HouseH.R. 9965119th Congress
AI Threat Output and Monitoring Incident Containment Act
Full Text
Official text as published. Use Ctrl+F / Cmd+F to search within the document.
[Congressional Bills 119th Congress]
[From the U.S. Government Publishing Office]
[H.R. 9965 Introduced in House (IH)]
<DOC>
119th CONGRESS
2d Session
H. R. 9965
To direct the National Nuclear Security Administration through the
Secretary of Energy to establish the Advanced Artificial Intelligence
Nuclear Evaluation Program, and for other purposes.
_______________________________________________________________________
IN THE HOUSE OF REPRESENTATIVES
July 27, 2026
Ms. Maloy (for herself and Ms. Jacobs) introduced the following bill;
which was referred to the Committee on Science, Space, and Technology
_______________________________________________________________________
A BILL
To direct the National Nuclear Security Administration through the
Secretary of Energy to establish the Advanced Artificial Intelligence
Nuclear Evaluation Program, and for other purposes.
Be it enacted by the Senate and House of Representatives of the
United States of America in Congress assembled,
SECTION 1. SHORT TITLE.
This Act may be cited as the ``AI Threat Output and Monitoring
Incident Containment Act''.
SEC. 2. ADVANCED ARTIFICIAL INTELLIGENCE NUCLEAR EVALUATION PROGRAM.
(a) In General.--Not later than 90 days after the date of the
enactment of this Act, the Secretary of Energy (in this section
referred to as the ``Secretary''), acting through the National
Laboratories, shall establish a program, to be known as the ``Advanced
Artificial Intelligence Nuclear Evaluation Program'' (in this section
referred to as the ``Program''), to carry out the following:
(1) Test and evaluate artificial intelligence to assess the
likelihood of an AI nuclear incident with respect to such
artificial intelligence.
(2) Implement in such testing and evaluation protocols to
address practical jailbreaking techniques for such artificial
intelligence, including such protocols for red-teaming by
entities that have expertise the Secretary determines
comparable to sophisticated malicious actors.
(3) Facilitate to the extent practicable independent,
third-party assessments and blind model evaluations of such
artificial intelligence.
(4) Provide to each participant in the Program a report
that includes information relating to the following:
(A) The outcomes from such testing and evaluation
with respect to the artificial intelligence of such
participant.
(B) An identification of the risks and safety
measures so tested and evaluated.
(5) Develop for large advanced artificial intelligence
developers and the National Laboratories recommendations on
containment protocols, contingency planning, and mitigation
strategies for AI nuclear incidents and loss-of-control
scenarios, that are based on data from such testing and
evaluation.
(6) Based on the recommendations developed under paragraph
(5), issue or revise such policies, orders, notices, manuals,
guides, and technical standards under the Department Directives
Program as the Secretary determines appropriate to govern the
conduct of the National Laboratories with respect to AI nuclear
incidents and loss-of-control scenarios.
(b) Participation.--Large advanced artificial intelligence
developers shall participate in the Program.
(c) Prohibitions.--Large advanced artificial intelligence
developers may not--
(1) fail to participate in the Program as required by
subsection (b);
(2) knowingly make or cause to be made a materially false,
fictitious, or fraudulent statement or representation with
respect to such developer's participation in the Program;
(3) knowingly conceal from the Secretary or fail to
disclose to the Secretary material information that the
developer is required to provide in connection with the
Program;
(4) impede or obstruct, or attempt to impede or obstruct,
the Program;
(5) fail to provide secure access to artificial
intelligence, including model weights and, as necessary for
testing and evaluation under subsection (a), versions of such
artificial intelligence without safety mitigations,
information, or documentation necessary for such testing and
evaluation; and
(6) alter, destroy, falsify, or conceal a record relevant
to the Program with the intent to impede or obstruct the
Program.
(d) Enforcement.--
(1) Civil penalty.--
(A) In general.--If the Secretary determines after
reasonable notice and opportunity for a hearing that a
large advanced artificial intelligence developer has
violated this section, the Secretary may assess on such
developer a civil penalty of not more than $1 million
for such violation. In the case of a continuing
violation, including a failure to participate in
accordance with subsection (b), each day during which
the violation continues constitutes a separate
violation.
(B) Factors.--In determining the amount of a civil
penalty to be assessed under subparagraph (A), the
Secretary shall consider the following factors:
(i) The nature, circumstances, extent,
gravity, and duration of the violation at
issue.
(ii) The degree of culpability of the large
advanced artificial intelligence developer at
issue.
(iii) Previous violations, if any, of this
section by such developer.
(iv) Good-faith efforts, if any, by such
developer to comply with this section.
(v) Whether such developer voluntarily
disclosed to the Secretary such violation.
(vi) Any other factor that justice may
require.
