PolicyBrief
H.R. 2152
119th CongressMay 13th 2026
AI PLAN Act
AWAITING HOUSE

This bill directs key federal agencies to report annually on strategies to defend U.S. interests against financial crimes facilitated by adversarial actors using artificial intelligence.

Zachary (Zach) Nunn
R

Zachary (Zach) Nunn

Representative

IA-3

LEGISLATION

AI PLAN Act Mandates Federal Strategy to Combat AI-Driven Financial Crimes and Digital Fraud

The AI PLAN Act is essentially the federal government’s attempt to get its ducks in a row before AI-powered scammers do more damage. The bill acknowledges a scary reality: adversarial actors (think foreign hackers or organized crime) are using artificial intelligence to mess with our money, our markets, and our personal security. To fight back, it requires the heads of Treasury, Homeland Security, and Commerce to stop working in silos and start submitting a joint game plan to Congress every single year, starting just 180 days after the bill becomes law.

Mapping the Digital Minefield

This isn't just a vague request for a status update. The bill (Section 2) specifically orders these agencies to look at the stuff that keeps us up at night: deepfakes used to bypass security, voice cloning that can trick a family member or an employee into sending money, and "synthetic identities" where AI creates a fake person to open credit lines. For the average person, this means the government is finally looking at how to protect your bank account from a scammer who sounds exactly like your boss or your kid. For business owners, it’s about defending against "false flags" designed to tank a stock price or disrupt a supply chain overnight.

The Federal Toolbelt

One of the most practical parts of this bill is the requirement for an "itemized list" of what we actually have in the shed to fight these high-tech crimes. The agencies have to audit their current hardware, software, and personnel to see what's working and what’s lacking. They also have to estimate the budgets needed to bridge the gap. It’s a bit like a tech audit for the country—figuring out if our federal agencies are trying to fight 21st-century AI with 20th-century computers and outdated software.

Moving from Reports to Results

To make sure this doesn't just result in a dusty stack of paper, the bill mandates a 90-day follow-up after every report. The Secretaries have to hand over specific legislative recommendations and, more importantly for the rest of us, a list of "best practices." This is where the rubber meets the road for small business owners and regular citizens. If the bill works as intended, these best practices should trickle down into better security standards for your banking apps and clearer guidelines for how companies should handle an AI-driven security breach. While the bill itself doesn't create new regulations today, it builds the foundation for the laws and security habits we'll likely be living with for the next decade.