HR 9333 would have NIST run a voluntary programme for reporting and tracking AI flaws — agreeing common definitions and classification criteria, supporting disclosure standards, and building a national database of AI flaws or extending an existing one. It passed committee 35-0 and is not yet in force.
The AI Flaw Reporting and Security Enhancement Act would set up a voluntary programme for reporting and tracking flaws in artificial intelligence systems, administered by the National Institute of Standards and Technology. The word doing the work is voluntary: the bill builds a place to report problems rather than a duty to disclose them.
NIST would first have to settle the vocabulary. The bill directs it to convene stakeholders to agree common definitions for terms relating to AI flaws and criteria for classifying them — separating, for example, security-related flaws from safety-related ones. That group would also support technical standards and guidance for detecting, managing and disclosing flaws, and for deciding which ones to fix first.
The second half is infrastructure. NIST would build, or enter cooperative agreements with universities and research institutions to build, the machinery for voluntarily reporting, collecting and tracking AI flaws — including a national database of AI flaws, or the modification of an existing national database to account for them. NIST already administers a national database of cybersecurity vulnerabilities, so the bill is deliberately reusing a working model rather than inventing one, and it requires NIST to weigh interoperability with existing systems, standards and best practices. NIST would report to Congress on implementation within three years of enactment.
The bill also defines its subject, which matters more than it sounds. An AI flaw is a set of conditions or behaviours that allow a policy — safety or security, for instance — to be violated, and it is explicitly not necessarily associated with malicious intent. That definition covers the model that fails without anyone attacking it, which is the case a purely security-framed regime tends to miss.
How does a voluntary federal reporting hub sit alongside the mandatory approaches elsewhere in this tracker? Alaska SB 2 bundles AI, deepfakes, cybersecurity and data transfers into a single measure and is still in committee, while Singapore's Cybersecurity Act 2018 is already in force. The federal bill is narrower than either and asks for cooperation rather than compliance — an open question is whether a database people opt into fills up fast enough to be useful.
The bill is pending. It was ordered to be reported in the nature of a substitute by a vote of 35 to 0, and it is not in force; the record carries no effective date, so there is no date on which any of this begins.
Sources & citations
- The NIST-administered voluntary reporting programme, the stakeholder convening on definitions and classification criteria, the standards and guidance work, the reporting infrastructure and national database of AI flaws, the interoperability consideration, the three-year report to Congress, the definition of an AI flaw, and the 35-0 committee vote and pending status. www.congress.gov
- Alaska SB 2 (AI, deepfakes, cybersecurity, data transfers), in committee. www.akleg.gov
- Singapore Cybersecurity Act 2018, in force. sso.agc.gov.sg
See the full AI law picture for United States (Federal)
Statuses, deadlines, penalties, and primary sources — kept current on AI Law Tracker.