October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Commerce’s 2024 proposal targeted frontier AI developers and cloud operators—not every tech firm

Commerce’s September 2024 BIS proposal targeted a small group of frontier AI developers and large computing operators, with reporting on compute, model weights, cybersecurity and red-team results—not every AI or cloud company.
From TheFinanceBase Team7 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Status: The U.S. Commerce Department’s Bureau of Industry and Security (BIS) announced a notice of proposed rulemaking on September 9, 2024. It would have required a small group of frontier-AI developers and operators of very large computing clusters to submit information to the government. The available official materials do not establish that this specific proposal became a final, generally applicable regulation, so it should not be treated as a current reporting duty without confirming a later BIS action.

The proposal was docket BIS–2024–0047 (RIN 0694–AJ55) and concerned BIS’s Industrial Base Surveys—Data Collections rules. Its purpose was visibility into defense-relevant AI capabilities, not a universal AI license or a pre-release approval system.

What Commerce proposed

BIS proposed mandatory data collection from certain U.S. persons developing extremely advanced “dual-use foundation models” and from entities acquiring, developing or possessing qualifying large-scale AI-computing clusters. Commerce said the effort followed President Biden’s October 30, 2023 executive order on safe, secure and trustworthy artificial intelligence and a BIS pilot survey conducted earlier in 2024.

The agency’s announcement is available at BIS.gov; the proposed rule was published in the Federal Register.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who could have been covered

Frontier-model developers

The proposal focused on U.S. persons developing or planning to develop a qualifying dual-use foundation model. That could include frontier-model labs, large technology companies training proprietary models, internal research groups and some government or defense contractors. A company would not have been covered merely because it marketed an AI product or used a popular model.

A contemporaneous legal analysis said BIS estimated that zero to 15 companies might initially meet the model or computing criteria. That was an estimate at publication, not a current list of covered companies.

Cloud and data-center operators

The infrastructure trigger was ownership, acquisition, development or possession of a qualifying cluster. It could therefore reach cloud providers, data-center operators and companies building dedicated private clusters. Offering ordinary GPU instances was not, by itself, enough. Coverage depended on the proposed technical thresholds and the entity’s status as a covered U.S. person.

Activities that might fall outside

  • Routine SaaS and application companies that do not develop a qualifying model.
  • Ordinary cloud customers renting compute below the proposed thresholds.
  • Models trained or fine-tuned at smaller scale, unless another provision applied.
  • Clusters used for non-AI workloads that did not meet the rule’s AI-training criteria.

The proposed technical thresholds

The proposal identified two principal ways activity could become reportable. These were proposed thresholds and could have been changed before any final rule.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Trigger Proposed level What it measures
Training run More than 1026 computational operations Total computational work for a model-training run, not parameter count or popularity.
Computing cluster More than 300 Gbit/s of transitively connected data-center networking and theoretical maximum performance above 1020 operations per second for AI training, without sparsity Interconnected infrastructure and its theoretical AI-training performance.

In practical terms, the thresholds targeted infrastructure at the extreme frontier. They were not measures of revenue, users, valuation or consumer adoption. Distributed training, rented capacity, shared legal entities and workloads split across regions could create difficult attribution questions that the proposed text would have needed to resolve.

What information companies would have reported

Area Examples of proposed information
Development and infrastructure Current or planned model development; acquisition, development or possession of qualifying clusters; hardware, capacity and training, development or production activity.
Model weights Ownership and possession of weights, custody arrangements and protections against unauthorized access or exfiltration.
Cybersecurity Physical security, cybersecurity resources and practices protecting model-development environments and computing assets.
Safety testing Red-team results, flaws and vulnerabilities, and findings about dangerous capabilities.
High-consequence risks Whether a model could materially lower barriers to cyberattacks; help non-experts develop or acquire chemical, biological, radiological or nuclear weapons; or evade human control through deception or obfuscation.

BIS’s description of the proposal appears in its announcement. The contemplated submissions were to the government; the proposal did not make red-team results public by default.

How the proposed reporting process would work

  1. Identify a covered activity. A company would determine whether a training run, cluster or other activity met the applicable proposed criteria.
  2. Notify BIS. The proposed structure called for an initial notification after an applicable activity.
  3. Complete the questionnaire. Legal analysis of the proposal described an expected 30-calendar-day response period for the initial questionnaire.
  4. Report quarterly. Ongoing quarterly reporting was contemplated.
  5. Continue affirmations after activity ends. The same analysis described seven quarters of continuing affirmations after the relevant activity ceased, including periods with no new activity.

