Federal · House Bill · 119th Congress
HB8516
American Leadership in AI Act (H.R. 8516, 119th Congress)

Status ● Introduced Effective N/A Passage Likelihood N/A

WHAT THIS BILL REGULATES · 3 REQUIREMENT TYPES

How Is This Bill Enforced

Enforcement Authority
Primarily a federal research, standards, and governance framework enforced through agency implementation (NIST, NSF, OMB, agency Chief AI Officers) with no general private compliance enforcer. Title V, Subtitle A creates a private right of action for nonconsensual intimate imagery and digital forgeries, enforced by the affected identifiable individual in federal district court. Title V, Subtitle C (AI Whistleblower Protection) is enforced by a covered individual filing a complaint with the Secretary of Labor, or bringing a federal district court action if the Secretary does not issue a final decision within 180 days; whistleblower claims follow the AIR21 (49 U.S.C. 42121(b)) procedures and burdens. Financial-crime provisions (Title V, Subtitle B) are enforced by federal criminal prosecution.
Private Right of Action
private right of action for nonconsensual intimate imagery and digital forgeries, enforced by the affected identifiable individual in federal district court.
Penalties
For nonconsensual intimate imagery / intimate digital forgery civil actions (Title V, Subtitle A): liquidated damages of $150,000, or $250,000 where the conduct related to actual or attempted sexual assault, stalking, or harassment; alternatively actual damages including disgorgement of defendant's attributable profits. Court may also award punitive damages, injunctive/equitable relief (deletion, destruction), and reasonable attorney fees and litigation costs. For AI whistleblower retaliation (Title V, Subtitle C): reinstatement, two times back pay with interest, compensatory damages including litigation costs, expert witness fees, and reasonable attorney fees. Financial-crime amendments (Title V, Subtitle B) raise criminal fines (e.g., up to $2,000,000) and imprisonment terms for AI-assisted mail, wire, and bank fraud, money laundering, and impersonation of federal officials.

What This Bill Requires

Verbatim statutory text on the left; plain-language analysis and a per-section checklist on the right. Numbered markers cross-link to the matching checklist row.

Statutory Text
Analysis & Obligations
Sec. 101 (15 U.S.C. 9401 note; NDAA FY2021 Title LIII, new Sec. 5304)
Center for AI Standards and Innovation

(a) DEFINITIONS.—Section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401; as enacted as part of division E of the William M. (Mac) Thornberry National Defense Authorization Act for Fiscal Year 2021; Public Law 116–283) is amended— (1) by redesignating paragraphs (4), (5), (6), (7), (8), (9), (10), and (11) as paragraphs (6), (8), (9), (10), (11), (12), (13), and (14), respectively; (2) by inserting after paragraph (3) the following new paragraphs: ''(4) ARTIFICIAL INTELLIGENCE RED TEAMINGArtificial intelligence red teamingThe term 'artificial intelligence red teaming' means a structured testing in a controlled environment simulating real-world conditions, using adversarial methods to find flaws and vulnerabilities in an artificial intelligence system and identify risks, flaws, and vulnerabilities of artificial intelligence systems, such as harmful outputs from such system, unforeseen or undesirable system behaviors, limitations, and potential risks associated with the misuse of such system.Sec. 101(a); Sec. 121 (15 U.S.C. 278h-1(h)).—The term 'artificial intelligence red teamingArtificial intelligence red teamingThe term 'artificial intelligence red teaming' means a structured testing in a controlled environment simulating real-world conditions, using adversarial methods to find flaws and vulnerabilities in an artificial intelligence system and identify risks, flaws, and vulnerabilities of artificial intelligence systems, such as harmful outputs from such system, unforeseen or undesirable system behaviors, limitations, and potential risks associated with the misuse of such system.Sec. 101(a); Sec. 121 (15 U.S.C. 278h-1(h))' means a structured testing in a controlled environment simulating real-world conditions, using adversarial methods to find flaws and vulnerabilities in an artificial intelligence systemArtificial intelligence systemThe term 'artificial intelligence system'— (A) means any data system, software, application, tool, or utility that operates in whole or in part using dynamic or static machine learning algorithms or other forms of artificial intelligence, whether— (i) the data system, software, application, tool, or utility is established primarily for the purpose of researching, developing, or implementing artificial intelligence technology; or (ii) artificial intelligence capability is integrated into another system or agency business process, operational activity, or technology system; and (B) does not include any common commercial product within which artificial intelligence is embedded, such as a word processor or map navigation system.Sec. 101(a); Sec. 311; Sec. 321(d) and identify risks, flaws, and vulnerabilities of artificial intelligence systemsArtificial intelligence systemThe term 'artificial intelligence system'— (A) means any data system, software, application, tool, or utility that operates in whole or in part using dynamic or static machine learning algorithms or other forms of artificial intelligence, whether— (i) the data system, software, application, tool, or utility is established primarily for the purpose of researching, developing, or implementing artificial intelligence technology; or (ii) artificial intelligence capability is integrated into another system or agency business process, operational activity, or technology system; and (B) does not include any common commercial product within which artificial intelligence is embedded, such as a word processor or map navigation system.Sec. 101(a); Sec. 311; Sec. 321(d), such as harmful outputs from such system, unforeseen or undesirable system behaviors, limitations, and potential risks associated with the misuse of such system. ''(5) ARTIFICIAL INTELLIGENCE SYSTEMArtificial intelligence systemThe term 'artificial intelligence system'— (A) means any data system, software, application, tool, or utility that operates in whole or in part using dynamic or static machine learning algorithms or other forms of artificial intelligence, whether— (i) the data system, software, application, tool, or utility is established primarily for the purpose of researching, developing, or implementing artificial intelligence technology; or (ii) artificial intelligence capability is integrated into another system or agency business process, operational activity, or technology system; and (B) does not include any common commercial product within which artificial intelligence is embedded, such as a word processor or map navigation system.Sec. 101(a); Sec. 311; Sec. 321(d).—The term 'artificial intelligence systemArtificial intelligence systemThe term 'artificial intelligence system'— (A) means any data system, software, application, tool, or utility that operates in whole or in part using dynamic or static machine learning algorithms or other forms of artificial intelligence, whether— (i) the data system, software, application, tool, or utility is established primarily for the purpose of researching, developing, or implementing artificial intelligence technology; or (ii) artificial intelligence capability is integrated into another system or agency business process, operational activity, or technology system; and (B) does not include any common commercial product within which artificial intelligence is embedded, such as a word processor or map navigation system.Sec. 101(a); Sec. 311; Sec. 321(d)'— ''(A) means any data system, software, application, tool, or utility that operates in whole or in part using dynamic or static machine learning algorithms or other forms of artificial intelligence, whether— ''(i) the data system, software, application, tool, or utility is established primarily for the purpose of researching, developing, or implementing artificial intelligence technology; or ''(ii) artificial intelligence capability is integrated into another system or agency business process, operational activity, or technology system; and ''(B) does not include any common commercial product within which artificial intelligence is embedded, such as a word processor or map navigation system.''; and (3) by inserting after paragraph (6), as so redesignated, the following new paragraph: ''(7) FEDERAL LABORATORY.—The term 'Federal laboratory' has the meaning given such term in section 4 of the Stevenson-Wydler Technology Innovation Act of 1980 (15 U.S.C. 3703).''.

(b) Sec. 5304(a)-(d) ''SEC. 5304. CENTER FOR AI STANDARDS AND INNOVATION. ''(a) ESTABLISHMENT.—''(1) IN GENERAL.—Subject to the availability of appropriations, the Director of the National Institute of Standards and Technology (in this section referred to as the 'Director') shall establish a center on artificial intelligence, to be known as the 'Center for AI Standards and Innovation' (in this section referred to as the 'Center'), to ensure continued United States leadership in research, development, and evaluation of the reliability, robustness, resilience, security, and safety of artificial intelligence systemsArtificial intelligence systemThe term 'artificial intelligence system'— (A) means any data system, software, application, tool, or utility that operates in whole or in part using dynamic or static machine learning algorithms or other forms of artificial intelligence, whether— (i) the data system, software, application, tool, or utility is established primarily for the purpose of researching, developing, or implementing artificial intelligence technology; or (ii) artificial intelligence capability is integrated into another system or agency business process, operational activity, or technology system; and (B) does not include any common commercial product within which artificial intelligence is embedded, such as a word processor or map navigation system.Sec. 101(a); Sec. 311; Sec. 321(d). [purposes, director, consultation, activities, requirements, and report provisions follow] ''(b) ESTABLISHMENT OF CONSORTIUM.— [consortium of academic, research, Federal laboratory, private industry, and civil society stakeholders] ''(c) SCIENTIFIC INTEGRITY.— [adherence to America COMPETES Act policies and anonymous reporting mechanisms] ''(d) SECURITY.— [carried out consistent with research security law].

