norwich University Applied Research Institutes, included a primer on AI and governance by Rachel Sickler, a senior developer and machine learning engineer at Nuare, a cybersecurity overview by Sussman and a discussion of information‑warfare concepts by John Kidder of the Applied Research Institute. The session was broadcast on YouTube and portioned into three instructional modules; the committee indicated it would enter executive session later for a confidential module.

Why it matters: committee members were briefed on technical, policy and operational issues that affect state government systems, municipalities, schools and small businesses. Presenters warned that rapid change in AI and an evolving threat environment in cyberspace raise governance, testing and resource questions for state and local institutions.

Rachel Sickler described distinctions among AI methods, the limits of generative models and governance best practices. "The purpose should never be just to use AI," Sickler said, arguing projects should start from well‑defined problems and measurable success criteria. She urged clear disclosures when the public is interacting with AI, records of AI use in decisionmaking, independent predeployment audits and an appeals process when automated systems affect citizens. Sickler also noted costs and environmental impacts of large models, saying inference can cost "as much as 15¢" per query and that training and hosting models consumes substantial compute and water resources.

Phil Sussman framed cybersecurity as an organizational and community problem, not solely an IT function, and walked the committee through identification, protection, detection, response and recovery steps from the NIST cybersecurity framework. Sussman cited a range of threats, from criminal marketplaces that lower the skill needed to mount attacks to nation‑state campaigns, and referenced past incidents to illustrate risk: the 2012 Saudi Aramco destructive attack that disabled thousands of computers, a multiyear malware campaign that went undetected on retail payment platforms, and the 2020 University of Vermont cyber incident he said was estimated at about $63,000,000 in impact. "We are a digital society," Sussman said, adding that small municipalities, school districts and manufacturers often lack resources to meet emerging requirements such as some federal contracting cybersecurity standards.

Speakers emphasized testing and exercises. Sussman described cross‑sector exercises (for example, the Quantum Dawn exercises in the finance sector) that created playbooks for restoring critical financial functions when technology is unavailable. Committee members asked about penetration testing; Sussman said the state conducts penetration testing of statewide networks and noted many smaller municipalities do not.

On data governance and consent, Sickler described "opt in" as applying before training a model on identifiable data and suggested outreach (for example, notification or survey) when an organization intends to use resident data for a model. She also cautioned that even when fields such as race or gender are removed, proxy variables can still produce discriminatory outputs and urged human‑in‑the‑loop testing and domain‑expert review.

Presenters proposed governance measures such as cross‑sector AI oversight committees, predeployment independent audits and stronger recordkeeping for when and how AI is used in public services. They also urged practical cyber hygiene steps — multifactor authentication, role‑based access, regular exercise of incident response plans — and relationships with law enforcement and federal partners before incidents occur.

No motions or formal votes occurred; the session was educational. Committee members and presenters discussed possible follow‑up topics including support for municipalities and school districts, workforce development, and the implications of federal proposals that could preempt state data governance. The committee planned a short break and said it would move off the public YouTube feed for a confidential portion of the training later in the morning.

The committee will receive the presenters' slides, and speakers offered to provide follow‑up information on specific items such as the geography of data centers and details on penetration testing at the state level.