Federal · Senate Bill · 119th Congress, 2nd Session
SB5061
Secure Artificial Intelligence Development Act of 2026 (S. 5061, 119th Congress)

Status ● Introduced Effective N/A Passage Likelihood L

WHAT THIS BILL REGULATES · 2 REQUIREMENT TYPES

How Is This Bill Enforced

Enforcement Authority
The Director of NIST refers violations of the pre-release NSA access requirement to the Attorney General, who enforces the section. Before commencing an enforcement action, the Attorney General must notify the provider and allow a 7-calendar-day cure period during which the provider may withdraw the model and provide the required NSA access. No private right of action.
Private Right of Action
No private right of action. Enforcement is exclusive to the designated authority.
Penalties
Violation of the pre-release NSA access requirement is subject to a civil fine of not less than $100,000 per day for each day a frontier model remains available in interstate or foreign commerce without the required voluntary security guidance. A 7-day right to cure applies, allowing the provider to withdraw the model and grant NSA access to avoid enforcement.

What This Bill Requires

Verbatim statutory text on the left; plain-language analysis and a per-section checklist on the right. Numbered markers cross-link to the matching checklist row.

Statutory Text
Analysis & Obligations
Sec. 1
Short Title

This Act may be cited as the ‘‘Secure Artificial Intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) Development Act of 2026’’ or the ‘‘Secure A.I. Development Act of 2026’’.

Establishes the short title of the Act as the Secure Artificial Intelligence Development Act of 2026 or the Secure A.I. Development Act of 2026. No compliance obligation.

Sec. 2
Definitions

(1) ADVERSARIAL-ARTIFICIAL INTELLIGENCEadversarial-artificial intelligenceThe term “adversarial-artificial intelligence” means techniques or procedures to extract information about the behavior or characteristics of an artificial intelligence system, or to learn how to manipulate an artificial intelligence system, in order to subvert the confidentiality, integrity, or availability of an artificial intelligence system or adjacent system.Sec. 2(1).—The term ‘‘adversarial-artificial intelligenceadversarial-artificial intelligenceThe term “adversarial-artificial intelligence” means techniques or procedures to extract information about the behavior or characteristics of an artificial intelligence system, or to learn how to manipulate an artificial intelligence system, in order to subvert the confidentiality, integrity, or availability of an artificial intelligence system or adjacent system.Sec. 2(1)’’ means techniques or procedures to extract information about the behavior or characteristics of an artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) system, or to learn how to manipulate an artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) system, in order to subvert the confidentiality, integrity, or availability of an artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) system or adjacent system.

(2) ARTIFICIAL INTELLIGENCEartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2).—The term ‘‘artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2)’’ has the meaning given the term in section 5002 of the National Artificial Intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) Initiative Act of 2020 (15 U.S.C. 9401).

(3) ARTIFICIAL INTELLIGENCE SAFETY INCIDENTartificial intelligence safety incidentThe term “artificial intelligence safety incident” means an event that materially increases the risk that operation of an artificial intelligence system leads to a state in which human life, health, property, or the environment is endangered.Sec. 2(3).—The term ‘‘artificial intelligence safety incidentartificial intelligence safety incidentThe term “artificial intelligence safety incident” means an event that materially increases the risk that operation of an artificial intelligence system leads to a state in which human life, health, property, or the environment is endangered.Sec. 2(3)’’ means an event that materially increases the risk that operation of an artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) system leads to a state in which human life, health, property, or the environment is endangered.

(4) ARTIFICIAL INTELLIGENCE SECURITY INCIDENTartificial intelligence security incidentThe term “artificial intelligence security incident” means an event that materially increases— (A) the risk that operation of an artificial intelligence system occurs in a way that enables the unauthorized extraction of information about the behavior or characteristics of an artificial intelligence system by an unauthorized party; or (B) the ability to manipulate an artificial intelligence system in order to subvert the confidentiality, integrity, or availability of an artificial intelligence system or adjacent system.Sec. 2(4).—The term ‘‘artificial intelligence security incidentartificial intelligence security incidentThe term “artificial intelligence security incident” means an event that materially increases— (A) the risk that operation of an artificial intelligence system occurs in a way that enables the unauthorized extraction of information about the behavior or characteristics of an artificial intelligence system by an unauthorized party; or (B) the ability to manipulate an artificial intelligence system in order to subvert the confidentiality, integrity, or availability of an artificial intelligence system or adjacent system.Sec. 2(4)’’ means an event that materially increases— (A) the risk that operation of an artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) system occurs in a way that enables the unauthorized extraction of information about the behavior or characteristics of an artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) system by an unauthorized party; or (B) the ability to manipulate an artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) system in order to subvert the confidentiality, integrity, or availability of an artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) system or adjacent system.

(5) ARTIFICIAL INTELLIGENCE SECURITY VULNERABILITYartificial intelligence security vulnerabilityThe term “artificial intelligence security vulnerability” means a weakness in an artificial intelligence system that could be exploited by a third party to subvert, without authorization, the confidentiality, integrity, or availability of an artificial intelligence system, including through techniques such as— (A) data poisoning; (B) evasion attacks; (C) privacy-based attacks; (D) model theft or extraction attacks; (E) attacks designed to circumvent or degrade the safety, alignment, or access control mechanisms of an artificial intelligence system; and (F) adversarial machine learning attacks as described in National Institute of Standards and Technology Trustworthy and Responsible Artificial Intelligence 100–2e2025 (relating to Adversarial Machine Learning), or successor publication.Sec. 2(5).—The term ‘‘artificial intelligence security vulnerabilityartificial intelligence security vulnerabilityThe term “artificial intelligence security vulnerability” means a weakness in an artificial intelligence system that could be exploited by a third party to subvert, without authorization, the confidentiality, integrity, or availability of an artificial intelligence system, including through techniques such as— (A) data poisoning; (B) evasion attacks; (C) privacy-based attacks; (D) model theft or extraction attacks; (E) attacks designed to circumvent or degrade the safety, alignment, or access control mechanisms of an artificial intelligence system; and (F) adversarial machine learning attacks as described in National Institute of Standards and Technology Trustworthy and Responsible Artificial Intelligence 100–2e2025 (relating to Adversarial Machine Learning), or successor publication.Sec. 2(5)’’ means a weakness in an artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) system that could be exploited by a third party to subvert, without authorization, the confidentiality, integrity, or availability of an artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) system, including through techniques such as— (A) data poisoning; (B) evasion attacks; (C) privacy-based attacks; (D) model theft or extraction attacks; (E) attacks designed to circumvent or degrade the safety, alignment, or access control mechanisms of an artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) system; and (F) adversarial machine learning attacks as described in National Institute of Standards and Technology Trustworthy and Responsible Artificial Intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) 100–2e2025 (relating to Adversarial Machine Learning), or successor publication.

