Secure A.I. Development Act

Full Title:
Secure A.I. Development Act of 2026

Summary#

This bill sets rules for how the federal government and private groups handle security and safety risks from advanced artificial intelligence (AI). It defines key terms and creates new bodies and processes. Key actions include creating an Artificial Intelligence Risk Board at the National Institute of Standards and Technology (NIST); requiring providers of high-risk "frontier" AI models to give the National Security Agency (NSA) access to models 21 days before public release; creating a public registry of frontier models; expanding an NSA research test-bed for pre-release testing; and building a voluntary public database for AI security and safety incidents. The bill also directs updates to national vulnerability databases and reporting processes to cover AI-related vulnerabilities, asks agencies to review how AI vulnerabilities fit into the Vulnerabilities Equities Process, and establishes a 3-year pilot program for secure intelligence and threat sharing between the NSA and covered private-sector AI developers that work with federal agencies. The bill includes rules for classified access, conflict-of-interest policies for board members, protections for information shared with the government from public disclosure, and a daily civil penalty for some failures to provide pre-release access.

What it means for you#

  • If you build or provide "frontier" AI models, you must register the model with NIST and give the NSA access to the model (including weights and configuration) 21 calendar days before public release.
  • Providers who fail to give required access may face fines (at least $100,000 per day) but are allowed a 7-day chance to cure the violation by withdrawing the model from commerce and providing access.
  • Researchers, critical infrastructure operators, and others could get access to a secure NSA test-bed to evaluate frontier models before public release.
  • Private companies that share incident reports or threat information with NIST or the NSA may have that information kept confidential and protected from public disclosure. The bill also shields companies from civil liability for sharing such information with the government under the pilot program.
  • NIST and CISA will run a voluntary public database where organizations can report AI security and safety incidents in an anonymized way. NIST will publish guidance to help decide when an event "materially increases" risk.

Expenses#

  • The bill sets a civil penalty of not less than $100,000 per day for each day a frontier model is available in commerce in violation of the pre-release access requirement in section 3(c).
  • No publicly available information on estimated federal budgetary costs, appropriations, or other fiscal impacts is provided in the bill text.

Proponents' View#

No publicly available information.

Opponents' View#

No publicly available information.