U.S. Department of Commerce Proposes New Reporting Rules for AI Developers and Cloud Providers

Washington, D.C. - On September 9, 2024, the U.S. Department of Commerce’s Bureau of Industry and Security (BIS) unveiled a Notice of Proposed Rule Making (NRPM) targeting new reporting obligations for developers of artificial intelligence (AI) and providers of cloud computing services. This initiative intends to institute enhanced oversight measures in accordance with Executive Order 14110, signed on October 30, 2023, aimed at ensuring the safe, secure, and trustworthy use of AI technologies.

Overview of the Proposal

The NRPM stipulates that entities engaged in the development of advanced AI models and the management of large-scale computing clusters must adhere to updated reporting mandates. The BIS, which oversees the enforcement of U.S. Export Administration Regulations (EAR) concerning dual-use goods and technologies, is tasked with implementing these changes. The proposed rules would be incorporated into the BIS’s “Industrial Base Surveys—Data Collections” regulations.

Reporting Obligations

Under Section 4.2(a)(i) of EO 14110, the Secretary of Commerce is directed to compel companies developing or aiming to develop dual-use foundation AI models to routinely submit specific information to the Federal Government. The directive extends to those managing large-scale computing clusters under Section 4.2(a)(ii), necessitating reports on the acquisition, development, and capabilities of these clusters.

A dual-use foundation model is detailed in EO 14110 as an AI system trained on extensive data, typically employing self-supervision, and consisting of a minimum of tens of billions of parameters. These models, which perform highly across various contexts, pose potential risks to security, national economic well-being, and public health.

Compliance Requirements

Entities involved in applicable activities—including running AI models with computational operations exceeding (10^{26}) operations and developing expansive computing clusters—are obligated to submit quarterly reports to the BIS. These reports must cover:

  • Developmental activities pertaining to dual-use AI models, alongside physical and cybersecurity measures.
  • Ownership and security protocols concerning AI model weights.
  • Outcomes from "red-team" testing, designed to examine and identify vulnerabilities within AI systems, potentially flagging risks like misuse in cyberattacks or weapon development.

Confidentiality measures, as per 15 CFR 702.3 and section 705(d) of the Defense Production Act, are guaranteed for all submitted information.

Compliance Timeline and Enforcement

Should the NRPM be enacted in its current form, entities will be required to provide comprehensive responses within 30 calendar days of engaging in covered activities. Follow-up questions from the BIS will necessitate answers within seven days of the request. Non-compliance could result in severe civil and/or criminal penalties.

Future Regulatory Considerations

The BIS is particularly interested in leveraging the gathered data to inform future regulatory actions, potentially imposing stricter controls on AI models that could jeopardise U.S. security or its defence sector. Although, presently, BIS estimates that no more than 15 U.S. entities meet the reporting criteria for such advanced models and computing clusters, the regulatory landscape may evolve with technological advancements.

Public Input

Stakeholders and interested parties are invited to submit their comments on the proposed rule by October 11, 2024, through the Federal rulemaking portal at www.regulations.gov. These comments will be vital in refining and finalising the reporting requirements.

Implications for Industry

For AI developers and cloud service providers, this proposed regulation signifies a shift towards increased government oversight in the realm of advanced and foundational AI technologies. Organisations may need to reassess their safety and security measures, ensuring compliance with the forthcoming regulations to avoid penalties and foster safe AI development practices.

Conclusion

As the landscape of artificial intelligence continues to advance, the proposed reporting requirements by the U.S. Department of Commerce underscore the government's effort to preempt and mitigate potential national security risks. The evolving regulatory framework is expected to play a significant role in shaping the responsible and secure deployment of AI technologies in the future.

Source: Noah Wire Services