Department of Commerce Seeks Comment on Proposed CIP Requirement and Foreign Access Restrictions for US Infrastructure as a Service (IaaS) Providers
On January 29, 2024, the US Department of Commerce’s Bureau of Industry and Security (the “Department”) issued a notice of proposed rulemaking seeking comment on a proposed regulation in response to the Executive Order (E.O.) 14110 of October 30, 2023, “Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence” and E.O. 13984 of January 19, 2021, “Taking Additional Steps To Address the National Emergency With Respect to Significant Malicious Cyber-Enabled Activities.” The proposed regulation would require providers of infrastructure as a service (IaaS) products to: (i) have a Customer Identification Program, similar to what banks and other financial institutions have had for many years (ii) authorizes the Department to prohibit or restrict IaaS transactions involving jurisdictions or persons engaged in malicious cyber activities involving US IaaS products, and (iii) to impose reporting requirements with respect to the use by foreign persons of cloud computing services for training large AI models.
Read more >>