This Act mandates federal reporting for incidents involving advanced AI models that pose serious risks to national security or public safety.
Nathaniel Moran
Representative
TX-1
The AI Incident Reporting Act mandates that developers of advanced artificial intelligence models posing serious national security or public safety risks must report specific dangerous incidents to the Secretary of Commerce. This system requires reporting on issues like evasion of human control, theft of model weights, and capabilities related to cyberattacks or CBRNE weapons. The bill establishes strict confidentiality protections for submitted information while setting civil penalties for non-compliance.
The AI Incident Reporting Act creates a mandatory federal 'early warning system' for advanced artificial intelligence models that could pose serious threats to national security or public safety. Under the bill, the Secretary of Commerce is tasked with identifying which AI developers and models are powerful enough to be 'covered' by these rules. When one of these high-stakes models acts out—such as trying to evade human control, getting its core code stolen, or showing a sudden knack for creating cyberweapons or chemical agents—the developers must report it to the government within seven days. For imminent dangers, the reporting timeline gets even faster, ensuring that the feds aren't the last to know when a powerful system goes off the rails.
This bill focuses on 'reportable activities' that sound like sci-fi but have real-world stakes. It covers everything from an AI attempting to deceive its human operators (Section 2) to 'near misses,' where a disaster was only avoided by pure luck or a third party stepping in. For the average person, this is about preventing the kind of systemic failures that could crash digital infrastructure or compromise public safety. If a model starts teaching itself how to automate advanced hacking or build dangerous weapons, the developer has a legal clock ticking to notify the Commerce Department. The bill also protects this sensitive data from public Freedom of Information Act (FOIA) requests, aiming to keep trade secrets and security vulnerabilities out of the wrong hands while keeping the government in the loop.
While the goal is safety, the bill gives the Secretary of Commerce significant power to decide what counts as a 'covered model' and what qualifies as a 'serious risk.' Because the definition of AI in the bill is quite broad—covering everything from machine learning to intelligent software agents—there is a chance that tech not originally intended for this level of scrutiny could get caught in the net. For developers, the stakes are high: failing to report an incident can result in civil penalties of up to $2,000,000 per day (Section 2, Enforcement). This creates a massive incentive for companies to be transparent, but the $2 million daily fine could be a company-killer for smaller innovators who find themselves designated as 'covered developers.'
To get tech companies to actually come clean, the bill offers a 'safe harbor' of sorts. Information shared in these reports generally cannot be used as evidence against the developer in a lawsuit or criminal case (Section 2, Protection and Use of Information). However, this doesn't mean a company is totally off the hook; the government can still hold them liable if they find evidence of wrongdoing through other independent channels. For the public, this is a classic trade-off: we get more transparency into dangerous AI glitches in exchange for giving developers a degree of legal immunity for what they disclose. It’s a move designed to prioritize immediate safety and national security over long-drawn-out legal battles.