Addressing emerging AI security requirements in new laws through AI model weights

Illinois' AI Safety Measures Act underscores the need for organizations to protect AI model weights with layered cybersecurity, governance and monitoring controls that go beyond traditional software security.

Contributors:
Lisa Nee
CIPP/E, CIPP/US, CIPM, CIPT, FIP
Director and Sr. Corporate Counsel
Magellan Health, Inc.
Gov. JB Pritzker, D-Ill., signed the Artificial Intelligence Safety Measures Act into law 6 July, making Illinois one of the first U.S. states to impose safety, transparency and cybersecurity obligations on large frontier AI developers.
Effective 1 Jan. 2027, the law requires covered developers to adopt cybersecurity safeguards against theft, tampering and unauthorized access for one of their most valuable assets: model weights.
The requirements build on a growing concern for privacy and AI governance professionals: once model weights are exposed or misused, organizations may face risks ranging from intellectual property loss, to privacy harms and regulatory remedies, including potential disgorgement obligations, such as those highlighted by the 2023 U.S. Federal Trade Commission settlement with Rite Aid.
With that backdrop, AI and cybersecurity can no longer be siloed subject matter areas. Professionals need to become familiar with each and how to work with both in order to develop an effective program around data use that complies with laws.
What are model weights and what do they do?
Model weights are the numerical parameters inside an AI's neural network that determine how data is processed. They perform two key functions that dictate whether an AI model will be successful.
First, they determine signal strength by controlling how much influence one piece of data has on the next step in a calculation so that if a specific weight has a high value, the model considers that corresponding feature or connection to be highly important.
Second, when an AI goes through training, it processes massive datasets and slowly adjusts its weights to minimize errors. The final weights represent all the patterns, rules and facts the AI has successfully memorized.
Contributors:
Lisa Nee
CIPP/E, CIPP/US, CIPM, CIPT, FIP
Director and Sr. Corporate Counsel
Magellan Health, Inc.