AI Governance Library

Assuring AI Security and Safety Through AI Regulation

MITRE Center for Data-Driven Policy presidential transition memo proposing nine data-driven recommendations for a US regulatory framework covering AI assurance, auditability, transparency, incident sharing and governance.
Cover of Assuring AI Security and Safety Through AI Regulation

⚡ Quick Summary

Published by MITRE's Center for Data-Driven Policy, this presidential transition priority topic memo, dated July 2024, argues that the incoming US administration should establish a comprehensive and effective regulatory framework for AI security and safety, balancing technological progression, ethical considerations and public trust while reinforcing United States international leadership in AI.

The memo sets out key challenges: bridging the gap between policymakers at the Executive Office of the President (EOP) and agency implementation; developing sector-specific AI assurance requirements and operationalizing the NIST AI Risk Management Framework (RMF) across sectors; and establishing system auditability and transparency, which it says is limited by the complexity of AI systems and a gap in technical expertise. It also identifies opportunities in rethinking regulatory and legal frameworks, strengthening critical infrastructure plans and allowing flexibility across agencies that differ in size, budget, mission and AI talent.

Its deliverable is nine data-driven recommendations: a four-step AI assurance process producing an AI Assurance Plan; an executive order mandating system auditability and disclosure of training data and foundation models; support for the AI Information Sharing and Analysis Center (AI-ISAC) and the ATLAS incident database; an AI Science and Technology Intelligence (AI S&TI) apparatus; and a National AI Center of Excellence (NAICE). A suggested timeline covers the first 100 days, six months, one year and ongoing work.

🧩 What’s Covered

The memo moves from the case for action to nine numbered recommendations and an implementation timeline.

  • The Case for Action: positions AI as a transformative technology with uses from healthcare to national security and argues that each presidential term brings an opportunity to reassess the approach to AI assurance.
  • Key Challenges and Opportunities: identifies the gap between EOP policymakers and agency implementation, the difficulty of sector-specific assurance requirements and of operationalizing the NIST AI RMF, and the auditability and transparency problems created by complex AI systems and scarce technical expertise.
  • Recommendations 1–3: bridge the policymaking-to-agency gap through EOP-interagency committees or a new dedicated committee; develop sector-specific assurance requirements and AI Assurance Plans via a four-step process (Discovering Assurance Needs, Characterizing and Prioritizing Risks, Evaluating Risks, Managing Risks); and support the AI-ISAC alongside a national incident database such as ATLAS.
  • Recommendations 4–6: build an at-scale AI Science and Technology Intelligence apparatus with continuous red-teaming; issue an executive order mandating system auditability, audit-trail standards and disclosure of training data and foundation models; and align AI principles, treating purpose as an inherently human quality while refining legal frameworks to separate appropriate research from misuse.
  • Recommendations 7–9: strengthen critical infrastructure plans for safety-critical cyber-physical systems with a dedicated executive task force; promote flexibility and adaptability in AI governance; and create a National AI Center of Excellence to coordinate the priorities.
  • Implementation Considerations: milestones for the first 100 days, first six months, first year and ongoing work, including a network of AI assurance labs modelled on MITRE's AI Assurance and Discovery Lab.
  • About the Center for Data-Driven Policy and MITRE Resources and Support: describes MITRE's nonpartisan, lobbying-restricted position and lists four related MITRE publications.

💡 Why it matters?

The memo addresses people who must turn high-level AI policy into operational practice, supplying a sequencing logic and named mechanisms rather than principles alone. Its four-step assurance process and AI Assurance Plan give assurance and risk teams a repeatable structure tied explicitly to the NIST AI RMF, while the AI-ISAC, ATLAS and AI S&TI proposals show where incident and adversary information would come from. The auditability recommendation names the disclosures it expects. The timeline offers governance leads a rough order of operations for an administration's first year, and the flexibility recommendation acknowledges differences in agency maturity, budget and mission.

❓ What’s Missing

The memo is bound to the United States federal context and to a presidential transition, so its recommendations assume an incoming administration willing to act; it does not address state-level regulation, Congress, or coordination with non-US regimes beyond asserting international leadership. No costs, funding levels, staffing estimates or success metrics are given, and the timeline assigns no owners. The audit-trail standards, sector-specific requirements and AI governance guidelines are described only in outline. The AI-ISAC is referred to as recently established without membership or governance detail, and most cited URLs point to other MITRE publications rather than to supporting evidence.

👥 Best For

Best for US federal policy staff, agency AI governance and assurance leads, and risk or audit teams that need to translate executive-level AI policy into agency practice. It also serves industry and academic stakeholders tracking MITRE's recommendations on assurance processes, incident sharing and AI auditability during a presidential transition.

📄 Source Details

Assuring AI Security and Safety Through AI Regulation, a Presidential Transition: Priority Topic Memo published by MITRE (Center for Data-Driven Policy), July 2024; no individual authors are named. Five pages, in English. It is marked "APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED. PUBLIC RELEASE CASE NUMBER 23-02057-31" and "© 2024 THE MITRE CORPORATION". No URL for this memo itself is printed; the contact address given is policy@mitre.org. The text extraction covered all five pages.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.