- jurisdiction
- US Federal
- level
- federal
- domain
- safety
- status
- proposed
- scope
- Federal bill establishing an Artificial Intelligence Risk Board within NIST, directing NIST/CISA to build AI-security-incident and vulnerability-management infrastructure, and requiring providers of 'frontier artificial intelligence models' to pre-share those models with the NSA's Artificial Intelligence Security Center and register them with NIST before commercial release.
- obligations
- Not later than 21 calendar days before a provider introduces a frontier artificial intelligence model into interstate or foreign commerce, the provider shall make available to the NSA's Artificial Intelligence Security Center access to the model, including its weights, configuration files, runtimes, or software libraries necessary to operate it (Sec. 3(c)). Each provider of a frontier AI model shall register that model with a NIST-established registry before introducing it into interstate or foreign commerce (Sec. 3(d)(3)). Within 90 days of enactment, the Secretary of Commerce must establish an Artificial Intelligence Risk Board within NIST to develop technical evaluations of high-risk AI capabilities and best practices (Sec. 3(b)). Within one year, NIST must establish voluntary AI-safety/security-incident information-sharing mechanisms for private-sector, public-sector, civil-society, and academic participants (Sec. 4(a)). Within 180 days, NIST and CISA must evaluate incorporating AI security vulnerabilities into the National Vulnerability Database and the CVE Program (Sec. 5).
- penalties
- Per Sec. 3(e) (Enforcement; Ability To Cure): a provider that violates the 21-day pre-release NSA Artificial Intelligence Security Center access requirement (subsection (c)) is fined not less than $100,000 per day for each day the frontier AI model remains available in interstate or foreign commerce without having obtained the voluntary security guidance issued under section 6504(e)(3) of the Intelligence Authorization Act for Fiscal Year 2025. The Director of NIST refers violations to the Attorney General, who enforces the section; before an enforcement action, the Attorney General must give the provider notice and a 7-calendar-day period to cure by withdrawing the model from commerce and giving NSA the access described in subsection (c).
- appliesTo
- providers of frontier AI models; NIST, CISA, and the National Security Agency (as directed federal implementers)
- notes
- Introduced by Sen. Mark Warner (D-VA) on July 21, 2026 as part of the same legislative package that produced the already-tracked us-safe-ai-act-s5057 and the candidate us-ai-agent-act-s5051 above; referred to the Senate Committee on Commerce, Science, and Transportation. Confirmed by downloading the introduced-bill PDF directly from GovInfo (BILLS-119s5061is) and reading its page text through Section 3(d); the pre-release-sharing and registry clauses quoted here are reproduced from that direct read, not a summarizer paraphrase. Not yet passed by either chamber; no penalty/enforcement schedule was reached in the pages reviewed (Section 3(e), titled 'Enforcement; Ability to Cure,' begins on the following page and was not independently confirmed, so penalties is left null). Distinct from all currently tracked entities, including ca-sb53 and ny-raise-act (state-level frontier-model transparency/incident-reporting laws) and il-ai-safety-measures-act (state-level recurring-audit mandate): this is a federal bill creating a pre-release model-sharing/registry requirement with a national-security agency, which none of the state frontier-safety laws impose.