PolicyBrief
H.R. 8819
119th CongressMay 14th 2026
Federal Artificial Intelligence Risk Management Act of 2026
IN COMMITTEE

This bill mandates that federal agencies adopt the National Institute of Standards and Technology's Artificial Intelligence Risk Management Framework for their use of artificial intelligence systems.

Ted Lieu
D

Ted Lieu

Representative

CA-36

LEGISLATION

Federal AI Risk Management Act Mandates New Safety Standards and Content Labeling by 2026

The Federal Artificial Intelligence Risk Management Act of 2026 requires every federal agency to follow strict safety and reliability rules when using AI. Under Section 5304, the National Institute of Standards and Technology (NIST) is tasked with creating a universal 'playbook' for how the government buys and uses AI, ensuring these systems are trustworthy and that any AI-generated images or text are clearly labeled. This isn't just about internal tech; it applies to any contractor working for the government, meaning the software used to process your taxes or manage federal benefits will have to meet these new benchmarks.

Labeling the Robots

One of the most immediate changes you’ll notice is how the government handles 'synthetic content'—that’s policy-speak for AI-generated photos, videos, or text. The bill requires NIST to develop standards for authenticating and labeling this material (Section 5304). Imagine you’re watching a public service announcement or reading a government report; this law aims to ensure you know exactly if a computer generated that content. For anyone worried about deepfakes or misinformation, this creates a clear paper trail for government communications, though it’s worth noting that national security systems are exempt from these specific labeling rules.

Vetting the Tech Vendors

If you’re a software developer or a small business owner contracting with the feds, the rules of the game are about to get a lot more detailed. NIST is required to perform a 'gap analysis' of current testing standards and then develop new guidelines for verifying that AI systems actually do what they claim to do before the government cuts a check. For a tech worker, this means more rigorous testing phases during procurement. For the taxpayer, it’s a safeguard intended to prevent the government from spending millions on 'black box' algorithms that might have hidden biases or security flaws.

The Risk Management Playbook

To keep things consistent, the bill forces agencies to create 'profiles'—essentially customized risk assessments—based on the NIST AI Risk Management Framework. This means an agency like the IRS and an agency like the Department of Transportation will each have to define their own 'risk tolerance' and implementation plans. While this flexibility is great for efficiency, the 'Medium' level of vagueness in how these risks are defined means we’ll have to watch closely. If one agency has a very high tolerance for risk, your data might be handled differently than it is at another, making the promised 'trustworthiness' a bit of a moving target depending on which office you're dealing with.