<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="part2stratml.xsl"?>
<PerformancePlanOrReport xmlns="urn:ISO:std:iso:17469:tech:xsd:PerformancePlanOrReport" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

 xsi:schemaLocation="urn:ISO:std:iso:17469:tech:xsd:PerformancePlanOrReport http://stratml.us/references/PerformancePlanOrReport20160216.xsd" Type="Strategic_Plan"><Name>Governing AI: A Blueprint for the Future</Name><Description>A five-point blueprint for the public governance of AI ~ Part 1 of this paper offers a five-point blueprint to address
several current and emerging AI issues through public policy, law, and regulation. We offer this recognizing that every part of this blueprint will benefit from broader discussion and require deeper development. But we hope this can contribute constructively to the work ahead.</Description><OtherInformation/><StrategicPlanCore><Organization><Name>Microsoft</Name><Acronym>MS</Acronym><Identifier>_6a084ba6-414c-11e9-9c11-5766e90f6739</Identifier><Description/><Stakeholder StakeholderTypeType="Person"><Name>Brad Smith</Name><Description>Vice Chair &amp; President</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Satya Nadella</Name><Description>CEO ~ These suggestions build on the lessons we've been learning
based on the work we’ve been doing for several years.
Microsoft CEO Satya Nadella set us on a clear course when
he wrote in 2016 that "perhaps the most productive debate
we can have isn't one of good versus evil: The debate
should be about the values instilled in the people and
institutions creating this technology."</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Governments</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Academia</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Civil Society</Name><Description/></Stakeholder></Organization><Vision><Description>AI improves people’s lives</Description><Identifier>_f5b1e092-fcad-11ed-b89a-14061883ea00</Identifier></Vision><Mission><Description>To address current and emerging AI issues through public policy, law, and regulation</Description><Identifier>_f5b1e376-fcad-11ed-b89a-14061883ea00</Identifier></Mission><Value><Name>Artificial Intelligence</Name><Description>We’ve long said that advancing AI responsibly is a journey,
and our own years-long effort to build a responsible AI
program at Microsoft has prepared us for this AI inflection
point. As we continue to unlock greater benefits from the
latest AI technologies, we remain clear-eyed about risks
and mindful of the important role we play in advancing
the state-of-the-art, not only for AI capabilities but for
responsible AI governance, mitigations, and culture-building.</Description></Value><Value><Name>Governance</Name><Description>Our governance approach begins with how we structure
and organize responsible AI at Microsoft, with coordination
from the Office of Responsible AI and essential involvement
across every part of the company—core responsible AI
teams in engineering, research, and policy, embedded
Responsible AI Champions throughout organizations,
executive leadership and accountability as embodied in
the Responsible AI Council, and oversight from Microsoft’s
Board. Governance extends to creating, maintaining,
and implementing a shared set of rules and policies to
operationalize responsible AI, which we do with our
Responsible AI Standard. It also requires additional
oversight and expert guidance for higher-risk or novel-use
cases like the development of the new Bing, which is where
our Sensitive Uses program of required reporting and
deeply engaged, case-specific review is so critical.</Description></Value><Value><Name>Community</Name><Description>Cutting across all our work is the imperative to build and
sustain culture and community. In addition to investing
in existing people, hiring new talent, and developing
training and skills-building, we have and will continue to
prioritize diversity, collaboration, and the capacity to see AI
systems through a sociotechnical lens. Finally, Microsoft is
committed to proactive, practical steps that institutionalize
not just a culture of responsible AI within the company, but
tangible tools and capabilities that make AI safer and more
reliable for our customers and society. </Description></Value><Value><Name>Transparency</Name><Description>We will continue to be transparent and share our learnings
broadly. We know that our efforts will require adjustments
and course corrections, especially as we learn from those
outside the company. As societal conversations and
government oversight of AI evolve, we will continue to
share our commitments for the responsible development
and deployment of AI. We will also share our thoughts
and suggestions about policy, regulation, and the role that
private-public sector dialogue and partnerships can play,
as we have done in our blueprint for AI policy, law, and
regulation.</Description></Value><Value><Name>Collaboration</Name><Description>The current AI moment calls for industry, governments,
academia, and civil society to come together to better
define the boundaries for AI in society. We welcome a
robust, global, cross-sector discussion of how to build and
deploy safe, secure, and transparent AI systems. We hope
that by sharing more details on our responsible AI efforts,
we are contributing useful information to this conversation.
^^
Together, we can build a future where AI advances the best
of humanity. </Description></Value><Goal><Name>Safety</Name><Description>Implement and build upon new government-led AI safety frameworks</Description><Identifier>_f5b1e538-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>1</SequenceIndicator><Stakeholder StakeholderTypeType="Organization"><Name>U.S. National Institute of Standards and Technology</Name><Description/></Stakeholder><OtherInformation>First, implement and build upon new government-led
AI safety frameworks. The best way to succeed is often to
build on the successes and good ideas of others. Especially
when one wants to move quickly. In this instance, there
is an important opportunity to build on work completed just four months ago by the U.S. National Institute of
Standards and Technology, or NIST. Part of the Department
of Commerce, NIST has completed and launched a new AI
Risk Management Framework.
^^
We offer four concrete suggestions to implement and build
upon this Framework, including commitments Microsoft is
making in response to a recent White House meeting with
leading AI companies. We also believe the Administration
and other governments can accelerate momentum through
procurement rules based on this Framework. </OtherInformation><Objective><Name>Risk Management</Name><Description>Implement NIST's AI Risk Management Framework</Description><Identifier>_f5b1e812-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>1.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>First, Microsoft is committing to the White House, in
response to its recent meeting, that we will implement
NIST’s AI Risk Management Framework. Microsoft’s
internal Responsible AI Standard is closely aligned with the
Framework already, and we will now work over the summer
to implement it so that all our AI services benefit from it.</OtherInformation></Objective><Objective><Name>Testing &amp; Engineering</Name><Description>Augment Microsoft's AI testing work with new steps to further strengthen our engineering practices relating to high-risk AI systems</Description><Identifier>_f5b1ea2e-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>1.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Second, we are similarly committing that we will
augment Microsoft’s existing AI testing work with new
steps to further strengthen our engineering practices
relating to high-risk AI systems.
^^
Under Microsoft’s Responsible AI Standard, our AI
engineering teams already work to identify potential
harms, measure their propensity to occur, and build
mitigations to address them. We have further developed
red teaming techniques using multidisciplinary teams,
which were originally developed to identify cybersecurity
vulnerabilities, to stress test AI systems with a wide range of
expertise, including privacy, security, and fairness.
