Covering GenAI-related risk management and software development, synthetic content risks in AI, and global AI standards collaboration
KPMG Regulatory Insights
__________________________________________________________________________________________________________________________________________________
May 2024
The U.S. Department of Commerce’s National Institute of Standards and Technology (NIST) releases four draft items, including two guidance documents, a report, and a global plan, covering the following:
The releases respond to directives in the Executive Order (EO) on the Safe, Secure and Trustworthy Development of AI (see KPMG’s Regulatory Alert, here), and are intended to help improve the safety, security and trustworthiness of AI and GenAI systems.
Highlights from each of the publications are detailed below.
In January 2023, NIST published its AI Risk Management Framework 1.0 (AI RMF 1.0) which is intended for voluntary use to assist companies’ incorporation of trustworthiness considerations into design, development, use, and evaluation of AI products, services, and systems.
The draft AI RMF: GenAI Profile (NIST AI 600-1) is designed as a “companion resource” for users of the AI RMF 1.0. It is similarly voluntary and serves as both a use-case and cross-sectoral profile of the AI RMF 1.0 related to GenAI risk management. It is intended to assist companies in considering legal and regulatory requirements, as well as industry best practices for managing GenAI-specific risks. In particular, the draft profile defines a group of risks that are unique to, or exacerbated by, the use of GenAI, and provides key actions to help govern, map, measure, and manage them. These risks include:
The draft Secure Software Development Practices for GenAI and Dual-Use Foundation Models (NIST SP 800-218A) is designed as a “Community Profile” companion resource to supplement NIST’s existing Secure Software Development Framework (SSDF) (SP 800-218) and is intended to be useful to producers of AI models, producers of AI systems that use those models, and acquirers of those AI systems.
While the existing SSDF focuses on assisting companies to secure software’s lines of code, the draft profile expands on that focus to help address concerns around malicious training data adversely affecting GenAI systems. The draft guidance adds practices, tasks, recommendations, considerations, notes, and other information specific to GenAI and dual-use foundation model development throughout the software development lifecycle, including potential risk factors (e.g., signs of data poisoning, bias, homogeneity, or) and strategies to address them.
NIST’s draft report, Reducing Risks Posed by Synthetic Content (NIST AI 100-4), provides an overview of technical approaches to promoting digital content transparency based on use case and specific context, including:
NIST notes that this report informs, and is complementary to, a separate report required under the AI EO Section 4.5(a) on monitoring the provenance and detection of synthetic content that will be submitted to the White House.
NIST’s draft Plan for Global Engagement on AI Standards (NIST AI 100-5) calls for a coordinated effort to work with key international allies and partners and standards developing organizations to drive development and implementation of AI-related standards, cooperation and coordination, and information sharing. The plan outlines recommendations in the areas of:
Comment Periods. NIST is soliciting public comments on all four releases (NIST AI 600-1, NIST SP 800-218A, NIST AI 100-4, and NIST AI 100-5), with a deadline to submit by June 2, 2024.
NIST Draft AI Guidance, Report, and Global Plan
Covering GenAI-related risk management and software development, synthetic content risks in AI, and global AI standards collaboration
Download PDFPoints of View
Insights and analyses of emerging regulatory issues and their impact.
Regulatory Insights View
Series covering regulatory trends and emerging topics
Regulatory Alerts
Quick hitting summaries of specific regulatory developments and their impact.
KPMG Regulatory Insights is the thought leader hub for timely insight on risk and regulatory developments.