(b) Sec. 5304(e)-(h) ''(e) LIMITATION.—Information shared by an entity with, or provided to, the Director for the purpose of the activities described in this section may not be used by any Federal, State, local, or Tribal department or agency to regulate the activity of such entity. ''(f) PROHIBITIONS.—Nothing in this section may be construed to— ''(1) provide the Director any enforcement authority that was not in effect on the day before the date of the enactment of this section; ''(2) confer any regulatory authority to any Federal, State, Tribal, or local department or agency; ''(3) require any private sector entity to share data, including proprietary information, with the Director, the Center, or the Consortium; or ''(4) modify any regulatory requirement to report or submit information to a Federal, State, Tribal or local department or agency. ''(g) SUNSET.—This section shall terminate on the date that is six years after the date of the enactment of this section. ''(h) AUTHORIZATION OF APPROPRIATIONS.—There is to be authorized to be appropriated to the Director $10,000,000 for fiscal year 2027 to carry out this section.''.

Section 101 amends the definitions in the National Artificial Intelligence Initiative Act to add artificial intelligence red teaming and a broad artificial intelligence system definition, and establishes a NIST Center for AI Standards and Innovation to advance measurement science, benchmarking, and voluntary technical standards for AI reliability, robustness, resilience, security, and safety.

The Center's work is voluntary and collaborative — it develops best practices, conducts evaluations, and supports international standards engagement. Critically, the section is loaded with anti-regulatory guardrails: it expressly confers no enforcement or regulatory authority, cannot require private entities to share data, and provides that information shared with the Director may not be used by any government to regulate the sharing entity. It sunsets six years after enactment. Product counsel should treat this as a standards-and-research provision that creates no private compliance obligation.

Secs. 111-113 (NIST support for AI standards)
NIST support for AI standards participation and meetings

Sec. 111 SEC. 111. DEFINITIONS. In this subtitle: (1) COVERED ARTIFICIAL INTELLIGENCE AND OTHER CRITICAL AND EMERGING TECHNOLOGIES.—The term ''covered artificial intelligence and other critical and emerging technologies'' means a subset of artificial intelligence and other critical and emerging technologies included in the list of such technologies identified and maintained by the National Science and Technology Council of the Office of Science and Technology Policy as the Director considers appropriate for purposes of this subtitle. (2) DIRECTOR.—The term ''Director'' means the Director of the National Institute of Standards and Technology.

Sec. 112 SEC. 112. UNITED STATES PARTICIPATION IN ORGANIZATIONS DEVELOPING STANDARDS AND SPECIFICATIONS FOR ARTIFICIAL INTELLIGENCE AND OTHER CRITICAL AND EMERGING TECHNOLOGIES. (a) BRIEFING REQUIRED.— [NIST briefing to Congress on standards opportunities, interagency consultation, elements, and a Federal agency notice requirement under which each head of a Federal agency shall transmit to the Director notice of the participation of their respective Federal agency in a standards activity relating to artificial intelligence and other critical and emerging technologies] (b) WEB PORTAL.— [NIST web portal to inform industry and agencies about international AI standards efforts].

Sec. 113 SEC. 113. PILOT PROGRAM TO SUPPORT STANDARDS MEETINGS FOR ARTIFICIAL INTELLIGENCE AND OTHER CRITICAL AND EMERGING TECHNOLOGIES IN THE UNITED STATES. [NIST pilot grant program to eligible entities hosting standards meetings, with eligibility, grants, considerations, guidance, congressional briefings, recommendations for permanent implementation, termination after 5 years, and authorization of appropriations].

These sections define covered artificial intelligence and other critical and emerging technologies and direct NIST to brief Congress on opportunities to support U.S. participation in AI standards bodies, to build a web portal informing industry and agencies about international standards efforts, and to run a pilot grant program supporting U.S.-hosted standards meetings. Federal agency heads must report their participation in AI standards activities to NIST through a mechanism NIST develops.

These are federal coordination and grant provisions. The only reporting-type duty falls on federal agency heads (Government), not on private AI developers or deployers, and no compliance obligation attaches to regulated private parties.

Sec. 121 (15 U.S.C. 278h-1(h))
NIST research on AI development best practices

(h)(1)-(4) ''(h) ASSESSMENT OF THE PRACTICES OF ARTIFICIAL INTELLIGENCE DEVELOPMENT.— ''(1) IN GENERAL.—The Director of the National Institute of Standards and Technology (in this subsection referred to as the 'Director') shall, subject to the availability of appropriations, develop, and periodically update, in collaboration with other public and private sector organizations, voluntary guidance for practices and guidelines relating to the development, release, and assessment of artificial intelligence systemsArtificial intelligence systemThe term 'artificial intelligence system'— (A) means any data system, software, application, tool, or utility that operates in whole or in part using dynamic or static machine learning algorithms or other forms of artificial intelligence, whether— (i) the data system, software, application, tool, or utility is established primarily for the purpose of researching, developing, or implementing artificial intelligence technology; or (ii) artificial intelligence capability is integrated into another system or agency business process, operational activity, or technology system; and (B) does not include any common commercial product within which artificial intelligence is embedded, such as a word processor or map navigation system.Sec. 101(a); Sec. 311; Sec. 321(d). [Guidelines shall define methods for developing reasonable risk tolerances; categorize and list practices and norms for communicating characteristics including robustness, resilience, security, safety, fairness, privacy, validation, reliability, accountability, and usability, including documentation of training and evaluation datasets, documentation of model information, evaluation benchmarks, metrics and methodologies, public reporting of capabilities and limitations, disclosure of security practices such as red teaming and third-party assessments, and release practices; and provide recommendations for utilizing each practice.] ''(2) IMPLEMENTATION.— [update the voluntary risk management framework; base guidance on international standards; not prescribe specific ICT products or services; collaborate with stakeholders.] ''(3) REPORT.— [brief House Science and Senate Commerce committees within 18 months.] ''(4) ARTIFICIAL INTELLIGENCE RED TEAMINGArtificial intelligence red teamingThe term 'artificial intelligence red teaming' means a structured testing in a controlled environment simulating real-world conditions, using adversarial methods to find flaws and vulnerabilities in an artificial intelligence system and identify risks, flaws, and vulnerabilities of artificial intelligence systems, such as harmful outputs from such system, unforeseen or undesirable system behaviors, limitations, and potential risks associated with the misuse of such system.Sec. 101(a); Sec. 121 (15 U.S.C. 278h-1(h)) DEFINED.—In this subsection, the term 'artificial intelligence red teamingArtificial intelligence red teamingThe term 'artificial intelligence red teaming' means a structured testing in a controlled environment simulating real-world conditions, using adversarial methods to find flaws and vulnerabilities in an artificial intelligence system and identify risks, flaws, and vulnerabilities of artificial intelligence systems, such as harmful outputs from such system, unforeseen or undesirable system behaviors, limitations, and potential risks associated with the misuse of such system.Sec. 101(a); Sec. 121 (15 U.S.C. 278h-1(h))' means a structured testing of adversarial efforts to find flaws and vulnerabilities in an artificial intelligence systemArtificial intelligence systemThe term 'artificial intelligence system'— (A) means any data system, software, application, tool, or utility that operates in whole or in part using dynamic or static machine learning algorithms or other forms of artificial intelligence, whether— (i) the data system, software, application, tool, or utility is established primarily for the purpose of researching, developing, or implementing artificial intelligence technology; or (ii) artificial intelligence capability is integrated into another system or agency business process, operational activity, or technology system; and (B) does not include any common commercial product within which artificial intelligence is embedded, such as a word processor or map navigation system.Sec. 101(a); Sec. 311; Sec. 321(d) and identify risks, flaws, and vulnerabilities of artificial intelligence systemsArtificial intelligence systemThe term 'artificial intelligence system'— (A) means any data system, software, application, tool, or utility that operates in whole or in part using dynamic or static machine learning algorithms or other forms of artificial intelligence, whether— (i) the data system, software, application, tool, or utility is established primarily for the purpose of researching, developing, or implementing artificial intelligence technology; or (ii) artificial intelligence capability is integrated into another system or agency business process, operational activity, or technology system; and (B) does not include any common commercial product within which artificial intelligence is embedded, such as a word processor or map navigation system.Sec. 101(a); Sec. 311; Sec. 321(d), such as harmful outputs from such system, unforeseen or undesirable system behaviors, limitations, and potential risks associated with the misuse of such system.''.

Section 121 adds a new subsection to the NIST Act directing the Director to develop and periodically update voluntary guidance for practices and guidelines relating to the development, release, and assessment of AI systems. The guidance is to define methods for developing reasonable risk tolerances across use cases; catalog practices and norms for communicating characteristics such as robustness, security, safety, fairness, privacy, and reliability; and cover documentation of training and evaluation datasets, model information, evaluation benchmarks, public reporting of capabilities and limitations, disclosure of security practices including red teaming and third-party assessments, and release practices.

The guidance is expressly voluntary and technology-neutral, must not prescribe specific products, and must build on international standards where practical. Because this creates a NIST work product rather than a binding duty on developers, it is retained here for context but carries no compliance obligation.

