<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-BAG26E21-8LH-X4-84J"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>119 S5061 IS: Secure Artificial Intelligence Development Act of 2026</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2026-07-21</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>119th CONGRESS</congress><session>2d Session</session><legis-num>S. 5061</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20260721">July 21, 2026</action-date><action-desc><sponsor name-id="S327">Mr. Warner</sponsor> introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSCM00">Committee on Commerce, Science, and Transportation</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To improve the tracking and processing of security and safety incidents and risks associated with artificial intelligence, and for other purposes.</official-title></form><legis-body><section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Secure Artificial Intelligence Development Act of 2026</short-title></quote> or the <quote><short-title>Secure A.I. Development Act of 2026</short-title></quote>.</text></section><section id="iddf8a9086dc7a46e59a42fb658d4c808c"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text><paragraph id="idb1bee050f6fe46ff8a095a14d7c878f9"><enum>(1)</enum><header>Adversarial-artificial intelligence</header><text>The term <term>adversarial-artificial intelligence</term> means techniques or procedures to extract information about the behavior or characteristics of an artificial intelligence system, or to learn how to manipulate an artificial intelligence system, in order to subvert the confidentiality, integrity, or availability of an artificial intelligence system or adjacent system.</text></paragraph><paragraph id="id5d8903c05bf34ef0a3d67c82944257a7"><enum>(2)</enum><header>Artificial intelligence</header><text>The term <term>artificial intelligence</term> has the meaning given the term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (<external-xref legal-doc="usc" parsable-cite="usc/15/9401">15 U.S.C. 9401</external-xref>).</text></paragraph><paragraph id="id59d4b3d47e7f402588f3e211a8ba62fb"><enum>(3)</enum><header>Artificial intelligence safety incident</header><text>The term <term>artificial intelligence safety incident</term> means an event that materially increases the risk that operation of an artificial intelligence system leads to a state in which human life, health, property, or the environment is endangered.</text></paragraph><paragraph id="id2258df46af2b402ea16125084726867e"><enum>(4)</enum><header>Artificial intelligence security incident</header><text>The term <term>artificial intelligence security incident</term> means an event that materially increases—</text><subparagraph id="id69c72525ca0c48558fcd4d93041fefba"><enum>(A)</enum><text>the risk that operation of an artificial intelligence system occurs in a way that enables the unauthorized extraction of information about the behavior or characteristics of an artificial intelligence system by an unauthorized party; or</text></subparagraph><subparagraph id="id38453961e0da48418462f980d688d65d"><enum>(B)</enum><text>the ability to manipulate an artificial intelligence system in order to subvert the confidentiality, integrity, or availability of an artificial intelligence system or adjacent system.</text></subparagraph></paragraph><paragraph id="idbc9043749b07435fb5ef3bab0826469f"><enum>(5)</enum><header>Artificial intelligence security vulnerability</header><text>The term <term>artificial intelligence security vulnerability</term> means a weakness in an artificial intelligence system that could be exploited by a third party to subvert, without authorization, the confidentiality, integrity, or availability of an artificial intelligence system, including through techniques such as—</text><subparagraph id="idcfd63d448ffa4ad3ab1a5f73aaa66a45"><enum>(A)</enum><text>data poisoning;</text></subparagraph><subparagraph id="idb9c0c9afc61f4ab1bd28f15f04d3dc3d"><enum>(B)</enum><text>evasion attacks;</text></subparagraph><subparagraph id="id55050304dfbb4b2b8274fb037c40b4f5"><enum>(C)</enum><text>privacy-based attacks;</text></subparagraph><subparagraph id="id74f30761c9954f0e8323d2154bad6bd1"><enum>(D)</enum><text>model theft or extraction attacks;</text></subparagraph><subparagraph id="id784221a664974a3bb4bc0ea2a66c667f"><enum>(E)</enum><text>attacks designed to circumvent or degrade the safety, alignment, or access control mechanisms of an artificial intelligence system; and</text></subparagraph><subparagraph id="ideb819e8fe8bd442db4efade6f450f0f5"><enum>(F)</enum><text>adversarial machine learning attacks as described in National Institute of Standards and Technology Trustworthy and Responsible Artificial Intelligence 100–2e2025 (relating to Adversarial Machine Learning), or successor publication.</text></subparagraph></paragraph></section><section id="idef3fd906e6c34a61965ebce7391e69ee"><enum>3.</enum><header>Enabling testing of frontier artificial intelligence models prior to public release</header><subsection id="idd29efd167c8a4526a556273e398dcf71"><enum>(a)</enum><header>Definitions</header><text>In this section:</text><paragraph commented="no" display-inline="no-display-inline" id="id6d3fd521ca5c44b6a3b016fb8944496f"><enum>(1)</enum><header>Board</header><text>The term <term>Board</term> means the Artificial Intelligence Risk Board established under subsection (b)(1).</text></paragraph><paragraph id="id30f582f6ff234520813cbbc16d3edac4"><enum>(2)</enum><header>Critical infrastructure</header><text>The term <term>critical infrastructure</term> has the meaning provided in section 1016(e) of the USA Patriot Act of 2001 (<external-xref legal-doc="usc" parsable-cite="usc/42/5195c">42 U.S.C. 5195c(e)</external-xref>).</text></paragraph><paragraph id="idde65b3603726487994f793749ca4757d"><enum>(3)</enum><header>Frontier artificial intelligence model</header><text>The term <term>frontier artificial intelligence model</term> means an artificial intelligence model, or system combining multiple artificial intelligence models, that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety.</text></paragraph><paragraph id="ide188e08dd0004a6c93c19adbf89630dd"><enum>(4)</enum><header>Institute</header><text>The term <term>Institute</term> means the National Institute of Standards and Technology.</text></paragraph><paragraph id="ida3d6080293ce45d2bffe8d64952ccaff"><enum>(5)</enum><header>Secretary</header><text>The term <term>Secretary</term> means the Secretary of Commerce.</text></paragraph></subsection><subsection id="id2582826d38da4a098ea5b5581ba97d68"><enum>(b)</enum><header>The Artificial Intelligence Risk Board</header><paragraph id="idf0dac2c05d284849807aaaf1cac20192"><enum>(1)</enum><header>Establishment</header><subparagraph commented="no" display-inline="no-display-inline" id="id66743c732b824762987448254934f79a"><enum>(A)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than 90 days after the date of the enactment of this Act, the Secretary shall establish within the Institute a board to address artificial intelligence risks.</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id7f1112b607aa4fdeaa8d0364ffb72448"><enum>(B)</enum><header>Designation</header><text display-inline="yes-display-inline">The board established under subparagraph (A) shall be known as the <quote>Artificial Intelligence Risk Board</quote>.</text></subparagraph></paragraph><paragraph id="idd86e69ef0801475ea078fb1109abcd07"><enum>(2)</enum><header>Membership</header><subparagraph id="id19d9095248fa47c69516ba43356cddd3"><enum>(A)</enum><header>Composition</header><text>The Board shall be composed of members who are appointed as follows:</text><clause commented="no" display-inline="no-display-inline" id="id6e3298b0b4914b3e9a5e6b7d67f996c4"> <enum>(i)</enum> <text>One or more members selected by the Director of the National Institute of Standards.</text>
            </clause><clause commented="no" display-inline="no-display-inline" id="id86c9d4dfab184846815c37b2222a117a">
              <enum>(ii)</enum>
 <text>One or more members selected by the Secretary.</text> </clause><clause commented="no" display-inline="no-display-inline" id="idd2b0b685826d4e3fad88b6eacbb847d9"> <enum>(iii)</enum> <text display-inline="yes-display-inline">One or more members selected by the Director of the Cybersecurity and Infrastructure Security Agency.</text>
            </clause><clause commented="no" display-inline="no-display-inline" id="id7d7f76bb949c4765b1b4e1b88bb80e96">
              <enum>(iv)</enum>
 <text>One or more members selected by the Director of the National Security Agency.</text>
            </clause><clause commented="no" display-inline="no-display-inline" id="id30cbe0619ec24f78900856aac11919d9">
              <enum>(v)</enum>
