The White House's October 30, 2023, Executive Order on Safe, Secure and Trustworthy Artificial Intelligence signals increased governmental regulation over the development and use of artificial intelligence models. While the United States currently does not have a comprehensive AI regulation regime, many federal government agencies already regulate the use and development of AI through a complex framework of rules and regulations. President Biden's order promises to add a new layer of complexity by introducing sweeping changes affecting a wide variety of industries. Below, we summarize the most significant changes stemming from the White House's AI executive order.
The executive order gives the National Institute of Standards and Technology (NIST) 270 days to act in concert with the Department of Commerce and other governmental stakeholders to create new guidelines, standards and best practices for AI safety and security. These standards will include (among other requirements) a companion piece to NIST's AI Risk Management Framework for generative AI use-cases, the development of a secure software development framework for AI and "dual-use foundation models" (defined by the executive order to include AI models trained on broad data containing at least 10 billion parameters, and having the capability of posing a risk to national economic security and public safety), as well as standards to conduct AI "red-teaming" tests to evaluate model safety.
Leveraging the Defense Production Act, the executive order also requires private companies working on dual-use foundation models to report to the government, on an ongoing basis, extensive development information such as data on model weighting and red-teaming test results in order to ensure responsible AI development. Companies who possess or develop "large-scale computing clusters," as will be defined by the Secretary of Defense and other federal government stakeholders, and companies providing "infrastructure as a service" to the United States, will also have new reporting responsibilities. The Secretary of Commerce will have 90 days to promulgate the applicable reporting scheme.
Information security strength is a theme of the executive order, discussed in several contexts throughout, balancing the need to identify and mitigate security risks associated with using AI while also leveraging the benefits of AI. The order emphasizes the importance of maintaining physical, administrative and technical safeguards that help protect against potentially dangerous exploitation of AI systems. In addition to developing guidelines that complement the NIST AI Risk Management Framework, the order calls for federal agencies to be diligent in risk-mitigation practices including proper staff training and the negotiation of appropriate terms of service with third-party providers to ensure the protection of government information is extended to its vendors (noting confidentiality, compliance, privacy and data protection requirements). The executive order also cites the need for the development and maintenance of secure testing environments (aka testbeds) in which systems can be developed and evaluated before deployment.
The executive order further addresses managing use of AI to protect critical infrastructure. It directs the Secretary of Homeland Security to establish and chair an AI Safety and Security Advisory Board made up of leading industry experts, software companies, research labs, critical infrastructure entities and the U.S. government to issue recommendations and best practices ensuring AI use in this area is secure and resilient. The Department of Homeland Security is also instructed to leverage AI to improve U.S. cyber defense.
The executive order emphasizes the need for the U.S. to promote responsible innovation, competition and collaboration via investments in AI-related education, training, research and development capacities while addressing intellectual property (IP) rights issues and challenges faced by inventors and creators. As part of the White House's efforts toward the promotion of innovation, the executive order directs several mandates with the aim of clarifying issues around AI and its potential to develop IP assets. Specifically, the order directs the Undersecretary of Commerce for IP and the U.S. Patent and Trademark Office (USPTO) to issue guidance on the patent eligibility of inventions developed using AI, as well as other emerging issues at the intersection of AI and IP. The order also requires the director of the USPTO to consult with the director of the U.S. Copyright Office and provide recommendations for further executive action, including potential copyright protection for works created using AI and the treatment of copyrighted works in connection with training AI models. In this line, the Secretary of Homeland Security is to develop a training, analysis and evaluation program to mitigate AI-related IP risks.
The executive order reflects U.S. government concerns that AI may exacerbate risks to privacy, including by its facilitation of the collection or use of information about individuals or the concluding of inferences about them. To address such risks, the order mandates the federal government to ensure that the collection, use and retention of personal data is lawful and secure. Specifically, the EO directs federal agencies to pursue the following actions:
- The evaluation of how agencies collect and use commercially available information—particularly containing personally identifiable information—and strengthening of privacy guidance for federal agencies to mitigate related privacy risks;
- The prioritization of federal support for accelerating the development and use of privacy-enhancing technologies (PETs);
- The creation of a Research Coordination Network dedicated to advancing privacy research and, in particular, the development, deployment and scaling of PETs; and
- The development of guidelines for federal agencies to evaluate the effectiveness of PETs, including those used in AI systems.
