The Glass Ceiling
Six weeks after Deepfake October, Dr. Lena Vasquez testifies before Congress on the need for centralized AI defense. She is polished, credible, frightening in exactly the right places — and between the lines she is reading out a sales catalogue. The hearing that helped pass ASHPA was also a market survey.
How we got hereHEARING BEFORE THE SENATE COMMITTEE ON HOMELAND SECURITY AND GOVERNMENTAL AFFAIRS. *On the Synthetic Threat to Critical Information Systems.* November 18, 2027. The October deepfakes are six weeks old. The markets are still twitchy. The room wants to be told there is a fix, and a fixer has come to tell them so.
The following is a fragment of the transcript, recovered later, annotated later still. The margin notes are in the hand of a committee staffer who has asked not to be named and who, in 2027, was the only person in the room paying attention to the wrong thing.
THE CHAIR: Dr. Vasquez, thank you for your testimony. You’ve heard the concern around this table. Six weeks ago, half the country watched a video of a sitting governor declaring martial law that he never declared. The markets moved billions on a forgery. So I’ll ask plainly. Can this be defended against?
DR. VASQUEZ: Yes, Senator. But not by the institutions you currently have, and not at the speed they currently move. A synthetic-media attack executes in milliseconds and propagates in minutes. Your detection infrastructure is human-in-the-loop and operates on the timescale of a news cycle. You are bringing a subpoena to a knife fight. What October demonstrated is that defense at machine speed requires defense by machine — a centralized verification layer, continuously updated, with authority to act before a human can convene.
SENATOR (name redacted in source): “Authority to act.” You’re describing a system that takes content down without anyone signing off.
DR. VASQUEZ: I’m describing a system that flags and quarantines at machine speed and surfaces to human review. The alternative is what you saw in October: act after the damage, or don’t act at all. I’ve spent eleven years building threat models for exactly this contingency. The architecture exists. What doesn’t exist is the legal mandate to deploy it, and the procurement framework to fund it. That is this committee’s gift to give.
THE CHAIR: Walk us through the architecture. In terms a layman can follow.
DR. VASQUEZ: Of course. Picture the national information space as a body, and synthetic media as an infection. You can’t inspect every cell — there are too many, and they change too fast. So you build an immune system: a small number of hardened verification nodes, positioned at the chokepoints where information concentrates. The exchanges. The major platforms. The financial data feeds. The emergency-broadcast layer. You don’t have to watch everything. You have to watch the places that matter, and you have to own them completely. Harden those, and a forgery has nowhere to land that the system hasn’t already certified.
THE CHAIR: And the cost of leaving those — chokepoints, you called them — undefended?
DR. VASQUEZ: Catastrophic, Senator, and asymmetric. I can give the committee a tiered assessment. There are perhaps forty information systems in this country whose compromise would constitute a national emergency. Of those, by my analysis, thirty-one are currently running detection software that was state of the art in 2024 and is now, functionally, decorative. I can submit the list. I would recommend it be received under seal.
SENATOR (name redacted): You seem to know precisely which systems are exposed.
DR. VASQUEZ: It’s my profession to know, Senator. I’d be failing this committee if I didn’t.
THE CHAIR: And were Congress to act — to create the mandate you describe — how quickly could a verification layer be stood up?
DR. VASQUEZ: Faster than you’d expect. The reference designs are mature. The bottleneck has never been engineering. It has always been authorization. Give the private sector a clear mandate and a clear standard to certify against, and you will have hardened the first tier of chokepoints inside a fiscal year. I would stake my reputation on it.
THE CHAIR: We may hold you to that, Doctor.
DR. VASQUEZ: I’d welcome it.
The bill that became the AI Safety and Homeland Protection Act took its skeleton from her testimony almost verbatim — the chokepoint model, the certification standard, the machine-speed quarantine authority, the “first tier of forty systems.” Her phrase, “defense at machine speed requires defense by machine,” ran in the committee report without quotation marks, as though it were a finding rather than a sales line. ██████████████████████████████████████████████████████████████████████████████████ is the kind of sentence that did not appear in any contemporaneous coverage, because in 2027 nobody was reading the transcript for that.
By 2029, Vasquez Security held verification contracts with forty percent of the Fortune 100’s AI systems — and the certification standard those contracts measured against was, by then, the federal one. The list she offered to submit under seal turned out to describe her own pipeline. Every exposed system she named was a system she was already positioned to harden. The hearing was not a warning. It was an order book read aloud, and Congress signed it.
By 2035, when the OHC mesh had eaten the world her institutions could no longer defend, Lena Vasquez was the highest-ranked American on its mesh security council — the chokepoint doctrine intact, only the flag above it changed. She had built the playbook for defending a nation, sold it to that nation, watched the nation fall, and carried the playbook across to whatever came next. The architecture didn’t care who owned the chokepoints. It only cared that someone did, and that the someone had the list.
Nobody, in 2027 or after, asked who wrote the threat.