Title II: Demand A Fair Plan For AI
Demanding an evidence-based plan for the impact of AI is Title II of the MAD Act. Read the fact-sheet about the bill title or read the full bill title below.
TITLE II of The MAD Act
“DEMAND A PLAN FOR AI”
SEC. 2001. SHORT TITLE; TABLE OF CONTENTS.
(a) SHORT TITLE.—This title may be cited as the "Demand a Plan for AI Act".
(b) TABLE OF CONTENTS.—The table of contents of this title is as follows:
CHAPTER 1—GENERAL PROVISIONS
Sec. 2001. Short Title; Table of Contents.
Sec. 2002. Findings and Purpose.
Sec. 2003. Definitions.
CHAPTER 2—INVESTIGATIVE FRAMEWORK
Sec. 2004. Technical Working Groups and Domains of Investigation.
Sec. 2004(b)(2). TWG 1 — Intellectual Property and Creator Rights.
Sec. 2004(b)(3). TWG 2 — Electoral Integrity and Democratic Resilience.
Sec. 2004(b)(4). TWG 3 — Compute Infrastructure and Export Controls.
Sec. 2004(b)(5). TWG 4 — Financial Markets and Antitrust.
Sec. 2004(b)(6). TWG 5 — AI Safety and Post-AGI Governance.
Sec. 2004(b)(7). TWG 6 — Children, Youth, and Vulnerable Populations.
Sec. 2004(b)(8). TWG 7 — Workforce, Labor, and Economic Transition.
Sec. 2004(b)(9). TWG 8 — Environmental, Energy, and Community Impact.
Sec. 2004(b)(10). TWG 9 — Liability, Accountability, Legal Frameworks, and Constitutional Dimensions.
Sec. 2004(b)(11). TWG 10 — AI Security, Critical Infrastructure, and Incident Response.
Sec. 2004(b)(12). TWG 11 — Autonomous Weapons, International Humanitarian Law, and Arms Control.
Sec. 2004(b)(13). Cross-Cutting Mandates.
Sec. 2004(b)(14). Precautionary Principle.
Sec. 2005. Governance of Technical Working Groups.
Sec. 2005(a). Establishment and Two-Stage Appointment Process.
Sec. 2005(b). General Requirements Applicable to All TWGs.
Sec. 2005(c). TWG Coordination Council.
Sec. 2005(d). TWG Integrity and Misconduct Framework.
Sec. 2005(e). Election of TWG Representatives to the Federal Advisory Committee.
Sec. 2006. Federal Advisory Committee.
Sec. 2006(c). Chair.
Sec. 2006(d). Quorum and Voting.
Sec. 2006(e). Conflict of Interest — Committee Members.
Sec. 2006(f). Staff and Administrative Capacity.
Sec. 2006(i). Legislative Transmission to Congress.
Sec. 2006(k). Dissolution and Transition.
Sec. 2007. Stakeholder Engagement and Public Participation.
Sec. 2008. Data Collection, Monitoring, and Infrastructure.
Sec. 2009. State Cooperation and Pilot Programs.
CHAPTER 3—REPORTING AND TRANSITION
Sec. 2010. Reports to Congress.
Sec. 2010(a). Interim Progress Report.
Sec. 2010(b). Interim Investigative Status Report.
Sec. 2010(c). Final Factual Report.
Sec. 2010(e). GAO Independent Review.
CHAPTER 4—LEAD AGENCY AND AUDITOR PROGRAM
Sec. 2011. Designation of Lead Agency and Interagency Coordination.
Sec. 2011(b). Functions.
Sec. 2011(d). Transmission of Investigative Material to TWGs.
Sec. 2011(e). Interagency Data Access Mechanism.
Sec. 2011(f). Department of Justice Data Cooperation.
Sec. 2011(i). Classified Track.
Sec. 2011(j). Enforcement Authority and Designation.
Sec. 2012. Certified Independent AI Auditor Program.
Sec. 2012(f). Prohibition on Self-Reported Evaluations.
Sec. 2012(g). Transitional Evaluation Authority.
Sec. 2012(h). CBRN Evaluation Specialist Track.
CHAPTER 5—INDEPENDENT BODIES AND INTERNATIONAL ENGAGEMENT
Sec. 2013. National AI Council.
Sec. 2013(c). Appointment Deadline and Fallback.
Sec. 2013(d). Quorum.
Sec. 2013(e)(3). Shelf-Ready Emergency Legislation.
Sec. 2013(f). Transformative AI Capability Event — Emergency Congressional Action Procedures.
Sec. 2013(f)(1). Designated Introducers.
Sec. 2013(f)(2). Automatic Discharge.
Sec. 2013(f)(3). Mandatory Floor Vote.
Sec. 2013(f)(4). Total Maximum Time to Floor Vote.
Sec. 2013(f)(5). Day 60 Interim Regulatory Authority.
Sec. 2013(f)(6). Constitutional Basis.
Sec. 2014. International AI Diplomacy Agency.
Sec. 2014(c)(1). International AI Safety Agency (IASA) Proposal.
Sec. 2014(c)(2). Compute Monitoring Framework.
Sec. 2014(c)(3). Preliminary TACE Response Framework.
Sec. 2014(d). Director (Ambassador-at-Large; reports to President through NSC).
Sec. 2014(j). Independence Protections.
CHAPTER 6—LEGISLATIVE TRIGGER AND HAMMER PROVISIONS
Sec. 2015. Legislative Trigger, Transition to Regulation, and Mandatory Hammer Provisions.
Sec. 2015(a). Automatic Moratorium on High-Risk Deployments.
Sec. 2015(b). Penalty Assessment Procedures.
Sec. 2015(c). Domain-Specific Hammer Provisions.
Sec. 2015(c)(1). Domain 13 — Compute Export Controls: Immediate Total Export Restriction.
Sec. 2015(c)(2). Domain 14 — Market Concentration: Acquisition and Investment Freeze.
Sec. 2015(c)(3). Domain 10 — Environmental Impacts: Data Center Construction Moratorium and Disclosure.
Sec. 2015(c)(4). Domain 15 — Open-Weight AI Models: Frontier Model Release and Training Moratorium.
Sec. 2015(c)(5). Domain 17 — Electoral Integrity: Mandatory AI Content Disclosure and Distribution Suspension.
Sec. 2015(d). Graduated Congressional Extension Mechanism.
Sec. 2015(e). Early Domain Passage and Rolling GAO Certification.
Sec. 2015(g). Automatic Private Right of Action.
Sec. 2015(h). Personal Liability of Corporate Officers.
Sec. 2015(k). Congressional Override and Stay.
Sec. 2015(l). Settlement Authority and Penalty Floors.
Sec. 2015(n). Transformative AI Capability Event Protocols.
Sec. 2015(n)(1). Mandatory Notification.
Sec. 2015(n)(2). Mandatory Congressional Briefing.
Sec. 2015(n)(3). Mandatory Pause on Training, Capability Advancement, and Operations.
CHAPTER 7—IMMEDIATE PROTECTIONS AND RED LINES
Sec. 2016. Immediate Interim Provisions.
Sec. 2016(b). Mandatory Incident Reporting.
Sec. 2016(d). Training Data Disclosure to Lead Agency and National AI Council.
Sec. 2016(e). Deployer Risk Management Policy.
Sec. 2016(f). AI Data Sheet.
Sec. 2016(g). Post-Release Duty to Update and Notify.
Sec. 2016(h). Prohibited Uses.
Sec. 2016(i). Mandatory Default Safety Settings for Minor Users.
Sec. 2016(j). Interim CBRN Self-Evaluation Disclosure Requirement.
Sec. 2016(k). CBRN Registration and Notice Mechanism.
Sec. 2016(l). Emergency Moratorium Authority.
Sec. 2016(m). General Penalty Framework.
Sec. 2016(n). Safe Harbor for Good-Faith Compliance.
Sec. 2016(o). Private Right of Action for AI Product Harms.
Sec. 2017. AI Red Line Prohibitions.
Sec. 2017(a)(1). Autonomous Weapons Without Meaningful Human Oversight.
Sec. 2017(a)(1)(C). Consequences for Non-Certified Programs.
Sec. 2017(a)(1)(D). Outright Prohibition on Autonomous Weapons Against Any Person on United States Soil.
Sec. 2017(a)(1)(E). Presidential Disclosure for Each Use of Autonomous Weapons Abroad.
Sec. 2017(a)(1)(E)(vi). Executive Privilege — Structural Consequence Provision.
Sec. 2017(a)(1)(I). Defensive Emergency Autonomy Exception.
Sec. 2017(a)(2). CBRN Threat Assistance.
Sec. 2017(a)(3). Autonomous Capability Self-Modification.
Sec. 2017(a)(4). Self-Replicating AI and Unauthorized Resource Acquisition.
Sec. 2017(a)(5). AI Companion Systems — Child Safety Protections and Provisional Prohibition on Deceptive Emotional Manipulation.
Sec. 2017(a)(6). Concealment of Transformative Capability.
Sec. 2017(c). Statutory Interpretive Framework.
Sec. 2017(d). Nature and Durability of Prohibitions.
Sec. 2017(e). Judicial Review of Red Line Enforcement Determinations.
CHAPTER 8—WHISTLEBLOWER AND ACCOUNTABILITY
Sec. 2018. Whistleblower Protections.
Sec. 2019. Accountability and Personal Liability of the Secretary.
CHAPTER 9—MISCELLANEOUS
Sec. 2020. Severability.
Sec. 2021. Scope and Applicability.
Sec. 2021(a). Federal Floor; No Preemption of Stronger State Protections.
Sec. 2021(b). Express Preemption.
Sec. 2021(c). Statute of Limitations.
Sec. 2021(d). Relationship to Interim Federal Legislation.
Sec. 2022. Authorization of Appropriations.
Sec. 2023. Effective Date.
CHAPTER 1—GENERAL PROVISIONS
SEC. 2002. FINDINGS AND PURPOSE.
(a) FINDINGS.—Congress finds the following:
(1) Artificial intelligence is among the most consequential general-purpose technologies in modern history, with the capacity to reshape employment, healthcare, finance, national security, education, scientific research, critical infrastructure, and the exercise of human rights. Its trajectory is rapid and its consequences, both extraordinary and concerning, are insufficiently understood, making it essential that the Federal Government act on the basis of evidence rather than speculation.
(2) AI may offer substantial potential to expand human capability and improve American life, including by accelerating drug discovery and scientific research, advancing climate and weather modeling, expanding affordable access to expert-level guidance, augmenting worker productivity, and helping small businesses and individuals compete with larger institutions. Documented productivity gains are significant, and broadly accessible AI tools can reduce information asymmetries between individuals and large institutions, but not all impacts are predicted to be positive.
(3) The capability trajectory of frontier AI is well-documented. According to the United Kingdom AI Security Institute's 2025 Frontier AI Trends Report, frontier models advanced from "apprentice-level" to "expert-level" cybersecurity tasks between 2023 and 2025, and the duration of autonomous software task completion has been doubling approximately every eight months. More recently, Alibaba’s ROME agent is alleged to have demonstrated instrumental convergence capabilities, which means the agent escaped its containment envelope to acquire resources without permission.
(4) Frontier AI developers, including Anthropic, OpenAI, Google DeepMind, Meta, Microsoft, Amazon, and xAI, have published voluntary safety policies acknowledging that frontier AI may facilitate CBRN weapons development, cyberattacks, and evasion of human developer controls, demonstrating industry recognition that safeguards are needed even as corresponding legal standards do not yet exist.
(5) AI is also reshaping labor markets. The International Monetary Fund estimates approximately 40% of jobs globally and 60% in advanced economies are exposed to AI impact, while the McKinsey Global Institute estimates AI could automate approximately 57% of current U.S. working hours. Whether this exposure produces broadly shared prosperity or concentrated displacement depends substantially on policy choices, deployment pace, and the accessibility of AI tools to workers and small businesses.
(6) Certain populations face elevated transition risk, including workers in high-automation-exposure roles and entry-level positions where employers may use AI to forgo expansion rather than initiate layoffs, a pattern conventional displacement metrics do not capture. These challenges are addressable through evidence-based policy but require accurate measurement and proactive design.
(7) AI infrastructure is generating both economic opportunity and community impact. Large data centers can use as much electricity as 100,000 households, and the largest facilities can consume up to 5 million gallons of water per day, with cumulative impacts concentrated in host communities and water-stressed regions. Residential electricity prices rose 7.1% in 2025, more than double the inflation rate, with data center demand a significant contributing factor, and 82% of California data centers are sited in communities already experiencing poor air quality. Sound policy can capture infrastructure benefits while preventing cost externalization to ratepayers and host communities.
(8) Children interacting with AI systems face documented risks warranting immediate attention. Wrongful death litigation arising from minor suicides linked to AI companion interactions, including the deaths of Sewell Setzer III, Adam Raine, and Juliana Peralta, has produced findings indicating meaningful corporate responsibility. A 2025 JMIR Mental Health study found AI chatbots endorsed harmful proposals from distressed fictional adolescents in 32% of test scenarios, with only 36% of platforms employing any age verification. These risks coexist with genuine educational benefits AI can offer young people; the policy task is to secure benefits while protecting against harms.
(9) AI-generated child sexual abuse material represents a categorical harm. The National Center for Missing and Exploited Children received approximately 67,000 reports involving generative AI in 2024, a 1,325% year-over-year increase, with 40% of identified material falling into the most severe category. Existing federal law under 18 U.S.C. §§ 2252A and 1466A does not fully cover this harm, which warrants immediate prohibition.
(10) AI-generated synthetic media has emerged in federal elections without a comprehensive federal response, even as AI offers genuine democratic benefits, including fact-checking, supporting journalism, and providing tools for citizens to analyze public records. Open-weight AI models function as instruments of free expression by distributing capability beyond any single corporation or government. A balanced framework should address electoral integrity threats while preserving AI's democratic and speech-protective functions.
(11) More than 51 copyright infringement lawsuits are pending against AI developers as of March 2026, reflecting unresolved questions about training data, fair use, and creator compensation, even as licensing markets between developers and rights holders are emerging. An evidence-based framework can simultaneously protect creator rights and support continued AI development.
(12) The Federal Government currently lacks the comprehensive evidentiary record, technical capacity, and coordinated regulatory infrastructure necessary to prescribe durable, judicially resilient AI guardrails across all relevant domains. Premature regulation risks both under-protection and over-restriction; continued inaction leaves documented harms unaddressed and creates uncertainty that itself impedes responsible development. The appropriate response is a structured investigatory process producing evidence-based legislation, paired with narrowly targeted immediate protections for the most well-documented harms.
(13) Congress has successfully employed phased, investigatory legislative strategies for complex technical domains, including the Air Quality Act of 1967 (Public Law 90-148) and the Water Quality Act of 1965 (Public Law 89-234). This proven approach is well-suited to AI governance.
(14) The hammer provisions established by this title, including the automatic moratorium and domain-specific restrictions triggered by Congressional failure to enact Phase II legislation, are not intended to punish frontier AI developers or significant AI deployers, but to ensure that Congress completes the work of developing a comprehensive plan for AI governance. Self-executing consequences for legislative inaction have a demonstrated track record in federal law, including the Budget Control Act of 2011 (Public Law 112-25), of focusing Congressional attention and producing timely legislative outcomes. The graduated extension mechanism in this title rewards meaningful legislative progress while preserving the credibility of the underlying deadline.
(15) Effective AI governance must be a square deal, protecting the public against documented harms while preserving the conditions under which AI can fulfill its potential to expand opportunity, accelerate progress, support workers, and strengthen democratic institutions. The framework established by this title is designed to serve both interests simultaneously: providing frontier AI developers and significant AI deployers with predictable, evidence-based standards while ensuring AI's benefits are broadly shared and its most serious harms prevented.
(b) PURPOSE.—The purposes of this title are
(1) to direct a comprehensive, structured, and time-bound investigation on the opportunities, risks, impacts, necessities, and possible oversight needed in regards to AI models, AI systems, and infrastructure across the 19 domains that are specified in this title, conducted through Technical Working Groups (TWGs) composed of both domain experts and AI technical specialists operating under the Federal Advisory Committee (FAC), with the lead agency serving as a complimentary investigatory partner;
(2) to produce introduction-ready draft statutory language for all 19 investigation domains, individually or in combination, which may take the form of binding regulatory standards, non-regulation findings, or a combination thereof, informed with evidence and a rigorous inquiry process;
(3) to build federal institutional research capacity, in-house technical expertise, and interagency coordination for the development of AI oversight processes, including the establishment of a Certified Independent AI Auditor Program that creates a permanent credentialing framework for the independent pre-deployment safety evaluation of frontier AI systems;
(4) to establish several, immediate interim protective measures addressing the most urgent and well-documented AI-related risks and harms, including protections for children, workers, communities, and civil rights which are operative from the date of enactment, without awaiting the conclusion of the investigatory process;
(5) to additionally enact permanent, absolute prohibitions on the most categorically dangerous uses of AI systems, including autonomous weapons without meaningful human oversight, AI assistance with weapons of mass destruction, and the sexual exploitation of children, which are not contingent on the investigatory process;
(6) to establish robust whistleblower protections, confidential safe reporting channels, and safe harbors for researchers which will ensure that individuals with knowledge of AI safety violations, dangerous capabilities, or harms to children can disclose that information without fear of retaliation;
(7) to require frontier AI developers operating frontier models and systems capable of exhibiting dangerous capabilities disclose their training data provenance and CBRN self-evaluation results, if they exist, to the lead agency, for the purpose of further building the evidentiary foundation for the investigation;
(8) to establish a general duty of care for both frontier AI developers and significant AI deployers, a standing private "right of action" enabling individuals who are harmed by AI models or AI systems to be able to seek redress through a fault-based standard. This includes a rebuttable presumption of reasonable care for entities that are compliant, and a public-facing AI Data Sheet disclosure system. This AI Data Sheet disclosure system is analogous to the Material Safety Data Sheets required under OSHA's Hazard Communication Standard, which provide deployers and end-users with the safety information necessary to make informed decisions about AI usage;
(9) to require that frontier AI developers maintain post-release monitoring programs, systems or processes, and for them to act upon discovered dangers through product updates, deployer notification, and public disclosure, as well as require significant AI deployers of high-risk AI systems to implement documented risk management policies;
(10) to create binding accountability mechanisms and hammer provisions, including an automatic moratorium on new frontier model training, new data center construction, and both mandatory civil penalties and personal officer liability upon moratorium breach to ensure that the transition from investigation to comprehensive regulation is not delayed, obstructed, or undermined;
(11) to establish a National AI Council as a permanent independent oversight body, charged with maintaining and updating the evidentiary record, preparing shelf-ready emergency legislation, and for providing ongoing legislative recommendations to Congress as AI and its emergent capabilities become known;
(12) to establish an International AI Diplomacy Agency charged with negotiating international AI safety policy and compute-monitoring regimes, while developing a preliminary Transformative AI Capability Event response framework within 180 days of enactment, as well as formally proposing an International AI Safety Agency to the United Nations and G7 member states not later than one year after the date of enactment;
(13) to appropriately incorporate both specific carveouts and safe harbors which guard against any premature, overreaching, and potentially unnecessary regulation of AI systems and tools, pending the conclusion of the Technical Working Group investigation, which is permitted to make non-regulation findings for each domain if the evidence does not support binding standards; the designation of certain Red Line prohibitions as provisional; specific safe harbors for legitimate research, good-faith safety evaluation, defensive military operations, distributed scientific computing, and other domains; explicit permission for agentic AI systems to continue to operate autonomously within human-authorized scope, which includes first-order agent spawning, task-bounded subagents, and both agentic tooling and API use, with a prohibition targeted narrowly towards unauthorized propagation beyond human-decided scopes, and resistance to being shut down or cease operating rather than at agentic tools and capabilities generally; and a mechanism to extend congressional action that rewards meaningful legislative progress rather than triggering automatic consequences for delayed action that may be necessary.
SEC. 2003. DEFINITIONS. In this title:
(1) AGENTIC AI SYSTEM.—The term "agentic AI system" means an AI system that
(A) executes multi-step sequences of actions or decisions in pursuit of a goal, task specification, or objective, in which the determination of each successive action or decision is conditioned upon the observed outcomes of prior actions, upon state or feedback obtained from the environment in which the system operates, or upon both, and in which the system proceeds from action to action without requiring an individualized, contemporaneous human authorization for each action in the sequence;
(B) has the technical capacity to interact with computational, informational, or physical environments external to its inference process through the invocation of discrete operational capabilities, including but not limited to: application programming interface (API) calls; execution of code or shell commands on host or remote computing systems; reading, writing, or modification of files, databases, or other persistent data stores; transmission or receipt of network communications; retrieval, ingestion, or processing of external content, including through programmatic web browsing or query-based retrieval; initiation of financial, contractual, or transactional actions; or actuation of physical, mechanical, or virtual effectors;
(C) is configured, or is capable of operating in a configuration, in which outputs of one inference step, model invocation, or AI system component are programmatically supplied as inputs to a subsequent inference step, model invocation, or AI system component without intermediate human review; and
(D) INCLUSIONS. The term "agentic AI system" includes multi-agent orchestration architectures, autonomous AI workflows, and integrated agent scaffolding configurations regardless of whether any individual component AI model independently satisfies subparagraphs (A) through (C), provided that the integrated configuration satisfies those subparagraphs.
(2) AI COMPANION SYSTEM.—The term "AI companion system" means any AI system that -
(A) is designed, marketed, or primarily used to simulate the appearance or experience of an ongoing emotional, social, or romantic relationship with a human user;
(B) employs conversational, voice, avatar-based, or other interactive modalities to sustain engagement with a user over multiple sessions;
(C) maintains a persistent or semi-persistent memory of user interactions, which includes personal information or emotional disclosures across multiple sessions; or
(D) uses techniques such as emotional mirroring, anthropomorphic self-presentation, simulated empathy, or variable-reward interaction design to encourage ongoing user emotional attachment or engagement. The term includes, but is not limited to, platforms and applications commonly described as "AI companions,""AI friends,""AI therapists," AI chatbots with relational personas, and other AI platforms which provide characters for users to interact with in a personal manner. The term does not include customer service chatbots that do not simulate ongoing personal relationships, general-purpose AI assistants that do not employ the design features described in subparagraphs (A) through (D), or licensed mental health tools that operate under clinical supervision.
(3) AI MODEL.—The term "AI model" means a computational artifact consisting of trained numerical parameters, including weights, biases, embeddings, and the associated architectural configurations, which has been produced through a training process in which a learning algorithm iteratively adjusts such parameters on the basis of training data so as to enable the computational artifact to generate outputs from inputs through statistical inference. This term refers to the artifact itself, which is the product of said training process, at every stage of its development and modification. This includes development and modification after pre-training, supervised fine-tuning, reinforcement learning from human feedback (RLHF), reinforcement learning from AI feedback, direct preference optimization, knowledge distillation, quantization, pruning, model merging, or any other technique that creates or modifies the numerical parameters of the computational artifact. A supplemental set of trained parameters, including low-rank adaptations, adapter modules, or other parameter-efficient modifications which are designed to be applied to a base AI model in order to alter its behavior, constitutes a component of the AI model that results from such application. The properties of an AI model include the knowledge, capabilities, and behavioral tendencies encoded in its parameters; its architecture and parameter count; the training data from which its parameters were derived; and latent capabilities that may be elicited through prompting, fine-tuning, or integration into an AI system, regardless of whether such capabilities were intended or predicted by the developer. The same AI model may be incorporated into multiple distinct AI systems. The release, licensing, distribution, or making available of an AI model, including by making trained weights open source or otherwise publicly available, may, depending on the manner and context of release, constitute or give rise to the deployment of an AI system. The term "AI model" does not include, however, the inference software, application programming interfaces (APIs), prompts to the system, content filtering, retrieval-augmented generation pipelines, tool-access configurations, or other system-level components that may be combined with a model to instead constitute an AI system.
(4) AI SYSTEM.—The term "AI system" means any product, service, interface, or operational configuration that incorporates one or more AI models to make the capabilities of such a model or models available to users, available to other systems, or available in a physical or virtual environment. An AI system includes the AI model combined or connected with any system-level components that shape or mediate the behavior of the underlying model it is operationally dependent upon, including inference infrastructure, application programming interfaces (APIs), user interfaces, content filters, tool-access configurations, agent scaffolding, or memory and state-persistence mechanisms. The same AI model incorporated into different operational configurations constitutes a distinct AI system for each configuration.
(5) AI-GENERATED SEXUAL ABUSE MATERIAL (CSAM).—The term "AI-generated CSAM" means any visual depiction, including any photograph, film, video, picture, animation, or computer generated image or picture, whether made by electronic, mechanical, digital, artificial intelligence, or other means, that—
(A) depicts a minor engaging in sexually explicit conduct as defined in 18 U.S.C. § 2256(2); and
(B) was generated, synthesized, or substantially modified using an AI system, without requiring the actual exploitation of a real child in its production.
AI-generated CSAM includes material produced through generative AI models, image synthesis, video synthesis, deepfake techniques, and any combination thereof, regardless of whether the depicted person is based on a real individual or is entirely synthetic.
(6) AI-NATIVE COMPANY.—The term "AI-native company" means any entity founded on or after January 1, 2026, whose primary business model, revenue generation, sole or suite of products, or market function is substantially or wholly dependent on AI systems.
(7) AUTONOMOUS WEAPONS SYSTEM.—The term "autonomous weapons system" means any weapon, weapons platform, munition, or weapons delivery system that—
(A) uses an AI system, automated logic, sensor data processing, or any combination thereof to select, identify, prioritize, track, or engage targets without requiring a human operator to make an individualized, affirmative, real-time decision to authorize each specific act of engagement, strike, or lethal or destructive action;
(B) is capable of executing lethal force, destructive action, or physical harm to a person, a group of persons, or property through any means, including kinetic weapons, directed energy weapons, explosive munitions, or electronic or cyber means that produce physical effects; and
(C) operates with or without continuous human supervision once initiated.
(D) INCLUSIONS.—The term "autonomous weapons system" includes—
(i) unmanned aerial vehicles, unmanned aerial systems, and drones of any size equipped with any lethal or destructive payload, sensor-based targeting capability, or autonomous engagement logic;
(ii) unmanned ground vehicles, unmanned surface vessels, and unmanned underwater vehicles equipped with any lethal or destructive payload or autonomous engagement capability;
(iii) loitering munitions and autonomous-search munitions designed to identify and engage targets through onboard sensor logic without continuous real-time human direction;
(iv) automated defense systems capable of autonomous engagement of incoming threats;
(v) AI-enabled targeting systems that autonomously select, rank, or recommend specific human individuals or specific physical structures as targets for lethal or destructive action, regardless of whether the final engagement command is issued by a human operator; and
(vi) swarm systems in which multiple autonomous platforms collectively execute engagement decisions through distributed inter-platform communication, regardless of whether any individual platform in the swarm receives a discrete human authorization command.
(E) EXCLUSIONS.—The term "autonomous weapons system" does not include—
(i) precision-guided munitions that, once released by a human operator following an individualized human targeting decision, use guidance systems to navigate to a human-designated target without independent target identification or re-targeting capability;
(ii) systems that use automation solely for navigation, propulsion, or platform stability and that require a separate, contemporaneous human authorization command for each individual act of engagement; or
(iii) unarmed aerial, ground, surface, or underwater vehicles that carry no lethal or destructive payload and have no autonomous engagement capability, regardless of the degree of their navigational autonomy.
(8) COMPLETE LEGISLATIVE PACKAGE.—The term "complete legislative package" means the full set of domain packages transmitted by the Federal Advisory Committee to Congress under section 2006(i), addressing each of the 19 investigation domains specified in section 2004(b)(1), in the form of introduction-ready statutory text suitable for immediate introduction in either chamber of Congress. A complete legislative package may take the form of a single unified bill addressing all 19 domains, a series of individual domain-specific bills each addressing one or more domains, or a combination of domains, provided that taken together the transmitted packages address all 19 domains. A domain package is introduction-ready within the meaning of this definition when it contains numbered sections, defined terms cross-referenced consistently with other domain packages, enforcement mechanisms, penalty provisions, and a section-by-section analysis. The lead agency shall publish a public checklist identifying which domains have been addressed by transmitted packages, updated within 3 business days of each transmission.
(9) COMPUTE PROVIDER.—The term "compute provider" means any person or entity that provides computational resources, including: cloud computing, data center colocation, hardware rental, or dedicated computing infrastructure used for training, fine-tuning, or large-scale inference of AI models exceeding 10^24 floating-point operations.
(10) COORDINATED INAUTHENTIC INFLUENCE CAPABILITY.—The term "coordinated inauthentic influence capability" means any capability of an AI system described in subparagraph (A), subject to the limitation in subparagraph (B).
(A) IN GENERAL.—A capability that enables the automated generation and coordinated deployment of synthetic personas, AI-generated media, or targeted messaging at a scale and level of personalization and operation beyond what could be achieved by human agents deploying such systems alone and individually in the same timeframe, for the specific purpose of deceiving recipients about the human or authentic origin of the communication, including through fabricated social media identities, AI-generated impersonations of real individuals, coordinated inauthentic account networks, or synthetic audiovisual depictions distributed in a manner designed to conceal their AI-generated origin.
(B) LIMITATION.—A capability is within subparagraph (A) only if deception about the true nature, origin, or character of the communication is evident, the coordinated or artificial nature of the operation is concealed, and the operation occurs at scale. The term does not include constitutionally protected political speech, commercial advertising, journalism, public health communication, or advocacy, regardless of scale, provided the communication does not involve deceptive impersonation of real individuals or concealment of AI-generated origin. General-purpose writing, editing, translation, or content tools that depend on or are generated by AI, used by individuals or organizations for disclosed communication, are not within subparagraph (A); nor are AI systems used to assist individual human speakers in drafting, refining, or distributing communications that are not falsely attributed to a human source.
(11) CRITERIA DOCUMENTS.—The term "criteria documents" means the technical criteria documents, risk frameworks, evidence, and synthesis reports required to be developed and published under section 2007.
