SenateS. 5576119th Congress
Artificial Intelligence Risk Management and Security Act of 2026
Full Text
Official text as published. Use Ctrl+F / Cmd+F to search within the document.
[Congressional Bills 119th Congress]
[From the U.S. Government Publishing Office]
[S. 5576 Introduced in Senate (IS)]
<DOC>
119th CONGRESS
2d Session
S. 5576
To establish the Artificial Intelligence Safety Board, and for other
purposes.
_______________________________________________________________________
IN THE SENATE OF THE UNITED STATES
September 29, 2026
Mr. Warner (for himself, Mr. Schatz, and Mr. Kim) introduced the
following bill; which was read twice and referred to the Committee on
Commerce, Science, and Transportation
_______________________________________________________________________
A BILL
To establish the Artificial Intelligence Safety Board, and for other
purposes.
Be it enacted by the Senate and House of Representatives of the
United States of America in Congress assembled,
SECTION 1. SHORT TITLE.
This Act may be cited as the ``Artificial Intelligence Risk
Management and Security Act of 2026''.
SEC. 2. DEFINITIONS.
In this Act:
(1) Artificial intelligence; artificial intelligence
system.--The terms ``artificial intelligence'' and ``artificial
intelligence system'' has the meaning given the term
``artificial intelligence'' in section 5002 of the National
Artificial Intelligence Initiative Act of 2020 (15 U.S.C.
9401).
(2) Artificial intelligence agent.--The term ``artificial
intelligence agent''--
(A) means an artificial intelligence system or
process that, given an objective or instruction--
(i) determines the action or sequence of
actions to be taken to accomplish that
objective; and
(ii) is capable of executing such actions
directly on information systems, data, or
external services; and
(B) does not include a system or process that
solely generates informational or advisory output for a
human operator to act upon.
(3) Artificial intelligence capabilities or risk
assessment.--The term ``artificial intelligence capabilities or
risk assessment'' means information regarding an assessment
performed by a developer of an artificial intelligence system
evaluating the capabilities of, or risks posed by, such system,
including an assessment of the potential of the artificial
intelligence system--
(A) to materially assist in the design,
development, acquisition, or use of a chemical,
biological, radiological, or nuclear weapon;
(B) to materially assist in the design,
development, or production of munitions or other
weapons;
(C) to materially assist in the unlawful
manufacture, synthesis, or distribution of a controlled
substance;
(D) to evade the control of, or act outside the
intended instructions of, its developer or operator;
(E) to facilitate a cybersecurity threat, including
through the discovery or exploitation of a security
vulnerability;
(F) to be subject to the unauthorized exfiltration
of the weights of the artificial intelligence system,
or unauthorized, deliberate, malicious modification of
such weights; or
(G) to be transformed, stolen, reverse-engineered,
or otherwise manipulated by an unauthorized user or
users acting outside of the terms of service governing
access to the artificial intelligence system.
(4) Artificial intelligence flaw.--The term ``artificial
intelligence flaw'' means a recurring or reproducible
characteristic, behavior, or failure mode of an artificial
intelligence system that causes, or materially increases the
risk of, an artificial intelligence safety incident absent any
intentional act of a user, including a characteristic,
behavior, or failure mode that may manifest across multiple
systems or providers.
(5) Artificial intelligence safety incident.--The term
``artificial intelligence safety incident'' means an event that
materially increases the risk that operation of an artificial
intelligence system leads to a state in which human life,
health, property, or the environment is endangered.
(6) Artificial intelligence security incident.--The term
``artificial intelligence security incident'' means an event
that materially increases--
(A) the risk that operation of an artificial
intelligence system occurs in a way that enables the
unauthorized extraction of information about the
behavior or characteristics of the system by an
unauthorized party; or
(B) the ability to manipulate an artificial
intelligence system in order to subvert the
confidentiality, integrity, or availability of the
system or adjacent system.