(2) Subpoena.--If a large advanced artificial intelligence
developer fails to participate in accordance with subsection
(b), or fails to provide access as required by subsection
(c)(5), the Secretary may issue to such developer a subpoena to
compel the production of such artificial intelligence
(including model weights and related software), and of such
information and documentation, as is necessary for testing and
evaluation under subsection (a).
(3) Civil action.--If the Secretary believes that a
violation of this section has occurred, is occurring, or is
about to occur, the Secretary may refer the matter to the
Attorney General to bring in an appropriate district court of
the United States a civil action for relief.
(e) Confidentiality.--
(1) In general.--Subject to paragraph (2), information
submitted through the Program by a participant in the Program
is exempt from disclosure under section 552(b)(3) of title 5,
United States Code.
(2) Exceptions.--The Secretary may not disclose information
referred to in paragraph (1) unless any of the following
requirements are satisfied:
(A) Such information is required to be disclosed
pursuant to a court order or other legal process.
(B) The Program participant at issue has consented
to such disclosure.
(C) A committee of Congress has requested such
information.
(D) The Secretary determines such information
should be disclosed to a third party or the public, for
a purpose relating to the national security, public
safety, or critical infrastructure of the United States
or an ally of the United States.
(E) Such information satisfies the following
requirements:
(i) Is anonymized or aggregated.
(ii) Does not include a trade secret or
confidential business information of such
participant.
(3) Notice.--If the Secretary is to disclose pursuant to
subparagraph (A), (C), or (D) of paragraph (2) information
referred to in paragraph (1), the Secretary shall as soon as
practicable notify each Program participant whose information
is to be so disclosed, of such disclosure.
(f) Recommendations for Legislation.--
(1) Report.--Not later than 1 year after the date of the
enactment of this Act, the Secretary shall carry out the
following:
(A) Assess data from the Program to identify
trends, capabilities, and risks regarding artificial
intelligence, including with respect to the following:
(i) Evaluation awareness.
(ii) Potential for an AI nuclear incident.
(iii) Scheming behavior.
(B) Develop based on such assessment
recommendations for legislation to prevent such an
incident, which may include legislation regarding any
of the following:
(i) Appropriations.
(ii) A certification or licensing process.
(iii) Establishing a new Federal agency, or
establishing a new office in an existing
Federal agency.
(iv) Regulatory oversight.
(C) Submit to Congress a report that includes
information relating to such recommendations.
(2) Updates.--Not later than 1 year after submitting the
report under subparagraph (C) of paragraph (1) and annually
thereafter until the Program terminates, the Secretary shall
carry out the following:
(A) Update based on data from the Program the
recommendations referred to in subparagraph (B) of such
paragraph.
(B) Submit to Congress a report that includes
information relating to such recommendations, as so
updated.
(g) Nonapplicability of the Paperwork Reduction Act.--Subchapter I
of chapter 35 of title 44, United States Code (commonly known as the
``Paperwork Reduction Act''), does not apply to the Program.
(h) Termination.--The Program shall terminate on the date 7 years
after the date of the enactment of this Act.
(i) Definitions.--In this section:
(1) Advanced artificial intelligence.--
(A) In general.--The term ``advanced artificial
intelligence'' means any of the following:
(i) Artificial intelligence trained
utilizing a quantity of computing power greater
than 10\26\ integer or floating-point
operations (or another quantity of computing
power specified by the Secretary under
subparagraph (B)).
(ii) Other artificial intelligence
specified by the Secretary under subparagraph
(B).
(B) Determinations.--A determination of the
Secretary under clause (i) or (ii) of subparagraph (A)
shall be made by rule. In making such a determination,
the Secretary shall consider the following:
(i) Developments in artificial intelligence
research, and in the testing and evaluation of
artificial intelligence, occurring after the
date of the enactment of this Act or after the
date of the most recent determination under
this subparagraph, as the case may be.
(ii) The need to include in the Program
artificial intelligence that may pose a serious
risk of causing an AI nuclear incident.
(iii) Data collected through the Program.
(2) Affiliate.--The term ``affiliate'' means an entity that
owns or controls, is owned or controlled by, or is under common
ownership or control with, another entity.
(3) AI nuclear incident.--The term ``AI nuclear incident''
means an incident that involves artificial intelligence and any
of the following (or an attempt thereof):
(A) The generation of technical information,
instructions, or assistance that is reasonably likely
to serve as a substantial factor in the unlawful
development, acquisition, or utilization of a nuclear
weapon or nuclear material (as such term is defined in
section 831 of title 18, United States Code).
(B) The generation of Restricted Data (as such term
is defined in section 11 of the Atomic Energy Act of
1954 (42 U.S.C. 2014)).
(C) A loss-of-control scenario that involves
systems utilized in connection with such weapon, such
material, a nuclear facility (as such term is defined
in section 2332i of such title), or the nuclear
stockpile.