Defines the AI-relevant terms used throughout the Act, including artificial intelligence security incident and artificial intelligence safety incident (which drive the incident-reporting database in Section 4) and artificial intelligence security vulnerability (which drives the vulnerability-management updates in Sections 5 and 6). These are definitions only and impose no independent compliance obligation.

Sec. 3
Enabling Testing of Frontier Artificial Intelligence Models Prior to Public Release
DeveloperDistributor

(a) DEFINITIONS.—In this section: (1) BOARDBoardThe term “Board” means the Artificial Intelligence Risk Board established under subsection (b)(1).Sec. 3(a)(1).—The term ‘‘BoardBoardThe term “Board” means the Artificial Intelligence Risk Board established under subsection (b)(1).Sec. 3(a)(1)’’ means the Artificial Intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) Risk BoardBoardThe term “Board” means the Artificial Intelligence Risk Board established under subsection (b)(1).Sec. 3(a)(1) established under subsection (b)(1). (2) CRITICAL INFRASTRUCTUREcritical infrastructureThe term “critical infrastructure” has the meaning provided in section 1016(e) of the USA Patriot Act of 2001 (42 U.S.C. 5195c(e)).Sec. 3(a)(2).—The term ‘‘critical infrastructurecritical infrastructureThe term “critical infrastructure” has the meaning provided in section 1016(e) of the USA Patriot Act of 2001 (42 U.S.C. 5195c(e)).Sec. 3(a)(2)’’ has the meaning provided in section 1016(e) of the USA Patriot Act of 2001 (42 U.S.C. 5195c(e)). (3) FRONTIER ARTIFICIAL INTELLIGENCE MODELfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3).—The term ‘‘frontier artificial intelligence modelfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3)’’ means an artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) model, or system combining multiple artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety. (4) INSTITUTEInstituteThe term “Institute” means the National Institute of Standards and Technology.Sec. 3(a)(4).—The term ‘‘InstituteInstituteThe term “Institute” means the National Institute of Standards and Technology.Sec. 3(a)(4)’’ means the National Institute of Standards and Technology. (5) SECRETARY.—The term ‘‘Secretary’’ means the Secretary of Commerce.

(b) THE ARTIFICIAL INTELLIGENCEartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) RISK BOARDBoardThe term “Board” means the Artificial Intelligence Risk Board established under subsection (b)(1).Sec. 3(a)(1).—(1) ESTABLISHMENT.—(A) IN GENERAL.—Not later than 90 days after the date of the enactment of this Act, the Secretary shall establish within the InstituteInstituteThe term “Institute” means the National Institute of Standards and Technology.Sec. 3(a)(4) a boardBoardThe term “Board” means the Artificial Intelligence Risk Board established under subsection (b)(1).Sec. 3(a)(1) to address artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) risks. ... (6) DUTIES.—(A) IN GENERAL.—The BoardBoardThe term “Board” means the Artificial Intelligence Risk Board established under subsection (b)(1).Sec. 3(a)(1) shall— (i) develop a process to perform technical evaluations to determine what capabilities or combination of capabilities constitute high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety; and (ii) develop best practices, including— (I) standardize formats and processes for publishing model cards with technical details of artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) systems; (II) recommendations for maintaining cybersecurity measures for developers or providers of artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) systems; (III) processes and metrics for developers or providers of artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) systems to use to evaluate risks from employees or other personnel who have access to artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) systems developed or in development by developers or providers of artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) systems; and (IV) recommendations on appropriate financial and other resourcing for developers or providers of artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) systems to robustly engage in safety and security research focused on the deployment of frontier artificial intelligence modelsfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3). (B) PERIODIC REASSESSMENT OF TECHNICAL EVALUATIONS AND BEST PRACTICES.—The BoardBoardThe term “Board” means the Artificial Intelligence Risk Board established under subsection (b)(1).Sec. 3(a)(1) shall periodically reassess the technical evaluations and best practices the BoardBoardThe term “Board” means the Artificial Intelligence Risk Board established under subsection (b)(1).Sec. 3(a)(1) develops under this subsection.

(c) 1 REQUIREMENT THAT PROVIDERS OF FRONTIER ARTIFICIAL INTELLIGENCE MODELSfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3) GIVE ACCESS TO NATIONAL SECURITY AGENCY BEFORE PUBLIC RELEASE.—Not later than 21 calendar days before a provider introduces into interstate or foreign commerce a frontier artificial intelligence modelfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3), the provider shall make available to the Artificial Intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) Security Center, established by the Director of the National Security Agency under section 6504 of the Intelligence Authorization Act for Fiscal Year 2025 (division F of Public Law 118–159; 50 U.S.C. 3602 note), access to the frontier artificial intelligence modelfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3), including model's weights, configuration files, runtimes, or software libraries necessary to operate the frontier artificial intelligence modelfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3).