(7) Artificial intelligence security vulnerability.--The
term ``artificial intelligence security vulnerability'' means a
weakness in an artificial intelligence system that could be
exploited by a third party to subvert, without authorization,
the confidentiality, integrity, or availability of the system,
including through techniques such as--
(A) data poisoning;
(B) evasion attacks;
(C) privacy-based attacks;
(D) model theft or extraction attacks;
(E) attacks designed to circumvent or degrade the
safety, alignment, or access control mechanisms of an
artificial intelligence system; and
(F) adversarial machine learning attacks as
described in National Institute of Standards and
Technology Trustworthy and Responsible Artificial
Intelligence 100-2e2025 (relating to Adversarial
Machine Learning), or successor publication.
(8) Board.--The term ``Board'' means the Artificial
Intelligence Safety Board established under section 3.
(9) Critical infrastructure.--The term ``critical
infrastructure'' has the meaning provided in section 1016(e) of
the USA Patriot Act of 2001 (42 U.S.C. 5195c(e)).
(10) Developer.--The term ``developer'' means a developer
of a frontier artificial intelligence model.
(11) Frontier artificial intelligence model.--The term
``frontier artificial intelligence model'' means an artificial
intelligence model, or system combining multiple artificial
intelligence models, that exhibits or could be modified to
exhibit high levels of performance at tasks that pose a serious
risk to national security, national economic security, or
public health or safety.
(12) Institute.--The term ``Institute'' means the National
Institute of Standards and Technology.
(13) Secretary.--The term ``Secretary'' means the Secretary
of Commerce.
SEC. 3. ARTIFICIAL INTELLIGENCE SAFETY BOARD.
(a) Artificial Intelligence Safety Board.--
(1) Establishment.--
(A) In general.--Not later than 30 days after the
date of the enactment of this Act, the Secretary shall
establish within the Department of Commerce a board to
address artificial intelligence risks.
(B) Designation.--The board established under
subparagraph (A) shall be known as the ``Artificial
Intelligence Safety Board'' (referred to in this Act as
the ``Board'').
(C) Permanent status.--The Board shall be a
permanent advisory committee, and section 1013 of title
5, United States Code, shall not apply to the Board.
(2) Membership.--
(A) Composition.--The Board shall be composed of
members who are appointed as follows:
(i) One member selected by the Director of
the Institute.
(ii) One member selected by the Secretary.
(iii) One member selected by the Director
of the Cybersecurity and Infrastructure
Security Agency.
(iv) One member selected by the Director of
the National Security Agency.
(v) One member selected by the Secretary of
the Treasury.
(B) Nongovernmental experts.--In addition to the
members of the Board appointed under subparagraph (A),
the Secretary shall appoint members who are not
officers or employees of the Federal Government and who
the Secretary selects from among individuals who--
(i) are leading technical experts not
affiliated with a developer or provider of
artificial intelligence systems;
(ii) are leading technical experts
affiliated with developers or providers of
artificial intelligence systems;
(iii) are individuals with expertise in
developing evaluations to test artificial
intelligence systems;
(iv) are individuals with expertise in
consumer protection and antitrust
jurisprudence; and
(v) have knowledge or expertise that the
Secretary determines would further the purpose
of the duties of the Board.
(C) International participation.--The Secretary, in
coordination with and subject to the agreement of the
Secretary of State, shall undertake negotiations with
foreign partners, and enter into agreements as
appropriate and subject to the disclosure requirements
of section 112b of title 1, United States Code, to
facilitate cooperative activities, regulatory
reciprocity, and appropriate protection of intellectual
property rights associated with addressing artificial
intelligence safety and security risks, including--
(i) the establishment of joint testing
environments;
(ii) jointly conducting competitive
processes or competitive research programs to
award cash prizes or other types of recognition
for basic, advanced, and applied research,
technology development, and prototype
development that advance the security and
safety of frontier artificial intelligence
models;
(iii) promulgating joint advisories or
technical guidance concerning security or
safety risks associated with frontier
artificial intelligence systems;
(iv) facilitating of secure information
sharing regarding artificial intelligence
security or safety incidents; and
(v) standardizing evaluation protocols.
(3) Terms and vacancies.--
(A) Terms.--Each member of the Board shall serve
for a term of not longer than 3 years and may be
reappointed for 1 successive term.