Secs. 201-211 (National Artificial Intelligence Research Resource)
National AI Research Resource (NAIRR) and pilot program

Sec. 201 / Sec. 5601-5605 SEC. 201. NATIONAL ARTIFICIAL INTELLIGENCE RESEARCH RESOURCE. [Establishes NAIRR Steering Subcommittee within the Interagency Committee; adds new Title LVI to the National Artificial Intelligence Initiative Act with definitions (Sec. 5601), establishment and governance including a Program Management Office and Advisory Committees (Sec. 5602), resources of the NAIRR including computational resources, data, educational tools, and AI testbeds (Sec. 5603), NAIRR processes and procedures including user eligibility, excluded foreign-country individuals, privacy/ethics/civil rights/safety/trustworthiness review, scientific integrity guidance, system security and user access controls, a fee schedule, and research security (Sec. 5604), and NAIRR funding (Sec. 5605).]

Sec. 211 SEC. 211. NATIONAL ARTIFICIAL INTELLIGENCE RESEARCH RESOURCE PILOT PROGRAM. (a) PARTNERSHIPS.—As part of the National Artificial Intelligence Research Resource pilot program, the Director of the National Science Foundation shall partner with leading technology companies to increase access to world-class private sector computing, models, data, and software resources in the research community. (b) CONNECTION.—The Director shall ensure the Program is operationally capable of connecting researchers and educators in the United States to critical AI resources.

These sections establish the National Artificial Intelligence Research Resource (NAIRR) — a shared federal research infrastructure providing computational resources, data, educational tools, and AI testbeds to eligible U.S. researchers, educators, and institutions. Governance runs through an NSF Program Management Office, a NAIRR Steering Subcommittee, an Operating Entity, and Advisory Committees. The provisions establish user eligibility (including foreign-country exclusions), privacy/ethics/civil-rights review processes, scientific integrity guidance, minimum security requirements, a fee schedule, and research security conformance.

All duties run to federal officials and the Operating Entity. There are no obligations on private AI developers or deployers; the privacy, security, and integrity provisions govern access to and use of a government research facility, not commercial AI products.

Secs. 221-251 (research programs, prize competitions, DOE AI program)
AI research grant, prize, and coordination programs

Sec. 221 SEC. 221. PRIZE COMPETITIONS FOR ARTIFICIAL INTELLIGENCE RESEARCH AND DEVELOPMENT. [NSF AI Grand Challenges Program awarding prizes across enumerated categories, including a required grand challenge for AI-enabled cancer breakthroughs, with eligibility, judging, prize amounts, funding, reports, and accessibility provisions.]

Sec. 231 SEC. 231. GRANTS TO PERFORM RESEARCH REGARDING THE USE OF GENERATIVE ARTIFICIAL INTELLIGENCEGenerative artificial intelligenceThe term 'generative artificial intelligence' means artificial intelligence that, in response to a prompt, uses data to produce text, media, computer code, or other content.Sec. 231(d)(3) IN HEALTH CARE. (a) IN GENERAL.—The Director of the National Institutes of Health shall establish a grant program to award grants to eligible entities to perform research regarding the use of generative artificial intelligenceGenerative artificial intelligenceThe term 'generative artificial intelligence' means artificial intelligence that, in response to a prompt, uses data to produce text, media, computer code, or other content.Sec. 231(d)(3) in health care. [permissible research, priority, and definitions follow].

Sec. 241 SEC. 241. DEPARTMENT OF AGRICULTURE AND NATIONAL SCIENCE FOUNDATION RESEARCH AND DEVELOPMENT COORDINATION. [USDA/NSF cross-cutting collaborative research and development activities, memoranda of understanding, coordination focus areas, agreements, report, research security, and definitions.]

Sec. 251 / Sec. 5501-5502 SEC. 251. DEPARTMENT OF ENERGY ARTIFICIAL INTELLIGENCE RESEARCH PROGRAM. [Amends Title LV of the National Artificial Intelligence Initiative Act to establish a DOE cross-cutting AI research and development program covering research areas, technology transfer, facility use and upgrades, testbeds, dataset aggregation/curation/distribution, development of advanced AI systems for scientific/energy/national security applications, shared resources, AI research institutes, energy permitting research, risk management and safety/security taxonomy, STEM education and workforce development, data privacy and sharing, partnerships, stakeholder engagement, a strategic plan, definitions, and authorization of appropriations; plus Sec. 5502 report on energy security for data centers.]

These sections create federal AI research and funding programs: NSF prize competitions (the AI Grand Challenges Program, including a cancer-breakthrough challenge), NIH grants for research on generative AI in health care, USDA/NSF research coordination, and a broad Department of Energy AI research program covering advanced computing, trustworthy AI development, testbeds, dataset curation, workforce development, risk management, and a strategic plan.

Every duty here runs to a federal Secretary or Director administering a research or grant program. None imposes a compliance obligation on private AI developers or deployers, so no obligations are mapped. They are retained for context because they define the federal AI research landscape the bill builds.

Sec. 301 (NDAA FY2021 Title LIII, new Sec. 5305)
Federal standards for artificial intelligence
Government

(a) Sec. 5305(a) 1 ''SEC. 5305. FEDERAL STANDARDS FOR ARTIFICIAL INTELLIGENCE. ''(a) IN GENERAL.—The Director of the National Institute of Standards and Technology (in this section referred to as the 'Director') shall— ''(1) develop standards and guidelines, including minimum requirements, for artificial intelligence systemsArtificial intelligence systemThe term 'artificial intelligence system'— (A) means any data system, software, application, tool, or utility that operates in whole or in part using dynamic or static machine learning algorithms or other forms of artificial intelligence, whether— (i) the data system, software, application, tool, or utility is established primarily for the purpose of researching, developing, or implementing artificial intelligence technology; or (ii) artificial intelligence capability is integrated into another system or agency business process, operational activity, or technology system; and (B) does not include any common commercial product within which artificial intelligence is embedded, such as a word processor or map navigation system.Sec. 101(a); Sec. 311; Sec. 321(d) used or operated by an agency or by a contractor of an agency or other organization on behalf of an agency, other than national security systemsNational security systemThe term 'national security system' has the meaning given such term in section 3552 of title 44, United States Code.Sec. 301 (5 U.S.C. 5305(e)(2)); ''(2) develop standards and guidelines, including minimum requirements, for managing risks associated with artificial intelligence systemsArtificial intelligence systemThe term 'artificial intelligence system'— (A) means any data system, software, application, tool, or utility that operates in whole or in part using dynamic or static machine learning algorithms or other forms of artificial intelligence, whether— (i) the data system, software, application, tool, or utility is established primarily for the purpose of researching, developing, or implementing artificial intelligence technology; or (ii) artificial intelligence capability is integrated into another system or agency business process, operational activity, or technology system; and (B) does not include any common commercial product within which artificial intelligence is embedded, such as a word processor or map navigation system.Sec. 101(a); Sec. 311; Sec. 321(d) for all agency operations and assets, but such standards and guidelines shall not apply to national security systemsNational security systemThe term 'national security system' has the meaning given such term in section 3552 of title 44, United States Code.Sec. 301 (5 U.S.C. 5305(e)(2)); ''(3) develop standards and guidelines, including minimum requirements, for authenticating, tracking provenance, and labeling synthetic contentSynthetic contentThe term 'synthetic content' means information, such as images, videos, audio clips, and text, that has been significantly modified or generated by algorithms, including by artificial intelligence.Sec. 301 (5 U.S.C. 5305(e)(4)) generated by an agency or by a contractor of an agency or other organization on behalf of an agency, other than national security systemsNational security systemThe term 'national security system' has the meaning given such term in section 3552 of title 44, United States Code.Sec. 301 (5 U.S.C. 5305(e)(2)); and ''(4) conduct research and development pursuant to section 5301 to inform the development of standards and guidelines for activities described in this section.

(a) Sec. 5305(b)-(c) 1 ''(b) STANDARDS AND GUIDELINES.—In developing standards and guidelines required by subsection (a), the Director shall— [provide standards consistent with the NIST AI risk management framework; consistent with OMB Circular A-119 and enabling conformity assessment; recommend training; develop performance indicators; develop profilesProfileThe term 'profile' means an implementation of the artificial intelligence risk management functions, categories, and subcategories for a specific setting or application based on the requirements, risk tolerance, and resources of the user of the framework at issue.Sec. 301 (5 U.S.C. 5305(e)(3)) including for small business concerns; evaluate national security systemNational security systemThe term 'national security system' has the meaning given such term in section 3552 of title 44, United States Code.Sec. 301 (5 U.S.C. 5305(e)(2)) policies; and periodically assess effectiveness]. ''(c) READINESS.—For standards and guidelines developed pursuant to subsection (a) that are deemed by the Director to be at a readiness level sufficient for standardization, the Director shall— ''(1) submit such standards and guidelines to the Secretary of Commerce for promulgation under section 11331 of title 40, United States Code; ''(2) where practicable and appropriate, provide technical review and assistance to agencies; and ''(3) evaluate the effectiveness and sufficiency of, and challenges to, agency implementation of such standards and guidelines.

