Cyber Policy Competition

Description

The rapid adoption of artificial intelligence across the digital ecosystem has reshaped how software and systems are developed. Practices such as “vibe coding”, using AI code-generation tools without deep technical expertise, are spreading quickly. At the same time, adversaries are experimenting with data poisoning, inserting malicious or falsified information into training pipelines to compromise AI models. These dynamics accelerate innovation but also create unprecedented cybersecurity risks: insecure code proliferates, poisoned datasets enable hidden backdoors, and attackers may gain systemic advantage as AI shifts the offense-defense balance.

Compounding the challenge, leading experts suggest that AI systems may never be fully secure. If this is true, policymakers, industry leaders, and researchers must grapple with how to manage residual risks, foster resilience, and ensure accountability. Without clear policies, responsibility for failures often falls to end-users, an unsustainable arrangement in a hyperconnected world.

The imperative today is to design governance frameworks that acknowledge AI’s dual nature: a powerful enabler of cybersecurity, but also a vector for new vulnerabilities. The CSAW 2025 Cyber Policy Competition focuses on addressing these concerns, working toward policies that balance innovation with accountability, liability, and resilience in the age of AI.

Key areas to research in this cyber policy area include:​

1. AI Security and Liability

  • Market Dynamics: Examine how AI-assisted development (e.g., vibe coding) rewards speed and functionality at the expense of secure engineering practices.
  • Duty of Care: Discuss the responsibility of AI tool developers, dataset curators, and vendors toward consumers, businesses, and critical infrastructure providers.
  • Liability Shift: Propose mechanisms to shift responsibility from end-users to those who deploy or distribute vulnerable AI-enabled products or poisoned datasets.

2. Global Impact and Best Practices

  • Global Standards: Explore whether international norms or standards for AI system assurance and dataset provenance are feasible, and what they might look like.
  • Cross-Border Risks: Analyze the global implications of AI-driven offense-defense dynamics and the role of export controls, multilateral cooperation, and norms.

Open-Source AI in the Global Arena: Debate the opportunities and challenges of open-source models and datasets, especially around accountability and transparency.

Cyber Policy Competition

This year’s edition is coming soon.