(B) Vacancy replacement.--The members of the Board
shall develop a vacancy replacement procedure that
includes--
(i) for vacancies occurring due to the end
of a member's term, a vote not later than 90
days before the last day of the member's term;
and
(ii) for vacancies occurring under
subparagraph (C) or for any other reason, the
chair of the Board shall nominate a replacement
from the same stakeholder category under
paragraph (2), to the extent practicable, as
the member creating the vacancy, subject to
approval by a majority vote of the members of
the Board.
(C) Removal.--A member shall be removed from the
Board if--
(i) the member fails to comply with the
conflict of interest policy adopted pursuant to
paragraph (5)(D); or
(ii) the member is denied the requisite
security clearance under paragraph (4)(A)(iii).
(D) Chair.--The chair of the Board shall be
selected by a majority vote among a quorum of the
members appointed under paragraph (2) and shall serve
not more than one 2-year term.
(4) Member access to classified information.--
(A) Access.--
(i) In general.--Not later than 60 days
after the date on which a member is first
appointed to the Board and before the member is
granted access to any classified information
necessary to participate in a closed session
pursuant to paragraph (5)(F), the Secretary
shall determine, for the purposes of the Board,
if the member should be restricted from
reviewing, discussing, or possessing classified
information.
(ii) Management.--Access to classified
information shall be managed in accordance with
Executive Order 13526 (50 U.S.C. 3161 note;
relating to classified national security
information), or any subsequent corresponding
Executive order.
(iii) Clearance requirement.--
(I) In general.--The Secretary
shall sponsor each member of the Board
for a security clearance at the Top
Secret level with access to sensitive
compartmented information, as
appropriate, for the purposes of
participating in carrying out the
duties of the Board.
(II) Denial.--Any member who fails
to obtain a security clearance,
including by being denied by the
appropriate authorities or if the
Secretary determines the member should
be restricted from reviewing,
discussing, or possessing classified
information, shall be removed from the
Board and a new member shall be
appointed pursuant to the vacancy
procedures under paragraph (3)(B).
(B) Protection of information.--A member of the
Board granted access to classified information shall
sign and comply with the agreements to protect such
information from unauthorized disclosure and to
otherwise protect the classified information in
accordance with the applicable requirements for the
particular level of classification of the information.
(C) Rule of construction.--Nothing in this
paragraph shall be construed to affect the existing
security clearance of a member of the Board or the
authority of a Federal agency to provide or deny a
member of the Board access to any specific pieces of
classified information.
(5) Procedures.--
(A) Designated federal officer.--The Secretary
shall designate a Federal officer or employee to serve
as the designated Federal officer of the Board,
consistent with the requirements of chapter 10 of title
5, United States Code (commonly known as the ``Federal
Advisory Committee Act'').
(B) Initial meeting and bylaws.--Not later than 60
days after the date of the enactment of this Act, the
Board shall convene and establish bylaws that--
(i) govern quorum and voting rules,
including implementation of the decisionmaking
majority voting requirement specified in
paragraph (5)(C)(ii); and
(ii) set deliverable timelines and meeting
schedules.
(C) Operating procedures.--Unless otherwise
specified, the Board shall adopt written procedures
governing its meetings, consistent with chapter 10 of
title 5, United States Code, that include--
(i) requirements for public notice of
meetings and the maintenance of records and
minutes;
(ii) decisionmaking by majority vote of
those present and voting;
(iii) authorization for the establishment
of subgroups as necessary, subject to the
approval of the chair of the Board; and
(iv) approval of the meeting agendas by the
chair in consultation with the designated
Federal officer under subparagraph (A) to
ensure compliance with applicable laws.
(D) Conflict-of-interest policy.--
(i) In general.--The Board shall adopt and
enforce a written conflict of interest policy
to ensure that members of the Board have a
fiduciary responsibility to the Board, a duty
to report conflicts of interest, including the
appearance of a conflict of interest, and do
not participate in deliberations or votes from
which they personally or their employer would
directly and materially benefit.
(ii) Required disclosures.--The policy
under clause (i) shall require each member to
publicly disclose all relevant financial and
employment relationships, including
relationships held by a spouse or immediate
family member, and include recusal procedures
in the event of a conflict.