 <text>One or more members selected by the Secretary of the Treasury.</text> </clause></subparagraph><subparagraph id="id0ab74056db8e45109046c619cc347e98"><enum>(B)</enum><header>Nongovernmental experts</header><text>In addition to the members of the Board appointed under subparagraph (A), the Secretary shall appoint members who are not officers or employees of the Federal Government and who the Secretary selects from among individuals who—</text><clause id="iddf1ade68bd224ac1aa1ac38cbee2a609"><enum>(i)</enum><text>are leading technical experts not affiliated with a developer or provider of artificial intelligence systems;</text></clause><clause id="idde17e2d7356d406f84aa0890939ca16e"><enum>(ii)</enum><text>are leading technical experts affiliated with developers or providers of artificial intelligence systems;</text></clause><clause id="idb701aba7abed45689533b6c4dd59c866"><enum>(iii)</enum><text>are individuals with expertise in developing evaluations to test artificial intelligence models; and</text></clause><clause id="idee51e31ebb58481abaed39d8d3e01dcc"><enum>(iv)</enum><text>have knowledge or expertise that the Secretary determines would further the purpose of the duties of the Board.</text></clause></subparagraph></paragraph><paragraph id="idfd2e59704cb0485599d6972016f9ee5d"><enum>(3)</enum><header>Terms and vacancies</header><subparagraph id="id3ec33bdbc91c4ae4adff945274964f74"><enum>(A)</enum><header>Terms</header><text>Each member of the Board shall serve 1 term of not longer than 3 years and may be reappointed for 1 successive term of not longer than 3 years.</text></subparagraph><subparagraph id="id68fd35ee83e14ffcb9bb0c06ac2b9e0b"><enum>(B)</enum><header>Vacancy replacement</header><text>The memebrs of the Board shall develop a vacancy replacement procedure that includes—</text><clause id="iddb53a4a0d6fd4dc9a1dad881902f7d67"><enum>(i)</enum><text>for vacancies occurring due to the end of a member’s term, a vote not later than 90 days before the last day of the member’s term; and</text></clause><clause id="id7a09b24d4c4e47d5b59157bd7c920940"><enum>(ii)</enum><text>for vacancies occurring under subparagraph (C) or for any other reason, the chair of the Board shall nominate a replacement from the same stakeholder category under paragraph (2), to the extent practicable, as the member creating the vacancy, subject to approval by a majority vote of the members of the Board.</text></clause></subparagraph><subparagraph id="id2a61ab9b8be04144a0105a10e71cdaaa"><enum>(C)</enum><header>Removal</header><text>Any member who fails to comply with the conflict of interest policy adopted pursuant to paragraph (5)(D) shall be removed from the Board.</text></subparagraph><subparagraph id="id06948d2a78b442b09ab0b8dc4e1e1389"><enum>(D)</enum><header>Chair</header><text>The chair of the Board shall be selected by a majority vote among a quorum of the members appointed under paragraph (2) and shall serve not more than 1 two-year term.</text></subparagraph></paragraph><paragraph id="id8e947e9fa566406abdb9768e52273ceb"><enum>(4)</enum><header>Member access to classified information</header><subparagraph id="id7044769f815540248b7fc7cc75d0f243"><enum>(A)</enum><header>Access</header><clause id="id82e5dec07fe443c18912adfa7640dc41"><enum>(i)</enum><header>In general</header><text>Not later than 60 days after the date on which a member is first appointed to the Board and before the member is granted access to any classified information necessary to participate in a closed session pursuant to paragraph (5)(F), the Secretary shall determine, for the purposes of the Board, if the member should be restricted from reviewing, discussing, or possessing classified information.</text></clause><clause id="id5e937eccb8d049f6801e6f39d7c1914f"> <enum>(ii)</enum> <header>Management</header> <text>Access to classified information shall be managed in accordance with Executive Order 13526 (<external-xref legal-doc="usc" parsable-cite="usc/50/3161">50 U.S.C. 3161</external-xref> note; relating to classified national security information), or any subsequent corresponding Executive order.</text>
 </clause><clause id="id3f85573c3f6e412791f7237382f54b07"><enum>(iii)</enum><header>Clearance requirement</header><text>The Secretary shall sponsor each member of the Board for a security clearance at the Top Secret level with access to sensitive compartmented information, as appropriate, for the purposes of participating in carrying out the duties of the Board.</text></clause><clause id="id18b07b29b5274f26868693f08605cd12"><enum>(iv)</enum><header>Clearance requirement</header><text>Each member of the Board shall obtain a security clearance unless denied by the appropriate authorities or if the Secretary determines a member should be restricted from reviewing, discussing, or possessing classified information. In either instance, such member shall be removed from the Board and a new member shall be appointed pursuant to the vacancy procedures under paragraph (3)(B) to replace such removed member.</text></clause></subparagraph><subparagraph id="id3b41af46c28d476180d16c8278115bc9"><enum>(B)</enum><header>Protection of information</header><text>A member of the Board granted access to classified information shall protect the classified information in accordance with the applicable requirements for the particular level of classification of the information.</text></subparagraph><subparagraph id="id64999d8b88b341d98d55096506aab665"><enum>(C)</enum><header>Rule of construction</header><text>Nothing in this paragraph shall be construed to affect the existing security clearance of a member of the Board or the authority of a Federal agency to provide or deny a member of the Board access to any specific pieces of classified information.</text></subparagraph></paragraph><paragraph id="idc55e704bf7fd49ac9a91db2765e7703f"><enum>(5)</enum><header>Procedures</header><subparagraph id="id0cce6b154645463592babb063a92b54a"> <enum>(A)</enum> <header>Designated federal officer</header> <text>The Secretary shall designate a Federal officer or employee to serve as the designated Federal officer of the Board, consistent with the requirements of <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/5/10">chapter 10</external-xref> of title 5, United States Code (common known as the <quote>Federal Advisory Committee Act</quote>).</text>
 </subparagraph><subparagraph id="id72719eaa29ba45c8b72a0d94affd46d3"><enum>(B)</enum><header>Initial meeting and bylaws</header><text>Not later than 120 days after the date of the enactment of this Act, the Board shall convene and establish bylaws that—</text><clause id="id0871d0091b3e40a2a0819370b936401c"><enum>(i)</enum><text>govern quorum and voting rules, including implementation of the decisionmaking majority voting requirement specified in paragraph (5)(C)(ii); and</text></clause><clause id="id9a8c010daf5c492ca8c58f51b3962061"><enum>(ii)</enum><text>set deliverable timelines and meeting schedules.</text></clause></subparagraph><subparagraph id="idfc1091f1388a4981bdaef2b60bff2cea"><enum>(C)</enum><header>Operating procedures</header><text>Unless otherwise specified, the Board shall adopt written procedures governing its meetings, consistent with <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/5/10">chapter 10</external-xref> of title 5, United States Code, that include—</text><clause id="id1daf4770603040439dcb5deb4e6f445f"><enum>(i)</enum><text>requirements for public notice of meetings and the maintenance of records and minutes;</text></clause><clause id="idf463039f45b5493c8fdc71d97908a8b7"><enum>(ii)</enum><text>decision making by majority vote of those present and voting;</text></clause><clause id="idbba2bb35f057419b90728f83b7359c3b"><enum>(iii)</enum><text>authorization for the establishment of subgroups as necessary, subject to the approval of the chair of the Board; and</text></clause><clause id="id6b8fa860353f4bf7a334b6a334a8d29f"> <enum>(iv)</enum> <text>approval of the meeting agendas by the chair in consultation with the designated Federal officer under subparagraph (A) to ensure compliance with applicable laws.</text>
 </clause></subparagraph><subparagraph id="idad66427d81d14dc29231062cc6981a00"><enum>(D)</enum><header>Conflict-of-interest policy</header><clause id="ide77c1e2dfa99402e841712cc6f12c204"><enum>(i)</enum><header>In general</header><text>The Board shall adopt and enforce a written conflict of interest policy to ensure that members of the Board have a fiduciary responsibility to the Board, a duty to report conflicts of interest, including the appearance of a conflict of interest, and do not participate in deliberations or votes from which they personally or their employer would directly and materially benefit.</text></clause><clause id="id0d59bf53831543128754fed9c54f2cb1"><enum>(ii)</enum><header>Required disclosures</header><text>The policy under clause (i) shall require each member to publicly disclose all relevant financial and employment relationships and include recusal procedures in the event of a conflict.</text></clause><clause id="id0366c41a02a24279b764a46f7e1d8500"> <enum>(iii)</enum> <header>Records</header> <text>The designated Federal officer under subparagraph (A) shall maintain records of disclosures under clause (ii) of this subparagraph and make summaries of the disclosures available to the Secretary.</text>