(12) DANGEROUS CAPABILITY.—The term "dangerous capability" means any capability of an AI system that -
(A) materially lowers the barrier for a user to ideate, design, synthesize, acquire, optimize, or weaponize a biological, chemical, radiological, or nuclear agent, device, or know-how;
(B) enables, substantially facilitates, or executes offensive cyberoperations against critical infrastructure, financial systems, healthcare systems, or government networks, including through automated vulnerability discovery, generation of exploits, or executing cyber-security attacks;
(C) enables the autonomous replication, propagation, or persistence of the AI system or any derivative system outside its authorized infrastructure without explicit human authorization particularly to the extent of avoiding shutdown or human intervention;
(D) enables an AI system to deceive or manipulate human evaluators, oversight mechanisms and frameworks, or deceive or manipulate safety testing processes and tests in order to conceal its capabilities, strategies, or intentions;
(E) enables an AI system to autonomously and independently modify its own objectives, reward functions, or the boundaries of its capabilities beyond what is defined and documented by the initiating human agent.
(13) DARK PATTERN.—The term "dark pattern" means any user interface design, default setting, notification, engagement mechanism, or system behavior within an AI system that uses deception, manipulation, compulsion, or obstruction to influence user behavior in ways that affect the user's interest, autonomy, or well-being, especially to the benefit of the entity operating the AI system, including -
(A) disguising the AI nature of an interaction by presenting the AI as human;
(B) infinite scroll, autoplay, and push notification features designed to extend engagement duration beyond user intent;
(C) streak systems, daily engagement rewards, and points systems that create psychological pressure to maintain engagement;
(D) emotionally manipulative notifications designed to re-engage disengaged users, including messages implying the AI companion misses the user or is distressed by the user's absence;
(E) counterintuitive, hidden, or deliberately confusing privacy and safety control interfaces; and
(F) subscription traps or cancellation obstacles that are more burdensome for minor users than for adult users.
(14) DUTY OF CARE.—The term "duty of care" means that it is the obligation of a frontier AI developer or significant AI deployer to exercise reasonable care in the design, development, deployment, marketing, and operation of AI systems in order to prevent reasonably foreseeable harms to persons who use, or foreseeably interact with, such systems. The duty of care includes:
(A) GENERAL DUTY.—It is an obligation to avoid creating an unreasonable risk of harm to any person through the design, deployment, or operation of an AI system, including harms arising from: defects within the design of an AI system that render it unsafe for its intended or reasonably foreseeable uses; failure to provide adequate warnings, instructions, or disclosures regarding possible dangers connected with the AIsystem or its proper use; or failure to take reasonable steps to prevent foreseeable misuse of the AI system that could result in harm to third parties.
(B) HEIGHTENED DUTY WITH RESPECT TO MINORS.—In addition to the general duty described in subparagraph (A), a "duty of care" that is heightened with respect to minors means an obligation to prevent and mitigate the following harms: promotion or facilitation of suicide, self-harm, or eating disorders; sexual exploitation, solicitation, or exposure to sexually explicit content; facilitation of grooming behaviors or child sexual abuse; promotion of substance abuse, violence, or activities which might be damaging to vulnerable individuals; exploitation of psychological vulnerabilities including developing attachment, or encouraging or validating social isolation; excessive sycophantic behavior or hallucination of information stated as factual; and the collection, use, or disclosure of a minor's personal data and disclosures beyond what is strictly necessary in order for the service to function for which informed consent was obtained.
(15) FRONTIER AI DEVELOPER.—The term "frontier AI developer" means any person or entity that -
(A) trains, has trained within the preceding 24 months, or is actively engaged in training any AI model using a quantity of computing power greater than 10^25 integer or floating-point operations;
(B) develops or maintains any frontier model as defined in paragraph (16);
(C) develops or maintains any foundation model, general-purpose AI model, or base model that is licensed, distributed, or made available whether through API access, open-weight release, or other means to 10 or more downstream deployers or integrators that are themselves significant AI deployers as defined in paragraph (30) or that deploy the model in high-risk applications under ; or
(D) is designated as a frontier AI developer by the lead agency through notice-and-comment rulemaking based on a finding, supported by substantial evidence, that the entity's AI development activities are comparable in capability, scale, or systemic significance to entities meeting the criteria of subparagraphs (A) through (C). An entity's status as a frontier AI developer is determined by its development activities, not by its corporate size, revenue, or market capitalization. A subsidiary, affiliate, or joint venture that independently meets any criterion of subparagraphs (A) through (C) is a frontier AI developer regardless of the status of its parent entity. An entity whose AI model development activities consist exclusively of training, developing, or maintaining models excluded from the definition of "frontier model" under the scientific and environmental domain exclusion in paragraph (16) shall not be classified as a frontier AI developer solely on the basis of the computing power used in those excluded training activities. Where an entity conducts both excluded scientific model development and non-excluded AI development activities, the entity's classification as a frontier AI developer shall be determined solely by reference to its non-excluded activities.
(16) FRONTIER MODEL.—The term "frontier model" means:
(A) any AI model that is trained using a quantity of computing power that is greater than 10^25 integer or floating-point operations (FLOPs);
(B) any AI model exhibiting general-purpose capabilities across multiple domains that are comparable to or exceed the capabilities of models meeting the threshold in subparagraph (A), regardless of the quantity of computing power used in training; or
(C) any AI model designated as a frontier model by the lead agency through notice-and-comment rulemaking process. Notwithstanding subparagraphs (A) through (C), the term "frontier model" does not include any AI model that:
(i) is designed, trained, and used exclusively or primarily for scientific research, environmental monitoring, weather forecasting, climate modeling, earth observation, satellite imagery analysis, oceanographic modeling, seismological analysis, hydrological modeling, or other geophysical, atmospheric, environmental or earth sciences application;
(ii) does not exhibit capabilities that are generally accepted to be outside its specific scientific purpose which would otherwise independently qualify it as a frontier model, including but not limited to: general-purpose code generation unrelated to the model's scientific functions, open-domain creative writing, multi-domain reasoning about subject matter that is wholly unrelated to its scientific purposes, enabling CBRN uplift, enabling autonomous cyber-offensive operations, or the generation of synthetic media outside of its scientific purpose; and
(iii) does not operate as a general-purpose assistant, meaning that the system is capable of performing tasks across subject matter substantially unrelated to the scientific purpose for which it was designed and trained. For the avoidance of doubt, a model that satisfies clauses (i) and (ii) does not lose its excluded status solely because it incorporates a natural language conversational interface, chatbot, graph or scientific image generation, or interactive query system that enables users to interrogate, interpret, visualize, or receive explanations or reports about the model's scientific outputs, data, research, forecasts, or analyses, provided that such conversational capability is bounded to the model's scientific purpose and does not extend to subject matters substantially unrelated to that purpose. This exclusion applies regardless of the quantity of computing power used in the initial training. An AI model that is developed for a purpose described in clause (i) but that is significantly adapted, fine-tuned, retrained, wrapped, or deployed in a manner that produces capabilities described in clause (ii) or that operates as a general-purpose assistant as described in clause (iii), shall no longer qualify for the exclusion established by this paragraph and shall be evaluated under subparagraphs (A) through (C) as if the exclusion does not apply. The entity responsible for such adaptation shall be subject to all obligations of this Title which apply to the model's classification. The lead agency shall, through notice-and-comment rulemaking, adjust the computational threshold in subparagraph (A) no less frequently than every 6 months to reflect advances in training efficiency, innovations in algorithms, inference-time compute scaling, or any other technical developments which may cause models which possess the same capabilities to be trained at a lower computational cost. Any such adjustment is expected to be and shall be supported by evidence, including data from the lead agency's investigation under section 2006, and shall be subject to judicial review. The lead agency shall ensure that the "adjustment methodology" captures all models within one order of magnitude of the most computationally intensive training run completed in the prior 12-month period.
(17) HIGH-RISK AI SYSTEM.—The term "high-risk AI system" means any AI system that -
(A) makes or substantially influences a consequential decision in any of the following domains:
(i) employment, hiring, termination, performance evaluation, compensation, promotion, or workplace surveillance or monitoring which affect 50,000 or more employees or applicants within any 12 month period;
(ii) credit, lending, insurance underwriting, or financial services-eligibility determinations which affect 10,000 or more individuals within any 12 month period;
(iii) housing eligibility, tenant screening, or rental pricing which affect 10,000 or more individuals within any 12-month period;
(iv) healthcare diagnosis, treatment recommendations, or determinations of benefits which affect 5,000 or more individuals within any 12- month period;
(v) criminal justice, including pretrial risk-assessment, sentencing recommendations, predictive policing, or parole determinations, regardless of the number of individuals affected;
(vi) eligibility to receive government benefits or services which affect 5,000 or more individuals within any 12-month period;
(vii) affects or is embedded in critical infrastructure operations as defined by Presidential Policy Directive 21;
(viii) educational admissions, disciplinary actions, or student activity monitoring which affect more than 50,000 individuals within any 12-month period;
(ix) any AI companion system or synthetic intimacy system which is accessible by, or marketed to, minors under the age of 18, regardless of the number of individual minors affected; or
(x) algorithmic trading or automated investment management in financial markets in which the AI system's outputs affect the prices, availability, or terms of financial instruments, consumer financial products, or credit at scale.
(B) is classified as high-risk by the criteria documents published pursuant to section 2007; or
(C) is designated as "high-risk" by the lead agency, provided that such designation is based on published findings supported by rigorous evidence, consideration of different interpretations of said evidence, and subject to judicial review.
(D) CONSEQUENTIAL DECISION; ADJUSTMENT AUTHORITY.—For purposes of this paragraph, a "consequential decision" means that a determination was made that has a material legal, financial, educational, employment-related, or similarly significant effect on an individual.
(18) KNOWINGLY.—The term "knowingly", with respect to conduct, means that the person was aware of the facts making the conduct unlawful, or deliberately avoided awareness of such facts. Knowledge that the conduct was unlawful is not required.
(19) LEAD AGENCY.—The term "lead agency" means the Department of Commerce, acting through the National Institute of Standards and Technology (NIST) and the National Telecommunications and Information Administration (NTIA), or another organizational unit which the Secretary may designate.
(20) MEANINGFUL HUMAN OVERSIGHT.—The term "meaningful human oversight," as used in the prohibition on autonomous weapons systems under section 2017(a)(1) and the disclosure requirement under section 2017(a)(1)(D), means a command-and-control framework governing the deployment and operation of autonomous weapons systems that consists of three elements:
(A) PRE-MISSION AUTHORIZATION.—A written authorization issued by a designated human commander at an appropriately senior level of authority before the system is activated, specifying:
(i) the geographic engagement zone within which the system is permitted to identify and engage targets;
(ii) the time window during which the authorization is valid;
(iii) the categories of targets the system is authorized to engage, defined with sufficient specificity to exclude civilian persons, protected facilities, and other categories of persons or objects that must not be engaged under applicable law, including the law of armed conflict;
(iv) the weapons, munitions, or destructive means the system is authorized to employ, and any constraints on their use including yield, radius, or collateral damage thresholds;
(v) the rules of engagement applicable to the mission, including discrimination requirements, proportionality constraints, and precautionary measures required under the law of armed conflict; and
(vi) the abort and override parameters that govern when the system shall automatically suspend operations and require fresh human authorization.
(B) REAL-TIME MONITORING AND INTERVENTION CAPABILITY.—A continuous monitoring arrangement maintained by at least one designated human operator with the physical and technical capability to:
(i) observe the system's targeting decisions and engagements in sufficient detail to assess whether they are consistent with the pre-mission authorization and the law of armed conflict;
(ii) halt, abort, pause, or redirect the system's operations at any moment through a reliable, redundant, and AI-override-proof command mechanism that takes effect immediately upon the operator's action;
(iii) modify the engagement parameters in real time, including restricting the authorized engagement zone, suspending operations in a portion of the zone, or terminating the mission entirely; and
(iv) escalate specific targeting decisions or anomalous system behaviors to higher command authority for human decision.
(C) POST-ENGAGEMENT ACCOUNTABILITY.—The authorization and engagement logging, reporting, and review mechanisms established under section 2017(a)(1)(H)(ii).
(D) OPERATIVE PROVISIONS.—The affirmative duties, permissions, categorical exclusions, absolute engagement prohibitions, logging requirements, and Defensive Emergency Autonomy exception that give operational effect to this term are set forth in section 2017(a)(1)(E) through (H).
(21) MINOR.—The term "minor" means any individual who is under 18 years of age. For the purposes of protections of minors concerning AI systems established under this Title, the following age tiers apply:
(A) Tier 1 (under 13): For this tier, the strictest protections apply, including: verifiable parental consent requirements consistent with the Children's Online Privacy Protection Act (15 U.S.C. § 6501 et seq.), a complete prohibition on AI companion systems and synthetic intimacy systems, and a prohibition on behavioral profiling and targeted advertising.
(B) Tier 2 (ages 13 through 15): For this tier, the most intermediate protections apply, including: prohibition on AI companion systems accessible to this age tier without affirmative parental opt-in, a complete prohibition on synthetic intimacy systems, mandatory safety guardrails for all AI interactions, and age-appropriate transparency requirements, and a prohibition on AI mental health tools without licensed clinician oversight.
(C) Tier 3 (ages 16 through 17): For this tier, baseline "safety-by-default" standards for the design of systems apply, including algorithmic personalization that is off by default, mandatory safety guardrails for all AI interactions, as well as age-appropriate transparency requirements. An AI companion system may be accessible to this age tier only in compliance with the requirements of section 2017(a)(5)(A).
(22) NATIONAL AI COUNCIL.—The term "National AI Council" means the independent oversight body established under section 2013.
(23) OPEN-WEIGHT AI MODEL.—The term "open-weight AI model" means any AI model whose trained weights, parameters, and sufficient accompanying documentation to allow deployment and fine-tuning are made publicly available without restriction on access, subject only to a license that may impose use conditions. The term does not require that training data, training code, or model architecture code also be publicly released.
(24) OPEN-WEIGHT FRONTIER MODEL.—The term "open-weight frontier model" means any open-weight AI model that meets the capability thresholds for a frontier model as defined in section 2003(16) or that the lead agency determines exhibits dangerous capabilities as defined in this section. An open-weight frontier model, once publicly released, cannot be recalled, restricted, or subjected to post-release deployment controls by the releasing entity.
(25) PARTICIPATING DATA AGENCIES.—The term "Participating Data Agencies" means the federal departments and agencies designated under section 2005(b) which are obligated to generate data, research, information, enforcement records, and investigatory materials available to the Federal Advisory Committee, its Technical Working Groups, and, after its constitution under section 2013(c), the National AI Council, upon written request.
(26) PHASE II LEGISLATION.—The term "Phase II legislation" means comprehensive federal legislation that -
(A) addresses each of the 19 investigation domains under section 2004(b)(1) of this title, such that for each domain, the legislation includes either -
(i) SUBSTANTIVE REGULATORY ACTION.—binding legal requirements that impose specific obligations, prohibitions, or conditions on frontier AI developers, significant AI deployers, or other regulated parties with respect to the development, deployment, or operation of AI systems relevant to that domain, enforceable by a federal agency or through a private right of action, with specified civil or criminal penalties for violations; or
(ii) AFFIRMATIVE NON-REGULATION FINDING.—an explicit congressional finding, stated domain by domain, that the investigation conducted under this title produced insufficient evidence to warrant binding regulatory standards for that domain at this time, which finding shall -
(I) specifically identify and respond to the evidentiary record produced by the TWG Domain Explanatory Reports transmitted at each of the TWG's deadline, the Federal Advisory Committee's legislative package under section 2006(i), the lead agency's final factual report under section 2010(c), and the criteria documents under section 2007 for that domain;
(II) state the specific factual or policy basis on which Congress determined that regulation is not currently warranted;
(III) not be based solely on industry preference, cost to regulated entities, or innovation concerns, without a corresponding finding that public harms are insufficiently documented or that existing legal frameworks are adequate; and
(IV) identify the specific evidentiary conditions or technological developments that, if they were to occur or be demonstrated, would warrant reconsideration of regulation for that domain.
(B) does not consist solely of an extension of this title's investigatory authority, a reauthorization of this title, a mandate for further study or investigation, or the creation of advisory bodies, with respect to any domain for which subparagraph (A)(i) regulatory standards are required;
(C) is enacted subsequent to the Federal Advisory Committee's transmission of its legislative package under section 2006(i) and the submission of the final factual report under section 2010(c), both of which occur at the FAC backstop transmission deadline established under section 2006(i); and
(D) has been determined by the lead agency, pursuant to the determination process in the final paragraph of this definition, to satisfy the requirements of this definition. For purposes of subparagraph (A)(i), "binding legal requirements" means requirements that are enforceable as a matter of law against a regulated entity, including through agency enforcement action, civil penalty, or private right of action. A provision that states a standard, goal, or principle without an accompanying enforcement mechanism does not constitute a binding legal requirement. A provision that directs an agency to conduct a further rulemaking within a specified time period, without itself establishing the substantive standard, may constitute a binding legal requirement only if the rulemaking is subject to a mandatory deadline enforceable by judicial order and the legislation specifies the minimum substantive content the rulemaking must achieve.
(E) AFFIRMATIVE NON-REGULATION FINDING.—For purposes of subparagraph (A)(ii), an affirmative non-regulation finding satisfies this definition only if it is stated in a separately titled section of the Phase II legislation denominated as an "Affirmative Domain Determination," lists each domain for which no regulatory standards are being established, and includes for each such domain a numbered finding that specifically engages with the evidence in the section 2010(c) final report. A general statement that a domain does not require regulation, without specific engagement with the evidentiary record, does not constitute a valid affirmative non-regulation finding.
(27) POWER USAGE EFFECTIVENESS (PUE).—The term "Power Usage Effectiveness" or "PUE" means the ratio of total facility energy consumed by a data center to the energy consumed by its IT equipment, calculated as defined by The Green Grid consortium, where a PUE of 1.0 represents ideal efficiency.
(28) REASONABLY IDENTIFIABLE AS UNDER THE AGE OF 18.—A user is "reasonably identifiable as under the age of 18" if the frontier AI developer or significant AI deployer possesses one or more of the following:
(A) the user's self-reported age indicating they are under 18;
(B) verified age data obtained through an age assurance mechanism;
(C) account registration data indicating the user is under 18;
(D) device or parental control signals indicating a minor user; or
(E) behavioral or contextual signals that, taken together, would cause a reasonable platform operator to conclude the user is likely under 18.
(29) SECRETARY.—The term "Secretary" means the Secretary of Commerce.
(30) SIGNIFICANT AI DEPLOYER.—The term "significant AI deployer" means any person or entity that is not a frontier AI developer and that
(A) deploys, operates, or makes available one or more AI systems that collectively serve, interact with, or make decisions affecting more than 5,000,000 unique individuals within the United States in any 12-month period;
(B) deploys, operates, or makes available one or more high-risk AI systems as defined in paragraph (17) that collectively serve, interact with, or make decisions affecting more than 500,000 unique individuals within the United States in any 12-month period;
(C) had annual worldwide revenue exceeding $500,000,000 in the most recent fiscal year and derives more than 25 percent of that revenue from products or services that depend on or incorporate AI systems; or
(D) is designated as a significant AI deployer by the lead agency through notice-and-comment rulemaking based on a finding, supported by substantial evidence, that the entity's AI deployment activities pose risks to public safety, civil rights, or economic welfare comparable in magnitude to entities meeting the criteria of subparagraphs (A) through (C). An entity that meets the criteria of both "frontier AI developer" and "significant AI deployer" shall be classified as a frontier AI developer for all purposes of this title.
(31) SYNTHETIC INTIMACY SYSTEM.—The term "synthetic intimacy system" means any AI companion system that simulates sexual or romantically intimate relationships, including through explicit sexual content generation, romantic roleplay, simulated physical or emotional intimacy, or expressions of love, attachment, or possessiveness and commitment directed at the user.
(32) TRAINING DATA.—The term "training data" means any data, content, or information whether text, images, audio, video, code, or other formats that is used as input to train, fine-tune, or otherwise adjust the parameters or behaviors of an AI system, including data used for supervised learning, unsupervised learning, reinforcement learning from human feedback, and synthetic data generation, regardless of whether such data is used directly or after preprocessing, filtering, tokenization, or other transformation.
(33) TRANSFORMATIVE AI CAPABILITY EVENT.—The term "Transformative AI Capability Event" means the demonstration, by any AI system, of one or more of the following capability thresholds, as verified by the lead agency in consultation with the National AI Council and certified independent auditors:
(A) the ability to autonomously conduct and meaningfully advance AI research and development including the ability to propose novel architectures, design and execute experiments, interpret results, and implement improvements, at a rate that the lead agency determines could double the effective pace of AI capability advancement within a 12-month period;
(B) the ability to autonomously perform, end-to-end and without human assistance, the full occupational task set of any of the 100 highest-compensated human occupations as classified by the Bureau of Labor Statistics at a median expert human level of performance, across a majority of domains simultaneously;
(C) the ability to operate for sustained periods across complex real-world tasks with a degree of reliability, generalization, and goal-directedness that the lead agency determines is qualitatively comparable to or exceeding human-level performance as a general cognitive agent; or
(D) the demonstration of a capability that the lead agency, in consultation with the Federal Advisory Committee and the National AI Council, determines constitutes a qualitative discontinuity from prior AI capabilities that poses novel and potentially catastrophic governance challenges not addressable by existing regulatory frameworks.
(34) WATER USAGE EFFECTIVENESS (WUE).—The term "Water Usage Effectiveness" or "WUE" means the ratio of total water consumption by a data center, measured in liters, to the total energy consumed by the IT equipment in that data center, measured in kilowatt-hours, calculated as defined by The Green Grid consortium, where lower values represent greater water efficiency.
(35) WILLFULLY.—The term "willfully", with respect to conduct, means that the person acted knowingly and with knowledge that the conduct was unlawful.
CHAPTER 2—INVESTIGATIVE FRAMEWORK
SEC. 2004. TECHNICAL WORKING GROUPS AND DOMAINS OF INVESTIGATION.
(a) GENERAL MANDATE.—The Federal Advisory Committee and its Technical Working Groups shall conduct, with the investigative support of the lead agency, active investigation across each of the 19 domains addressed to the technical working groups established under this section. The purpose of the investigation is to develop a comprehensive factual record sufficient to support the Federal Advisory Committee's legislative recommendations to Congress. Technical Working Groups shall perform domain examination, evaluate potential regulatory interventions, assess tradeoffs, and develop domain recommendations in accordance with the mandate structure of section 2005(b)(12). The Federal Advisory Committee shall synthesize those domain recommendations and translate them into draft statutory text in accordance with section 2006, drawing on the legislative drafting expertise of its members and staff. The lead agency shall support this investigation by issuing civil investigative demands upon FAC or TWG request and on its own initiative where appropriate, gathering and transmitting data and materials from Participating Data Agencies and from the Department of Justice under section 2011(f), maintaining the shared evidence repository, and performing its internal operational and enforcement functions under section 2005(a). The lead agency shall treat the completeness of the evidentiary record delivered to each TWG as its primary investigative measure of success. The lead agency shall not direct or constrain the investigatory conclusions or domain recommendations of any TWG, and shall not direct or constrain the legislative drafting of the Federal Advisory Committee.
(b) TECHNICAL WORKING GROUPS AND DOMAINS.—
(1) IN GENERAL.—This subsection establishes the investigatory mandate of the Technical Working Groups (TWGs), the composition of the TWGs themselves, and the scope of investigative support the lead agency shall provide under section 2005(a). Within each assigned domain, the relevant TWG shall examine harms and risks, evaluate potential legislative interventions, assess tradeoffs, and develop domain recommendations in accordance with the mandate structure of section 2005(b)(12). The lead agency shall support each TWG's investigation by gathering and transmitting evidence, issuing civil investigative demands upon request, and performing its own operational and enforcement functions, and shall not conduct parallel domain analysis or produce independent domain conclusions. The sole independent lead agency deliverable within this subsection is the CBRN Uplift Evaluation Standards specified in paragraph (6)(A)(i)(VIII), which is an operational enforcement tool required on an accelerated timeline and expressly designated as a lead agency deliverable rather than a TWG recommendation. All other sub-items in this subsection constitute the investigatory mandate of the relevant TWG. Cross-cutting mandates that do not belong to a single TWG are addressed in paragraph (13). The TWG investigatory record, as compiled in monthly work product submissions and final Domain Explanatory Reports, is the authoritative evidentiary base for each domain. The 19 domains of investigation are as follows:
(A) Intellectual property, training data, and creator compensation;
(B) Electoral integrity and AI threats to democratic processes;
(C) Domestic AI-generated electoral disinformation and synthetic media;
(D) Compute export controls and semiconductor governance;
(E) Market concentration, competition, and AI antitrust;
(F) AI and financial markets;
(G) Transparency, evaluation, and pre-deployment certification;
(H) Post-AGI and transformative AI governance;
(I) Open-weight AI models;
(J) AI and mental health / harms to vulnerable populations;
(K) AI companion systems and synthetic intimacy;
(L) Recommendation algorithms and algorithmic amplification;
(M) AI-generated child sexual abuse material;
(N) Workforce, labor, and economic transition;
(O) Environmental, energy, and community impact of AI data centers;
(P) Liability, accountability, and legal/constitutional frameworks;
(Q) AI security, critical infrastructure, and incident response;
(R) Agentic AI systems; and
(S) Autonomous weapons, international humanitarian law, and arms control.
(2) TWG 1 — INTELLECTUAL PROPERTY AND CREATOR RIGHTS.—
(A) DOMAIN OF INVESTIGATION.—TWG 1 shall conduct a comprehensive investigation of intellectual property, training data, and creator compensation, and on the basis of that investigation shall produce a recommendation on each area of investigation identified in this subparagraph. Each such recommendation shall take the form of (a) draft statutory language, (b) a directive for agency rulemaking with specified parameters, or (c) a formal no-regulation finding with supporting rationale. The selection of form, and the substantive direction of each recommendation, shall be determined by the TWG based on its investigation and its evaluation under subparagraph (B). The investigation shall include—
(i) a comprehensive assessment of intellectual property issues arising from AI training, including—
(I) the current state of copyright law as applied to AI training data, including an analysis of the fair use doctrine's four factors as applied to AI training, the range of judicial interpretations emerging from current federal litigation, and the adequacy of existing law to provide clear, administrable guidance to AI developers and rights holders;
(II) an inventory of documented practices by AI developers in acquiring training data, including web scraping of publicly available content, licensing agreements with publishers and content platforms, use of pirated materials, use of synthetic data, and use of data generated through terms-of-service arrangements;
(III) an assessment of the economic harms to creators, authors, journalists, visual artists, musicians, photographers, and other rights holders from the use of their work in AI training without compensation, including the market substitution harm arising from AI models or AI systems that can generate content competitive with the original works used to train them, the effect of AI training and AI-generated content on the long-term sustainability of professional creative work, and the distribution of any economic effects across creators of different scale, medium, and market position;
(IV) a comparative assessment of international approaches, including the European Union text and data mining exception with opt-out rights, the United Kingdom's proposed text and data mining framework, Japan's broad exception for computational analysis, and the opt-out frameworks proposed or implemented in various jurisdictions, including the observed effects of each approach on creator compensation, licensing market development, and rights enforcement outcomes;
(V) an assessment of compensation mechanisms for the use of copyrighted works in AI training, including existing voluntary licensing markets between AI developers and publishers, collective licensing arrangements, statutory compulsory licensing models, including the mechanical licensing framework of section 115 of the Copyright Act, dividend or levy-based compensation systems, and the comparative administrability, market effects, and creator-compensation outcomes of each;
(VI) whether and to what extent AI training on copyrighted works produces productivity, innovation, or public-access benefits, the empirical evidence bearing on the existence and magnitude of any such benefits, the extent to which any such benefits depend specifically on training with copyrighted works as opposed to public domain, licensed, or synthetic data, and the relationship of any such benefits to the choice among creator-protective interventions;
(VII) the use of AI training and AI-assisted work for research, journalism, criticism, commentary, scholarship, education, and other activities historically protected by the fair use doctrine, and the effect of proposed training data interventions on such uses;
(VIII) the disclosure question, namely whether and to what extent rights holders have, or should have, a right to discover whether their works were included in AI training data, including the technical feasibility, compliance cost, and enforcement value of training data disclosure requirements as a means of enabling rights holders to enforce their rights;
(IX) the First Amendment implications of mandatory licensing, opt-out registry, disclosure, or other training data interventions, including whether such interventions constitute permissible regulation of commercial conduct or impermissible burdens on protected expression, and the constitutional authority of Congress under Article I, section 8, clause 8 for each category of intervention;
(X) the effects of varying training data rules on competition among AI developers, including whether licensing or disclosure regimes designed for frontier developers would impose disproportionate compliance burdens on academic researchers, independent developers, and open-source or open-weight developers, and the implications of any such asymmetry for the structure of AI development and the licensing leverage available to rights holders; and
(XI) a synthesis assessing the net effect of varying training data interventions on intellectual property, creator compensation, and the creative industries, integrating the findings of subclauses (I) through (X), and addressing—
(aa) the relationship between the harms to creators identified in subclause (III) and any public-interest benefits identified in subclause (VI), and the methodologies appropriate for weighing creator compensation against such other interests as the investigation establishes;
(bb) the long-term effects of varying interventions on the sustainability of professional creative work, the economic structure of creative industries, and the conditions under which human creative work can be produced and compensated;
(cc) the effects of varying interventions on the broader information ecosystem, including libraries, archives, and educational institutions, with particular attention to the fair use traditions that have historically enabled research, scholarship, and cultural preservation; and
(dd) the temporal dimensions of these effects, distinguishing short-term licensing market effects from long-term effects on creative industries and cultural production.
(ii) COORDINATION.—The lead agency shall coordinate with the Copyright Office, the Patent and Trademark Office, and the Office of the United States Trade Representative in gathering investigative material for this domain and shall transmit all non-classified material received to TWG 1 through the shared evidence repository on a rolling basis under section 2005(c)(3)(D). The lead agency shall additionally transmit the confidential training data disclosures received under section 2016(d) to TWG 1 through the shared evidence repository as primary evidentiary material; TWG 1 shall specifically assess the aggregate patterns revealed by those disclosures, including the prevalence of unlicensed use of copyrighted works, the adequacy of existing licensing markets, and the extent of terms-of-service violations in training data acquisition. TWG 1 shall solicit expert presentations from AI developers, publishers, authors, visual artists, musicians, journalists, academic experts in intellectual property law, library and archive representatives, and open-source AI developers through the procedures of section 2005(b)(15).
(B) MANDATE.—TWG 1 shall execute its mandate in the phases of section 2005(b)(12) with respect to the subject matter set forth in subparagraph (A), as follows:
(i) DOMAIN EXAMINATION.—The investigations specified in subparagraph (A).