(iii) Records.--The designated Federal
officer under subparagraph (A) shall maintain
records of disclosures under clause (ii) of
this subparagraph and make summaries of the
disclosures available to the Secretary.
(E) Threat information access.--The Director of
National Intelligence, in coordination with the heads
of other appropriate Federal entities, shall ensure
that the Board has access to relevant intelligence,
including through closed or classified briefings or the
provision of classified information, when appropriate.
(F) Closed sessions.--Notwithstanding section 1009
of title 5, United States Code, the Board may hold
closed or restricted-access sessions when the Secretary
determines that the matters to be discussed involve any
of the following:
(i) Classified information.
(ii) An artificial intelligence security
incident.
(iii) An artificial intelligence security
vulnerability.
(iv) An artificial intelligence flaw.
(v) Threat information.
(vi) Proprietary business information.
(vii) Other information exempt from public
disclosure under section 552 of title 5, United
States Code.
(6) Duties.--
(A) In general.--The Board shall--
(i) develop a process to perform technical
evaluations to determine what capabilities or
combination of capabilities constitute high
levels of performance at tasks that pose a
serious risk to national security, national
economic security, or public health or safety;
(ii) develop processes and metrics for
evaluating risks posed by frontier artificial
intelligence models, model variants,
checkpoints, or other artificial intelligence
models or versions used during development,
training, testing, evaluation, or red-teaming,
including versions that are not publicly
available, whether or not they are intended for
eventual public release, where such models,
variants, checkpoints, or other versions meet
or could be modified to meet the risks
described in section 2(3);
(iii) develop technical standards and
conformity assessment methodologies,
including--
(I) standardize formats and
processes for publishing model or
system cards with technical details of
artificial intelligence systems;
(II) recommendations for
maintaining cybersecurity measures for
developers or providers of artificial
intelligence systems across the
lifecycle;
(III) processes and security
controls for developers or providers of
artificial intelligence systems to use
to evaluate risks from employees or
other personnel who have access to
artificial intelligence systems
developed or in development; and
(IV) recommendations on appropriate
financial and other resourcing for
developers or providers of artificial
intelligence systems, including small-
and medium-sized developers or
providers, to robustly engage in safety
and security research focused on the
deployment of frontier artificial
intelligence models; and
(iv) establish technical standards,
security controls, and reference architectures
for securing testing environments during
evaluations of frontier artificial intelligence
models, or models with known or reasonably
foreseeable capabilities to discover and
exploit software vulnerabilities without direct
prompting by a human user, including--
(I) procedures for effective risk-
modeling prior to commencing any
evaluation;
(II) technical controls to ensure
effective isolation and hardening of
evaluation environments, including
continuous re-evaluation of security
configurations throughout evaluations;
(III) policies and procedures for
continuous monitoring of model
behavior, including monitoring in real-
time, using pre-established or
conditional checkpoints, and through
post-evaluation audits;
(IV) policies, procedures, and
technical controls for continuous
monitoring of evaluation environments,
including automated identification of
changes to security controls or
configurations;
(V) policies, procedures, and
technical controls for safeguarding
identity and access management
resources associated with the
evaluation environment, or encompassing
systems, from access by any model under
evaluation; and
(VI) conditions, policies,
procedures, and technical controls for
prompt termination of any evaluation in
which a model has operated beyond the
policies, procedures, or technical
controls described in clauses (I)
through (V) or that otherwise poses an
imminent risk to any individual or
property outside the scope of the
evaluation.
(B) Periodic reassessment of technical evaluations
and best practices.--Not less frequently than once
every year, the Board shall--
(i) review each standard developed under
subparagraph (A);
(ii) determine whether the standard should
be modified or revoked; and
(iii) submit to the Secretary any proposed
modification or revocation.
(7) Support staff.--The Director of the Institute, acting
through the Center for Artificial Intelligence Standards and
Innovation (or any successor office or entity), shall provide
staff and other support necessary to assist the Board in
carrying out its duties under this Act. Such staff shall work
under the direction of the Board, shall exercise on behalf of
the Board the access provided to the Board under subsection
(f), and shall remain employees of the Institute.
