House Intelligence Committee to Examine AI Modernization Versus Legacy Security Risks
House Intelligence Committee hearing Sept. 2 examines Pentagon AI modernization clash with vulnerable legacy systems targeted by state actors.
The House Permanent Select Committee on Intelligence will hold a hearing Wednesday on the collision between the Pentagon's drive to deploy artificial intelligence at wartime speed and the security crisis embedded in decades-old legacy systems. Chairman Rick Crawford, Republican of Arkansas, and Ranking Member Jim Himes, Democrat of Connecticut, lead the session titled Persistent Competition and Legacy Architectures. No formal witnesses have been announced.
The Pentagon's 2026 AI Strategy explicitly directs the military to reject what it calls the legacy linear model and adopt AI-first approaches to maintain technological advantage. That mandate reflects a broader push across the Defense Department and intelligence community to integrate machine learning, autonomous systems, and real-time data analytics into core operations. The strategy treats speed of adoption as a strategic imperative.
That imperative runs directly into a documented vulnerability. Legacy, internet-facing systems remain prime targets for state-sponsored actors. The Cybersecurity and Infrastructure Security Agency has identified organizations across energy, water, manufacturing, and communications sectors as facing immediate risk from adversaries including Volt Typhoon, a China-linked group that specifically targets operational technology systems to compromise and maintain persistent access. CISA guidance released this year calls out legacy constraints in operational technology environments as a primary vulnerability.
The tension is not abstract. Operational technology — the hardware and software that monitors and controls physical infrastructure — was designed decades ago without modern threat models. Many systems lack encryption, authentication, or the ability to receive security patches. Connecting these systems to AI-driven analytics or cloud platforms expands the attack surface unless the underlying architecture is replaced or rigorously segmented.
Senator Ron Wyden, Democrat of Oregon, pressed the issue in July. He urged the Office of Management and Budget, CISA, and the National Institute of Standards and Technology to mandate the phase-out of insecure legacy remote-access systems. His letter argued that voluntary guidance has failed to dislodge equipment that provides known entry points for adversaries.
The hearing will test whether Congress can align funding, acquisition authority, and oversight to resolve the standoff. The intelligence community's budget requests increasingly prioritize AI capabilities, but appropriations for legacy replacement lag. Program offices often face a choice: sustain existing systems to maintain operational continuity or divert resources to modernization that may not field for years.
Crawford and Himes have both signaled concern about intelligence community readiness. Crawford has emphasized supply chain risks in critical infrastructure. Himes has warned that adversaries are exploiting the gap between policy directives and operational reality. The hearing's focus on persistent competition suggests the committee views this as an enduring structural problem rather than a discrete procurement issue.
What emerges from Wednesday's session will indicate whether the committee treats legacy modernization as a prerequisite for AI deployment or as a parallel track that can be managed separately. The evidence so far suggests the two are inseparable. AI models trained on data from compromised systems produce compromised outputs. Autonomous systems dependent on legacy communications links inherit the vulnerabilities of those links. The hearing's framing — persistent competition — implies the committee understands the timeline: adversaries are already inside the architecture the Pentagon is trying to build on top of.
Continue reading
More in this thread
Conversation
Reader notes
Loading comments...