<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-BAG23E44-KS0-0C-TPM"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 S3205 IS: Federal Artificial Intelligence Risk Management Act of 2023</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2023-11-02</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>118th CONGRESS</congress><session>1st Session</session><legis-num>S. 3205</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20231102">November 2, 2023</action-date><action-desc><sponsor name-id="S347">Mr. Moran</sponsor> (for himself and <cosponsor name-id="S327">Mr. Warner</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To require Federal agencies to use the Artificial Intelligence Risk Management Framework developed by the National Institute of Standards and Technology with respect to the use of artificial intelligence.</official-title></form><legis-body><section id="idf9fc33b8c48247ffa84401d0715bf3a2" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Federal Artificial Intelligence Risk Management Act of 2023</short-title></quote>.</text></section><section id="id9B148D1392FF4EE6B8990D98E1628751"><enum>2.</enum><header>Agency use of artificial intelligence</header><subsection id="id4F2DDA51A5734DA4B03C1F204DD0C83A"><enum>(a)</enum><header>Definitions</header><text>In this section:</text><paragraph id="id4cdc119c99c14779a5e06c9f3dc1d587"><enum>(1)</enum><header>Administrator</header><text>The term <term>Administrator</term> means the Administrator of Federal Procurement Policy.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id951094b1c71f4224a55b8a505941f279"><enum>(2)</enum><header display-inline="yes-display-inline">Agency</header><text>The term <term>agency</term> means any department, independent establishment, Government corporation, or other agency of the executive branch of the Federal Government.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id7bdcd48da2c54befbd9c8e8b9e6f9bfd"><enum>(3)</enum><header display-inline="yes-display-inline">Artificial intelligence</header><text>The term <term>artificial intelligence</term> has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (<external-xref legal-doc="usc" parsable-cite="usc/15/9401">15 U.S.C. 9401</external-xref>). </text></paragraph><paragraph id="id8b635167d3164ad69b24b9f55e25055a"><enum>(4)</enum><header>Director</header><text>The term <term>Director</term> means the Director of the National Institute of Standards and Technology.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ida3b74da4945e42c88f39e88b365ab438"><enum>(5)</enum><header display-inline="yes-display-inline">Framework</header><text>The term <term>framework</term> means document number NIST AI 100–1 of the National Institute of Standards and Technology entitled <quote>Artificial Intelligence Risk Management Framework</quote>, or any successor document.</text></paragraph><paragraph id="idee8645465f534282afd4ab05a6af96fa" commented="no" display-inline="no-display-inline"><enum>(6)</enum><header>Playbook</header><text>The term <term>playbook</term> means the AI RMF Playbook developed by the National Institute of Standards and Technology.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idb7f1516756e348a6ae3bcc5101f2c350"><enum>(7)</enum><header>Profile</header><text>The term <term>profile</term> means an implementation of the artificial intelligence risk management functions, categories, and subcategories for a specific setting or application based on the requirements, risk tolerance, and resources of the framework user.</text></paragraph></subsection><subsection id="idBA965DB028AF4711AC3785F8F6E6EFC0"><enum>(b)</enum><header>Requirements for agency use of artificial intelligence</header><paragraph commented="no" display-inline="no-display-inline" id="idb4c76630174b422f8bdce90e7bac19ff"><enum>(1)</enum><header display-inline="yes-display-inline">OMB Guidance</header><text>Not later than 180 days after the date on which the Director of the National Institute of Standards and Technology issues guidelines under paragraph (2), the Director of the Office of Management and Budget shall issue guidance requiring agencies to incorporate the framework and the guidelines into their artificial intelligence risk management efforts, consistent with such guidelines.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id55333996e17348c3a9500c196285ccae"><enum>(2)</enum><header display-inline="yes-display-inline">NIST Guidelines</header><text>Not later than 1 year after the date of the enactment of this Act, the Director of the National Institute of Standards and Technology shall, in consultation with the Administrator, issue guidance for agencies to incorporate the framework into the artificial intelligence risk management efforts of the agency, which shall— </text><subparagraph commented="no" display-inline="no-display-inline" id="id224f0f4a0797452e8cd6a475a9b796ad"><enum>(A)</enum><text display-inline="yes-display-inline">provide standards, practices, and tools consistent with the framework and how they can leverage the framework to reduce risks to people and the planet for agency implementation in the development, procurement, and use of artificial intelligence; </text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idb1e288c929da40189c497cb4cf9101e9"><enum>(B)</enum><text display-inline="yes-display-inline">specify appropriate cybersecurity