(b) Adoption of Standards.--
(1) Deadline for submission of standards.--Not later than
90 days after the date of the establishment of the Board under
subsection (a)(1), the Board shall develop and submit to the
Secretary the proposed standards required under subsection
(a)(6).
(2) Adoption of standards.--
(A) In general.--Not later than 30 days after the
date on which the Secretary receives a proposed
standard under paragraph (1), the Secretary shall adopt
the proposed standard or the modified standards by
rule.
(B) Modification of standard.--The Secretary may
modify a proposed standard received under paragraph (1)
if the Secretary determines that the modification is
necessary for the purpose of national security.
(C) Publication.--The Secretary shall publish in
the Federal Register the reasons for any modification
made under this paragraph consistent with laws and
regulations governing the disclosure of classified
information or material.
(c) Mandatory Compliance.--Each developer shall comply with each
standard adopted under subsection (b)(2) that is applicable to the
developer.
(d) Enforcement.--
(1) In general.--The Secretary shall enforce compliance
with this section.
(2) Civil penalty.--A developer that violates subsection
(c) shall be liable to the United States for a civil penalty of
not more than $250,000 for each violation.
(3) Continuing violations.--Each day during which a
violation under subsection (c) continues shall constitute a
separate violation.
(4) Civil action.--The Attorney General may, at the request
of the Secretary, bring a civil action in an appropriate
district court of the United States--
(A) to enjoin a violation of subsection (c); or
(B) to recover a civil penalty imposed under
paragraph (2).
(e) Secure Research-Test-Beds.--In developing a process to perform
technical evaluations pursuant to section 6(A)(i), the Secretary may--
(1) seek to utilize secure computing environments, on a
reimbursable basis, provided by Federal partners, including--
(A) the National Security Agency; and
(B) the National Laboratories of the Department of
Energy; and
(2) make such secure computing environments available to
private sector, Federal agencies, and qualified independent
expert participants, on a cost-recovery basis, to engage in
artificial intelligence security research, including through
the secure provision of access in a secure environment for pre-
deployment testing of any frontier artificial intelligence
model prior to public release if security requirements
necessitate hosting outside a commercial computing environment.
(f) Requirement That Developers of Frontier Artificial Intelligence
Models Give Access to Board Before Public Release.--Not later than 45
calendar days before a developer introduces into interstate or foreign
commerce a frontier artificial intelligence model, the developer shall
make available to the Board access to the frontier artificial
intelligence model, including model's weights, configuration files,
runtimes, or software libraries necessary to operate the frontier
artificial intelligence model.
SEC. 4. SAFETY PLAN REQUIREMENT.
(a) In General.--Each developer shall develop, publish, and follow
a safety plan (referred to in this section as the ``Model Safety
Plan'') for each artificial intelligence system or model that the
developer--
(1) creates;
(2) substantially modifies; or
(3) uses in the training or evaluation of other artificial
intelligence models.
(b) Required Criteria.--Each Model Safety Plan shall include--
(1) the artificial intelligence model or system to which it
applies;
(2) an artificial intelligence capabilities or risk
assessment prepared by the developer specifically for the
artificial intelligence model or system associated with the
Model Safety Plan;
(3) a list of the specific mitigation measures that the
developer will undertake for each item described in the
artificial intelligence capabilities or risk assessment
prepared pursuant to paragraph (2), across product lifecycle;
and
(4) the identity of the corporate officer responsible for
the implementation of the Model Safety Plan.
(c) Requirement To File.--Each Model Safety Plan shall be submitted
to the Secretary in the form and manner determined by the Secretary.
SEC. 5. DATABASE FOR ARTIFICIAL INTELLIGENCE SECURITY AND SAFETY
INCIDENTS, FLAWS, AND RISKS.