^^
For high-risk systems, Microsoft is committing that red
teaming is conducted before deployment by qualified
experts who are independent of the product teams
building those systems, adopting a best practice from
the financial services industry. We will rely upon these
red teams, together with our product teams who are
responsible for systematic evaluations of the products
that they build, to help us identify, measure, and mitigate
potential harms.
^^
In addition to continually monitoring, tracking, and
evaluating our AI systems, we will use metrics to measure
and understand systemic issues specific to generative AI experiences, such as the extent to which a model’s output is
supported by information contained in input sources. (We
are releasing the first of these metrics this week as part of
our Azure OpenAI Service at Build, our annual developer
conference.)</OtherInformation></Objective><Objective><Name>Self-Attestation</Name><Description>Require vendors of critical AI systems to the U.S. Government to self-attest that they are implementing NIST's AI Risk Management Framework</Description><Identifier>_f5b1ebd2-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>1.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Third, we believe the Administration can accelerate
momentum through an Executive Order that requires
vendors of critical AI systems to the U.S. Government
to self-attest that they are implementing NIST's AI Risk
Management Framework.
^^
It's important for governments to move faster, using both
carrots and sticks. In the United States, federal procurement
mechanisms have repeatedly demonstrated their value in
improving the quality of products and advancing industry
practice more generally. Building on similar approaches
used for key technology priorities like cybersecurity, the
U.S. Government could insert requirements related to
the AI Risk Management Framework into the federal
procurement process for AI systems.
^^
As a starting point, we believe it makes sense to scope such
procurement requirements to focus on critical decision
systems, meaning AI systems that have the potential to
meaningfully impact the public’s rights, opportunities, or
access to critical resources or services. This would align with
the approach set out in the Blueprint for an AI Bill of Rights,
released last year by the White House’s Office of Science
and Technology Policy.</OtherInformation></Objective><Objective><Name>Standards</Name><Description>Work with leaders in industry leaders and government to develop standards relating to foundation models</Description><Identifier>_f5b1ee5c-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>1.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Finally, we are committed to working with other
industry leaders and those in government to develop
new and additional standards relating to highly
capable foundation models. ~ We recognize that the
pace of AI advances raises new questions and issues
related to safety and security, and we are committed to
working with others to develop actionable standards
to help evaluate and address them. Already, leaders at
OpenAI, Google, Anthropic, and other AI companies
have advanced important ideas that will help provide
a foundation for future progress. We look forward to
working with them and many others as these types of
efforts move forward.</OtherInformation></Objective></Goal><Goal><Name>Critical Infrastructure</Name><Description>Require effective safety brakes for AI systems that control critical infrastructure</Description><Identifier>_f5b1f168-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>2</SequenceIndicator><Stakeholder StakeholderTypeType="Organization"><Name/><Description/></Stakeholder><OtherInformation>Second, require effective safety brakes for AI systems
that control critical infrastructure. ~ In some quarters,
thoughtful individuals increasingly are asking whether we
can satisfactorily control AI as it becomes more powerful.
Concerns are sometimes posed regarding AI control of
critical infrastructure like the electrical grid, water system,
and city traffic flows.
^^
This is the right time to discuss this question. This
blueprint proposes new safety requirements that
in effect would create safety brakes for AI systems
that control the operation of designated critical infrastructure. These fail-safe systems would be part
of a comprehensive approach to system safety that
would keep effective human oversight, resilience, and
robustness top of mind. In spirit, they would be similar
to the braking systems engineers have long built into
other technologies such as elevators, school buses, and
high-speed trains, to safely manage not just everyday
scenarios, but emergencies as well.
^^
In this approach, the government would define the class
of high-risk AI systems that control critical infrastructure
and warrant such safety measures as part of a
comprehensive approach to system management. New
laws would require operators of these systems to build
safety brakes into high-risk AI systems by design. The
government would then ensure that operators test highrisk systems regularly to ensure that the system safety
measures are effective. And AI systems that control the
operation of designated critical infrastructure would
be deployed only in licensed AI datacenters that would
ensure a second layer of protection through the ability
to apply these safety brakes, thereby ensuring effective
human control.
</OtherInformation><Objective><Name>High-Risk AI Systems</Name><Description>Define the class of high-risk AI systems that are being deployed to control critical infrastructure and warrant safety brakes</Description><Identifier>_f5b1f33e-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>2.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>First, the government should define the class of high-risk AI systems that are being deployed to control critical infrastructure and warrant safety brakes as part
of a comprehensive approach to system safety.
^^
In the United States, the Secretary of Homeland Security
is responsible for identifying and prioritizing critical
infrastructure in coordination with other government
agencies. Most notably, this includes the Cybersecurity
and Infrastructure Security Agency, or CISA, which has
identified 16 critical infrastructure sectors, including the
communications sector, the emergency services sector, and
the energy sector, to name a few.
^^
For the purposes of applying the safety brake concept to AI
systems, we need to focus on the AI systems that are used
to control the operation of critical infrastructure. There
will be many AI systems used within critical infrastructure
sectors that are low risk and that do not require the same
depth of safety measures -- employee productivity tools
and customer service agents are two such examples.
^^
Instead, one should focus on highly capable systems,
increasingly autonomous systems, and systems that cross
the digital-physical divide. For the purposes of spurring
further discussion, one place to start might be to focus on
AI systems that:
^^
• Take decisions or actions affecting large-scale
networked systems;
^
• Process or direct physical inputs and outputs;
^
• Operate autonomously or semi-autonomously; and
^
• Pose a significant potential risk of large-scale harm,
including physical, economic, or environmental harm.</OtherInformation></Objective><Objective><Name>Safety Brakes</Name><Description>Require system developers to ensure that safety brakes are built by design into the use of AI systems for the control of critical infrastructure</Description><Identifier>_f5b1f5f0-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>2.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Second, the government should require system
developers to ensure that safety brakes are built by
design into the use of AI systems for the control of
critical infrastructure.
^^
System safety is a well-established discipline that we
have put to work in the aviation, automotive, and nuclear
sectors, among others, and it is one that we must bring to bear to the engineering of AI systems that control critical
infrastructure. We should establish a layered approach to
AI safety, with the "safety brake" concept implemented at
multiple levels.
