 tools to find and fix vulnerabilities in critical software. Second, to mitigate the potential risks posed by AI to our critical infrastructure, EO 14110 directs DHS to establish an AI Safety and Security Board and, based on NIST’s AI Risk Management Framework, provide safety and security guidelines to critical infrastructure owners and operators. Third, to protect the AI ecosystem against cyber threats, developers of certain AI models will be required to report to the Department of Commerce their capabilities for defending against sophisticated threat actors. The Federal Government continues to engage with a wide range of stakeholders to prepare for a post-quantum future. In August 2023, NIST submitted for public comment three draft Federal Information Processing Standards (FIPS) designed to resist future attacks by cryptanalyticallyrelevant quantum computers. To support non-Federal cryptographic transitions, OMB, CISA, NIST, and NSA published resources for organizations to develop and implement their own Quantum-Readiness Roadmaps. NIST, NSA, and partners are working across multiple standards developing organizations to integrate the expected NIST post-quantum cryptographic standard in a wide variety of security standards. NIST also continues to engage with a working group of industry, academic, and government stakeholders to identify and address the challenges related to cryptographic transitions at the NIST National Cybersecurity Center of Excellence. Managing Risks to Data Security and Privacy In the absence of a national data privacy law, the Administration is pursuing targeted measures to protect Americans’ data and their privacy, and enable safe, data-rich cross-border commerce. EO 14117 on Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern authorizes the Attorney General to prevent the large-scale transfer of Americans’ personal data to countries of concern and provides safeguards around other activities that can give those countries access to Americans’ sensitive data. The protections authorized by EO 14117 will extend to genomic data, biometric data, personal health data, geolocation data, financial data, and certain kinds of personal identifiers that adversaries may exploit for a variety of nefarious purposes, including to engage in malicious cyber-enabled activities. The EU-U.S. Data Privacy Framework, finalized in July 2023, is a leading example of the international partnership required for safe and trusted cross-border data flows. Alongside the framework’s finalization, the Department of Commerce released the Data Privacy Framework program website for companies participating in cross-border data transfers. EO 14110 on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence, reinforces the importance of mitigating privacy risks in emerging technologies. EO 14110 directs departments and agencies to take steps to safeguard Americans’ privacy in the development and deployment of AI. In December 2023, NIST issued draft guidance for agencies on evaluating differential-privacy-guarantee protections. In February 2024, DOE and NSF established a Research Coordination Network to advance research, development, and implementation of privacy-enhancing technologies (PETs). PETs are an important part of the Administration’s affirmative vision for a secure, trustworthy, and rights-respecting digital ecosystem. To coordinate Federal efforts to harness PETs, the 2024 REPORT 24 ON THE CYBERSECURITY OF THE UNITED STATES POSTURE

Select target paragraph3