This act would require the Secretary of Defense to create a department-wide program to report, track, analyze, and fix AI incidents and vulnerabilities that arise during development, testing, procurement, fielding, or operation of AI systems used by the Department of Defense. The program must identify recurring risks and failure modes, support mitigation of significant risks, and help inform testing, procurement, cybersecurity, and deployment decisions. It must be designed using practices from safety incident reporting and vulnerability disclosure programs, emphasize non-punitive reporting, protect sensitive and proprietary information, and enable timely access to logs, system data, and model information for analysis. The Secretary must name an official to receive and standardize reports, perform trend analysis, and issue guidance. Reports must be categorized by whether they need a Department-wide, program-level, or local response. For Department-wide or program-level matters, the official must coordinate remediation, retesting, mitigation, or deployment restrictions, and require documented corrective action plans and validation before continued operational use. The act creates a protected disclosure process that prevents retaliation for good-faith reporters and requires procedures to protect sensitive and classified submissions. It also requires annual unclassified reports (with optional classified annexes) to the congressional defense committees for 2027–2031, including counts of reports, summaries of trends and corrective actions, recommendations, and detailed information for any incidents that caused death or bodily harm. The act defines key terms including "artificial intelligence," "covered AI incident," and "covered AI vulnerability."
No publicly available information.
Proponents would say the program will help identify recurring risks and systemic weaknesses, support mitigation of significant risks, and improve the safety, security, reliability, and operational effectiveness of AI systems by informing testing, procurement, cybersecurity, and deployment decisions.
No publicly available information.