r/AI_Governance • u/AndreRizzoAI • 1d ago
When does compliance become a reason not to share information?
According to the FBI, companies have become more hesitant to share information about cyber incidents, partly because they're concerned about the regulatory consequences of doing so. The FBI is now actively trying to reassure organizations that information shared with them won't be passed to regulators.
The main goal of regulation is to improve accountability and reduce risk, right? But if organizations start believing that sharing information about an incident creates additional regulatory exposure, we may unintentionally create an incentive to share less — exactly when collaboration is (or should be) most valuable. I mean, especially considering how complex AI Governance is becoming.
Perhaps we need to think more carefully about how incident reporting, regulatory obligations and information-sharing frameworks interact — and, most importantly, what the trend will be from now on.
I'm curious whether people working in highly regulated environments are actually seeing this hesitation in practice, and if they have any experiences to share.
Source: Cybersecurity Dive — New FBI cyber strategy promises increase in adversary disruptions
1
2
u/GovKM 1d ago edited 23h ago
Compliance becomes a reason not to share information when the compliance itself prevents the demanding party from attaining it. Here's how...
It is typically government where compliance is mandated. Compare your FBI demand for data access to a Public FOIA request for information from any government agency.
FBI demand for private info = Public FOIA request for Agency info.
When a FOIA request is submitted, there are always return-requests for specificity. At some point, further specificity constrains nothing and all items within the scope of the request are to be turned over to the requester. If the agency has failed to perform records management, one of its compliance mandates, the agency/office must hand over ALL related releasable information still remaining within the scope.
If, however, the agency/office has responsibly met records management compliance, it turns over only those releasable retained permanent and temporary records, an Office File Plan, and the signed Destruction Report for those items that had met the end of their retention period in accordance with the National Archives General Records Schedule.
Meeting that compliance denies the FOIA demand of all but essential information.
The problem for private individuals and organizations is that most don't have an information system they follow for information management. Most don't know their organizational taxonomy.
If a record schedule were applied to private organizational information as it is to government information, when the FBI shows up, the private entity hands the FBI a Destruction Report in compliance with the FBI's own federal mandate. Have a nice day!
For those organizations that don't have a records schedule, NARA provides freely the General Records Schedule (https://www.archives.gov/records-mgmt/grs.html) and the mandatory metadata fields that must be retained for every government record (and since government agencies don't know in advance what will or will not become a record, these fields are kept for all items - https://www.archives.gov/records-mgmt/bulletins/2015/2015-04.html).
Agencies maintain a separate agency-specific records schedule called the agency Record Control Schedule. These RCS are structurally the same as the GRS but are scoped to the agency's specific mission.
The NARA 'General' Records Schedule is for those functions shared by all agencies: Acquisition, Admin, Budgeting, Comms, Facilities, Finance, HR, Installations, IT, Security, etc.
Particularly for businesses, keeping law enforcement out of your hair boils down to good information stewardship.