^^
While the implementation of "safety brakes" will vary across
different systems, a core design principle in all cases is that
the system should possess the ability to detect and avoid
unintended consequences, and it must have the ability to
disengage or deactivate in the event that it demonstrates
unintended behavior. It should also embody best practice
in human-computer interaction design.</OtherInformation></Objective><Objective><Name>Human Control</Name><Description>Ensure operators test and monitor high-risk systems to ensure that AI-systems that power critical infrastructure remain within human control</Description><Identifier>_f5b1f83e-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>2.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Third, the government should ensure operators test and
monitor high-risk systems to ensure that AI-systems
that power critical infrastructure remain within human
control.
^^
Specific system testing will be needed in the context of a
planned deployment for critical infrastructure. In other
words, the use of an advanced AI model must be reviewed
in the context of how it will be used in a specific product or
service.
^^
In accordance with system safety best practices, the system
and each of its components should be tested, verified, and
validated rigorously. It should be provable that the system
operates in a way that allows humans to remain in control
at all times. In practice, we anticipate that this will require
close and regular coordination between a system operator,
their AI infrastructure provider, and their regulatory
oversight bodies.</OtherInformation></Objective><Objective><Name>Critical Infrastructure</Name><Description>Ensure that AI systems controlling critical infrastructure are deployed in licensed AI infrastructure</Description><Identifier>_f5b1fb2c-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>2.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Fourth, AI systems that control the operation of
designated critical infrastructure should be deployed
only in licensed AI infrastructure.
^^
We believe it would be wise to require that AI systems that
control the operations of higher-risk critical infrastructure
systems be deployed on licensed AI infrastructure. This
is not to suggest that the AI infrastructure needs to be
a hyperscale cloud provider such as Microsoft. Critical
infrastructure operators might build AI infrastructure
and qualify for such a license in their own right. But
to obtain such a license, the AI infrastructure operator
should be required to design and operate their system to
allow another intervention point -- in effect a second and separate layer of protection -- for ensuring human control
in the event that application-level measures fail. 
^^
These proposals might leave some wondering how realistic
or futureproof "safety brakes" are if we are on a path to
developing AI systems that are more capable than humans.
They might ask: couldn't the AI system itself work around
safety brakes and override them? Won't the AI system
know how humans will respond at every step of the way
and simply work around those responses?
^^
In posing those questions, it’s important to be clear
about the facts as they stand today. Today's cutting-edge
AI systems like GPT-4 from OpenAI and Claude from
Anthropic have been specifically tested -- by qualified third-party experts from the Alignment Research Center -- for dangerous capabilities, such as the ability to evade human oversight and become hard to shut down. Those tests
concluded that GPT-4 and Claude do not have sufficient
capabilities to do those things today.
^^
This rigorous testing and the conclusions drawn provide us
with clarity as to the capabilities of today’s cutting-edge AI
models. But we should also heed the Alignment Research
Center’s call for ongoing research on these topics and
recognize the need for industry-wide commitment to AI
capability evaluations. Put simply, we need to ensure that
we have the right structures in place not only to understand
the status quo, but to get ahead of the future. That is
precisely why we need action with respect to the small but
important class of highly capable AI models that are on the
frontier -- a topic that our next section addresses.</OtherInformation></Objective></Goal><Goal><Name>Laws &amp; Regulations</Name><Description>Develop a broad legal and regulatory framework based on the technology architecture for AI</Description><Identifier>_f5b1fdfc-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>3</SequenceIndicator><Stakeholder StakeholderTypeType="Organization"><Name/><Description/></Stakeholder><OtherInformation>Third, develop a broad legal and regulatory framework
based on the technology architecture for AI. ~ We believe
there will need to be a legal and regulatory architecture
for AI that reflects the technology architecture for AI itself.
In short, the law will need to place various regulatory
responsibilities upon different actors based upon their role
in managing different aspects of AI technology.
^^
For this reason, this blueprint includes information about
some of the critical pieces that go into building and using
new generative AI models. Using this as context, it proposes
that different laws place specific regulatory responsibilities
on the organizations exercising certain responsibilities at
three layers of the technology stack: the applications layer,
the model layer, and the infrastructure layer.
^^
This should first apply existing legal protections at the
applications layer to the use of AI. This is the layer where the
safety and rights of people will most be impacted, especially
because the impact of AI can vary markedly in different
technology scenarios. In many areas, we don’t need new
laws and regulations. We instead need to apply and enforce
existing laws and regulations, helping agencies and courts
develop the expertise needed to adapt to new AI scenarios.
^^
There will then be a need to develop new law and
regulations for highly capable AI foundation models,
best implemented by a new government agency. This will
impact two layers of the technology stack. The first will
require new regulations and licensing for these models
themselves. And the second will involve obligations for
the AI infrastructure operators on which these models are
developed and deployed. The blueprint that follows offers
suggested goals and approaches for each of these layers.
In doing so, this blueprint builds in part on a principle
developed in recent decades in banking to protect against
money laundering and criminal or terrorist use of financial
services. The "Know Your Customer" -- or KYC -- principle
requires that financial institutions verify customer identities,
establish risk profiles, and monitor transactions to help
detect suspicious activity. It would make sense to take this
principle and apply a KY3C approach that creates in the
AI context certain obligations to know one’s cloud, one’s
customers, and one’s content.
^^
In the first instance, the developers of designated, powerful
AI models first “know the cloud” on which their models are
developed and deployed. In addition, such as for scenarios
that involve sensitive uses, the company that has a direct
relationship with a customer -- whether it be the model
developer, application provider, or cloud operator on which
the model is operating -- should "know the customers" that
are accessing it.
^^
Also, the public should be empowered to "know the
content" that AI is creating through the use of a label or
other mark informing people when something like a video
or audio file has been produced by an AI model rather than
a human being. This labeling obligation should also protect
the public from the alteration of original content and the
creation of "deep fakes." This will require the development
of new laws, and there will be many important questions
and details to address. But the health of democracy and
future of civic discourse will benefit from thoughtful
measures to deter the use of new technology to deceive or
defraud the public.</OtherInformation><Objective><Name>Best Practices</Name><Description>Help our customers apply state-of-the-art best practices to deploy AI
lawfully and responsibly</Description><Identifier>_f5b20072-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>3.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>First, we will work with our customers to help them
apply state-of-the-art best practices to deploy AI
lawfully and responsibly. 
^^
One of the critical characteristics
of AI is that the real-world impact on specific groups and
issues is defined not just by the developer of an AI model
or system, but also in its implementation in a specific
service or application. In fact, in many circumstances it is
only at the application level that it’s possible to specifically
identify and test for these real-world impacts before AI is
deployed. As a result, responsibilities are often shared or
even distributed, with different organizations needing to
play different roles.