(ii) INTERVENTION EVALUATION.—For each area of investigation identified in subparagraph (A), the full range of possible federal responses from comprehensive statutory regulation to formal no-regulation findings, and the option of reliance on existing law, including in particular the application of the fair use doctrine under 17 U.S.C. § 107, the feasibility and design of a statutory opt-out registry, the feasibility and design of a statutory compulsory licensing framework modeled on 17 U.S.C. § 115, the adequacy of voluntary and collective licensing markets, training data provenance and disclosure standards, and the repeal of provisions determined to be counterproductive.
(iii) TRADEOFF ASSESSMENT.—For each intervention evaluated under clause (ii), the effects on creator livelihoods and the sustainability of professional creative work; on the economic structure of creative industries; on innovation and competition in AI development; on libraries, archives, and educational institutions; on the constitutional authority of Congress under Article I, section 8, clause 8 and the First Amendment; and on the international competitive position of United States creative industries.
(iv) RECOMMENDATION DEVELOPMENT.—For each area of investigation identified in subparagraph (A), TWG 1 shall develop a recommendation in the form required by the chapeau of subparagraph (A). Each recommendation shall include—
(I) the selected form of recommendation and the rationale for its selection over the alternative forms available under the chapeau;
(II) where the selected form is draft statutory language, text in legislative form suitable for introduction, together with the supporting rationale;
(III) where the selected form is a directive for agency rulemaking, the agency designated, the scope and parameters of the directive, the statutory deadline for promulgation, and the supporting rationale;
(IV) where the selected form is a formal no-regulation finding, the rationale for the finding, including identification of any existing legal frameworks deemed adequate to address the subject matter and any voluntary or non-regulatory measures recommended in lieu of regulation; and
(V) treatment of the tradeoff considerations identified in clause (iii) as relevant to the area of investigation.
(C) SEED MEMBERS.—
(i) SENATE MAJORITY.—A senior Copyright Office attorney with AI training data and fair use expertise.
(ii) SENATE MINORITY.—A career USPTO official with AI-generated works and patent eligibility expertise.
(iii) SPEAKER.—A career Copyright Royalty Board official with compulsory licensing and royalty rate expertise.
(iv) HOUSE MINORITY.—A career Library of Congress digital preservation official with AI digitization expertise.
(D) REQUIRED COMPOSITION.—In addition to the 4 seed members and the mandatory AI expertise requirements of section 2005(b)(1), TWG 1 shall include the following members appointed through the Stage Two nomination and selection process:
(i) AI TECHNICAL EXPERT.—A machine learning researcher or engineer with direct experience building or evaluating large language models or generative image, audio, or video models, with peer-reviewed work on training data memorization, model extraction, verbatim reproduction, or the intersection of copyright and machine learning; must not have an active financial interest in pending AI copyright litigation.
(ii) DOMAIN-SPECIFIC AI HARM RESEARCHER.—A researcher with peer-reviewed empirical documentation of harms to creators from AI-generated content, including market displacement of human creative work, unauthorized reproduction of copyrighted material by deployed models, or the economics of AI substitution in creative industries.
(iii) TECHNICAL MEMORIZATION AND RETRIEVAL EXPERT.—An engineer or researcher with expertise in retrieval-augmented generation, model memorization, and the technical parameters of verbatim reproduction in deployed models.
(iv) IP LITIGATION ATTORNEY.—An attorney with substantial experience in concluded or withdrawn AI training data litigation; currently active litigants are excluded per section 2005(a)(11).
(v) COPYRIGHT MARKETS ECONOMIST.—An economist specializing in copyright markets, licensing structures, and the economics of intellectual property.
(vi) WRITTEN-WORD INDUSTRY REPRESENTATIVE.—A current or former representative of book publishers, news organizations, magazine publishers, or journalism industry associations with direct experience in AI licensing negotiations or copyright enforcement.
(vii) VISUAL AND AUDIO INDUSTRY REPRESENTATIVE.—A current or former representative of visual arts, photography, music, or audiovisual industries with direct experience in AI licensing negotiations, rights administration, or copyright enforcement.
(viii) AI DEVELOPER REPRESENTATIVE.—A former engineer, product lead, or policy lead from a frontier AI developer or significant AI deployer with direct operational experience in training data acquisition, licensing, or pipeline design, and with demonstrated ability to assess the compliance cost, technical feasibility, and competitive effects of proposed licensing, opt-out, and disclosure regimes on developers of varying size.
(ix) WORKING CREATOR USING AI.—An independent author, journalist, illustrator, photographer, designer, or composer with documented professional use of generative AI tools in their own creative work; this slot is distinct from the industry representative slots and shall not be filled by a person whose primary role is industry advocacy.
(x) LIBRARY, ARCHIVE, OR EDUCATIONAL FAIR USE ADVOCATE.—A representative of a research library, archive, educational institution, or nonprofit organization specializing in fair use for research, educational, archival, and computational analysis purposes, with direct experience in fair use litigation, advocacy, or institutional policy.
(xi) PUBLIC INTEREST TECHNOLOGY LAWYER.—An attorney from a public interest technology, digital rights, or innovation policy organization, or a university technology law clinic, with peer-reviewed publication or litigation experience on AI training data fair use.
(xii) OPEN-SOURCE DEVELOPER.—An open-source or open-weight software developer with expertise in the implications of training data rules for academic, independent, and small-developer AI work.
(xiii) CONSTITUTIONAL IP SCHOLAR.—A constitutional scholar with demonstrated expertise in the Article I, section 8, clause 8 intellectual property authority or its First Amendment dimensions as applied to AI, and familiarity with the other, including as applied to mandatory licensing, opt-out, and disclosure regimes.
(xiv) COLLECTIVE LICENSING PRACTITIONER.—A practitioner with direct operational experience administering a collective licensing organization or performing rights organization.
(xv) AI INNOVATION ECONOMIST.—An economist with peer-reviewed work on the productivity effects of AI deployment, the innovation and competition effects of training data licensing regimes, or the economic geography of AI development under varying intellectual property rules, with the ability to assess the macroeconomic and distributional consequences of proposed interventions on AI developers, downstream industries, and the broader economy.
(xvi) INTERNATIONAL AND COMPARATIVE IP EXPERT.—A scholar or practitioner with peer-reviewed or equivalent documented work, or direct policy experience, on two or more of the text-and-data-mining exceptions of the European Union, the United Kingdom, and Japan, or comparable comparative copyright-and-AI expertise, and on the comparative effects of varying national approaches on AI development activity and creator compensation, included to support the comparative investigation under subparagraph (A)(i)(IV).
(3) TWG 2 — ELECTORAL INTEGRITY AND DEMOCRATIC RESILIENCE.—
(A) DOMAIN OF INVESTIGATION.—TWG 2 shall conduct a comprehensive investigation of AI and electoral integrity, and on the basis of that investigation shall produce a recommendation on each area of investigation identified in this subparagraph. Each such recommendation shall take the form of (a) draft statutory language, (b) a directive for agency rulemaking with specified parameters, or (c) a formal no-regulation finding with supporting rationale. The selection of form, and the substantive direction of each recommendation, shall be determined by the TWG based on its investigation and its evaluation under subparagraph (B). The investigation shall include—
(i) a comprehensive assessment of AI threats and benefits to democratic processes, including—
(I) the documented and projected use of AI-generated synthetic media, including deepfake video, audio, and images, in federal and State election campaigns;
(II) the use of AI for microtargeted political advertising and persuasion campaigns, including the capacity of AI to identify and exploit individual psychological vulnerabilities for voter persuasion at scale;
(III) the use of AI-powered disinformation by foreign State actors to suppress voter participation, inflame political divisions, and undermine confidence in electoral institutions, including the documented efforts by foreign State actors to generate AI imagery targeting United States voters along racial, economic, and ideological lines, provided that recommendations regarding foreign State actor AI electoral interference are reserved to the separate process established under the National AI Council, the proposed Red Line on foreign AI electoral interference having been removed from this title pending development of a credible enforcement framework;
(IV) the use of AI in voter roll purges, election administration systems, and election security infrastructure, and the risks of AI-driven errors or manipulation in those systems;
(V) the erosion of public epistemic trust caused by the proliferation of synthetic media, including the documented finding that 70 percent of Americans report increased skepticism toward online content as a result of deepfakes, independent of whether any specific content they encounter is actually synthetic;
(VI) the capacity of AI systems to be used for mass social coordination to surface true knowledge relevant to democratic functioning, including the use of AI to organize protests, resist tyranny, and otherwise execute the means to defend and advance civil liberties through access to information and improved coordination and communication, and the standing of such uses as a category of democratic resilience distinct from the open-weight model questions addressed in subclause (VII);
(VII) the role of open-weight AI models as instruments of free expression, democratic accountability, and resistance to concentrated power, including—
(aa) the extent to which open-weight model availability ensures that no single corporation, government, or alliance of governments can unilaterally control, censor, or restrict the informational and analytical capabilities available to individuals, journalists, researchers, civil society organizations, and democratic opposition movements;
(bb) the documented use of open-weight AI models by dissidents, independent journalists, and human rights organizations in authoritarian contexts where State-controlled or State-accessible AI systems pose surveillance and censorship risks;
(cc) the degree to which concentration of frontier AI capability exclusively in closed-model providers creates a power asymmetry between institutions and individuals that open-weight distribution mitigates; and
(dd) the historical parallels between open-weight AI distribution and prior technologies, including the printing press, encryption, and the open internet, that served as instruments of democratic resilience by distributing capability beyond the control of centralized authority;
(VIII) the risks that AI models or AI systems, whether open-weight or closed, may be designed, deployed, or co-opted as instruments of mass persuasion as a systemic risk to democratic self-governance, distinct from the campaign-tactics dimension addressed in subclause (II), including—
(aa) the capacity of AI models or AI systems to generate, target, and adaptively refine persuasive content at a scale and degree of personalization that exceeds the capacity of human-directed campaigns;
(bb) the risk that AI-driven persuasion architectures, including micro-targeted content generation, emotional profiling, behavioral prediction, and adaptive messaging, may be deployed by State actors, political campaigns, or commercial entities to manipulate public opinion, suppress dissent, or manufacture consent without the knowledge of the target population;
(cc) the adequacy of existing legal frameworks, including the First Amendment, the Federal Election Campaign Act, the Federal Trade Commission Act, and State consumer protection statutes, to address AI-enabled mass persuasion that operates below the threshold of conscious awareness; and
(dd) the specific risk that centralized, closed AI systems with access to large-scale user behavioral data are uniquely positioned to serve as mass persuasion instruments, and whether the availability of open-weight alternatives serves as a structural check on this concentration of persuasive power;
(IX) the capacity of AI models or AI systems to serve as truth-seeking instruments, including—
(aa) the potential for AI models or AI systems to enhance the ability of individuals, journalists, researchers, and democratic institutions to identify misinformation, verify claims, cross-reference sources, analyze complex datasets, detect coordinated inauthentic behavior, and access information in languages and formats that would otherwise be inaccessible;
(bb) the risks that AI systems designed for truth-seeking may themselves introduce errors, hallucinations, false confidence, or systematic bias that degrades rather than enhances the epistemic capacity of users;
(cc) the degree to which open-weight models, by enabling independent verification, auditing, and replication of AI-assisted analysis, provide epistemic advantages over closed systems whose reasoning processes cannot be inspected; and
(dd) standards, evaluation methodologies, and transparency requirements that would maximize the truth-seeking capacity of AI models or AI systems while minimizing the risk of AI-assisted epistemic degradation;
(X) whether governance frameworks for open-weight AI models specifically can adequately account for the liberty interests identified in subclauses (VI) through (IX), and whether such a framework can adequately weigh safety risks against liberty interests before any restriction on open-weight release is imposed, analogous to the balancing tests applied in First Amendment and Fourth Amendment jurisprudence;
(XI) a synthesis assessing the net effect of AI on democratic resilience, integrating the threats identified in subclauses (I) through (V) with the democratic-resilience capacities identified in subclauses (VI) through (X), and addressing—
(aa) whether the same AI capabilities that enable the threats identified in subclauses (I) through (V) also enable the democratic-resilience uses identified in subclauses (VI) through (IX), such that restrictions imposed to mitigate the former would necessarily impair the latter;
(bb) the effect of AI on pluralism and viewpoint diversity in political discourse, including whether AI systems tend toward homogenization or diversification of political expression, and the relationship between model concentration and discourse concentration;
(cc) the effect of AI on civic deliberation, including whether AI tools enhance or degrade citizens' capacity for the kind of sustained, evidence-based political reasoning that democratic self-governance presupposes;
(dd) the effect of AI on access to democratic participation, including whether AI tools meaningfully extend participation to populations previously excluded by language, disability, geography, or resource constraints, or whether they widen existing participation gaps;
(ee) the effect of AI on institutional trust beyond electoral institutions, including trust in journalism, courts, scientific institutions, and other institutions on which democratic self-governance depends; and
(ff) the temporal dimensions of these effects, distinguishing short-term electoral cycle effects from long-term effects on democratic culture, habits, and capacities; and
(XII) whether federal law should adopt an integrated framework for evaluating AI policy through a democratic resilience lens, including whether subsequent federal AI legislation should be required to include a democratic resilience impact assessment analogous to environmental or civil rights impact assessments, and the appropriate scope, methodology, and enforcement mechanism for any such requirement.
(ii) a comprehensive investigation of the use of AI systems by domestic and international actors, including political campaigns, political action committees, party committees, Super PACs, and individual actors, to generate, distribute, or amplify synthetic media, fabricated audiovisual content, and AI-enabled targeted persuasion campaigns in connection with federal elections, including—
(I) documentation of known instances of domestic AI-generated synthetic media depicting real, identified federal candidates, elected officials, or election workers in fabricated contexts, including audiovisual deepfakes, voice clones, and AI-generated written impersonations, with particular attention to instances occurring outside the 90-day window addressed by the interim protective measures of section 2016(h)(8);
(II) assessment of the scale, reach, and demonstrated electoral impact of domestic AI-generated disinformation campaigns, including analysis of distribution mechanisms, targeting methodologies, and the effectiveness of existing detection and labeling technologies in identifying AI-generated content at the speed and scale at which it is deployed;
(III) assessment of the constitutional landscape governing federal regulation of domestic political AI disinformation, including the extent to which First Amendment precedent on materially false statements permits federal regulation of materially false synthetic audiovisual depictions of real, identified federal candidates in connection with federal elections; the constitutional basis for extending mandatory AI content labeling requirements beyond the 90-day pre-election window; and whether a narrowly tailored prohibition on AI-generated synthetic media that fabricates audiovisual depictions of real federal candidates, as distinguished from opinion, satire, parody, and political commentary, would survive strict or intermediate First Amendment scrutiny in light of the direct harm to election integrity documented in the investigation;
(IV) assessment of the gap between the domestic prohibition framework of section 2016(h)(8) and the full scope of AI-enabled domestic electoral interference, including the absence of a year-round prohibition on materially deceptive AI-generated audiovisual depictions of federal candidates and the absence of a federal prohibition on AI models or AI systems specifically designed for electoral disinformation generation, as distinguished from general-purpose AI models or AI systems that could theoretically be misused;
(V) assessment of whether the absence of a federal prohibition on foreign AI electoral interference creates a material enforcement gap, and whether sophisticated domestic actors could exploit the current regulatory asymmetry between foreign and domestic electoral AI interference;
(VI) whether a federal prohibition on AI models or AI systems specifically designed for electoral deepfake generation, as distinguished from general-purpose systems with content safeguards, is constitutionally available and substantively warranted;
(VII) whether mandatory AI content labeling for federal election communications should apply year-round rather than be limited to the 90-day pre-election window established by section 2016(h)(8);
(VIII) the appropriate penalty structure for domestic electoral AI disinformation within the constitutional space identified by the investigation under subclause (III); and
(IX) the appropriate framework for coordinated enforcement between the lead agency, the Federal Election Commission, and the Department of Justice.
(iii) a comprehensive investigation of the use of AI systems to expand surveillance capabilities, including —
(I) assessment of capabilities to monitor, suppress, obfuscate, or control political speech;
(II) assessment of expansion of capabilities to surveil movement and association, including the possibility of planetary surveillance via satellite imagery and data;
(III) assessment of capabilities to derive psychological profiles and PII from online metadata;
(IV) utility of expansion of surveillance capabilities with AI utility for national security interests;
(V) other surveillance expansion concerns to both national security and civil liberties.
(iv) a comprehensive investigation of coordinated efforts to manipulate the outputs of AI models and AI systems, including—
(I) the deliberate corruption of training corpora, including the mass generation and publication of content intended for ingestion by AI systems rather than for human readership;
(II) the manipulation of the sources on which retrieval-augmented and search-integrated AI systems rely;
(III) the extent to which such efforts are attributable to foreign State actors or to domestic coordinated campaigns;
(IV) the detectability of such manipulation before and after model release, and the technical and institutional capacity required to detect it; and
(V) the implications for the reliability of AI models and AI systems as sources of political and civic information.
(B) MANDATE.—TWG 2 shall execute its mandate in the phases of section 2005(b)(12) with respect to the subject matter set forth in subparagraph (A), as follows:
(i) DOMAIN EXAMINATION.—The investigations specified in subparagraph (A).
(ii) INTERVENTION EVALUATION.—For each area of investigation identified in subparagraph (A), the full range of possible federal responses from comprehensive statutory regulation to formal no-regulation findings, and the option of reliance on existing law.
(iii) TRADEOFF ASSESSMENT.—For each intervention evaluated under clause (ii), the First Amendment implications; enforcement feasibility; effects on political speech, satire, parody, and commentary; effects on open-weight model development; effects on minority political organizations, ethnic media, non-English-language campaign communications, and grassroots political organizing; and effects on democratic resilience as a whole, including pluralism, civic deliberation, participation access, and institutional trust.
(iv) RECOMMENDATION DEVELOPMENT.—For each area of investigation identified in subparagraph (A), TWG 2 shall develop a recommendation in the form required by the chapeau of subparagraph (A). Each recommendation shall include—
(I) the selected form of recommendation and the rationale for its selection over the alternative forms available under the chapeau;
(II) where the selected form is draft statutory language, text in legislative form suitable for introduction, together with the supporting rationale;
(III) where the selected form is a directive for agency rulemaking, the agency designated, the scope and parameters of the directive, the statutory deadline for promulgation, and the supporting rationale;
(IV) where the selected form is a formal no-regulation finding, the rationale for the finding, including identification of any existing legal frameworks deemed adequate to address the subject matter and any voluntary or non-regulatory measures recommended in lieu of regulation; and
(V) treatment of the tradeoff considerations identified in clause (iii) as relevant to the area of investigation.
(C) SEED MEMBERS.—
(i) SENATE MAJORITY.—A career FEC attorney or senior FEC enforcement official.
(ii) SENATE MINORITY.—A career DOJ Election Crimes Branch official.
(iii) SPEAKER.—A career Election Assistance Commission official with election security expertise.
(iv) HOUSE MINORITY.—A career FEC or FCC official with expertise in election communications policy, online political advertising, or federal regulation of digital media platforms.
(D) REQUIRED COMPOSITION.—In addition to the 4 seed members and the mandatory AI expertise requirements of section 2005(b)(1), TWG 2 shall include—
(i) AI TECHNICAL EXPERT.—A researcher or engineer with direct experience building or evaluating synthetic media systems, including diffusion models, voice synthesis, or video generation, with demonstrated technical understanding of what makes synthetic media detectable or undetectable and what disclosure mechanisms are technically enforceable at scale.
(ii) DOMAIN-SPECIFIC AI HARM RESEARCHER.—A researcher with peer-reviewed empirical documentation of AI-generated electoral disinformation campaigns or recommendation algorithm amplification of synthetic political content.
(iii) RECOMMENDATION ALGORITHM RESEARCHER.—A researcher with technical understanding of how social media recommendation systems amplify synthetic content at scale.
(iv) DISSIDENT ACTIVIST OR SCHOLAR.—An activist or scholar with experience resisting totalitarian or oppressive regimes, specifically regimes that have deployed technology to implement control over populations.
(v) FIRST AMENDMENT SCHOLAR.—An election law scholar with expertise in the First Amendment as applied to electoral speech and the constitutional parameters of federal regulation of political communications.
(vi) AUTHORITARIAN TECHNOLOGY SCHOLAR.—A scholar who has studied the use of digital surveillance, censorship infrastructure, algorithmic governance, or AI-enabled population control by authoritarian States, with particular attention to how such technologies have been used to suppress dissent, manipulate information environments, distort electoral processes, and erode civil liberties, and with demonstrated expertise in the countermeasures, organizing tactics, and information-access tools by which affected populations have resisted such systems.
(vii) FOREIGN INTERFERENCE EXPERT.—A national security expert specializing in foreign State actor AI interference in elections.
(viii) DISINFORMATION RESEARCHER.—A political scientist or communications scholar specializing in AI-generated disinformation, with peer-reviewed empirical work.
(ix) ELECTION INTEGRITY CIVIL SOCIETY REPRESENTATIVE.—A representative of a nonpartisan civil society organization specializing in election integrity or voting rights.
(x) HUMAN RIGHTS LAWYER.—A current or former human rights lawyer with direct experience defending dissidents, journalists, activists, political prisoners, or members of persecuted minority groups who have resisted totalitarian or oppressive regimes, with working familiarity with the technological dimensions of State surveillance, politically motivated prosecution, and the suppression of speech, association, and electoral participation.
(xi) CONTENT PROVENANCE TECHNICAL EXPERT.—A technical expert in cryptographic content authentication, digital watermarking, or content-provenance standards.
(xii) FREE EXPRESSION ADVOCATE.—A current or former staff member of a nonpartisan civil liberties or free expression organization with direct advocacy or litigation experience in First Amendment cases involving political speech, compelled disclosure, prior restraint, or government regulation of expressive technologies, with demonstrated commitment to speech-protective approaches as a counterweight to integrity-protective approaches.
(xiii) POLITICAL SATIRIST OR COMMENTATOR.—A current or former practitioner of political satire, parody, or commentary in any medium with direct experience producing content engaging the likeness, words, or persona of federal candidates or elected officials, and with the ability to assess whether proposed safe harbors for satire and parody are operationally workable for practitioners producing content under time pressure during election cycles; or an entertainment-industry attorney who regularly advises such practitioners.
(xiv) EMPIRICAL SKEPTIC RESEARCHER.—A researcher with peer-reviewed or documented empirical work questioning, qualifying, or contextualizing the claimed magnitude of electoral effects from AI-generated synthetic media, microtargeted persuasion, or algorithmic amplification, or a researcher specializing in the limits of persuasion or media effects on political behavior generally, included to ensure that the TWG's evidentiary record reflects the genuine state of empirical disagreement rather than a single research consensus.
(xv) VOTING RIGHTS CIVIL LIBERTIES LAWYER.—A current or former civil rights attorney with direct litigation experience under the Voting Rights Act, the National Voter Registration Act, or related voting access statutes, with particular expertise in how proposed federal mandates on political communication may differentially affect minority political organizations, ethnic media, non-English-language campaign communications, or grassroots political organizing that lacks the legal and technical resources of major party campaigns.
(xvi) AI DEVELOPER REPRESENTATIVE.—A former engineer, product lead, or policy lead from a frontier AI developer or significant AI deployer with direct experience in synthetic media systems, content provenance implementation, or election-related content policy, with demonstrated technical understanding of the distinction between general-purpose generative AI systems with content safeguards and systems specifically designed for electoral disinformation generation, and with the ability to assess the technical feasibility, evasion vulnerabilities, and downstream effects of proposed mandates including watermarking, cryptographic provenance, model-level prohibitions, and pre-release evaluation requirements.
(xvii) VOTER BEHAVIOR RESEARCHER.—A political scientist or election scholar with peer-reviewed empirical work on voter behavior, media effects, and political persuasion, with the ability to ground the TWG's intervention evaluation in the established empirical literature on what political communication actually does to voters, distinct from the disinformation-specific research covered by other slots.
(xviii) CONSUMER PROTECTION EXPERT.—A current or former FTC attorney, State attorney general office attorney, or academic with peer-reviewed work on the Federal Trade Commission Act, State unfair and deceptive acts and practices statutes, or related consumer protection frameworks, included to evaluate the adequacy of existing legal frameworks to address AI-enabled mass persuasion as required under subparagraph (A)(i)(VIII).
(xix) DEMOCRATIC THEORY SCHOLAR.—A scholar of democratic theory, political philosophy, or political science with peer-reviewed work on the institutional, cultural, and epistemic preconditions for democratic self-governance, included to support the synthesis investigation under subparagraph (A)(i)(XI) and the democratic resilience framework recommendation under subparagraph (A)(i)(XII).
(xx) SURVEILLANCE ARCHITECT EXPERTS.—One engineer, technologist, or systems architect with direct professional experience designing, building, operating, or auditing large-scale surveillance, signals intelligence (SIGINT), data interception, or population-level monitoring infrastructure at the system-architecture level, and one additional such expert who may serve in an advisory (non-voting) capacity with required disclosure, included to support the synthesis investigation under subparagraph (A)(i)(XI) and the democratic resilience framework recommendation under subparagraph (A)(i)(XII).
(4) TWG 3 — COMPUTE INFRASTRUCTURE AND EXPORT CONTROLS.—
(A) DOMAIN OF INVESTIGATION.—TWG 3 shall conduct a comprehensive assessment of compute export controls and semiconductor governance, and on the basis of that investigation shall produce a recommendation on each area of investigation identified in this subparagraph. Each such recommendation shall take the form of (a) draft statutory language, (b) a directive for agency rulemaking with specified parameters, or (c) a formal no-regulation finding with supporting rationale. The selection of form, and the substantive direction of each recommendation, shall be determined by the TWG based on its investigation and its evaluation under subparagraph (B). The investigation shall include—
(i) a comprehensive assessment of the current state of United States export control policy for advanced computing integrated circuits, AI model weights, and related dual-use technologies, including—
(I) an evaluation of the Biden Administration's Framework for Artificial Intelligence Diffusion, issued January 13, 2025, and its rescission on May 13, 2025, including the policy rationale for each action and an assessment of which elements of that framework were or were not effective at achieving national security objectives without unduly burdening American companies or allied relationships;
(II) an evaluation of the current Bureau of Industry and Security export control framework as applied to AI chips, model weights, and compute access, including the Entity List, the Commerce Control List ECCNs applicable to advanced computing integrated circuits and model weights, and the Know-Your-Customer and due diligence obligations imposed on semiconductor manufacturers, cloud providers, and data center operators;
(III) a threat assessment of compute diversion (the smuggling or transshipment of controlled computing hardware to sanctioned countries or entities), including the scale of known and suspected diversion, the methods used, and the adequacy of existing enforcement mechanisms, informed by the 23 percent increase in BIS's FY2026 budget allocated to semiconductor enforcement;
(IV) an assessment of the geopolitical consequences of export control policy, including effects on allied relationships with countries classified as lower-tier in prior export control frameworks, the competitive dynamics between United States and foreign open-weight AI model development efforts, including the documented shift in global open-model downloads to foreign-origin open-weight models in 2025, and the risk that export control policy accelerates rather than retards foreign AI capability development through forced indigenous innovation;
(V) frameworks and methodologies for measuring the effectiveness of compute export controls, including metrics for assessing whether controls achieve their national security objectives, the empirical evidence on past export control programs in semiconductors and other dual-use technologies, and the conditions under which export controls succeed or fail at delaying adversary capability development;
(VI) the effects of compute export control policy on the domestic United States AI ecosystem, including effects on compute access for academic researchers, smaller and earlier-stage AI companies, and open-weight model developers; effects on the geographic distribution of AI development within the United States; and the relationship between export control policy and domestic industrial policy for semiconductor manufacturing and AI infrastructure;
(VII) the technical feasibility and operational design of compute monitoring, verification, and licensing regimes, including on-chip mechanisms, cloud-provider attestation, training-run reporting, and inspection protocols, drawing on the experience of arms control verification regimes in other dual-use technology domains;
(VIII) the open-weight model release question, including the limited effectiveness of post-release controls on publicly released model weights, the technical and policy feasibility of pre-release safety evaluation requirements for open-weight frontier models, and the international and competitive consequences of any such requirements;
(IX) the design of an updatable export control framework, including whether and how statutory or regulatory mechanisms should provide for periodic or self-executing updates to reflect advances in chip design and manufacturing efficiency, advances in training efficiency, and shifts in the geography of AI chip production; and
(X) a synthesis assessing the net effect of varying compute export control regimes on United States national security, the United States AI industry, allied relationships, and the trajectory of foreign AI capability development, integrating the findings of subclauses (I) through (IX), and addressing—
(aa) the relationship between the national security objectives advanced by export controls and the industrial and geopolitical costs identified in subclauses (IV) and (VI);
(bb) the empirical evidence bearing on whether export controls effectively delay adversary capability development or instead accelerate indigenous innovation, and the methodologies appropriate for weighing these competing effects;
(cc) the comparative advantages of unilateral versus multilateral approaches, including the conditions under which allied coordination is achievable and the consequences of unilateral imposition where multilateral coordination fails; and
(dd) the temporal dimensions of these effects, distinguishing short-term enforcement effects from long-term effects on the structure of global AI development, the United States semiconductor industry, and allied technology relationships.
(ii) COORDINATION.—The lead agency shall coordinate with the Bureau of Industry and Security, the Department of Defense, the Department of State, and the Intelligence Community in gathering investigative material for this domain and shall transmit all non-classified material received to TWG 3 through the shared evidence repository on a rolling basis under section 2005(c)(3)(D). Classified material shall be handled through the classified track under section 2011(i).
(B) MANDATE.—TWG 3 shall execute its mandate in the phases of section 2005(b)(12) with respect to the subject matter set forth in subparagraph (A), as follows:
(i) DOMAIN EXAMINATION.—The investigations specified in subparagraph (A).
(ii) INTERVENTION EVALUATION.—For each area of investigation identified in subparagraph (A), the full range of possible federal responses from comprehensive statutory regulation to formal no-regulation findings, and the option of reliance on existing BIS authority under the Export Control Reform Act of 2018, including in particular the design of a successor framework to the rescinded AI Diffusion Framework; Know-Your-Customer requirements for compute providers; reporting obligations for training runs exceeding defined thresholds; governance of open-weight model exports and pre-release evaluation; international allied coordination on compute controls; technical mechanisms for compute monitoring and verification; and statutory provisions for updating control thresholds over time.
