Define "information system" as per section 3502 of title 44, United States Code. Mandates the Director to issue guidance on AI use by agencies to enhance cybersecurity of information systems. Requires the Director and agency heads to consider AI systems where automation aids cybersecurity. Obligates the Director to report annually for 5 years to Congress on AI use in enhancing cybersecurity. Instructs the Comptroller General to report to Congress on AI-associated privacy and cybersecurity risks within 2 years. Directs the Comptroller General to study and report within 2 years on AI and automation use across the federal government for cybersecurity, including automated updates to cybersecurity tools and processes.
Paper
Full text
Federal Information Security Modernization Act, Sec. 14 ("Automation and AI")
ETO AGORA · U.S. federal laws · 2023
Summary
Define "information system" as per section 3502 of title 44, United States Code.
Mandates the Director to issue guidance on AI use by agencies to enhance cybersecurity of information systems.
Requires the Director and agency heads to consider AI systems where automation aids cybersecurity.
Obligates the Director to report annually for 5 years to Congress on AI use in enhancing cybersecurity.
Instructs the Comptroller General to report to Congress on AI-associated privacy and cybersecurity risks within 2 years.
Directs the Comptroller General to study and report within 2 years on AI and automation use across the federal government for cybersecurity, including automated updates to cybersecurity tools and processes.
Defines "information system" using section 3502 of title 44, United States Code.
SEC. 14. AUTOMATION AND ARTIFICIAL INTELLIGENCE.
(a) Definition.—In this section, the term “information system” has the meaning given the term in section 3502 of title 44, United States Code.
Issues guidance on AI use for cybersecurity. Considers AI capabilities. Submits annual reports to Congress.
(b) Use Of Artificial Intelligence.—
(1) IN GENERAL.—As appropriate, the Director shall issue guidance on the use of artificial intelligence by agencies to improve the cybersecurity of information systems.
(2) CONSIDERATIONS.—The Director and head of each agency shall consider the use and capabilities of artificial intelligence systems wherever automation is used in furtherance of the cybersecurity of information systems.
(3) REPORT.—Not later than 1 year after the date of enactment of this Act, and annually thereafter until the date that is 5 years after the date of enactment of this Act, the Director shall submit to the appropriate congressional committees a report on the use of artificial intelligence to further the cybersecurity of information systems.
Mandates Comptroller General to report on AI privacy, cybersecurity risks, and automation in federal agencies.
(c) Comptroller General Reports.—
(1) IN GENERAL.—Not later than 2 years after the date of enactment of this Act, the Comptroller General of the United States shall submit to the appropriate congressional committees a report on the risks to the privacy of individuals and the cybersecurity of information systems associated with the use by Federal agencies of artificial intelligence systems or capabilities.
(2) STUDY.—Not later than 2 years after the date of enactment of this Act, the Comptroller General of the United States shall perform a study, and submit to the Committees on Homeland Security and Governmental Affairs and Commerce, Science, and Transportation of the Senate and the Committees on Oversight and Accountability, Homeland Security, and Science, Space, and Technology of the House of Representatives a report, on the use of automation, including artificial intelligence, and machine-readable data across the Federal Government for cybersecurity purposes, including the automated updating of cybersecurity tools, sensors, or processes employed by agencies under paragraphs (1), (5)(C), and (8)(B) of section 3554(b) of title 44, United States Code, as amended by this Act.