This bill establishes the Center for AI Security and Innovation within NIST to measure AI risks, support information sharing, and ensure U.S. leadership in artificial intelligence research and evaluation.
Jay Obernolte
Representative
CA-23
This bill, the "AI Security and Innovation Act," establishes a new Center for AI Security and Innovation within the National Institute of Standards and Technology (NIST). The Center will focus on measuring AI risks, supporting information sharing, and ensuring U.S. leadership in AI research and evaluation. It will specifically evaluate the security of advanced AI systems against threats from foreign adversaries. The legislation authorizes funding through fiscal year 2032 and explicitly prohibits the Center from having any regulatory or enforcement authority.
The AI Security and Innovation Act is a direct move to keep the U.S. at the front of the pack in the global tech race. By updating the National Artificial Intelligence Initiative Act of 2020, this bill sets up a dedicated Center for AI Security and Innovation within the National Institute of Standards and Technology (NIST). Its job is clear: measure the risks that advanced AI poses to our national and economic security, help private companies and the government share intel on threats, and ensure the U.S. doesn't fall behind foreign adversaries. Think of it as a high-tech watchdog and research hub rolled into one, designed to make sure the software running everything from your bank to your power grid is actually reliable.
The bill gives the new Center a specific to-do list focused on the 'fine print' of software security. Under Section 2, the Director is tasked with spotting and stopping sophisticated attacks you might not hear about at the dinner table—like 'model tampering' or 'data leakage'—where hackers try to trick or steal the logic behind an AI. For a software developer at a startup or a technician at a manufacturing plant, this means the government is finally putting resources into creating a voluntary 'playbook' for security. By establishing standards for 'covered frontier systems'—the most powerful AI models out there—the Center aims to catch vulnerabilities before they become headline-news data breaches.
One of the most interesting parts of this bill is what it doesn't do: it doesn't create a new set of heavy-handed regulations. The bill explicitly states that the Center has no rulemaking or enforcement authority. Instead, it focuses on a 'voluntary process' where tech companies can work with the Director on classified risk evaluations (Section 2). For a business owner, this is a 'carrot' rather than a 'stick' approach, offering a way to vet their tech against national security standards without the fear of immediate fines. Plus, the bill includes a FOIA exemption for information shared with the Center, meaning companies can be honest about their security flaws without worrying that their trade secrets will end up in a public records request.
Keeping an eye on the competition is a major theme here. The bill requires an annual report to Congress comparing U.S. AI milestones against those of 'foreign adversaries'—specifically nations like China, North Korea, Russia, and Iran. It also allows our experts to swap talent and info with friendly allies, while strictly banning any collaboration with those adversary nations. To get the best minds on the job, the Secretary of Commerce can skip some of the usual slow-moving civil service hiring rules to bring on 15 specialized experts at top-tier pay. While the $20 million annual budget (starting in 2027) is a relatively small slice of the federal pie, the goal is to ensure that the U.S. remains the place where the safest and most advanced tech is built.