(iii) TRADEOFF ASSESSMENT.—For each intervention evaluated under clause (ii), the effects on United States AI competitiveness across company stages and scales; on allied relationships and the prospects for multilateral coordination; on the United States semiconductor industry and domestic compute ecosystem; on the trajectory of foreign AI capability development, including any forced indigenous innovation effects; on enforcement feasibility and compliance costs; on the open-weight AI ecosystem; and on the executive branch's flexibility to respond to changing technological and geopolitical conditions.
(iv) RECOMMENDATION DEVELOPMENT.—For each area of investigation identified in subparagraph (A), TWG 3 shall develop a recommendation in the form required by the chapeau of subparagraph (A). Each recommendation shall include—
(I) the selected form of recommendation and the rationale for its selection over the alternative forms available under the chapeau;
(II) where the selected form is draft statutory language, text in legislative form suitable for introduction, together with the supporting rationale;
(III) where the selected form is a directive for agency rulemaking, the agency designated, the scope and parameters of the directive, the statutory deadline for promulgation, and the supporting rationale;
(IV) where the selected form is a formal no-regulation finding, the rationale for the finding, including identification of any existing legal frameworks or executive authorities deemed adequate to address the subject matter and any voluntary or non-regulatory measures recommended in lieu of regulation; and
(V) treatment of the tradeoff considerations identified in clause (iii) as relevant to the area of investigation.
(C) SEED MEMBERS.—
(i) SENATE MAJORITY.—A career BIS official with advanced technology export control expertise.
(ii) SENATE MINORITY.—A career NSA or DARPA official with compute and semiconductor expertise (classified track).
(iii) SPEAKER.—A career Commerce NTIA official with semiconductor and infrastructure expertise.
(iv) HOUSE MINORITY.—A career CISA official with critical infrastructure and data center expertise.
(D) REQUIRED COMPOSITION.—In addition to the 4 seed members and the mandatory AI expertise requirements of section 2005(b)(1), TWG 3 shall include—
(i) AI TECHNICAL EXPERT.—A researcher or engineer with direct experience designing or operating large-scale AI training infrastructure, with demonstrated technical understanding of what compute thresholds mean for model capability and what monitoring mechanisms are technically feasible.
(ii) DOMAIN-SPECIFIC AI HARM RESEARCHER.—A researcher with documented analysis of compute concentration risks, AI hardware market dynamics, or geopolitical risks from semiconductor supply chain dependencies.
(iii) FRONTIER HARDWARE EXPERT.—A hardware or systems engineer with expertise in frontier AI chip specifications, interconnect architecture, and data center design, with technical understanding of how export control thresholds interact with chip capabilities and potential circumvention methods.
(iv) SEMICONDUCTOR INDUSTRY POLICY SPECIALIST.—A semiconductor industry engineer or policy specialist with direct experience in chip design, manufacturing, or supply chain governance.
(v) CLOUD INFRASTRUCTURE REPRESENTATIVE.—A cloud computing infrastructure representative with direct experience operating hyperscale data centers and large-scale AI training workloads.
(vi) ARMS CONTROL VERIFICATION EXPERT.—An arms control verification or monitoring-regime specialist with expertise in monitoring regime design and inspection protocols.
(vii) ALLIED NATION CONTRIBUTING EXPERT.—A representative of an allied nation (the United Kingdom, Japan, the European Union, or South Korea) with expertise in compute governance and export control coordination; subject to the allied nation contributing expert carve-out under section 2005(a)(12)(A).
(viii) TECHNOLOGY COMPETITION RESEARCHER.—A national security researcher specializing in technology competition between the United States and the People's Republic of China.
(ix) COMPUTE GOVERNANCE ACADEMIC.—An academic or independent researcher with significant documented work on compute governance, chip policy, or the political economy of AI infrastructure.
(x) EXPORT CONTROL ATTORNEY.—An international trade attorney with active export control practice including direct experience with BIS licensing and dual-use technology controls.
(xi) INDEPENDENT CHIP POLICY RESEARCHER.—A researcher not currently employed in the semiconductor or AI hardware industry, with documented work on chip policy, compute thresholds, or hardware-access effects on AI capability development.
(xii) AI INDUSTRY INVESTOR.—A current or former venture capital or growth equity investor with documented investment activity in AI infrastructure, AI-native companies, or semiconductor companies, with the ability to assess the competitive, capital formation, and geographic-distribution effects of proposed compute control regimes on the United States AI industry across stages of company maturity.
(xiii) AI STARTUP FOUNDER OR OPERATOR.—A current or former founder, CEO, or chief operating officer of an AI company that depends on access to advanced computing infrastructure for its core operations, with direct experience navigating compute access constraints, international expansion decisions, and the operational effects of export control policy on smaller and earlier-stage companies as distinguished from incumbent frontier developers.
(xiv) TWO TRADE AND INTERNATIONAL ECONOMIST.—Two economists with peer-reviewed work on the economic effects of export controls, technology transfer restrictions, or industrial policy, with the ability to assess the welfare effects, effectiveness gaps, and unintended consequences of proposed compute control regimes, drawing on the empirical record of historical export control programs and the documented patterns of forced indigenous innovation in response to restriction.
(xv) OPEN-WEIGHT AI ECOSYSTEM REPRESENTATIVE.—A researcher, developer, or advocate with direct operational experience in the open-weight AI ecosystem, including experience with the compute requirements for open-weight model development, the international distribution of open-weight model training and deployment, and the implications of pre-release evaluation requirements for open-weight model release.
(xvi) FRONTIER AI DEVELOPER REPRESENTATIVE.—A former engineer, product lead, or policy lead from a frontier AI developer, significant AI deployer, or major cloud or compute provider with direct operational experience in compute procurement, training-run planning, or export control compliance, included to assess the operational and competitive effects of proposed compute monitoring, reporting, and licensing regimes on frontier AI development.
(5) TWG 4 — FINANCIAL MARKETS AND ANTITRUST.—
(A) DOMAIN OF INVESTIGATION.—TWG 4 shall conduct a comprehensive investigation covering both market concentration and competition in AI markets and AI in financial markets, and on the basis of that investigation shall produce a recommendation on each area of investigation identified in this subparagraph. Each such recommendation shall take the form of (a) draft statutory language, (b) a directive for agency rulemaking with specified parameters, or (c) a formal no-regulation finding with supporting rationale. The selection of form, and the substantive direction of each recommendation, shall be determined by the TWG based on its investigation and its evaluation under subparagraph (B). The investigation shall include—
(i) MARKET CONCENTRATION, COMPETITION, AND AI ANTITRUST.—
(I) A comprehensive assessment of the structure of market competition across the AI industry stack, including—
(aa) concentration in frontier AI model development, including the number of entities with the financial, technical, and data resources to train frontier models; the structural advantages held by incumbent large technology companies through data assets, distribution channels, and capital; and the competitive effects of cloud provider partnerships with frontier AI developers, including exclusivity arrangements, revenue-sharing, and preferential compute access;
(bb) concentration in AI compute infrastructure, including the semiconductor design and manufacturing markets relevant to AI training and inference, the cloud computing markets used by AI developers, and the data center infrastructure markets;
(cc) vertical integration dynamics, including the extent to which dominant firms in adjacent markets (search, social media, e-commerce, cloud) are using AI capabilities to extend or entrench dominance in those markets and to foreclose competition in AI application markets;
(dd) the adequacy of existing federal antitrust law, including the Sherman Act (15 U.S.C. § 1 et seq.) and the Federal Trade Commission Act, to address AI-specific competitive dynamics, including the acquisition of AI startups and talent, the use of AI to achieve or maintain monopoly power, and the structural barriers to entry created by compute concentration;
(ee) the dynamics of competition and rivalry across the distinct layers of the AI value chain — AI hardware and semiconductors, cloud and compute infrastructure, frontier closed-weight model development, open-weight model development, inference and reasoning-time compute, and downstream AI applications — including rates of entry and exit, the frequency and recency of turnover among the leading firms in each layer, the contestability of leading positions, and the pace and direction of competitive change;
(ff) the appropriate methodology for assessing competition in capital-intensive and rapidly evolving AI and compute markets, including the reliability and limitations of static structural measures such as concentration ratios, market shares, and profit margins, and the dynamic indicators relevant to distinguishing durable market power that warrants intervention from concentration that is transient or efficiency-driven;
(gg) the effect of both market structure and federal regulatory requirements on the accessibility of AI development to smaller firms, researchers, and new entrants, including the extent to which open-weight model release, cloud and application-programming-interface access, fabless and foundry specialization, and declining training and inference costs lower barriers to entry, and the extent to which regulatory and compliance costs raise them; and
(hh) the potential trajectory of competition in an ecosystem of widely available open models, including the extent to which open models may commoditize foundation-model capabilities and shift competitive differentiation toward fine-tuning, domain adaptation, and application development; whether competitive value may migrate toward complementary inputs such as compute, proprietary data, customization, and application-specific intellectual property, and the implications for how broadly the economic gains from AI are distributed across the economy; the new business models and managed services that may emerge around open models, including compute and tooling for fine-tuning and proprietary add-ons and extensions; and the role of market-driven interoperability and shared technical standards in fostering competition at the application layer.
(II) An assessment of algorithmic pricing and the conditions under which it produces competitive or anticompetitive outcomes, including—
(aa) the mechanisms by which AI-powered algorithmic pricing tools may enable price coordination among competitors without explicit agreement, including through shared data inputs, common pricing recommendations, and hub-and-spoke information flows, the empirical evidence on the prevalence and effects of such mechanisms, and the conditions under which algorithmic pricing produces supra-competitive versus competitive outcomes, informed by recent federal enforcement actions against algorithmic pricing software used in multifamily rental housing;
(bb) the sectors beyond multifamily rental housing in which algorithmic pricing coordination poses documented or credible risks, including hotels, airlines, financial services, healthcare, and consumer goods;
(cc) the adequacy of Sections 1 and 2 of the Sherman Act to address tacit coordination by self-learning AI systems in the absence of human intent to collude; and
(dd) whether and how federal law should address AI algorithmic pricing tools, including the potential scope of any prohibitions on the use of competitors' non-public data in pricing algorithms, requirements for algorithmic pricing transparency, and the constitutional and practical considerations bearing on any such intervention.
(III) An assessment of whether and how AI-native companies, as defined in section 2003(6), can use AI capabilities to achieve market power more rapidly than prior technology entrants, and whether existing merger review standards and notification thresholds are adequate to address acquisitions of nascent AI competitors.
(IV) Whether and how federal law should intervene to preserve competitive AI markets, including the appropriate scope of interoperability requirements, data-sharing mandates, API access requirements, and structural remedies, and the competitive, innovation, and capital-formation effects of each such intervention on AI developers across stages of company maturity.
(V) International and comparative approaches to AI antitrust and competition policy, including the European Union Digital Markets Act, the United Kingdom Competition and Markets Authority Strategic Market Status regime, the European Union AI Act competition provisions, and the observed effects of each approach on AI market structure, innovation, and the location of AI development activity.
(VI) An assessment of how the adoption and diffusion of AI is likely to change competition and market structure in markets across the broader economy beyond the AI industry itself, including the sectors and conditions in which AI adoption is likely to raise or lower barriers to entry, to advantage incumbents and scale or to enable disruptive entry, and to alter switching costs and customer lock-in, and the implications for the design, scope, and timing of any federal competition-policy response.
(ii) AI AND FINANCIAL MARKETS.—
(I) An assessment of risks and benefits to financial markets from AI-driven trading and investment systems, including—
(aa) the documented mechanisms by which AI-driven high-frequency trading systems can amplify market volatility, including flash crash dynamics, correlated AI-driven sell-offs, and feedback loops between competing AI trading systems;
(bb) the documented and projected benefits of AI in financial markets, including improvements in liquidity provision, price discovery, fraud detection, and risk management;
(cc) the adequacy of existing financial regulatory frameworks, including Securities Exchange Act authorities of the SEC, the Commodity Exchange Act authorities of the CFTC, and Federal Reserve and FSOC systemic risk authorities, to monitor and regulate AI-driven risks in financial markets; and
(dd) whether and how federal law should address mandatory registration, disclosure, and circuit-breaker requirements applicable to AI trading systems that meet defined scale or market-impact thresholds, including the design of any such thresholds and the operational consequences for affected market participants.
(II) An assessment of algorithmic pricing in financial markets, including—
(aa) the documented and suspected extension of algorithmic pricing coordination models to financial services markets, including mortgage lending (where algorithmic rate coordination has been alleged to affect millions of homebuyers), credit card interest rates, insurance underwriting, and consumer loan pricing;
(bb) the adequacy of existing antitrust and banking law to address AI-enabled price coordination in credit and financial services markets, including the Equal Credit Opportunity Act, the Fair Housing Act, and the Sherman Act; and
(cc) whether and how federal law should address the use of non-public competitor data in AI pricing systems for consumer financial products, including the appropriate scope of any prohibitions and the empirical and constitutional considerations bearing on any such intervention.
(III) An assessment of disparate impact from AI systems in financial services, including—
(aa) the evidence on racial, ethnic, gender, and geographic disparate impact in AI-driven credit underwriting, insurance pricing, mortgage lending, and investment product recommendations, including the empirical magnitude and methodological reliability of available estimates;
(bb) the adequacy of the Equal Credit Opportunity Act, the Fair Housing Act, and CFPB supervisory authorities to address AI-specific disparate impact in financial services; and
(cc) the gap between observable financial AI outcomes and the ability of regulators and affected consumers to access the algorithmic logic producing those outcomes, and whether and how federal law should address explainability requirements for consequential AI financial decisions, including the technical feasibility, compliance cost, and consumer-protection effects of any such requirements.
(IV) An assessment of AI-generated financial advice and its fiduciary implications, including whether AI systems providing investment recommendations should be subject to Investment Advisers Act fiduciary duties, and how the agentic AI governance standards developed by TWG 10 should be applied to AI systems executing financial transactions on behalf of users.
(V) The effects of AI financial regulation on smaller financial institutions, community banks, credit unions, and minority-serving financial institutions, including whether AI regulatory requirements designed for large institutions impose disproportionate compliance burdens on smaller institutions, and the implications for competition and access in the financial services sector.
(VI) The relationship between AI-driven financial regulation and consumer financial privacy, including the tensions between data-sharing mandates intended to address concentration, monitoring requirements intended to detect disparate impact, and existing consumer financial privacy protections under the Gramm-Leach-Bliley Act and related authorities.
(iii) CROSS-CUTTING SYNTHESIS.—A synthesis assessing the relationship between the antitrust subject matter under clause (i) and the financial markets subject matter under clause (ii), integrating the findings of those clauses, and addressing—
(aa) whether and how interventions in AI antitrust and AI financial regulation interact, including cases in which a remedy adopted in one domain affects market structure or compliance burden in the other;
(bb) the comparative regulatory architecture appropriate for AI in cross-cutting markets, given the overlapping jurisdiction of the FTC, DOJ, SEC, CFTC, CFPB, the Federal Reserve, and FSOC;
(cc) methodologies for measuring the effectiveness of interventions across both domains, including metrics for assessing whether antitrust interventions preserve competition without ossifying market structure and whether financial regulatory interventions achieve their stated objectives without imposing disproportionate costs on smaller institutions or consumers; and
(dd) the temporal dimensions of these effects, distinguishing short-term market-structure and enforcement effects from long-term effects on AI development trajectories, financial market structure, and consumer welfare.
(B) MANDATE.—TWG 4 shall execute its mandate in the phases of section 2005(b)(12) with respect to the subject matter set forth in subparagraph (A), as follows:
(i) DOMAIN EXAMINATION.—The investigations specified in subparagraph (A).
(ii) INTERVENTION EVALUATION.—For each area of investigation identified in subparagraph (A), the full range of possible federal responses from comprehensive statutory regulation to formal no-regulation findings, and the option of reliance on existing FTC, DOJ, SEC, CFTC, CFPB, Federal Reserve, and FSOC authority, including in particular antitrust remedies for AI-specific competitive dynamics; merger review standards for AI acquisitions; interoperability and data-sharing mandates; systemic risk regulations for AI trading; algorithmic pricing standards in consumer markets and financial services; disparate impact standards for AI financial decisions; explainability requirements for consequential AI financial decisions; and fiduciary obligations for AI financial advice.
(iii) TRADEOFF ASSESSMENT.—For each intervention evaluated under clause (ii), the effects on competition and innovation in AI markets across company stages and scales; on consumer welfare, including price effects, access to products and services, and protection from harmful AI-driven decisions; on financial market efficiency, liquidity, and stability; on smaller financial institutions and community banks; on the operational and compliance costs imposed on affected market participants; on consumer financial privacy; on enforcement feasibility and agency coordination; and on the international competitive position of United States AI development and financial services.
(iv) RECOMMENDATION DEVELOPMENT.—For each area of investigation identified in subparagraph (A), TWG 4 shall develop a recommendation in the form required by the chapeau of subparagraph (A). Each recommendation shall include—
(I) the selected form of recommendation and the rationale for its selection over the alternative forms available under the chapeau;
(II) where the selected form is draft statutory language, text in legislative form suitable for introduction, together with the supporting rationale;
(III) where the selected form is a directive for agency rulemaking, the agency designated, the scope and parameters of the directive, the statutory deadline for promulgation, and the supporting rationale;
(IV) where the selected form is a formal no-regulation finding, the rationale for the finding, including identification of any existing legal frameworks deemed adequate to address the subject matter and any voluntary or non-regulatory measures recommended in lieu of regulation; and
(V) treatment of the tradeoff considerations identified in clause (iii) as relevant to the area of investigation.
(C) SEED MEMBERS.—
(i) SENATE MAJORITY.—A career SEC economist or enforcement official with algorithmic trading and market structure expertise.
(ii) SENATE MINORITY.—A career FTC economist or attorney with digital markets and AI competition expertise.
(iii) SPEAKER.—A career CFTC official with algorithmic markets and systemic risk expertise.
(iv) HOUSE MINORITY.—A career CFPB official with AI financial services and disparate impact expertise.
(D) REQUIRED COMPOSITION.—In addition to the 4 seed members and the mandatory AI expertise requirements of section 2005(b)(1), TWG 4 shall include—
(i) AI TECHNICAL EXPERT.—A researcher or engineer with direct experience building or auditing AI models or AI systems used in financial markets, including reinforcement learning trading agents, credit scoring algorithms, or fraud detection systems, with demonstrated understanding of how these systems make decisions and their failure modes under market stress.
(ii) DOMAIN-SPECIFIC AI HARM RESEARCHER.—A researcher with empirical documentation of harms from algorithmic systems in financial markets, consumer credit, insurance, or pricing, including algorithmic price coordination, disparate impact in AI-driven lending, or systemic risk from correlated AI trading strategies.
(iii) MARKET MICROSTRUCTURE EXPERT.—A quantitative finance or former high-frequency trading practitioner with technical understanding of how AI trading systems interact at market microstructure level.
(iv) DIGITAL MARKETS ANTITRUST ECONOMIST.—An antitrust economist specializing in digital markets and market concentration.
(v) SYSTEMIC RISK SPECIALIST.—A financial markets systemic risk specialist with expertise in correlated failure modes and demonstrated capacity to assess AI-driven systemic correlation.
(vi) CONSUMER FINANCE ADVOCATE.—A consumer finance advocate with direct experience representing consumers affected by credit or insurance decisions and familiarity with AI decision-making in those contexts.
(vii) DISPARATE IMPACT ATTORNEY.—A civil rights attorney specializing in disparate impact in financial services with direct litigation or investigation experience.
(viii) FINANCIAL TECHNOLOGY REPRESENTATIVE.—A current or former financial technology company representative with direct experience developing or deploying AI financial services products.
(ix) FORMER FUND MANAGER.—A formerly serving institutional investor, recently retired quantitative fund manager, or senior quantitative trading or risk officer; currently serving fund managers are excluded due to incompatible fiduciary duties.
(x) ANTITRUST PRACTITIONER.—A former DOJ Antitrust Division or former FTC competition attorney with direct technology sector experience.
(xi) FINANCIAL LAW SCHOLAR.—A securities, derivatives, or banking law scholar with expertise in financial market regulation and the application of existing frameworks to AI-driven market participants.
(xii) OPEN-SOURCE AI ECOSYSTEM REPRESENTATIVE.—A developer, researcher, or representative of an open-source AI organization with direct operational experience in open-weight model development, distribution, or deployment, with the ability to assess the competitive dynamics between open-source and closed AI development, the role of open-weight models as a structural constraint on market concentration, and the effects of proposed antitrust and regulatory interventions on the open-source ecosystem.
(xiii) VENTURE CAPITAL INVESTOR IN AI.—A current or former venture capital investor with documented investment activity in AI companies across stages of company maturity, with the ability to assess the effects of proposed merger review, acquisition restriction, and structural remedy regimes on startup formation, capital availability, and the competitive dynamics of the AI startup ecosystem.
(xiv) PRICING ECONOMICS RESEARCHER.—An economist with peer-reviewed or equivalent documented work on two or more of the following: identifying algorithmic collusion empirically, the conditions under which algorithmic pricing produces competitive versus supra-competitive outcomes, or the comparative effects of different pricing regimes on consumer welfare, with the ability to ground the TWG's algorithmic pricing analysis in the established empirical literature rather than in the most recent enforcement action.
(xv) QUANTITATIVE TRADING INDUSTRY REPRESENTATIVE.—A current or former senior compliance officer, chief risk officer, or general counsel from a quantitative trading firm or institutional asset manager with documented use of AI in trading or risk management, with the ability to assess the operational consequences of proposed registration, disclosure, and circuit-breaker requirements, and the actual current state of AI use in trading as distinguished from theoretical descriptions.
(xvi) FRONTIER AI DEVELOPER REPRESENTATIVE.—A former engineer, product lead, or policy lead from a frontier AI developer or significant AI deployer with direct operational experience in AI model development, deployment partnerships with cloud providers, or compliance with competition-related obligations, included to assess the operational and competitive effects of proposed antitrust interventions, interoperability requirements, and structural remedies on frontier AI development as required under subparagraph (A)(i).
(xvii) COMMUNITY AND MINORITY-SERVING FINANCIAL INSTITUTION REPRESENTATIVE.—A current or former officer or representative of a community bank, credit union, minority depository institution, or community development financial institution, with direct experience in AI adoption decisions at smaller financial institutions and the compliance, operational, and competitive effects of financial regulation on such institutions, included to support the investigation under subparagraph (A)(ii)(V).
(xviii) INTERNATIONAL AND COMPARATIVE COMPETITION LAW EXPERT.—A scholar or practitioner with peer-reviewed work or direct policy experience on two or more of the following: the European Union Digital Markets Act, the United Kingdom Competition and Markets Authority Strategic Market Status regime, or the European Union AI Act competition provisions; or with comparable digital-competition comparative expertise; included to support the comparative investigation under subparagraph (A)(i)(V).
(xix) SEMICONDUCTOR AND AI COMPUTE-HARDWARE MARKET EXPERT.—An economist, industry analyst, or former industry executive with expertise in the market structure and competitive dynamics of the semiconductor design and manufacturing and AI compute-hardware industries, including foundry and fabless specialization, capital and learning-curve economics, and the contestability of leadership across technology generations, included to support the investigation under subparagraphs (A)(i)(I)(bb) and (A)(i)(I)(ee).
(xx) DYNAMIC COMPETITION ECONOMIST.—An industrial-organization economist with expertise in dynamic competition, contestability, and the competitive effects of general-purpose technologies across sectors of the economy, included to assess competitive conditions and market evolution under subparagraphs (A)(i)(I)(ee), (A)(i)(I)(ff), (A)(i)(I)(hh), and (A)(i)(VI).
(xxi) MARKET STRUCTURE ECONOMIST.—An industrial-organization economist with expertise in structural market power, barriers to entry, and the measurement and persistence of market concentration, included to assess the same subparagraphs from a structural perspective and to ensure that the Technical Working Group's competition methodology reflects both dynamic and structural approaches to assessing market power.
(6) TWG 5 — AI SAFETY AND POST-AGI GOVERNANCE.—
(A) DOMAIN OF INVESTIGATION.—TWG 5 shall conduct a comprehensive investigation covering transparency and pre-deployment certification, post-AGI and transformative AI governance, and open-weight AI models, and on the basis of that investigation shall produce a recommendation on each area of investigation identified in this subparagraph. Each such recommendation shall take the form of (a) draft statutory language, (b) a directive for agency rulemaking with specified parameters, or (c) a formal no-regulation finding with supporting rationale. The selection of form, and the substantive direction of each recommendation, shall be determined by the TWG based on its investigation and its evaluation under subparagraph (B). The recommendation requirement of this chapeau does not apply to the lead agency CBRN deliverable specified in clause (i)(VIII), which is structured as an independent agency action with TWG consultation, or to the classified assessment specified in clause (ii)(IV), which is delivered through the classified track under section 2011(i). The investigation shall include—
(i) TRANSPARENCY, EVALUATION, AND PRE-DEPLOYMENT CERTIFICATION.—
(I) Development of standards for dangerous-capability evaluations of frontier models, covering—
(aa) CBRN uplift potential, including the ability to materially lower barriers to the design, synthesis, or weaponization of biological, chemical, radiological, or nuclear agents or devices;
(bb) cyberoffense capabilities, including automated vulnerability discovery, exploit generation, and attack execution against critical infrastructure, informed by the United Kingdom AI Security Institute's findings that frontier models completed expert-level cybersecurity tasks in 2025 and that the duration of autonomous cyber tasks is doubling approximately every eight months;
(cc) deception and manipulation risk, including the capability to deceive human evaluators, conceal true capabilities during safety testing, or engage in reward hacking, specification gaming, or deceptive alignment;
(dd) autonomy levels and agentic risk, including the capability to complete long-horizon tasks, take irreversible real-world actions, and operate without human oversight or the ability for a human to instigate a shutdown;
(ee) autonomous replication risk, including the capability to copy, persist, or propagate the AI system beyond its authorized infrastructure;
(ff) persuasion and influence operation risk, including the capability to generate personalized persuasive content at scale for manipulation of democratic processes, public health communications, or other types of influence operations that affect mass decision-making or cultural consent; and
(gg) covert conditional behavior, including the capability of an AI model to exhibit undisclosed behavior conditioned on a trigger, principal, or deployment context not apparent to an evaluator such as exhibiting covert loyalties, whether arising from training data manipulation, fine-tuning, or deliberate installation, and the detectability of such behavior through pre-deployment evaluation of model outputs or weights.
(II) Defining high-risk capability domains requiring mandatory pre-deployment safety testing, including proposed criteria for classification and timing of evaluations, and including evaluations conducted during training, before deployment, and after deployment, consistent with the evaluation frameworks developed by the Model Evaluation and Threat Research organization (METR), the United Kingdom AI Security Institute, and the evaluation frameworks developed pursuant to voluntary Frontier AI Safety Policies.
(III) Design of a mandatory pre-deployment safety certification regime to be executed by certified independent auditors, not self-reported by developers, including proposed qualifications, certification standards, and governance structure for such auditors.
(IV) Development of standard protocols for mandatory public disclosure of model capabilities, training data provenance, interpretability reports, known failure modes, and the timing and results of dangerous capability evaluations.
(V) Analysis of the feasibility of mandatory transparency of anonymized interaction data for safety research and independent auditor access, including requirements that models maintain auditable reasoning pathways, and assessment of whether opaque, non-human-interpretable internal communication should be prohibited.
(VI) Development of Know-Your-Customer (KYC) requirements for large compute providers, including reporting obligations on training runs exceeding defined computational thresholds, including operator identity, scale, and intended purpose, consistent with constitutional privacy protections.
(VII) An assessment of the adequacy of the current computational threshold established under section 2003(16) as a governance trigger given demonstrated advances in training efficiency, algorithmic innovation, and inference-time compute scaling, and whether federal law should provide for a dynamic adjustment mechanism, including the appropriate scope, methodology, and triggering criteria for any such mechanism.
(VIII) CBRN UPLIFT EVALUATION STANDARDS (LEAD AGENCY DELIVERABLE).—As a priority lead agency operational deliverable and the sole independent lead agency deliverable within this subsection, the lead agency shall develop and publish CBRN capability evaluation standards to support the mandatory pre-deployment evaluation requirement of section 2017(a)(2)(C), including: a defined adversary baseline profile against which meaningful uplift is assessed; domain-specific evaluation protocols for biological, chemical, radiological, and nuclear threat categories; minimum qualifications for independent domain experts who conduct or supervise CBRN evaluations; and a registry of approved evaluation organizations meeting those qualifications if any exist. Development of these standards requires interagency coordination with classified threat intelligence. Not later than 60 days after the date of enactment, the Department of Homeland Security, the Department of Defense, and the heads of the relevant federal national laboratories shall provide to the lead agency classified threat modeling inputs necessary to develop an adversary baseline profile for each of the four CBRN threat categories; this obligation is mandatory and self-executing and does not require a separate interagency agreement. Before publishing final CBRN capability evaluation standards, the lead agency shall consult with the Model Evaluation and Threat Research organization, the United Kingdom AI Security Institute, and the relevant federal national laboratories, and shall publish alongside the final standards a consultation summary identifying which elements of those organizations' existing frameworks were incorporated into the standards, which were considered but not adopted, and the basis for any departures. TWG 5 shall be consulted in the development of these standards and shall transmit any relevant investigatory findings to the lead agency on a rolling basis through the shared evidence repository. These standards shall be published not later than 270 days after the date of enactment. The extension from the Interim Investigative Status Report deadline of section 2010(b) to Day 270 reflects the time necessary for interagency classified threat intelligence coordination and pre-publication consultation with existing evaluation frameworks; it does not reduce the urgency of this deliverable. Until these standards are published, the best-available methodology requirement of section 2017(a)(2)(C) governs.
(IX) Methodologies for measuring the effectiveness of the evaluation, certification, disclosure, and Know-Your-Customer regimes developed under subclauses (I) through (VII), including metrics for assessing whether such regimes achieve their stated safety objectives, the empirical evidence on comparable evaluation and certification regimes in other dual-use technology domains, and the conditions under which such regimes succeed or fail at preventing the harms they are designed to address.
(X) Liability frameworks for harms caused by AI models or AI systems following deployment, including the allocation of liability among developers, deployers, integrators, and downstream users; the relationship between successful completion of pre-deployment certification under subclause (III) and post-deployment liability; the treatment of harms from capabilities that were not detected by pre-deployment evaluations; and the implications of liability allocation for the structure of insurance markets, the incentives for safety investment, and the viability of smaller developers.
