Bipartisan US Bill Mandates AI Developers Report Model Evasion and Security Incidents
A newly introduced bipartisan bill requires frontier AI developers to report security breaches and model evasion tactics to the Commerce Department within 72 hours. The legislation aims to create a centralized federal clearinghouse for AI threat intelligence while exempting smaller open-source projects.
By Factlen Editorial Team
- National Security Advocates
- Argue that mandatory reporting is essential to prevent foreign adversaries from exploiting vulnerabilities in foundational AI systems.
- Commercial AI Developers
- Support a unified federal standard to avoid a patchwork of state laws, but remain highly concerned about the confidentiality of their vulnerability data.
- Open-Source Defenders
- Relieved by the high compute thresholds that exempt smaller researchers, ensuring the mandate does not crush independent innovation.
What's not represented
- · Independent AI auditors who may be sidelined by direct government reporting
- · International regulators coordinating with the EU AI Act
Why this matters
As AI systems become deeply integrated into critical infrastructure, a hidden vulnerability in a major model could trigger cascading failures across multiple industries. This bill ensures that when one company discovers a critical flaw or is targeted by a novel attack, the entire industry and federal defenders are immediately alerted, preventing widespread exploitation.
Key points
- A new bipartisan bill requires frontier AI developers to report severe security incidents to the Commerce Department within 72 hours.
- The legislation targets concrete cybersecurity threats like model evasion and data poisoning rather than theoretical AI risks.
- A federal clearinghouse will anonymize and share threat intelligence to protect the broader AI ecosystem from zero-day exploits.
- Open-source projects and smaller models are exempt, as the mandate only applies to systems trained with massive compute power.
- Companies failing to comply face fines up to $15 million or a percentage of their global revenue.
- The bill explicitly protects submitted vulnerability data from public disclosure laws to ease corporate confidentiality concerns.
A bipartisan coalition in the US Congress has introduced landmark legislation requiring developers of advanced artificial intelligence to report severe security incidents and model evasion tactics to the federal government. The proposed framework represents a significant shift in how the United States approaches artificial intelligence regulation, moving away from broad, theoretical safety guidelines toward concrete, incident-based cybersecurity mandates. By treating frontier AI systems as critical national infrastructure, lawmakers are signaling that the era of voluntary self-regulation and opaque vulnerability patching is coming to an end. The bill aims to establish a unified federal standard that compels transparency without stifling the rapid pace of technological innovation.[1][4]
The proposed legislation, formally titled the "AI Threat Intelligence and Defense Act of 2026," mandates that creators of frontier models notify the Department of Commerce within 72 hours of discovering a critical vulnerability or suffering a breach. This tight reporting window mirrors the stringent requirements recently imposed on the banking, energy, and healthcare sectors for traditional cyberattacks. The goal is to ensure that federal agencies are not left in the dark when a foundational technology underpinning modern enterprise software is compromised by malicious actors.[2][6]
Unlike previous regulatory attempts that focused heavily on hypothetical existential risks or long-term alignment problems, this legislation targets immediate, concrete cybersecurity threats. It acknowledges that AI models are complex software systems susceptible to unique attack vectors that traditional firewalls cannot block. By focusing on measurable security incidents rather than abstract safety evaluations, the bill has garnered unusual bipartisan support, bridging the gap between lawmakers focused on national security and those prioritizing consumer protection.[4]
The core mechanism of the bill establishes a secure threat intelligence clearinghouse within the US AI Safety Institute, a division of the Commerce Department. When a company detects a novel "jailbreak," a data poisoning attempt, or an unauthorized exfiltration of model weights, they must submit technical details to this federal repository. The clearinghouse is designed to act as a central nervous system for the domestic AI industry, processing raw vulnerability data into actionable defensive intelligence.[1][5]

Model evasion—a technique where attackers use carefully crafted inputs to bypass an AI's safety guardrails and force it to generate restricted code, sensitive data, or harmful outputs—is explicitly categorized as a reportable incident. As AI agents gain the ability to execute code and interact with external APIs, evasion tactics have evolved from academic curiosities into severe security liabilities. The bill recognizes that a successful evasion attack against an enterprise AI assistant could lead to unauthorized network access or massive data leaks.