(a) Sec. 5305(d)-(e) 1 ''(d) TESTING AND EVALUATION OF ARTIFICIAL INTELLIGENCE ACQUISITIONS.— ''(1) STUDY.—Subject to the availability of appropriations, the Director shall complete a study to review the existing and forthcoming voluntary technical standards for the testing, evaluation, verification, and validation of artificial intelligence acquisitions. ''(2) TESTING AND EVALUATION STANDARDS.—Not later than 90 days after the date of the completion of the study required by paragraph (1), the Director shall— ''(A) develop standards and guidelines for the testing, evaluation, verification, and validation of artificial intelligence acquisitions pursuant to this section; ''(B) convene relevant stakeholders to facilitate such development; ''(C) continuously update such standards and guidelines; and ''(D) review and make recommendations to the head of each agency on risk management policies and principles for relevant artificial intelligence acquisitions. ''(e) DEFINITIONS.— [agency, national security systemNational security systemThe term 'national security system' has the meaning given such term in section 3552 of title 44, United States Code.Sec. 301 (5 U.S.C. 5305(e)(2)), profileProfileThe term 'profile' means an implementation of the artificial intelligence risk management functions, categories, and subcategories for a specific setting or application based on the requirements, risk tolerance, and resources of the user of the framework at issue.Sec. 301 (5 U.S.C. 5305(e)(3)), synthetic contentSynthetic contentThe term 'synthetic content' means information, such as images, videos, audio clips, and text, that has been significantly modified or generated by algorithms, including by artificial intelligence.Sec. 301 (5 U.S.C. 5305(e)(4))].

Section 301 directs the NIST Director to develop standards and guidelines, including minimum requirements, for AI systems used or operated by federal agencies (or contractors acting on their behalf), for managing AI risks in agency operations, and for authenticating, tracking provenance, and labeling synthetic content generated by or for federal agencies — in each case excluding national security systems. The section also directs a study and standards for testing, evaluation, verification, and validation of AI acquisitions.

These standards govern federal agency use and procurement of AI, and where ready for standardization are submitted to the Secretary of Commerce for promulgation under 40 U.S.C. 11331 (FISMA-style binding federal standards). The obligation here is a NIST standards-development duty in the federal-procurement context; the eventual binding effect falls on agencies, not private commercial developers.

Compliance actions 1 item
1
NIST must develop standards, guidelines, and minimum requirements for federal agency use, risk management, and procurement of AI systems (excluding national security systemsNational security systemThe term 'national security system' has the meaning given such term in section 3552 of title 44, United States Code.Sec. 301 (5 U.S.C. 5305(e)(2))), including standards for authenticating, tracking provenance, and labeling agency-generated synthetic contentSynthetic contentThe term 'synthetic content' means information, such as images, videos, audio clips, and text, that has been significantly modified or generated by algorithms, including by artificial intelligence.Sec. 301 (5 U.S.C. 5305(e)(4)), and standards for testing, evaluation, verification, and validation of AI acquisitions.
PS-01.4
Secs. 311-317 (AI Leadership to Enable Accountable Deployment)
Federal AI governance: CAIO Council and agency AI officers

Sec. 311 SEC. 311. DEFINITIONS. In this subtitle: (1) AGENCY.—[44 U.S.C. 3502]. (2) ARTIFICIAL INTELLIGENCE.—[15 U.S.C. 9401]. (3) ARTIFICIAL INTELLIGENCE SYSTEMArtificial intelligence systemThe term 'artificial intelligence system'— (A) means any data system, software, application, tool, or utility that operates in whole or in part using dynamic or static machine learning algorithms or other forms of artificial intelligence, whether— (i) the data system, software, application, tool, or utility is established primarily for the purpose of researching, developing, or implementing artificial intelligence technology; or (ii) artificial intelligence capability is integrated into another system or agency business process, operational activity, or technology system; and (B) does not include any common commercial product within which artificial intelligence is embedded, such as a word processor or map navigation system.Sec. 101(a); Sec. 311; Sec. 321(d).—[broad definition excluding common commercial products]. (4) CHIEF ARTIFICIAL INTELLIGENCE OFFICERChief Artificial Intelligence OfficerThe term 'Chief Artificial Intelligence Officer' means an official designated by the head of an agency pursuant to section 313(b)(1).Sec. 311(4).—[official designated under section 313(b)(1)]. (5) COUNCIL.—[Chief Artificial Intelligence OfficersChief Artificial Intelligence OfficerThe term 'Chief Artificial Intelligence Officer' means an official designated by the head of an agency pursuant to section 313(b)(1).Sec. 311(4) Council under section 312(a)]. (6) DIRECTOR.—[Director of OMB]. (7) RELEVANT CONGRESSIONAL COMMITTEES.—[Senate HSGAC and House Oversight].

Sec. 312 SEC. 312. CHIEF ARTIFICIAL INTELLIGENCE OFFICERSChief Artificial Intelligence OfficerThe term 'Chief Artificial Intelligence Officer' means an official designated by the head of an agency pursuant to section 313(b)(1).Sec. 311(4) COUNCIL. (a) ESTABLISHMENT.—Not later than 90 days after the date of the enactment of this Act, the Director shall establish a Chief Artificial Intelligence OfficersChief Artificial Intelligence OfficerThe term 'Chief Artificial Intelligence Officer' means an official designated by the head of an agency pursuant to section 313(b)(1).Sec. 311(4) Council. (b) DUTIES.— [promote AI innovation and responsible design; oversee compliance with Governmentwide requirements including AI use-case inventory and publication; develop best practices; assess workforce needs; track costs and benefits; review deployed federal AI systems for potential harm; ensure federal AI is responsibly developed and evaluated; and ensure accountability for AI systems producing flawed, inaccurate, or biased decisions affecting individuals]. (c) MEMBERSHIP.— [chair, cochair, members]. (d) ADMINISTRATIVE SUPPORT.—[GSA].

Sec. 313 SEC. 313. AGENCY ARTIFICIAL INTELLIGENCE OFFICERS. (a) DUTIES OF AGENCIES.—The head of each agency shall ensure the responsible research, development, acquisition, application, governance, and use of artificial intelligence by the agency that is consistent with democratic values, including privacy; civil rights and civil liberties; information security; nondiscrimination; transparency; and trustworthiness. (b) CHIEF ARTIFICIAL INTELLIGENCE OFFICERChief Artificial Intelligence OfficerThe term 'Chief Artificial Intelligence Officer' means an official designated by the head of an agency pursuant to section 313(b)(1).Sec. 311(4).— [designation within 45 days; responsibilities including a risk management plan, inventorying and publishing agency use cases, ensuring compliance and responsible development, monitoring capabilities, and ensuring accountability; structure, seniority, roles, full-time-employee requirement]. (c) INFORMING CONGRESS.— [notify committees].

Sec. 314 SEC. 314. AGENCY COORDINATION ON ARTIFICIAL INTELLIGENCE. (a) ESTABLISHMENT.—Not later than 120 days after the date of the enactment of this Act, the Director shall issue guidance directing the head of each agency described in section 901(b) of title 31, United States Code, to establish within the agency an Artificial Intelligence Coordination Board [to coordinate AI issues and publish a statement of principles and goals]. (b) CONTENTS.— [structure and membership]. (c) STRATEGY.— [each agency head shall establish an AI strategy for responsible and trustworthy adoption, with enumerated contents including risk mitigation, values/ethics, safeguards, and workforce].

Secs. 315-317 SEC. 315. GAO REPORTS. [GAO reports on implementation and effectiveness of Coordination Boards and Chief AI Officers, cost-benefit analysis, jobs at risk, an inventory of agency AI use cases, and a report on biased datasets.] SEC. 316. POST-ENACTMENT GUIDANCE FROM THE DIRECTOR. [Within five years, the Director shall consider developments and issue a directive to agencies updating leadership roles and structures.] SEC. 317. SUNSET. Beginning on the date that is 90 days after the date of issuance of the directive under section 316, this subtitle shall have no force or effect.

This subtitle builds a federal AI governance apparatus. It establishes a Chief Artificial Intelligence Officers Council chaired by the OMB Director, directs each agency to designate a Chief Artificial Intelligence Officer responsible for AI innovation, risk management, inventorying and publishing agency AI use cases, and ensuring agency AI systems are responsibly developed and do not infringe rights, and requires each agency to establish an Artificial Intelligence Coordination Board and adopt an agency AI strategy. GAO reporting and a five-year OMB post-enactment guidance requirement round it out, with a sunset triggered 90 days after that guidance issues.

All duties run to federal agencies, agency heads, the OMB Director, and GAO (Government roles). These are internal federal governance obligations, not compliance duties on private AI developers or deployers, so no obligations are mapped to the taxonomy.