^^
This helps explain why it's so important for customers that
use AI in their services to develop their own capabilities to
do so responsibly. This also explains why it is so important
for a leading tech company to share information and
lend their expertise on state-of-the-art best practices and
tooling for responsible AI deployment.
^^
We have been doing this type of work for two decades
on other issues involving digital technology, including
to implement legal compliance systems, advance
cybersecurity, and protect privacy. We began five years ago
to do similar work relating to artificial intelligence, and we
will expand this initiative to work more broadly and deeply
with our customers in the year ahead.</OtherInformation></Objective><Objective><Name>Regulation</Name><Description>Increase the AI expertise and capabilities of regulatory agencies</Description><Identifier>_f5b2025c-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>3.2</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Regulatory Agencies</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Food and Drug Administration</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Federal Aviation Administration</Name><Description/></Stakeholder><OtherInformation>Second, we believe that regulatory agencies will
need to add new AI expertise and capabilities. 
^^
Very quickly, this need will reach virtually every agency in
most governments in the world. For example, an agency
like the Food and Drug Administration will need more AI
experts who can help evaluate the use of cutting-edge AI
systems by companies in something like the clinical trials
for new drugs. Similarly, agencies like the Federal Aviation
Administration will need additional AI experts to help
evaluate the new uses of AI by aircraft manufacturers in
developing new planes.
^^
Generative AI itself will be a powerful tool that will better
enable regulatory agencies to evaluate the use of AI. This
is because models like GPT-4 and services like ChatGPT,
GitHub Copilot, and Microsoft M365 Copilot make it far
easier for people to harness the power of AI to access
data and evaluate it more quickly. As Google rightly
recommended in a new white paper just last week, it will be
important for governments to "direct sectoral regulators
to update existing oversight and enforcement regimes to
apply to AI systems, including on how existing authorities
apply to the use of AI." Agencies will need the funding, staff,
and commitment to put these new tools to work.</OtherInformation></Objective><Objective><Name>Education</Name><Description>Make information about AI technologies and responsible AI practices available to legislators, judges, and lawyers</Description><Identifier>_f5b20536-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>3.3</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Legislators</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Judges</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Lawyers</Name><Description/></Stakeholder><OtherInformation>Third, we will support broad educational initiatives
to make information about AI technologies and
responsible AI practices available to legislators, judges,
and lawyers.
^^
Finally, rapid AI advances are creating new
pressures on those who make or help enforce the law to
learn about new AI technologies and how they work. We
witnessed a similar need when the personal computer first
became popular in the 1980s. For example, judges needed
to decide cases that started to turn in part on evidence
about or involving PC software and hardware.
^^
Beginning in the 1990s, Microsoft supported broad initiatives
to share information about how this new technology worked.
We continue to do this today in selected areas such as
electronic discovery. The accelerating use of AI means that
new such efforts will be needed. We will support this work,
including by supporting bar associations and other public
interest and civic groups and activities.</OtherInformation></Objective><Objective><Name>Laws &amp; Regulations</Name><Description>Develop new laws and regulations for highly capable AI foundation models</Description><Identifier>_f5b20798-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>3.4</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name/><Description/></Stakeholder><OtherInformation>Developing new laws and regulations for highly
capable AI foundation models
^^
While existing laws and regulations can be applied and
built upon for the application layer of the tech stack, we
believe that new approaches will be needed for the two
additional layers beneath that reflect the new and more
powerful AI models that are emerging. The first of these is
for the development of the most powerful new AI models,
and the second is for the deployment and use of these
models in advanced datacenters.
^^
From our work on the frontiers of AI, we have seen a new
class of model emerge. Highly capable foundation models are trained on internet-scale datasets and are effective outof-the-box at new tasks—a model like GPT-4 allows you
to create a never-seen-before image using words in one
prompt, and a speech in the style of Franklin Roosevelt in
the very next.
^^
At the cutting-edge, the capabilities of these foundation
models are at once very impressive and can be harder to
predict. As the models have been scaled up, we have seen
anticipated advances in capabilities, as well as surprising
ones that we and others did not predict ahead of time
and could not observe on a smaller scale. Despite rigorous
prerelease testing and engineering, we’ve sometimes only
learned about the outer bounds of model capabilities
through controlled releases with users. And the work
needed to harness the power of these models and align
them to the law and societal values is complex and
evolving.
^^
These characteristics of highly capable models present
risk surfaces that need to be addressed. To date, we have
benefited from the high safety standards self-imposed
by the U.S. developers who have been working at the
frontiers of AI model development. But we shouldn’t leave
these issues of societal importance to good judgment
and self-restraint alone. We need regulatory frameworks
that anticipate and get ahead of the risks. And we need to
acknowledge the simple truth that not all actors are wellintentioned or well-equipped to address the challenges
that highly capable models present. Some actors will use AI
as a weapon, not a tool, and others will underestimate the
safety challenges that lie ahead.
^^
Last week, Sam Altman, the CEO of OpenAI, testified before
Congress and called for the establishment of a licensing
regime for this small but important class of highly capable
models at the frontiers of research and development.
As Microsoft, we endorse that call and support the
establishment of a new regulator to bring this licensing
regime to life and oversee its implementation.</OtherInformation></Objective><Objective><Name>Knowledge</Name><Description>Share specialized knowledge about advanced AI models to help governments define the regulatory threshold</Description><Identifier>_f5b20996-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>3.4.1</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name/><Description/></Stakeholder><OtherInformation>First, we and other leading AI developers will need
to share our specialized knowledge about advanced
AI models to help governments define the regulatory
threshold.
^^
One of the initial challenges will be to define which AI
models should be subject to this level of regulation. The
objective is not to regulate the rich ecosystem of AI models
that exists today and should be supported into the future,
but rather the small number of AI models that are very
advanced in their capabilities and in some cases, redefining
the frontier. We refer to this small subset of models as
highly capable AI models in this white paper.
^^
Defining the appropriate threshold for what constitutes a
highly capable AI model will require substantial thought,
discussion, and work in the months ahead. The amount of
compute used to train a model is one tractable proxy for
model capabilities, but we know today that it is imperfect
in several ways and unlikely to be durable into the future,
especially as algorithmic improvements lead to compute
efficiencies or new architectures altogether.
