HR9333-119

Reported

AI Flaw Reporting and Security Enhancement Act

119th Congress Introduced Jun 18, 2026

Summary

What This Bill Does

The AI Flaw Reporting and Security Enhancement Act would require the National Institute of Standards and Technology, in consultation with the Cybersecurity and Infrastructure Security Agency, to operate a program supporting voluntary reporting, collection, and tracking of artificial-intelligence flaws. NIST must convene industry, universities, research institutions, nonprofits, standards organizations, civil-society groups, and public agencies to create common definitions and taxonomies for AI vulnerabilities, failure modes, accidents, hazards, misuse, incidents, and other safety or security problems. The program would also develop standards, severity or risk measures, detection methods, reporting practices, documentation formats, and norms for deciding whether and when flaws should be disclosed publicly.

NIST must build the reporting infrastructure itself or use cooperative agreements with one or more eligible universities, research institutions, or consortia. The infrastructure must include a national AI-flaw database or modify an existing national database. NIST must consider machine readability, interoperability with existing systems, future taxonomy and stakeholder updates, and policies for dissemination and public disclosure. Within three years of enactment, NIST must report to Congress on stakeholder findings, the infrastructure and database, and recommendations for standardized voluntary reporting mechanisms.

Who Benefits and How

AI developers, deployers, security teams, researchers, and standards organizations could use common terminology and severity measures to detect, compare, prioritize, and remediate flaws. AI users and members of the public could benefit from earlier identification of safety and security problems and more consistent public-disclosure practices. Universities, research institutions, and their consortia could receive cooperative agreements to develop or maintain the database. NIST, CISA, and other public agencies would gain a shared source of standardized information about emerging AI risks. Congressional committees would receive an implementation assessment and policy recommendations.

Who Bears the Burden and How

NIST staff must convene stakeholders, design definitions and standards, build or contract for reporting infrastructure, manage the national database, coordinate with CISA and other agencies, and prepare the three-year report. Universities or research contractors selected under cooperative agreements must develop, secure, maintain, and update the infrastructure. AI companies, academic researchers, nonprofits, and civil-society organizations that choose to participate may incur reporting, documentation, review, and disclosure costs, but the bill does not require them to submit a flaw. AI providers whose flaws are eventually disclosed could face remediation and reputational pressure, with the disclosure rules left to program norms rather than fixed by the bill.

Key Provisions

  • Requires NIST and CISA consultation on a voluntary AI-flaw reporting and tracking program.
  • Directs stakeholders to develop common flaw definitions, taxonomies, technical standards, risk measures, detection methods, and disclosure norms.
  • Requires a national AI-flaw database that NIST or eligible research entities may develop and maintain.
  • Allows cooperative agreements with universities, research institutions, or consortia for the reporting infrastructure.
  • Requires NIST to report to Congress within three years on implementation and future standardized voluntary-reporting mechanisms.

Evidence Chain:

This summary is generated from the full bill text using AI analysis. Expand "Detailed Analysis" below for identified beneficiaries/burden bearers with clause-level evidence links.

At a Glance

What This Bill Does

Require NIST, in consultation with CISA and outside stakeholders, to create a voluntary national system for defining, reporting, tracking, prioritizing, and disclosing artificial-intelligence safety and security flaws.

Key Policy Areas

Artificial Intelligence, Cybersecurity, Science and Technology, Public Safety, Education

Primary Purpose

Require NIST, in consultation with CISA and outside stakeholders, to create a voluntary national system for defining, reporting, tracking, prioritizing, and disclosing artificial-intelligence safety and security flaws.