Sec. 321 (AI Incident Reporting and Security Enhancement)
Voluntary AI vulnerability and incident tracking

(a) UPDATE TO NATIONAL VULNERABILITY DATABASE.—The Director of the National Institute of Standards and Technology, in coordination with industry stakeholders, standards development organizations, and appropriate Federal agencies, as appropriate, shall carry out the following: (1) Establish or identify common definitions and any characteristics of artificial intelligence security vulnerabilities that make utilization of the National Vulnerability Database inappropriate for the management of such vulnerabilities, and develop processes and procedures for vulnerability management of such vulnerabilities. (2) Support the development of standards and guidance for technical vulnerability management processes related to artificial intelligence. (3) Consistent with paragraphs (1) and (2), as appropriate, initiate a process to update the Institute's processes and procedures associated with the National Vulnerability Database to ensure such Database and associated vulnerability management processes incorporate artificial intelligence security vulnerabilities to the greatest extent practicable.

(b) ASSESSING VOLUNTARY TRACKING OF SUBSTANTIAL ARTIFICIAL INTELLIGENCE SECURITY AND SAFETY INCIDENTS.— (1) IN GENERAL.—The Director of the National Institute of Standards and Technology, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, shall convene a multi-stakeholder process to consider the development of a process relating to the voluntary collection, reporting, and tracking of substantial artificial intelligence security incidentsand substantial artificial intelligence safety incidents. (2) ACTIVITIES.— [establish common definitions and taxonomies distinguishing AI security incidents from AI safety incidents; assess usefulness and cost-effectiveness; identify guidelines, best practices, and processes for tracking and reporting; support standardized reporting and documentation mechanisms; and support norms for reporting]. (3) REPORT.— [report to Congress within three years].

(c)-(d) LIMITATION.—Nothing in this section provides the Director of the National Institute of Standards and Technology with any enforcement authority that was not in effect on the day before the date of the enactment of this section. (d) DEFINITIONS.— [artificial intelligence; artificial intelligence security vulnerability; artificial intelligence systemArtificial intelligence systemThe term 'artificial intelligence system'— (A) means any data system, software, application, tool, or utility that operates in whole or in part using dynamic or static machine learning algorithms or other forms of artificial intelligence, whether— (i) the data system, software, application, tool, or utility is established primarily for the purpose of researching, developing, or implementing artificial intelligence technology; or (ii) artificial intelligence capability is integrated into another system or agency business process, operational activity, or technology system; and (B) does not include any common commercial product within which artificial intelligence is embedded, such as a word processor or map navigation system.Sec. 101(a); Sec. 311; Sec. 321(d); nonprofit organization; Sector Risk Management Agency; threat source].

Section 321 directs NIST to update the National Vulnerability Database processes to accommodate AI security vulnerabilities and to convene a multi-stakeholder process to consider a voluntary process for collecting, reporting, and tracking substantial AI security incidents and AI safety incidents. NIST is to establish common definitions and taxonomies distinguishing security incidents from safety incidents, assess cost-effectiveness, and develop guidelines, reporting mechanisms, and norms — then report findings to Congress.

The section is explicitly voluntary and expressly grants NIST no enforcement authority it did not already have. It is study-and-convene work, not a mandatory incident-reporting regime imposed on deployers, so no obligation is mapped. Contrast this with taxonomy R-01, which contemplates mandatory incident reporting.

Secs. 401-411 (workers and small businesses)
AI Workforce Research Hub and small business AI resources

Sec. 401 SEC. 401. AI WORKFORCE RESEARCH HUB. (a) IN GENERAL.—There is established in the Department of Labor the AI Workforce Research Hub. (b) DUTIES.—The Secretary of Labor, acting through the Hub and in collaboration with the Commissioner of the Bureau of Labor Statistics, the Director of the U.S. Census Bureau, and the Director of the Bureau of Economic Analysis, shall carry out the following: (1) Evaluate the impact of AI on the labor market and the experience of United States workers. (2) Produce recurring evaluations of such impact. (3) Conduct scenario planning for a range of potential levels of such impact. (4) Identify insights to inform workforce and education policy with respect to such impact. (c) AI DEFINED.—[15 U.S.C. 9401].

Sec. 411 (15 U.S.C. 278h-1(h)) SEC. 411. RESOURCES FOR SMALL BUSINESSES TO UTILIZE ARTIFICIAL INTELLIGENCE. [Adds NIST Act subsection directing the Director to develop or identify and disseminate voluntary resources for small business concerns relating to AI, with requirements, review and update every two years, dissemination through SBA resource partners, a voluntary-use provision, and a report.]

Title IV establishes an AI Workforce Research Hub in the Department of Labor to evaluate AI's impact on the labor market and inform workforce and education policy, and directs NIST to develop, disseminate, and periodically update voluntary AI adoption resources for small business concerns, coordinated with the Small Business Administration.

Both duties run to federal agencies (DOL and NIST). The small business resources are expressly voluntary in use. Neither provision imposes a compliance obligation on private AI developers or deployers, so no obligations are mapped.

15 U.S.C. 6851 (as amended by Sec. 501)
Civil action for nonconsensual intimate images and intimate digital forgeries
DeployerDeveloperPublisher

(a) 2 DEFINITIONS.—Section 1309 of the Consolidated Appropriations Act, 2022 (15 U.S.C. 6851) is amended— (1) in the section heading, by inserting ''OR NONCONSENSUAL ACTIVITY INVOLVING DIGITAL FORGERIES'' after ''INTIMATE IMAGES''; and (2) in subsection (a)— [adds definitions of 'identifiable individualIdentifiable individualThe term 'identifiable individual' means an individual whose body appears in whole or in part in an intimate visual depiction or intimate digital forgery and who is identifiable by virtue of the individual's face, likeness, or other distinguishing characteristic, such as a unique birthmark or other recognizable feature, or from information displayed in connection with the intimate visual depiction or intimate digital forgery.Sec. 501(a) (15 U.S.C. 6851(a)(4))' and 'intimate digital forgeryIntimate digital forgery(A) IN GENERAL.—The term 'intimate digital forgery' means any intimate visual depiction of an identifiable individual that— (i) falsely represents, in whole or in part— (I) the identifiable individual; or (II) the conduct or content that makes the visual depiction intimate; (ii) is created through the use of software, machine learning, artificial intelligence, or any other computer-generated or technological means, including by adapting, modifying, manipulating, or altering an authentic visual depiction; and (iii) is indistinguishable from an authentic visual depiction of the identifiable individual when viewed as a whole by a reasonable person. (B) LABELS, DISCLOSURE, AND CONTEXT.—Any visual depiction described in subparagraph (A) constitutes an intimate digital forgery for purposes of this paragraph regardless of whether a label, information disclosed with the visual depiction, or the context or setting in which the visual depiction is disclosed states or implies that the visual depiction is not authentic.Sec. 501(a) (15 U.S.C. 6851(a)(5))', the latter meaning any intimate visual depiction of an identifiable individualIdentifiable individualThe term 'identifiable individual' means an individual whose body appears in whole or in part in an intimate visual depiction or intimate digital forgery and who is identifiable by virtue of the individual's face, likeness, or other distinguishing characteristic, such as a unique birthmark or other recognizable feature, or from information displayed in connection with the intimate visual depiction or intimate digital forgery.Sec. 501(a) (15 U.S.C. 6851(a)(4)) that falsely represents the individual or the intimate conduct/content, is created through software, machine learning, artificial intelligence, or other computer-generated or technological means, and is indistinguishable from an authentic depiction; and providing that a label, disclosure, or context stating the depiction is not authentic does not exempt it].