(d) 2 FRONTIER ARTIFICIAL INTELLIGENCE MODELfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3) REGISTRY.—(1) ESTABLISHMENT OF REGISTRY.—Not later than 90 days after the date of the enactment of this Act, the Director of the National Institute of Standards and Technology shall establish a registry of frontier models that are available to the public. (2) RULES AND PROCEDURES.—In establishing the registry under paragraph (1), the Director of the National Institute of Standards and Technology shall establish rules and procedures for— (A) a provider of a frontier artificial intelligence modelfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3) to register the frontier artificial intelligence modelfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3); (B) a provider of a frontier artificial intelligence modelfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3) to contest the need for registering the frontier artificial intelligence modelfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3); (C) removing a frontier artificial intelligence modelfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3) from the registry; (D) a provider of a frontier artificial intelligence modelfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3) to attest that the provider submitted the frontier artificial intelligence modelfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3) to the test-bed established under section 6504(e) of the Intelligence Authorization Act for Fiscal Year 2025 ...; and (E) such other purposes the Director deems necessary. (3) OBLIGATION TO REGISTER.—Each provider of a frontier artificial intelligence modelfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3) shall register that frontier artificial intelligence modelfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3) with the registry established under paragraph (1) before introducing the frontier artificial intelligence modelfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3) into interstate or foreign commerce.

(e) ENFORCEMENT; ABILITY TO CURE.—(1) REFERRALS FOR ENFORCEMENT.—In any case in which the Director of the National Institute of Standards and Technology determines that a frontier artificial intelligence modelfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3) has been introduced into interstate or foreign commerce by a provider of the frontier artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) in violation of subsection (c), the Director of the National Institute of Standards and Technology shall notify the Attorney General. (2) ENFORCEMENT.—The Attorney General shall enforce this section. (3) PENALTY.—Whoever violates subsection (c) shall be fined an amount equal to not less than $100,000 per day for each day during which a frontier artificial intelligence modelfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3) controlled by that person is available through interstate and foreign commerce without having obtained the voluntary security guidance issued under section 6504(e)(3) of the Intelligence Authorization Act for Fiscal Year 2025 ... (4) RIGHT TO CURE.—(A) NOTIFICATION.—Prior to commending an enforcement action against a provider of a frontier artificial intelligence modelfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3) for violating subsection (c), the Attorney General shall notify the provider and allow the provider 7 calendar days following the notice of violation for the violator to come into compliance pursuant to subparagraph (B). (B) PROCESS TO CURE.—In order for a provider of a frontier artificial intelligence modelfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3) to come into compliance pursuant to this subparagraph, the provider shall demonstrate to the Attorney General that the provider has— (i) withdrawn from interstate and foreign commerce the frontier artificial intelligence modelfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3) that gave rise to the violation of subsection (c); and (ii) given to the National Security Agency access to the frontier artificial intelligence modelfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3) pursuant to subsection (c).

(f) NATIONAL SECURITY AGENCY RESEARCH-TESTBED.—Section 6504 of the Intelligence Authorization Act for Fiscal Year 2025 (division F of Public Law 118–159; 50 U.S.C. 3602 note) is amended— ... ‘‘(e) TEST-BED REQUIREMENTS.— ‘‘(1) ACCESS AND TERMS OF USAGE.— ‘‘(A) OUTSIDE PARTICIPATION.—The Director shall establish a process by which critical infrastructurecritical infrastructureThe term “critical infrastructure” has the meaning provided in section 1016(e) of the USA Patriot Act of 2001 (42 U.S.C. 5195c(e)).Sec. 3(a)(2) operators, as well private sector entities that develop or maintain information systems utilized by critical infrastructurecritical infrastructureThe term “critical infrastructure” has the meaning provided in section 1016(e) of the USA Patriot Act of 2001 (42 U.S.C. 5195c(e)).Sec. 3(a)(2) operators, shall access a secure test-bed for the purpose of testing and evaluating the impact of frontier artificial intelligence modelsfrontier artificial intelligence modelThe term “frontier artificial intelligence model” means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.Sec. 3(a)(3) on information systems maintained by critical infrastructurecritical infrastructureThe term “critical infrastructure” has the meaning provided in section 1016(e) of the USA Patriot Act of 2001 (42 U.S.C. 5195c(e)).Sec. 3(a)(2) operators prior to public release or distribution of such models. ... ‘‘(3) VOLUNTARY SECURITY GUIDANCE.—The Director shall share relevant guidance, informed by pre-deployment testing in the secure test-bed environment ...’’.

This is the operative core of the bill for private-sector counsel. It establishes an Artificial Intelligence Risk Board within NIST to develop technical evaluations and best practices, and it imposes two concrete duties on providers of frontier artificial intelligence models. First, at least 21 calendar days before introducing a frontier model into interstate or foreign commerce, a provider must give the NSA's AI Security Center access to the model, including its weights, configuration files, runtimes, and software libraries. Second, each provider must register its frontier model with a NIST-established public registry before commercialization.

Enforcement runs through the Attorney General on referral from NIST, with a civil fine of not less than $100,000 per day and a mandatory 7-day right to cure that lets a provider avoid enforcement by withdrawing the model and granting NSA access. Subsection (f) amends the Intelligence Authorization Act to create a research test-bed and voluntary security guidance; those provisions impose duties on the NSA Director, not on private entities.

