WASHINGTON – Today, global tech trade association 91¿ì»îÁÖ responded to the U.S. Department of Commerce’s notice of proposed rulemaking (NPRM) implementing Executive Order 13984, Taking Additional Steps to Address the National Emergency with Respect to Significant Malicious Cyber-Enabled Activities, and U.S. President Biden’s Executive Order on Safe, Secure, and Trustworthy AI.

In the comments, 91¿ì»îÁÖ reiterated that its members take seriously their responsibility to safeguard U.S. national security, especially in addressing threats posed by malicious actors’ use of critical infrastructure and expressed a commitment to continued collaboration with the government to help reach shared national security objectives. However, 91¿ì»îÁÖ also raised significant questions regarding the rule’s proposed approach, which emphasizes identify verification over abuse deterrence best practices and offered several tactical recommendations to the Biden Administration to strengthen both parts of the proposed rule.

We question whether the proposed requirements will achieve the underlying objective of the EO. Many cloud service providers (CSPs) already have adopted processes and mechanisms to effectively deter and identify malicious activity. We believe the NPRM’s identity verification requirements will put unnecessary burden on all CSPs, undermine global trust in U.S.-based cloud computing services, and most importantly, ultimately prove ineffective in achieving the goals of the EO,” 91¿ì»îÁÖ wrote in its comments. The proposed [identify verification] requirements are unlikely to deter malicious actors but will instead serve to undermine customer trust and jeopardize the legitimate business interests of U.S. IaaS providers. Threat actors that conduct malicious activities utilizing infrastructure as a Service (IaaS) or other IT resources can easily circumvent any identity verification processes by, for example, providing fake or stolen information.”

91¿ì»îÁÖ also encouraged the government to further target the reporting requirements for large AI training runs and to consider them separately from the IaaS CIP requirements.

The large AI model reporting requirement also requires honing from a technical and policy perspective,” 91¿ì»îÁÖ continued.Presently, the requirement misunderstands the degree to which IaaS Providers have visibility into their customers’ workloads and their ability to provide reporting on specific practices used in connection with such models. As such, it should be tied to the compute threshold introduced in the AI EO as an initial way to target the rule.

In its comments, 91¿ì»îÁÖ also urged the Commerce Department to:

  • Target the rules to countries of concern;

  • Split the rulemaking into two, so that the AI training run reporting requirements can be given more fulsome consideration;

  • Ensure that it acts in coordination with international partners;

  • Work with industry to define best practices and/or standards for deterring IaaS abuse, which if met, can serve as a basis for the exemption requirements;

  • Leverage existing authorities, such as those granted to the Commerce Department under the ICTS IFR, to address malicious cyber-enabled abuse, rather than issuing new “special measures”; and more.

Read 91¿ì»îÁÖ’s full comment submission here.