AI Safety Procurement Rules

Full Title:
Safeguarding Against Fabricated Exploitation Through Artificial Intelligence Act of 2026

Summary#

This bill would ban the Federal Government from buying or using certain artificial intelligence (AI) models that can create realistic images or video if those models fail safety standards or are found by a Federal court to have produced sexual images of children or non-consensual sexual images of identifiable adults. It tasks NIST (the National Institute of Standards and Technology) with creating performance benchmarks and a voluntary testing program to prevent such harmful outputs. It also creates a private right of action (a way for people to sue) and forbids selling tools designed to defeat technical safeguards.

  • Main change: Federal agencies would not be allowed to procure or use AI models that are judged to be unsafe under new performance benchmarks or found by a Federal court to have generated child sexual abuse material or non-consensual intimate images.
  • NIST duties: NIST must set performance benchmarks within 90 days and run a voluntary vendor test program within 180 days.
  • Agency duties: Agencies must remove covered AI models from their systems within 180 days after enactment or within 180 days after a model is determined to be covered.
  • Safeguards and cure: Agencies may adopt temporary technical safeguards if vendors cannot fix a model, and vendors can be offered a chance to modify models at their own cost to avoid removal.
  • Private lawsuits and penalties: Individuals and certain developers can sue for violations. Courts can award damages (actual or statutory up to $50,000), injunctions, and other remedies. Repeat violations may allow triple damages.
  • Anti-circumvention rule: It would be illegal to make, import, or offer products mainly designed to bypass technical controls that prevent generation of prohibited content.

What it means for you#

  • Federal agencies and procurement officers

    • Agencies must remove or stop using AI models that meet the bill’s definition of a covered application. This applies to systems the agency runs and to contractor-run systems.
    • Agencies must review products and services regularly (GSA every 90 days after 1 year; agencies at least annually after 1 year) to check for covered applications.
    • If a vendor cannot or will not modify a model, the agency may implement extra safeguards and must publicly certify those safeguards within 30 days.
  • Developers and vendors of AI models

    • Vendors may be required to modify models at their own expense if the model is deemed a covered application.
    • Vendors could face civil liability if they fail to implement sufficiently robust technical controls and someone is harmed, or if their controls are subverted.
    • Vendors should expect voluntary testing by NIST and updates to performance benchmarks over time.
  • Contractors that provide IT or AI services to the government

    • Contractors must remove covered applications from systems they operate for agencies, on the same schedule as agencies.
  • Individuals whose images are used without consent

    • People whose images are used to create child sexual abuse material or non-consensual intimate images may sue the person or developer responsible.
    • Court remedies may include damages, injunctions, impounding devices, and orders to modify or destroy violating products.
  • Businesses making tools that defeat safeguards

    • Making, importing, or offering tools mainly designed to bypass technical controls could be illegal under this bill.

Expenses#

No publicly available information.

  • This bill would likely create administrative costs for NIST to develop benchmarks and run a voluntary testing program.
  • Federal agencies may incur costs to identify, remove, or replace covered AI models and to implement or certify technical safeguards.
  • Vendors may face costs to modify models to meet benchmarks or to defend against private lawsuits.
  • Potential legal costs and damages from civil suits could be significant for parties found liable.

Proponents' View#

  • The bill appears intended to stop government use of AI models that can produce synthetic child sexual abuse material or non-consensual intimate images.
  • Supporters may argue the bill would protect people from exploitation by removing dangerous models from federal systems and by pushing developers to adopt stronger safety controls.
  • Requiring NIST benchmarks and vendor testing could improve technical standards and give agencies clearer criteria for safe AI use.
  • Allowing agencies to demand vendor fixes (at vendor cost) or to adopt safeguards could speed removal or mitigation of risky models.
  • The private right of action gives victims and affected developers a way to seek remedies and to deter both misuse and selling tools that defeat protections.

Opponents' View#

  • One concern is that the bill does not fully define how NIST benchmarks will work or what “sufficient” technical controls are, leaving important details uncertain until NIST issues guidance.
  • The definition of which AI models are covered could be broad. This may unintentionally include legitimate models that generate benign imagery, depending on how benchmarks and tests are applied.
  • The timelines (90 days for benchmarks, 180 days for agency removal) may be tight for agencies, vendors, and NIST to carry out technical reviews and changes.
  • The private right of action could lead to increased litigation. That may raise legal costs for developers, vendors, and other parties even in unclear or borderline cases.
  • The anti-circumvention ban could affect dual-use tools (tools with both legitimate and illegitimate uses) if it is hard to separate “primarily designed” circumvention products from legitimate software.
  • It is unclear how the bill would be enforced in practice, how courts will interpret key terms, and how international or open-source models would be handled.