Compliance actions 2 items
1
Providers of frontier AI models must give the NSA's AI Security Center access to the model, including its weights, configuration files, runtimes, and software libraries, at least 21 calendar days before introducing it into interstate or foreign commerce.
S-03.4
2
Providers of frontier AI models must register each publicly available frontier model with the NIST frontier-model registry before introducing it into interstate or foreign commerce.
R-02.3
Sec. 4
Database for Artificial Intelligence Security and Safety Incidents and Risks

(a)(1) VOLUNTARY SUBMISSIONS.—Not later than 1 year after the date of the enactment of this Act, the Director of the National Institute of Standards and Technology shall, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, establish mechanisms by which private sector entities, public sector organizations, civil society groups, and academic researchers may voluntarily share information with the National Institute of Standards and Technology on confirmed or suspected artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) security or artificial intelligence safety incidentsartificial intelligence safety incidentThe term “artificial intelligence safety incident” means an event that materially increases the risk that operation of an artificial intelligence system leads to a state in which human life, health, property, or the environment is endangered.Sec. 2(3), in a manner that preserves confidentiality of any affected party, which shall— (A) leverage, to the greatest extent possible, standardized disclosure and incident description formats; (B) develop processes to associate reports pertaining to the same incident with a single incident identifier; (C) establish classification, information retrieval, and reporting mechanisms that sufficiently differentiate between artificial intelligence security incidentsartificial intelligence security incidentThe term “artificial intelligence security incident” means an event that materially increases— (A) the risk that operation of an artificial intelligence system occurs in a way that enables the unauthorized extraction of information about the behavior or characteristics of an artificial intelligence system by an unauthorized party; or (B) the ability to manipulate an artificial intelligence system in order to subvert the confidentiality, integrity, or availability of an artificial intelligence system or adjacent system.Sec. 2(4) and artificial intelligence safety incidentsartificial intelligence safety incidentThe term “artificial intelligence safety incident” means an event that materially increases the risk that operation of an artificial intelligence system leads to a state in which human life, health, property, or the environment is endangered.Sec. 2(3); and (D) create appropriate taxonomies to classify incidents based on relevant characteristics, impact, or other relevant criteria.

(a)(2) PUBLICLY ACCESSIBLE DATABASE.—(A) ESTABLISHMENT OF DATABASE REQUIRED.—Not later than 1 year after the date of the enactment of this Act, the Director of the InstituteInstituteThe term “Institute” means the National Institute of Standards and Technology.Sec. 3(a)(4) shall, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, establish a publicly accessible database of artificial intelligence security incidentsartificial intelligence security incidentThe term “artificial intelligence security incident” means an event that materially increases— (A) the risk that operation of an artificial intelligence system occurs in a way that enables the unauthorized extraction of information about the behavior or characteristics of an artificial intelligence system by an unauthorized party; or (B) the ability to manipulate an artificial intelligence system in order to subvert the confidentiality, integrity, or availability of an artificial intelligence system or adjacent system.Sec. 2(4) and artificial intelligence safety incidentsartificial intelligence safety incidentThe term “artificial intelligence safety incident” means an event that materially increases the risk that operation of an artificial intelligence system leads to a state in which human life, health, property, or the environment is endangered.Sec. 2(3). (B) REVIEW AND POPULATION OF DATABASE.—Upon receipt of relevant information on an artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) security or artificial intelligence safety incidentartificial intelligence safety incidentThe term “artificial intelligence safety incident” means an event that materially increases the risk that operation of an artificial intelligence system leads to a state in which human life, health, property, or the environment is endangered.Sec. 2(3) under paragraph (1), the Director of the InstituteInstituteThe term “Institute” means the National Institute of Standards and Technology.Sec. 3(a)(4) shall review the information and determine whether the described incident constitutes an artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) security or artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) safety risk appropriate for inclusion in the database ... (C) IDENTIFICATION OF CAUSAL FACTORS ... (D) PRIORITIES ...

(a)(3) EXEMPTION FROM DISCLOSURE; REPORTS AND ANONYMITY.—(A) ANONYMITY.—The Director shall populate the voluntary database ... ensuring that any incident description sufficiently anonymizes those affected, unless those who are affected have consented ... (B) EXEMPTION FROM DISCLOSURE.—Any information shared using the mechanism established pursuant to paragraph (1)— (i) shall be exempt from disclosure and withheld ... pursuant to section 552(b)(3)(B) of title 5 ...; and (ii) shall not be deemed a waiver of any applicable privilege or protection, including trade secret protection. (C) CONSULTATION REQUIRED.—Before publishing information regarding artificial intelligence safety incidentartificial intelligence safety incidentThe term “artificial intelligence safety incident” means an event that materially increases the risk that operation of an artificial intelligence system leads to a state in which human life, health, property, or the environment is endangered.Sec. 2(3) under paragraph (2)(B), the Director shall consult with the developer or provider of the artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) system involved in an incident.

(b) MATERIAL RISK GUIDANCE.—Not later than 180 days after the date of the enactment of this Act the Director of the National Institute of Standards and Technology shall, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, publish nonbinding guidance that provides illustrative criteria and examples for determining when an event ‘‘materially increases’’ a risk for purposes of paragraphs (3) and (4) of section 2.

Directs NIST, in coordination with CISA, to establish voluntary mechanisms for private entities, public organizations, civil society, and researchers to share confirmed or suspected AI security and safety incidents, and to build a publicly accessible incident database with anonymization and FOIA-exemption protections. Because reporting is voluntary and the operative duties fall on NIST and CISA rather than on any private covered entity, this section imposes no new private-sector compliance obligation. It is retained for scope and timing context, as it foreshadows a federal AI incident-tracking regime.

Sec. 5
Updating Processes and Procedures Relating to Cybersecurity Vulnerabilities

(a) DEFINITIONS.—In this section: (1) COMMON VULNERABILITIES AND EXPOSURES PROGRAM.—The term ‘‘Common Vulnerabilities and Exposures Program’’ means the reference guide and classification system for publicly known information security vulnerabilities sponsored by the Cybersecurity and Infrastructure Security Agency. (2) RELEVANT CONGRESSIONAL COMMITTEES.—The term ‘‘relevant congressional committees’’ means— (A) the Committee on Homeland Security and Governmental Affairs, the Committee on Commerce, Science, and Transportation, the Select Committee on Intelligence, and the Committee on the Judiciary of the Senate; and (B) the Committee on Oversight and Government Reform, the Committee on Energy and Commerce, the Permanent Select Committee on Intelligence, and the Committee on the Judiciary of the House of Representatives.