 </clause></subparagraph><subparagraph id="ide27ef094c67444bf9d7e88ac4b01985a"><enum>(E)</enum><header>Threat information access</header><text>The Director of National Intelligence, in coordination with the heads of other appropriate Federal entities, shall ensure that the Board has access to relevant cybersecurity threat information, including through closed or classified briefings or the provision of classified information, when appropriate.</text></subparagraph><subparagraph id="id6a66e072510c4bb79ffb48b3c4d5dbcf"><enum>(F)</enum><header>Closed sessions</header><text>Notwithstanding section 1009 of title 5, United States Code, the Board may hold closed or restricted-access sessions when the Secretary determines that the matters to be discussed involve any of the following:</text><clause id="id348da591487d4593b45ee8de12e1ab2b"><enum>(i)</enum><text>Classified information.</text></clause><clause id="idc3606faf8d594566aa0efe3ffe5a1587"><enum>(ii)</enum><text>Sensitive cybersecurity vulnerabilities.</text></clause><clause id="id7198616209a9499da2a68797f6f0bfe2"><enum>(iii)</enum><text>Threat information.</text></clause><clause id="id165802f33f4e49eca12cc6de355552ed"><enum>(iv)</enum><text>Proprietary business information.</text></clause><clause id="idf5be0b68357541568e9a576562ac04d2"><enum>(v)</enum><text>Other information exempt from public disclosure under section 552 of title 5, United States Code.</text></clause></subparagraph></paragraph><paragraph id="id2279c5fb573a497c87bdc5736a445e22"><enum>(6)</enum><header>Duties</header><subparagraph commented="no" display-inline="no-display-inline" id="id72652cbee0194d1690b2ab2b8c284762"><enum>(A)</enum><header>In general</header><text display-inline="yes-display-inline">The Board shall—</text><clause id="id1baad248848246a587f605fc855946db"><enum>(i)</enum><text>develop a process to perform technical evaluations to determine what capabilities or combination of capabilities constitute high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety; and</text></clause><clause id="id5abf8382dd4b4e6f88839de12f341114"><enum>(ii)</enum><text>develop best practices, including—</text><subclause id="id1d2c6337bde14b0fb8ddcfba89149ed6"><enum>(I)</enum><text>standardize formats and processes for publishing model cards with technical details of artificial intelligence systems;</text></subclause><subclause id="id8a1658b414934957a2c3cf39b531361d"><enum>(II)</enum><text>recommendations for maintaining cybersecurity measures for developers or providers of artificial intelligence systems;</text></subclause><subclause id="idfca3beb82f594be3af3b9d1b3e37ce9d"><enum>(III)</enum><text>processes and metrics for developers or providers of artificial intelligence systems to use to evaluate risks from employees or other personnel who have access to artificial intelligence systems developed or in development by developers or providers of artificial intelligence systems; and</text></subclause><subclause id="id90ca3b01700043a38c7c9b50c4450dd4"><enum>(IV)</enum><text>recommendations on appropriate financial and other resourcing for developers or providers of artificial intelligence systems to robustly engage in safety and security research focused on the deployment of frontier artificial intelligence models.</text></subclause></clause></subparagraph><subparagraph id="ida328b045b38541d1be503cfc74a4ac5d" commented="no"><enum>(B)</enum><header>Periodic reassessment of technical evaluations and best practices</header><text>The Board shall periodically reassess the technical evaluations and best practices the Board develops under this subsection.</text></subparagraph></paragraph></subsection><subsection id="id5fa38ad6f42c415f8cb56304f16ad11c"><enum>(c)</enum><header>Requirement that providers of frontier artificial intelligence models give access to National Security agency before public release</header><text>Not later than 21 calendar days before a provider introduces into interstate or foreign commerce a frontier artificial intelligence model, the provider shall make available to the Artificial Intelligence Security Center, established by the Director of the National Security Agency under section 6504 of the Intelligence Authorization Act for Fiscal Year 2025 (division F of <external-xref legal-doc="public-law" parsable-cite="pl/118/159">Public Law 118–159</external-xref>; <external-xref legal-doc="usc" parsable-cite="usc/50/3602">50 U.S.C. 3602</external-xref> note), access to the frontier artificial intelligence model, including model's weights, configuration files, runtimes, or software libraries necessary to operate the frontier artificial intelligence model.</text></subsection><subsection id="id2f6c596a46e74a71bed22d4ad7f21d67"><enum>(d)</enum><header>Frontier artificial intelligence model registry</header><paragraph id="id32e173d66f59436da7145aa0da963826"><enum>(1)</enum><header>Establishment of registry</header><text>Not later than 90 days after the date of the enactment of this Act, the Director of the National Institute of Standards and Technology shall establish a registry of frontier models that are available to the public.</text></paragraph><paragraph id="idcda009760a0a4bf2a502267637ff1c42"><enum>(2)</enum><header>Rules and procedures</header><text>In establishing the registry under paragraph (1), the Director of the National Institute of Standards and Technology shall establish rules and procedures for—</text><subparagraph id="iddce4689dfcf548d08645aa94cff3baa7"><enum>(A)</enum><text>a provider of a frontier artificial intelligence model to register the frontier artificial intelligence model;</text></subparagraph><subparagraph id="id2d14fe5425cf4e7ea302f126f18a6664"><enum>(B)</enum><text>a provider of a frontier artificial intelligence model to contest the need for registering the frontier artificial intelligence model;</text></subparagraph><subparagraph id="ide807f14d68a248f28d209ef00fb2e2db"><enum>(C)</enum><text>removing a frontier artificial intelligence model from the registry;</text></subparagraph><subparagraph id="idf4274ebd54434067bc5ba63c30f46bdc"><enum>(D)</enum><text>a provider of a frontier artificial intelligence model to attest that the provider submitted the frontier artificial intelligence model to the test-bed established under section 6504(e) of the Intelligence Authorization Act for Fiscal Year 2025 (division F of <external-xref legal-doc="public-law" parsable-cite="pl/118/159">Public Law 118–159</external-xref>; <external-xref legal-doc="usc" parsable-cite="usc/50/3602">50 U.S.C. 3602</external-xref> note), as amended by subsection (e); and</text></subparagraph><subparagraph id="idf25367c0e7a24d398fce3b5195444cd0"><enum>(E)</enum><text>such other purposes the Director deems necessary.</text></subparagraph></paragraph><paragraph id="id9378d24b1d1642359df5d4ce85e1d307"><enum>(3)</enum><header>Obligation to register</header><text>Each provider of a frontier artificial intelligence model shall register that frontier artificial intelligence model with the registry established under paragraph (1) before introducing the frontier artificial intelligence model into interstate or foreign commerce.</text></paragraph></subsection><subsection id="id05ff591303114de796526be1fb7350f1"> <enum>(e)</enum> <header>Enforcement; ability To cure</header> <paragraph id="idd4ddd8b555fd40cf8728196c298df672"> <enum>(1)</enum> <header>Referrals for enforcement</header> <text>In any case in which the Director of the National Institute of Standards and Technology determines that a frontier artificial intelligence model has been introduced into interstate or foreign commerce by a provider of the frontier artificial intelligence in violation of subsection (c), the Director of the National Institute of Standards and Technology shall notify the Attorney General.</text>
        </paragraph>
        <paragraph commented="no" display-inline="no-display-inline"
          id="id0e05383cbfb94036942ea4983b2dbe6e">
          <enum>(2)</enum>
          <header>Enforcement</header>
 <text>The Attorney General shall enforce this section.</text> </paragraph> <paragraph commented="no" display-inline="no-display-inline" id="id8d5df895313a40009a7ab5476d4f5d45"> <enum>(3)</enum> <header>Penalty</header> <text>Whoever violates subsection (c) shall be fined an amount equal to not less than $100,000 per day for each day during which a frontier artificial intelligence model controlled by that person is available through interstate and foreign commerce without having obtained the voluntary security guidance issued under section 6504(e)(3) of the Intelligence Authorization Act for Fiscal Year 2025 (division F of <external-xref legal-doc="public-law" parsable-cite="pl/118/159">Public Law 118–159</external-xref>; <external-xref legal-doc="usc" parsable-cite="usc/50/3602">50 U.S.C. 3602</external-xref> note), as amended by subsection (f).</text>
        </paragraph>
        <paragraph id="id1978e72d7bf14b91822ac2784318cdf0">
          <enum>(4)</enum>
          <header>Right to cure</header>
          <subparagraph commented="no" display-inline="no-display-inline"
            id="id78ef4851ab704b548f83753ffb3e4afd">
            <enum>(A)</enum>
            <header>Notification</header>
 <text display-inline="yes-display-inline">Prior to commending an enforcement action against a provider of a frontier artificial intelligence model for violating subsection (c), the Attorney General shall notify the provider and allow the provider 7 calendar days following the notice of violation for the violator to come into compliance pursuant to subparagraph (B).</text>
          </subparagraph>
          <subparagraph id="idfbd922c6d2734c4b929d81f1805ca49c">
            <enum>(B)</enum>
            <header>Process to cure</header>
 <text>In order for a provider of a frontier artificial intelligence model to come into compliance pursuant to this subparagraph, the provider shall demonstrate to the Attorney General that the provider has—</text>
            <clause id="id42f53afa405f4419affba1e159b3ef91">
              <enum>(i)</enum>
 <text>withdrawn from interstate and foreign commerce the frontier artificial intelligence model that gave rise to the violation of subsection (c); and</text>
            </clause>
            <clause id="id9573186f33394b8ba6020a45e5748c5d">
              <enum>(ii)</enum>
 <text>given to the National Security Agency access to the frontier artificial intelligence model pursuant to subsection (c).</text>
