AI Flaw Reporting and Security Enhancement Act
Summary
What This Bill Does
The AI Flaw Reporting and Security Enhancement Act would require the National Institute of Standards and Technology, in consultation with the Cybersecurity and Infrastructure Security Agency, to operate a program supporting voluntary reporting, collection, and tracking of artificial-intelligence flaws. NIST must convene industry, universities, research institutions, nonprofits, standards organizations, civil-society groups, and public agencies to create common definitions and taxonomies for AI vulnerabilities, failure modes, accidents, hazards, misuse, incidents, and other safety or security problems. The program would also develop standards, severity or risk measures, detection methods, reporting practices, documentation formats, and norms for deciding whether and when flaws should be disclosed publicly.
NIST must build the reporting infrastructure itself or use cooperative agreements with one or more eligible universities, research institutions, or consortia. The infrastructure must include a national AI-flaw database or modify an existing national database. NIST must consider machine readability, interoperability with existing systems, future taxonomy and stakeholder updates, and policies for dissemination and public disclosure. Within three years of enactment, NIST must report to Congress on stakeholder findings, the infrastructure and database, and recommendations for standardized voluntary reporting mechanisms.
Who Benefits and How
AI developers, deployers, security teams, researchers, and standards organizations could use common terminology and severity measures to detect, compare, prioritize, and remediate flaws. AI users and members of the public could benefit from earlier identification of safety and security problems and more consistent public-disclosure practices. Universities, research institutions, and their consortia could receive cooperative agreements to develop or maintain the database. NIST, CISA, and other public agencies would gain a shared source of standardized information about emerging AI risks. Congressional committees would receive an implementation assessment and policy recommendations.
Who Bears the Burden and How
NIST staff must convene stakeholders, design definitions and standards, build or contract for reporting infrastructure, manage the national database, coordinate with CISA and other agencies, and prepare the three-year report. Universities or research contractors selected under cooperative agreements must develop, secure, maintain, and update the infrastructure. AI companies, academic researchers, nonprofits, and civil-society organizations that choose to participate may incur reporting, documentation, review, and disclosure costs, but the bill does not require them to submit a flaw. AI providers whose flaws are eventually disclosed could face remediation and reputational pressure, with the disclosure rules left to program norms rather than fixed by the bill.
Key Provisions
- Requires NIST and CISA consultation on a voluntary AI-flaw reporting and tracking program.
- Directs stakeholders to develop common flaw definitions, taxonomies, technical standards, risk measures, detection methods, and disclosure norms.
- Requires a national AI-flaw database that NIST or eligible research entities may develop and maintain.
- Allows cooperative agreements with universities, research institutions, or consortia for the reporting infrastructure.
- Requires NIST to report to Congress within three years on implementation and future standardized voluntary-reporting mechanisms.
Evidence Chain:
This summary is generated from the full bill text using AI analysis. Expand "Detailed Analysis" below for identified beneficiaries/burden bearers with clause-level evidence links.
At a Glance
What This Bill Does
Require NIST, in consultation with CISA and outside stakeholders, to create a voluntary national system for defining, reporting, tracking, prioritizing, and disclosing artificial-intelligence safety and security flaws.
Key Policy Areas
Artificial Intelligence, Cybersecurity, Science and Technology, Public Safety, Education
Primary Purpose
Require NIST, in consultation with CISA and outside stakeholders, to create a voluntary national system for defining, reporting, tracking, prioritizing, and disclosing artificial-intelligence safety and security flaws.
Policy Domains
Section 2 - voluntary artificial-intelligence flaw reporting
Identified Gains
- Artificial intelligence developers and security teams
- Artificial intelligence users exposed to safety and security flaws
- Universities eligible for NIST cooperative agreements
- Research institutions eligible to maintain the national database
- Cybersecurity and Infrastructure Security Agency analysts
- Artificial intelligence standards organizations
Identified Costs
- National Institute of Standards and Technology program staff
- Research contractors maintaining the national AI-flaw database
- Artificial intelligence companies voluntarily documenting flaws
- Academic researchers voluntarily reporting AI flaws
- Nonprofit and civil-society organizations joining program consultations
Sponsors
Legislative Progress
ReportedOrdered to be Reported in the Nature of a Substitute …
Committee Consideration and Mark-up Session Held
Ms. Ross (for herself, Mr. Hurd of Colorado, and Mr. …
Referred to the House Committee on Science, Space, and Technology.
Introduced in House
Stakeholder Effects
cui bono?How this legislation distributes effects. Mention counts reflect frequency, not effect magnitude.
Artificial intelligence companies voluntarily documenting flaws, Artificial intelligence developers using standardized flaw data, Artificial intelligence standards organizations
Positive-direction: Artificial intelligence developers using standardized flaw data, Artificial intelligence standards organizations, Artificial intelligence users exposed to safety and security flaws
Negative-direction: Artificial intelligence companies voluntarily documenting flaws
Cybersecurity and Infrastructure Security Agency AI analysts, National Institute of Standards and Technology AI-flaw program staff
Universities eligible for NIST cooperative agreements
Research institutions eligible to maintain the national AI-flaw database
Bill Structure & Actor Mappings
Who is "The Secretary" in each section?
- "cisa_director"
- → Director of the Cybersecurity and Infrastructure Security Agency
- "nist_director"
- → Director of the National Institute of Standards and Technology
- "eligible_entities"
- → Universities, research institutions, and their consortia
Note: {'scope_ids': ['voluntary_ai_flaw_reporting'], 'description': "Outside reporting is voluntary, but NIST's duty to operate the program, develop the infrastructure and database, and report to Congress is mandatory."}
Key Definitions
Terms defined in this bill
An institution of higher education, a research institution under the Small Business Act definition, or a consortium of those entities.
Conditions or behaviors that permit violation of an explicit or implicit safety, security, or undesirable-effects policy for an AI system, including vulnerabilities and incidents, whether or not malicious intent or related harm is present.
The term as defined in section 7223 of the Advancing American AI Act.
We use a combination of our own taxonomy and classification in addition to large language models to assess meaning and potential beneficiaries. High confidence means strong textual evidence. Always verify with the original bill text.
Learn more about our methodology