On 28 February 2024, President Biden issued the Executive Order on Preventing Access to Americans' Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern, a strategic measure aimed at fortifying data protections and safeguarding the nation's informational assets.
This executive order was issued in response to the mounting threats that the US is facing as adversaries seek unauthorized access to vast stores of sensitive personal and governmental data. These incursions not only represent a challenge to cybersecurity and national security but also threaten individual privacy and the bedrock principles of democratic governance.
Given that AI systems are trained on and use vast amounts of data, which may cross geographical borders, the Executive Order will have important implications for the monitoring and assessment of AI systems developed and used in the US.
Key Takeaways:
The Executive Order primarily addresses the handling and misuse of both bulk sensitive personal information of US citizens and government-related data by foreign entities. This exploitation, which includes cyber operations, espionage, and actions that undermine civil liberties, poses a significant threat to national security. There are multiple mechanisms for gaining unauthorized access to data, which range from data brokerage to third-party agreements, as well as certain employment practices, and all are directly targeted by the provisions of the Executive Order.
The core strategy of the Executive Order is to impose prohibitions or limitations on transactions involving the processing and exploitation of sensitive data by foreign adversaries. Through this, the Executive Order aims to uphold human rights and the core tenets of democracy. Moreover, it strives to strike an equitable balance between necessary restrictions and the United States' advocacy for a global framework that supports open and secure data flows across international boundaries.
The Order outlines a comprehensive definition of sensitive personal data, which includes but is not limited to personal identifiers, biometric and geolocation data, sensor outputs, genomic information, health records, financial details, or any aggregation of these data categories.
There are two critical dimensions to this definition:
Although Biden previously issued the Executive Order on AI safety and security, which specifically targets AI, the personal data executive order is also set to affect AI. Indeed, this latest Executive Order recognizes data as the linchpin of AI systems, with bulk sensitive personal data serving as a crucial resource for developing potent AI models. The Order explicitly acknowledges the potential misuse of AI technologies in conducting espionage, carrying out influential cyber operations, and engaging in other malicious activities. Consequently, there are two significant implications for AI:
Through these measures, the Executive Order aims to balance the advancement of AI technologies to protect sensitive information and maintain national security, influencing how AI models are trained and deployed in the future.
The Executive Order presents a nuanced approach to addressing the complex interplay between technological advancement, data privacy, and national security. By focusing on specific threats rather than imposing broad restrictions, the Order seeks to protect bulk sensitive personal data and government-related data without stifling innovation or international trade.
While the regulations from the Attorney General are awaited, AI providers, developers, and deployers involved in data processing and network infrastructures must prepare for a landscape that will demand greater vigilance and compliance.
Schedule a demo with our experts to find out how our Global AI Tracker can help you stay on top of AI legislation, regulation, guidance, and more around the world.
DISCLAIMER: This news article is for informational purposes only. This blog article is not intended to, and does not, provide legal advice or a legal opinion. It is not a do-it-yourself guide to resolving legal issues or handling litigation. This blog article is not a substitute for experienced legal counsel and does not provide legal advice regarding any situation or employer.
Schedule a call with one of our experts