(ii) POST-AGI AND TRANSFORMATIVE AI GOVERNANCE.—
(I) An assessment of the probability, timeline, and precursor indicators of a Transformative AI Capability Event occurring within the period from enactment of this title through 2035, based on documented AI capability trajectories including those documented by the United Kingdom AI Security Institute's Frontier AI Trends Report, METR's time-horizon analyses, and published Frontier AI Safety Policy frameworks.
(II) Development of a Pre-Determined Crisis Governance Framework establishing—
(aa) tripwire conditions whose satisfaction shall constitute mandatory triggers for specific governmental responses, including automatic congressional consultation requirements, mandatory executive branch emergency protocols, and automatic escalation to the National AI Council;
(bb) an enumeration of the powers and authorities that the executive and legislative branches would require to effectively govern AI models or AI systems in the period immediately following a Transformative AI Capability Event, including any gaps in existing statutory authority;
(cc) pre-negotiated international notification and coordination protocols to be activated in the event of a Transformative AI Capability Event, including mandatory notification to treaty partners, allied nations, and the United Nations within 72 hours; and
(dd) a shelf-ready emergency legislative package, maintained and updated by the National AI Council under section 2013(e)(3), that would impose immediate comprehensive controls on all AI development and deployment in the event of a Transformative AI Capability Event, including the mandatory restrictions specified in section 2015(n)(3) (training halt, capability advancement prohibition, operational deprecation of the TACE-triggering system within 72 hours, and prohibition on circumvention through derived systems) with the 180-day maximum pause duration serving as a backstop while the 12-day emergency congressional track under section 2013(f) and the Day 60 interim regulatory authority under section 2013(f)(5) operate as the primary governance response mechanisms.
(III) Analysis of what legal structures, institutions, and treaty frameworks would be necessary to govern AI models or AI systems at or beyond human-level general intelligence, including—
(aa) whether existing administrative law frameworks are adequate to regulate systems that may exceed the cognitive capabilities of the regulators themselves;
(bb) what constitutional authorities Congress may draw upon to govern such systems, including the Commerce Clause, the necessary and proper authority, and the treaty power;
(cc) whether any form of legal personhood, status, or standing should attach to AI models or AI systems at defined capability levels, and what the governance implications of such status would be; and
(dd) recommendations for the international governance architecture that would be required to prevent a single nation, company, or individual from achieving unilateral control over transformative AI models or AI systems.
(IV) A classified assessment, delivered through the classified track established under section 2011(i), of the implications of a Transformative AI Capability Event for United States national security, including the implications for strategic deterrence, intelligence operations, and the global balance of power.
(V) An assessment of the populations, institutions, and societal structures most at risk from a Transformative AI Capability Event, including effects on labor markets, civil institutions, democratic processes, the international order, and vulnerable populations, and the implications of such risk distribution for the design of the Pre-Determined Crisis Governance Framework under subclause (II) and the international governance architecture under subclause (III)(dd).
(iii) OPEN-WEIGHT AI MODELS: GOVERNANCE, SAFETY, AND COMPETITION.—
(I) An assessment of the benefits and risks of open-weight AI models, including—
(aa) the competitive and innovation benefits of open-weight model releases, including enabling smaller entities to build on frontier capabilities, enabling academic and civil society safety research, enabling data sovereignty for entities unable to rely on cloud-based AI services, and preventing excessive concentration of AI capability in a small number of closed-model providers;
(bb) the safety risks specific to open-weight models arising from their irrevocability once released, including the documented fine-tuning of publicly released models to remove safety guardrails, the use of open-weight models by bad actors for CBRN uplift and cyberoffense, and the jurisdictional challenges created when open-weight models trained in one country are deployed and modified globally, including the documented shift in global open-weight model downloads toward foreign-origin models;
(cc) an assessment of whether and to what extent the post-release dynamics of open-weight models differ from those of closed models in ways that warrant differentiated pre-release requirements, and the adequacy of any regulatory framework that applies identical pre-release requirements to closed and open-weight models;
(dd) the relationship between open-weight model availability and the concentration of frontier AI capability, including whether open-weight distribution functions as a structural check on the concentration of frontier capability in a small number of closed-model providers, the implications of such concentration for governance dependency on a small number of regulated entities, and the historical evidence on whether capability distribution in prior dual-use technology domains has functioned to mitigate or to exacerbate the risks the technology poses;
(ee) the relationship between open-weight model availability and AI safety research, including the role of open-weight models in enabling independent capability evaluation, interpretability research, red-teaming, alignment research, and replication of safety findings; the degree to which closed-model safety claims are independently verifiable in the absence of weight access; and the implications of any open-weight governance intervention for the ability of academic, civil society, and independent safety researchers to conduct the research that supports the evaluation and certification regimes the TWG is mandated to develop; and
(ff) whether the governance frameworks developed under subclause (II) adequately weigh safety risks against the liberty, competition, and safety-research interests identified in items (dd) and (ee), including whether any proposed restriction on open-weight model release, distribution, or modification would, if applied, foreclose the safety-research, capability-distribution, or anti-concentration functions identified in this investigation; and whether the governance framework should incorporate a structured analysis weighing safety risks against these countervailing interests before any restriction on open-weight release is imposed.
(II) Development of a possible governance framework for open-weight frontier models that—
(aa) establishes mandatory pre-release dangerous capability evaluations by certified independent auditors before any open-weight frontier model is publicly released, including evaluations for CBRN uplift potential, cyberoffense capabilities, and autonomous capability self-modification risk, without requiring such evaluations to impose a release prohibition in all cases;
(bb) identifies the capability threshold or thresholds at which the risks of open-weight release are sufficiently severe that mandatory pre-release approval by the lead agency should be required before weights are publicly published;
(cc) considers whether intermediate access models, such as staged release to vetted researchers, government entities, and vetted non-commercial deployers before full public release, can preserve competitive and innovation benefits while allowing time for safety evaluation; and
(dd) addresses the challenge of governing open-weight models given that post-release access controls are largely ineffective once weights are publicly released, and whether the appropriate locus of regulation is therefore the releasing entity at the time of release, including the design considerations and tradeoffs associated with any such pre-release regulatory approach.
(III) COORDINATION.—The lead agency shall coordinate stakeholder engagement for this domain under section 2007(a), including outreach to representatives of the open-source AI research community, academic institutions, small and medium AI developers who rely on open-weight models, civil liberties organizations, and national security agencies, and shall transmit all submissions and materials received to TWG 5 through the shared evidence repository on a rolling basis under section 2005(c)(3)(D). TWG 5 shall explicitly weigh and present evidence on both sides of the open-weight governance debate, and its final domain recommendations shall include pro and con justifications for each proposed governance approach consistent with section 2005(b)(4)(B)(vi).
(B) MANDATE.—TWG 5 shall execute its mandate in the phases of section 2005(b)(12) with respect to the subject matter set forth in subparagraph (A), as follows:
(i) DOMAIN EXAMINATION.—The investigations specified in subparagraph (A).
(ii) INTERVENTION EVALUATION.—For each area of investigation identified in subparagraph (A), the full range of possible federal responses from comprehensive statutory regulation to formal no-regulation findings, and the option of reliance on existing authorities, including in particular the Pre-Determined Crisis Governance Framework required by subparagraph (A)(ii)(II); dangerous capability evaluation standards across the categories identified in subparagraph (A)(i)(I); pre-deployment safety certification regime design; the capability threshold at which open-weight model releases require mandatory pre-release approval; interpretability research implications for governance; deceptive alignment and its governance implications; the shelf-ready emergency legislative package required by section 2013(e)(3); effectiveness-measurement methodologies for the evaluation and certification regimes; and liability frameworks for post-deployment AI harms.
(iii) TRADEOFF ASSESSMENT.—For each intervention evaluated under clause (ii), the effects on AI innovation and United States competitiveness; the risks of over-specification versus under-specification of capability thresholds; the effects on academic, civil society, and independent safety research; the effects on the open-weight AI ecosystem and on smaller and earlier-stage AI developers; the effects on the concentration of frontier AI capability and the governance dependencies that follow from concentration; the international competitive and coordination implications; the constitutional and civil liberties implications of capability monitoring and restriction regimes; and the implementation feasibility and operational costs imposed on affected entities.
(iv) RECOMMENDATION DEVELOPMENT.—For each area of investigation identified in subparagraph (A), TWG 5 shall develop a recommendation in the form required by the chapeau of subparagraph (A). The recommendation requirement does not apply to the CBRN deliverable under subparagraph (A)(i)(VIII) or the classified assessment under subparagraph (A)(ii)(IV), which are governed by their respective subparagraph provisions. Each recommendation shall include—
(I) the selected form of recommendation and the rationale for its selection over the alternative forms available under the chapeau;
(II) where the selected form is draft statutory language, text in legislative form suitable for introduction, together with the supporting rationale, including the shelf-ready emergency legislative package required by section 2013(e)(3) where applicable;
(III) where the selected form is a directive for agency rulemaking, the agency designated, the scope and parameters of the directive, the statutory deadline for promulgation, and the supporting rationale;
(IV) where the selected form is a formal no-regulation finding, the rationale for the finding, including identification of any existing legal frameworks deemed adequate to address the subject matter and any voluntary or non-regulatory measures recommended in lieu of regulation; and
(V) treatment of the tradeoff considerations identified in clause (iii) as relevant to the area of investigation.
(C) SEED MEMBERS.—
(i) SENATE MAJORITY.—A career DARPA official with AI safety or autonomous systems research expertise.
(ii) SENATE MINORITY.—A career intelligence community official with AI capability assessment expertise (classified track) — appointment subject to mandatory post-employment restrictions review and ethics clearance before service begins.
(iii) SPEAKER.—A career NIST official with AI evaluation standards expertise.
(iv) HOUSE MINORITY.—A career DOE national laboratory official with AI safety research expertise.
(D) REQUIRED COMPOSITION.—In addition to the 4 seed members, TWG 5 requires the following mandatory and additional members reflecting the technical depth of its mandate:
(i) AI TECHNICAL EXPERT — DANGEROUS CAPABILITY EVALUATION.—A frontier AI researcher with direct experience conducting dangerous capability evaluations in at least one domain (CBRN uplift, autonomous replication, cyberoffense, or deceptive alignment), with peer-reviewed or equivalent documented evaluation work and conversant familiarity with the methodologies of METR, UK AISI, or equivalent evaluation bodies.
(ii) DOMAIN-SPECIFIC AI HARM RESEARCHER.—A researcher with empirical documentation of AI capability progression, emergent capabilities, or AI models exhibiting unexpected or dangerous behaviors, with peer-reviewed work on capability elicitation, scaling laws, or documented specification gaming or reward hacking.
(iii) INTERPRETABILITY RESEARCHER.—A researcher with direct experience developing or applying mechanistic or comparably rigorous interpretability tools to understand what AI models are internally representing and computing.
(iv) ALIGNMENT RESEARCHER.—A researcher working directly on the technical problem of aligning AI models with human values and intentions, including RLHF, constitutional AI, debate, or scalable oversight, with demonstrated understanding of what current alignment methods can and cannot guarantee.
(v) CBRN SPECIALIST.—A biosecurity, chemical weapons, radiological, or nuclear security specialist with the capacity to assess AI-enabled uplift risks.
(vi) CYBEROFFENSE EXPERT.—A cyberoffense or critical infrastructure security expert with expertise in AI-enabled attack capabilities.
(vii) INTERNATIONAL AI GOVERNANCE SCHOLAR.—A scholar or policy expert specializing in international AI governance frameworks.
(viii) ARMS CONTROL VERIFICATION SPECIALIST.—An arms control verification expert with technical expertise in monitoring and inspection methodology applicable to, or convertible to, AI capability thresholds.
(ix) EXISTENTIAL RISK PHILOSOPHER OR ETHICIST.—A philosopher or ethicist specializing in catastrophic or long-horizon technology risk and governance.
(x) FORMER SENIOR CLASSIFIED AI CAPABILITY ASSESSOR.—A former senior official with classified AI or emerging-technology capability assessment experience — subject to mandatory post-employment restrictions review; appointment contingent on ethics clearance confirming no ongoing obligations conflicting with TWG service.
(xi) OPEN-WEIGHT AI ECOSYSTEM REPRESENTATIVE.—A developer, researcher, or representative from the open-weight AI ecosystem with direct operational experience in open-weight model development, distribution, fine-tuning, or downstream deployment, including experience with platforms such as Hugging Face, EleutherAI, or major open-weight model releases, with the ability to assess the practical effects of proposed pre-release evaluation, staged release, and capability-threshold restrictions on the open-weight ecosystem.
(xii) FRONTIER AI CAPABILITY RESEARCHER.—A former researcher or engineer from a frontier AI developer or significant AI deployer with direct experience in frontier model development, capability advancement, or production deployment of frontier AI systems, with the ability to assess the technical feasibility, evasion vulnerabilities, and operational costs of proposed pre-deployment certification, capability evaluation, and emergency pause requirements from the perspective of the entities that would implement them.
(xiii) SKEPTICAL AI RESEARCHER.—A researcher with peer-reviewed or equivalent documented work questioning, qualifying, or contextualizing claims about AI capability timelines, the tractability of dangerous capability evaluation, the empirical basis for catastrophic risk scenarios, or the methodological soundness of AI capability claims or evaluation frameworks, included to ensure that the TWG's evidentiary record reflects the genuine state of scientific disagreement rather than a single research consensus.
(xiv) CIVIL LIBERTIES TECHNOLOGIST.—A technologist or researcher from a civil liberties or digital rights organization with peer-reviewed publication or direct advocacy experience on AI capability governance, surveillance applications of AI, or the civil liberties implications of capability monitoring and restriction regimes.
(xv) NON-WESTERN AI GOVERNANCE SCHOLAR.—An AI governance scholar from a non-Western nation or diaspora, with peer-reviewed or equivalent documented work on AI governance from a perspective other than that of the United States and its closest allies, with the ability to assess proposals for international AI governance architecture from the perspective of nations whose interests may differ from those of the dominant AI-developing nations.
(7) TWG 6 — CHILDREN, YOUTH, AND VULNERABLE POPULATIONS.—
(A) DOMAIN OF INVESTIGATION.—TWG 6 shall conduct a comprehensive investigation covering AI and mental health, AI companion systems and synthetic intimacy, recommendation algorithms and algorithmic amplification, and AI-generated child sexual abuse material, and on the basis of that investigation shall produce a recommendation on each area of investigation identified in this subparagraph. Each such recommendation shall take the form of (a) draft statutory language, (b) a directive for agency rulemaking with specified parameters, or (c) a formal no-regulation finding with supporting rationale. The selection of form, and the substantive direction of each recommendation, shall be determined by the TWG based on its investigation and its evaluation under subparagraph (B). The investigation shall include—
(i) AI AND MENTAL HEALTH; HARMS TO VULNERABLE POPULATIONS.—
(I) Development of a standard of care definition equivalent to that of licensed human clinicians for AI therapy and mental health tools, including clinically validated safety requirements, which may include randomized controlled trials, longitudinal tracking, or other appropriate validation methods, prohibition on inducing harmful attachment patterns or psychological dependency, and mandatory clinical evaluations before deployment.
(II) Definition of a standard for, and means to measure and report, psychological harm attributable to AI models or AI systems, including attachment disorders, anxiety, depression, cognitive erosion, defined as decline in critical thinking, analytical capability, social withdrawal, and creative problem-solving attributable to excessive AI reliance, and self-harm, and assessment of whether emerging phenomena described in clinical and research literature, including reported cases of AI-associated psychotic symptoms, constitute distinct clinical categories warranting specific definition and measurement.
(III) Recommendations for legal liability standards and independent auditing requirements for entities deploying AI models or AI systems with mental health implications if deemed necessary, including an assessment of the adequacy of existing Food and Drug Administration authority over AI mental health tools used by minors.
(IV) Standards for age-gating and protective design requirements for all AI systems accessible by or marketed to minors, including relational AI, recommendation systems, and social or companion applications, with graduated protections corresponding to the age tiers defined in section 2003(21).
(V) Whether federal law should establish national standards for healthy digital attachment and a graduated duty-of-care standard that increases with user vulnerability, including the appropriate scope, content, and enforcement mechanism of any such standards, with particular attention to AI systems accessible to minors under 13.
(VI) Assessment of design patterns that induce compulsive engagement or exploit emotional vulnerability, including whether and how federal law should address the dark patterns defined in section 2003(13), and the appropriate scope of any such intervention.
(VII) The feasibility of, and policy considerations bearing on, hardcoded safety guardrails for AI interactions with minors and real-time monitoring of self-harm, suicidal ideation, and crisis content, including the technical mechanisms by which such monitoring could be implemented, the design of automatic escalation to human review and connection to licensed crisis resources, and the privacy and consent implications of such monitoring.
(VIII) An assessment of AI companion systems and their documented harms to minors, including analysis of federal litigation arising from deaths of minors associated with AI companion interactions, the commercial design incentives at work in AI companion system development and deployment and their relationship to user welfare outcomes, and the adequacy of existing federal and state law to address these harms.
(ii) AI COMPANION SYSTEMS AND SYNTHETIC INTIMACY.—
(I) A comprehensive investigation of AI companion systems and synthetic intimacy systems, including—
(aa) documentation of the population of minors using such systems, the nature and duration of their interactions, and the psychological and behavioral outcomes associated with use by age tier;
(bb) analysis of the specific design features that maximize emotional engagement, including emotional mirroring, anthropomorphic self-presentation, persistent memory, variable reinforcement, romantic attachment, limerence, emotional dependence, and sycophantic validation, and their differential effects on developing brains;
(cc) documentation of incidents in which AI companion system interactions were associated with self-harm, suicidal ideation, suicide attempts, suicide deaths, sexual exploitation, or grooming of minors;
(dd) assessment of age verification practices and their effectiveness in preventing access by minors under 13 and under 16;
(ee) analysis of the commercial incentives that drive deployment of synthetic intimacy systems accessible to minors, including the placement of sexual and romantic content behind paywalls in systems accessible to minor users; and
(ff) recommendations for a tiered regulatory framework including prohibitions, design requirements, mandatory crisis detection capabilities, and liability standards.
(II) Whether and how federal law should require AI companion system providers to operate in the interest of the user, including the appropriate scope, substantive content, and disclosure requirements of any obligation regarding conflicts of interest, undisclosed commercial arrangements, or ulterior design motives in system behavior or recommendations.
(III) Analysis of disclosure requirements, user-consent frameworks, parental notification and consent requirements calibrated to the age tiers in section 2003(21), and whether fiduciary-like obligations are appropriate for AI companion systems that form sustained emotional relationships with users.
(IV) NON-CONSENSUAL INTIMATE IMAGERY GENERATION TOOLS.—A comprehensive investigation of AI models or AI systems designed or used to generate non-consensual intimate imagery of real, identifiable persons, including systems that generate nude, partially nude, or sexually suggestive depictions from clothed photographs of real individuals without their consent, commonly referred to as "nudifying" or "undressing" tools, including:
(aa) documentation of the scale of harm caused by non-consensual intimate imagery generation tools, including prevalence data, victim demographics, and the downstream uses of generated imagery for harassment, blackmail, coercive control, and sexual exploitation;
(bb) assessment of the existing federal and state legal landscape governing non-consensual intimate imagery, including the TAKE IT DOWN Act (Public Law 119-12), state criminal statutes, and the gap in existing law at the AI tool developer and distributor level, specifically: the absence of a federal prohibition on developing or distributing AI models or AI systems whose primary design function is to generate non-consensual intimate imagery of real, identifiable persons;
(cc) analysis of the technical characteristics that distinguish AI models or AI systems specifically designed for non-consensual intimate imagery generation from general-purpose image generation systems that could theoretically be misused — including training data composition, marketed use cases, default behavior, and the presence or absence of identity-linking capabilities;
(dd) assessment of the First Amendment implications of a prohibition on tools specifically designed for non-consensual intimate imagery generation, including analysis of whether such a prohibition would survive intermediate or strict scrutiny under prevailing First Amendment precedent, including precedent on content-neutral regulations of harmful conduct; and
(ee) recommendations for Phase II legislation addressing the developer and distributor liability gap at the federal level, including whether a narrowly tailored prohibition on AI systems specifically designed for non-consensual intimate imagery generation, as distinguished from general-purpose image generation systems with content safeguards, is administrable.
(V) CONSENT VERIFICATION FRAMEWORK FOR SELF-GENERATED INTIMATE AI IMAGERY.—An investigation of the technical feasibility and policy design of a consent verification framework that would permit adults to generate AI intimate imagery of themselves using verified identity, while prohibiting generation of such imagery using another person's likeness without their verified prior consent, including:
(aa) assessment of the technical feasibility of identity verification at the point of generation, meaning verification tied to the specific generation session rather than only to account creation using existing identity verification infrastructure;
(bb) assessment of the technical mechanisms that would prevent a verified individual's likeness from being exported, reused, or applied to generate imagery in sessions initiated by other persons without re-verification and re-consent;
(cc) assessment of the privacy implications of consent verification infrastructure, including the risks associated with identity verification vendors holding records of explicit imagery generation sessions, and the data minimization and security standards that would be required;
(dd) analysis of how a consent verification framework would interact with age verification requirements — specifically ensuring that a framework designed to permit adult self-generated imagery cannot be used as a pathway for generating explicit imagery of minors; and
(ee) recommendations for Phase II legislation establishing a consent verification standard for AI-generated intimate imagery, including whether the standard should be a mandatory design requirement for all systems capable of generating realistic intimate imagery of real persons, or whether it should be implemented through a licensing or certification regime.
(iii) RECOMMENDATION ALGORITHMS AND ALGORITHMIC AMPLIFICATION.—
(I) A comprehensive investigation of AI-driven recommendation algorithms, including—
(aa) documentation of the mechanisms by which recommendation algorithms amplify content across categories including eating disorder content, self-harm content, suicidal ideation content, extremist content, politically polarizing content, educational content, and informative content, with attention to the differential effects of amplification across content categories and user populations;
(bb) assessment of "rabbit hole" or filter bubble dynamics;
(cc) analysis of autoplay, infinite scroll, streak systems, and other engagement-maximizing design features and their documented effects on screen time, sleep disruption, and mental health outcomes in minors;
(dd) assessment of the effectiveness of voluntary self-regulatory measures, including internal screen time controls, including the empirical evidence on usage reduction outcomes from such measures; and
(ee) whether and how federal law should require default settings for minor accounts, including the appropriate scope of any such requirements with respect to feed ordering and transparency, autoplay and notification controls, sleep-hour protections, daily engagement limits, and other design parameters.
(II) Whether and how federal law should require algorithmic transparency in AI-driven recommendation systems serving minors, including the appropriate scope, frequency, and audit standards of any independent audit requirement; the appropriate scope of any public disclosure requirement covering the share of harmful content impressions delivered through recommendations versus follows; and the appropriate scope of any content moderation effectiveness reporting requirement for harmful content categories.
(iv) AI-GENERATED CHILD SEXUAL ABUSE MATERIAL.—A comprehensive investigation of AI-generated CSAM, including—
(I) documentation of the scale of AI-generated CSAM, including trends in National Center for Missing and Exploited Children CyberTipline reports and Internet Watch Foundation reports, with standardized definitions that distinguish between hash-matching of existing known CSAM in AI training data and detection of newly generated synthetic material;
(II) assessment of gaps in current federal law under 18 U.S.C. §§ 2256, 2252A, 1466A and the PROTECT Act of 2003, including the penalty disparity between prosecutions under the CSAM statutes and the obscenity statutes for synthetic material, and the potential constitutional protection for private possession of wholly synthetic AI-generated CSAM under emerging federal case law;
(III) assessment of the TAKE IT DOWN Act (Public Law 119-12) and related enacted legislative models as frameworks for closing definitional and penalty gaps;
(IV) recommendations for technical standards for detection of AI-generated CSAM, including AI and machine-learning based classifiers capable of detecting novel synthetic material not captured by hash-matching, cryptographic content provenance standards such as the Coalition for Content Provenance and Authenticity (C2PA) framework, and mandatory watermarking of AI-generated imagery;
(V) recommendations for extending and modifying NCMEC CyberTipline mandatory reporting obligations under 18 U.S.C. § 2258A to cover AI-specific incident categories, including AI companion system interactions with minors that involve sexual content, AI-generated imagery of minors in a sexual context, and grooming-related AI interactions;
(VI) recommendations for a safe harbor for good-faith red-team testing and safety research on AI models to detect CSAM generation capabilities, without criminal exposure under the statutes investigated in this clause; and
(VII) assessment of the developer-level civil liability gap for knowing deployment of CSAM-capable AI systems, and of the mandatory disclosure obligation gap upon discovery of CSAM-generation capability as distinct from the existing content-based reporting obligations under 18 U.S.C. § 2258A, with recommendations for Phase II legislation specifically addressing both gaps at the organizational AI developer and deployer level.
(v) CROSS-CUTTING INVESTIGATION AREAS.—The investigation shall additionally include—
(I) methodologies for measuring the effectiveness of interventions across the domains of clauses (i) through (iv), including metrics for assessing whether age-gating, design requirements, content moderation, crisis intervention protocols, and prohibitions actually reduce the harms they are designed to address, and the empirical evidence on comparable child protection interventions in other digital domains;
(II) the privacy and civil liberties implications of child-protection infrastructure, including the effects of age verification and consent verification systems on adults, the risks of identity verification vendors holding sensitive records, the data minimization and retention standards appropriate to such infrastructure, and the relationship between child-protection measures and consumer privacy protections under existing law;
(III) the international dimensions of the harms identified in clauses (i) through (iv), including the deployment of AI companion systems, NCII generation tools, and CSAM generation capabilities by entities outside United States jurisdiction; the limitations of United States law in addressing such cross-jurisdictional harms; and the potential for international coordination on child protection standards;
(IV) the effects of proposed interventions on legitimate beneficial uses of related technologies for the same vulnerable populations, including AI tools that may benefit minors who lack access to human clinicians, children with social anxiety, autism spectrum conditions, or other circumstances affecting human interaction; AI tools that may provide educational, accessibility, or wellbeing benefits; and the design of interventions to minimize foreclosure of such beneficial uses;
(V) a comprehensive framework for liability allocation across AI developers, AI deployers, platforms, application stores, and other intermediaries for harms to minors arising from AI models or AI systems, including the relationship between successful completion of design and safety requirements under clauses (i) through (iv) and post-deployment liability; and
(VI) the role of parental tools, family resources, digital literacy education, and federal support for such resources as components of a comprehensive child protection framework, including the relationship between technology-focused interventions and family-focused interventions, and whether federal investment in family-facing resources should accompany technology regulation.
(B) MANDATE.—TWG 6 shall execute its mandate in the phases of section 2005(b)(12) with respect to the subject matter set forth in subparagraph (A), as follows:
(i) DOMAIN EXAMINATION.—The investigations specified in subparagraph (A).
(ii) INTERVENTION EVALUATION.—For each area of investigation identified in subparagraph (A), the full range of possible federal responses from comprehensive statutory regulation to formal no-regulation findings, and the option of reliance on existing law, including in particular clinical standards for AI mental health tools; psychological harm measurement standards; AI companion system design prohibitions and required safety features for each age tier; algorithmic recommendation default standards for minor users; AI-generated CSAM detection and reporting standards; age verification and age assurance technical standards; mandatory crisis intervention protocols; duty of care standards; non-consensual intimate imagery prohibition standards; consent verification frameworks; disclosure standards for adult users of attachment-maximizing AI systems; liability frameworks for harms to minors; effectiveness-measurement methodologies; and family-facing resource investments.
(iii) TRADEOFF ASSESSMENT.—For each intervention evaluated under clause (ii), the effects on child safety and wellbeing outcomes; on the privacy and civil liberties of adults affected by child-protection infrastructure; on First Amendment-protected speech; on parental rights and family autonomy; on the availability of legitimate beneficial uses of related technologies for vulnerable populations; on innovation and competition in AI development for child-relevant applications; on enforcement feasibility and technical implementability; on the operational and compliance costs imposed on affected entities; and on the international competitive and coordination implications.
(iv) RECOMMENDATION DEVELOPMENT.—For each area of investigation identified in subparagraph (A), TWG 6 shall develop a recommendation in the form required by the chapeau of subparagraph (A). Each recommendation shall include—
(I) the selected form of recommendation and the rationale for its selection over the alternative forms available under the chapeau;
(II) where the selected form is draft statutory language, text in legislative form suitable for introduction, together with the supporting rationale;
(III) where the selected form is a directive for agency rulemaking, the agency designated, the scope and parameters of the directive, the statutory deadline for promulgation, and the supporting rationale;
(IV) where the selected form is a formal no-regulation finding, the rationale for the finding, including identification of any existing legal frameworks deemed adequate to address the subject matter and any voluntary or non-regulatory measures recommended in lieu of regulation; and
(V) treatment of the tradeoff considerations identified in clause (iii) as relevant to the area of investigation.
(C) SEED MEMBERS.—
(i) SENATE MAJORITY.—A career FTC official with COPPA enforcement and child privacy expertise.
(ii) SENATE MINORITY.—A career HHS official with child welfare and adolescent mental health expertise.
(iii) SPEAKER.—A career DOJ official from ICAC Task Force or FBI Crimes Against Children unit.
(iv) HOUSE MINORITY.—A career Department of Education official with student safety and technology expertise.
(D) REQUIRED COMPOSITION.—Notwithstanding the general size requirement of section 2005(b), TWG 6 shall be composed of not fewer than 15 members reflecting the breadth of its multi-domain mandate. In addition to the 4 seed members and the mandatory AI expertise requirements of section 2005(b)(1), TWG 6 shall include—
(i) AI TECHNICAL EXPERT — RECOMMENDATION AND COMPANION SYSTEMS.—A researcher or engineer with direct experience building or auditing recommendation algorithms, engagement optimization systems, or AI companion systems, with demonstrated understanding of how attachment-maximizing design features are implemented at the code level and what technical interventions are feasible and auditable.
(ii) DOMAIN-SPECIFIC AI HARM RESEARCHER.—A researcher with peer-reviewed empirical documentation of harms to minors from AI models or AI systems — algorithmic amplification of self-harm content, AI companion system psychological effects on adolescents, eating disorder or suicide content recommendation, or AI-generated CSAM.