(b) PROCESSES AND PROCEDURES FOR VULNERABILITY MANAGEMENT.—Not later than 180 days after the date of the enactment of this Act, the Director of the National Institute of Standards and Technology shall— (1) comprehensively evaluate, and develop a strategic plan to reform, the structure and processes of the National Vulnerability Database ...; (2) initiate a process to utilize advanced artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) systems to characterize vulnerabilities as part of the National Vulnerability Database; (3) initiate a process to update processes and procedures associated with the National Vulnerability Database ...; (4) identify any characteristics of artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) security vulnerabilities that make utilization of the National Vulnerability Database inappropriate ...; and (5) initiate a process to update the Secure Software Development Framework set forth in National Institute of Standards and Technology Special Publication 800–218 and include guidance and best practices for using artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) in code generation and security review.

(c) UPDATES TO COMMON VULNERABILITIES AND EXPOSURES PROGRAM.—Not later than 180 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall— (1) initiate a process to update processes and procedures associated with the Common Vulnerabilities and Exposures Program ...; and (2) identify any characteristic of artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) security vulnerabilities that make utilization of the Common Vulnerabilities and Exposures Program inappropriate and develop processes and procedures for vulnerability identification and enumeration for those artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) security vulnerabilities.

(d) SUBMISSION TO CONGRESS.—Upon completion of the processes required in subsections (a) and (b), the Director of the National Institute of Standards and Technology and the Director of the Cybersecurity and Infrastructure Security Agency, respectively, shall submit a strategic plan to Congress identifying courses of action under existing authorities, or identifying specific legislative amendments, necessary to address accelerating security risks associated with artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) systems.

(e) EVALUATION OF CONSENSUS STANDARDS FOR VULNERABILITY DISCLOSURE.—(1) IN GENERAL.—Not later than 30 days after the date of the enactment of this Act, the Director of the National Institute of Standards and Technology shall, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, initiate a multi-stakeholder process to evaluate whether existing voluntary consensus standards and processes for vulnerability reporting processes ... effectively accommodate the significant increased volume of vulnerabilities in information systems identified by artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) systems ... (2) REPORT.—...

Directs NIST and CISA to reform the National Vulnerability Database and the Common Vulnerabilities and Exposures Program to account for the increased volume and unique nature of AI-identified and AI security vulnerabilities, to update the Secure Software Development Framework (SP 800–218), and to report to Congress. All duties fall on federal agencies; no private-sector compliance obligation is created. Retained for scope and timing context.

Sec. 6
Review of Artificial Intelligence Security Vulnerabilities Under Vulnerabilities Equities Process

(a) DEFINITIONS.—In this section: (1) APPROPRIATE CONGRESSIONAL COMMITTEES.—The term ‘‘appropriate congressional committees’’ means— (A) the Select Committee on Intelligence of the Senate; (B) the Committee on Homeland Security and Governmental Affairs of the Senate; (C) the Committee on the Judiciary of the Senate; (D) the Committee on Armed Services of the Senate; (E) the Permanent Select Committee on Intelligence of the House of Representatives; (F) the Committee on Homeland Security of the House of Representatives; (G) the Committee on the Judiciary of the House of Representatives; and (H) the Committee on Armed Services of the House of Representatives. (2) VULNERABILITIES EQUITIES POLICY AND PROCESS DOCUMENT.—... (3) VULNERABILITIES EQUITIES PROCESS.—...

(b) EVALUATION; REPORT.—Not later than 90 days after the date of the enactment of this Act, the Federal departments and agencies participating in the Vulnerabilities Equities Process shall— (1) evaluate whether the existing Vulnerabilities Equities Process sufficiently accommodates the submission and review of artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) security vulnerabilities; and (2) submit to the appropriate congressional committees a report describing the applicability of the Vulnerabilities Equities Process to such vulnerabilities ...

(c) PROCESS.—In carrying out subsection (b), if the Federal departments and agencies participating in the Vulnerabilities Equities Process determine that the existing Vulnerabilities Equities Process does not sufficiently accommodate the submission and review of artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) security vulnerabilities ... the Federal departments and agencies participating in the Vulnerabilities Equities Process shall establish a process for the submission and review of such vulnerabilities under the Vulnerabilities Equities Process not later than 30 days after the date of such determination.

(d) REPORT ON VULNERABILITIES IDENTIFIED BY ARTIFICIAL INTELLIGENCEartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) SYSTEMS.—Not later than 90 days after the date of the enactment of this Act, the Director of National Intelligence shall submit to the congressional intelligence committees ... a report on— (1) the volume of vulnerabilities of information systems identified by artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) systems; (2) the impact of any change in such volume on the functioning of the Vulnerabilities Equities Process; and (3) whether the increasingly rapid discovery and exploitation of such vulnerabilities by external cyber actors using artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) systems materially alters the equity of disclosure.

Directs federal agencies participating in the Vulnerabilities Equities Process, and the Director of National Intelligence, to evaluate whether the existing process adequately accommodates AI security vulnerabilities and to report to Congress. All duties are on federal agencies; no private-sector compliance obligation. Retained for scope and timing context.

Sec. 7
Security of Artificial Intelligence Systems and Laboratories
DeployerDeveloper