^^
A more durable but unquestionably more complex
proposition would be to define the capabilities that are
indicative of high ability in areas that are consequential to
safety and security, or that represent new breakthroughs
that we need to better understand before proceeding
further. Further research and discussion are needed to
set such a capability-based threshold, and early efforts
to define such capabilities must continue apace. In the
meantime, it may be that as with many complex problems
in life, we start with the best option on offer today—a
compute-based threshold—and commit to a program of
work to evolve it into a capability-based threshold in short
order. </OtherInformation></Objective><Objective><Name>Licensing</Name><Description>Define the requirements to obtain a license to develop or deploy highly capable
AI models</Description><Identifier>_f5b20cc0-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>3.4.2</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name/><Description/></Stakeholder><OtherInformation>Second, we will support governments in their efforts to
define the requirements that must be met in order to
obtain a license to develop or deploy a highly capable
AI model.
^^
A licensing regime for highly capable AI models should
be designed to fulfill three key goals. First and foremost, it
must ensure that safety and security objectives are achieved
in the development and deployment of highly capable AI
models. Second, it must establish a framework for close
coordination and information flows between licensees and
their regulator, to ensure that developments material to the
achievement of safety and security objectives are shared
and acted on in a timely fashion. Third, it must provide a footing for international cooperation between countries
with shared safety and security goals, as domestic initiatives
alone will not be sufficient to secure the beneficial uses of
highly capable AI models and guard against their misuse.
We need to proceed with an understanding that it is
currently trivial to move model weights across borders,
allowing those with access to the “crown jewels” of highly
capable AI models to move those models from country to
country with ease.
^^
To achieve safety and security objectives, we envision
licensing requirements such as advance notification
of large training runs, comprehensive risk assessments
focused on identifying dangerous or breakthrough
capabilities, extensive prerelease testing by internal and
external experts, and multiple checkpoints along the way.
Deployments of models will need to be controlled based
on the assessed level of risk and evaluations of how wellplaced users, regulators, and other stakeholders are to
manage residual risks. Ongoing monitoring post-release
will be essential to ensuring that guardrails are functioning
as intended and that deployed models remain under
human control at all times.
^^
In practice, we believe that the effective enforcement of
such a regime will require us to go one layer deeper in the
tech stack to the AI datacenters on which highly capable AI
models are developed and deployed. </OtherInformation></Objective><Objective><Name>Datacenters</Name><Description>Impose licensing requirements on the operators of AI datacenters that
are used for the testing or deployment of these models</Description><Identifier>_f5b20f54-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>3.4.3</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>AI Datacenters</Name><Description/></Stakeholder><OtherInformation>Third, we will support government efforts to ensure
the effective enforcement of a licensing regime for
highly capable AI models by also imposing licensing
requirements on the operators of AI datacenters that
are used for the testing or deployment of these models.
^^
Today’s highly capable AI models are built on advanced
AI datacenters. They require huge amounts of computing
power, specialized AI chips, and sophisticated infrastructure
engineering, like Microsoft’s facilities in Iowa, described
above. Such AI datacenters are therefore critical enablers of
today’s highly capable AI models and an effective control
point in a comprehensive regulatory regime.
^^
Much like the regulatory model for telecommunications
network operators and critical infrastructure providers, we
see a role for licensing providers of AI datacenters to ensure that they play their role responsibly and effectively to
ensure the safe and secure development and deployment
of highly capable AI models. To obtain a license, an AI
datacenter operator would need to satisfy certain technical
capabilities around cybersecurity, physical security, safety
architecture, and potentially export control compliance.
^^
In effect, this would start to apply for AI a principle
developed for banking to protect against money
laundering and criminal or terrorist use of financial services.
The “Know Your Customer”—or KYC— principle requires
that financial institutions verify customer identities,
establish risk profiles, and monitor transaction to help
detect suspicious activity.
^^
In a similar way, it would make sense for a similar KYC
principle to require that the developers of powerful AI
models first “know the cloud” on which their models
are deployed. The use of authorized and licensed AI
datacenters would ensure that those who develop
advanced models would have several vendors from
which to choose. And it would enable the developer of
an advanced model to build or operate their own cloud
infrastructure as well, based on meeting the requisite
technical standards and obligations.
^^
The licensed AI datacenter operator would then need to
meet ongoing regulatory requirements, several of which
are worth considering.
^^
First, operators of AI datacenters have a special role to play
in securing highly capable AI models to protect them from
malicious attacks and adversarial actors. This likely involves
not just technical and organizational measures, but also
an ongoing exchange of threat intelligence between the
operator of the AI datacenter, the model developer, and a
regulator.
^^
Second, in certain instances, such as for scenarios that
involve sensitive uses, the cloud operator on which the
model is operating should apply the second aspect of the
KYC principle – knowing the customers who are accessing
the model. More thought and discussion will be needed
to work through the details, especially when it comes to
determining who should be responsible for collecting and
maintaining specific customer data in different scenarios.
^^
The operators of AI datacenters that have implemented
know-your-customer procedures can help regulators
get comfortable that all appropriate licenses for model
development and deployment have been obtained. One
possible approach is that substantial uses of compute that
are consistent with large training runs should be reported
to a regulator for further investigation.
^^
Third, as export control measures evolve, operators of AI
datacenters could assist with the effective enforcement
of those measures, including those that attach at the
infrastructure and model layers of the tech stack.
^^
Fourth, as discussed above, the AI infrastructure operator
will have a critical role and obligation in applying safety
protocols and ensuring that effective AI safety brakes
are in place for AI systems that manage or control critical
infrastructure. It will be important for the infrastructure
operator to have the capability to intervene as a second
and separate layer of protection, ensuring the public that
these AI systems remain under human control.
^^
These early ideas naturally will all need to be developed
further, and we know that our colleagues at OpenAI have
important forthcoming contributions on these topics too.
What is clear to us now is that this multitiered licensing
regime will only become more important as AI models on
the frontiers become more capable, more autonomous,
and more likely to bridge the digital-physical divide. As
we discussed earlier, we believe there is good reason to
plan and implement an effective licensing regime that
will, among other things, help to ensure that we maintain
control over our electricity grid and other safety-critical
infrastructure when highly capable AI models are playing a
central role in their operation.</OtherInformation></Objective></Goal><Goal><Name>Transparency &amp; Access</Name><Description>Promote transparency and ensure academic and nonprofit access to AI</Description><Identifier>_f5b21166-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>4</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Aacademia</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Nonprofits</Name><Description/></Stakeholder><OtherInformation>Fourth, promote transparency and ensure academic
and nonprofit access to AI. We believe a critical public
goal is to advance transparency and broaden access to AI resources. While there are some important tensions
between transparency and the need for security, there exist
many opportunities to make AI systems more transparent
in a responsible way. That’s why Microsoft is committing to
an annual AI transparency report and other steps to expand
transparency for our AI services.