(a) Tracking of Artificial Intelligence Security and Artificial
Intelligence Safety Incidents and Artificial Intelligence Flaws.--
(1) Voluntary submissions.--Not later than 180 days after
the date of the enactment of this Act, the Director of the
Institute shall, in coordination with the Director of the
Cybersecurity and Infrastructure Security Agency, establish
mechanisms by which private sector entities, public sector
organizations, civil society groups, and academic researchers
may voluntarily share information with the Institute on
confirmed or suspected artificial intelligence security or
artificial intelligence safety incidents, or on confirmed or
suspected artificial intelligence flaws, including flaws
identified through testing, evaluation, red-teaming, or post-
incident analysis in a manner that preserves confidentiality of
any affected party. Such mechanisms shall--
(A) leverage, to the greatest extent possible,
standardized disclosure and incident description
formats;
(B) develop processes to associate reports
pertaining to the same incident with a single incident
identifier, and to associate incidents or near misses
that appear to arise from the same artificial
intelligence flaw with a common flaw identifier;
(C) establish classification, information
retrieval, and reporting mechanisms that sufficiently
differentiate between artificial intelligence security
incidents and artificial intelligence safety incidents,
and between such incidents and artificial intelligence
flaws; and
(D) create appropriate taxonomies to classify
incidents based on relevant characteristics, impact, or
other relevant criteria, and to classify artificial
intelligence flaws based on their characteristics,
affected capabilities, likely consequences, and
recurrence across models or systems.
(2) Publicly accessible database.--
(A) Establishment of database required.--Not later
than 1 year after the date of the enactment of this
Act, the Director of the Institute shall, in
coordination with the Director of the Cybersecurity and
Infrastructure Security Agency, establish a publicly
accessible database of artificial intelligence security
incidents and artificial intelligence safety incidents,
together with a catalog of artificial intelligence
flaws identified through reports, testing, evaluations,
or investigations under this section.
(B) Review and population of database.--Upon
receipt of relevant information on an artificial
intelligence security incident or artificial
intelligence safety incident under paragraph (1), or on
an artificial intelligence flaw under paragraph (1),
the Director of the Institute shall review the
information and determine whether the described
incident or flaw constitutes an artificial intelligence
security or artificial intelligence safety risk
appropriate for inclusion in the database developed and
established under subparagraph (A).
(C) Identification of causal factors and artificial
intelligence flaws.--When making a determination under
subparagraph (B), the Director of the Institute shall
identify causal factors for the artificial intelligence
security incident or the artificial intelligence safety
incident and determine whether the incident reveals, is
associated with, or provides evidence of an artificial
intelligence flaw. If the Director of the National
Institute of Standards and Technology identifies such a
flaw, the Director shall assign or associate the
incident with a common flaw identifier and, to the
extent practicable, identify other known incidents,
near misses, models, or systems associated with the
same flaw, including--
(i) the artificial intelligence system;
(ii) the deployment of the artificial
intelligence systems; and
(iii) practices related to the operation of
the artificial intelligence system, including
misuse of the artificial intelligence system.
(3) Mandatory submissions.--
(A) In general.--The following entities shall
report any confirmed artificial intelligence safety
incident or artificial intelligence security incident
within 30 days of confirmation of such incident and
within 72 hours if such incident poses an imminent
threat to national security, critical infrastructure,
or public safety:
(i) Any developer or provider of a frontier
artificial intelligence model.
(ii) Any operator of critical
infrastructure that utilizes an artificial
intelligence model in the context of managing
industrial control systems or other operational
technologies.
(B) Applicability.--For the purposes of
subparagraph (A), the reporting requirement under this
paragraph shall apply regardless of whether the
frontier artificial intelligence model, or any model
variant, checkpoint, or other version of such model
involved in the incident, is or is intended to be made
publicly available, and regardless of whether the
incident occurs during development, training, testing,
evaluation, red-teaming, deployment, or operation.
(4) Priorities.--In evaluating information under paragraph
(2) and determining under such subparagraph whether to include
a report of an incident in the database required by paragraph
(2)(A), the Director of the Institute shall prioritize
inclusion in the database of cases in which a described
incident--
(A) describes an artificial intelligence system
used in critical infrastructure or safety-critical
systems;
(B) would result in a high-severity or catastrophic
impact to the people or economy of the United States;
(C) includes an artificial intelligence system
widely used in commercial or public sector contexts in
the United States; or
(D) constitutes a mandatory submission pursuant to
subsection (a)(3).
