U.S. Vice President Kamala Harris this week unveiled the White House Office of Management and Budget's (OMB) first-ever government-wide policy to provide a roadmap for federal agencies to safely and responsibly manage and deploy artificial intelligence (AI) and harness its benefits.

This AI governance policy is a follow-up to the AI Executive Order issued by President Biden last year, which lists actions to address risks from AI usage, expand transparency, advance responsible AI innovation and grow the AI workforce.

Firstly, the memo announced new standards to protect the rights and safety, Harris said during a press call. “When government agencies use AI tools, we will now require them to verify that those tools do not endanger the rights and safety of the American people.”

By December 1, 2024, federal agencies are required to deploy concrete safeguards when using AI in a way that could impact Americans’ rights or safety, which includes a range of mandatory actions to reliably assess, test and monitor AI’s impacts on the public, mitigate the risks of algorithmic discrimination, and provide the public with transparency into how the government uses AI.

For example, “if the Veterans Administration wants to use AI in VA hospitals to help doctors diagnose patients, they would first have to demonstrate that AI does not produce racially biased diagnoses,” Harris said.

The initiative also aims to bolster public transparency and accountability in AI usage. From now on, U.S. government agencies are required to publish online a list of their AI systems, an assessment of the risks those systems might pose, and how those risks are being managed every year.

To grow the AI workforce, the Biden-Harris Administration has committed to hiring 100 AI professionals by this summer to promote the trustworthy and safe use of AI and the Fiscal Year 2025 President’s Budget includes an additional $5 million to expand the General Services Administration’s government-wide AI training program.

Meanwhile, the OMB policy requires federal agencies to designate chief AI officers and establish AI governance boards to coordinate the use of AI across their agencies.

“This is to make sure that AI is used responsibly, understanding that we must have senior leaders across our government who are specifically tasked with overseeing AI adoption and use,” Harris said.

She also continues to call on other nations to follow suit and put the public interest first when it comes to government use of AI.

Cybersecurity experts voice their support for the new AI policy

In response to the policy, security industry experts have voiced their support and highlighted its potential benefits.

David Brauchler, principal security consultant at NCC group, praised the guidelines for their focus on transparency and accountability. “The pledge to release models whenever feasible presents an excellent opportunity for knowledge sharing and information growth between the public and private sectors.”

Moreover, ISC2 CEO Clar Rosso emphasizes the need for collaboration and a skilled workforce to address the challenges and opportunities presented by AI technologies. “Our members have been reporting a concerning need for comprehensive and specific regulations to govern the acceptable and ethical use of AI in their organizations, as well as clear leadership as to who is responsible for creating it.”

Rosso also cited ISC2’s 2023 Workforce Study, which found that 45% of surveyed cyber professionals said they believe AI will be the biggest challenge facing the industry within the next two years, nearly one-third reported having AI or machine learning skills gaps in their organizations, and 84% reported having no/minimal or some/moderate knowledge of AI/ML.

The surge of AI usage and its risks

The new federal AI policy comes at a time of rapid growth in AI usage and activity. Zscaler's 2024 AI Security Report found a staggering 600% increase in enterprise AI/ML transitions, from 521 million per month in April 2023 to 3.1 billion per month in January 2024 on the Zscaler Zero Trust Exchange cloud security platform.

Researchers pointed out the growing use of generative AI (genAI) tools introduced significant cybersecurity risks in three main areas:

  1. The data leakage risk: It brings more challenges in the protection of intellectual property and non-public information.
  2. AI application data privacy and security risks, including an expanded attack surface, new threat delivery vectors and increased supply chain risks.
  3. Data quality concerns and the potential for data poisoning.