By centralizing these threat reports, the Commerce Department aims to rapidly disseminate anonymized warnings to other AI developers, effectively immunizing the broader ecosystem against zero-day exploits before they can be widely weaponized. If a state-sponsored hacking group develops a novel method to manipulate a specific language model architecture, the clearinghouse can alert all developers utilizing similar architectures to patch the vulnerability immediately. This collaborative defense model is heavily inspired by the Cybersecurity and Infrastructure Security Agency's (CISA) approach to traditional software vulnerabilities.[2][3]
The legislation arrives after a turbulent year of high-profile AI security incidents that highlighted the fragility of the current ecosystem. Recent months have seen sophisticated threat actors successfully exfiltrate proprietary model weights from cloud environments and manipulate enterprise AI agents into executing unauthorized financial transactions. These incidents demonstrated that the rapid deployment of AI capabilities has vastly outpaced the development of robust security protocols, creating a lucrative new attack surface for cybercriminals.[5]
Historically, AI companies have treated these vulnerabilities as closely guarded trade secrets, patching them silently to avoid public relations fallout and maintain a competitive edge. This siloed approach meant that an attack vector discovered and mitigated in one model could often be reused against a competitor's system weeks later with devastating effect. The lack of a shared threat intelligence framework left the entire industry vulnerable to repeated exploitation by the same adversaries using identical tactics.[3]

The lack of a shared threat intelligence framework left the entire industry vulnerable to repeated exploitation by the same adversaries using identical tactics.
"We can no longer afford a fragmented defense where every AI lab is fighting the same adversaries in the dark," the bill's co-sponsors noted in a joint memorandum accompanying the draft legislation. "Shared infrastructure requires shared threat intelligence. When a frontier model is compromised, it is not just a corporate public relations problem; it is a national security incident that requires a coordinated federal response." The memorandum emphasizes that proactive intelligence sharing is the only viable defense against rapidly evolving AI threats.[4][6]
A critical component of the new framework is its precise scoping, designed to avoid collateral damage to the broader tech ecosystem. The reporting mandate applies exclusively to "frontier models"—defined mathematically as systems trained using more than 10^26 floating-point operations (FLOPs), or those deeply integrated into federal networks. This specific threshold ensures that the regulatory burden falls squarely on the multi-billion-dollar tech giants developing the most capable and potentially dangerous systems, rather than small startups.[1]
This compute threshold represents a significant victory for open-source advocates and academic researchers, who have fiercely lobbied against blanket AI regulations. By exempting smaller, experimental models and open-weight projects that fall below the FLOP limit, the bill avoids placing crushing compliance burdens on the open-source community. Advocates argue this exemption is vital for maintaining American competitiveness and ensuring that AI safety research remains accessible to independent scientists rather than being monopolized by a few massive corporations.[5]

Industry giants have signaled cautious support for the federal framework, driven largely by a desire for regulatory certainty. Facing a looming patchwork of state-level AI regulations—most notably stringent proposals in California and New York—major developers view a unified national standard as a necessary compromise. Navigating a single set of federal reporting requirements is vastly preferable to complying with fifty different state laws, each with its own definitions of what constitutes a security incident.[2][3]
However, the mechanics of the reporting process remain a point of intense contention among commercial labs. Developers have expressed deep concern regarding the confidentiality of the submitted data, fearing that highly sensitive vulnerability reports could leak to competitors or be subject to Freedom of Information Act (FOIA) requests. Disclosing the exact mechanics of a model evasion tactic could inadvertently provide a roadmap for malicious actors if the clearinghouse's own security is ever compromised.[3][4]
To address these fears, the legislation explicitly exempts the threat intelligence clearinghouse from standard public disclosure laws, classifying the submissions under a new tier of protected critical infrastructure information. The Commerce Department is legally barred from sharing the raw, unanonymized vulnerability reports with other federal agencies for regulatory enforcement purposes, ensuring the clearinghouse functions strictly as a defensive mechanism rather than a punitive oversight body.[6]
Enforcement mechanisms outlined in the draft include substantial financial penalties to ensure strict compliance. Companies that fail to report a qualifying incident within the 72-hour window could face fines of up to $15 million per violation, or a percentage of their global revenue, whichever is higher. These steep penalties are designed to fundamentally alter the risk calculus for corporate executives, making the cost of covering up a breach far higher than the reputational damage of reporting it.[1][2]

The bill also allocates $150 million in new funding to the Commerce Department to hire specialized machine learning auditors and cybersecurity experts. This funding is critical, as analyzing the influx of highly technical telemetry requires a specialized workforce that the federal government currently lacks. The new division within the AI Safety Institute will be tasked with reverse-engineering reported evasion tactics and developing generalized defensive countermeasures that can be shared with the public.[4]
Uncertainty remains around how the Commerce Department will define the threshold for a "critical" evasion tactic in practice. Because AI models are probabilistic by nature, users discover minor bypasses and quirky jailbreaks daily; regulators will need to establish clear, technical guidelines to prevent the clearinghouse from being overwhelmed by trivial reports. The rulemaking process over the next year will be crucial in determining whether the system functions as an agile threat-hunting tool or a bureaucratic bottleneck.[5]
If passed, the legislation will position the United States alongside the European Union in establishing hard regulatory baselines for AI security, shifting the industry from an era of voluntary commitments to one of mandatory federal oversight. By forcing the industry to share its failures, the bill aims to accelerate the development of robust, secure AI systems capable of withstanding the sophisticated cyber threats of the next decade.[2][6]
How we got here
Late 2024
White House issues executive orders establishing voluntary AI safety commitments from major tech companies.