strategies and the installation of effective cybersecurity tools to improve security of artificial intelligence systems; </text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id5c0a61f1d06244918847d79a73dd5299"><enum>(C)</enum><text display-inline="yes-display-inline">provide standards—</text><clause commented="no" display-inline="no-display-inline" id="id93c5af4309224c4b84f4e8b2cc6ced3c"><enum>(i)</enum><text display-inline="yes-display-inline">that are consistent with the framework and Circular A–119 of the Office of Management and Budget;</text></clause><clause commented="no" display-inline="no-display-inline" id="idbec66768c073483080ef620278dd41c5"><enum>(ii)</enum><text display-inline="yes-display-inline">that are tailored to risks that could endanger people and the planet; and </text></clause><clause commented="no" display-inline="no-display-inline" id="id6b04e994d7664107bc89d3b1ca8552fe"><enum>(iii)</enum><text display-inline="yes-display-inline">which a supplier of artificial intelligence for the agency must attest to meet before the head of an agency may procure artificial intelligence from that supplier;</text></clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id4b490297fdf043dfb86d434e7bd30af7"><enum>(D)</enum><text display-inline="yes-display-inline">recommend training on the framework and the guidelines for each agency responsible for procuring artificial intelligence;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id3b841befcba847e880a084b982a2e2af"><enum>(E)</enum><text display-inline="yes-display-inline">set minimum requirements for developing profiles for agency use of artificial intelligence consistent with the framework; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id39c72d6efa364d189bbc3ebb45971d72"><enum>(F)</enum><text display-inline="yes-display-inline">develop profiles for framework use for an entity that is a small business concern (as defined in section 3 of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632</external-xref>)).</text></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ide4e0e3622d1344a09ae60a487a67da1c"><enum>(3)</enum><header>Additional requirements</header><subparagraph commented="no" display-inline="no-display-inline" id="id13517b7d3c474510b89eb313ee8a3df0"><enum>(A)</enum><header>Draft contract language</header><text display-inline="yes-display-inline">The Administrator shall, in consultation with the Director, provide draft contract language for each agency to use in procurement that requires a supplier of artificial intelligence—</text><clause commented="no" display-inline="no-display-inline" id="id79aa823297f947808e41c81430ebcb72"><enum>(i)</enum><text display-inline="yes-display-inline">to adhere to certain actions that are consistent with the framework; and</text></clause><clause id="idbaddbbf9967341deaec9ad228a5f3039"><enum>(ii)</enum><text>to provide appropriate access to data, models, and parameters, as defined by the Director, to enable sufficient test and evaluation, verification, and validation. </text></clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id738c9127fbe14076b032195941546c57"><enum>(B)</enum><header>Templates</header><text display-inline="yes-display-inline">The Director of the Office of Management and Budget shall, in consultation with the Director, provide a template for agency use on the guidance issued under paragraph (1) that includes recommended procedures for implementation.</text></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id4079ff0a376349509a3d12821dbdee90"><enum>(4)</enum><header>Conforming requirement</header><text>The head of each agency shall conform any policy, principle, practice, procedure, or guideline governing the design, development, implementation, deployment, use, or evaluation of an artificial intelligence system by the agency to the framework and to the guidance issued under paragraph (1).</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id896e7237aecd4879a710ccbf8b9a84a0"><enum>(5)</enum><header>Supporting material</header><text>In carrying out paragraph (4), the head of each agency may use the supporting materials of the framework, including the playbook. </text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id232b4d3741db4327a8206823fca4b6b0"><enum>(6)</enum><header>Study</header><text>Not later than 1 year after the date of enactment of this Act, the Comptroller General of the United States shall conduct a study on the impact of the application of the framework on agency use of artificial intelligence.</text></paragraph><paragraph id="id0154eca8ae74403f9337e80972640caf" commented="no" display-inline="no-display-inline"><enum>(7)</enum><header>Reporting requirement</header><text>Not later than 1 year after the date of the enactment of this Act, and not less frequently than once every 3 years thereafter, the Director of the Office of Management and Budget shall submit to Congress a report on agency implementation of and conformity to the framework. </text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idd30443b027bd4009b13367ddf214dbc2"><enum>(8)</enum><header>Exception for national security systems</header><text>Nothing in this subsection shall apply to a national security system (as defined in section 3552 of title 44, United States Code).