← Back to Blog

Corridor Testifies Before Congress on the AI Security Landscape

On June 4th, Corridor CEO and co-founder Jack Cable testified before the House Committee on Homeland Security's Subcommittee on Cybersecurity and Infrastructure Protection. The hearing titled "The AI Security Landscape: How Frontier Models, Agentic AI, and AI Coding Tools Are Reshaping Cybersecurity and Critical Infrastructure Resilience" took on major questions the industry has been wrestling with about frontier models. Here were Jack’s main points at the testimony.

Image of Jack

Code volume and vulnerabilities are rising, but patching isn't keeping up

Attackers generally aren't exploiting new kinds of vulnerabilities. They're exploiting the same ones we've known about for decades, like buffer overflows and vulnerable network edge devices. These represent weak spots in underlying software that should have been fixed years ago.

The rapidly-increasing scale of this problem is striking. Of the 1,500+ vulnerabilities Anthropic has disclosed through Mythos, only around 6% have been fixed. While this illustrates how effectively Mythos-class models can find vulnerabilities at scale, it also shows how far behind developers have fallen on patching them. If the pattern holds, the next model will only find more with developers left with the burden of fixing them.

This is the primary dynamic Congress was wrestling with, as frontier models are accelerating both the introduction and the discovery of vulnerabilities at once. GitHub reported a 14x increase in code committed in 2026 versus 2025, and Sundar Pichai has said 75% of new code at Google is AI-generated. More AI-generated code means more vulnerabilities at scale, and Mythos-class models are better at finding and exploiting them than any tool in the history of hacking. Traditional code review (which is already a bottleneck) has broken down under the volume. Patching alone won't get us out of this.

We should be moving upstream of code written

Much of the hearing framed AI security as a detection-and-response problem. We deploy AI to find threats faster, respond at record speed, and build smarter monitoring. However, our solution was instead to move upstream.

Congressman Fong asked how rural hospitals and small utilities could possibly keep up with the immense volume of AI-generated vulnerability findings. There are two prevailing approaches to answering this question:

  1. Shift right: improve detection and defense once code is already running.
  2. Shift left: move into the development process itself and stop vulnerabilities from shipping in the first place.

Corridor is built on shifting left. Our internal data shows that 13% of code changes generated by AI coding agents contain security vulnerabilities, and our customers see a 60% reduction in vulnerabilities when security context is applied at the planning stage, before the agent writes a single line.

AI can also help clear the remediation backlog. Work that used to take years of human effort and millions of dollars to refactor can now be done in weeks. DARPA's TRACTOR program, focused on translating unsafe C code into memory-safe languages, is exactly the kind of initiative that scales this approach. The goal is software that's resilient to entire classes of vulnerabilities, not just the ones the latest model happened to surface.

Open-weight models remain a gap

One of the sharper exchanges was about PRC-origin models in the software supply chain. The question on the table was: if Chinese open-weight models become the global default for developer tooling because they're inexpensive, capable, and run locally, what leverage does that hand to adversaries?

We believe that developers reach for those models because there simply are no viable frontier open-weight models from the United States. Meta and OpenAI have released open-weight models, but they've quickly fallen out of date. Meanwhile, Kimi and Qwen rival the performance of US frontier models from six months ago at a fraction of the cost.

Restricting Chinese models isn't the answer, as their capabilities can't be contained. The answer is to build competitive American alternatives. Initiatives like Marin and Olmo from AI2 are promising starts, and the NSF–NVIDIA partnership to support open multimodal AI infrastructure is a step in the right direction.

Three recommendations to the committee

The testimony closed with three recommendations:

  1. Prevent vulnerabilities in new code. The federal government should require AI coding guardrails across agencies and contractors that stop entire vulnerability classes before code ships. What the government mandates for itself will naturally propagate to the rest of the industry.
  2. Harden the open source foundation. Open source software underpins critical infrastructure and the federal government alike, and it will be hit hardest by adversaries with access to Mythos-class models. Our recommendation: a multi-billion-dollar initiative for large-scale, security-oriented refactors of the critical open source components everything else is built on, rather than one-off patches.
  3. Build the open-weight ecosystem. The US needs frontier open-weight models that can compete globally on performance and cost. This takes sustained, intentional investments.

The technology to do all three already exists. The open question is whether policy can move fast enough to use it before the next model release creates another emergency.

Learn more on the Homeland Security website or read Jack Cable’s Written Testimony.

Get Started Today

Security should move at the same pace as innovation. Start building securely with Corridor.