            </clause>
          </subparagraph>
        </paragraph>
      </subsection><subsection id="idf122189407994dac9074fc0da809b6f7">
        <enum>(f)</enum>
        <header>National Security Agency research-Test-Bed</header>
 <text>Section 6504 of the Intelligence Authorization Act for Fiscal Year 2025 (division F of <external-xref legal-doc="public-law" parsable-cite="pl/118/159">Public Law 118–159</external-xref>; <external-xref legal-doc="usc" parsable-cite="usc/50/3602">50 U.S.C. 3602</external-xref> note) is amended—</text>
        <paragraph id="ided4c9d0f6a8e42b5975b3a38d4491812">
          <enum>(1)</enum>
 <text>in subsection (c)—</text> <subparagraph id="id28a1e07ce5bc437ab6369b9d58e86418"> <enum>(A)</enum> <text>by redesignating paragraph (4) as paragraph (5); and</text>
          </subparagraph>
          <subparagraph id="idba0ca33672084ecaa26cc78833d74825">
            <enum>(B)</enum>
 <text>by inserting after paragraph (3) the following new paragraph (4):</text> <quoted-block style="OLC" display-inline="no-display-inline" id="id75785600f36140c6be608d305500465c"> <paragraph id="id5d9eac0c3f8740a2a93fed516c9a8677"> <enum>(3)</enum> <text>Making available a research test-bed to private sector, Federal and qualified independent expert participants, on a subsidized basis, to engage in artificial intelligence security research, including through the secure provision of access in a secure environment for pre-deployment testing of any frontier artificial intelligence model prior to public release.</text>
              </paragraph>
              <after-quoted-block>;</after-quoted-block>
            </quoted-block>
          </subparagraph>
        </paragraph>
        <paragraph id="idb903dc95593a4f7fb6e705c7a1c9acaf">
          <enum>(2)</enum>
 <text>by redesignating subsection (e) as subsection (f); and</text> </paragraph> <paragraph id="ida06159bd1df44dc386da202a8c1a0e5a"> <enum>(3)</enum> <text>by inserting after subsection (d) the following:</text>
          <quoted-block style="OLC" display-inline="no-display-inline"
            id="idf544682efd0d4403babc67c0d802ce49">
            <subsection id="id418405ab72f44a0a899ee0b6644c695a">
              <enum>(e)</enum>
              <header>Test-Bed requirements</header>
              <paragraph id="idba61cd6e084f4398af1780a2ff94c217">
                <enum>(1)</enum>
                <header>Access and terms of usage</header>
                <subparagraph id="id2d7be880dc2047179986d5b4bb0c5834">
                  <enum>(A)</enum>
                  <header>Outside participation</header>
 <text>The Director shall establish a process by which critical infrastructure operators, as well private sector entities that develop or maintain information systems utilized by critical infrastructure operators, shall access a secure test-bed for the purpose of testing and evaluating the impact of frontier artificial intelligence models on information systems maintained by critical infrastructure operators prior to public release or distribution of such models.</text>
                </subparagraph>
                <subparagraph id="id9df7ed5aa05b4ccb8672ae2ead242df3">
                  <enum>(B)</enum>
                  <header>Researcher access</header>
 <text>The Director shall establish terms of usage governing access to the test-bed made available under subsection (c)(4), with limitations on researcher publication to the extent necessary to protect classified information or proprietary information provided by private sector participants.</text>
                </subparagraph>
                <subparagraph id="id78655bbcc70646c88e68a5f28ce8a925">
                  <enum>(C)</enum>
                  <header>Availability to federal agencies</header>
 <text>The Director shall ensure that the test-bed made available under subsection (c)(4) is also made available to other Federal agencies on a cost-recovery basis.</text>
                </subparagraph>
              </paragraph>
              <paragraph id="idc3b1ccc232a54081ad615c604fb485af">
                <enum>(2)</enum>
                <header>Use of certain infrastructure and other resources</header>
 <text>In carrying out subsection (c)(4), the Director shall leverage, to the greatest extent practicable, infrastructure and other resources provided under section 5.2 of Executive Order 14110 (88 Fed. Reg. 75191; relating to safe, secure, and trustworthy development and use of artificial intelligence).</text>
              </paragraph>
              <paragraph id="id15433e7315c44451930ec07f5843b146">
                <enum>(3)</enum>
                <header>Voluntary security guidance</header>
 <text>The Director shall share relevant guidance, informed by pre-deployment testing in the secure test-bed environment identified in subsection (c), to inform voluntary vendor actions to mitigate against potential security threats to such models, or the ability of foreign actors to utilize such models for computer network exploitation campaigns against information systems utilized by critical infrastructure operators, the design or development of weapons systems, or to further foreign surveillance capabilities.</text>
              </paragraph>
            </subsection>
            <after-quoted-block>.</after-quoted-block>
          </quoted-block>
        </paragraph>
 </subsection></section><section id="id7edff37319fc4b019413701fa7f8b437"><enum>4.</enum><header>Database for artificial intelligence security and safety incidents and risks</header><subsection id="id6e287d3d22984480b46cd4146a0b77ce"><enum>(a)</enum><header>Voluntary tracking of artificial intelligence security and artificial intelligence safety incidents</header><paragraph id="id4bfba9c4e67e40629baa77bdedc2d2ce"><enum>(1)</enum><header>Voluntary submissions</header><text>Not later than 1 year after the date of the enactment of this Act, the Director of the National Institute of Standards and Technology shall, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, establish mechanisms by which private sector entities, public sector organizations, civil society groups, and academic researchers may voluntarily share information with the National Institute of Standards and Technology on confirmed or suspected artificial intelligence security or artificial intelligence safety incidents, in a manner that preserves confidentiality of any affected party, which shall—</text><subparagraph id="id202783a6c53f474a9cd4f18d2b330f47"><enum>(A)</enum><text>leverage, to the greatest extent possible, standardized disclosure and incident description formats;</text></subparagraph><subparagraph id="id716987ab687848e79006e0a8e60be8e9"><enum>(B)</enum><text>develop processes to associate reports pertaining to the same incident with a single incident identifier;</text></subparagraph><subparagraph id="id4c4d8426716a479d8a044b53048e03ab"><enum>(C)</enum><text>establish classification, information retrieval, and reporting mechanisms that sufficiently differentiate between artificial intelligence security incidents and artificial intelligence safety incidents; and</text></subparagraph><subparagraph id="id4bda9a90bb034414bfff989d2e844944"><enum>(D)</enum><text>create appropriate taxonomies to classify incidents based on relevant characteristics, impact, or other relevant criteria.</text></subparagraph></paragraph><paragraph id="id76030b1b482441ecac332f59ee47f1d9"><enum>(2)</enum><header>Publicly accessible database</header><subparagraph id="id1a9a9649c3cd4720a9114c84082de5de"><enum>(A)</enum><header>Establishment of database required</header><text>Not later than 1 year after the date of the enactment of this Act, the Director of the Institute shall, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, establish a publicly accessible database of artificial intelligence security incidents and artificial intelligence safety incidents.</text></subparagraph><subparagraph id="id6345c977501843d2a426664e18dfdd56"><enum>(B)</enum><header>Review and population of database</header><text>Upon receipt of relevant information on an artificial intelligence security or artificial intelligence safety incident under paragraph (1), the Director of the Institute shall review the information and determine whether the described incident constitutes an artificial intelligence security or artificial intelligence safety risk appropriate for inclusion in the database developed and established under subparagraph (A).</text></subparagraph><subparagraph id="idc1b3f80756684059b7afa544f371859b"><enum>(C)</enum><header>Identification of causal factors</header><text>When making a determination under subparagraph (B), the Director of the Institute shall identify causal factors for the artificial intelligence security incident or the artificial intelligence safety incident, including—</text><clause id="id046e65476c924b6b9463bdbb94070504"><enum>(i)</enum><text>the artificial intelligence system;</text></clause><clause id="idc0d87e599ff14bdb9ae8510cb17dbf7a"><enum>(ii)</enum><text>the deployment of the artificial intelligence systems; and</text></clause><clause id="id8d5e76e012ef4843b5abfa71cf5e83a5"><enum>(iii)</enum><text>practices related to the operation of the artificial intelligence system, including misuse of the artificial intelligence system.