Showing posts with label AI. Show all posts
Showing posts with label AI. Show all posts

Saturday, March 14, 2026

BIS Withdraws AI Action Plan Final Rule

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that the DOC’s Bureau of Industry and Security (BIS) has withdrawn their submitted final rule on “AI Action Plan Implementation”. The final rule was submitted to OIRA on February 26th, 2026.

According to the Spring 2025 Unified Agenda entry for this rulemaking:

“The Bureau of Industry and Security (BIS) intends to rescind portions of the revisions and additions implemented by the Framework for Artificial Intelligence Diffusion,” published January 15, 2025. BIS intends to issue a new rule which will provide a more streamlined framework for enabling the secure deployment of advanced U.S. AI technology abroad.”

I am not sure why this final rule was withdrawn, but the Administration’s AI Action Plan is a significant part of its agenda, so I would expect BIS to resubmit a revised final rule, sooner rather than later.

As I noted in my earlier post on this rulemaking, this does not appear to be something that I would expect to cover in any detail, but AI is increasingly touching on cybersecurity and process management, so it is something that I would expect to be mentioning in passing.

Wednesday, March 11, 2026

Review – HR 7294 Introduced – AI for Secure Networks

Last month Rep Menendez (D,NJ) introduced HR 7294, the AI for Secure Networks Act. The bill would require the Department of Commerce to conduct a study on the impact of artificial intelligence technology with respect to the security of telecommunications networks. No new funding is authorized by this bill.

A press release from the office  of Menendez notes that:

“While artificial intelligence has unfortunately given our adversaries powerful new tools to launch mass cyberattacks against critical infrastructure, AI can, and should, also be used to harden and defend those same systems. That’s why I’m proud to lead the bipartisan, common-sense AI for Secure Networks Act to harness AI to strengthen real-time threat detection, boost resiliency and interoperability, and make our next-generation networks more secure and efficient. The threat is real, and the United States must act now to secure our networks for the future.”

Moving Forward

Menendez, and his three cosponsors {Rep Pfluger (R,TX), Rep McClellan (D,NJ), and Rep Landsman (D,OH)}, are all members of the House Energy and Commerce Committee to which this bill was assigned for consideration. This means that there could be sufficient influence to see the bill considered in the Committee. I see nothing in the legislation that would engender any organized opposition. I suspect that there would be significant bipartisan support for the bill. Whether there would be sufficient support for the bill to be considered by the full House under the suspension of the rules process.

 

For more information on the provisions of this bill, as well as commentary on the reason for such reports from the Executive Branch, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-7294-introduced-ai-for-secure - subscription required.

Friday, February 27, 2026

BIS Sends AI Action Plan Final Rule to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a final rule from the DOC’s Bureau of Industry and Security (BIS) on “AI Action Plan Implementation”. An interim final rule was published (under the earlier title of this rulemaking; Framework for Artificial Intelligence Diffusion) on January 15th, 2025.

According to the Spring 2025 Unified Agenda for this rulemaking:

“The Bureau of Industry and Security (BIS) intends to rescind portions of the revisions and additions implemented by the Framework for Artificial Intelligence Diffusion,” published January 15, 2025. BIS intends to issue a new rule which will provide a more streamlined framework for enabling the secure deployment of advanced U.S. AI technology abroad.”

This final rule would appear to be beyond the normal scope of coverage of this blog, so I do not plan on detailed coverage of its publication. I would expect to announce that, however, in the appropriate Short Takes post.

Tuesday, December 10, 2024

BIS Sends AI Export Control Framework IFR to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received an interim final rule (IFR) from the DOC’s Bureau of Industry and Security (BIS) on “Export Control Framework for Artificial Intelligence Diffusion”. This rulemaking was not listed in the Spring 2024 Unified Agenda.

NOTE: I cannot wait to see how BIS is going to define ‘artificial intelligence diffusion’….

Wednesday, October 9, 2024

Review - HR 9720 Introduced – NVD AI Update

Last month Rep Ross (D,NC) introduced HR 9720, the AI Incident Reporting and Security Enhancement Act. The bill would require the National Institute of Standards and Technology (NIST) to update the National Vulnerability Database (NVD) definitions and process to encourage voluntary disclosures of artificial intelligence safety and security incidents. NIST would also be required to track AI vulnerability reporting. No new funding is authorized by this legislation.

Moving Forward

Ross and one of her two cosponsors, Rep Obernolte (R,CA), are both members of the House Science, Space, and Technology Committee to which this bill was assigned for consideration. This means that there may be sufficient influence to see the bill considered in Committee. With the emphasis in the language on voluntary participation, I see nothing in the bill that would engender organized opposition to this legislation. I suspect that there will be some level of bipartisan support for HR 9720, whether it will be enough to allow the bill to be considered in the full House under the suspension of the rules process remains to be seen.

 

For more information about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-9720-introduced - subscription required.

Tuesday, October 8, 2024

Review – HR 9466 Introduced – AI Standards

Last month, Rep Baird (R,IN) introduced HR 9466, the AI Development Practices Act of 2024. The bill would amend 15 USC 278h-1, Standards for artificial intelligence. It would require the National Institute of Standards and Technology (NIST) to develop “voluntary guidance for practices and guidelines relating to the development, release, and assessment of artificial intelligence systems”. No new funding would be authorized by this bill.

Moving Forward

Baird, and one of his six cosponsors {Rep Bonamici (D,OR)}, are members of the House Science, Space, and Technology Committee to which this bill was assigned for consideration. This means that there may be sufficient influence to see the bill considered in Committee. Especially with no new funding authorization, I see nothing in the bill that engender any organized opposition. I suspect that the bill would receive some level of bipartisan report, sufficient bipartisan support, in fact, to see the bill (if reported favorably by the SST Committee) considered by the full House under the suspension of the rules process.

Commentary

My interest in AI, at least as far as this blog is concerned, is the need for cybersecurity protections for what is, at base, a sophisticated, complex, self-correcting, computer program. This is briefly and ineffectively accomplished here by requiring the development of security benchmarks {(h)(1)(B)(iii)} and disclosure of security practices {(h)(1)(B)(vi)} (thus the need for the definition of security of the term “artificial intelligence red teaming”).

As the use of AI systems is being expanded in the area of chemical and biological process development and control, the need for such cybersecurity protections becomes more important. While all software deserves at least some level of such protections, process controls that could be used to cause catastrophic disruptions of facilities and local communities should arguably be required to have some minimal level protection against unauthorized manipulations.

 

For more information on the provisions of this bill, as well as my suggestions for some added cybersecurity related verbiage, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-9466-introduced - subscription required.

Thursday, June 6, 2024

BIS Sends AI Reporting NPRM To OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking from the DOC’s Bureau of Industry and Security (BIS) on “Establishment of Reporting Requirement for the Development of Advanced Artificial Intelligence Models and Computing Clusters.” This rulemaking was not listed in the latest version of the Unified Agenda, so there is no information there about the content of this NPRM.

I probably will not be covering this rulemaking in any depth, but you never can tell with BIS what the scope of this rulemaking will entail.

 
/* Use this with templates/template-twocol.html */