<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="H8F45017DF12949A7B5F3B18538FFE400" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 HR 9466 IH: AI Development Practices Act of 2024</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2024-09-06</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">118th CONGRESS</congress><session display="yes">2d Session</session><legis-num display="yes">H. R. 9466</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20240906">September 6, 2024</action-date><action-desc><sponsor name-id="B001307">Mr. Baird</sponsor> (for himself and <cosponsor name-id="L000582">Mr. Lieu</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HSY00">Committee on Science, Space, and Technology</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To direct the National Institute of Standards and Technology to catalog and evaluate emerging practices and norms for communicating certain characteristics of artificial intelligence systems, including relating to transparency, robustness, resilience, security, safety, and usability, and for other purposes.</official-title></form><legis-body id="H41C14B8C260543F385D6C42C9B94F9C3" style="OLC"><section id="HFA27BC0139E044A68909D69DC104092D" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>AI Development Practices Act of 2024</short-title></quote>.</text></section><section id="H9F68D09A939E4253BEA669DE0AF65200"><enum>2.</enum><header>NIST research on development best practices</header><text display-inline="no-display-inline">Section 22A of the National Institute of Standards and Technology Act (<external-xref legal-doc="usc" parsable-cite="usc/15/278h-1">15 U.S.C. 278h–1</external-xref>) is amended—</text><paragraph id="H290F3FFF91FA45CA824D520C7AA2A70C"><enum>(1)</enum><text>by redesignating subsection (h) as subsection (i); and</text></paragraph><paragraph id="HBE2B4C96B6034CAC82654CF5249F6AF0"><enum>(2)</enum><text>by inserting after subsection (g) the following new subsection:</text><quoted-block id="HD330FDFD788E49109346E04DCC7A12CC" style="OLC"><subsection id="H740B2456F2A34BF18C69A8FBED1293C2"><enum>(h)</enum><header>Assessment of the practices of artificial intelligence development</header><paragraph id="H1F13627DDCF54ED195A5FB134B93B4D9" commented="no"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">The Director of the National Institute of Standards and Technology (in this subsection referred to as the <quote>Director</quote>) shall, subject to the availability of appropriations, develop, and periodically update, in collaboration with other public and private sector organizations, voluntary guidance for practices and guidelines relating to the development, release, and assessment of artificial intelligence systems. Such guidelines shall satisfy the following:</text><subparagraph id="H896A461144E5415780E51EE0BCB9B956" commented="no"><enum>(A)</enum><text display-inline="yes-display-inline">Define methods and guidelines for developing reasonable risk tolerances for various use cases of artificial intelligence systems based on the following:</text><clause id="HB5B03185C5674DF28FE3DC5248CF9786" commented="no"><enum>(i)</enum><text display-inline="yes-display-inline">The risks associated with the intended and unintended applications, use cases, and outcomes of the artificial intelligence system at issue, based on the guidelines specified in the voluntary risk management framework for trustworthy artificial intelligence systems, or successor framework, authorized under subsection (c), which may include different categories of risk, such as the following:</text><subclause id="H4E49B7DB3B054B348EADEC33FCC9B25A" commented="no"><enum>(I)</enum><text>Security risks, including threats to national security.</text></subclause><subclause id="H21AB019A22564403894315F12BBA5832" commented="no"><enum>(II)</enum><text>Economic risks, including threats to economic opportunities.</text></subclause><subclause id="HFA7532EF655348F9B3410DB189387CAC" commented="no"><enum>(III)</enum><text>Social risks, including infringement upon constitutional rights, privileges, or liberties.</text></subclause></clause><clause id="HA281D97B8A00496286D23C0BDFC6E25D" commented="no"><enum>(ii)</enum><text>Such other factors as the Director determines appropriate and consistent with this subsection.</text></clause></subparagraph><subparagraph id="HDE48CAFB03204EAD9A517FE049EC3924" commented="no"><enum>(B)</enum><text display-inline="yes-display-inline">Categorize and list practices and norms for communicating relevant characteristics, including robustness, resilience, security, safety, fairness, privacy, validation, reliability, accountability, and usability, of artificial intelligence systems, and including any characteristics identified by the voluntary risk management framework for trustworthy artificial intelligence systems, or successor framework, authorized under subsection (c). Such practices and norms may relate to the following:</text><clause id="H688D69024C304A008EB2661C4FCE7D3E" commented="no"><enum>(i)</enum><text>Documentation of training and evaluation datasets, such as information and statistics about a dataset’s size, curation, annotation, and sources, and the protocols for a dataset’s selection, creators, provenance, processing, augmentation, filters, inclusion of personally identifiable information, and intellectual property usage.</text></clause><clause id="HFC0A620F2562484C82BAB8AAF15B8ECC" commented="no"><enum>(ii)</enum><text>Documentation of model information, such as a model’s development stages, training objectives, training strategies, inference objectives, capabilities, reproducibility of capabilities, input and output modalities, components, size, and architecture.</text></clause><clause id="H56C26BB75F654A989C30E901A4FE6890" commented="no"><enum>(iii)</enum><text display-inline="yes-display-inline">Evaluation of benchmarks for multi-metric assessments, such as an assessment of an appropriate combination of robustness, resilience, security, safety, fairness, privacy, accuracy, validity, reliability, accountability, usability, transparency, efficiency, and calibration, and any characteristics identified by the voluntary risk management framework for trustworthy artificial intelligence systems, or successor framework, authorized under subsection (c).