Summary#
This bill directs the National Institute of Standards and Technology (NIST) to run a voluntary program to collect, track, and speed up detection of flaws in artificial intelligence (AI) systems. It calls for multi‑stakeholder work to create shared definitions, taxonomies, standards, reporting methods, and infrastructure — including a national database or a modification of an existing one. The goal is to make it easier to find, share, and prioritize fixes for AI safety and security problems.
- Main change: NIST must create a voluntary AI flaw reporting program and develop or fund a national database to store reports.
- Work to be done: Convene industry, academia, nonprofits, standards bodies, civil society, and federal agencies to set definitions, taxonomies, severity measures, and reporting best practices.
- Technical goals: Promote machine‑readable standards, interoperability, automated reporting, and methods to accelerate detection and monitoring.
- Disclosure norms: Develop guidance on when and how to publicly disclose AI flaws.
- Reporting to Congress: NIST must report back within three years on findings, the infrastructure built, and recommendations for voluntary reporting mechanisms.
- Who may build the system: NIST can enter cooperative agreements with eligible entities (universities, research institutions, or consortia) to develop the infrastructure.
What it means for you#
- AI developers and companies: The bill would create a voluntary way to report and track AI flaws. This could make it easier to share information about vulnerabilities and to follow common standards for describing problems.
- Researchers and universities: Eligible institutions can be designated to help build or host the national database and take part in setting standards and taxonomies.
- Standards groups and civil society: The bill asks NIST to include these groups when making definitions, reporting formats, and norms for disclosure, so they can help shape how flaws are classified and shared.
- Government agencies: NIST will consult with the Cybersecurity and Infrastructure Security Agency (CISA) and other federal entities; agencies may use the database and guidance for oversight or risk assessment.
- The public and organizations that rely on AI: There may be more publicly available information over time about known AI flaws, depending on the disclosure norms NIST develops. The bill does not require public disclosure of every report.
- Small businesses and non‑profits using AI: They could benefit from shared standards and a central repository of known issues, which may help prioritize fixes and improve security practices.
Expenses#
No publicly available information.
- The bill requires NIST to develop a program and either create or modify a national database and to enter cooperative agreements with eligible entities. Those activities imply funding and staff time, but the bill does not include a fiscal estimate or identified appropriations.
- Possible cost categories (not estimated in the bill text): cooperative agreement grants, database development and maintenance, staff and contractor support, and costs for convening stakeholders and producing the required report.
- It is unclear whether existing federal budgets would cover these tasks or whether new appropriations would be requested.
Proponents' View#
The bill appears intended to address gaps in how AI flaws are found, described, and shared. Possible supporting points that follow from the bill text:
- Establish shared definitions and taxonomies to make reports consistent and easier to compare across sectors.
- Create a central or coordinated database so organizations can learn about known AI flaws and avoid repeating the same mistakes.
- Promote technical standards and machine‑readable reporting to speed automated detection and monitoring tools.
- Provide methods to rate severity or risk so organizations can prioritize fixes that reduce the most harm.
- Develop norms for when disclosure is appropriate to balance transparency with safety and confidentiality concerns.
Opponents' View#
The bill leaves several important details unspecified, which could raise concerns or limit effectiveness:
- One concern is that the program is voluntary; without mandates, some organizations may not report serious flaws, limiting the usefulness of a central database.
- The bill does not clearly explain how sensitive information (trade secrets, personally identifiable data, or national security details) will be protected when flaws are reported or shared.
- It is unclear how public disclosure decisions will be made and whether disclosure rules will protect victims or avoid enabling misuse of flaw details.
- The bill does not provide a cost estimate or specify funding, so it is unclear whether NIST will have enough resources to develop and maintain a national database and run sustained multi‑stakeholder activities.
- There could be overlap with existing vulnerability databases or industry efforts; the bill does not detail how duplication will be avoided or how the new system will interoperate with current systems beyond a general requirement to consider interoperability.