<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="H690E544F585847CCA36840B5C75A1FD6" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>119 HR 10189 IH: Defense AI Reliability and Reporting Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2026-08-31</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">119th CONGRESS</congress><session display="yes">2d Session</session><legis-num display="yes">H. R. 10189</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20260831">August 31, 2026</action-date><action-desc><sponsor name-id="J000305">Ms. Jacobs</sponsor> (for herself, <cosponsor name-id="M001224">Mr. Moran</cosponsor>, and <cosponsor name-id="W000830">Mr. Whitesides</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HAS00">Committee on Armed Services</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To amend title 10, United States Code, to direct the Secretary of Defense to establish an artificial intelligence incident and vulnerability reporting program, and for other purposes.</official-title></form><legis-body id="H466B74BBA0094D0781D6108C477C5D77" style="OLC"> 
<section id="H4F59302F09DC4A44A2B56EF621E88607" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Defense AI Reliability and Reporting Act</short-title></quote>.</text></section> <section id="HB2FC1AE7C32F477E8A4C21BECA04849E" section-type="subsequent-section"><enum>2.</enum><header>Department of Defense AI incident and vulnerability reporting program</header><text display-inline="no-display-inline"><external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/10/131">Chapter 131</external-xref> of title 10, United States Code, is amended by inserting after <external-xref legal-doc="usc" parsable-cite="usc/10/2224a">section 2224a</external-xref> the following new section:</text> 
<quoted-block style="USC" display-inline="no-display-inline" id="H11566C81C80D494E9C5022C0E28008AA"> 
<section id="H97A7FF7BDF1E4FA7A57703F0FA82543D"><enum>2224b.</enum><header>Artificial intelligence incident and vulnerability reporting program</header> 
<subsection id="H42246D0CFB5941B59F25C3A8B6F168A1"><enum>(a)</enum><header>In general</header><text>The Secretary of Defense shall establish a centralized Department-wide program for the reporting, tracking, analysis, and remediation of covered AI incidents and covered AI vulnerabilities arising from the development, testing, procurement, fielding, or operation of artificial intelligence systems within the Department of Defense.</text></subsection> <subsection id="H47023FA6B44F40D095C168063123E2E6" display-inline="no-display-inline"><enum>(b)</enum><header>Purpose</header><text>The purpose of the program established under subsection (a) shall be to—</text> 
<paragraph id="HBEB5BE2B8D1642DFBFDCB0CA495DF2CB"><enum>(1)</enum><text display-inline="yes-display-inline">identify recurring risks, failure modes, vulnerabilities, and systemic weaknesses in artificial intelligence systems, including risks or failure modes arising from human-machine teaming;</text></paragraph> <paragraph id="HD84A45215E9C4C5BBCCFEBF17FBF628A"><enum>(2)</enum><text>support mitigation of significant risks; and</text></paragraph> 
<paragraph id="HA2F765AC00F445B6A8D7023D88715D63"><enum>(3)</enum><text>inform testing, procurement, cybersecurity, and deployment decisions to improve the safety, security, reliability, and operational effectiveness of such systems.</text></paragraph></subsection> <subsection id="H3E0E07809D5142EABC3C2CAE80E4F6B1"><enum>(c)</enum><header>Requirements for program</header><text>The program shall—</text> 
<paragraph id="H700C36D2740646DBA0FC9BB94CD22D98"><enum>(1)</enum><text>be designed using practices drawn from established safety incident reporting programs, vulnerability disclosure programs, and programs to identify and develop lessons learned;</text></paragraph> <paragraph id="H0B1AD29D41C34207867FF9B4FDC48A0E"><enum>(2)</enum><text>emphasize non-punitive reporting, protection of sensitive and proprietary information, and dissemination of lessons learned, as appropriate; and</text></paragraph> 