Policy Domains

Artificial Intelligence Cybersecurity Science and Technology Public Safety Education

Section 2 - voluntary artificial-intelligence flaw reporting

Identified Gains
  • Artificial intelligence developers and security teams
  • Artificial intelligence users exposed to safety and security flaws
  • Universities eligible for NIST cooperative agreements
  • Research institutions eligible to maintain the national database
  • Cybersecurity and Infrastructure Security Agency analysts
  • Artificial intelligence standards organizations
Model: codex-gpt-5 | Version: bill_summary_v2 | Source: ih
Artificial intelligence standards organizations:
Artificial intelligence developers and security teams:
Universities eligible for NIST cooperative agreements:
Cybersecurity and Infrastructure Security Agency analysts:
Research institutions eligible to maintain the national database:
Artificial intelligence users exposed to safety and security flaws:
Identified Costs
  • National Institute of Standards and Technology program staff
  • Research contractors maintaining the national AI-flaw database
  • Artificial intelligence companies voluntarily documenting flaws
  • Academic researchers voluntarily reporting AI flaws
  • Nonprofit and civil-society organizations joining program consultations
Model: codex-gpt-5 | Version: bill_summary_v2 | Source: ih
Academic researchers voluntarily reporting AI flaws:
National Institute of Standards and Technology program staff:
Research contractors maintaining the national AI-flaw database:
Artificial intelligence companies voluntarily documenting flaws:
Nonprofit and civil-society organizations joining program consultations:

Legislative Progress

Reported
Introduced Committee Passed
Jun 25, 2026

Ordered to be Reported in the Nature of a Substitute …

Jun 25, 2026

Committee Consideration and Mark-up Session Held

Jun 18, 2026

Ms. Ross (for herself, Mr. Hurd of Colorado, and Mr. …

Jun 18, 2026

Referred to the House Committee on Science, Space, and Technology.

Jun 18, 2026

Introduced in House

Stakeholder Effects

cui bono?

How this legislation distributes effects. Mention counts reflect frequency, not effect magnitude.

Technology
4 mentions across 1 clause
+3 positive -1 negative

Artificial intelligence companies voluntarily documenting flaws, Artificial intelligence developers using standardized flaw data, Artificial intelligence standards organizations

Positive-direction: Artificial intelligence developers using standardized flaw data, Artificial intelligence standards organizations, Artificial intelligence users exposed to safety and security flaws

Negative-direction: Artificial intelligence companies voluntarily documenting flaws

Government
2 mentions across 1 clause
-1 negative ?1 uncertain

Cybersecurity and Infrastructure Security Agency AI analysts, National Institute of Standards and Technology AI-flaw program staff

Education
1 mention across 1 clause
+1 positive

Universities eligible for NIST cooperative agreements

Research & Science
1 mention across 1 clause
+1 positive

Research institutions eligible to maintain the national AI-flaw database

2/2
sections analyzed
Full impact breakdown

Bill Structure & Actor Mappings

Who is "The Secretary" in each section?

Domains
Artificial Intelligence Cybersecurity Science and Technology Public Safety Education
Actor Mappings
"cisa_director"
→ Director of the Cybersecurity and Infrastructure Security Agency
"nist_director"
→ Director of the National Institute of Standards and Technology
"eligible_entities"
→ Universities, research institutions, and their consortia

Note: {'scope_ids': ['voluntary_ai_flaw_reporting'], 'description': "Outside reporting is voluntary, but NIST's duty to operate the program, develop the infrastructure and database, and report to Congress is mandatory."}

Key Definitions

Terms defined in this bill

3 terms
"eligible entity" §eligible_entity

An institution of higher education, a research institution under the Small Business Act definition, or a consortium of those entities.

"artificial intelligence flaw" §artificial_intelligence_flaw

Conditions or behaviors that permit violation of an explicit or implicit safety, security, or undesirable-effects policy for an AI system, including vulnerabilities and incidents, whether or not malicious intent or related harm is present.

"artificial intelligence system" §artificial_intelligence_system

The term as defined in section 7223 of the Advancing American AI Act.

We use a combination of our own taxonomy and classification in addition to large language models to assess meaning and potential beneficiaries. High confidence means strong textual evidence. Always verify with the original bill text.

Learn more about our methodology