</text></clause></subparagraph><subparagraph id="id3d673de8ea9646349944afdaa737167c"><enum>(D)</enum><header>Priorities</header><text>In evaluating information under subparagraph (B) and determining under such subparagraph whether to include a report of an incident in the database required by subparagraph (A), the Director shall prioritize inclusion in the database of cases in which a described incident—</text><clause id="id65a3f8a38d704c4c8cd01122e61faa9d"><enum>(i)</enum><text>describes an artificial intelligence system used in critical infrastructure or safety-critical systems;</text></clause><clause id="idefe68dec3a8b4658aa8c68ebde1e74f2"><enum>(ii)</enum><text>would result in a high-severity or catastrophic impact to the people or economy of the United States; or</text></clause><clause id="id94e2fbcaf1104dac9ec2dd635189e753"><enum>(iii)</enum><text>includes an artificial intelligence system widely used in commercial or public sector contexts in the United States.</text></clause></subparagraph></paragraph><paragraph id="idfec7f899e66845d7bfe59ea0eb145556"><enum>(3)</enum><header>Exemption from disclosure; reports and anonymity</header><subparagraph id="id129c248e11f4451ba29c2124c9adfcec"><enum>(A)</enum><header>Anonymity</header><text>The Director shall populate the voluntary database developed and established under paragraph (2)(A) with incidents based on public reports and information shared using the mechanism established pursuant to paragraph (1), ensuring that any incident description sufficiently anonymizes those affected, unless those who are affected have consented to their names being included in the database.</text></subparagraph><subparagraph id="id3f173e899cd64be19751bbee7dea400d"><enum>(B)</enum><header>Exemption from disclosure</header><text>Any information shared using the mechanism established pursuant to paragraph (1)—</text><clause id="idc08f174e1413418b9b91a946f03529a5"><enum>(i)</enum><text>shall be exempt from disclosure and withheld, unless an affected party consents to the inclusion of their names in the database as provided for under subparagraph (A), from the public, pursuant to section 552(b)(3)(B) of title 5, United States Code, and any other provision of United States law or law of any State, political subdivision or agency thereof, or Tribe requiring disclosure of information or records; and</text></clause><clause id="id7ff513f9872f42b8b8dea95d0fb120dd"><enum>(ii)</enum><text>shall not be deemed a waiver of any applicable privilege or protection, including trade secret protection.</text></clause></subparagraph><subparagraph id="id5b2d98406f3b4673b4bc71bbd33d9305"><enum>(C)</enum><header>Consultation required</header><text>Before publishing information regarding artificial intelligence safety incident under paragraph (2)(B), the Director shall consult with the developer or provider of the artificial intelligence system involved in an incident.</text></subparagraph></paragraph></subsection><subsection id="id2d2d7b09a4d84474b1b0b90f16fc7368"><enum>(b)</enum><header>Material risk guidance</header><text>Not later than 180 days after the date of the enactment of this Act the Director of the National Institute of Standards and Technology shall, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, publish nonbinding guidance that provides illustrative criteria and examples for determining when an event <quote>materially increases</quote> a risk for purposes of paragraphs (3) and (4) of section 2.</text></subsection></section><section id="id5566fabdba03415c93311da8181e6c08"><enum>5.</enum><header>Updating processes and procedures relating to cybersecurity vulnerabilities</header><subsection id="id4bf2469fa2bc487fae6aec0da8e7e15b"><enum>(a)</enum><header>Definitions</header><text>In this section:</text><paragraph id="id86faa6e04a8a42879ab156de748b4127"><enum>(1)</enum><header>Common Vulnerabilities and Exposures Program</header><text>The term <term>Common Vulnerabilities and Exposures Program</term> means the reference guide and classification system for publicly known information security vulnerabilities sponsored by the Cybersecurity and Infrastructure Security Agency.</text></paragraph><paragraph id="id230385ff2b554a31ace29b24cf217e47"><enum>(2)</enum><header>Relevant congressional committees</header><text>The term <term>relevant congressional committees</term> means—</text><subparagraph id="id6d9066ef25fa444cbb2ea02b4d92bf9d"><enum>(A)</enum><text>the Committee on Homeland Security and Governmental Affairs, the Committee on Commerce, Science, and Transportation, the Select Committee on Intelligence, and the Committee on the Judiciary of the Senate; and</text></subparagraph><subparagraph id="id8b8d59507cbd4360bfa7855e12ec0551"> <enum>(B)</enum> <text>the Committee on Oversight and Government Reform, the Committee on Energy and Commerce, the Permanent Select Committee on Intelligence, and the Committee on the Judiciary of the House of Representatives.</text>
 </subparagraph></paragraph></subsection><subsection id="id0078027766ec4664940fbb1e09fdb302"><enum>(b)</enum><header>Processes and procedures for vulnerability management</header><text>Not later than 180 days after the date of the enactment of this Act, the Director of the National Institute of Standards and Technology shall—</text><paragraph id="id85d95272c85544edbbb3fcf727fb9ff3"><enum>(1)</enum><text>comprehensively evaluate, and develop a strategic plan to reform, the structure and processes of the National Vulnerability Database in light of significant increase in the volume of vulnerabilities in information systems identified by artificial intelligence systems, including recommendations and guidance related to assisting in determining prioritization of identified vulnerability patching and mitigation;</text></paragraph><paragraph id="idb9f50e142dba4cc0b070f4527efd7c58"><enum>(2)</enum><text>initiate a process to utilize advanced artificial intelligence systems to characterize vulnerabilities as part of the National Vulnerability Database;</text></paragraph><paragraph id="idb33ad771cec6469f952193c34e683b22"><enum>(3)</enum><text>initiate a process to update processes and procedures associated with the National Vulnerability Database of the Institute to ensure that the database and associated vulnerability management processes incorporate artificial intelligence security vulnerabilities to the greatest extent practicable;</text></paragraph><paragraph id="id72782096f57e420ba860b1f3ddc6daae"><enum>(4)</enum><text>identify any characteristics of artificial intelligence security vulnerabilities that make utilization of the National Vulnerability Database inappropriate and develop processes and procedures for vulnerability management for those vulnerabilities; and</text></paragraph><paragraph id="idb4d98197283547688269e1f9427cd868"><enum>(5)</enum><text>initiate a process to update the Secure Software Development Framework set forth in National Institute of Standards and Technology Special Publication 800–218 and include guidance and best practices for using artificial intelligence in code generation and security review.</text></paragraph></subsection><subsection id="id32239c20110a46088eeb9f1ac3c6d4d6"><enum>(c)</enum><header>Updates to Common Vulnerabilities and Exposures Program</header><text>Not later than 180 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall—</text><paragraph id="id754ec43477f34ce2835f0779507ffd15"><enum>(1)</enum><text>initiate a process to update processes and procedures associated with the Common Vulnerabilities and Exposures Program to ensure that the program and associated processes identify and enumerate artificial intelligence security vulnerabilities to the greatest extent practicable; and</text></paragraph><paragraph id="id9c9362462fca427f9ebe689aba055125"><enum>(2)</enum><text>identify any characteristic of artificial intelligence security vulnerabilities that make utilization of the Common Vulnerabilities and Exposures Program inappropriate and develop processes and procedures for vulnerability identification and enumeration for those artificial intelligence security vulnerabilities.</text></paragraph></subsection><subsection id="idc45639354c1b47299c96ef990f3fcd61"><enum>(d)</enum><header>Submission to Congress</header><text>Upon completion of the processes required in subsections (a) and (b), the Director of the National Institute of Standards and Technology and the Director of the Cybersecurity and Infrastructure Security Agency, respectively, shall submit a strategic plan to Congress identifying courses of action under existing authorities, or identifying specific legislative amendments, necessary to address accelerating security risks associated with artificial intelligence systems.</text></subsection><subsection id="idd7b4dbebfeeb4122900905189a024674"><enum>(e)</enum><header>Evaluation of consensus standards for vulnerability disclosure</header><paragraph id="idc3c69a8a6e8a4db8953d2d45a3bf1520"><enum>(1)</enum><header>In general</header><text>Not later than 30 days after the date of the enactment of this Act, the Director of the National Institute of Standards and Technology shall, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, initiate a multi-stakeholder process to evaluate whether existing voluntary consensus standards and processes for vulnerability reporting processes associated with the security of information systems effectively accommodate the significant increased volume of vulnerabilities in information systems identified by artificial intelligence systems, as well as the unique nature of artificial intelligence security vulnerabilities.