</text></clause><clause id="H1A7E50BEE07143EB8CBF2270BE16162E" commented="no"><enum>(iv)</enum><text display-inline="yes-display-inline">Metrics and methodologies for evaluations of artificial intelligence systems, such as establishing evaluation datasets.</text></clause><clause id="H5A068716110E4F1B98671B75A508050D" commented="no"><enum>(v)</enum><text>Public reporting of artificial intelligence systems’ capabilities, limitations, and possible areas of appropriate and inappropriate use.</text></clause><clause id="H1FE9D093869F44EB9DF8C2A3A1972CC9" commented="no"><enum>(vi)</enum><text display-inline="yes-display-inline">Disclosure of security practices, such as artificial intelligence red teaming and third-party assessments, that were used in the development of an artificial intelligence system.</text></clause><clause id="HFD4659BF327E4D70BE2D6CFF1EB142FB" commented="no"><enum>(vii)</enum><text display-inline="yes-display-inline">How to release to the public components of an artificial intelligence system or information about an artificial intelligence system, including aspects of the model, associated training data, and license agreements.</text></clause><clause id="HE844436B8D7841289BAD68A0546EC1AB" commented="no"><enum>(viii)</enum><text>Approaches and channels for collaboration and knowledge-sharing of best practices across industry, governments, civil society, and academia.</text></clause><clause id="H18C1848FD4004D4AADCF41CBDB59B80B" commented="no"><enum>(ix)</enum><text>Such other categories as the Director determines appropriate and consistent with this subsection.</text></clause></subparagraph><subparagraph id="HA6814764FC8B483F8A696E03F20BBB76" commented="no"><enum>(C)</enum><text>For each practice and norm categorized and listed in accordance with subparagraph (B), provide recommendations and practices for utilizing such practice or norm.</text></subparagraph></paragraph><paragraph id="HD656ADB4F83B49DE908618B502079EA7" commented="no"><enum>(2)</enum><header>Implementation</header><text display-inline="yes-display-inline">In conducting the Director’s duties under paragraph (1), the Director shall carry out the following:</text><subparagraph id="HBFB02F9BE7014062B9E2DD4E415AE677" commented="no"><enum>(A)</enum><text display-inline="yes-display-inline">Update the voluntary risk management framework for trustworthy artificial intelligence systems, or successor framework, authorized under subsection (c) as the Director determines appropriate.</text></subparagraph><subparagraph id="HAFAEC4E3C3064C94B3BB212325F79D9E" commented="no"><enum>(B)</enum><text>Ensure that voluntary guidance developed in paragraph (1) is based on international standards and industry best practices to the extent possible and practical.</text></subparagraph><subparagraph id="H9BCD113D75DB4D88A9A19C3BDD2B8C43" commented="no"><enum>(C)</enum><text>Not prescribe or otherwise require the use of specific information or communications technology products or services.</text></subparagraph><subparagraph id="H3AC217BCA930489B97545D339AE927CC" commented="no"><enum>(D)</enum><text>Collaborate with public, industry, and academic entities as the Director determines appropriate, including conducting periodic outreach to receive public input from public, industry, and academic stakeholders.</text></subparagraph></paragraph><paragraph id="HD09FCED611284160B371C5AB7391560C" commented="no"><enum>(3)</enum><header>Report</header><text display-inline="yes-display-inline">In conducting the Director’s duties under paragraph (1), the Director shall, not later than 18 months after the date of the enactment of this subsection, brief the Committee on Science, Space, and Technology of the House of Representatives and the Committee on Commerce, Science, and Transportation of the Senate on the following:</text><subparagraph id="H2D4FC2E0AEE942C5B0133FFB809B0859" commented="no"><enum>(A)</enum><text display-inline="yes-display-inline">New or updated materials, programs, or systems that were produced as a result of carrying out this subsection.</text></subparagraph><subparagraph id="H30D50DF734324B458C4AB8059D672EC2" commented="no"><enum>(B)</enum><text>Policy recommendations of the Director that could facilitate and improve communication and coordination between the private sector and relevant Federal agencies regarding implementing the recommended practices identified in this subsection.</text></subparagraph></paragraph><paragraph id="HE288287CFE4843D19E7EB932CF5BD4CE"><enum>(4)</enum><header>Definitions</header><text>In this subsection:</text><subparagraph id="H1F1F1936F2DD4CE09EB8B45740FC8B68" commented="no"><enum>(A)</enum><header>Artificial intelligence red teaming</header><text display-inline="yes-display-inline">The term <quote>artificial intelligence red teaming</quote> means a structured testing of adversarial efforts to find flaws and vulnerabilities in an artificial intelligence system and identify risks, flaws, and vulnerabilities of artificial intelligence systems, such as harmful outputs from such system, unforeseen or undesirable system behaviors, limitations, and potential risks associated with the misuse of such system.</text></subparagraph><subparagraph id="H4499F3DBCDB64C1392127118B2472957" commented="no"><enum>(B)</enum><header>Artificial intelligence system</header><text display-inline="yes-display-inline">The term <quote>artificial intelligence system</quote> has the meaning given such term in section 7223 of the Advancing American AI Act (<external-xref legal-doc="usc" parsable-cite="usc/40/11301">40 U.S.C. 11301</external-xref> note; as enacted as part of title LXXII of division G of the James M. Inhofe National Defense Authorization Act for Fiscal Year 2023; <external-xref legal-doc="public-law" parsable-cite="pl/117/263">Public Law 117–263</external-xref>).</text></subparagraph></paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></section></legis-body></bill> 