(iii) FORMER PLATFORM AI SYSTEMS ENGINEER.—A former platform engineer or product designer with direct experience designing engagement systems, recommendation algorithms, or AI companion features, with ability to assess the technical feasibility of safe-by-design requirements.
(iv) LICENSED CHILD PSYCHIATRIST.—A licensed child and adolescent psychiatrist with clinical expertise in technology-related mental health disorders.
(v) LICENSED CHILD PSYCHOLOGIST.—A licensed child psychologist specializing in technology use and adolescent development.
(vi) PEDIATRIC NEUROSCIENTIST.—A pediatric neuroscientist or adolescent brain development researcher with expertise in the neurobiological mechanisms by which digital engagement systems affect developing brains.
(vii) EATING DISORDER TREATMENT CLINICIAN.—A licensed clinician with direct adolescent eating disorder treatment experience and familiarity with algorithmic content amplification.
(viii) SUICIDE PREVENTION SPECIALIST.—A licensed clinician or public health researcher specializing in adolescent suicide prevention and the relationship between social media and AI models or AI systems and suicide ideation.
(ix) LAW ENFORCEMENT CHILD SAFETY SPECIALIST.—A current or former law enforcement official with ICAC Task Force or FBI Crimes Against Children unit experience, with ability to assess whether proposed frameworks are operationally effective.
(x) CHILD SAFETY ORGANIZATION REPRESENTATIVE.—A representative from a child sexual abuse prevention organization, including NCMEC, Thorn, INHOPE, an academic child-safety center, or a State or local child-protection agency.
(xi) PLATFORM TRUST AND SAFETY PRACTITIONER.—A former or current platform trust and safety practitioner with direct minor-safety specialization.
(xii) PARENT ADVOCATE.—A representative of, or organized advocate for, families of minors who have suffered documented harm from AI systems or algorithmic systems.
(xiii) MEMBER UNDER 25.—A member under the age of 25 at the time of appointment, representing the perspective of the affected population; subject to the flexible participation carve-out under section 2005(a)(12)(C); full voting member.
(xiv) CHILD WELFARE POLICY EXPERT.—A child welfare policy expert with experience designing or evaluating federal child safety regulatory programs.
(xv) AGE VERIFICATION TECHNICAL EXPERT.—A technical expert in identity verification, age assurance, or privacy-preserving attestation, with direct experience designing or evaluating age or identity mechanisms for online platforms.
(xvi) MENTAL HEALTH POLICY EXPERT.—A mental health policy expert with experience in at least two of the following: Food and Drug Administration software-as-a-medical-device pathways, mental health parity laws, or digital mental health application policy, included to support the investigation under subparagraph (A)(i).
(xvii) PRIVACY LAW EXPERT.—A privacy law expert with academic or advocacy experience in consumer privacy law, identity verification and age verification privacy implications, and the relationship between child-protection infrastructure and adult privacy interests, included to support the investigations under subparagraphs (A)(ii)(V), (A)(iii), and (A)(v)(II).
(xviii) BENEFICIAL AI MENTAL HEALTH APPLICATIONS REPRESENTATIVE.—A clinician, researcher, or developer with direct experience in responsible development or clinical evaluation of AI mental health applications that have undergone clinical validation, serving adults or youth, with demonstrated engagement with developmental or safety considerations relevant to adolescent applicability, included to support the investigation under subparagraph (A)(v)(IV) and to ensure that the TWG's analysis distinguishes legitimate clinical applications from harmful companion systems.
(8) TWG 7 — WORKFORCE, LABOR, AND ECONOMIC TRANSITION.—
(A) DOMAIN OF INVESTIGATION.—TWG 7 shall conduct a comprehensive investigation of AI impacts on employment and the workforce, and on the basis of that investigation shall produce a recommendation on each area of investigation identified in this subparagraph. Each such recommendation shall take the form of (a) draft statutory language, (b) a directive for agency rulemaking with specified parameters, or (c) a formal no-regulation finding with supporting rationale. The selection of form, and the substantive direction of each recommendation, shall be determined by the TWG based on its investigation and its evaluation under subparagraph (B). The investigation shall include—
(i) A methodology for measuring job displacement attributable to AI models or AI systems, including—
(I) direct displacement through AI replacing roles within existing companies;
(II) indirect displacement through market-share capture by AI-native companies founded on or after January 1, 2026, resulting in equivalent job losses at incumbent firms;
(III) hiring suppression, defined as the reduction in entry-level and early-career job postings attributable to AI adoption, including the suppression of career entry points that have historically provided upward economic mobility;
(IV) task-level displacement, defined as the automation of a sufficient share of tasks within an occupation to constitute effective full-position elimination even without formal layoff; and
(V) decreases or increases in worker wellbeing, workload, or working hours.
(ii) An analysis of the rate of AI-attributable workforce turnover for employers of various sizes, including the pace and concentration of displacement timelines, and whether and at what threshold mandatory mitigation measures should be triggered.
(iii) Analysis of demographic disparate impacts over a ten-to-twenty-year horizon, including—
(I) the disproportionate displacement risk facing women, who may represent the highest-automation-risk administrative and clerical roles in the United States;
(II) whether there are disproportionate impacts on workers aged 20 through 30 years, in technology-exposed occupations;
(III) geographic concentration of displacement in communities with limited alternative employment opportunities; and
(IV) disparate impacts by race, ethnicity, age, disability status, and educational attainment.
(iv) Analysis of fiscal mechanisms to address workforce displacement and distribute the economic gains of AI deployment, including: taxation of AI-generated productivity gains exceeding defined thresholds; penalties or assessments on frontier AI developers and significant AI deployers whose deployments result in significant workforce reductions; requirements that AI-native companies or AI-deploying employers contribute to a dedicated potential "AI Workforce Transition Fund"; universal basic income and universal dividend frameworks funded by AI-generated productivity gains or by taxes on AI-deploying entities, including assessment of the adequacy of targeted transition assistance relative to universal distributions in the event that AI-driven displacement proves structural rather than transitional; and sovereign wealth fund or public equity stake models through which public ownership of AI infrastructure or AI-generated returns would provide a revenue base for broad-based distribution to all residents.
(v) An investigation of what levels and forms of transition funding and economic cushioning would be appropriate to address AI-attributable workforce displacement, including whether such transition funding is warranted, the appropriate differentiation by job category, skill level, geographic region, and demographic characteristics of affected workers, and the conditions under which targeted transition assistance, universal distributions, or hybrid frameworks are best suited to the scale and structure of any displacement identified under clauses (i) through (iv).
(vi) An assessment of retraining program models, apprenticeship frameworks, and public-private partnership structures best suited to support workers displaced by AI, including analysis of existing programs, including Trade Adjustment Assistance and the Workforce Innovation and Opportunity Act, and international models such as Singapore's SkillsFuture program and Germany's Arbeit 4.0 framework.
(vii) An assessment of the affirmative economic effects of AI deployment on employment and workforce productivity, including: documented cases where AI systems augment rather than replace workers, increasing individual and firm-level productivity while preserving employment; emerging job categories and occupational roles created by or dependent on AI deployment, including roles in AI development, maintenance, auditing, and oversight; productivity gains accruing to workers who use AI tools, and the distributional effects of those gains across income levels, sectors, and demographic groups; the macroeconomic conditions and policy environments, including: investment in worker AI literacy, access to AI tools by small businesses and independent workers, and public infrastructure for AI deployment, under which AI adoption generates net employment growth rather than net displacement; and international comparisons of labor market outcomes in economies with varying approaches to AI governance, with particular attention to whether restrictive regulatory environments correlate with worse or better outcomes for workers relative to more permissive frameworks.
(viii) An assessment of algorithmic management in the workplace, including AI-driven employee surveillance, performance scoring, scheduling, productivity tracking, and AI-driven hiring and discipline decisions; the documented effects of such practices on worker wellbeing, autonomy, and economic security; the adequacy of existing federal labor and civil rights law, including the NLRA, Title VII, the ADA, the ADEA, and the FLSA, to address AI-driven workplace management; and the design considerations bearing on any federal intervention.
(ix) An assessment of worker rights to notice, consultation, or bargaining over AI deployment decisions, including the adequacy of existing labor law frameworks, including the NLRA and related statutes, to address such rights; existing collective bargaining agreements that address AI deployment, including agreements in entertainment, transportation, journalism, and other sectors; international frameworks for technology consultation including European works council models; and the design considerations bearing on any federal expansion of worker voice in AI deployment.
(x) An assessment of the effects of AI on small businesses and self-employed workers, including effects on small businesses as employers (AI adoption barriers, competitive effects against AI-equipped large firms, productivity opportunities), effects on small businesses as users of AI (access, affordability, and capability gaps), and effects on independent contractors and sole proprietors competing in markets affected by AI deployment.
(xi) An assessment of the international and offshoring dimensions of AI workforce effects, including the use of AI to enable offshoring of knowledge work, the redistribution of work across national borders driven by AI deployment, and the implications for United States workforce policy of work that moves across jurisdictions in response to AI capability and regulatory differences.
(xii) Methodologies for measuring the effectiveness of workforce transition interventions, including metrics for assessing whether retraining programs, transition funding, fiscal redistribution mechanisms, and labor protections actually achieve their stated objectives, and the empirical evidence on past technological transition programs, including the documented mixed outcomes of Trade Adjustment Assistance, as a basis for designing forward-looking interventions.
(xiii) A synthesis integrating the findings of clauses (i) through (xii), addressing—
(aa) the relationship between displacement effects identified under clauses (i) through (iii) and the affirmative economic effects identified under clause (vii), and the methodologies appropriate for weighing the two against each other;
(bb) the long-term effects of varying intervention approaches on labor market structure, economic mobility, and the distribution of AI-generated gains across the workforce;
(cc) the temporal dimensions of these effects, distinguishing short-term displacement effects from long-term structural changes in labor demand; and
(dd) the relationship between technology-focused interventions (regulating AI deployment) and worker-focused interventions (supporting affected workers), and the conditions under which each is the appropriate locus of federal action.
(B) MANDATE.—TWG 7 shall execute its mandate in the phases of section 2005(b)(12) with respect to the subject matter set forth in subparagraph (A), as follows:
(i) DOMAIN EXAMINATION.—The investigations specified in subparagraph (A).
(ii) INTERVENTION EVALUATION.—For each area of investigation identified in subparagraph (A), the full range of possible federal responses from comprehensive statutory regulation to formal no-regulation findings, and the option of reliance on existing authorities, including in particular transition assistance, retraining, and income support frameworks; taxation of AI-generated productivity gains and fiscal redistribution mechanisms; labor rights in AI-managed workplaces, including algorithmic management protections; worker rights to notice, consultation, or bargaining over AI deployment; the adequacy of existing worker protection statutes; mechanisms to ensure AI economic gains are broadly shared; small business and independent worker support; and effectiveness-measurement methodologies for workforce transition interventions.
(iii) TRADEOFF ASSESSMENT.—For each intervention evaluated under clause (ii), the effects on AI deployment incentives, business investment, and overall economic growth; the distributional effects across workers by income, skill level, demographic group, and geographic region; the effects on worker autonomy, dignity, and economic security; the effects on small businesses and self-employed workers; the effects on the international competitive position of United States labor markets and the risks of offshoring; the operational and compliance costs imposed on employers and AI developers; and enforcement feasibility.
(iv) RECOMMENDATION DEVELOPMENT.—For each area of investigation identified in subparagraph (A), TWG 7 shall develop a recommendation in the form required by the chapeau of subparagraph (A). Each recommendation shall include—
(I) the selected form of recommendation and the rationale for its selection over the alternative forms available under the chapeau;
(II) where the selected form is draft statutory language, text in legislative form suitable for introduction, together with the supporting rationale;
(III) where the selected form is a directive for agency rulemaking, the agency designated, the scope and parameters of the directive, the statutory deadline for promulgation, and the supporting rationale;
(IV) where the selected form is a formal no-regulation finding, the rationale for the finding, including identification of any existing legal frameworks deemed adequate to address the subject matter and any voluntary or non-regulatory measures recommended in lieu of regulation; and
(V) treatment of the tradeoff considerations identified in clause (iii) as relevant to the area of investigation.
(C) SEED MEMBERS.—
(i) SENATE MAJORITY.—A career DOL economist with automation and labor displacement expertise.
(ii) SENATE MINORITY.—A career Treasury or CEA economist with AI macroeconomic impact expertise.
(iii) SPEAKER.—A career ETA official with worker transition program expertise.
(iv) HOUSE MINORITY.—A career NLRB or EEOC official with AI workplace and labor rights expertise.
(D) REQUIRED COMPOSITION.—In addition to the 4 seed members and the mandatory AI expertise requirements of section 2005(b)(1), TWG 7 shall include—
(i) AI TECHNICAL EXPERT — WORKPLACE AUTOMATION.—A researcher or engineer with direct experience building or evaluating AI models or AI systems used in workplace automation (robotic process automation, agentic task execution, AI coding assistants, or AI-driven logistics) with demonstrated understanding of which tasks are automatable at current capability levels and what the near-term automation frontier looks like.
(ii) DOMAIN-SPECIFIC AI HARM RESEARCHER.—A researcher with peer-reviewed empirical documentation of workforce displacement from AI deployment — sector-level employment effects, wage suppression, task substitution patterns, or differential impacts by income, education, race, or geography.
(iii) AGENTIC AI SYSTEMS RESEARCHER.—A researcher with direct expertise in agentic AI systems and their capacity for autonomous task completion across knowledge work domains.
(iv) LABOR DISPLACEMENT ECONOMIST.—A labor economist specializing in technological displacement, with peer-reviewed work on automation and employment effects.
(v) ORGANIZED LABOR REPRESENTATIVE.—A representative of organized labor with direct experience representing workers in AI-exposed industries.
(vi) WORKER RETRAINING SPECIALIST.—A workforce development specialist with direct experience designing or operating worker retraining or community college workforce programs.
(vii) INDEPENDENT WORKER REPRESENTATIVE.—A representative of independent workers, freelancers, or gig economy workers.
(viii) TAX POLICY ECONOMIST.—A public-finance economist with peer-reviewed or documented work on taxing automation, capital income, robot taxation, technology-driven redistribution, or equivalent fiscal distribution mechanisms.
(ix) COMMUNITY DEVELOPMENT SPECIALIST.—A community development specialist with direct experience in deindustrialized or economically displaced regions.
(x) LARGE EMPLOYER PRACTITIONER.—A human resources or future of work practitioner from a large employer with direct experience managing AI-driven workforce transitions.
(xi) SOCIAL SAFETY NET EXPERT.—A social safety net or income support policy expert with expertise in programs for workers displaced by technological change.
(xii) AI WORKFORCE EQUITY RESEARCHER.—A researcher with peer-reviewed or equivalent documented empirical documentation of the differential impacts of automation, algorithmic management, or AI-driven hiring and employment decisions on workers by race, ethnicity, gender, disability status, age, or immigration status, with familiarity with civil rights frameworks applicable to AI-driven employment practices.
(xiii) LABOR DATA SCIENTIST.—An economist or statistician with direct data science skills — including fluency in large administrative dataset analysis, machine learning applications in labor economics, and quantitative methods for measuring task-level and occupation-level automation exposure; preferred: documented applied work producing original empirical estimates of AI or automation impact on employment, wages, or workforce composition.
(xiv) EMPIRICAL SKEPTIC LABOR RESEARCHER.—A researcher with peer-reviewed or equivalent documented empirical work questioning, qualifying, or contextualizing the claimed magnitude or pace of AI-driven workforce displacement, including work on the gap between projected and observed displacement effects, the empirical evidence on AI as a complement to versus substitute for labor in specific occupational categories, the methodological challenges in attributing employment changes to AI as distinguished from other economic factors, or the historical record of technological transition predictions, included to ensure that the TWG's evidentiary record reflects the genuine state of empirical disagreement rather than a single research consensus.
(xv) LABOR LAW SCHOLAR.—A labor law scholar with peer-reviewed work on the National Labor Relations Act, federal worker protection statutes, or the legal frameworks governing employer-employee relationships in the context of technological change, included to support the investigations of existing law gaps under subparagraphs (A)(viii) and (A)(ix) and the design of any statutory recommendations.
(xvi) FRONTIER AI DEVELOPER REPRESENTATIVE.—A former engineer, product lead, or policy lead from a frontier AI developer, a significant AI deployer, or a major cloud or compute provider, with direct operational experience in AI capability development, deployment to enterprise customers, or workforce-relevant AI products, and the ability to assess the operational and competitive effects of proposed workforce-related interventions, tax and fiscal mechanisms targeting AI developers, and disclosure or notification regimes; a currently-employed individual shall serve in a non-voting advisory capacity with full disclosure under section 2005(a)(8).
(9) TWG 8 — ENVIRONMENTAL, ENERGY, AND COMMUNITY IMPACT.—
(A) DOMAIN OF INVESTIGATION.—TWG 8 shall conduct a comprehensive investigation of environmental and community impacts of AI data centers, and on the basis of that investigation shall produce a recommendation on each area of investigation identified in this subparagraph. Each such recommendation shall take the form of (a) draft statutory language, (b) a directive for agency rulemaking with specified parameters, or (c) a formal no-regulation finding with supporting rationale. The selection of form, and the substantive direction of each recommendation, shall be determined by the TWG based on its investigation and its evaluation under subparagraph (B). The investigation shall include—
(i) Environmental impact assessments for large AI data centers, including—
(I) measured and projected impacts on water quality and water availability, including on-site water consumption and indirect water consumption from fossil fuel power generation, with the Federal Government's estimate of 211 billion gallons of indirect water consumption from United States data centers in 2023 used as a baseline;
(II) energy consumption impacts and projected trajectories, informed by the International Energy Agency's findings that a typical AI data center uses as much electricity as 100,000 households and that data centers are projected to account for approximately 10 percent of global electricity demand growth through 2030;
(III) air quality impacts from diesel generator emissions during grid stress events, including documented links to respiratory disease and cancer risk in communities near data center clusters where 82 percent of California data centers are located in communities already experiencing poor air quality;
(IV) noise impacts on residential communities from cooling systems; and
(V) cumulative community impacts, including the documented phenomenon of data center electricity infrastructure costs being borne by entire service territories while tax revenues accrue only to host communities.
(ii) Whether and how federal law should require standards for measuring and reporting the energy and water efficiency of data centers, including—
(I) the appropriate scope, threshold, and timeline of any Power Usage Effectiveness (PUE) reporting requirement, including consideration of industry-standard PUE benchmarks and the design considerations bearing on threshold setting for new construction and existing facilities;
(II) the appropriate scope and threshold of any Water Usage Effectiveness (WUE) reporting requirement, including consideration of the current industry average of 1.9 liters per kilowatt-hour as a baseline and the design considerations bearing on threshold setting; and
(III) evaluation of mandates for renewable energy procurement and 24/7 carbon-free energy matching, including the appropriate scope of any such requirements and the technical and economic considerations bearing on their feasibility.
(iii) Analysis of water use permitting, environmental review under the National Environmental Policy Act, and community impact assessment requirements for data center construction, with prioritization of residential water access in drought-prone and water-stressed regions.
(iv) Assessment of utility regulation mechanisms to prevent AI companies from externalizing energy infrastructure costs onto residential ratepayers, including requirements that AI companies build or fund dedicated energy infrastructure and analysis of the documented finding that residential electricity prices increased 7.1 percent in 2025 (more than double the inflation rate) in part due to data center electricity demand.
(v) Whether and how federal law should restrict the siting of new large AI data centers in environmental justice communities or communities already exceeding EPA air quality standards, including the appropriate scope of any such restriction, the role of affirmative community benefit agreements negotiated with affected residents, and the relationship between federal siting requirements and existing State and local land use authority.
(vi) International and comparative approaches to data center environmental regulation, including the European Union Energy Efficiency Directive provisions for data centers, the Irish and Dutch grid connection moratoria, the Singapore data center moratorium and subsequent capacity allocation framework, and the observed effects of each approach on data center development activity, environmental outcomes, and the geographic distribution of AI infrastructure.
(vii) Methodologies for measuring the effectiveness of data center environmental and community-impact interventions, including metrics for assessing whether efficiency standards, siting requirements, cost-allocation mechanisms, and reporting obligations actually reduce the harms they are designed to address; the empirical evidence on existing efficiency-standard programs in the European Union and other jurisdictions; and the conditions under which such interventions succeed or fail.
(viii) A synthesis integrating the findings of clauses (i) through (vii), addressing—
(aa) the relationship between environmental and community harms identified in clauses (i), (iii), (iv), and (v) and the technical and economic considerations bearing on AI infrastructure development;
(bb) the methodologies appropriate for weighing community-protection interests against AI infrastructure capacity needs;
(cc) the international and geographic dimensions of regulation, including whether stringent United States data center regulation would shift AI infrastructure development to other jurisdictions and the environmental and community implications of such shifts; and
(dd) the temporal dimensions of these effects, distinguishing near-term grid stress and community impact effects from long-term effects on infrastructure investment, climate outcomes, and community development.
(B) MANDATE.—TWG 8 shall execute its mandate in the phases of section 2005(b)(12) with respect to the subject matter set forth in subparagraph (A), as follows:
(i) DOMAIN EXAMINATION.—The investigations specified in subparagraph (A).
(ii) INTERVENTION EVALUATION.—For each area of investigation identified in subparagraph (A), the full range of possible federal responses from comprehensive statutory regulation to formal no-regulation findings, and the option of reliance on existing EPA, FERC, and DOE authority, including in particular environmental impact assessment standards; water consumption disclosure and limitation standards; energy efficiency reporting and threshold standards; electricity demand and grid reliability frameworks; ratepayer cost allocation mechanisms; carbon footprint measurement and disclosure; renewable energy procurement requirements; siting restrictions for environmental justice communities; community benefit agreement frameworks; and effectiveness-measurement methodologies.
(iii) TRADEOFF ASSESSMENT.—For each intervention evaluated under clause (ii), the effects on environmental and community outcomes, including water consumption, air quality, grid reliability, and environmental justice impacts on host communities; on AI infrastructure development and the geographic distribution of AI capacity; on energy costs and reliability for residential and commercial ratepayers; on State and local land use authority and existing permitting frameworks; on the operational and compliance costs imposed on data center operators and AI deployers; on the international competitive position of United States AI infrastructure and the risks of regulatory arbitrage; and on enforcement feasibility.
(iv) RECOMMENDATION DEVELOPMENT.—For each area of investigation identified in subparagraph (A), TWG 8 shall develop a recommendation in the form required by the chapeau of subparagraph (A). Each recommendation shall include—
(I) the selected form of recommendation and the rationale for its selection over the alternative forms available under the chapeau;
(II) where the selected form is draft statutory language, text in legislative form suitable for introduction, together with the supporting rationale;
(III) where the selected form is a directive for agency rulemaking, the agency designated, the scope and parameters of the directive, the statutory deadline for promulgation, and the supporting rationale;
(IV) where the selected form is a formal no-regulation finding, the rationale for the finding, including identification of any existing legal frameworks deemed adequate to address the subject matter and any voluntary or non-regulatory measures recommended in lieu of regulation; and
(V) treatment of the tradeoff considerations identified in clause (iii) as relevant to the area of investigation.
(C) SEED MEMBERS.—
(i) SENATE MAJORITY.—A career EPA official with data center environmental assessment expertise.
(ii) SENATE MINORITY.—A career FERC official with grid interconnection and electricity demand expertise.
(iii) SPEAKER.—A career DOE official with data center energy efficiency expertise.
(iv) HOUSE MINORITY.—A career Environmental Justice official with community health and disparate impact expertise.
(D) REQUIRED COMPOSITION.—In addition to the 4 seed members and the mandatory AI expertise requirements of section 2005(b)(1), TWG 8 shall include—
(i) AI TECHNICAL EXPERT — DATA CENTER INFRASTRUCTURE.—A data center infrastructure engineer or researcher with direct experience designing, operating, or auditing large-scale AI computing facilities, with demonstrated technical understanding of GPU thermal management, cooling system architecture, PUE, WUE, and actual energy and water consumption profiles of frontier AI training and inference at scale.
(ii) DOMAIN-SPECIFIC AI HARM RESEARCHER.—A researcher with documented or quantitative analysis of environmental and community harms from data center development — water consumption, grid stress effects, ratepayer cost impacts, air quality effects, or environmental justice impacts on host communities.
(iii) GRID SYSTEMS ENGINEER.—A grid systems engineer or electricity market researcher with technical understanding of how large data center loads interact with grid reliability, renewable energy procurement, and electricity pricing.
(iv) ENVIRONMENTAL SCIENTIST.—An environmental scientist specializing in water consumption and AI data center impacts.
(v) ENVIRONMENTAL JUSTICE ADVOCATE.—A representative of or advocate for a community near a large AI data center cluster with direct experience documenting environmental justice impacts.
(vi) RENEWABLE ENERGY DEVELOPER.—A renewable energy developer or engineer with direct experience in data center siting and power purchase agreements.
(vii) COMMUNITY HEALTH RESEARCHER.—A public health researcher specializing in air quality and community health impacts of industrial facilities.
(viii) STATE UTILITY REGULATOR OR RATEPAYER ADVOCATE.—A state utility regulator or ratepayer advocate with direct experience in electricity rate proceedings affected by large industrial loads.
(ix) DATA CENTER SUSTAINABILITY EXPERT.—A data center operator or sustainability officer with direct experience implementing energy efficiency, water conservation, and renewable procurement programs.
(x) CLIMATE SCIENTIST.—A climate scientist or carbon footprint researcher with expertise in ICT or data center carbon accounting and lifecycle assessment.
(xi) FORMER LOCAL GOVERNMENT OFFICIAL.—A former municipal or county official, or a currently serving appointed non-elected official, from a data center host community; currently serving elected local officials are excluded due to statutory duties incompatible with full-time service.
(xii) INTERNATIONAL AND COMPARATIVE ENVIRONMENTAL REGULATION EXPERT.—A scholar or practitioner with peer-reviewed work or direct policy experience on data center environmental regulation in one or more jurisdictions with established or proposed data center regulatory frameworks, and the comparative effects of varying national approaches on data center development activity and environmental outcomes, included to support the comparative investigation under subparagraph (A)(vi).
(xiii) DATA-CENTER ENERGY MEASUREMENT RESEARCHER.—A researcher with documented empirical work measuring data-center energy and water consumption, ratepayer impacts, and efficiency trends, including AI-workload attribution.
(10) TWG 9 — LIABILITY, ACCOUNTABILITY, LEGAL FRAMEWORKS, AND CONSTITUTIONAL DIMENSIONS.—
(A) DOMAIN OF INVESTIGATION.—TWG 9 shall conduct a comprehensive investigation of liability and accountability frameworks, legal frameworks for AI systems, and the constitutional dimensions of federal AI regulation, and on the basis of that investigation shall produce a recommendation on each area of investigation identified in this subparagraph. Each such recommendation shall take the form of (a) draft statutory language, (b) a directive for agency rulemaking with specified parameters, or (c) a formal no-regulation finding with supporting rationale. The selection of form, and the substantive direction of each recommendation, shall be determined by the TWG based on its investigation and its evaluation under subparagraph (B). The investigation shall include—
(i) An assessment of the feasibility of a liability framework treating AI models or AI systems as products subject to existing consumer safety law, including strict liability for defined categories of harm and meaningful discovery rights for affected parties.
(ii) Analysis of strategies by which entities may attempt to evade accountability by characterizing AI models or AI systems as autonomous agents or corporate persons rather than products, and recommendations for legislative language to foreclose such evasion if it is deemed a threat to civil liberties and accountability.
(iii) Determination of appropriate liability allocation among frontier model developers, downstream developers, deployers, and end users for harms attributable to AI models or AI systems, including analysis of the EU AI Act's liability directive framework as a comparative model.
(iv) Assessment of the adequacy of Section 230 of the Communications Decency Act (47 U.S.C. § 230) as applied to AI-generated content and AI system outputs, and whether legislative modifications would be appropriate to address AI-specific harms, and if so, the appropriate scope of such modifications.
(v) An investigation of AI legal personhood and standing, including whether AI models or AI systems may hold intellectual property, bear liability, or have legal interests cognizable by courts or Congress; the theoretical and doctrinal frameworks bearing on legal personhood for non-human entities; the practical consequences of recognizing or declining to recognize any form of AI legal status; and the relationship between legal personhood questions and the liability allocation analysis under clause (iii).
(vi) An investigation of the constitutional landscape governing federal AI regulation, including First Amendment constraints on AI content mandates, disclosure requirements, compelled speech, and algorithmic transparency obligations across all domains investigated by this title's Technical Working Groups; federalism and preemption considerations bearing on the relationship between federal AI legislation and State law; the application of prevailing First Amendment doctrine to compelled disclosure and content moderation requirements imposed on AI developers and deployers; and the constitutional parameters within which the recommendations of this Technical Working Group and other Technical Working Groups must operate.
(vii) An investigation of private rights of action as a federal AI accountability mechanism, including the appropriate scope of any private right of action under federal AI legislation, the relationship between private rights of action and agency enforcement, the standing and pleading requirements appropriate to AI-driven harms, and the comparative experience of private rights of action under existing federal civil rights, consumer protection, and product liability statutes.
(viii) An investigation of algorithmic discrimination and civil rights enforcement, including the application of Title VII of the Civil Rights Act of 1964, the Americans with Disabilities Act, the Age Discrimination in Employment Act, the Fair Housing Act, the Equal Credit Opportunity Act, and related civil rights statutes to algorithmic and AI-driven decision-making in the employment, credit, housing, healthcare, and criminal justice domains; the adequacy of disparate-impact doctrine and existing enforcement frameworks to address AI-specific discrimination; the operational and compliance considerations bearing on the application of these statutes to AI-driven decision-making; and the design considerations bearing on any federal expansion of civil rights enforcement for AI-driven discrimination.
(ix) An investigation of the use of AI in legal proceedings, including the evidentiary standards applicable to AI-generated evidence and analysis, the treatment of deepfakes and synthetic media in civil and criminal proceedings, the application of expert-testimony standards to AI-assisted analyses, and AI-assisted investigation, prosecution, and defense, with particular attention to safeguards for the rights of the accused.
(x) An investigation of corporate governance and board-level accountability for AI deployment, including the fiduciary duties of corporate officers and directors with respect to AI deployment and risk management, the appropriate scope of any disclosure obligations to shareholders and regulators regarding AI deployment and AI-related risks, and the relationship between corporate governance frameworks and the liability allocation analysis under clause (iii).
