Prince George's County - Procurement Preference Programs - Regulation PG 404-26
HB0376 revises the Maryland Cybersecurity Council by changing how its members are selected, who chairs the Council, and which organizations and experts are represented. The bill shifts appointment and chair-selection authority away from the Attorney General and to the Governor and the Council itself, and it expands the Council to include additional public, private, nonprofit, and academic stakeholders. It also adds specific representation from entities such as the Maryland Chamber of Commerce, the Cybersecurity Association of Maryland, financial institutions, hospitals, water and electric utilities, privacy organizations, and technology governance groups.
The bill also broadens the Council’s charge. In addition to its existing cybersecurity planning and coordination duties, the Council must now work with the National Institute of Standards and Technology, federal agencies, private businesses, nonprofits, and cybersecurity experts to assess and address cybersecurity threats and associated risks from artificial intelligence and quantum computing. It must also address privacy concerns of Maryland residents and emerging AI-related threats such as adversarial AI, cyberattacks, deepfakes, unethical use, and fraud. The Council is directed to continue recommending legislative changes and to review its subcommittee structure and bylaws by December 1, 2025.
The bill amends Section 9-2901 of the State Government Article, altering the composition, selection process, and leadership structure of the Maryland Cybersecurity Council. It adds and reclassifies several membership categories, changes the appointing authority for certain members, and requires periodic election of a chair and vice chair from among Council members. It also expands the Council’s statutory responsibilities to include AI and quantum computing risk assessment, privacy issues, and coordination with NIST and other partners, thereby updating Maryland’s cybersecurity policy framework to reflect newer technological threats.
The overall sentiment reflected in the bill text is strongly supportive of expanding and modernizing the Council’s expertise and mission. The legislation appears designed to bring in a broader mix of government, industry, academic, and public-interest voices, suggesting a consensus-oriented approach to cybersecurity governance. No committee transcripts or recorded votes were provided, and the bill history indicates it was withdrawn by the sponsor in the House, so there is no documented floor or committee opposition in the supplied materials.
The main points of potential contention are structural rather than ideological: the bill redistributes control over Council membership and leadership from the Attorney General to the Governor and the Council, which could raise questions about executive authority and appointment influence. Another possible area of debate is the expanded inclusion of private-sector and advocacy organizations, which may prompt concerns about balance, representation, and the size or manageability of the Council. The addition of AI- and quantum-related duties also broadens the Council’s mandate, which could be viewed as necessary modernization by supporters but as an expansion of scope by skeptics.