PolicyBrief
H.R. 9333
119th CongressJun 25th 2026
AI Flaw Reporting and Security Enhancement Act
AWAITING HOUSE

This bill establishes a NIST-led program to support the voluntary reporting, collection, and tracking of artificial intelligence flaws through multi-stakeholder collaboration and the development of national infrastructure.

Deborah Ross
D

Deborah Ross

Representative

NC-2

LEGISLATION

AI Security Upgrade: National Database to Track Tech Glitches and Safety Hazards Starting Soon

Think of the AI Flaw Reporting and Security Enhancement Act as a 'check engine light' for the algorithms that are increasingly running our world. Right now, when an AI system makes a weird mistake or creates a security hole, there isn't a central place to report it. This bill changes that by tasking the National Institute of Standards and Technology (NIST) with building a voluntary reporting system and a national database to track AI 'flaws.' Whether it’s a chatbot giving out dangerous medical advice or a security system with a backdoor, this bill aims to get those issues documented in one place so they can be fixed before they cause real-world trouble.

Speaking the Same Language

One of the biggest hurdles in tech is that everyone uses different words for the same problem. Under Section 2, the government will bring together tech giants, college professors, and civil society groups to agree on what actually counts as an AI 'accident,' 'hazard,' or 'catastrophe.' For a software developer or a small business owner using AI tools, this is a big deal because it creates a standard playbook. Instead of guessing if a glitch is a minor bug or a major safety risk, there will be clear taxonomies to help prioritize what needs fixing first. It’s about moving away from the 'Wild West' of AI development and toward a more predictable, professional standard.

A Digital Safety Net

The bill doesn’t just define problems; it builds the plumbing to track them. NIST is required to create a national database—or upgrade an existing one—to store these reports in a way that machines can easily read and analyze. Imagine you’re a IT manager at a local hospital; having access to a centralized, machine-readable database of known AI vulnerabilities means you can protect your systems more effectively. The bill also pushes for 'automated reporting,' which could eventually mean that software might be able to flag its own flaws to this national system, speeding up the time it takes to warn the public about a potential risk.

The Three-Year Check-In

Because AI moves faster than a caffeinated intern, the bill includes a built-in deadline. Within three years, NIST has to hand over a full report to Congress detailing how the database is working and offering recommendations for better data sharing. While the reporting is voluntary—meaning companies aren't legally forced to air their dirty laundry yet—the goal is to establish 'norms' for disclosure. For the rest of us, this means more transparency. It’s a step toward ensuring that the AI tools we use for work, banking, and healthcare are being watched by more than just the companies selling them.