(a) DEFINITIONS.—In this section: ... (5) COVERED PERSONcovered personThe term “covered person” means a non-Federal person who— (A) is a United States person; (B) develops, deploys, or operates artificial intelligence models or critical enabling infrastructure; and (C) provides the services described in subparagraph (B) to a Federal department or agency.Sec. 7(a)(5).—The term ‘‘covered personcovered personThe term “covered person” means a non-Federal person who— (A) is a United States person; (B) develops, deploys, or operates artificial intelligence models or critical enabling infrastructure; and (C) provides the services described in subparagraph (B) to a Federal department or agency.Sec. 7(a)(5)’’ means a non-Federal person who— (A) is a United States person; (B) develops, deploys, or operates artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) models or critical enabling infrastructure; and (C) provides the services described in subparagraph (B) to a Federal department or agency. ... (12) THREAT INFORMATIONthreat informationThe term “threat information” means information on— (A) efforts by foreign adversary countries to use products or research of covered persons or other entities or individuals to generate synthetic media for foreign-directed influence campaigns, develop and manage computer network exploitation campaigns, design or develop weapons systems, or enhance surveillance capabilities in ways that undermine the privacy or threaten the security of citizens of the United States; (B) threats posed by foreign entities of concern, including indications of compromise to networks associated with covered persons or other technical indicators, indicating a compromise to the confidentiality, integrity, or availability of an artificial intelligence system, or to the supply chain of an artificial intelligence system, including training or test data, frameworks or software libraries, training or inference computing environments, or other components necessary for the training, management, deployment, or maintenance of an artificial intelligence system; (C) activity of foreign entities of concern to clandestinely, fraudulently, or otherwise maliciously access the systems of covered persons for purposes of illicit technology transfer or otherwise gaining unfair economic advantage, including through techniques to extract a model's technical capabilities to replicate, develop, or improve a foreign artificial intelligence model without authorization by the covered person; (D) activity of foreign entities of concern to sabotage or otherwise clandestinely degrade artificial intelligence systems or the supply chain of an artificial intelligence system...; (E) observations, emerging concerns, or other inputs from vendors or researchers regarding relevant malicious or clandestine activity of foreign entities of concern toward an artificial intelligence system, its supply chain, or other necessary components; (F) efforts by foreign adversaries or foreign entities to evade detection of malicious activity described in subparagraphs (A), (B), (C) and (D); and (G) any other relevant information the Director of the National Counterintelligence and Security Center and the Assistant Director of the Federal Bureau of Investigation for the Counterintelligence Division deem appropriate.Sec. 7(a)(12).—The term ‘‘threat informationthreat informationThe term “threat information” means information on— (A) efforts by foreign adversary countries to use products or research of covered persons or other entities or individuals to generate synthetic media for foreign-directed influence campaigns, develop and manage computer network exploitation campaigns, design or develop weapons systems, or enhance surveillance capabilities in ways that undermine the privacy or threaten the security of citizens of the United States; (B) threats posed by foreign entities of concern, including indications of compromise to networks associated with covered persons or other technical indicators, indicating a compromise to the confidentiality, integrity, or availability of an artificial intelligence system, or to the supply chain of an artificial intelligence system, including training or test data, frameworks or software libraries, training or inference computing environments, or other components necessary for the training, management, deployment, or maintenance of an artificial intelligence system; (C) activity of foreign entities of concern to clandestinely, fraudulently, or otherwise maliciously access the systems of covered persons for purposes of illicit technology transfer or otherwise gaining unfair economic advantage, including through techniques to extract a model's technical capabilities to replicate, develop, or improve a foreign artificial intelligence model without authorization by the covered person; (D) activity of foreign entities of concern to sabotage or otherwise clandestinely degrade artificial intelligence systems or the supply chain of an artificial intelligence system...; (E) observations, emerging concerns, or other inputs from vendors or researchers regarding relevant malicious or clandestine activity of foreign entities of concern toward an artificial intelligence system, its supply chain, or other necessary components; (F) efforts by foreign adversaries or foreign entities to evade detection of malicious activity described in subparagraphs (A), (B), (C) and (D); and (G) any other relevant information the Director of the National Counterintelligence and Security Center and the Assistant Director of the Federal Bureau of Investigation for the Counterintelligence Division deem appropriate.Sec. 7(a)(12)’’ means information on— (A) efforts by foreign adversary countries to use products or research of covered personscovered personThe term “covered person” means a non-Federal person who— (A) is a United States person; (B) develops, deploys, or operates artificial intelligence models or critical enabling infrastructure; and (C) provides the services described in subparagraph (B) to a Federal department or agency.Sec. 7(a)(5) ... (G) any other relevant information the Director of the National Counterintelligence and Security Center and the Assistant Director of the Federal Bureau of Investigation for the Counterintelligence Division deem appropriate.

(b) BEST PRACTICES.—Not later than 90 days after the date of the enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall, in collaboration with the Director and the Director of the National Institute of Standards and Technology ... convene a multi-stakeholder process to encourage the development and adoption of best practices relating to addressing supply chain risks associated with training and maintaining artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) models ...