</text></paragraph></subsection><subsection id="id2FEBAD76BCC44D82823127B66EB22BCF"><enum>(c)</enum><header>Requirements for agency procurement of artificial intelligence</header><text>Not later than 1 year after the issuance of guidance pursuant to subsection (b)(1), the Federal Acquisition Regulatory Council shall promulgate regulations that provide for—</text><paragraph id="id5b8ab25918fa4d3db0a949d319b61b2b"><enum>(1)</enum><text>the requirements for the acquisition of artificial intelligence products, services, tools, and systems, to include risk-based compliance with the framework; and</text></paragraph><paragraph id="id2af3b21115bb472fb13329de4e529716" commented="no" display-inline="no-display-inline"><enum>(2)</enum><text>solicitation provisions and contract clauses that include references to the requirements described in paragraph (1) and the framework for use in artificial intelligence acquisitions.</text></paragraph></subsection><subsection id="idacc96a088d0e436baedb271073b70b75"><enum>(d)</enum><header>Artificial intelligence workforce</header><paragraph commented="no" display-inline="no-display-inline" id="id53d60ed654a74ac7a9fe62eb1e43e00a"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than 180 days after the date of the enactment of this Act, the Director of the Office of Management and Budget shall, in consultation with the Administrator of the General Services Administration, establish an initiative to provide to agencies expertise on artificial intelligence pursuant to requests for such expertise by the heads of such agencies.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idec30d976c2dc44d78a31ca9fd4cad697"><enum>(2)</enum><header>Elements</header><text display-inline="yes-display-inline">The initiative established pursuant to paragraph (1) shall include the following:</text><subparagraph id="idac83a8d418394f1c959179eeffb15cb7"><enum>(A)</enum><text>The recruitment and hiring of interdisciplinary experts who can assist agencies in the development, procurement, use, and assessment of artificial intelligence tools.</text></subparagraph><subparagraph id="idc64e8225b3e14a4f98fac4183efe3868"><enum>(B)</enum><text>A process for establishing development and deployment guidelines and tools for managing artificial intelligence risks under which the initiative can assist agencies.</text></subparagraph><subparagraph id="id478c85357a174664ac0ef0fd9dbbf3aa"><enum>(C)</enum><text>Consultation with existing initiatives, including United States Digital Service and the technology transformation services of the General Services Administration, to incorporate best practices for assisting agencies in the development, procurement, use, and assessment of artificial intelligence tools. </text></subparagraph></paragraph></subsection><subsection id="id06c5abc528b14619a0981e092018e2ed"><enum>(e)</enum><header>Testing and evaluation of artificial intelligence</header><paragraph commented="no" display-inline="no-display-inline" id="idc14457f13fed4edea456daa90d2dd09a"><enum>(1)</enum><header>Study</header><text>Not later than 90 days after the date of the enactment of this Act, the Director of the National Institute of Standards and Technology shall complete a study to review the existing and forthcoming voluntary consensus standards for the test, evaluation, verification, and validation of artificial intelligence acquisitions.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id0d86222ea7494af28756ed358eda7898"><enum>(2)</enum><header>Development of voluntary consensus standards</header><text display-inline="yes-display-inline">Not later than 90 days after the date of the completion of the study required by paragraph (1), the Director shall—</text><subparagraph id="id81ca36e02fc94e7e8360930d6417e390" commented="no"><enum>(A)</enum><text>convene relevant stakeholders to develop voluntary consensus standards for the test, evaluation, verification, and validation of artificial intelligence acquisitions; </text></subparagraph><subparagraph id="ida3ebae5a4b6549348870c474e0da966f" commented="no"><enum>(B)</enum><text>upon completion of the standards described in subparagraph (A) or within 1 year, whichever is sooner—</text><clause id="id2f480869fff1408cbc76faf870168b93" commented="no"><enum>(i)</enum><text>develop methods and principles, based on the standards described in subparagraph (A), for the conduct of test, evaluation, verification, and validation of artificial intelligence acquisitions;</text></clause><clause id="id11c028dedbf242738585ba86f798b105" commented="no"><enum>(ii)</enum><text>establish the resources for the conduct of test, evaluation, verification, and validation of artificial intelligence acquisitions;</text></clause><clause id="idd3d1912fafa04d6e936c2edaa81e450c" commented="no"><enum>(iii)</enum><text>monitor and review all test, evaluation, verification, and validation of artificial intelligence acquisitions; and</text></clause><clause id="id6f4fdf39576f4968a64d12f57d436d88" commented="no"><enum>(iv)</enum><text>review and make recommendations to the head of each agency of risks to people and the plant on relevant artificial intelligence acquisitions; and</text></clause></subparagraph><subparagraph id="id4e144dd897794f66aa03349e51ebe8e6" commented="no"><enum>(C)</enum><text>continuously update the methods and principles described in subparagraph (B)(i) based on evolving voluntary consensus standards. </text></subparagraph></paragraph></subsection></section></legis-body></bill> 