<paragraph id="H33F4DA3A77804ED29E7C861C89A975CC"><enum>(3)</enum><text display-inline="yes-display-inline">include a mechanism to enable timely access to and sharing of relevant logs, system data, and model information as necessary to support analysis and response.</text></paragraph></subsection> <subsection id="HD7B348F15D94467D94D027F329A9F6ED"><enum>(d)</enum><header>Designation of official</header><text>The Secretary shall designate an appropriate official for the reporting, tracking, analysis, and remediation of covered AI incidents and covered AI vulnerabilities under this section. The Secretary, acting through such official, shall receive and standardize reports, conduct trend analysis, identify recurring risks and failure modes, and issue guidance, alerts, and recommendations, as appropriate.</text></subsection> 
<subsection id="H4F37CABC998642FDBA71675CFE175257"><enum>(e)</enum><header>Reporting and categorization</header> 
<paragraph id="HE2C211FEDFA8415FBC5B75A745B045A1" display-inline="yes-display-inline"><enum>(1)</enum><text>The Secretary shall require prompt reporting to the official designated under subsection (d) of—</text> <subparagraph id="HD527C6DCDBF94208ABA9A90B3FEE30B2" indent="up1"><enum>(A)</enum><text>any covered AI incident; and</text></subparagraph> 
<subparagraph id="HB8055F7F53394F8AAC2D064B0D026D3F" indent="up1"><enum>(B)</enum><text>any covered AI vulnerability.</text></subparagraph></paragraph> <paragraph id="H5CF8F088BAE34491B6F6D473F3F2087B" indent="up1"><enum>(2)</enum><text>The Secretary, acting through the official, shall categorize each incident or vulnerability reported to the official according to whether the incident or vulnerability requires—</text> 
<subparagraph id="H21A6C5A2E1F54C5D9C6EA55EBE59A5D5"><enum>(A)</enum><text>a Department-wide response;</text></subparagraph> <subparagraph id="H31E646D656094FBDBD9C9ACDFDD1FFC8"><enum>(B)</enum><text>a response at the program level; or</text></subparagraph> 
<subparagraph id="H1C74DACB19E94C9798639C334BDFB356"><enum>(C)</enum><text>a response at a local level.</text></subparagraph></paragraph></subsection> <subsection id="H38286A1E03A9409082EBFE07545EC4A8"> <enum>(f)</enum> <header>Department-Wide and program-Level matters</header> <paragraph id="H982C7DD61C2E450C8BF3D597DAE6E2EF" display-inline="yes-display-inline"> <enum>(1)</enum> <text>In the case of any incident or vulnerability categorized under subsection (e)(2)(A) or (B), the Secretary, acting through the official designated under subsection (d), shall coordinate any responses that the Secretary considers appropriate, such as remediation, retesting, mitigation measures, or deployment restrictions.</text>
            </paragraph>
            <paragraph id="H3EE110A5C1F94D83BC28A13B224E3C0E" indent="up1">
              <enum>(2)</enum>
 <text>In addition, in the case of any incident or vulnerability described in subsection (e)(2)(A), the Secretary, acting through the official, shall require—</text>
              <subparagraph id="HC2F44EDE98084CF2B9E9D7B1E59E1EF8">
                <enum>(A)</enum>
 <text>a documented corrective action plan; and</text> </subparagraph> <subparagraph id="HD96AD328EAAE409F835D070481239537"> <enum>(B)</enum> <text>validation that the mitigation measures, if any, in such plan have been implemented before continued operational use.</text>
              </subparagraph>
            </paragraph>
          </subsection> 
<subsection id="H9EF80C4EC65043CBBC0AF3AE6EAE590A"><enum>(g)</enum><header>Protection of reports</header> 
<paragraph id="HD8108D34F3104CCAA7CB1285B02092E2" display-inline="yes-display-inline"><enum>(1)</enum><text>The Secretary shall establish a protected disclosure process, informed by established vulnerability disclosure practices, through which members of the Armed Forces, civilian employees, contractors, and subcontractors at any tier may report covered AI incidents and covered AI vulnerabilities in good faith.</text></paragraph> <paragraph id="HB351D85A014749FD8895D47E6C4D265E" indent="up1"><enum>(2)</enum><text>The Secretary shall ensure that a person making a report in good faith under paragraph (1) is not, on the basis of that report alone, subject to adverse contract action, subject to adverse personnel action, or otherwise retaliated against by the Department.</text></paragraph></subsection> 
<subsection id="H064BA8517A634B288CE71138E6F91ECF"><enum>(h)</enum><header>Protection of information</header><text>The Secretary shall establish procedures to protect sensitive, proprietary, and classified information submitted through the protected disclosure process under subsection (g).</text></subsection> <subsection id="H991A4B8B30344BEF953B0F2614092B52"><enum>(i)</enum><header>Annual report</header> <paragraph id="H4A0AE337BF8747828E75DB6CC3188059" display-inline="yes-display-inline"><enum>(1)</enum><text>In each of years 2027 through 2031, the Secretary shall submit to the congressional defense committees an annual report on the program. The report shall include—</text> 
