Sec. 1513. Physical and cybersecurity procurement requirements for artificial intelligence systems
950 words·~4 min read·
/bill/119/s/1071/eah/section-1513A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
The Secretary of Defense shall develop a framework for the implementation of cybersecurity and physical security standards and best practices relating to covered artificial intelligence and machine learning technologies to mitigate risks to the Department of Defense from the use of such technologies. The framework developed under paragraph
(1)shall cover all relevant aspects of the security of artificial intelligence and machine learning systems of the Department of Defense, including the following: Risk posed to and by the workforce of the Department of Defense, including insider threat risks. Training and workforce development requirements, including with respect to the following: Artificial intelligence security awareness. Artificial intelligence-specific threats and vulnerabilities. Development of a continuum of professional development and education of artificial intelligence security expertise. Risks to the supply chains of such systems, including counterfeit parts or data poisoning risks. Risks relating to adversarial tampering with artificial intelligence systems. Risks relating to the unintended exposure or theft of artificial intelligence systems or data. Security posture management practices, including governance of security measures, continuous monitoring, and incident reporting procedures. An evaluation of commercially available platforms for continuous monitoring and assessment of such systems. The framework developed under paragraph
(1)shall be risk-based, including security that is proportional to the national security or foreign policy risks posed by the covered artificial intelligence and machine learning technology being stolen or tampered with. To the maximum extent feasible, the framework developed under paragraph
(1)shall— draw on existing cybersecurity reference documents, including the NIST Special Publication 800 series; and be implemented as an extension or augmentation of existing cybersecurity frameworks developed by the Department of Defense, including the Cybersecurity Maturity Model Certification framework. The framework developed under paragraph
(1)shall prioritize the most highly capable artificial intelligence systems that may be of highest interest to cyber threat actors, based on risk assessments and threat reporting. The Secretary shall ensure that the framework developed under paragraph
(1)imposes requirements for security on contractors that are designed to mitigate the cyberesecurity risks posed by the cyber threat actors described in subparagraph (A), with the most stringent security requirements under such frameworks providing protection that is similar to the protection offered by national security systems (as defined in section 3552(b)(6) of title 44, United States Code). To the extent feasible, any additional security requirements developed pursuant to subparagraph
(B)shall be designed generally for all software systems of the Department of Defense, but may contain components designed specifically for highly capable artificial intelligence systems. The Secretary of Defense shall amend the Defense Federal Acquisition Regulation Supplement, or take other similar action, to require covered entities to implement the best practices described in subsection
(a)under the framework developed under such subsection. Any requirements implemented pursuant to paragraph
(1)shall, to the extent practicable, be narrowly tailored to the specific covered artificial intelligence and machine learning technologies developed, deployed, stored, or hosted by a covered entity, and shall be calibrated accordingly to the different tasks involved in development, deployment, storage, or hosting of components of such covered artificial intelligence and machine learning technologies. In carrying out paragraph (1), the Secretary of Defense shall— consider the costs and benefits to the Department of Defense and to the national security and technological leadership of the United States, of imposing security requirements on covered entities; and to the extent feasible, design the requirements implemented pursuant to such paragraph to allow for trade space analysis by the Department in a transparent manner between competing requirements in order to minimize the costs and maximize the benefits of such requirements. In carrying out subparagraph (A), the Secretary shall weigh the costs of slowing the development and deployment of artificial intelligence and machine learning against the benefits of mitigating national security risks and potential security risks to the Department of Defense from using commercial software for imposing additional physical or cybersecurity requirements for such systems. In carrying out the requirements of subsection (a), the Secretary of Defense shall seek to collaborate with industry and academia in the development of the framework under such subsection using a process for consultation that uses a new or existing mechanism for public-private partnerships. The framework required by subsection (a)(1) shall include a detailed plan for the implementation of the framework that— establishes timelines and milestones for achieving the objectives outlined in the framework; identifies resource requirements and funding mechanisms; and provides metrics for measuring progress and effectiveness. Not later than 180 days after the date of the enactment of this Act, the Secretary shall submit to the congressional defense committees an update on the status of implementation of the requirements of this section. In this section: The term artificial intelligence has the meaning given such term in 238(g) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 ( Public Law 115–232 ; 10 U.S.C. 4061 note prec.). The term covered artificial intelligence and machine learning technology means an artificial intelligence or machine learning system acquired by the Department of Defense or an element of the Department and all associated components involved in the development and deployment lifecycle of such system, including source code, numerical parameters (including model weights) of the trained artificial intelligence or machine learning system, details of any methods and algorithms used to develop such system, data used in the development of such system, and software used for evaluating the trustworthiness of the artificial intelligence or machine learning system during development or deployment. The term covered entity means an entity that enters into a contract or other agreement with the Department of Defense under which such entity engages in the development, deployment, storage, or hosting of one or more covered artificial intelligence and machine learning technologies.
Connectionstraces to 2
Traces to 2 documents
Citation graph
cites case law
Sec. 1513
Physical and cybersecurity procurement requirements for artificial intelligence systems
Cites 2Cited by 0 across 0 sources