(5) Exemption from disclosure; reports and anonymity.--
(A) Anonymity.--The Director of the Institute shall
populate the database developed and established under
paragraph (2)(A) with incidents and artificial
intelligence flaws based on public reports and
information shared using the mechanism established
pursuant to paragraphs (1) and (3), ensuring that any
incident description sufficiently anonymizes those
affected, unless those who are affected have consented
to their names being included in the database.
(B) Exemption from disclosure.--Any information
shared using the mechanism established pursuant to
paragraphs (1) and (3)--
(i) shall be exempt from disclosure and
withheld, unless an affected party consents to
the inclusion of their names in the database as
provided for under subparagraph (A), from the
public, pursuant to section 552(b)(3)(B) of
title 5, United States Code, and any other
provision of United States law or law of any
State, political subdivision or agency thereof,
or Tribe requiring disclosure of information or
records; and
(ii) shall not be deemed a waiver of any
applicable privilege or protection, including
trade secret protection.
(C) Consultation required.--Before publishing
information regarding an artificial intelligence safety
incident or an artificial intelligence security
incident, the Director of the Institute shall consult
with the developer or provider of the artificial
intelligence system involved in an incident.
(b) Material Risk Guidance.--Not later than 180 days after the date
of the enactment of this Act, the Director of the Institute shall, in
coordination with the Director of the Cybersecurity and Infrastructure
Security Agency, publish nonbinding guidance that provides illustrative
criteria and examples for determining when an event ``materially
increases'' a risk for purposes of an artificial intelligence safety
incident or an artificial intelligence security incident.
SEC. 6. AGENTIC ARTIFICIAL INTELLIGENCE TRUST AND VERIFICATION.
(a) Agentic Artificial Intelligence Profile.--
(1) In general.--Not later than 18 months after the date of
the enactment of this Act, the Director of the Institute shall
develop, in collaboration with other public and private sector
organizations as appropriate, a cross-sectoral profile
(referred to in this section as the ``Agentic AI Profile'') of
the Artificial Intelligence Risk Management Framework (NIST AI
100-1) or any successor framework (referred to in this section
as the ``Framework'') for artificial intelligence agents.
(2) Purpose and contents.--The Agentic AI Profile shall
assist organizations in using the Framework to map, measure,
manage, and govern risks associated with artificial
intelligence agents. The Agentic AI Profile shall, at a
minimum--
(A) define risks that are novel to or exacerbated
by artificial intelligence agents;
(B) include a framework for classification of agent
autonomy levels; and
(C) address cybersecurity risks specific to
artificial intelligence agents, including risks related
to agent identity, authentication, and authorization,
and the relationship of such risks to the Cybersecurity
Framework (NIST CSWP-29) or any successor framework.
(3) Relationship to the framework.--The Agentic AI Profile
shall be a companion resource to the Framework and shall not
modify or supersede the Framework.
(b) Common Template for Artificial Intelligence Agent Assurance.--
(1) In general.--Not later than 18 months after the date of
the enactment of this Act, the Director of the Institute shall
initiate, in collaboration with other public and private sector
organizations and Federal agencies as appropriate, the
development of a common template to document artificial
intelligence agents and their evaluation against widely
recognized standards and frameworks.
(2) Elements.--The template shall enable the consistent
documentation of artificial intelligence agents by providing
standardized terminology and fields that relate to, at a
minimum, the following elements:
(A) Identity and version.
(B) Intended use and evaluated scope.
(C) Ownership and authority boundaries.
(D) Access to data, systems, and tools.
(E) Evaluations against widely recognized standards
and frameworks.
(F) The identity of any independent evaluator,
where applicable.
(G) Known limitations and conditions of use.
(3) Applicability.--The Director shall design the template
to be used across sectors, industries, and organizational
contexts by entities of differing sizes and resources.
(c) Coordination.--The Director shall ensure that the template
developed under this subsection is consistent with and not duplicative
of other efforts by the Institute related to artificial intelligence
agents.
<all>