The Inner Circle

 View Only
Expand all | Collapse all

Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence

  • 1.  Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence

    Posted Oct 31, 2023 01:56:00 PM

    Hi All,

    The White House issued an Executive Order (EO) on Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence (AI), which will support an array of work across the federal government. To advance the objectives of the AI EO, FedRAMP will establish strategies for authorizing emerging technologies, including cloud-based AI-related products, ensuring agencies have the tools they need to more effectively serve the public.

    In collaboration with stakeholders from the commercial and federal space, FedRAMP is conducting an analysis to determine the impact to security controls with the introduction of AI systems into a FedRAMP authorized system boundary. We will also spearhead collaboration with the FedRAMP Board, the Office of Management & Budget, the National Institute of Standards and Technology, and the Federal Secure Cloud Advisory Committee to create and gain consensus on the authorization strategy for emerging technologies.

    FedRAMP will communicate the details of the finalized framework through a series of FAQs, blogs, and forums to educate and train the community.

    We look forward to partnering with our stakeholders on this important endeavor as we set the standard for what's possible through AI and emerging technologies.

    Please reach out to [email protected] with any questions.

    https://www.whitehouse.gov/briefing-room/presidential-actions/2023/10/30/executive-order-on-the-safe-secure-and-trustworthy-development-and-use-of-artificial-intelligence/



    ------------------------------
    Michael Roza CPA, CISA, CIA, CC, MBA, Exec MBA, CSA Research Fe
    ------------------------------


  • 2.  RE: Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence

    Posted Nov 06, 2023 09:56:00 AM

    Hi Michael, lets chat. I did a blog post on AI policies comparison between the Oct 2023 US EO and the EU AI Act and how it affects cybersecurity and innovation. 

    //Romeo



    ------------------------------
    Romeo Ayalin II
    ------------------------------



  • 3.  RE: Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence

    Posted Nov 07, 2023 04:13:00 AM

    Hello Romeo. Where can we find that post? I sit on an industry working group looking at the governance of AI. Your post comparing the US EO and the EU AI Act would be insightful. Cheers, alex.



    ------------------------------
    Alex Sharpe
    Principal
    Sharpe42
    [email protected]
    Co-Chair Philosophy & Guiding Principles Working Group
    Co-Chair Organizational Strategy & Governance Working Group
    ------------------------------



  • 4.  RE: Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence

    Posted Nov 07, 2023 07:41:00 AM

    Hi Alex, it's being checked for plagiarism and being vetted and I hear it should be done by end of this week so it can get some published online. What working group are you a part of?

    Romeo 



    ------------------------------
    Romeo Ayalin II
    ------------------------------



  • 5.  RE: Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence

    Posted Nov 08, 2023 07:33:00 AM

    Hi Alex here's the link to the blog post I wrote comparing and contrasting the EU AI Act and the Oct 2023 U.S. EO.

    https://cybersecurityadvisors.network/2023/11/08/the-tale-of-two-approaches-ai/



    ------------------------------
    Romeo Ayalin II
    ------------------------------



  • 6.  RE: Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence

    Posted Nov 09, 2023 07:28:00 AM

    Thank you, Romeo. Much appreciated.



    ------------------------------
    Alex Sharpe
    Principal
    Sharpe42
    [email protected]
    Co-Chair Philosophy & Guiding Principles Working Group
    Co-Chair Organizational Strategy & Governance Working Group
    ------------------------------



  • 7.  RE: Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence

    Posted Nov 12, 2023 02:04:00 PM

    Hi Alex - The 3rd talks of the EU AI Act was reached an impasse this past Friday, as the EU Parliament, the Council of Europe were not able to agree on.  Instead, they focused their discussion on foundation models - there was a consensus before and that's how the tiered approach  came to be. France, Germany and Italy pushed back against any type of regulation for foundation models and thus the impasse. Mistral the French AI company is really lobbying and arguing that the AI Act could kill the company and regulation would put the EU competitiveness behind the US and China. 