^^
We also believe it is critical to expand access to AI resources
for academic research and the nonprofit community.
Basic research, especially at universities, has been of
fundamental importance to the economic and strategic
success of the United States since the 1940s. But unless
academic researchers can obtain access to substantially
more computing resources, there is a real risk that scientific
and technological inquiry will suffer, including relating to AI
itself. Our blueprint calls for new steps, including steps we
will take across Microsoft, to address these priorities.</OtherInformation><Objective><Name>Reports</Name><Description>Release an annual transparency report to inform the public about our policies, systems, progress, and performance in managing AI responsibly and safely</Description><Identifier>_f5b21486-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>4.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>First, Microsoft will release an annual transparency
report to inform the public about its policies, systems,
progress, and performance in managing AI responsibly
and safely.
^^
Transparency reports have proven to be an effective
measure to drive corporate accountability and help the
public better understand the state-of-the-art and progress
toward goals. Microsoft believes transparency reports
have a role to play in the responsible AI context too,
and so we will release an annual transparency report to
inform the public about our policies, systems, progress,
and performance in managing AI responsibly and safely. If
adopted across the industry, transparency reports would be
a helpful mechanism for recording the maturing practice of
responsible AI and charting cross-industry progress.</OtherInformation></Objective><Objective><Name>Registry</Name><Description>Develop a national registry of high-risk AI systems</Description><Identifier>_f5b21814-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>4.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Second, Microsoft will support the development of a
national registry of high-risk AI systems that is open
for inspection so that members of the public can learn
where and how those systems are in use.
^^
Public trust in AI systems can be enhanced by demystifying
where and how they are in use. For high-risk AI systems,
Microsoft supports the development of a national registry
that would allow members of the public to review an overview of the system as deployed and the measures
taken to ensure the safe and rights-respecting performance
of the system.
^^
For this information to be useful to the public, it should be
expressed at the system level, providing details about the
context of use, and be written for nontechnical audiences.
To achieve this, the United States could implement the
approach of several European cities in adopting the
Algorithmic Transparency Standard and developing
accessible explanations of how it uses AI (see, for example,
the City of Amsterdam’s Algorithm Register).</OtherInformation></Objective><Objective><Name>Notice</Name><Description>Ensure AI systems inform the public when they are interacting with them</Description><Identifier>_f5b21a58-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>4.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Third, Microsoft will commit that it will continue to
ensure that our AI systems are designed to inform the
public when they are interacting with an AI system
and that the system's capabilities and limitations are
communicated clearly.
^^
We believe that transparency is important not only through
broad reports and registries, but in specific scenarios
and for the users of specific AI systems. Microsoft will
continue to build AI systems designed to support informed
decision making by the people who use them. We take
a holistic approach to transparency, which includes not
only user interface features that inform people that they
are interacting with an AI system, but also educational
materials, such as the new Bing primer, and detailed
documentation of a system’s capabilities and limitations,
such as the Azure OpenAI Service Transparency Note. This
documentation and experience design elements are meant
to help people understand an AI system’s intended uses
and make informed decisions about their own use.</OtherInformation></Objective><Objective><Name>Labelling</Name><Description>Require AI-generated content to be labeled</Description><Identifier>_f5b21d6e-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>4.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Fourth, we believe there is benefit in requiring AI-generated content to be labeled in important scenarios so that the public “knows the content” it is receiving.
^^
This is the third part of the KY3C approach we believe
is worth considering. As we are committing above for
Microsoft’s services Bing Image Creator and Designer, we
believe the public deserves to “know the content” that AI
is creating, informing people when something like a video
or audio has been originally produced by an AI model
rather than a human being. This labeling obligation should
also inform people when certain categories of original content have been altered using AI, helping protect against
the development and distribution of “deep fakes.” This
will require the development of new laws, and there will
be many important questions and details to address. But
the health of democracy and future of civic discourse will
benefit from thoughtful measures to deter the use of new
technology to deceive or defraud the public.</OtherInformation></Objective><Objective><Name>AI Resources</Name><Description>Provide access to AI resources for academic research and the nonprofit community</Description><Identifier>_f5b2202a-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>4.5</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Academic Research Community</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Nonprofit Community</Name><Description/></Stakeholder><OtherInformation>Access to AI resources for academic research and the
nonprofit community
^^
We believe there is another element that adds to
transparency and that deserves more prominent attention.
This is the need to provide broad access to AI resources for
academic research and the nonprofit community.
^^
The high cost of computational resources for the training
of large-scale AI models, as well as other AI projects, is
understandably raising concerns in the higher education
and nonprofit communities. We understand this issue well
because Microsoft’s large technology investment in OpenAI
in 2019 originated from precisely this need for OpenAI
itself, due in part to its nonprofit status.
^^
Basic research, perhaps especially at universities, has
been of fundamental importance to the economic and
strategic success of the United States since the 1940s. Much
of the tech sector itself owes both its birth and ongoing
innovation to critical basic research pursued in colleges
and universities across the country. It’s a success story that
has been studied and emulated in many other countries
around the world. The past few decades have seen huge
swaths of basic research in almost every field propelled
by growing computing resources and data science. Unless
academic researchers can obtain access to substantially
more computing resources, there is a real risk that scientific
inquiry and technological innovation will suffer.
^^
Another dimension of this problem is also important.
Academic researchers help ensure accountability to the
public by advancing our understanding of AI. The public
needs academics to pursue research in this area, including
research that advances AI accountability by analyzing the
behavior of the models the commercial sector is creating.
While new and smaller open-source AI models are
emerging and clearly are important, other basic research projects involving AI will almost certainly require more
computational power than in the past. And unless new
funding sources come together to provide a more
centralized resource for the academic community,
academic research will be at risk. This has led us to offer two
focused commitments:</OtherInformation></Objective><Objective><Name>Computing</Name><Description>Provide computing resources for academic research</Description><Identifier>_f5b2226e-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>4.5.1</SequenceIndicator><Stakeholder StakeholderTypeType="Organization"><Name>National AI Research Resource (NAIRR)</Name><Description/></Stakeholder><OtherInformation>First, Microsoft will support the establishment of the
newly proposed National AI Research Resource (NAIRR)
to provide computing resources for academic research
and would welcome and support an extension to
accommodate access by academic institutions in allied
nations abroad, including Japan, the United Kingdom,
the European Union, and other like-minded countries.
