This legislation, titled the Secure Artificial Intelligence Development Act of 2026, aims to enhance the tracking and processing of security and safety incidents and risks associated with artificial intelligence. It defines key terms such as artificial intelligence safety incident and artificial intelligence security vulnerability , setting the scope for its provisions. A central component is the establishment of an Artificial Intelligence Risk Board within the National Institute of Standards and Technology (NIST). This board, comprising government and non-government experts, is tasked with developing processes to evaluate high-risk AI capabilities and creating best practices for AI system developers, including standardized model cards, cybersecurity recommendations, and insider risk management. The bill mandates that providers of frontier artificial intelligence models — those posing serious risks to national security, economic security, or public health — must grant the National Security Agency (NSA) access to their models for testing 21 days prior to public release. This access includes critical components like model weights and configuration files. Non-compliance with this requirement can result in significant daily penalties, though a right to cure is provided. To support this, NIST is directed to establish a public registry for frontier artificial intelligence models , requiring providers to register their models before commercial introduction. The NSA's Artificial Intelligence Security Center will also expand its research test-bed to facilitate pre-deployment testing of these models, informing voluntary security guidance for vendors. Furthermore, the legislation requires NIST, in coordination with the Cybersecurity and Infrastructure Security Agency (CISA), to create mechanisms for voluntary sharing of AI security and safety incident information. This data will populate a publicly accessible database, prioritizing incidents involving critical infrastructure or those with high-severity impacts, while ensuring the anonymity of affected parties. The bill also addresses the integration of AI-specific vulnerabilities into existing cybersecurity frameworks. NIST is directed to evaluate and reform the National Vulnerability Database and update the Secure Software Development Framework to account for AI-identified and AI-specific vulnerabilities. Similarly, CISA must update the Common Vulnerabilities and Exposures Program to include AI security vulnerabilities. Federal agencies participating in the Vulnerabilities Equities Process (VEP) are required to assess whether the current VEP can adequately handle AI security vulnerabilities and, if not, establish new processes. Finally, the bill mandates the NSA to establish a three-year pilot program to securely share intelligence and threat information with "covered persons" – non-federal entities developing AI for the federal government – to mitigate supply chain risks from foreign adversaries, ensuring privacy and civil liberties protections.
Get AI-generated questions to help you understand this bill better
Timeline
Introduced in Senate
Read twice and referred to the Committee on Commerce, Science, and Transportation.
Introduced in Senate
Read twice and referred to the Committee on Commerce, Science, and Transportation.
Secure A.I. Development Act of 2026
USA119th CongressS-5061| Senate
| Updated: 7/21/2026
This legislation, titled the Secure Artificial Intelligence Development Act of 2026, aims to enhance the tracking and processing of security and safety incidents and risks associated with artificial intelligence. It defines key terms such as artificial intelligence safety incident and artificial intelligence security vulnerability , setting the scope for its provisions. A central component is the establishment of an Artificial Intelligence Risk Board within the National Institute of Standards and Technology (NIST). This board, comprising government and non-government experts, is tasked with developing processes to evaluate high-risk AI capabilities and creating best practices for AI system developers, including standardized model cards, cybersecurity recommendations, and insider risk management. The bill mandates that providers of frontier artificial intelligence models — those posing serious risks to national security, economic security, or public health — must grant the National Security Agency (NSA) access to their models for testing 21 days prior to public release. This access includes critical components like model weights and configuration files. Non-compliance with this requirement can result in significant daily penalties, though a right to cure is provided. To support this, NIST is directed to establish a public registry for frontier artificial intelligence models , requiring providers to register their models before commercial introduction. The NSA's Artificial Intelligence Security Center will also expand its research test-bed to facilitate pre-deployment testing of these models, informing voluntary security guidance for vendors. Furthermore, the legislation requires NIST, in coordination with the Cybersecurity and Infrastructure Security Agency (CISA), to create mechanisms for voluntary sharing of AI security and safety incident information. This data will populate a publicly accessible database, prioritizing incidents involving critical infrastructure or those with high-severity impacts, while ensuring the anonymity of affected parties. The bill also addresses the integration of AI-specific vulnerabilities into existing cybersecurity frameworks. NIST is directed to evaluate and reform the National Vulnerability Database and update the Secure Software Development Framework to account for AI-identified and AI-specific vulnerabilities. Similarly, CISA must update the Common Vulnerabilities and Exposures Program to include AI security vulnerabilities. Federal agencies participating in the Vulnerabilities Equities Process (VEP) are required to assess whether the current VEP can adequately handle AI security vulnerabilities and, if not, establish new processes. Finally, the bill mandates the NSA to establish a three-year pilot program to securely share intelligence and threat information with "covered persons" – non-federal entities developing AI for the federal government – to mitigate supply chain risks from foreign adversaries, ensuring privacy and civil liberties protections.