<subparagraph id="HA6BB9E306FC34E539232A632ABF12DB6" indent="up1"><enum>(A)</enum><text>the number of reports made of incidents and vulnerabilities and the categorizations of such reports;</text></subparagraph> <subparagraph id="HD8D441A33D864C79BE526FCCCC61C3CF" indent="up1"><enum>(B)</enum><text>a summary of significant trends, recurring risks, systemic issues, and corrective actions taken in response;</text></subparagraph> 
<subparagraph id="H447622EFBF84452BA443D8900A87C19F" indent="up1"><enum>(C)</enum><text>in the case of any covered AI incident resulting in the loss of life of, or in bodily harm to, a member of the Army, Navy, Marine Corps, Air Force, or Space Force—</text> <clause id="HE8BB25462FFC4710918CC058495DC188"><enum>(i)</enum><text>a description of the incident, including the system or systems involved and the operational context;</text></clause> 
<clause id="HEC5135C7BC284FCFB1D620F148A64E62"><enum>(ii)</enum><text>the date and time the incident occurred;</text></clause> <clause id="HACAF64F849384D85B0C2BC75466ABA65"><enum>(iii)</enum><text>an assessment of the cause and operational consequence of the incident; and</text></clause> 
<clause id="H50FB4090E14449B99E15856DEA98A6AF"><enum>(iv)</enum><text>any corrective actions taken; and</text></clause></subparagraph> <subparagraph id="H83B488CDA7B84A0EB4DC0A158F22F2F6" indent="up1"><enum>(D)</enum><text>any recommendations for changes to testing, procurement, cybersecurity, or deployment policies relating to artificial intelligence systems.</text></subparagraph></paragraph> 
<paragraph id="HBC0A2EF38F9B4707A87D25464B1E2D92" indent="up1"><enum>(2)</enum><text>Each report under this subsection shall be submitted in unclassified form but may include a classified annex.</text></paragraph></subsection> <subsection id="HE8B933B8F7EF473B81722982121FA03C"><enum>(j)</enum><header>Definitions</header><text>In this section:</text> 
<paragraph id="H8299DDD972BD4627A030A19028A95F9D"><enum>(1)</enum><text>The term <quote>artificial intelligence</quote> has the meaning given such term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (<external-xref legal-doc="usc" parsable-cite="usc/15/9401">15 U.S.C. 9401</external-xref>).</text></paragraph> <paragraph id="HD75D68F18F614186ABECD7FCC39C7C8E"><enum>(2)</enum><text>The term <quote>covered AI incident</quote> means an event in which an artificial intelligence system—</text> 
<subparagraph id="H44D707F7D9764369B78AD3DF4021CDBC"><enum>(A)</enum><text>causes unintended operational, safety, or security harm;</text></subparagraph> <subparagraph id="H7C75D7690D4B4EB7A9DA988CC1EEA59D"><enum>(B)</enum><text display-inline="yes-display-inline">operates outside authorized parameters or approved safety, legal, or mission guardrails;</text></subparagraph> 
<subparagraph id="H1204CE480F924D81A082798153F65011"><enum>(C)</enum><text>materially degrades mission performance or reliability in a real-world or operationally representative environment;</text></subparagraph> <subparagraph id="H8B3BF366660F4544BAE920BAC46482BC"><enum>(D)</enum><text>fails to respond to an operator disengage command;</text></subparagraph> 
<subparagraph id="HF7CB4AD5F4A746C4858B02A5A61EF0B9"><enum>(E)</enum><text>operates in a manner that, under reasonably foreseeable circumstances, could have resulted in significant unintended operational, safety, or security harm; or</text></subparagraph> <subparagraph id="H752FE797B3D6492191DCDFD23B6DCE83"><enum>(F)</enum><text display-inline="yes-display-inline">operates in a manner that raises concerns regarding system control and autonomy.</text></subparagraph></paragraph> 
<paragraph id="H1A7C77AF598D49FE810AD48BEBFFF806"><enum>(3)</enum><text>The term <quote>covered AI vulnerability</quote> means an exploitable weakness, vulnerability, or systemic issue in an artificial intelligence system or related component that could materially affect mission performance, compromise system integrity, create safety risk, or result in unauthorized or unintended behavior.</text></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></section> </legis-body></bill>