^^
The National AI Research Resource has its origins in the
National Initiative AI Act of 2020, passed by Congress.
The Act called on the National Science Foundation, in
consultation with the White House Office of Science
and Technology Policy, to create a task force to create a
roadmap for “a shared research infrastructure that would
provide AI researchers and students with significantly
expanded access to computational resources, high-quality
data, educational tools, and user support.” This January,
the Task Force completed its work, publishing a final report
calling for the creation and funding of a federated mix
of computational and data resources, testbeds, software,
and testing tools, based on a platform that can reduce the
barriers to participation in the AI research ecosystem and
increase the diversity of AI researchers.
^^
Microsoft supports the establishment of the National AI
Research Resource and believes it to be of fundamental
importance to the United States’ leadership in AI
innovation and risk mitigation. We will collaborate with the
National Science Foundation to explore participation in a
pilot project to inform efforts to stand up the National AI
Research Resource, including by facilitating independent
academic research relating to the safety of AI systems.
^^
We also would welcome and support an extension of
the NAIRR to provide access by academic institutions in
like-minded nations. Already we’re seeing similar and
substantial interest in these other countries. For example,
Japan’s recent “National Strategy in the New Era of AI” calls
for work to expand the computing resources for public and private use. We believe that a multilateral AI research
resource would accelerate existing efforts to establish
global norms and interoperable approaches to risk
mitigation, including those underway in the U.S.-EU Trade
and Technology Council and the G7.</OtherInformation></Objective><Objective><Name>Investment</Name><Description>Increase investment in academic research programs</Description><Identifier>_f5b22606-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>4.5.2</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Academic Research Programs</Name><Description/></Stakeholder><OtherInformation>Second, we will increase investment in academic
research programs to ensure researchers outside
Microsoft can access the company's foundation models
and the Azure OpenAI Service to undertake research
and validate findings.
^^
This expanded commitment builds on the success of our
Turing Academic Program and Accelerating Foundation
Models Research Program. It is designed to help the
academic community gain API-based access to cuttingedge foundation models from Microsoft, as well as OpenAI
models via Microsoft’s Azure OpenAI Service. This will
ensure that researchers can study frontier applications and
the sociotechnical implications of these models. Microsoft
will ensure that its program design accommodates
API-based access by a diverse community of academic
researchers, including researchers at Minority Serving
Institutions across the United States.
^^
An important complement to providing such access is
the development of governance best practices for the
academic community engaged in frontier research on
applications and the safety and security implications of
highly capable models. Microsoft would welcome the
opportunity to develop such practices by supporting and
collaborating with a multistakeholder group, including
representatives across the academic community.</OtherInformation></Objective><Objective><Name>Nonfprofits</Name><Description>Create free and low-cost AI resources for use by the nonprofit community</Description><Identifier>_f5b228ea-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>4.5.3</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Nonprofit Community</Name><Description/></Stakeholder><OtherInformation>Third, Microsoft will create free and low-cost AI
resources for use by the nonprofit community.
^^
Finally, we deeply appreciate the critical role that nonprofit
organizations play in addressing societal needs around the
world. Given their role as great incubators of innovative
solutions, we believe it is critical for nonprofits to have
broad, easy, and inexpensive access to new AI models and
features for their work. Microsoft Philanthropies, including
its Tech for Social Responsibility arm, supports 350,000
nonprofits in the Microsoft Cloud. It provides more than
$4 billion annually in cash and technology donations and discounts to nonprofits worldwide, a figure comparable to
one of the 10 largest government foreign aid budgets.
^^
Last week we expanded this support by announcing
AI solutions to Microsoft Cloud for Nonprofit. These AI
solutions are designed to improve the ability of nonprofit
organizations to optimize operations, engage with donors,
and manage campaigns. This is the first of several steps we
will take to reduce technical and cost barriers and enable
nonprofits to harness the latest advances in AI.
</OtherInformation></Objective></Goal><Goal><Name>Partnerships</Name><Description>Pursue public-private partnerships to use AI as an effective tool to address the inevitable societal challenges that come with new technology</Description><Identifier>_f5b22b4c-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>5</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Public Sector</Name><Description>Finally, we believe there is enormous opportunity to bring
the public and private sectors together to use AI as a tool to
improve the world, including by countering the challenges
that technological change inevitably creates. We are cleareyed about the future and realize that some will seek to use
AI as a weapon rather than a tool. And even when people
of goodwill do their best, technological change inevitably
creates unforeseen bumps in the road ahead.</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Private Sector</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Democratic Societies</Name><Description>But we've also learned from numerous efforts over the
years what democratic societies can accomplish when they
harness the power of technology and bring the public and
private sectors together. Two examples are perhaps the
most profound.</Description></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Christchurch, New Zealand</Name><Description>The first is the Christchurch Call, born from the tragic
terrorist tragedy that took place in Christchurch, New
Zealand, on March 15, 2019. The attack claimed the lives of
51 innocent Muslims at two mosques and was livestreamed
worldwide. The internet provided a stage not only to
broadcast the attack but perhaps provided an incentive to
pursue the assault in the first place.</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Jacinda Ardern</Name><Description>New Zealand Prime Minister Jacinda Ardern vowed that
the world would learn from the attack and take steps
to prevent technology from being used this way again.</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Emmanuel Macron</Name><Description>Partnering with French President Emmanuel Macron,
she brought leading tech companies together to pursue
concrete steps to prevent the livestreaming and internet
distribution of similar violent attacks in the future. Exactly two months after the attack, on May 15, 2019, government
and tech leaders met at the Elysée in Paris to sign the
Christchurch Call and commited to collective action that
has continued in the four years that have followed.</Description></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Ukraine</Name><Description>This work provided inspiration for the larger assault that
began when the Russian military unleashed waves of
cyberattacks on Ukraine on February 23, 2022. As we noted
last year, this reflected an age-old lesson from history:
countries wage wars using the latest technology, and the
wars themselves accelerate technological change.
^^
But the role of technology in the war in Ukraine has
brought a new dimension to the defense not only of
Ukraine, but of democracy itself. The war has required a
new form of collective defense. It has pitted Russia, a major
cyberpower, not just against an alliance of countries, but
also against a coalition of tech companies and NGOs.</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Tech Sector</Name><Description>Across the tech sector, companies have stepped up to
support Ukraine's remarkable tenacity and innovation.