(b)(1) 2 CIVIL ACTION.—Section 1309(b) of the Consolidated Appropriations Act, 2022 (15 U.S.C. 6851(b)) is amended— (1) in paragraph (1)— [creating civil actions: (i) for disclosure of an identifiable individualIdentifiable individualThe term 'identifiable individual' means an individual whose body appears in whole or in part in an intimate visual depiction or intimate digital forgery and who is identifiable by virtue of the individual's face, likeness, or other distinguishing characteristic, such as a unique birthmark or other recognizable feature, or from information displayed in connection with the intimate visual depiction or intimate digital forgery.Sec. 501(a) (15 U.S.C. 6851(a)(4))'s intimate visual depiction without consent by a person who knows or recklessly disregards lack of consent; (ii) against any person that knowingly produced or possessed an intimate digital forgeryIntimate digital forgery(A) IN GENERAL.—The term 'intimate digital forgery' means any intimate visual depiction of an identifiable individual that— (i) falsely represents, in whole or in part— (I) the identifiable individual; or (II) the conduct or content that makes the visual depiction intimate; (ii) is created through the use of software, machine learning, artificial intelligence, or any other computer-generated or technological means, including by adapting, modifying, manipulating, or altering an authentic visual depiction; and (iii) is indistinguishable from an authentic visual depiction of the identifiable individual when viewed as a whole by a reasonable person. (B) LABELS, DISCLOSURE, AND CONTEXT.—Any visual depiction described in subparagraph (A) constitutes an intimate digital forgery for purposes of this paragraph regardless of whether a label, information disclosed with the visual depiction, or the context or setting in which the visual depiction is disclosed states or implies that the visual depiction is not authentic.Sec. 501(a) (15 U.S.C. 6851(a)(5)) with intent to disclose it, knowingly disclosed it, or knowingly solicited and received it, where the individual did not consent, the person knew or recklessly disregarded the lack of consent, and the conduct affects interstate or foreign commerce; and (iii) against any person that knowingly produced the intimate digital forgeryIntimate digital forgery(A) IN GENERAL.—The term 'intimate digital forgery' means any intimate visual depiction of an identifiable individual that— (i) falsely represents, in whole or in part— (I) the identifiable individual; or (II) the conduct or content that makes the visual depiction intimate; (ii) is created through the use of software, machine learning, artificial intelligence, or any other computer-generated or technological means, including by adapting, modifying, manipulating, or altering an authentic visual depiction; and (iii) is indistinguishable from an authentic visual depiction of the identifiable individual when viewed as a whole by a reasonable person. (B) LABELS, DISCLOSURE, AND CONTEXT.—Any visual depiction described in subparagraph (A) constitutes an intimate digital forgery for purposes of this paragraph regardless of whether a label, information disclosed with the visual depiction, or the context or setting in which the visual depiction is disclosed states or implies that the visual depiction is not authentic.Sec. 501(a) (15 U.S.C. 6851(a)(5)) where the individual did not consent, the person knew or recklessly disregarded the lack of consent and that the individual was harmed or reasonably likely to be harmed, and the production affects interstate or foreign commerce].

(b)(3)-(4) 2 [Relief: an identifiable individualIdentifiable individualThe term 'identifiable individual' means an individual whose body appears in whole or in part in an intimate visual depiction or intimate digital forgery and who is identifiable by virtue of the individual's face, likeness, or other distinguishing characteristic, such as a unique birthmark or other recognizable feature, or from information displayed in connection with the intimate visual depiction or intimate digital forgery.Sec. 501(a) (15 U.S.C. 6851(a)(4)) may recover damages and the cost of the action including reasonable attorney fees; the court may award punitive damages or equitable relief including temporary restraining orders, preliminary injunctions, or permanent injunctions ordering deletion, destruction, or cessation of display or disclosure. Damages: liquidated damages of $150,000, or $250,000 if the conduct was committed in relation to or was the direct and proximate cause of actual or attempted sexual assault, stalking, or harassment; or actual damages including disgorgement of the defendant's attributable profits. Preservation of privacy: pseudonym use, redaction, sealing, and protective orders.]

(b)(6)-(7) 2 ''(6) STATUTE OF LIMITATIONS.—Any action commenced under this section shall be barred unless the complaint is filed not later than 10 years from the later of— ''(A) the date on which the identifiable individualIdentifiable individualThe term 'identifiable individual' means an individual whose body appears in whole or in part in an intimate visual depiction or intimate digital forgery and who is identifiable by virtue of the individual's face, likeness, or other distinguishing characteristic, such as a unique birthmark or other recognizable feature, or from information displayed in connection with the intimate visual depiction or intimate digital forgery.Sec. 501(a) (15 U.S.C. 6851(a)(4)) reasonably discovers the violation that forms the basis for the claim; or ''(B) the date on which the identifiable individualIdentifiable individualThe term 'identifiable individual' means an individual whose body appears in whole or in part in an intimate visual depiction or intimate digital forgery and who is identifiable by virtue of the individual's face, likeness, or other distinguishing characteristic, such as a unique birthmark or other recognizable feature, or from information displayed in connection with the intimate visual depiction or intimate digital forgery.Sec. 501(a) (15 U.S.C. 6851(a)(4)) reaches 18 years of age. ''(7) DUPLICATIVE RECOVERY BARRED.—No relief may be ordered under paragraph (3) against a person who is subject to a judgment under section 2255 of title 18, United States Code, for the same conduct involving the same identifiable individualIdentifiable individualThe term 'identifiable individual' means an individual whose body appears in whole or in part in an intimate visual depiction or intimate digital forgery and who is identifiable by virtue of the individual's face, likeness, or other distinguishing characteristic, such as a unique birthmark or other recognizable feature, or from information displayed in connection with the intimate visual depiction or intimate digital forgery.Sec. 501(a) (15 U.S.C. 6851(a)(4)) and the same intimate visual depiction or intimate digital forgeryIntimate digital forgery(A) IN GENERAL.—The term 'intimate digital forgery' means any intimate visual depiction of an identifiable individual that— (i) falsely represents, in whole or in part— (I) the identifiable individual; or (II) the conduct or content that makes the visual depiction intimate; (ii) is created through the use of software, machine learning, artificial intelligence, or any other computer-generated or technological means, including by adapting, modifying, manipulating, or altering an authentic visual depiction; and (iii) is indistinguishable from an authentic visual depiction of the identifiable individual when viewed as a whole by a reasonable person. (B) LABELS, DISCLOSURE, AND CONTEXT.—Any visual depiction described in subparagraph (A) constitutes an intimate digital forgery for purposes of this paragraph regardless of whether a label, information disclosed with the visual depiction, or the context or setting in which the visual depiction is disclosed states or implies that the visual depiction is not authentic.Sec. 501(a) (15 U.S.C. 6851(a)(5)).''.

(c) CONTINUED APPLICABILITY OF FEDERAL, STATE, AND TRIBAL LAW.— (1) IN GENERAL.—This subtitle shall not be construed to impair, supersede, or limit a provision of Federal, State, or Tribal law. (2) NO PREEMPTION.—Nothing in this subtitle shall prohibit a State or Tribal government from adopting and enforcing a provision of law governing disclosure of intimate images or nonconsensual activity involving an intimate digital forgeryIntimate digital forgery(A) IN GENERAL.—The term 'intimate digital forgery' means any intimate visual depiction of an identifiable individual that— (i) falsely represents, in whole or in part— (I) the identifiable individual; or (II) the conduct or content that makes the visual depiction intimate; (ii) is created through the use of software, machine learning, artificial intelligence, or any other computer-generated or technological means, including by adapting, modifying, manipulating, or altering an authentic visual depiction; and (iii) is indistinguishable from an authentic visual depiction of the identifiable individual when viewed as a whole by a reasonable person. (B) LABELS, DISCLOSURE, AND CONTEXT.—Any visual depiction described in subparagraph (A) constitutes an intimate digital forgery for purposes of this paragraph regardless of whether a label, information disclosed with the visual depiction, or the context or setting in which the visual depiction is disclosed states or implies that the visual depiction is not authentic.Sec. 501(a) (15 U.S.C. 6851(a)(5)), as defined in section 1309(a) of the Consolidated Appropriations Act, 2022 (15 U.S.C. 6851(a)), as amended by this subtitle, that is at least as protective of the rights of a victim as this subtitle.

Section 501 substantially amends the federal civil cause of action for disclosure of intimate images (15 U.S.C. 6851) to reach AI-generated intimate digital forgeries — deepfake intimate imagery created with software, machine learning, or AI that is indistinguishable from an authentic depiction of an identifiable individual. Critically, a disclosure label or context stating that the image is not authentic does not exempt the content.

The amended statute creates distinct civil actions against anyone who knowingly produces, possesses with intent to disclose, discloses, or solicits and receives such forgeries. This is the bill's clearest private-facing prohibition: developers and operators of image/video generation tools, and anyone distributing such content, face liability. Remedies include liquidated damages of $150,000 (or $250,000 where tied to sexual assault, stalking, or harassment), actual damages with profit disgorgement, punitive damages, injunctive relief, and attorney fees, with a 10-year statute of limitations and privacy-protective procedures. The bill preserves more protective state and Tribal law.