Mid 2025
A surge in sophisticated AI model evasion and data poisoning attacks highlights the inadequacy of siloed corporate defenses.
Early 2026
Several US states introduce fragmented, conflicting AI security regulations, prompting industry calls for a unified federal standard.
July 2026
Bipartisan lawmakers introduce the AI Threat Intelligence and Defense Act to mandate federal reporting.
Viewpoints in depth
National Security Advocates
Argue that mandatory reporting is essential to prevent foreign adversaries from exploiting vulnerabilities in foundational AI systems.
National security experts and defense-oriented lawmakers view frontier AI models as critical infrastructure, akin to the power grid or financial networks. They argue that allowing private companies to silently patch vulnerabilities creates a dangerous blind spot for federal cyber defenders. By mandating a 72-hour reporting window, this camp believes the US government can rapidly identify coordinated attacks by state-sponsored actors and deploy countermeasures across the entire domestic tech sector before adversaries can weaponize a single exploit against multiple targets.
Commercial AI Developers
Support a unified federal standard to avoid a patchwork of state laws, but remain highly concerned about the confidentiality of their vulnerability data.
Major technology companies are cautiously backing the legislation primarily as a defensive maneuver against a looming chaotic landscape of state-level regulations. Complying with one federal standard is vastly cheaper and less legally perilous than navigating fifty different state mandates. However, corporate executives remain deeply anxious about the mechanics of the Commerce Department's clearinghouse. They fear that submitting detailed technical breakdowns of their models' flaws could lead to catastrophic leaks, either through cyberattacks on the federal repository itself or through overly broad interpretations of public disclosure laws.
Open-Source Defenders
Relieved by the high compute thresholds that exempt smaller researchers, ensuring the mandate does not crush independent innovation.
Academic researchers and open-source advocates have historically viewed federal AI regulation with intense suspicion, fearing that compliance costs would entrench a monopoly of massive tech giants. This camp considers the bill's strict 10^26 FLOPs threshold a major legislative victory. By explicitly exempting smaller, experimental models, the legislation allows the open-source community to continue iterating rapidly without the burden of maintaining enterprise-grade incident reporting pipelines. Nevertheless, they remain vigilant against future amendments that might lower the compute threshold and capture independent developers in the regulatory net.
What we don't know
- How the Commerce Department will precisely define the threshold between a trivial 'jailbreak' and a critical model evasion incident.
- Whether the $150 million budget allocation will be sufficient to hire the highly specialized machine learning experts needed to analyze the threat data.
- How this US reporting framework will interoperate with the incident reporting requirements of the European Union's AI Act.
Key terms
- Model Evasion
- A technique where attackers use carefully crafted inputs to bypass an AI system's safety guardrails, forcing it to generate restricted or harmful outputs.
- Frontier Model
- A highly capable, large-scale artificial intelligence system that pushes the boundaries of current technology, defined in this bill by a specific computational training threshold.
- Data Poisoning
- A cyberattack where malicious actors intentionally introduce corrupted or misleading data into an AI model's training set to compromise its future behavior.
- FLOPs
- Floating-point operations; a measure of computational power used to quantify the massive scale of resources required to train advanced AI models.
Frequently asked
Who is required to report incidents under this bill?
Only developers of 'frontier models'—defined as AI systems trained using more than 10^26 FLOPs—are subject to the mandatory reporting requirements.
What constitutes a reportable security incident?
Reportable incidents include critical vulnerabilities, data poisoning attempts, unauthorized exfiltration of model weights, and novel model evasion (jailbreak) tactics.
How quickly must companies report a breach?
Developers have a strict 72-hour window to notify the Commerce Department after discovering a qualifying security incident.
Will the reported vulnerabilities be made public?
No. The raw data is exempt from FOIA requests. The Commerce Department will only share anonymized, generalized threat intelligence with other developers to help them patch their systems.
Sources
[1]ReutersNational Security Advocates
US lawmakers propose mandatory AI security reporting to Commerce Department
Read on Reuters →[2]BloombergCommercial AI Developers
AI Giants Face $15 Million Fines in New Bipartisan Threat Intelligence Bill
Read on Bloomberg →[3]TechCrunchCommercial AI Developers
How did the government decide OpenAI’s frontier model was safe to release?
Read on TechCrunch →[4]PoliticoNational Security Advocates
Congress moves to end 'siloed' AI defenses with new Commerce clearinghouse
Read on Politico →[5]WiredOpen-Source Defenders
OpenAI Launches Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic’s Mythos
Read on Wired →[6]US Congress
H.R. 8422 - AI Threat Intelligence and Defense Act of 2026
Read on US Congress →
Every angle. Every day.
Get technology stories with full source coverage and perspective breakdowns delivered to your inbox.








