A new report says the U.S. government has no reliable way to check whether AI companies are telling the truth about their own products. The finding comes from a survey published Wednesday by the Institute for Security and Technology, known as IST.
The survey gathered responses from 111 people working in national security. They came from different fields, including cybersecurity, defense, and policy. The survey ran from late April to mid-July.
Why Verification Is a Problem
Respondents said the government has underinvested in testing and evaluating AI systems for years. There is no independent process to check these systems. There is also no reliable way to measure how powerful a frontier AI model actually is.
Without its own testing tools, the government has to trust what AI companies say. The report put it simply: officials are "left to take capability claims on faith rather than measurement."
This matters most when AI gets built into military systems or other critical technology. Leaders cannot confirm how these systems will behave before they are put to use.
Many experts also said they do not trust AI systems to act on their own. Hallucination, when an AI system produces false information, was described as a built-in problem rather than a bug that can be fixed.
One expert summed it up this way: AI can make a good analysis better, but it can also make a bad one worse.
Cyber Defense Gets Mixed Reviews
More than 80% of respondents said AI would likely improve cyber defense tools. This includes tasks like finding software flaws, studying malware, and responding to security incidents.
Despite that optimism, 57% of respondents said AI is currently helping attackers more than defenders. This suggests hackers may be adapting to the technology faster than security teams.
The single biggest cybersecurity risk, according to the survey, is AI's ability to find and exploit vulnerabilities in software. Respondents ranked this risk well above others.
Legal and regulatory gaps ranked as the second biggest obstacle to fighting AI-driven threats. But experts did not agree on the best fix.
About a quarter of respondents wanted federal rules that apply across every industry. 31% preferred rules written for specific sectors, like finance or defense. The largest group, 36%, wanted a mix of both approaches.
Experts also warned policymakers not to focus too much on AI's unusual abilities. They said basic cybersecurity failures, the kind that have existed for decades, remain the most likely cause of serious problems.
These problems include loss of control over AI systems, manipulation by outside attackers, and theft of AI model data or weapons designs.
IST's report stated that the real bottleneck is not the technology itself. It is the difficulty of deploying strong cyber defense at scale across government and industry.
Weak cybersecurity practices, the report added, will make many of these other AI risks more likely to happen. The survey results are meant to guide policymakers as they shape future AI rules.