    Here's the article- https://www.euractiv.com/section/artificial-intelligence/news/eus-ai-act-negotiations-hit-the-brakes-over-foundation-models/

    Here are some of my guesses on how this can turn out:  

    1- they manage to overcome the impasse and get a consensus. they would need to have intense discussion to put down on a paper a clear and comprehensive framework for regulating foundation models. 

    2-they fail and negotiations and talks with stall and be discussed indefinetely. No law makes common coherent approach in the EU non-existent causing uncertainty and perhaps fragmentation of the application of AI across the EU.  

    3-EU reaches compromise but with concessions and loopholes for foundation models. Affect on AI companies in EU will make competitiveness weaker as the legislation will be weak. 

    Will see what the talks this coming Tuesday brings.

    //Romeo 



    ------------------------------
    Romeo Ayalin II
    ------------------------------



  • 8.  RE: Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence

    Posted Dec 14, 2023 02:04:00 PM

    Hello, 

    I'm a new member to CSA (and info security in general). It seems some progress was made this month, though serious decisions still need to be made (e.g., law enforcement use of AI) - https://www.euractiv.com/section/artificial-intelligence/news/ai-act-eu-policymakers-nail-down-rules-on-ai-models-butt-heads-on-law-enforcement/

    For those more "in the know," where does that leave things now? 

    Thank you all for this enlightening exchange. The blog post was interesting. 

    - Kevin Tuczek



    ------------------------------
    Kevin Tuczek
    Unknown
    Unknown
    ------------------------------



  • 9.  RE: Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence

    Posted Dec 15, 2023 04:35:00 PM

    I am preparing a research paper and presentation on this subject.  Following is the draft abstract.

    ABSTRACT: EO 14110 The Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence

    Over the past two months, the US Federal Government has outlined its approach to artificial intelligence. The Executive Order (EO) 14110, released on October 30, 2023, aims to ensure artificial intelligence's safe, secure, and trustworthy development and use. This order is significant as it mandates the executive branch of the government to complete 100 actions within 270 days of the order's release date. On November 17, 2023, the Congressional Reference Service (CRS) issued a report summarizing the EO to the US Congress. On November 27, 2023, the UK's National Cyber Security Centre (NCSC), a part of Government Communications Headquarters (GCHQ), released the "Guidelines for secure AI system development." This publication provides four key areas. The areas are Secure Design, Development, Deployment, Operation and Maintenance.

    The presentation will discuss the companion publications that have been released by three organizations, namely the Cybersecurity and Infrastructure Security Agency (CISA), The National Institute of Standards and Technology (NIST), and The Open Web Application Security Project (OWASP). The publications from CISA and NIST are based on the EO's provisions; however, the EO does suggest using OWASP provisions.

    The actions will impact various areas, such as the federal government, private industry, supporting contractors, and the international community. Academia must keep an eye on these actions taken by the executive branch and adjust their instruction programs accordingly. Many professionals will be working for the U.S. federal government or supporting contractors. For this reason, academia is responsible for providing their students with the most up-to-date knowledge on artificial intelligence.

    Dr. Ron Martin, CPP



    ------------------------------
    [Ron] [Martin] [Ph.D.]
    [Professor of Practice]
    [Capitol Technology University
    [[email protected]]
    ------------------------------



  • 10.  RE: Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence

    Posted Dec 18, 2023 10:03:00 AM

    I think it is important to "compare and contrast" the US EI with the EU AI Act. Many providers of AI capabilities will use or sell their products in both markets -- and this will get worse as other jurisdictions reinvent the wheel and create their own distinct laws and regulations. 

    The two approaches start from typically different philosophies: the US doesn't prohibit or restrict products, it just says to use safe practices through the lifecycle.  The EU only cares about the final product but imposes restrictions and potentially severe fines (up to 7% of annual revenue). Global suppliers will have to navigate both environments. I think it would be possible to go through a development and deployment that conform to whatever standards will come out of the US EO and still come out with a product that violates the EU AI Act. As with GDPR, some companies will blithely  ignore the punitive EU regime until they get in trouble. AI suppliers need help to guide them between the rock and the hard place.



    ------------------------------
    Claude Baudoin
    cébé IT Knowledge Management
    Co-Chair, OMG Cloud Working Group
    https://www.omg.org/cloud
    ------------------------------