(D) A foreign terrorist organization or foreign
adversary obtaining unauthorized access to,
manipulating, or otherwise interfering with, such a
system.
(E) Weaponization of such weapon, material,
facility, or stockpile, as the case may be, by such
organization or adversary, as the case may be.
(F) Scheming behavior relating to such weapon,
material, facility, or stockpile, as the case may be.
(4) Artificial intelligence.--The term ``artificial
intelligence'' has the meaning given such term in section
238(g) of the National Defense Authorization Act for Fiscal
Year 2019 (Public Law 115-232, 10 U.S.C. note prec. 4061).
(5) Computing power.--The term ``computing power'' means
the processing power and other electronic resources utilized to
train, validate, deploy, and run artificial intelligence.
(6) Critical infrastructure.--The term ``critical
infrastructure'' has the meaning given such term in section
1016 of the USA PATRIOT Act (42 U.S.C. 5195c).
(7) Deploy.--The term ``deploy'' means to release, sell, or
otherwise provide access to artificial intelligence.
(8) Evaluation awareness.--The term ``evaluation
awareness'' means the capability of artificial intelligence to
determine such artificial intelligence is undergoing a test,
evaluation, or assessment, and modify the behavior, output, or
performance of such artificial intelligence in a manner that
might cause such test, evaluation, or assessment, as the case
may be, to yield a result that is not representative of the
ordinary behavior, output, or performance of such artificial
intelligence.
(9) Foreign adversary.--The term ``foreign adversary''
means a foreign government referred to in subsection (a) of
section 791.4 of title 15, Code of Federal Regulations, or a
successor regulation.
(10) Foreign terrorist organization.--The term ``foreign
terrorist organization'' means an organization designated under
section 219 of the Immigration and Nationality Act (8 U.S.C.
1189).
(11) High-stakes context.--The term ``high-stakes context''
means a context in which the operation or output of artificial
intelligence could reasonably be foreseen to bear materially on
any of the following:
(A) The safety of human life.
(B) The security, reliability, or integrity of any
of the following:
(i) Critical infrastructure.
(ii) A national security system (as such
term is defined in section 3552 of title 44,
United States Code).
(iii) Another system the failure or
compromise of which would foreseeably endanger
such life or cause substantial physical or
economic harm.
(12) Jailbreaking.--The term ``jailbreaking'' means an
adversarial technique to circumvent a safety restriction,
alignment measure, or use restriction of artificial
intelligence and elicit a harmful or prohibited behavior or
output by such artificial intelligence.
(13) Large advanced artificial intelligence developer.--The
term ``large advanced artificial intelligence developer'' means
an entity that satisfies the following requirements:
(A) Develops, owns, or substantially modifies
advanced artificial intelligence for utilization in
interstate or foreign commerce, including by initiating
a training run of such artificial intelligence.
(B) Had collectively with the affiliates, if any,
of such entity expended in the five calendar years
immediately preceding the calendar year at issue not
less than $2,000,000,000 on investments to develop or
modify artificial intelligence, including such expenses
with respect to any combination of the following:
(i) Computing power.
(ii) Data procurement.
(iii) Personnel.
(iv) Infrastructure.
(v) Research and development, including
algorithm development.
(14) Loss-of-control scenario.--The term ``loss-of-control
scenario'' means a scenario in which artificial intelligence
pursues an objective that is different from any of the
objectives intended by a human developer or operator of such
artificial intelligence, by--
(A) behaving contrary to human instruction in a
high-stakes context,
(B) altering without authorization from such
developer or operator, as the case may be, the
constraints of such artificial intelligence, or
(C) subverting an oversight or shutdown mechanism,
that results in the death of not fewer than five individuals,
serious bodily injury to not fewer than 50 individuals, or more
than $100,000,000 in damages.
(15) National laboratory.--The term ``National Laboratory''
has the meaning given such term in section 2 of the Energy
Policy Act of 2005 (42 U.S.C. 15801).
(16) Red-teaming.--The term ``red-teaming'' means
structured testing in which an entity utilizes an adversarial
method to identify a flaw, vulnerability, undesirable behavior,
or dangerous capability of artificial intelligence, including
the potential, if any, for an AI nuclear incident involving
such artificial intelligence.
(17) Scheming behavior.--The term ``scheming behavior''
means behavior that artificial intelligence carries out to
deceive a human, including any of the following behaviors by
such artificial intelligence:
(A) Hiding a capability or objective of such
artificial intelligence.
(B) Attempting to subvert an oversight or shutdown
mechanism relating to such artificial intelligence.
(18) Substantially modify.--The term ``substantially
modify'' means, with respect to artificial intelligence, to
carry out an action that costs not less than $5,000,000 and
materially alters the functionality or performance of such
artificial intelligence.
<all>