Compliance actions 1 item
2
No person may knowingly produce, possess with intent to disclose, disclose, or solicit and receive AI-generated intimate imagery (an intimate digital forgeryIntimate digital forgery(A) IN GENERAL.—The term 'intimate digital forgery' means any intimate visual depiction of an identifiable individual that— (i) falsely represents, in whole or in part— (I) the identifiable individual; or (II) the conduct or content that makes the visual depiction intimate; (ii) is created through the use of software, machine learning, artificial intelligence, or any other computer-generated or technological means, including by adapting, modifying, manipulating, or altering an authentic visual depiction; and (iii) is indistinguishable from an authentic visual depiction of the identifiable individual when viewed as a whole by a reasonable person. (B) LABELS, DISCLOSURE, AND CONTEXT.—Any visual depiction described in subparagraph (A) constitutes an intimate digital forgery for purposes of this paragraph regardless of whether a label, information disclosed with the visual depiction, or the context or setting in which the visual depiction is disclosed states or implies that the visual depiction is not authentic.Sec. 501(a) (15 U.S.C. 6851(a)(5))) of a real, identifiable individualIdentifiable individualThe term 'identifiable individual' means an individual whose body appears in whole or in part in an intimate visual depiction or intimate digital forgery and who is identifiable by virtue of the individual's face, likeness, or other distinguishing characteristic, such as a unique birthmark or other recognizable feature, or from information displayed in connection with the intimate visual depiction or intimate digital forgery.Sec. 501(a) (15 U.S.C. 6851(a)(4)) without consent; developers and operators of image- or video-generation tools face civil liability for knowingly producing such content, and a disclosure label or context stating the content is not authentic provides no defense.
CP-02.1
Sec. 502
Severability; rule of construction

(a)-(b) SEC. 502. SEVERABILITY; RULE OF CONSTRUCTION. (a) SEVERABILITY.—If any provision of this subtitle, an amendment made by this subtitle, or the application of such a provision or amendment to any person or circumstance, is held to be unconstitutional, the remaining provisions of and amendments made by this subtitle, and the application of the provision or amendment held to be unconstitutional to any other person or circumstance, shall not be affected thereby. (b) RULE OF CONSTRUCTION.—Nothing in this subtitle, or an amendment made by this subtitle, shall be construed to limit or expand any law pertaining to intellectual property.

Section 502 provides that the deepfake subtitle is severable and that nothing in it limits or expands intellectual property law. These are boilerplate savings and severability clauses that create no compliance obligation; they are retained for completeness.

Secs. 511-512 (18 U.S.C. 1341, 1343, 1344, 1346, 1956, 912)
Enhanced criminal penalties for AI-assisted fraud and impersonation

Sec. 511 SEC. 511. FINANCIAL CRIMES AND ARTIFICIAL INTELLIGENCE. [Amends 18 U.S.C. 1341 (mail fraud), 1343 (wire fraud), and 1344 (bank fraud) to raise base fines and add elevated fine and imprisonment tiers where the violation is committed with the assistance of artificial intelligence; adds an artificial intelligence definition to 18 U.S.C. 1346; and amends 18 U.S.C. 1956 (money laundering) to add enhanced fines and imprisonment for AI-assisted violations and an AI definition.]

Sec. 512 SEC. 512. AI IMPERSONATION OF FEDERAL OFFICIALS. Section 912 of title 18, United States Code, is amended by inserting after ''or both'' the following: '', or, in the case that such violation is committed with the assistance of artificial intelligence (as such term is defined in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401)), shall be fined not more than $1,000,000, or imprisoned not more than three years, or both''.

Subtitle B raises federal criminal penalties where the underlying offense is committed with the assistance of artificial intelligence. It amends the mail fraud, wire fraud, and bank fraud statutes (18 U.S.C. 1341, 1343, 1344) to add elevated AI-assisted fine and imprisonment tiers, adds an AI definition to chapter 63 (18 U.S.C. 1346), enhances money-laundering penalties (18 U.S.C. 1956) for AI-assisted violations, and enhances penalties for impersonation of federal officials (18 U.S.C. 912) committed with AI assistance.

These are criminal sentencing enhancements enforced by federal prosecution, not affirmative compliance duties on developers or deployers. They are retained for context; no taxonomy obligation is mapped because the taxonomy addresses affirmative compliance obligations rather than criminal penalty enhancements.

Secs. 521-522 (AI Whistleblower Protection)
Anti-retaliation protection for AI whistleblowers
DeployerDeveloper

Sec. 521 SEC. 521. DEFINITIONS. In this subtitle: [defines AI security vulnerabilityAI security vulnerabilityThe term 'AI security vulnerability' means any failure or lapse in security that could potentially allow emerging artificial intelligence technology to be acquired by a person (including a foreign entity) by theft or other means.Sec. 521(1); AI violationAI violationThe term 'AI violation' means— (A) any violation of Federal law, including rules and regulations, related to or committed during the development, deployment, or use of artificial intelligence; or (B) any failure to appropriately respond to a substantial and specific danger that the development, deployment, or use of artificial intelligence may pose to public safety, public health, or national security.Sec. 521(2); artificial intelligence; artificial system; commerce and industry or activity affecting commerce; covered individualCovered individualThe term 'covered individual' includes— (A) an employee, including a former employee; and (B) an independent contractor, including a former independent contractor.Sec. 521(6) (employee or independent contractor, including former); emerging artificial intelligence technologyEmerging artificial intelligence technologyThe term 'emerging artificial intelligence technology', with respect to an AI security vulnerability, means any artificial system that exhibits a level of performance, complexity, or autonomy that is comparable to or exceeds capabilities that are generally considered state-of-the-art as of the time of the AI security vulnerability.Sec. 521(7); and employerEmployerThe term 'employer' means any person (including any officer, employee, contractor, subcontractor, agent, company, partnership, or other individual or entity) engaged in commerce or an industry or activity affecting commerce who pays any compensation to a covered individual in exchange for the covered individual providing work to the person.Sec. 521(8) (any person engaged in commerce or an industry or activity affecting commerce who pays compensation to a covered individualCovered individualThe term 'covered individual' includes— (A) an employee, including a former employee; and (B) an independent contractor, including a former independent contractor.Sec. 521(6) in exchange for work)].

Sec. 522(a) 3 PROHIBITION AGAINST RETALIATION.—No employerEmployerThe term 'employer' means any person (including any officer, employee, contractor, subcontractor, agent, company, partnership, or other individual or entity) engaged in commerce or an industry or activity affecting commerce who pays any compensation to a covered individual in exchange for the covered individual providing work to the person.Sec. 521(8) may, directly or indirectly, discharge, demote, suspend, threaten, blacklist, harass, or in any other manner discriminate against a covered individualCovered individualThe term 'covered individual' includes— (A) an employee, including a former employee; and (B) an independent contractor, including a former independent contractor.Sec. 521(6) in the terms and conditions of employment or post-employment of the covered individualCovered individualThe term 'covered individual' includes— (A) an employee, including a former employee; and (B) an independent contractor, including a former independent contractor.Sec. 521(6) (or the terms and conditions of work provided by the covered individualCovered individualThe term 'covered individual' includes— (A) an employee, including a former employee; and (B) an independent contractor, including a former independent contractor.Sec. 521(6) as an independent contractor) because of any lawful act done by the covered individualCovered individualThe term 'covered individual' includes— (A) an employee, including a former employee; and (B) an independent contractor, including a former independent contractor.Sec. 521(6)— (1) in providing information regarding an AI security vulnerabilityAI security vulnerabilityThe term 'AI security vulnerability' means any failure or lapse in security that could potentially allow emerging artificial intelligence technology to be acquired by a person (including a foreign entity) by theft or other means.Sec. 521(1) or AI violationAI violationThe term 'AI violation' means— (A) any violation of Federal law, including rules and regulations, related to or committed during the development, deployment, or use of artificial intelligence; or (B) any failure to appropriately respond to a substantial and specific danger that the development, deployment, or use of artificial intelligence may pose to public safety, public health, or national security.Sec. 521(2), or any conduct that the covered individualCovered individualThe term 'covered individual' includes— (A) an employee, including a former employee; and (B) an independent contractor, including a former independent contractor.Sec. 521(6) reasonably believes constitutes an AI security vulnerabilityAI security vulnerabilityThe term 'AI security vulnerability' means any failure or lapse in security that could potentially allow emerging artificial intelligence technology to be acquired by a person (including a foreign entity) by theft or other means.Sec. 521(1) or AI violationAI violationThe term 'AI violation' means— (A) any violation of Federal law, including rules and regulations, related to or committed during the development, deployment, or use of artificial intelligence; or (B) any failure to appropriately respond to a substantial and specific danger that the development, deployment, or use of artificial intelligence may pose to public safety, public health, or national security.Sec. 521(2), to— (A) the appropriate regulatory official or the Attorney General; (B) a regulatory or law enforcement agency; or (C) any Member of Congress or any committee of Congress; (2) in initiating, testifying in, or assisting in any investigation or judicial or administrative action of an appropriate regulatory or law enforcement agency or the Department of Justice, or any investigation of Congress, based upon or related to the information described in paragraph (1); or (3) in providing information regarding an AI security vulnerabilityAI security vulnerabilityThe term 'AI security vulnerability' means any failure or lapse in security that could potentially allow emerging artificial intelligence technology to be acquired by a person (including a foreign entity) by theft or other means.Sec. 521(1) or AI violationAI violationThe term 'AI violation' means— (A) any violation of Federal law, including rules and regulations, related to or committed during the development, deployment, or use of artificial intelligence; or (B) any failure to appropriately respond to a substantial and specific danger that the development, deployment, or use of artificial intelligence may pose to public safety, public health, or national security.Sec. 521(2), or any conduct that the covered individualCovered individualThe term 'covered individual' includes— (A) an employee, including a former employee; and (B) an independent contractor, including a former independent contractor.Sec. 521(6) reasonably believes constitutes an AI security vulnerabilityAI security vulnerabilityThe term 'AI security vulnerability' means any failure or lapse in security that could potentially allow emerging artificial intelligence technology to be acquired by a person (including a foreign entity) by theft or other means.Sec. 521(1) or AI violationAI violationThe term 'AI violation' means— (A) any violation of Federal law, including rules and regulations, related to or committed during the development, deployment, or use of artificial intelligence; or (B) any failure to appropriately respond to a substantial and specific danger that the development, deployment, or use of artificial intelligence may pose to public safety, public health, or national security.Sec. 521(2), to— (A) a person with supervisory authority over the covered individualCovered individualThe term 'covered individual' includes— (A) an employee, including a former employee; and (B) an independent contractor, including a former independent contractor.Sec. 521(6) at the employer of the covered individualCovered individualThe term 'covered individual' includes— (A) an employee, including a former employee; and (B) an independent contractor, including a former independent contractor.Sec. 521(6); or (B) another individual working for the employerEmployerThe term 'employer' means any person (including any officer, employee, contractor, subcontractor, agent, company, partnership, or other individual or entity) engaged in commerce or an industry or activity affecting commerce who pays any compensation to a covered individual in exchange for the covered individual providing work to the person.Sec. 521(8) described in subparagraph (A) whom the covered individualCovered individualThe term 'covered individual' includes— (A) an employee, including a former employee; and (B) an independent contractor, including a former independent contractor.Sec. 521(6) reasonably believes has the authority to— (i) investigate, discover, or terminate the misconduct; or (ii) take any other action to address the misconduct.