(c) ESTABLISHMENT OF PILOT PROGRAM ON SHARING OF INTELLIGENCE AND THREAT INFORMATIONthreat informationThe term “threat information” means information on— (A) efforts by foreign adversary countries to use products or research of covered persons or other entities or individuals to generate synthetic media for foreign-directed influence campaigns, develop and manage computer network exploitation campaigns, design or develop weapons systems, or enhance surveillance capabilities in ways that undermine the privacy or threaten the security of citizens of the United States; (B) threats posed by foreign entities of concern, including indications of compromise to networks associated with covered persons or other technical indicators, indicating a compromise to the confidentiality, integrity, or availability of an artificial intelligence system, or to the supply chain of an artificial intelligence system, including training or test data, frameworks or software libraries, training or inference computing environments, or other components necessary for the training, management, deployment, or maintenance of an artificial intelligence system; (C) activity of foreign entities of concern to clandestinely, fraudulently, or otherwise maliciously access the systems of covered persons for purposes of illicit technology transfer or otherwise gaining unfair economic advantage, including through techniques to extract a model's technical capabilities to replicate, develop, or improve a foreign artificial intelligence model without authorization by the covered person; (D) activity of foreign entities of concern to sabotage or otherwise clandestinely degrade artificial intelligence systems or the supply chain of an artificial intelligence system...; (E) observations, emerging concerns, or other inputs from vendors or researchers regarding relevant malicious or clandestine activity of foreign entities of concern toward an artificial intelligence system, its supply chain, or other necessary components; (F) efforts by foreign adversaries or foreign entities to evade detection of malicious activity described in subparagraphs (A), (B), (C) and (D); and (G) any other relevant information the Director of the National Counterintelligence and Security Center and the Assistant Director of the Federal Bureau of Investigation for the Counterintelligence Division deem appropriate.Sec. 7(a)(12) WITH COVERED PERSONScovered personThe term “covered person” means a non-Federal person who— (A) is a United States person; (B) develops, deploys, or operates artificial intelligence models or critical enabling infrastructure; and (C) provides the services described in subparagraph (B) to a Federal department or agency.Sec. 7(a)(5).—(1) IN GENERAL.—Not later than 180 days after the date of the enactment of this Act, the Director shall, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, establish a pilot program to assess the feasibility and advisability of facilitating the secure sharing with covered persons of intelligence and threat informationthreat informationThe term “threat information” means information on— (A) efforts by foreign adversary countries to use products or research of covered persons or other entities or individuals to generate synthetic media for foreign-directed influence campaigns, develop and manage computer network exploitation campaigns, design or develop weapons systems, or enhance surveillance capabilities in ways that undermine the privacy or threaten the security of citizens of the United States; (B) threats posed by foreign entities of concern, including indications of compromise to networks associated with covered persons or other technical indicators, indicating a compromise to the confidentiality, integrity, or availability of an artificial intelligence system, or to the supply chain of an artificial intelligence system, including training or test data, frameworks or software libraries, training or inference computing environments, or other components necessary for the training, management, deployment, or maintenance of an artificial intelligence system; (C) activity of foreign entities of concern to clandestinely, fraudulently, or otherwise maliciously access the systems of covered persons for purposes of illicit technology transfer or otherwise gaining unfair economic advantage, including through techniques to extract a model's technical capabilities to replicate, develop, or improve a foreign artificial intelligence model without authorization by the covered person; (D) activity of foreign entities of concern to sabotage or otherwise clandestinely degrade artificial intelligence systems or the supply chain of an artificial intelligence system...; (E) observations, emerging concerns, or other inputs from vendors or researchers regarding relevant malicious or clandestine activity of foreign entities of concern toward an artificial intelligence system, its supply chain, or other necessary components; (F) efforts by foreign adversaries or foreign entities to evade detection of malicious activity described in subparagraphs (A), (B), (C) and (D); and (G) any other relevant information the Director of the National Counterintelligence and Security Center and the Assistant Director of the Federal Bureau of Investigation for the Counterintelligence Division deem appropriate.Sec. 7(a)(12) germane to the securing of the supply chain risks associated with training and maintaining artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) models procured by the Federal Government. (2) PARTICIPATION.—The Director may not select or exclude covered personscovered personThe term “covered person” means a non-Federal person who— (A) is a United States person; (B) develops, deploys, or operates artificial intelligence models or critical enabling infrastructure; and (C) provides the services described in subparagraph (B) to a Federal department or agency.Sec. 7(a)(5) to participate in the pilot program in a manner that provides a competitive advantage or procurement preference to any covered personcovered personThe term “covered person” means a non-Federal person who— (A) is a United States person; (B) develops, deploys, or operates artificial intelligence models or critical enabling infrastructure; and (C) provides the services described in subparagraph (B) to a Federal department or agency.Sec. 7(a)(5) ... (3) DURATION.—The Director shall carry out the pilot program ... for not less than a 3-year period ...

(d)-(f) PARTICIPATION REQUIREMENTS.—(1) CRITERIA.—The Director shall establish criteria governing engagement with covered personscovered personThe term “covered person” means a non-Federal person who— (A) is a United States person; (B) develops, deploys, or operates artificial intelligence models or critical enabling infrastructure; and (C) provides the services described in subparagraph (B) to a Federal department or agency.Sec. 7(a)(5) under the pilot program ... (e) INTELLIGENCE SHARING STRUCTURE.—(1) AUTHORIZED MODES.—Under the pilot program required by subsection (c), the Director may authorize the sharing of intelligence and threat informationthreat informationThe term “threat information” means information on— (A) efforts by foreign adversary countries to use products or research of covered persons or other entities or individuals to generate synthetic media for foreign-directed influence campaigns, develop and manage computer network exploitation campaigns, design or develop weapons systems, or enhance surveillance capabilities in ways that undermine the privacy or threaten the security of citizens of the United States; (B) threats posed by foreign entities of concern, including indications of compromise to networks associated with covered persons or other technical indicators, indicating a compromise to the confidentiality, integrity, or availability of an artificial intelligence system, or to the supply chain of an artificial intelligence system, including training or test data, frameworks or software libraries, training or inference computing environments, or other components necessary for the training, management, deployment, or maintenance of an artificial intelligence system; (C) activity of foreign entities of concern to clandestinely, fraudulently, or otherwise maliciously access the systems of covered persons for purposes of illicit technology transfer or otherwise gaining unfair economic advantage, including through techniques to extract a model's technical capabilities to replicate, develop, or improve a foreign artificial intelligence model without authorization by the covered person; (D) activity of foreign entities of concern to sabotage or otherwise clandestinely degrade artificial intelligence systems or the supply chain of an artificial intelligence system...; (E) observations, emerging concerns, or other inputs from vendors or researchers regarding relevant malicious or clandestine activity of foreign entities of concern toward an artificial intelligence system, its supply chain, or other necessary components; (F) efforts by foreign adversaries or foreign entities to evade detection of malicious activity described in subparagraphs (A), (B), (C) and (D); and (G) any other relevant information the Director of the National Counterintelligence and Security Center and the Assistant Director of the Federal Bureau of Investigation for the Counterintelligence Division deem appropriate.Sec. 7(a)(12) ... (2) LIMITATION.—Any mechanism established under this section shall be limited to the dissemination of intelligence and threat informationthreat informationThe term “threat information” means information on— (A) efforts by foreign adversary countries to use products or research of covered persons or other entities or individuals to generate synthetic media for foreign-directed influence campaigns, develop and manage computer network exploitation campaigns, design or develop weapons systems, or enhance surveillance capabilities in ways that undermine the privacy or threaten the security of citizens of the United States; (B) threats posed by foreign entities of concern, including indications of compromise to networks associated with covered persons or other technical indicators, indicating a compromise to the confidentiality, integrity, or availability of an artificial intelligence system, or to the supply chain of an artificial intelligence system, including training or test data, frameworks or software libraries, training or inference computing environments, or other components necessary for the training, management, deployment, or maintenance of an artificial intelligence system; (C) activity of foreign entities of concern to clandestinely, fraudulently, or otherwise maliciously access the systems of covered persons for purposes of illicit technology transfer or otherwise gaining unfair economic advantage, including through techniques to extract a model's technical capabilities to replicate, develop, or improve a foreign artificial intelligence model without authorization by the covered person; (D) activity of foreign entities of concern to sabotage or otherwise clandestinely degrade artificial intelligence systems or the supply chain of an artificial intelligence system...; (E) observations, emerging concerns, or other inputs from vendors or researchers regarding relevant malicious or clandestine activity of foreign entities of concern toward an artificial intelligence system, its supply chain, or other necessary components; (F) efforts by foreign adversaries or foreign entities to evade detection of malicious activity described in subparagraphs (A), (B), (C) and (D); and (G) any other relevant information the Director of the National Counterintelligence and Security Center and the Assistant Director of the Federal Bureau of Investigation for the Counterintelligence Division deem appropriate.Sec. 7(a)(12) and shall not establish standards, requirements, or best practices governing artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) development or deployment. (f) TAILORING, HANDLING, AND PROTECTION OF INTELLIGENCE.—(1) PROCEDURES REQUIRED.—The Director shall codify procedures to tailor, sanitize, or downgrade the classification level of intelligence shared under the pilot program ...

