Defense AI Reliability and Reporting Act

Full Title:
Defense AI Reliability and Reporting Act

Summary#

This act would require the Secretary of Defense to create a department-wide program to report, track, analyze, and fix AI incidents and vulnerabilities that arise during development, testing, procurement, fielding, or operation of AI systems used by the Department of Defense. The program must identify recurring risks and failure modes, support mitigation of significant risks, and help inform testing, procurement, cybersecurity, and deployment decisions. It must be designed using practices from safety incident reporting and vulnerability disclosure programs, emphasize non-punitive reporting, protect sensitive and proprietary information, and enable timely access to logs, system data, and model information for analysis. The Secretary must name an official to receive and standardize reports, perform trend analysis, and issue guidance. Reports must be categorized by whether they need a Department-wide, program-level, or local response. For Department-wide or program-level matters, the official must coordinate remediation, retesting, mitigation, or deployment restrictions, and require documented corrective action plans and validation before continued operational use. The act creates a protected disclosure process that prevents retaliation for good-faith reporters and requires procedures to protect sensitive and classified submissions. It also requires annual unclassified reports (with optional classified annexes) to the congressional defense committees for 2027–2031, including counts of reports, summaries of trends and corrective actions, recommendations, and detailed information for any incidents that caused death or bodily harm. The act defines key terms including "artificial intelligence," "covered AI incident," and "covered AI vulnerability."

What it means for you#

  • Members of the Armed Forces, civilian employees, contractors, and subcontractors may report AI incidents and vulnerabilities through a protected disclosure process.
  • Reporters are protected from adverse contract or personnel actions for good-faith reports.
  • Program managers and operators must promptly report covered incidents and vulnerabilities and may face required remediation, retesting, deployment limits, and validated corrective action plans for serious issues.
  • The Department will track trends and issue guidance, alerts, and recommendations that can affect testing, procurement, cybersecurity, and deployment of AI systems.

Expenses#

No publicly available information.

Proponents' View#

Proponents would say the program will help identify recurring risks and systemic weaknesses, support mitigation of significant risks, and improve the safety, security, reliability, and operational effectiveness of AI systems by informing testing, procurement, cybersecurity, and deployment decisions.

Opponents' View#

No publicly available information.