Showing posts with label AI Security. Show all posts
Showing posts with label AI Security. Show all posts

Sunday, January 4, 2026

Review – S 3202 Introduced – AI Security

Back in November Sen Young (R,IN) introduced S 3202, the Advanced Artificial Intelligence Security Readiness Act of 2025. The bill would require the NSA’s Artificial Intelligence Security Center (AISC) to develop and disseminate security guidance that identifies potential vulnerabilities in covered artificial intelligence technologies and artificial intelligence supply chains. No new funding is authorized.

Moving Forward

Young and his sole cosponsor, Sen Kelly (D,AZ), are members of the Senate Select Committee on Intelligence, the committee to which this bill was referred for consideration. This means that there may be sufficient influence to see the bill considered in Committee. I was surprised to see that the word ‘voluntary’ was not used in this bill to describe the guidance being developed. Other than that, I see nothing in this bill that would engender any organized opposition. I suspect that there would be broad bipartisan support for the bill were it to be considered (after clarifying that the guidance was completely voluntary).

This bill will run into the same problem that most bills encounter in the Senate; it simply is not politically important enough to take the time necessary to proceed under regular order. I do suspect that this bill might be a reasonable candidate for consideration under the Senate’ unanimous consent process, but that is always an iffy process, being potentially subject to opposition for reasons having nothing to do with the provisions of the bill. This is a better candidate to be included in the annual intelligence authorization bill for FY 2027.

Commentary

For purposes of determining coverage in this blog, I am assuming that “performance in chemical, biological, radiological, and nuclear matters” in §2(f)(4) includes industrial control systems used in manufacturing in those ‘matters. I would, however, prefer to see that more explicitly laid out in the bill. To that end I would like to propose a new term: artificial intelligence supported manufacturing and would insert “including artificial intelligence supported manufacturing,” after the word ‘matters’ in that definition. I would then define that term in a new §2(f)(7):

“(7) The term ‘artificial intelligence supported manufacturing’ means the use of artificial intelligence to design, monitor, or control an information system, as that term is defined in 6 USC 650(14), in a manufacturing process.”

 

For more information on the provisions of the bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-3202-introduced-ai-security - subscription required.

Thursday, October 30, 2025

Review – S 2938 Introduced – Advanced AI Evaluation

Last month Sen Hawley (R,MO) introduced S 2938, the Artificial Intelligence Risk Evaluation Act of 2025. The bill would require DOE to establish an Advanced Artificial Intelligence Evaluation Program, and each year submit to Congress a detailed recommendation for Federal oversight of advanced artificial intelligence systems. No new funding is provided in the bill.

Commentary

This bill does not actually allow for DOE to conduct regulatory oversight of covered advanced AI system developers or systems, but the requirement for information provision to DOE with the accompanying penalty for noncompliance makes this a de facto regulatory scheme, that would be certain to morph into an active regulatory effort. This is especially important because there is no language in the bill that would prohibit DOE regulatory efforts. More importantly, there is no language that would limit DOE from sharing the information either on its own initiative or under provisions of the Freedom of Information Act.

 

For more information on the provisions of this bill, including commentary on the selection of DOE as the action agency, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-2938-introduced-advanced-ai-evaluation - subscription required.

Wednesday, September 11, 2024

Review – BIS Publishes AI Reporting Requirements NPRM

Today, the DOC’s Bureau of Industry and Security published a notice of proposed rulemaking (NPRM) in the Federal Register (89 FR 73612-73617) on “Establishment of Reporting Requirements for the Development of Advanced Artificial Intelligence Models and Computing Clusters”. This rulemaking would fulfill the requirements for §4.2(a)(i) of EO 14110, Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence. This proposed rule would amend the BIS Industrial Base Surveys—Data Collections regulations by establishing reporting requirements for the development of advanced artificial intelligence (AI) models and computing clusters.

Public Comments

BIS is soliciting public comments on this rulemaking, including comments about the following topics:

Quarterly Notification Schedule,

Information Collection and Storage,

Collection thresholds.

Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # BIS-2024-0047). Comments should be submitted by October 11th, 2024,

Commentary

BIS notes that: “For similar reasons, the U.S. Government must minimize the vulnerability of dual-use foundation models to cyberattacks.” Unfortunately, the only cybersecurity reporting action that BIS is taking in this rulemaking is including a requirement to “including the physical and cybersecurity protections taken to assure the integrity of that training process against sophisticated threats”. Anyone that follows cybersecurity news has to realize that even well designed systems are subject to 3rd party researchers finding and exploiting vulnerabilities that are unidentified by the vendor. While design reviews such as the one required in this rulemaking are important, a comprehensive cybersecurity program also requires a vulnerability disclosure program and a cyber incident reporting program.

 

For more details about the requirements of this proposed regulation, including a potential fix to one of the problems identified in my commentary, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/bis-publishes-ai-reporting-requirements - subscription required.

Sunday, June 9, 2024

Review - S 4230 Introduced – Secure AI Act

Last month, Sen Warner (D,VA) introduced S 4230, the Secure Artificial Intelligence (Secure A.I.) Act of 2024. The bill would provide for voluntary reporting and tracking of AI security and safety incidents. It would require updating of the Common Vulnerabilities and Exposures Program to better include AI vulnerabilities. It would also establish within the NSA’s Cybersecurity Collaboration Center an AI security center. No new funding is authorized by this bill.

Moving Forward

Neither Warner nor his sole cosponsor {Sen Tillis (R,NC)} are members of the Senate Commerce, Science, and Technology Committee to which this bill was assigned for consideration. This means that there is not likely enough influence to see this bill considered in Committee. I suspect that there would be some level of bipartisan support for this legislation were it to be considered. Unfortunately, like most proposed legislation, this bill is not politically important enough for the Senate to take up the bill under regular order. This leaves the unanimous consent process, which allows a single Senator to stop consideration, or add the language in the bill as an amendment to some more politically important legislation. Both processes are very iffy.

Commentary

As more control system vendors are offering AI enhanced systems to control operational technology (OT), safety and security of such AI enhanced systems is becoming more important. The second part of the definition of ‘artificial intelligence safety incident’ clearly attempts to address OT use of AI. Unfortunately, there is not equivalent OT language in the definition of ‘artificial intelligence security incident’. I would add a new §2(2)(C):

“(C) the ability of a third party to manipulate an artificial intelligence system in order to cause the loss of view, or the of loss of control of an operational control system.”

 

For more information on the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-4230-introduced - subscription required.

 
/* Use this with templates/template-twocol.html */