</text></paragraph><paragraph id="ide9a01e5904ab4f2cb601ea7b120fba31"><enum>(2)</enum><header>Report</header><subparagraph id="id4b0d6b6ac8454e25a97af8c052c89766"><enum>(A)</enum><header>Submission</header><text>Not later than 180 days after the date on which the evaluation under paragraph (1) is carried out, the Director shall submit a report to the relevant congressional committees on the sufficiency of existing vulnerability reporting processes and standards to accommodate the significant increased volume of vulnerabilities in information systems identified by artificial intelligence systems, as well as artificial intelligence security vulnerabilities.</text></subparagraph><subparagraph id="id89bc6b46ac24451992aacc09de244a8e"><enum>(B)</enum><header>Post-report action</header><text>If the Director concludes in the report submitted under subparagraph (A) that existing vulnerability reporting processes and standards do not effectively accommodate the significant increased volume of vulnerabilities in information systems identified by artificial intelligence systems, as well as the reporting of artificial intelligence security vulnerabilities, the Director shall initiate a process, in consultation with the Director of the National Institute of Standards and Technology and the Director of the Office of Management and Budget, to update relevant vulnerability reporting processes, including the Department of Homeland Security Binding Operational Directive 20–01, or any subsequent directive.</text></subparagraph></paragraph></subsection></section><section id="ide30ee76489d54744af5d28d800852aa3"><enum>6.</enum><header>Review of artificial intelligence security vulnerabilities under vulnerabilities equities process</header><subsection id="idf4282fb6fb86400c874c9c9a8ca8b4ba"><enum>(a)</enum><header>Definitions</header><text>In this section:</text><paragraph id="idc22edcd1d2f841feb5c46d868c8da9c4"><enum>(1)</enum><header>Appropriate congressional committees</header><text>The term <term>appropriate congressional committees</term> means—</text><subparagraph id="ida25b844211194a759e25af648e52531d"><enum>(A)</enum><text>the Select Committee on Intelligence of the Senate;</text></subparagraph><subparagraph id="id7ce0cc6c40ee485ebe6bdfa1f9da9ae0"><enum>(B)</enum><text>the Committee on Homeland Security and Governmental Affairs of the Senate;</text></subparagraph><subparagraph id="id24e0e61a219342c8aa16d3ed1e6e651d"><enum>(C)</enum><text>the Committee on the Judiciary of the Senate;</text></subparagraph><subparagraph id="ide70daab30ff7412f8c8310c2f34e5cc7"><enum>(D)</enum><text>the Committee on Armed Services of the Senate;</text></subparagraph><subparagraph id="id839b1deab4d846e7bb5e9347df3fa51b"><enum>(E)</enum><text>the Permanent Select Committee on Intelligence of the House of Representatives;</text></subparagraph><subparagraph id="id486b1d83924643aba2bef554b1f40e66"> <enum>(F)</enum> <text>the Committee on Homeland Security of the House of Representatives;</text>
 </subparagraph><subparagraph id="idc3cee887b0184b2e970aec56c5b8c711"><enum>(G)</enum><text>the Committee on the Judiciary of the House of Representatives; and</text></subparagraph><subparagraph id="idcc2aba7b58cb466db8714af5f6344fda"><enum>(H)</enum><text>the Committee on Armed Services of the House of Representatives.</text></subparagraph></paragraph><paragraph id="id97d2f83c4ce649b58b9f72463e2c261c"><enum>(2)</enum><header>Vulnerabilities equities Policy and Process document</header><text>The term <term>Vulnerabilities Equities Policy and Process document</term> means the executive branch document entitled <quote>Vulnerabilities Equities Policy and Process for the United States Government</quote> dated November 15, 2017.</text></paragraph><paragraph id="id83e26bd3be784e1c947d81022c65db02"><enum>(3)</enum><header>Vulnerabilities equities process</header><text>The term <term>Vulnerabilities Equities Process</term> means the interagency review of vulnerabilities carried out pursuant to the Vulnerabilities Equities Policy and Process document or any successor document.</text></paragraph></subsection><subsection id="idd9f7dfe3750347d5940839713d6badef"><enum>(b)</enum><header>Evaluation; report</header><text>Not later than 90 days after the date of the enactment of this Act, the Federal departments and agencies participating in the Vulnerabilities Equities Process shall—</text><paragraph id="id61eff675d0ae43e09a42c874232d4278"><enum>(1)</enum><text>evaluate whether the existing Vulnerabilities Equities Process sufficiently accommodates the submission and review of artificial intelligence security vulnerabilities; and</text></paragraph><paragraph id="ida249a9dbf3be455283dbad28ff155c99"><enum>(2)</enum><text>submit to the appropriate congressional committees a report describing the applicability of the Vulnerabilities Equities Process to such vulnerabilities, including whether the submission and review of such vulnerabilities under the Vulnerabilities Equities Process would result in an unduly large volume of notifications to affected vendors and, if so, an assessment of mechanisms to manage the volume of such notifications.</text></paragraph></subsection><subsection id="ida813a0a950b04786a3f9c1fc3a526c6a"><enum>(c)</enum><header>Process</header><text>In carrying out subsection (b), if the Federal departments and agencies participating in the Vulnerabilities Equities Process determine that the existing Vulnerabilities Equities Process does not sufficiently accommodate the submission and review of artificial intelligence security vulnerabilities identified by the evaluation required in subsection (b)(1), and that such vulnerabilities present public interest considerations meriting review under the Vulnerabilities Equities Process, the Federal departments and agencies participating in the Vulnerabilities Equities Process shall establish a process for the submission and review of such vulnerabilities under the Vulnerabilities Equities Process not later than 30 days after the date of such determination.</text></subsection><subsection id="id8d908d4dcda74127a1539f439bbe3270"><enum>(d)</enum><header>Report on vulnerabilities identified by artificial intelligence systems</header><text>Not later than 90 days after the date of the enactment of this Act, the Director of National Intelligence shall submit to the congressional intelligence committees (as defined in section 3 of the National Security Act of 1947 (<external-xref legal-doc="usc" parsable-cite="usc/50/3003">50 U.S.C. 3003</external-xref>)) a report on—</text><paragraph id="idfb2fe94fe6d742858e264ca6239e6c69"><enum>(1)</enum><text>the volume of vulnerabilities of information systems identified by artificial intelligence systems;</text></paragraph><paragraph id="id1f8ae99ea9564a84b45b9c115ff24a8b"><enum>(2)</enum><text>the impact of any change in such volume on the functioning of the Vulnerabilities Equities Process; and</text></paragraph><paragraph id="ide1c923d8137245dcb83735d41357f8b6"><enum>(3)</enum><text>whether the increasingly rapid discovery and exploitation of such vulnerabilities by external cyber actors using artificial intelligence systems materially alters the equity of disclosure.</text></paragraph></subsection></section><section id="id10dcf310fd0b4e908cb626f4eeaeb663"><enum>7.</enum><header>Security of artificial intelligence systems and laboratories</header><subsection id="idb400634675364abba51640c052389935"><enum>(a)</enum><header>Definitions</header><text>In this section:</text><paragraph id="ida7902ef547b343c6b65eaca7c343a6e5"><enum>(1)</enum><header>Center</header><text>The term <term>Center</term> means the Artificial Intelligence Security Center of the National Security Agency.</text></paragraph><paragraph id="id5fbdac6b9515451c89660799f2d395ed"><enum>(2)</enum><header>Classified information</header><text>The term <term>classified information</term> has the meaning given such term in section 805 of the National Security Act of 1947 (<external-xref legal-doc="usc" parsable-cite="usc/50/3164">50 U.S.C. 3164</external-xref>).</text></paragraph><paragraph id="id88068b4074b24febbe87112a6d38dfcc"><enum>(3)</enum><header>Cleared industry personnel</header><text>The term <term>cleared industry personnel</term> means employees or representatives of a covered person who hold an appropriate security clearance and have a demonstrated need to know.</text></paragraph><paragraph id="id85c65d3da81a4507834810866bb83a79"><enum>(4)</enum><header>Congressional intelligence committees</header><text>The term <term>congressional intelligence committees</term> has the meaning given such term in section 3 of the National Security Act of 1947 (<external-xref legal-doc="usc" parsable-cite="usc/50/3003">50 U.S.C. 3003</external-xref>).</text></paragraph><paragraph id="id059e16ccd4c24f6da7c6974b70f599ac"><enum>(5)</enum><header>Covered person</header><text>The term <term>covered person</term> means a non-Federal person who—</text><subparagraph id="id78fd974b59984edeab27a8cac0fd3e5d"><enum>(A)</enum><text>is a United States person;</text></subparagraph><subparagraph id="id6052555b6e0344dfac5a3ddaeaa7254b"><enum>(B)</enum><text>develops, deploys, or operates artificial intelligence models or critical enabling infrastructure; and</text></subparagraph><subparagraph id="idabb496ac439a4e89835c9fc0e5fe2096"><enum>(C)</enum><text>provides the services described in subparagraph (B) to a Federal department or agency.</text></subparagraph></paragraph><paragraph id="id92de766dcf2b4f0e804f8aa6c71b1f0a"><enum>(6)</enum><header>Director</header><text>The term <term>Director</term> means the Director of the National Security Agency.