Those deadlines and mechanics were proposed procedures, not an independently verified current compliance schedule. The proposed text is identified in the Federal Register materials at public-inspection.federalregister.gov and the docket page at The Federal Register.

Why the government wanted the data

BIS said the information would help Commerce assess defense-relevant AI capabilities, the resilience of advanced systems to cyberattack, emerging dangerous capabilities, potential misuse by foreign adversaries or non-state actors, and the competitiveness and resilience of the U.S. AI industrial base. The underlying policy problem is an information gap: government agencies cannot evaluate strategic risk if they do not know who controls the largest clusters, which models are being trained and how those systems perform under adversarial testing.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Reporting would improve visibility, but it would not itself make a model safe. Its value would depend on accurate and timely submissions, BIS’s analytical capacity, follow-up action and the government’s ability to protect sensitive information.

What the proposal did not do

  • It was not a universal AI license. The proposal concerned information collection, not general permission to train or release a model.
  • It was not a mandatory pre-release review. It did not, on its face, require government approval before a model could be developed or published.
  • It was not a blanket cloud-surveillance mandate. Ordinary cloud customers and routine GPU offerings were not automatically covered.
  • It was not an export-control rule. Export controls govern international transfers of chips, servers, software, cloud services or related technology.

A later White House AI policy separately discussed innovation and said certain actions should not be construed as creating mandatory licensing, pre-clearance or permitting for model development or release. That policy is distinct from the 2024 BIS proposal; see the White House fact sheet.

How it differs from export controls and cloud-security measures

Policy type Primary question Typical subject
2024 BIS reporting proposal What frontier models and computing capacity exist inside the relevant U.S. industrial base? Covered developers and operators of qualifying clusters.
Export controls Can specified technology or services be transferred to a destination, end user or end use? Chips, servers, software, cloud services and related technology.
Cloud-security initiatives How can foreign users obtain advanced AI capability through U.S. cloud infrastructure? Cloud providers, customers and cross-border access arrangements.

A provider could face export-control duties without being covered by the reporting proposal, or potentially fall within the reporting proposal while a particular transaction raised no export-control issue. The White House’s separate export-promotion action is at whitehouse.gov, with related policy detail in the America’s AI Action Plan.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Compliance and business implications

Records a frontier operator would need

  • Compute inventories showing hardware, networking and theoretical performance.
  • Training-run measurements capable of identifying when a computational threshold is crossed.
  • Ownership, custody and access records for model weights.
  • Physical-security and cybersecurity evidence for development environments.
  • Red-team plans, test results and records of dangerous-capability evaluations.
  • A compliance owner coordinating research, infrastructure, security and legal teams.
  • Procedures for reviewing confidential business information before submission.

Key trade-offs

Detailed reporting could give the government strategically important visibility while exposing sensitive intellectual property and creating a high-value concentration of security information. Numerical thresholds offer clarity but can invite threshold gaming through sparsity, workload splitting, distributed clusters or separate legal entities. Cloud providers may also observe technical usage without reliably knowing a customer’s ultimate purpose, especially when resellers, nested accounts or overseas affiliates are involved.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Important edge cases

Coverage could be complicated when a company rents rather than owns a cluster, several entities share infrastructure, training spans multiple regions or providers, a model is trained privately, or a company crosses a threshold only briefly. A model below the compute threshold could still present serious risks, while a qualifying cluster might be used for a mixture of AI and non-AI workloads. The proposed materials do not establish a definitive answer for every scenario, so legally consequential determinations require the regulatory text and professional advice.

What executives should do now

Organizations operating near the frontier can prepare without assuming that this proposal alone creates a present filing obligation:

  • Maintain a consolidated inventory of clusters, networking and AI-training capacity.
  • Record computational work for major training runs and retain methodology.
  • Document model-weight ownership, custody and access controls.
  • Preserve red-team and dangerous-capability evaluation evidence.
  • Map U.S. persons, foreign affiliates, cloud customers and shared infrastructure.
  • Coordinate AI-governance processes with export-control and cybersecurity reviews.
  • Monitor BIS for a final rule, withdrawal, replacement or new forms before treating the 2024 proposal as enforceable.

Bottom line on the proposal’s status

Commerce’s September 2024 initiative was a narrowly targeted proposed data-collection rule for the most advanced AI developers and computing operators. It was designed to improve national-security and industrial-base visibility, not to regulate every AI company or impose general model licensing. Because the available materials do not establish a final rule for this specific proposal, companies should distinguish preparedness from a current legal reporting duty.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.