1. Home
  2. |Insights
  3. |Commerce to Publish Proposed Regulations to Implement EO on "Securing the Information and Communications Technology and Services Supply Chain"

Commerce to Publish Proposed Regulations to Implement EO on "Securing the Information and Communications Technology and Services Supply Chain"

Client Alert | 1 min read | 11.26.19

The Commerce Department will publish, in proposed form, long-awaited regulations to implement the sweeping language of the May 2019 Executive Order entitled “Securing the Information and Communications Technology and Services Supply Chain.” 

The proposed regulations, to be promulgated under the authority of the International Emergency Economic Powers Act (IEEPA) and the EO, would establish a case-by-case process, by which the Secretary of Commerce could initiate (at its discretion, or at the request of another agency, or even a private party, via a dedicated web portal for “credible” tips) a review of any specific transaction (meaning “any acquisition, importation, transfer, installation, dealing in, or use of any information and communications technology or service”) that is: (1) initiated, pending, or to be completed after May 15, 2019; (2) involves persons or property subject to US jurisdiction; (3) involves any property in which a foreign country or national has an interest; (4) “involves information and communications technology or services designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of a foreign adversary” (with the definition of “foreign adversary” adopted from the EO, not narrowed to identify any specific foreign governments or persons); and (5) that poses either:

  1. Undue risk of sabotage to or subversion of the design, integrity, manufacturing, production, distribution, installation, operation, or maintenance of information and communications technology or services in the United States;
  2. Undue risk of catastrophic effects on the security or resiliency of United States critical infrastructure or the digital economy of the United States; or
  3. Otherwise poses an unacceptable risk to the national security of the United States or the security and safety of United States persons.

The parties to a transaction under review would receive a preliminary determination of the Secretary’s findings and would then have 30 days to present “an opposition,” or proposed measures for mitigation in lieu of an outright prohibition of the transaction. Commerce will accept public comments on all aspects of the proposed regulations for 30 days (until December 27, 2019).  

Insights

Client Alert | 4 min read | 03.25.26

NAIC Intensifies AI Regulatory Focus: What Health Insurance Payors Need to Know

The National Association of Insurance Commissioners (NAIC) is intensifying its oversight of how insurers use AI — and the pace of regulatory activity shows no signs of slowing. Over the past several months, the NAIC has published a formal Issue Brief staking out its position on federal AI legislation, launched a multistate AI Evaluation Tool pilot aimed at examining insurers’ AI governance programs, and continued to expand adoption of its AI Model Bulletin across state lines. These developments continue a trend towards enhancing regulation; the NAIC adopted AI Principles in 2020 and a Model Bulletin in 2023 clarifying that existing insurance laws apply to AI systems and establishing expectations for governance, documentation, testing, and third-party oversight. That Model Bulletin has now been adopted in approximately 24 states....