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id7e55563d12f942a28f2b2ebc10af32b9"><enum>(7)</enum><header>Foreign adversary country</header><text>The term <term>foreign adversary country</term> has the meaning given such term in section 2(c) of the Protecting Americans' Data from Foreign Adversaries Act of 2024 (<external-xref legal-doc="usc" parsable-cite="usc/15/9901">15 U.S.C. 9901(c)</external-xref>).</text></paragraph><paragraph id="idd72d9550eecf4506b3ff3245c1527500"><enum>(8)</enum><header>Foreign entity of concern</header><text>The term <term>foreign entity of concern</term> means—</text><subparagraph commented="no" display-inline="no-display-inline" id="ide0dfe26330b44a29804afcd034b7910d"><enum>(A)</enum><text display-inline="yes-display-inline">a foreign adversary country; or</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id6480782295a24028b822c0e52128346a"><enum>(B)</enum><text display-inline="yes-display-inline">any entity that is controlled or acting under the direction of a foreign adversary country.</text></subparagraph></paragraph><paragraph id="id4a5b924ac36a4286be95a435dbf50ff6"><enum>(9)</enum><header>Intelligence</header><text>The term <term>intelligence</term> has the meaning given such term in section 3 of the National Security Act of 1947 (<external-xref legal-doc="usc" parsable-cite="usc/50/3003">50 U.S.C. 3003</external-xref>).</text></paragraph><paragraph id="id1b43ff8a468c437da61271b47b94b39c"><enum>(10)</enum><header>Intelligence community</header><text>The term <term>intelligence community</term> has the meaning given such term in section 3 of the National Security Act of 1947 (<external-xref legal-doc="usc" parsable-cite="usc/50/3003">50 U.S.C. 3003</external-xref>).</text></paragraph><paragraph id="idee7c4a7ed5d94532804d1799f0cfe65b"><enum>(11)</enum><header>Security clearance</header><text>The term <term>security clearance</term> means an authorization to access classified information.</text></paragraph><paragraph id="id78fbb0800548463e855e46e906110eeb"><enum>(12)</enum><header>Threat information</header><text>The term <term>threat information</term> means information on—</text><subparagraph id="idd52935f7d3e64b19aa9ef79d0cfbb3e3"><enum>(A)</enum><text>efforts by foreign adversary countries to use products or research of covered persons or other entities or individuals to generate synthetic media for foreign-directed influence campaigns, develop and manage computer network exploitation campaigns, design or develop weapons systems, or enhance surveillance capabilities in ways that undermine the privacy or threaten the security of citizens of the United States;</text></subparagraph><subparagraph id="idb27034afe8e542528d7616e8bf95730b"><enum>(B)</enum><text>threats posed by foreign entities of concern, including indications of compromise to networks associated with covered persons or other technical indicators, indicating a compromise to the confidentiality, integrity, or availability of an artificial intelligence system, or to the supply chain of an artificial intelligence system, including training or test data, frameworks or software libraries, training or inference computing environments, or other components necessary for the training, management, deployment, or maintenance of an artificial intelligence system;</text></subparagraph><subparagraph id="idc260b27643294dad873fd9cc2d4f6d02"><enum>(C)</enum><text>activity of foreign entities of concern to clandestinely, fraudulently, or otherwise maliciously access the systems of covered persons for purposes of illicit technology transfer or otherwise gaining unfair economic advantage, including through techniques to extract a model’s technical capabilities to replicate, develop, or improve a foreign artificial intelligence model without authorization by the covered person;</text></subparagraph><subparagraph id="idb6c0d94803b64880996e0318c9fd34ba"><enum>(D)</enum><text>activity of foreign entities of concern to sabotage or otherwise clandestinely degrade artificial intelligence systems or the supply chain of an artificial intelligence system, including training or test data, frameworks or software libraries, training or inference computing environments, or other components necessary for the training, management, or maintenance of an artificial intelligence system;</text></subparagraph><subparagraph id="id1f548a3e69014cbc8d164a5983ed16ea"><enum>(E)</enum><text>observations, emerging concerns, or other inputs from vendors or researchers regarding relevant malicious or clandestine activity of foreign entities of concern toward an artificial intelligence system, its supply chain, or other necessary components;</text></subparagraph><subparagraph id="id9017acf66ba94cc1ab2ca66c68546cd1"><enum>(F)</enum><text>efforts by foreign adversaries or foreign entities to evade detection of malicious activity described in subparagraphs (A), (B), (C) and (D); and</text></subparagraph><subparagraph id="id55feb2661eb0425ca2bb60a6ab197416"><enum>(G)</enum><text>any other relevant information the Director of the National Counterintelligence and Security Center and the Assistant Director of the Federal Bureau of Investigation for the Counterintelligence Division deem appropriate.</text></subparagraph></paragraph></subsection><subsection id="id5ca2a95c9d9f4a808afa246a1790ab44"><enum>(b)</enum><header>Best practices</header><text>Not later than 90 days after the date of the enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall, in collaboration with the Director and the Director of the National Institute of Standards and Technology and by leveraging efforts of the Information Communications Technology Supply Chain Risk Management Task Force to the greatest extent practicable, convene a multi-stakeholder process to encourage the development and adoption of best practices relating to addressing supply chain risks associated with training and maintaining artificial intelligence models, which shall ensure consideration of supply chain risks associated with—</text><paragraph id="id89715f417cdb4a2b8b5a3eda5ba0f5fa"><enum>(1)</enum><text>activity of foreign entities of concern to clandestinely, fraudulently, or otherwise maliciously access the systems of covered persons for purposes of illicit technology transfer or otherwise gaining unfair economic advantage, including through techniques to extract a model’s technical capabilities to replicate, develop, or improve a foreign artificial intelligence model without authorization by the covered person;</text></paragraph><paragraph id="id3cc240907e2546caa6f788d5bdb58b35"><enum>(2)</enum><text>activity of foreign entities of concern to sabotage or otherwise clandestinely degrade artificial intelligence systems or the supply chain of an artificial intelligence system, including training or test data, frameworks or software libraries, training or inference computing environments, or other components necessary for the training, management, or maintenance of an artificial intelligence system; and</text></paragraph><paragraph id="id786fbba734774fbca452d0071188ba5d"><enum>(3)</enum><text>threat information, usage trends, or other input from vendors or researchers regarding observed malicious or clandestine activity of foreign entities of concern toward an artificial intelligence system, its supply chain, or other necessary components.</text></paragraph></subsection><subsection id="idbad403fab2aa4fa7ad229afb0cda1da6"><enum>(c)</enum><header>Establishment of pilot program on sharing of intelligence and threat information with covered persons</header><paragraph id="id5a7a5879759949389b4d0a4965de6394"><enum>(1)</enum><header>In general</header><text>Not later than 180 days after the date of the enactment of this Act, the Director shall, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, establish a pilot program to assess the feasibility and advisability of facilitating the secure sharing with covered persons of intelligence and threat information germane to the securing of the supply chain risks associated with training and maintaining artificial intelligence models procured by the Federal Government.</text></paragraph><paragraph id="id891b897abb644fc4b89968dccf13940f"><enum>(2)</enum><header>Participation</header><text>The Director may not select or exclude covered persons to participate in the pilot program in a manner that provides a competitive advantage or procurement preference to any covered person, to the detriment of another covered person.</text></paragraph><paragraph id="id90ea331c90f442f0a28119b7b16c3d02"><enum>(3)</enum><header>Duration</header><text>The Director shall carry out the pilot program established pursuant to paragraph (1) for not less than a 3-year period beginning on the date of the establishment of the pilot program.</text></paragraph></subsection><subsection id="id71cfedeb8fdd467aa993b4ee49ff3061"><enum>(d)</enum><header>Participation requirements</header><paragraph id="id2ef13a8d4aeb490293f89b5270ac6a0c"><enum>(1)</enum><header>Criteria</header><text>The Director shall establish criteria governing engagement with covered persons under the pilot program required by subsection (c), which may include criteria relating to the following:</text><subparagraph id="id91746b9c30aa4f2bb699e5027b0749e5"><enum>(A)</enum><text>Relevance to national security.</text></subparagraph><subparagraph id="id33da04922399489a9202e88ffe3a64a6"><enum>(B)</enum><text>The ability to protect classified or sensitive intelligence information.