Sec. 522(b) 3 ENFORCEMENT.— [A covered individualCovered individualThe term 'covered individual' includes— (A) an employee, including a former employee; and (B) an independent contractor, including a former independent contractor.Sec. 521(6) aggrieved by a violation may file a complaint with the Secretary of Labor governed by the rules, procedures, and burdens of 49 U.S.C. 42121(b), or bring a federal district court action if the Secretary has not issued a final decision within 180 days absent bad-faith delay. Jury trial rights apply. Statute of limitations: within 6 years of the violation or 3 years after material facts are known or reasonably should have been known, but in no case more than 10 years. Relief includes reinstatement with the same seniority, two times back pay with interest, compensatory damages including litigation costs, expert witness fees, and reasonable attorneys' fees, and other appropriate remedies.]

Sec. 522(c) 3 NONENFORCEABILITY WAIVERS OF RIGHTS OR REMEDIES.—The rights and remedies provided for in this section may not be waived or altered by any contract, agreement, policy form, or condition of employment (or condition of work as an independent contractor), including by any agreement requiring a covered individualCovered individualThe term 'covered individual' includes— (A) an employee, including a former employee; and (B) an independent contractor, including a former independent contractor.Sec. 521(6) to engage in arbitration, mediation, or any other alternative dispute resolution process prior to seeking relief under subsection (b).

Subtitle C creates a federal anti-retaliation regime for AI whistleblowers. It prohibits any employer — broadly defined to include officers, contractors, and subcontractors — from retaliating against a covered individual (employee or independent contractor, current or former) for reporting an AI security vulnerability or AI violation, or conduct reasonably believed to constitute one, to regulators, the Attorney General, Congress, or internally to a supervisor or someone with authority to address the misconduct, or for participating in a related investigation.

Enforcement runs through a DOL complaint (governed by AIR21 procedures and burdens, 49 U.S.C. 42121(b)) with a federal district court kick-out after 180 days, jury trial rights, and a 6-year/3-year discovery statute of limitations capped at 10 years. Prevailing whistleblowers recover reinstatement, double back pay with interest, and compensatory damages including litigation costs, expert fees, and attorney fees. The rights cannot be waived by contract, including by pre-dispute arbitration agreements. This is a genuine affirmative obligation on employers involved in AI development, deployment, or use.

Compliance actions 1 item
3
EmployersEmployerThe term 'employer' means any person (including any officer, employee, contractor, subcontractor, agent, company, partnership, or other individual or entity) engaged in commerce or an industry or activity affecting commerce who pays any compensation to a covered individual in exchange for the covered individual providing work to the person.Sec. 521(8) involved in developing, deploying, or using AI must not retaliate against employees or independent contractors (current or former) for reporting AI security vulnerabilities or AI violationsAI violationThe term 'AI violation' means— (A) any violation of Federal law, including rules and regulations, related to or committed during the development, deployment, or use of artificial intelligence; or (B) any failure to appropriately respond to a substantial and specific danger that the development, deployment, or use of artificial intelligence may pose to public safety, public health, or national security.Sec. 521(2), or conduct reasonably believed to be one, to regulators, the Attorney General, Congress, or internally, and may not use contracts, NDAs, or mandatory arbitration agreements to waive these anti-retaliation rights.
G-03.3
Secs. 601-644 (education, literacy, and inclusion)
AI literacy, education, and workforce programs

Sec. 601 SEC. 601. AI LITERACYAI literacyThe term 'AI literacy' means having the age-appropriate knowledge and ability to use AI effectively, to critically interpret outputs, to solve problems in an AI-enabled world, and to safely and ethically use AI.Sec. 621(e)(2) EFFORTS OF THE AI TASK FORCE. The Director of the National Science Foundation shall take such actions as may be necessary to provide to the STEM Teachers Corps Pilot Program and the Computer Science for All Program of the Foundation general support in accordance with the recommendations of the AI Task Force established on February 20, 2024, of the House of Representatives.

Secs. 611-612 SEC. 611. EMPLOYEE CYBERSECURITY EDUCATION. [Adds new IRC section 45BB providing a general business tax credit equal to 50 percent of qualified employee cybersecurity education expenses, capped at $5,000 per employee, tied to NICE Cybersecurity Workforce Framework work roles.] SEC. 612. CYBERSECURITY TRAINING INCENTIVE FOR GOVERNMENT CONTRACTS. [Directs executive agencies to award a five percent proposal score increase to qualified offerors that have claimed the section 45BB credit, for contracts over $5,000,000.]

Sec. 621 SEC. 621. PREPARING K–12 EDUCATORS AND STUDENTS FOR AN AI LITERATE FUTURE. [Sense of Congress on AI literacyAI literacyThe term 'AI literacy' means having the age-appropriate knowledge and ability to use AI effectively, to critically interpret outputs, to solve problems in an AI-enabled world, and to safely and ethically use AI.Sec. 621(e)(2); authorizes the NSF Director to make merit-reviewed competitive awards to institutions of higher education and nonprofits to develop K-12 AI literacyAI literacyThe term 'AI literacy' means having the age-appropriate knowledge and ability to use AI effectively, to critically interpret outputs, to solve problems in an AI-enabled world, and to safely and ethically use AI.Sec. 621(e)(2) curricula and evaluation methods; use of funds; implementation; and definitions including AI literacyAI literacyThe term 'AI literacy' means having the age-appropriate knowledge and ability to use AI effectively, to critically interpret outputs, to solve problems in an AI-enabled world, and to safely and ethically use AI.Sec. 621(e)(2).]

Sec. 631 SEC. 631. EXPANDING CAPACITY IN ARTIFICIAL INTELLIGENCE SCIENCE. [Amends the National Artificial Intelligence Initiative Act to authorize NSF awards to eligible under-resourced, HBCU, minority-serving, and Tribal institutions and nonprofits to broaden participation and capacity in AI research, education, and workforce development.]

Secs. 641-644 SEC. 641. SCHOLARSHIPS AND FELLOWSHIPS IN ARTIFICIAL INTELLIGENCE. [NSF student and professional-development scholarships and fellowships in AI.] SEC. 642. COMMUNITY COLLEGE AND AREA CAREER AND TECHNICAL EDUCATIONAL SCHOOL CENTERS OF AI EXCELLENCE. [NSF establishment of up to eight Centers of AI Excellence.] SEC. 643. AWARDS FOR RESEARCH ON ARTIFICIAL INTELLIGENCE IN EDUCATION. [NSF awards for research on AI teaching models and integration for K-12, plus a Rural and Underserved Communities AI Collaborative pilot.] SEC. 644. NATIONAL STEM TEACHER CORPS. [Incorporates AI skills development into the National STEM Teacher Corps.]

Title VI directs the NSF to support AI literacy efforts, fund K-12 AI literacy curriculum and educator development, expand AI research capacity at under-resourced and minority-serving institutions, award AI scholarships and fellowships, establish community-college Centers of AI Excellence, and fund research on AI in education, plus a New Collar Jobs cybersecurity education tax credit and a related government-contract scoring incentive.

Every operative duty runs to the NSF Director, the Secretary of Labor, or (for the tax provisions) the tax code and executive agencies administering procurement. These are grant, education, and tax-incentive programs; none imposes a compliance obligation on private AI developers or deployers, so no taxonomy obligations are mapped.

Passage Likelihood

Pending
Status Introduced

Legislative History

No history on file

Entry Last Reviewed

2026-07-12
AI generated