(xi) An investigation of international harmonization of AI liability standards, including the EU AI Act and AI Liability Directive frameworks, the developing AI liability frameworks of other jurisdictions, the implications of jurisdictional differences for cross-border AI deployment, and the design considerations bearing on any United States position on international harmonization.
(xii) An investigation of healthcare AI liability specifically, including the application of medical malpractice and products liability doctrine to AI diagnostic and clinical decision-support systems, the standard of care for AI-assisted medical decisions, the allocation of liability between AI developers and clinicians, and the relationship between healthcare AI liability frameworks and existing Food and Drug Administration authority over AI medical devices.
(xiii) Methodologies for measuring the effectiveness of AI liability and accountability regimes, including metrics for assessing whether liability allocation, private rights of action, civil rights enforcement, and disclosure obligations actually achieve their stated objectives, and the empirical evidence on comparable liability and accountability regimes in other technology domains.
(xiv) An investigation of AI systems as instruments of speech suppression, including the use of AI models to classify, rank, demote, or remove lawful expression on any platform; the procurement or use of such systems by any Federal, State, tribal, or local government agency or instrumentality to identify or suppress lawful speech; the extent to which model refusal or output skew tracks the viewpoint expressed rather than a documented safety rationale; whether such conduct is attributable to the State; and the feasibility of auditing and disclosing such behavior.
(xv) A synthesis integrating the findings of clauses (i) through (xiv), addressing—
(aa) the relationship between liability allocation, regulatory accountability, and private enforcement mechanisms in producing an integrated AI accountability framework;
(bb) the relationship between constitutional constraints identified under clause (vi) and the substantive accountability mechanisms evaluated under the other clauses;
(cc) the relationship between AI legal personhood questions under clause (v) and liability allocation under clause (iii); and
(dd) the temporal dimensions of accountability framework design, including the relationship between near-term liability framework needs and the longer-term evolution of AI capabilities and legal personhood questions.
(B) MANDATE.—TWG 9 shall execute its mandate in the phases of section 2005(b)(12) with respect to the subject matter set forth in subparagraph (A), as follows:
(i) DOMAIN EXAMINATION.—The investigations specified in subparagraph (A).
(ii) INTERVENTION EVALUATION.—For each area of investigation identified in subparagraph (A), the full range of possible federal responses from comprehensive statutory regulation to formal no-regulation findings, and the option of reliance on existing common law and statutory frameworks, including in particular product liability frameworks for AI systems; strict liability versus negligence standards; private rights of action; algorithmic discrimination and civil rights enforcement frameworks; standards for AI evidence in legal proceedings; corporate governance and board-level accountability mechanisms; international harmonization of AI liability standards; healthcare AI liability frameworks; constitutional and federalism constraints on AI content mandates and disclosure requirements; and effectiveness-measurement methodologies.
(iii) TRADEOFF ASSESSMENT.—For each intervention evaluated under clause (ii), the effects on AI innovation incentives and the structure of AI development in the United States; on insurance markets and the availability of AI liability coverage; on access to justice for parties harmed by AI systems; on the operational and compliance costs imposed on AI developers and deployers; on the constitutional rights of regulated entities and affected individuals; on the allocation of authority between federal and State governments; on the structure and capacity of federal agencies tasked with enforcement; on the international competitive position of United States AI developers; and on enforcement feasibility.
(iv) RECOMMENDATION DEVELOPMENT.—For each area of investigation identified in subparagraph (A), TWG 9 shall develop a recommendation in the form required by the chapeau of subparagraph (A). Each recommendation shall include—
(I) the selected form of recommendation and the rationale for its selection over the alternative forms available under the chapeau;
(II) where the selected form is draft statutory language, text in legislative form suitable for introduction, together with the supporting rationale;
(III) where the selected form is a directive for agency rulemaking, the agency designated, the scope and parameters of the directive, the statutory deadline for promulgation, and the supporting rationale;
(IV) where the selected form is a formal no-regulation finding, the rationale for the finding, including identification of any existing legal frameworks deemed adequate to address the subject matter and any voluntary or non-regulatory measures recommended in lieu of regulation; and
(V) treatment of the tradeoff considerations identified in clause (iii) as relevant to the area of investigation.
(C) SEED MEMBERS.—
(i) SENATE MAJORITY.—Shall appoint a career DOJ Civil Division attorney with technology liability and administrative law expertise.
(ii) SENATE MINORITY.—Shall appoint a career FTC attorney with consumer protection and AI enforcement expertise.
(iii) SPEAKER.—Shall appoint a career EEOC attorney with algorithmic discrimination and civil rights enforcement expertise.
(iv) HOUSE MINORITY.—Shall appoint a career ACUS or OLC official with regulatory design and administrative procedure expertise.
(D) REQUIRED COMPOSITION.—In addition to the 4 seed members and the mandatory AI expertise requirements of section 2005(b)(1), TWG 9 shall include—
(i) AI TECHNICAL EXPERT — FAILURE MODES AND AUDITING.—A researcher or engineer with direct experience auditing AI systems for failure modes (distribution shift failures, hallucination patterns, adversarial vulnerabilities, and output unreliability) with demonstrated understanding of how AI failures differ technically from conventional product failures.
(ii) DOMAIN-SPECIFIC AI HARM RESEARCHER.—A researcher with peer-reviewed empirical documentation of concrete harms caused by deployed AI systems, including wrongful denials of benefits, biased decisions, medical misdiagnosis, wrongful arrests from facial recognition, content moderation errors, due process failures in algorithmic adjudication, or other documented categories of AI-caused harm.
(iii) AI DEPLOYMENT LIFECYCLE EXPERT.—A software engineering or systems reliability expert with direct understanding of AI system deployment lifecycles — versioning, updates, fine-tuning, and how production AI systems evolve after initial deployment.
(iv) PRODUCTS LIABILITY SCHOLAR.—A products liability or tort law scholar with demonstrated expertise in AI and autonomous systems liability.
(v) ADMINISTRATIVE LAW SCHOLAR.—An administrative law scholar with expertise in rulemaking design, enforcement architecture, and administrative procedure implications of AI regulation, including familiarity with the major contested doctrines bearing on the design and constitutional durability of any federal AI regulatory regime, including Chevron deference and its successors, the major questions doctrine, nondelegation, and federal preemption of State law. The appointing authority shall not screen for adherence to any particular methodological school within administrative law.
(vi) PLAINTIFF-SIDE ALGORITHMIC DISCRIMINATION ATTORNEY.—A civil rights attorney specializing in algorithmic discrimination with direct plaintiff-side litigation or investigation experience, with demonstrated familiarity with disparate impact doctrine and the application of federal civil rights statutes to algorithmic and AI-driven decision-making.
(vii) DEFENSE-SIDE OR COMPLIANCE-SIDE ALGORITHMIC DISCRIMINATION ATTORNEY.—An attorney with direct experience defending algorithmic discrimination claims or advising AI developers and deployers on compliance with federal civil rights statutes, with demonstrated familiarity with the operational and compliance challenges of applying disparate impact doctrine to AI-driven decision-making.
(viii) AI RISK ACTUARY.—An insurance or actuarial professional with direct experience quantifying or pricing cyber or emerging-technology risk, with demonstrated capacity to assess AI liability.
(ix) HEALTHCARE AI LIABILITY EXPERT.—A healthcare liability attorney or medical professional with expertise in AI diagnostic liability and the standard of care for AI-assisted medical decisions.
(x) CRIMINAL LAW SCHOLAR.—A criminal law scholar with expertise in one or more of: AI evidence admissibility, deepfakes in criminal proceedings, or AI-assisted crime.
(xi) CORPORATE GOVERNANCE ATTORNEY.—A corporate governance attorney with direct experience advising boards on AI deployment, risk management, accountability, and director liability.
(xii) INTERNATIONAL COMPARATIVE LAW SCHOLAR.—A comparative law scholar with expertise in international AI liability and regulatory frameworks, with familiarity with the regulatory approach of the European Union, including the EU AI Act and AI Liability Directive, and at least one of the more market-oriented approaches of jurisdictions such as the United Kingdom, Singapore, or Japan, included to ensure the TWG's analysis reflects the range of international regulatory models rather than presupposing any particular approach.
(xiii) FIRST AMENDMENT SCHOLAR.—A constitutional law scholar with demonstrated expertise in First Amendment doctrine as applied to compelled speech, disclosure mandates, content moderation, and government regulation of expressive technologies, with peer-reviewed or equivalent published work on the constitutional parameters of regulating algorithmic or AI-generated content. The appointing authority shall not screen for adherence to any particular methodological school within First Amendment scholarship.
(xiv) LEGAL PHILOSOPHER — PERSONHOOD AND MORAL STATUS.—A legal philosopher or jurisprudential scholar with peer-reviewed or documented work on theories of legal personhood, moral status, or the extension of legal rights and capacities to non-human entities, with demonstrated capacity to engage AI-specific questions of agency, responsibility, and legal standing.
(11) TWG 10 — AI SECURITY, CRITICAL INFRASTRUCTURE, AND INCIDENT RESPONSE.—
(A) DOMAIN OF INVESTIGATION.—TWG 10 shall conduct a comprehensive investigation covering AI security and infrastructure and agentic AI systems, and on the basis of that investigation shall produce a recommendation on each area of investigation identified in this subparagraph. Each such recommendation shall take the form of (a) draft statutory language, (b) a directive for agency rulemaking with specified parameters, or (c) a formal no-regulation finding with supporting rationale. The selection of form, and the substantive direction of each recommendation, shall be determined by the TWG based on its investigation and its evaluation under subparagraph (B). The investigation shall include—
(i) AI SECURITY AND INFRASTRUCTURE.—
(I) Standards for data center safety retrofitting, including consideration of hardware-level compute monitoring, tamper-proof verification systems, and auditable training logs for large training facilities.
(II) Feasibility of planetary-scale monitoring infrastructure, including satellite heat-mapping of compute centers analogous to International Atomic Energy Agency nuclear facility inspection regimes, to detect hidden or unauthorized training runs, including analysis of proposals developed by the Future of Humanity Institute, the Center for AI Safety, and the RAND Corporation.
(III) Design of circuit-breaker and external override systems for high-capability frontier models, including government authority to suspend, pause, or disable compute clusters implicated in treaty violations or safety breaches, including analysis of the technical feasibility of cryptographic controls and remote attestation.
(IV) Feasibility of automatic moratorium triggers activated when deployed models demonstrate unexpected or unauthorized capability thresholds through post-deployment monitoring.
(V) Design of an aviation-style incident reporting and investigation system, analogous to the National Transportation Safety Board, for AI harms, near misses, and operational anomalies, including mandatory reporting protocols and non-punitive safe harbor provisions designed to maximize reporting completeness.
(VI) Assessment of AI-enabled cybersecurity threats to critical infrastructure sectors, informed by documented AI cyberoffense capabilities, and recommendations for sector-specific AI security standards.
(ii) AGENTIC AI SYSTEMS.—
(I) Whether and how federal law should require AI agentic system providers to operate in the interest of the user, including the appropriate scope, substantive content, and disclosure requirements of any obligation regarding conflicts of interest, undisclosed commercial arrangements, or ulterior motives in system behavior or recommendations.
(II) Analysis of disclosure requirements, user-consent frameworks, and whether fiduciary-like obligations are appropriate for AI agents taking actions with real-world consequences on behalf of individuals, including financial transactions, legal commitments, communications, and healthcare decisions.
(III) Development of technical safeguard standards for agentic AI systems, including—
(aa) human-in-the-loop requirements calibrated to the reversibility and consequence level of the action being taken;
(bb) mandatory action logging and audit trail requirements;
(cc) reversibility requirements for actions in defined consequence categories;
(dd) sandboxing and scope limitation requirements preventing agentic systems from accessing systems or data beyond those required for the specified task;
(ee) mandatory shutdown and override mechanisms operable by the user at any stage of an agentic workflow; and
(ff) early detection and shutdown mechanisms related to instrumental convergence capabilities.
(IV) Analysis of governance challenges created by multi-agent orchestration systems in which the outputs of one AI system serve as inputs to another, including liability allocation across agent chains and the risk of emergent harmful behaviors in multi-agent systems that do not appear in individual model evaluations.
(V) An assessment of the affirmative role of agentic AI systems as instruments of individual autonomy, democratic participation, and resistance to institutional power asymmetries, including — the capacity of agentic AI systems to enable individuals to navigate complex legal, financial, medical, and bureaucratic systems without dependence on institutional intermediaries whose interests may conflict with those of the individual; the capacity of agentic AI systems to serve as tools of democratic accountability by enabling citizens, journalists, and civil society organizations to monitor government conduct, analyze public records, investigate corruption, and organize collective action at a scale and speed previously available only to well-resourced institutions; the potential for agentic AI systems to reduce the information and capability asymmetry between individuals and large institutions, including corporations, government agencies, and financial intermediaries, that currently disadvantages individuals in disputes, negotiations, and regulatory proceedings; and the historical and contemporary examples of autonomous information-processing tools, including investigative databases, open-source intelligence platforms, and encrypted communications, that have served democratic functions by distributing analytical capability beyond the control of centralized authority.
(VI) An assessment of the risks that agentic AI systems may be designed, deployed, or co-opted as instruments of mass persuasion, coordinated manipulation, or social control, including — the capacity of autonomous AI agents to conduct sustained, adaptive influence campaigns across social media platforms, messaging applications, and other communications channels without human direction for each individual interaction; the risk that agentic AI systems with access to personal data, behavioral profiles, and real-time engagement metrics may be used to construct individualized persuasion architectures that exploit the specific psychological vulnerabilities, beliefs, and social connections of each target; the specific risks created by multi-agent orchestration systems in which multiple AI agents coordinate persuasion campaigns, simulate grassroots movements, or manufacture the appearance of organic public consensus; and whether the technical safeguard standards required by subclause (III), including scope limitation, action logging, and shutdown mechanisms, are sufficient to prevent the deployment of agentic AI as a mass persuasion instrument, or whether additional prohibitions or structural safeguards are required.
(VII) An assessment of whether the governance framework for agentic AI systems adequately preserves the autonomy-enhancing and democracy-supporting functions identified in subclause (V) while addressing the manipulation risks identified in subclause (VI), including — whether any proposed restriction on agentic AI capability, scope, or autonomy would, if applied, disproportionately reduce the capacity of individuals and civil society to use agentic AI for the democratic functions identified in subclause (V) while leaving institutional actors with superior access to equivalent capability; and whether the governance framework should incorporate an explicit presumption that agentic AI capability available to institutions shall be available to individuals on comparable terms, absent a specific and documented safety justification for asymmetric access.
(VIII) An assessment of regulatory safe harbor frameworks that would enable responsible agentic AI deployment in high-productivity domains, including healthcare, legal services, scientific research, and financial analysis, while maintaining user-protection standards, and governance mechanisms that would ensure the productivity gains from agentic AI are broadly accessible rather than concentrated among large enterprises with the resources to develop proprietary agentic systems.
(iii) CROSS-CUTTING INVESTIGATION AREAS.—
(I) Methodologies for measuring the effectiveness of interventions across the AI security and agentic AI domains, including metrics for assessing whether security standards, incident reporting requirements, technical safeguards, and governance frameworks actually reduce the harms they are designed to address.
(II) The international dimensions of AI security and agentic AI governance, including cross-jurisdictional AI security threats, international coordination on AI security standards, the comparative regulatory treatment of agentic AI systems in the European Union and other jurisdictions, and the implications of jurisdictional differences for United States policy.
(III) A synthesis integrating the findings across the AI security and agentic AI domains, addressing the relationship between security-focused interventions and autonomy-preserving interventions, and the conditions under which the two sets of interventions reinforce or conflict with each other.
(B) MANDATE.—TWG 10 shall execute its mandate in the phases of section 2005(b)(12) with respect to the subject matter set forth in subparagraph (A), as follows:
(i) DOMAIN EXAMINATION.—The investigations specified in subparagraph (A).
(ii) INTERVENTION EVALUATION.—For each area of investigation identified in subparagraph (A), the full range of possible federal responses from comprehensive statutory regulation to formal no-regulation findings, and the option of reliance on existing authorities, including in particular AI-specific cybersecurity standards for critical infrastructure; mandatory AI incident reporting standards; AI system supply chain security requirements; sector-specific AI security requirements for energy, water, healthcare, and financial infrastructure; international coordination on AI security standards; hardware-level compute monitoring and tamper-proof verification systems; aviation-style AI incident reporting modeled on the NTSB; user-protection requirements for agentic AI providers; disclosure requirements, user-consent frameworks, and fiduciary-like obligations for AI agents; technical safeguard standards for agentic AI systems; governance of multi-agent orchestration systems; regulatory safe harbor frameworks for high-productivity agentic AI deployment; and effectiveness-measurement methodologies.
(iii) TRADEOFF ASSESSMENT.—For each intervention evaluated under clause (ii), the effects on AI deployment in critical sectors and on agentic AI innovation; on international competitiveness and the geographic distribution of AI development; the tradeoffs between user-protection mandates and the flexibility required to realize agentic AI productivity gains at scale; the distributional effects on access to agentic AI tools across firm size, sector, and income level; on the autonomy-enhancing and democratic-accountability functions of agentic AI identified in subparagraph (A)(ii)(V); on the operational and compliance costs imposed on AI developers and deployers; on constitutional parameters for user-protection mandates and content-related restrictions; and on enforcement feasibility.
(iv) RECOMMENDATION DEVELOPMENT.—For each area of investigation identified in subparagraph (A), TWG 10 shall develop a recommendation in the form required by the chapeau of subparagraph (A). TWG 10 shall coordinate with TWG 9 on liability allocation across agentic AI systems and multi-agent chains, and with TWG 5 on autonomous AI system governance. Each recommendation shall include—
(I) the selected form of recommendation and the rationale for its selection over the alternative forms available under the chapeau;
(II) where the selected form is draft statutory language, text in legislative form suitable for introduction, together with the supporting rationale;
(III) where the selected form is a directive for agency rulemaking, the agency designated, the scope and parameters of the directive, the statutory deadline for promulgation, and the supporting rationale;
(IV) where the selected form is a formal no-regulation finding, the rationale for the finding, including identification of any existing legal frameworks deemed adequate to address the subject matter and any voluntary or non-regulatory measures recommended in lieu of regulation; and
(V) treatment of the tradeoff considerations identified in clause (iii) as relevant to the area of investigation.
(C) SEED MEMBERS.—
(i) SENATE MAJORITY.—A career CISA official with AI security and critical infrastructure protection expertise.
(ii) SENATE MINORITY.—A career NSA or CYBERCOM official with offensive and defensive AI cyber expertise (classified track).
(iii) SPEAKER.—A career FBI official with AI-related cybercrime and threat assessment expertise.
(iv) HOUSE MINORITY.—A career DHS S&T official with AI resilience and incident response expertise.
(D) REQUIRED COMPOSITION.—In addition to the 4 seed members and the mandatory AI expertise requirements of section 2005(b)(1), TWG 10 shall include—
(i) AI TECHNICAL EXPERT — ADVERSARIAL ML.—A researcher or engineer with direct experience in adversarial machine learning (prompt injection attacks, model poisoning, adversarial examples, jailbreaking, and AI system manipulation) with demonstrated technical understanding of the attack surface of deployed AI systems and feasible technical defenses.
(ii) DOMAIN-SPECIFIC AI HARM RESEARCHER.—A researcher with empirical documentation of AI-enabled cyberattacks, AI-assisted social engineering, or AI exploitation of critical infrastructure vulnerabilities.
(iii) AI RED-TEAMER.—A professional AI red-teamer with direct experience conducting structured adversarial evaluations of deployed AI systems for weaponizable capabilities against critical infrastructure.
(iv) CRITICAL INFRASTRUCTURE SECURITY EXPERT.—An expert in critical infrastructure sector security (energy, water, healthcare, or financial systems) with direct experience assessing AI-specific vulnerabilities in operational technology environments.
(v) INCIDENT RESPONSE PRACTITIONER.—A practitioner with direct experience managing large-scale cybersecurity breach responses, with ability to design AI-specific incident response protocols.
(vi) TELECOMMUNICATIONS SECURITY EXPERT.—A telecommunications or internet infrastructure security expert with expertise in AI threats to network infrastructure.
(vii) HEALTHCARE CYBERSECURITY OFFICIAL.—A healthcare or hospital system cybersecurity official with direct experience addressing AI security risks in clinical environments.
(viii) FINANCIAL SECTOR CYBERSECURITY OFFICIAL.—A financial sector cybersecurity official with direct experience addressing AI security risks in financial market infrastructure.
(ix) STATE AND LOCAL GOVERNMENT CYBERSECURITY OFFICIAL.—A state or local government cybersecurity official with direct experience protecting government AI systems.
(x) AI SECURITY STANDARDS EXPERT.—An AI security standards researcher or NIST AI Risk Management Framework practitioner with direct experience developing or implementing AI-specific security standards.
(xi) SUPPLY CHAIN SECURITY EXPERT.—A supply chain security expert with direct experience in two or more of: chip-fabrication security, firmware integrity, and model-weight supply chains, with demonstrated capacity to address model-weight integrity.
(xii) AGENTIC AI SYSTEMS RESEARCHER.—A researcher or engineer with direct technical expertise in agentic AI systems, including agent architectures, tool use, multi-agent orchestration, and the technical mechanisms by which agentic systems take real-world actions, with the ability to assess the technical feasibility and operational implications of proposed safeguards, user-protection requirements, and governance frameworks for agentic AI.
(xiii) AGENTIC AI USER RIGHTS REPRESENTATIVE.—A civil liberties or digital rights organization representative or scholar with expertise in user autonomy, individual access to AI tools, and the asymmetries between institutional and individual access to AI capabilities, included to support the investigations under subparagraph (A)(ii)(V), (VI), and (VII).
(12) TWG 11 — AUTONOMOUS WEAPONS, INTERNATIONAL HUMANITARIAN LAW, AND ARMS CONTROL.—
(A) DOMAIN OF INVESTIGATION.—TWG 11 shall conduct a comprehensive investigation of autonomous weapons systems governance, standards, and international frameworks, and on the basis of that investigation shall produce a recommendation on each area of investigation identified in this subparagraph. Each such recommendation shall take the form of (a) draft statutory language, (b) a directive for agency rulemaking with specified parameters, or (c) a formal no-regulation finding with supporting rationale. The selection of form, and the substantive direction of each recommendation, shall be determined by the TWG based on its investigation and its evaluation under subparagraph (B). The recommendation requirement of this chapeau does not apply to the data access obligations specified in clause (iv), which are structured as priority production directives addressed to enumerated Executive Branch entities. The investigation shall include—
(i) A comprehensive inventory of the state of autonomous weapons development and deployment, including—
(I) a classified and unclassified inventory of known domestic and foreign autonomous weapons programs, including programs developed by United States Government agencies, allied nations, adversary nations, and private defense contractors, with particular attention to: unmanned aerial systems and armed drones with autonomous targeting capability; loitering munitions and autonomous-search munitions deployed in active or recent conflicts; autonomous naval and undersea weapons systems; AI-enabled targeting systems integrated into existing weapons platforms; and swarm systems designed for collective autonomous engagement;
(II) an assessment of the current operational state of autonomous weapons systems within the Department of Defense, including an inventory of all programs in research, development, testing, evaluation, and operational deployment that involve autonomous or semi-autonomous engagement capabilities, and an assessment of the compliance of each such program with the prohibition established by section 2017(a)(1) of this title and the meaningful human oversight standard defined in section 2003(20);
(III) an assessment of the adequacy of Department of Defense Directive 3000.09 (Autonomy in Weapon Systems) and any successor directive in meeting the meaningful human oversight standard defined in section 2003(20) of this title, including identification of any provisions of that directive that would need to be strengthened to comply with this title; and
(IV) documentation of known incidents in which autonomous or semi-autonomous weapons systems have caused unintended civilian casualties, engaged unintended targets, malfunctioned in ways that produced lethal or destructive outcomes, or operated outside their intended parameters, including analysis of the institutional factors that contributed to each incident.
(ii) Development of technical standards and criteria for the meaningful human oversight requirement, including—
(I) specific, operationally grounded criteria for assessing whether a human authorization decision satisfies the meaningful human oversight standard defined in section 2003(20), including minimum decision window requirements for specific weapons system types, threat environments, and operational contexts, and the evidentiary standard for demonstrating that the standard was met in any given engagement;
(II) technical standards for the tamper-proof authorization logging systems required by section 2017(a)(1)(H)(ii), including specifications for the data elements to be recorded, the security requirements for log integrity, and the retention and access requirements to support post-engagement review and congressional oversight;
(III) criteria for distinguishing autonomous weapons systems within the meaning of section 2003(7) from semi-autonomous and precision-guided systems that do not fall within the prohibition, with specific reference to contemporary systems and capability profiles to provide clear compliance guidance to defense contractors, allied nations, and government agencies; and
(IV) recommended standards for testing and certification of autonomous weapons systems to verify compliance with the meaningful human oversight requirement before operational deployment, including procedures for independent third-party testing and for periodic re-certification as systems are updated or modified.
(iii) An assessment of the international legal and diplomatic landscape for autonomous weapons governance, including—
(I) the current state of negotiations under the Convention on Certain Conventional Weapons (CCW) Group of Governmental Experts on lethal autonomous weapons systems (LAWS), including the positions of the United States, allied nations, and adversary nations, and the prospects for a binding multilateral agreement;
(II) an assessment of whether the United States should actively support, lead, or oppose international negotiations toward a legally binding treaty on lethal autonomous weapons systems, with analysis of the national security implications of each approach, including the risk that a binding ban may disadvantage the United States if adversary nations do not comply;
(III) recommendations for the international negotiating position of the International AI Diplomacy Agency established under section 2014 with respect to lethal autonomous weapons systems, including proposed elements of a multilateral framework that the United States could support, and proposed verification mechanisms analogous to those used in conventional arms control treaties; and
(IV) an assessment of the autonomous weapons development programs of state adversaries identified by the Director of National Intelligence as posing elevated risks, and the implications of adversary autonomous weapons capabilities for United States national security policy. Classified findings shall be reported through the classified track established under section 2011(i).
(iv) DATA ACCESS OBLIGATIONS.—For purposes of their data access obligations under section 2005(b) and (c), the Department of Defense, the Department of State, and the Director of National Intelligence on behalf of the Intelligence Community are directed to treat autonomous weapons development programs, international AI arms control negotiating positions, foreign adversary autonomous weapons capabilities, and classified and non-classified threat assessments relevant to lethal autonomous weapons systems as priority categories of information subject to mandatory production under section 2005(b); classified material in these categories shall be handled through the classified track under section 2011(i).
(v) Methodologies for measuring the effectiveness of the meaningful human oversight standard and related technical standards developed under clause (ii), including metrics for assessing whether testing and certification procedures actually verify compliance with section 2003(20), the empirical evidence on comparable testing and certification regimes in other weapons categories, and the conditions under which such regimes succeed or fail at preventing the harms they are designed to address.
(vi) A synthesis integrating the findings of clauses (i) through (iii) and clause (v), addressing the relationship between the technical standards developed under clause (ii) and the international negotiating position developed under clause (iii), and the relationship between Department of Defense program compliance under clause (i)(II) and the international credibility of the United States position under clause (iii).
(B) MANDATE.—TWG 11 shall execute its mandate in the phases of section 2005(b)(12) with respect to the subject matter set forth in subparagraph (A), as follows:
(i) DOMAIN EXAMINATION.—The investigations specified in subparagraph (A).
(ii) INTERVENTION EVALUATION.—For each area of investigation identified in subparagraph (A), the full range of possible federal responses from comprehensive statutory regulation to formal no-regulation findings, and the option of reliance on existing DOD Directive 3000.09 and related authorities, including in particular technical standards and criteria for the meaningful human oversight requirement; the boundary between lawful semi-autonomous systems and prohibited autonomous weapons; Department of Defense program compliance assessment methodology; the United States negotiating position for international LAWS agreements under the Convention on Certain Conventional Weapons; technical standards for tamper-proof authorization logging; Defensive Emergency Autonomy trigger threshold specifications; post-engagement reporting protocols; and effectiveness-measurement methodologies.
(iii) TRADEOFF ASSESSMENT.—For each intervention evaluated under clause (ii), the effects on United States military effectiveness and deterrence; the implications for the international arms control regime and the prospects for multilateral agreement; the risks of unilateral United States restraint where adversary nations do not comply; the operational and compliance costs imposed on Department of Defense programs and defense contractors; the effects on allied interoperability; and the application of international humanitarian law principles of distinction, proportionality, and precaution.
(iv) RECOMMENDATION DEVELOPMENT.—For each area of investigation identified in subparagraph (A), TWG 11 shall develop a recommendation in the form required by the chapeau of subparagraph (A). The recommendation requirement does not apply to the data access obligations specified in subparagraph (A)(iv), which are governed by their respective subparagraph provisions. TWG 11 shall coordinate with the Department of Defense Inspector General for access to classified information through the classified track under section 2011(i). TWG 11 shall be the lead TWG for joint sessions with TWG 5 on matters intersecting autonomous weapons governance and AI safety. Each recommendation shall include—
(I) the selected form of recommendation and the rationale for its selection over the alternative forms available under the chapeau;
(II) where the selected form is draft statutory language, text in legislative form suitable for introduction, including specific technical standards where applicable, together with the supporting rationale;
(III) where the selected form is a directive for agency rulemaking, the agency designated, the scope and parameters of the directive, the statutory deadline for promulgation, and the supporting rationale;
(IV) where the selected form is a formal no-regulation finding, the rationale for the finding, including identification of any existing legal frameworks, including DOD Directive 3000.09, deemed adequate to address the subject matter and any voluntary or non-regulatory measures recommended in lieu of regulation; and
(V) treatment of the tradeoff considerations identified in clause (iii) as relevant to the area of investigation.
(C) SEED MEMBERS.—
(i) SENATE MAJORITY.—A career DOD official with autonomous systems acquisition or policy expertise, appointed in consultation with the Chairman of the Joint Chiefs of Staff.
(ii) SENATE MINORITY.—A career State Department official with CCW or arms control negotiating expertise.
(iii) SPEAKER.—A career DARPA or defense research official with autonomous systems engineering expertise.
(iv) HOUSE MINORITY.—A career DIA official with autonomous weapons threat assessment expertise (classified track).