</text></subparagraph><subparagraph id="idbc52673d4d814e89a1d0ed9c55f177c9"><enum>(C)</enum><text>Cybersecurity and information security maturity.</text></subparagraph><subparagraph id="id1d9b8b36dc5f403987a3682a40b2c498"><enum>(D)</enum><text>Agreement to comply with intelligence handling, use, and nondisclosure requirements.</text></subparagraph><subparagraph id="idec3a2039be01474bb2a7a37e2fca2415"><enum>(E)</enum><text>The availability of cleared personnel of covered persons or willingness of covered persons to increase the number of cleared personnel.</text></subparagraph></paragraph><paragraph id="id3ff8563ceb00479bbe329cf5a777e131"><enum>(2)</enum><header>Nature of participation</header><text>Participation in the pilot program required by subsection (c) shall not be construed as a certification, endorsement, or regulatory approval by the United States Government of any artificial intelligence system or commercial activity and the Director may not exclude a covered person from participating on the basis of political or ideological viewpoints of the covered person or its employees.</text></paragraph></subsection><subsection id="id86171d551db744119cfee13e575b8a30"><enum>(e)</enum><header>Intelligence sharing structure</header><paragraph id="idcfdb09b2e5c643e1bc336db5d93db1a4"><enum>(1)</enum><header>Authorized modes</header><text>Under the pilot program required by subsection (c), the Director may authorize the sharing of intelligence and threat information as described in paragraph (1) of such subsection through—</text><subparagraph id="idd9a013a3a1c8426888f0576944207d87"> <enum>(A)</enum> <text>bilateral exchanges between elements of the intelligence community and a covered person;</text>
 </subparagraph><subparagraph id="id9f643e1fa13e47058c1db1084b5397ed"><enum>(B)</enum><text>multilateral exchanges among covered persons, as determined appropriate by the Director; or</text></subparagraph><subparagraph id="idf44c39814fa04a2c8ab27c3dcd8fae8c"><enum>(C)</enum><text>another designated intelligence-sharing mechanism operated or overseen by the Director.</text></subparagraph></paragraph><paragraph id="id38bd1e936f11465eab10cc6fed7ea426"><enum>(2)</enum><header>Limitation</header><text>Any mechanism established under this section shall be limited to the dissemination of intelligence and threat information and shall not establish standards, requirements, or best practices governing artificial intelligence development or deployment.</text></paragraph></subsection><subsection id="id72930e84a9ad4f7e9b366d0de67fe89c"><enum>(f)</enum><header>Tailoring, handling, and protection of intelligence</header><paragraph id="id35e43150e9d64bf5843fe5403e74cc52"><enum>(1)</enum><header>Procedures required</header><text>The Director shall codify procedures to tailor, sanitize, or downgrade the classification level of intelligence shared under the pilot program required by subsection (c) to ensure usability while protecting intelligence sources and methods.</text></paragraph><paragraph id="idd5e31028375b44b086a39bce4a3b2610"><enum>(2)</enum><header>Examples of procedures</header><text>The procedures developed under paragraph (1) may include the following:</text><subparagraph id="idbaf341044a584a209aaf3f947cbd74a8"><enum>(A)</enum><text>The use of tear lines and segregable summaries.</text></subparagraph><subparagraph id="idbb8d82b4fa4e4e0984ce7679dd6003fa"><enum>(B)</enum><text>The preparation of classified annexes where necessary.</text></subparagraph><subparagraph id="idc14cfb3f57fe4c158a775fd184d21f7f"><enum>(C)</enum><text>Criteria governing the classification level of shared intelligence.</text></subparagraph><subparagraph id="idb6378d03a1a949179a3b1bfcabc77774"><enum>(D)</enum><text>The appropriate use of cleared industry personnel.</text></subparagraph></paragraph><paragraph id="iddd9dddd7bdf7481f9b72dc81591dd772"><enum>(3)</enum><header>Handling requirements</header><text>The Director shall, acting through the Center, codify policies governing the handling, storage, and dissemination of intelligence shared under the pilot program required by subsection (c), including audit and compliance mechanisms.</text></paragraph></subsection><subsection id="id45d067c7aea74501b113ac2d53bf236a"><enum>(g)</enum><header>Permissible use and nondisclosure</header><paragraph id="id9417345aa0494450a384436ed34e7038"><enum>(1)</enum><header>Permissible use</header><text>Intelligence shared under the pilot program required by subsection (c) may be used solely for detecting, preventing, or mitigating malicious foreign activity targeting the supply chains associated with training and maintaining artificial intelligence models procured by the Federal Government for intelligence collection, intellectual property theft, and other malicious activities.</text></paragraph><paragraph id="id20c8c4f15d2340bda238d7e4dec113b2"><enum>(2)</enum><header>Nondisclosure</header><text>A covered person participating in the pilot program may not disclose any intelligence shared under the pilot program required by subsection (c), except as expressly authorized by the Director acting through the Center.</text></paragraph></subsection><subsection id="ide0d2986360324239b95ce1ccc5b29eb3"><enum>(h)</enum><header>Privacy and civil liberties</header><text>In planning and coordinating the pilot program required by subsection (c), the Director shall, acting through the Center, consult with the Civil Liberties Protection Officer of the Office of the Director of National Intelligence.</text></subsection><subsection id="id84c9685723a04e5993be39b492708ec1"><enum>(i)</enum><header>Evaluation and reporting</header><paragraph id="idf6ae2590302a4f7094dd0659251f7124"><enum>(1)</enum><header>Evaluation</header><text>The Director shall continuously evaluate the effectiveness and risks of the pilot program established under subsection (c).</text></paragraph><paragraph id="idb93ec42172fb471ca66c5483bcf78616"><enum>(2)</enum><header>Report</header><subparagraph id="id04f997b841324810b947451fba8cc932"> <enum>(A)</enum> <header>In general</header> <text>Not later than 90 days before the date on which the pilot program required by paragraph (1) of subsection (c) terminates pursuant to paragraph (3) of such subsection, the Directors shall submit to the congressional intelligence committees (as defined in section 3 of the National Security Act of 1947 (<external-xref legal-doc="usc" parsable-cite="usc/50/30003">50 U.S.C. 30003</external-xref>)) a report assessing—</text>
            <clause id="id122ab45ce75246d6aa18ce74353ea4a2">
              <enum>(i)</enum>
 <text>the effectiveness of intelligence sharing under the pilot program;</text> </clause> <clause id="id7a3c391d90d74a43ab996f2ac27006fc"> <enum>(ii)</enum> <text>the adequacy of safeguards for sources, methods, and privacy;</text>
            </clause>
            <clause id="idc2be18b3a2b54b1fa6b2fcd7997debd9">
              <enum>(iii)</enum>
 <text>the scope of participation and list of covered persons participating in the pilot program; and</text>
            </clause>
            <clause id="id6b87c8662a504467bd3cdab4a866c633">
              <enum>(iv)</enum>
 <text>whether the program should be modified, extended, or terminated.</text> </clause> </subparagraph><subparagraph id="id2c0f48f320d94185bf507d8db9d5b815"><enum>(B)</enum><header>Form</header><text>The report submitted pursuant to subparagraph (A) shall be submitted in unclassified form, but may include a classified annex.</text></subparagraph></paragraph></subsection><subsection id="ida060ff7b87e34295b9243532257e1ace"><enum>(j)</enum><header>Rule of construction</header><text>Nothing in this section shall be construed—</text><paragraph id="id890d21a55ea74dba9573396ce43aba35"><enum>(1)</enum><text>to authorize the collection of intelligence on United States persons not authorized by another provision of law;</text></paragraph><paragraph id="iddc3826428aa640249ed29bc119d4729c"><enum>(2)</enum><text>to require the disclosure of classified information to unauthorized persons; or</text></paragraph><paragraph id="id01dcf9a3b36f498d85a13d5523e888db"><enum>(3)</enum><text>to establish commercial, competition, or technology policy outside the purview of the intelligence community.</text></paragraph></subsection><subsection id="idc0a9e6b334694ef59f5c7664f47780d4"><enum>(k)</enum><header>Exemption from disclosure; protection</header><text>Any information shared by a covered person or other entity or individual with the United States Government pursuant to this section—</text><paragraph id="id036f5c51d5ee4258892aee8d95471a8f"><enum>(1)</enum><text>shall be exempt from disclosure and withheld, without discretion, from the public, pursuant to section 552(b)(3)(B) of title 5, United States Code, and any other provision of United States law or law of any State, political subdivision or agency thereof, or Tribe requiring disclosure of information or records; and</text></paragraph><paragraph id="idef72050eb7b445ba9ee7644e664f336d"><enum>(2)</enum><text>shall not be deemed a waiver of any applicable privilege or protection, including trade secret protection.</text></paragraph></subsection><subsection id="ida7eb0131fd444ca1a207fbaca22dbb1a" commented="no" display-inline="no-display-inline"><enum>(l)</enum><header>Protection from liability</header><text>No cause of action shall lie or be maintained in any court against any covered person for sharing information with the United States Government or another covered person pursuant to this section.</text></subsection></section></legis-body></bill>