Importantly, with this order President Biden calls for congressional action to pass bipartisan data privacy legislation to protect all Americans against the data privacy risks posed by AI.
The executive order calls upon the U.S. Department of Health & Human Services (HHS) to develop a strategic plan for the development of AI-enabled healthcare technology tools within 365 days through an HHS AI task force. The AI task force is to consider possible regulations and input on the responsible deployment of technologies for healthcare, including in advances in the drug development process. The AI task force is also to focus on addressing healthcare challenges for underserved communities, veterans and small businesses. As expected, HHS is also to provide guidance on the safety, privacy and security of patient information in the development of AI software tools, especially to avoid cybersecurity threats. Other AI healthcare initiatives may also be reviewed and addressed by HHS as they develop.
The executive order identifies education as a critical field where the federal government will take advantage of advances in AI technologies, but also needs to protect consumers and the public from adverse impacts. Job training and education will provide access to students to learn about AI. Resources will be made available to those who experience displacement in the workforce due to AI. The order makes clear that the federal government will continue to enforce existing consumer protections as AI evolves. These include those safeguarding consumers from "fraud, unintended bias, discrimination, infringements on privacy, and other harms from AI."
The executive order also directs the Secretary of Education to develop policies concerning the use and impact of AI in education in consultation with stakeholders. This will include the creation of an "AI toolkit" for institutions to use in implementing the department's recommendations concerning appropriate use of AI, including human review of AI decisions, the design of AI to enhance trust and safety, and alignment of AI systems with U.S. privacy laws and regulations, among other things.
While the executive order does not explicitly address export controls, many aspects of AI are embedded within both the Export Administration Regulations (EAR) administered by the U.S. Department of Commerce and the International Traffic in Arms Regulations (ITAR) enforced by the U.S. Department of State. Moreover, the order authorizes the Secretary of Commerce to take action pursuant to the International Emergency Economic Powers Act as necessary. Accordingly, we expect both Commerce and State to engage in reviews to update the control lists under both the EAR and ITAR and to issue regulations in this area that will result in additional export controls.
In line with the White House's commitment to advance equity and civil rights, the executive order endeavors to ensure that AI is used responsibly to improve workers' lives and provide safeguards against harmful use. Within 180 days of issuing the order, the Secretary of Labor is tasked with consulting with agencies and outside entities (including labor unions and workers) to develop and publish principles and best practices for employers to maximize AI's potential benefits. These key principles and best practices will focus on job displacement, labor standards, job quality, employers' AI-related collection and use of worker data and preventing harm to employees' well-being. With AI becoming increasingly used in processes for making employment decisions, the order confirms that the federal government is fully tuned in to this emerging technology and closely scrutinizing its potential impact.
The executive order regarding AI and other emerging technologies is part of a broad mandate to promote innovation and competition, and includes directing the Departments of State, Labor and Homeland Security to "expand the ability of highly skilled immigrants and nonimmigrants with expertise in critical areas to study, stay, and work in the United States by modernizing and streamlining visa criteria, interviews, and reviews." The key directives concerning immigration include:
- Expanding visa availability and streamlining visa processing for AI work, study or research;
- Implementing a domestic visa renewal program rather than requiring AI workers to leave the U.S. to renew their visas;
- Modernizing immigration pathways and streamlining the green card process for AI specialists with extraordinary ability or advanced degrees and for AI investors and entrepreneurs; and
- Expanding the list of Schedule A occupations that benefit from a streamlined permanent labor certification process.
These sweeping directives touch virtually every aspect of employment-based immigration in the United States and represent a creative and timely approach to address labor shortages and attract foreign talent in order to facilitate U.S. innovation and competition. If implemented effectively, this executive order could go a long way to provide more streamlined, predictable paths to work visas and legal immigration.
For More Information
Disclaimer: This Alert has been prepared and published for informational purposes only and is not offered, nor should be construed, as legal advice. For more information, please see the firm's full disclaimer.