This bill requires Department of Defense contractors to provide a comprehensive, machine-readable "Artificial Intelligence Functional Bill of Materials" detailing the software, data, and hardware components of any AI systems used in defense contracts to ensure security and transparency.
Elissa Slotkin
Senator
MI
This bill requires the Department of Defense to mandate an "Artificial Intelligence Functional Bill of Materials" for all AI-related contracts. Contractors must provide detailed, machine-readable documentation covering the software, data, and hardware components of their AI systems to ensure transparency, security, and risk assessment. This measure aims to strengthen oversight by requiring contractors to maintain and update these records throughout the lifecycle of the AI technology.
The Department of Defense (DoD) is about to get a lot pickier about the artificial intelligence it buys. A new bill requires any company selling AI to the military to provide a 'functional bill of materials'—basically a detailed ingredient list of every piece of code, data, and hardware that makes the system tick. If a contractor wants to sign, renew, or extend a contract, they have to hand over this digital manifest to the Chief Digital and Artificial Intelligence Officer. Plus, they have to be ready to produce an updated version within 48 hours if the Pentagon asks. It’s a move designed to ensure that if a security flaw is discovered in a common piece of software, the military knows exactly which of its AI tools are at risk.
Think of this like the nutrition label on a box of cereal, but for complex algorithms. Under this bill, contractors can’t just hand over a black box; they have to disclose the 'Software Section' (Section 1). This includes the specific AI models used, where they came from, who licensed them, and even the 'hyperparameters'—the settings that tell the AI how to learn. For the tech workers and software engineers in the room, this means documenting every third-party package, open-source library, and machine-learning framework used during development. It even requires an audit trail showing who changed what and why, ensuring that the 'brain' of the system hasn't been tampered with before it reaches the military.
The bill doesn’t stop at code; it digs into the data and the physical machines running the show. Contractors must disclose the 'Data Section,' which lists the datasets used to train the AI, where that data originated, and how sensitive it is. For a data scientist, this is a massive documentation lift, requiring everything from cryptographic hashes to the country of origin for every dataset. On the physical side, the 'Hardware Section' requires details on the specific chips (like GPUs or TPUs) and cloud environments being used. This is about supply chain integrity—making sure the hardware isn't coming from a compromised source and that the cloud regions are secure.
While this is a win for national security, it’s a significant new hurdle for AI contractors, especially smaller startups that might not have the administrative muscle of a giant like Lockheed Martin. The bill gives the Secretary of Defense 180 days to figure out how to fold these AI requirements into existing software rules. There’s also the '48-hour rule' for updates, which could be a logistical nightmare for companies managing rapidly evolving models. However, the bill also mandates strict cybersecurity for these 'ingredient lists' themselves, ensuring that the blueprints for our military AI don't fall into the wrong hands. It’s a high-stakes balancing act between needing to know exactly how a weaponized algorithm works and the reality of how fast modern software moves.