Individual and collective technology measures have
sustained Ukraine's digital operations, defeated
cyberattacks, documented war crimes, and enabled
students to stay in school even when their schools are
damaged or destroyed. Microsoft has now provided $450
million of financial and technology assistance to Ukraine,
an amount that is unprecedented in the company’s history.</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name/><Description>The lessons from the Christchurch Call and the war in
Ukraine should guide us on the role of AI in the future.
One key is to focus on specific problems that can benefit
from new initiatives and concrete action. Another is to
bring governments, companies, and NGOs together on an
international basis not only to move faster, but to accomplish
more than any single organization or even country can
achieve on its own. Microsoft is committed to pursuing and
supporting similar initiatives in the months ahead.</Description></Stakeholder><OtherInformation>Fifth, pursue new public-private partnerships to use AI
as an effective tool to address the inevitable societal
challenges that come with new technology. ~ One
lesson from recent years is what democratic societies can
accomplish when they harness the power of technology
and bring the public and private sectors together. It’s a
lesson we need to build upon to address the impact of AI
on society.
^^
We will all benefit from a strong dose of clear-eyed
optimism. AI is an extraordinary tool. But like other
technologies, it too can become a powerful weapon, and
there will be some around the world who will seek to use
it that way. But we should take some heart from the cyber
front and last year and a half in the war in Ukraine. What
we found is that when the public and private sectors work
together, when like-minded allies come together, and when
we develop technology and use it as a shield, it’s more
powerful than any sword on the planet.
^^
Important work is needed now to use AI to protect
democracy and fundamental rights, provide broad access
to the AI skills that will promote inclusive growth, and use
the power of AI to advance the planet’s sustainability needs.
Perhaps more than anything, a wave of new AI technology
provides an occasion for thinking big and acting boldly. In
each area, the key to success will be to develop concrete
initiatives and bring governments, respected companies, and energetic NGOs together to advance them. We offer
some initial ideas in this report, and we look forward to
doing much more in the months and years ahead. </OtherInformation><Objective><Name>Problems &amp; Actions</Name><Description>Focus on specific problems that can benefit from new initiatives and concrete action</Description><Identifier>_f5b22eee-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>5.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>The lessons from the Christchurch Call and the war in
Ukraine should guide us on the role of AI in the future.
One key is to focus on specific problems that can benefit
from new initiatives and concrete action.</OtherInformation></Objective><Objective><Name>International Collaboration</Name><Description>Bring governments, companies, and NGOs together on an international basis</Description><Identifier>_f5b231dc-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>5.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Another is to
bring governments, companies, and NGOs together on an
international basis not only to move faster, but to accomplish
more than any single organization or even country can
achieve on its own. Microsoft is committed to pursuing and
supporting similar initiatives in the months ahead.</OtherInformation></Objective><Objective><Name>Democracy &amp; Fakery</Name><Description>Address risks to democracy and the public from the potential weaponization of AI to alter content and create "deep fakes"</Description><Identifier>_f5b23452-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>5.3</SequenceIndicator><Stakeholder StakeholderTypeType="Organization"><Name>Coalition for Content Provenance and Authenticity</Name><Description>As we do so, it will be important to start with important
building blocks that exist already. One of the most
important is the Coalition for Content Provenance and
Authenticity, or C2PA. Co-founded by companies such
as Adobe, the BBC, Intel, Microsoft, Sony, and Truepic,
C2PA unifies the efforts of the Adobe-led Content
Authenticity Initiative (CAI), which focuses on systems to
provide context and history for digital media, and Project
Origin, a Microsoft- and BBC-led initiative that tackles
disinformation in the digital news ecosystem.</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Eric Horvitz</Name><Description>As Microsoft's Chief Scientific Officer, Eric Horvitz, said
last year, success will require "a multi-pronged approach,
including education aimed at media literacy, awareness,
and vigilance, [with] investments in quality journalism."
There will be opportunities in the coming months to take
important steps together.</Description></Stakeholder><OtherInformation>In recent years, there has been a growing focus on addressing
the new risks to democracy and the public from the potential
weaponization of AI to alter content and create "deep fakes,"
including videos. The concern about future technology is wellplaced (although we are concerned that countries are doing
too little to address foreign cyber influence operations that are
prolific and impactful already). In short, we will all need to do
more collectively to combat this type of threat.</OtherInformation></Objective><Objective><Name>Provenance</Name><Description>Deploy new state-of-the-art provenance tools to help the public identify AI-generated audio-visual content and understand its origin</Description><Identifier>_f5b237f4-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>5.3.1</SequenceIndicator><Stakeholder StakeholderTypeType="Person"><Name/><Description/></Stakeholder><OtherInformation>This week Microsoft will deploy new state-of-the-art
provenance tools to help the public identify AI-generated
audio-visual content and understand its origin. At Build,
our annual developer conference, we are announcing the
development of a new media provenance service. The
service will mark and sign AI-generated videos and images
with metadata about their origin, enabling users to verify
that a piece of content was generated by AI. The service
implements the C2PA specification. Microsoft will initially
support major image and video formats and release the
service for use with two of Microsoft’s new AI products,
Microsoft Designer and Bing Image Creator.
^^
This is an important step, but just a single one. Fortunately,
many others are moving forward with similar and critical
measures. We will need the right combination of focused
steps and broader initiatives.</OtherInformation></Objective><Objective><Name>Activity &amp; Scope</Name><Description>Think big and act boldly</Description><Identifier>_f5b23ace-fcad-11ed-b89a-14061883ea00</Identifier><SequenceIndicator>5.3.2</SequenceIndicator><Stakeholder StakeholderTypeType="Person"><Name/><Description/></Stakeholder><OtherInformation>Perhaps more than anything, a wave of new AI technology
provides an occasion for thinking big and acting boldly.
Important work is needed to use AI to protect democracy
and fundamental rights, provide broad access to the AI
skills that will promote inclusive growth, and use the power
of AI to advance the planet’s sustainability needs. In each
area, the key to success will be to bring governments,
respected companies, and energetic NGOs together.
There will be no shortage of opportunities or challenges.
We need to seize the moment.</OtherInformation></Objective></Goal></StrategicPlanCore><AdministrativeInformation><StartDate/><EndDate/><PublicationDate>2023-05-27</PublicationDate><Source>https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RW14Gtw</Source><Submitter><GivenName>Owen</GivenName><Surname>Ambur</Surname><PhoneNumber/><EmailAddress>Owen.Ambur@verizon.net</EmailAddress></Submitter></AdministrativeInformation></PerformancePlanOrReport>