S5061119th CongressWALLET

Secure A.I. Development Act of 2026

Sponsored By: Senator Warner, Mark R. [D-VA]

Introduced

Summary

Frontier AI safety and security. This bill would create a NIST-based Artificial Intelligence Risk Board, require frontier AI providers to give the NSA pre-release access to models, and build a public registry, NSA test-bed, incident databases, and updated vulnerability processes to manage high-risk AI systems.

Show full summary
  • AI developers and providers: Must register frontier models and provide the NSA with model weights and runtime details at least 21 days before introducing a model into interstate or foreign commerce. Companies that fail to comply face fines of not less than $100,000 per day while the model remains available.
  • Researchers and independent experts: Gain subsidized access to an NSA research test-bed for secure pre-deployment testing and security research. Access comes with researcher participation rules and limits on publication to protect sensitive findings.
  • National security, infrastructure operators, and federal users: A NIST-led Board would set technical evaluation methods, model-card best practices, and cybersecurity guidance. The bill also creates a multi-year pilot to share tailored intelligence and threat information with covered persons to protect AI supply chains and critical systems.

Personalized for You

How does this bill affect your finances?

Personalize government policy and PRIA will tell you what this bill means for your household, plus every other piece of legislation we track. PRIA reads each provision against your financial profile to show you exactly what matters to your wallet.

Bill Overview

Analyzed Economic Effects

4 provisions identified: 3 benefits, 0 costs, 1 mixed.

New rules for frontier AI providers

If enacted, providers of "frontier" AI models would have to register each model in a public NIST registry within 90 days of enactment and before offering it across state lines or abroad. Providers must give the NSA’s AI Security Center access to model weights, runtimes, configs, and libraries at least 21 calendar days before introduction and must attest they submitted the model to the NSA test-bed. The NSA test-bed would be available at subsidized rates for private-sector and independent researchers to run secure pre-release tests. If a provider breaks the pre-release access or registration rules, the Attorney General could fine them at least $100,000 per day, but the provider gets a 7-calendar-day notice period to withdraw the model and cure the violation before fines start.

New AI incident and vulnerability programs

If enacted, NIST and CISA would set up voluntary, confidential reporting and a public, anonymized database of AI safety and security incidents within one year. CISA would update the CVE program within 180 days to better handle AI vulnerabilities, and NIST would review and plan reforms to the National Vulnerability Database and update secure software guidance within 180 days. Agencies in the Vulnerabilities Equities Process would evaluate within 90 days whether VEP can handle AI vulnerabilities and report to Congress; the DNI must also report to intelligence committees within 90 days on AI vulnerability volume and impacts.

New intelligence sharing for AI supply chains

If enacted, the NSA would start a pilot within 180 days that runs at least three years to securely share classified threat intelligence with covered industry participants about AI supply-chain risks tied to federal procurement. The pilot must protect classified and trade-secret information, not give competitive advantage to participants, and limit use of shared intelligence to detecting or mitigating malicious foreign activity. Separately, CISA would convene stakeholders within 90 days to develop supply-chain best practices for training and maintaining AI models.

NIST AI risk board and guidance

If enacted, NIST would create an Artificial Intelligence Risk Board within 90 days to set technical thresholds, best practices, and model documentation standards. The board must adopt bylaws within 120 days and include federal officials and outside technical experts; some members may need security clearances. NIST, working with CISA, would also publish nonbinding guidance within 180 days showing examples of when an event "materially increases" risk for reporting and incident definitions.

Sponsors & CoSponsors

Sponsor

Warner, Mark R. [D-VA]

VA • D

Cosponsors

There are no cosponsors for this bill.

Roll Call Votes

No roll call votes available for this bill.

View on Congress.gov
Back to Legislation