(g) 3 PERMISSIBLE USE AND NONDISCLOSURE.—(1) PERMISSIBLE USE.—Intelligence shared under the pilot program required by subsection (c) may be used solely for detecting, preventing, or mitigating malicious foreign activity targeting the supply chains associated with training and maintaining artificial intelligenceartificial intelligenceThe term “artificial intelligence” has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).Sec. 2(2) models procured by the Federal Government for intelligence collection, intellectual property theft, and other malicious activities. (2) NONDISCLOSURE.—A covered personcovered personThe term “covered person” means a non-Federal person who— (A) is a United States person; (B) develops, deploys, or operates artificial intelligence models or critical enabling infrastructure; and (C) provides the services described in subparagraph (B) to a Federal department or agency.Sec. 7(a)(5) participating in the pilot program may not disclose any intelligence shared under the pilot program required by subsection (c), except as expressly authorized by the Director acting through the Center.

(h)-(l) PRIVACY AND CIVIL LIBERTIES.—In planning and coordinating the pilot program required by subsection (c), the Director shall, acting through the Center, consult with the Civil Liberties Protection Officer of the Office of the Director of National Intelligence. (i) EVALUATION AND REPORTING.—... (j) RULE OF CONSTRUCTION.—Nothing in this section shall be construed— (1) to authorize the collection of intelligence on United States persons not authorized by another provision of law; (2) to require the disclosure of classified information to unauthorized persons; or (3) to establish commercial, competition, or technology policy outside the purview of the intelligence community. (k) EXEMPTION FROM DISCLOSURE; PROTECTION.—Any information shared by a covered personcovered personThe term “covered person” means a non-Federal person who— (A) is a United States person; (B) develops, deploys, or operates artificial intelligence models or critical enabling infrastructure; and (C) provides the services described in subparagraph (B) to a Federal department or agency.Sec. 7(a)(5) or other entity or individual with the United States Government pursuant to this section— (1) shall be exempt from disclosure and withheld, without discretion, from the public, pursuant to section 552(b)(3)(B) of title 5, United States Code ...; and (2) shall not be deemed a waiver of any applicable privilege or protection, including trade secret protection. (l) PROTECTION FROM LIABILITY.—No cause of action shall lie or be maintained in any court against any covered personcovered personThe term “covered person” means a non-Federal person who— (A) is a United States person; (B) develops, deploys, or operates artificial intelligence models or critical enabling infrastructure; and (C) provides the services described in subparagraph (B) to a Federal department or agency.Sec. 7(a)(5) for sharing information with the United States Government or another covered personcovered personThe term “covered person” means a non-Federal person who— (A) is a United States person; (B) develops, deploys, or operates artificial intelligence models or critical enabling infrastructure; and (C) provides the services described in subparagraph (B) to a Federal department or agency.Sec. 7(a)(5) pursuant to this section.

Directs the NSA Director, in coordination with CISA and NIST, to convene a multi-stakeholder process on AI supply-chain best practices and to establish a 3-year pilot program for secure sharing of intelligence and threat information with covered persons — U.S. non-federal entities that develop, deploy, or operate AI models or critical enabling infrastructure for federal agencies. The operative duties (establishing the pilot, setting criteria, codifying handling procedures) fall on the NSA Director. The only private-facing constraint is a nondisclosure duty on covered persons participating in the pilot: they may not disclose shared intelligence except as authorized. The section also provides FOIA exemptions and liability protection for information covered persons voluntarily share with the government.

Compliance actions 1 item
3
Covered personscovered personThe term “covered person” means a non-Federal person who— (A) is a United States person; (B) develops, deploys, or operates artificial intelligence models or critical enabling infrastructure; and (C) provides the services described in subparagraph (B) to a Federal department or agency.Sec. 7(a)(5) participating in the NSA intelligence-sharing pilot must not disclose any intelligence shared with them under the program except as expressly authorized by the NSA Director acting through the AI Security Center, and may use it solely to detect, prevent, or mitigate malicious foreign activity targeting AI model supply chains.

Passage Likelihood

Low
Status Introduced
Chamber No passage
Committee No action
Majority party (No data)
Bipartisan No
Prior session None

Legislative History

2026-07-21 Read twice and referred to the Committee on Commerce, Science, and Transportation.

Entry Last Reviewed

2026-08-05
AI generated