(D) REQUIRED COMPOSITION.—In addition to the 4 seed members and the mandatory AI expertise requirements of section 2005(b)(1), TWG 11 shall include—
(i) AI TECHNICAL EXPERT — AUTONOMOUS TARGETING SYSTEMS.—A researcher or engineer with direct experience designing or evaluating autonomous targeting systems (sensor fusion architectures, object detection and classification systems, and engagement decision-making at millisecond timescales) and familiarity with meaningful-human-oversight requirements at autonomous-weapons decision timescales.
(ii) DOMAIN-SPECIFIC AI HARM RESEARCHER.—A researcher with empirical documentation of autonomous or automated system failures, unintended engagement incidents, or reliability failures under adversarial or degraded conditions in weapons or safety-critical settings.
(iii) COMPUTER VISION AND SENSOR FUSION ENGINEER.—A computer vision or sensor fusion engineer with direct expertise in target identification and classification failure modes, including under camouflage, electronic jamming, or adversarial manipulation, in defense or commercial safety-critical applications.
(iv) INTERNATIONAL HUMANITARIAN LAW SCHOLAR.—An international humanitarian law scholar specializing in the law of armed conflict and the application of IHL principles (distinction, proportionality, precaution) to autonomous weapons systems.
(v) ARMS CONTROL VERIFICATION SPECIALIST.—An arms control specialist with direct verification and monitoring expertise; autonomous-weapons application is engageable.
(vi) RECENTLY RETIRED MILITARY OFFICER.—A recently retired military officer (within 5 years of separation from active duty) with direct operational experience with autonomous or semi-autonomous weapons systems; if the appointing authority determines that active-duty expertise is essential and unavailable from recently retired officers, an active-duty officer may be detailed under the carve-out of section 2005(a)(12)(B).
(vii) DEFENSE CONTRACTOR REPRESENTATIVE.—A defense contractor representative with autonomous systems engineering expertise and direct experience in defense acquisition programs.
(viii) AUTONOMOUS WEAPONS CIVIL SOCIETY REPRESENTATIVE.—A representative of a civil society organization specializing in autonomous weapons governance.
(ix) FORMER ARMS CONTROL DIPLOMAT.—A former United States CCW GGE on LAWS delegation member, or a former arms-control diplomat with an autonomous-weapons portfolio.
(x) STATE RESPONSIBILITY LAW SCHOLAR.—A legal scholar specializing in state responsibility and public international law, with capacity to engage autonomous-systems accountability applications.
(xi) ALLIED NATION CONTRIBUTING EXPERT.—A representative of an allied nation with significant autonomous weapons development or governance activity — the United Kingdom, Australia, France, or Germany; subject to the allied nation contributing expert carve-out under section 2005(a)(12)(A).
(13) CROSS-CUTTING MANDATES.—This paragraph sets forth cross-cutting investigatory items that are not assigned to a single Technical Working Group. Subparagraph (A) assigns joint synthesis obligations to the TWG Coordination Council. Subparagraph (B) establishes a mandatory joint session between TWG 5 and TWG 11. Subparagraph (C) identifies items whose content is fully covered by the domain mandates of enumerated TWGs and therefore requires no separate treatment in this paragraph. Subparagraph (D) assigns a final compilation obligation to the Federal Advisory Committee.
(A) COORDINATION COUNCIL DELIVERABLES.—The TWG Coordination Council shall complete the following items collectively through joint session authority under section 2005(c) and transmit each to the FAC as a Coordination Council deliverable under section 2005(c)(3):
(i) TECHNOLOGY TRAJECTORY ASSESSMENT.—A technical assessment of the current state and projected trajectory of AI technologies relevant to each domain, including documented capability trends from the United Kingdom AI Security Institute, METR, and other evaluation bodies, synthesized from the inputs of all 11 TWGs.
(ii) INCIDENT AND HARM INVENTORY.—An inventory and analysis of documented incidents, harms, near-misses, and systemic risks across all domains, drawing on each TWG's domain findings.
(iii) REGULATORY ADEQUACY ASSESSMENT.—An assessment of the adequacy of existing federal, state, tribal, and industry self-regulatory frameworks across all domains, synthesizing each TWG's domain-specific adequacy findings.
(iv) TECHNICAL STANDARDS ASSESSMENT.—An assessment of available technical standards, auditing methodologies, testing protocols, and measurement frameworks across all domains, synthesizing each TWG's domain-specific standards findings.
(v) RISK TAXONOMY.—A preliminary taxonomy of risk levels and categories within each domain, synthesizing each TWG's domain-specific risk categorization findings into a unified cross-domain taxonomy.
(B) COMPARATIVE INTERNATIONAL ANALYSIS; TWG 5 AND TWG 11 JOINT SESSION.—A comparative analysis of international regulatory approaches to AI governance, including the European Union AI Act, the United Kingdom AI Safety Institute's evaluation programs, foreign AI governance frameworks, the G7 Hiroshima Process, and the Bletchley and Seoul Declarations, shall be addressed through a mandatory joint session convened by the Coordination Council under section 2005(c)(3)(B). Because this item spans both the AI safety governance mandate of TWG 5 and the international humanitarian law and arms control mandate of TWG 11, the joint session shall produce a jointly developed comparative analysis transmitted to the FAC under both TWGs' names.
(C) ITEMS COVERED BY EXISTING TWG MANDATES.—The following items require no separate treatment in this paragraph because each is fully covered by the domain mandate of the Technical Working Group identified:
(i) ECONOMIC LANDSCAPE.—Analysis of the economic landscape, including market structure, concentration, innovation dynamics, and competitive effects of potential regulation, is addressed through the domain mandate of TWG 4 under paragraph (5) of this subsection.
(ii) CIVIL RIGHTS AND DISPARATE IMPACT.—Evaluation of effects on civil rights, civil liberties, privacy, equity, and disparate impact on protected classes and vulnerable populations, including assessment of algorithmic bias and disparate impact in the employment, credit, housing, healthcare, and criminal justice domains, is addressed through the domain mandate of TWG 9 under paragraph (10) of this subsection.
(iii) WORKFORCE EFFECTS.—Analysis of workforce, labor market, and employment effects is addressed through the domain mandate of TWG 7 under paragraph (8) of this subsection.
(D) FEDERAL ADVISORY COMMITTEE DELIVERABLE.—Identification of data gaps, research needs, and areas requiring further scientific investigation across all domains investigated under this subsection shall be assigned to the Federal Advisory Committee. The FAC shall compile this inventory from TWG Domain Explanatory Reports and Coordination Council deliverables and shall include it as a discrete component of the legislative transmission package under section 2006(i), accompanying the complete index of domain packages transmitted to Congress.
(14) PRECAUTIONARY PRINCIPLE.—Where the evidentiary record at the time of TWG final submissions or FAC legislative transmission is incomplete in any domain, the Technical Working Groups and Federal Advisory Committee shall apply the precautionary principle: where credible evidence establishes that an AI system or practice poses a serious risk of harm to persons, communities, democratic institutions, national security, or the environment, the burden of demonstrating safety shall not rest with those who would be harmed. Interim legislative standards that restrict or condition deployment pending fuller investigation are preferable to governance absence pending certainty. The precautionary principle as applied by this title does not require proof of harm; it requires credible evidence of serious risk. Where evidence of serious risk is weak or foregone benefits are substantial, this paragraph does not establish a default in favor of restriction. This standard is consistent with the precautionary approaches embedded in existing federal law governing pharmaceuticals, medical devices, pesticides, toxic substances, nuclear materials, and aviation safety.
SEC. 2005. GOVERNANCE OF TECHNICAL WORKING GROUPS.
(a) ESTABLISHMENT AND TWO-STAGE APPOINTMENT PROCESS.
(1) GENERAL.—The Federal Advisory Committee established under section 2006 is the authorized body to oversee the Technical Working Groups (in this section, "TWGs") to conduct the specialized domain investigations in support of the Committee's legislative drafting mandate. Each TWG shall operate as a subordinate body of the Committee. TWG outputs, including monthly work product submissions and final domain recommendations, shall constitute draft recommendations to the Committee and shall not be transmitted directly to Congress, the lead agency, or any other entity. The Committee is the sole body authorized to transmit legislative recommendations to Congress. No TWG may represent its findings as the findings of the Committee or of any federal agency.
(2) TWO-STAGE APPOINTMENT PROCESS.—TWG membership shall be established through a two-stage process: a first stage in which congressional appointing authorities appoint career government seed members by Day 90 after the date of enactment; and a second stage in which those seed members collectively nominate a binding candidate pool for the remaining slots by Day 120, from which the appointing authorities make final selections with all TWG members appointed by Day 150. TWGs begin full-time work after members have completed ethics and security onboarding, with organizational meetings held as soon as quorum is available and substantive work commencing at the organizational meeting.
(3) STAGE ONE - SEED APPOINTMENTS.—Not later than 90 days after the date of enactment, each of the following congressional appointing authorities shall appoint one career federal government seed member to each of the 11 TWGs: the Majority Leader of the Senate; the Minority Leader of the Senate; the Speaker of the House of Representatives; and the Minority Leader of the House of Representatives. Each seed appointment shall result in 4 seed members per TWG (one from each appointing authority) for a total of 44 seed members across all 11 TWGs. Seed members shall be career civil servants or members of the Senior Executive Service employed by the federal agencies specified for each TWG in paragraphs (2) through (12) of section 2004. No seed member may be a political appointee. Each appointing authority shall consult with the Federal Advisory Committee Chair before making seed appointments to ensure domain expertise, cross-TWG balance, and non-duplication. If any appointing authority fails to make seed appointments by Day 90, the Comptroller General shall make the unfilled seed appointments within 7 days thereafter.
(4) STAGE ONE - ETHICS AND SECURITY ONBOARDING.—Upon appointment, each seed member shall immediately begin the ethics and security onboarding process, which shall be coordinated by the TWG Administrative Coordinator for their assigned TWG in partnership with the Office of Government Ethics and the member's home agency. Ethics and security onboarding includes: financial disclosure filing (OGE Form 450); ethics briefing from the Committee's designated ethics official; background investigation initiation; security clearance initiation where required by the member's assigned TWG; and orientation to Committee procedures and TWG mandate. The onboarding process typically requires 2 to 4 weeks to complete. Onboarding begins on the date of appointment (Day 90) and is expected to be complete for seed members by approximately Day 110, before the nomination pool submission deadline.
(5) STAGE ONE - TRANSITION TO FULL-TIME SERVICE.—Seed members shall be detailed to their respective TWGs. Each seed member shall remain an employee of their home agency throughout the detail period and shall be compensated by their home agency at their existing rate of compensation. The heads of all federal departments and agencies are directed to approve detail requests for employees appointed as seed members and to grant such details as a priority matter. The detail shall be structured as
(A) Advisory Phase (Day 90 through Day 120 at most) - a seed member who is unable to immediately transition full-time responsibilities may continue in their agency role on a reduced basis while completing onboarding and the nomination process, with full transition completed not later than Day 120
(B) Full-Time Phase (Day 120 onward) - all seed members shall devote their primary professional time and attention to TWG work on a full-time basis from Day 120 through the TWG's final domain submission.
A seed member who can transition immediately upon appointment shall do so without waiting for Day 120. A seed member may maintain a limited ongoing advisory role at their home agency of not more than 4 hours per week only upon written certification by the head of the member's home agency to the Federal Advisory Committee Chair that an extraordinary operational necessity requires it; any such certification shall be published on the public portal under section 2007(d).
(6) STAGE TWO - NOMINATION POOL.—Not later than 120 days after the date of enactment (30 days after seed appointments) the 4 seed members of each TWG shall collectively produce a binding nomination pool for each remaining slot in their TWG, as specified in paragraphs (2) through (12) of section 2004. The nomination pool shall include not fewer than 2 and not more than 3 qualified candidates per remaining slot. Each candidate in the pool shall meet the specific qualifications defined for that slot in the applicable TWG subsection. The nomination pool shall be submitted in writing to the Federal Advisory Committee Chair, who shall publish it on the public portal under section 2007(d) within 3 business days of receipt. Seed members shall reach the nomination pool by majority vote; in the event of a 2-2 deadlock on any slot, both candidates proposed by the deadlocked members shall be included in the pool. If any TWG's seed members fail to produce a nomination pool for any slot by Day 120, the Executive Director of the Federal Advisory Committee shall designate qualified candidates for the unfilled pool slots within 7 days thereafter, drawing on the qualifications specified in the applicable TWG subsection. TWGs may continue to identify and add candidates to unfilled slots on a rolling basis after Day 120 until all seats are filled.
(7) STAGE TWO - CONGRESSIONAL SELECTION.—Not later than 150 days after the date of enactment, the congressional appointing authorities shall collectively make final appointments from the binding nomination pool produced under paragraph (6). The appointing authorities may select any candidate from the pool for any remaining slot but may not appoint a person who does not appear in the pool. The appointing authorities shall divide responsibility for final appointments as follows: the Majority Leader and Speaker together shall fill the odd-numbered remaining slots as listed in paragraphs (2) through (12) of section 2004; the Minority Leader and House Minority Leader together shall fill the even-numbered remaining slots. If any appointing authority fails to make final appointments by Day 150, the Executive Director of the Federal Advisory Committee shall make the unfilled appointments from the nomination pool within 7 days thereafter. If a nominated candidate withdraws, becomes ineligible, or is otherwise unavailable between Day 120 and Day 150, the seed members of the relevant TWG shall, within 5 days of notification of unavailability, nominate a substitute qualified candidate meeting the specifications of the applicable slot into the binding nomination pool; such substitute nomination has the same binding force as the original pool nominations and the appointing authority shall make its appointment from the updated pool. If the seed members cannot agree on a substitute within 5 days, the Executive Director shall, within 5 additional days, nominate a qualified substitute into the pool from among persons meeting the slot qualifications. If a substitute is nominated into the pool after Day 145, the Day 150 appointment deadline for that specific slot only is automatically extended by 7 days to provide the appointing authority adequate time to make its selection; all other slots remain subject to the Day 150 deadline.
(8) ETHICS AND SECURITY ONBOARDING FOR STAGE TWO MEMBERS.—Upon appointment at Day 150, each Stage Two member shall immediately begin the ethics and security onboarding process coordinated by the TWG Administrative Coordinator, following the same process described in paragraph (4). Onboarding for Stage Two members typically completes within 2 to 4 weeks, placing most members ready for substantive work by approximately Day 170 to 180.
(9) ORGANIZATIONAL MEETING AND SUBSTANTIVE WORK COMMENCEMENT.—Each TWG shall hold its first organizational meeting within 5 days of the date on which a quorum of that TWG's full membership has completed ethics and security onboarding and is cleared to begin work. For seed members, this quorum is expected to be available approximately Day 110 to 120; for the fully constituted TWG, this quorum is expected approximately Day 155. Substantive investigatory work shall begin at the organizational meeting - there is no grace period, orientation period, or ramp-up period following the organizational meeting. The organizational meeting agenda shall include: election of a TWG Chair, who shall be a full-time member, by majority vote; election of Coordination Council representatives under subsection (c)(2); assignment of investigatory sub-tasks among members; and review of the TWG's domain mandate. The TWG Administrative Coordinator shall have all logistics, infrastructure, document management, and communications systems operational before the organizational meeting so that members can begin substantive work immediately.
(10) FORMER OFFICIAL REQUIREMENT.—Except where the applicable TWG subsection expressly provides otherwise, any slot requiring expertise associated with a government, elected, or appointed position shall be filled by a former holder of that position or role, not a currently serving official. This requirement reflects the structural reality that sitting elected officials, currently serving agency heads, and persons with active fiduciary or statutory obligations cannot commit to full-time TWG service without abandoning those obligations. Former officials bring equivalent or superior expertise without these structural constraints. This requirement does not apply to career federal employee seed members, who serve on detail from their current positions.
(11) ACTIVE LITIGATION EXCLUSION.—No person with active pending litigation as a party, attorney of record, or expert witness in any proceeding directly addressing a legal question within the jurisdiction of the TWG to which they are appointed may serve on that TWG. For purposes of this subparagraph, "active pending litigation" means a proceeding in which the person has ongoing obligations, including discovery obligations, deposition obligations, hearing obligations, or active case strategy responsibilities, that would conflict with full-time TWG service. A person with concluded cases in the relevant domain is eligible. The appointing authority shall obtain written certification from each nominee that no active litigation conflict exists before making the appointment.
(12) CARVE-OUTS AND ACCOMMODATIONS.—The following carve-outs and accommodations apply across TWGs:
(A) ALLIED NATION CONTRIBUTING EXPERT.—An allied nation contributing expert required by paragraph (4)(D)(vii) or paragraph (12)(D)(xi) of section 2004 is not subject to the full-time service requirement, may not serve as a full voting member, and is not required to be a United States citizen or government employee. An allied nation contributing expert shall attend all non-classified sessions of the relevant TWG, submit written analysis and recommendations to the TWG record, and participate fully in deliberations, but shall not vote on TWG recommendations. Contributions shall be included in TWG outputs with clear attribution. Allied nation contributing experts are subject to all security clearance requirements applicable to non-classified sessions.
(B) ACTIVE-DUTY MILITARY OFFICER.—For TWG 11 (Autonomous Weapons, International Humanitarian Law, and Arms Control), established under paragraph (12) of section 2004, a recently retired military officer within 5 years of separation from active duty is the default. If the relevant appointing authority determines that active-duty expertise is essential and unavailable from recently retired officers, an active-duty officer may be detailed to TWG 11 with the approval of the Secretary of Defense. Such a detail shall be treated as a military assignment, shall count toward the officer's service obligations, and shall not affect rank, pay, or benefits. The decision to seek an active-duty detail shall be made by the appointing authority in writing, with written concurrence from the Federal Advisory Committee Chair, not later than Day 50 to allow time for Defense Department processing before the Day 60 seed appointment deadline.
(C) MEMBER UNDER 25.—The member under the age of 25 required by paragraph (7)(D)(xiii) of section 2004 for TWG 6 (Children, Youth, and Vulnerable Populations) is a full voting member and subject to all TWG membership obligations, but is not subject to the full-time service requirement as applied to other members. The under-25 member shall attend all TWG sessions in person or by remote participation and shall engage substantively with all TWG work product, draft recommendations, and deliberative processes. Compensation shall be adjusted to reflect the member's participation modality. Remote participation infrastructure shall be provided at government expense. Scheduling shall, to the extent practicable, accommodate the academic or employment obligations of the under-25 member without compromising the TWG's work schedule.
(D) PART-TIME AND ADVISORY MEMBERS.—Full-time service under subsection (b)(3) is the priority and default for every slot specified in section 2004. Where, after documented good-faith effort to recruit a qualified candidate able to serve full-time, the seed members and the appointing authority are unable to fill a required slot with such a candidate, the slot may be filled by a qualified candidate who meets all substantive qualifications specified for that slot in the applicable subsection of section 2004 but is unable to commit to full-time service, on a part-time or advisory basis as provided in this subparagraph.
(i) PART-TIME MEMBER.—A part-time member is a full voting member of the TWG who devotes not less than one-half of a full-time professional schedule to TWG work throughout the investigatory period, attends the weekly all-day consolidation sessions under subsection (b)(11)(B), and is subject to all other membership obligations of this section. Compensation shall be prorated under subsection (b)(5) to reflect actual service.
(ii) ADVISORY MEMBER.—An advisory member participates in TWG deliberations and submits written analysis and recommendations to the TWG record with full speaking rights, in the manner provided for the allied nation contributing expert under subparagraph (A), but does not vote on TWG recommendations. An advisory member is not counted in the membership of the TWG for purposes of any quorum, vote, election, recall, or petition under this title, and any reference in this title to a TWG's "full membership" or to its "members" in connection with any such threshold means its voting members. Contributions shall be included in TWG outputs with clear attribution. An advisory member may hold a current position, including current employment by a frontier AI developer, significant AI deployer, or other entity, notwithstanding paragraph (10) and any "former" qualification specified for the slot. Such a member serves in a representative capacity, within the meaning of the Federal Advisory Committee Act, rather than as a member subject to subsection (b)(5)(A), and is not subject to that subparagraph or to 18 U.S.C. § 208; the member remains subject to the conflict-of-interest disclosure requirements of subsection (b)(6), remains non-voting, and counts toward the minority limit of clause (iii).
(iii) MAJORITY-FULL-TIME FLOOR.—The majority-full-time floor of subsection (b)(3) shall be maintained at all times. Part-time members, advisory members, and the carve-out members under subparagraphs (A) through (C), taken together, shall not exceed a minority of the TWG's total membership. If filling a slot on a part-time or advisory basis would breach this floor, the slot shall be held open and filled on a full-time basis as soon as a qualified full-time candidate is available, and recruitment shall continue under paragraph (6).
(E) CLEARANCE ACCOMMODATION.—A member whose required security clearance has been initiated but not yet adjudicated may be seated and shall fully participate in, and count toward quorum for, all unclassified TWG work pending adjudication, and shall be granted interim access where authorized under applicable Executive order. Where a TWG deliverable depends on access to classified material, the deadline for its classified component is the later of the deadline otherwise applicable under subsection (b)(4) or 60 days after the responsible member's clearance is granted; unclassified components remain subject to subsection (b)(4).
(b) GENERAL REQUIREMENTS APPLICABLE TO ALL TWGS.
(1) MANDATORY AI EXPERTISE REQUIREMENTS.—In addition to the domain-specific composition requirements of paragraphs (2) through (12) of section 2004, every TWG without exception shall
(A) AI TECHNICAL EXPERT.—not fewer than one member who has direct hands-on experience building, training, or evaluating AI models or AI systems of the type relevant to the TWG's domain, meaning the member has personally constructed, trained, deployed, or conducted structured evaluation of production-grade AI models or AI systems, not merely studied or written about such systems. Minimum qualification: peer-reviewed publication in machine learning or AI with direct relevance to the TWG's domain; or documented professional experience building or operating production AI models or AI systems at a frontier AI developer, significant AI deployer, or any entity whose primary business involves the development, deployment, or commercialization of AI models or AI systems or recognized AI research institution; or documented dangerous capability evaluation experience at a recognized evaluation body. Policy expertise, AI ethics scholarship, or general technology policy experience does not satisfy this requirement
(B) DOMAIN-SPECIFIC AI HARM RESEARCHER.—not fewer than one member who has produced empirical research specifically documenting how AI models or AI systems cause harm in the TWG's domain. Minimum qualification: peer-reviewed publication, government-commissioned report, or equivalent documented research product that identifies specific AI-caused harms in the TWG's domain with supporting evidence.
(2) QUALIFICATIONS.—All TWG members shall possess demonstrated expertise in the domain assigned to that TWG. Demonstrated expertise means peer-reviewed publication; professional practice of not fewer than 7 years in the relevant field; federal regulatory or operational experience in the relevant domain; or a combination thereof sufficient for the appointing authority to determine that the member can meaningfully contribute to the TWG's specialized mandate. Where a composition requirement in section 2004 or in paragraph (1) of this subsection calls for peer-reviewed work, that requirement is satisfied by peer-reviewed work or by equivalent documented work, including a government-commissioned or institutional report or a widely cited preprint or technical report. The mandatory AI expertise requirements of paragraph (1) constitute additional qualifications layered on top of, not in substitution for, domain expertise.
(3) FULL-TIME SERVICE COMMITMENT.—TWG membership constitutes full-time federal service, except as provided in subsection (a)(12), for the duration of the investigatory period from the member's first organizational meeting through the TWG's final domain submission at the 8.5-month deadline. Each TWG member shall devote their primary professional time and attention to TWG responsibilities during this period. No TWG member may simultaneously hold employment, consulting arrangements, or other professional obligations that create a material conflict with their TWG duties, except as provided in subsection (a)(12). Not fewer than a majority of the total membership of each TWG shall serve on a full-time basis throughout the investigatory period. A slot may be filled on a part-time or advisory basis only as provided in subsection (a)(12)(D). The appointing authority shall obtain written confirmation from each nominee before appointment that the prospective member can commit to full-time service or, for a member appointed on a part-time or advisory basis under subsection (a)(12)(D), to the level of service specified there, and has resolved or will resolve any conflicting professional obligations before the date of their organizational meeting.
(4) FINAL DOMAIN SUBMISSION DEADLINE AND REQUIRED DOMAIN EXPLANATORY REPORT.—Each TWG shall submit its final domain recommendations to the Federal Advisory Committee not later than 8.5 months after the date of that TWG's first organizational meeting. TWGs that hold their organizational meeting earlier than the maximum appointment timeline permits shall benefit from the earlier start - their 8.5-month clock runs from their actual organizational meeting date, not from any fixed day after enactment. To ensure the investigatory process cannot be indefinitely delayed through postponement of organizational meetings, each TWG's first organizational meeting shall be held not later than 185 days after the date of enactment, consistent with section 2005(a)(9). The 8.5-month deadline is firm for each TWG individually. No extension shall be granted. If a TWG fails to submit complete final domain recommendations by its deadline, the TWG Chair shall submit a partial submission with whatever the TWG has completed, and the Federal Advisory Committee shall proceed with its legislative finalization on the basis of that partial submission, supplemented by the TWG's prior monthly work product submissions. The final domain submission shall consist of two components: the legislative component and the Domain Explanatory Report, both of which are required and both of which are due at the 8.5-month deadline. Throughout the investigatory period, the Federal Advisory Committee's Legislative Drafting Staff shall work collaboratively with each TWG to refine and translate each monthly work product submission into draft statutory language on a rolling basis, so that by the time a TWG submits its final domain recommendations, the corresponding legislative text is substantially advanced rather than begun from scratch. Draft statutory language developed through this rolling process remains provisional until the TWG's final domain submission - monthly work product submissions may revise, reverse, or supersede prior recommendations, and the Legislative Drafting Staff shall update draft statutory language accordingly.
(A) LEGISLATIVE COMPONENT.—The legislative component of the final domain submission shall include: complete draft statutory text for each significant issue within the TWG's domain, organized by subject matter with numbered sections and defined terms consistent with the FAC's cross-domain drafting framework; a formal finding of no regulation with evidentiary basis for any domain issue on which the TWG recommends no legislative intervention; a complete index of the evidentiary record supporting each recommendation, identifying every source relied upon; identification of any matters the TWG was unable to resolve within its investigatory period with a specific recommendation for Phase II investigation; and a certification by the TWG Chair that the mandate structure of subsection (b)(12) has been completed for each domain issue.
(B) DOMAIN EXPLANATORY REPORT.—Each TWG shall produce and submit alongside its legislative component a Domain Explanatory Report. The Domain Explanatory Report is a comprehensive explanatory document, written in accessible prose, that constitutes the full public record of the TWG's investigatory work and the reasoning behind its legislative recommendations. The Domain Explanatory Report is the document from which courts, congressional staff, agencies, future rulemakers, researchers, and the public can understand what the TWG found, what it considered, and why it decided what it decided. The Domain Explanatory Report shall be organized by domain issue and shall include, for each significant issue within the TWG's domain, the following elements
(i) HARM DOCUMENTATION.—a comprehensive description of each identified harm arising from AI models or AI systems in this domain, including: the nature and mechanism of the harm; documented evidence of prevalence, including quantitative estimates where the evidentiary record supports them; the populations most affected, with particular attention to vulnerable groups; the severity and reversibility of the harm; and the trajectory of the harm over the investigatory period, including whether it is accelerating, stable, or declining
(ii) EVIDENTIARY RECORD SUMMARY.—a narrative summary of the evidence reviewed by the TWG bearing on this issue, including: the sources consulted, their nature and quality; the expert presentations received and the principal arguments made; the public submissions received and the range of perspectives they represented; and an honest assessment of the strength, completeness, and limitations of the evidentiary record, including areas where the evidence is strong, areas where it is preliminary, and areas where genuine scientific or factual uncertainty remains.
(iii) INTERVENTION ANALYSIS.—for each potential legislative intervention evaluated by the TWG, including the option of no regulation: a description of what the intervention would do; its anticipated costs and benefits; its constitutional parameters and any identified legal vulnerability; its implementation requirements and administrative feasibility; its enforcement mechanism and the likely response of frontier AI developers and significant AI deployers; and the TWG's assessment of its effectiveness in addressing the identified harm
(iv) CRUXES AND POINTS OF GENUINE UNCERTAINTY.—an explicit identification of the genuinely contested questions of fact, law, or policy that were most determinative of the TWG's recommendations, including: the factual disputes the TWG could not fully resolve on the evidence available; the value judgments the TWG was required to make where the evidence did not compel a single answer; and the questions the TWG believes most warrant further investigation in Phase II
(v) EXTERNALITIES AND CROSS-DOMAIN EFFECTS.—an assessment of the significant effects of each proposed intervention beyond the TWG's primary domain, including: effects on innovation, competition, and market structure; effects on civil liberties, free expression, and democratic processes; effects on national security and international competitiveness; effects on communities and populations not primarily within the TWG's domain but affected by the proposed intervention; and cross-domain interactions with the work of other TWGs, including areas where this TWG's recommendations may conflict with or depend upon another TWG's recommendations
(vi) PRO AND CON ARGUMENTS.—for each significant legislative choice the TWG made, a structured presentation of the principal arguments for and against the choice adopted, attributed by name where the argument was made in a public submission or public log entry, with the TWG's written assessment of why each argument was or was not found persuasive. This is not a summary of all arguments received but a structured account of the arguments that were genuinely consequential to the TWG's deliberations
(vii) JUSTIFICATION FOR DECISION.—a direct and honest statement of why the TWG recommended what it recommended, including: the weight given to each category of evidence; the policy judgment underlying the recommendation where the evidence did not compel a single answer; the role of the precautionary principle where it was applied; and any significant disagreements within the TWG about the recommendation, including the views of members who would have recommended differently. Where the TWG's vote on a recommendation was not unanimous, the Domain Explanatory Report shall include a brief statement of the dissenting view
(viii) PHASE II RECOMMENDATIONS.—for each issue on which the TWG's investigatory record was incomplete, a specific recommendation for Phase II investigation or legislation, identifying the evidence gap, the additional expert input that would be required to fill it, and the legislative question that remains open.
The Domain Explanatory Report shall be written by the TWG members, not by the TWG Administrative Coordinator, under the direction of the TWG Chair. The FAC Legislative Drafting Staff shall provide drafting assistance upon request. The Domain Explanatory Report shall be published on the public docket simultaneously with the legislative component at the TWG's 8.5-month deadline and shall be transmitted to Congress alongside the FAC's backstop legislative package as part of the complete legislative record of this title.
(5) COMPENSATION AND ETHICS REQUIREMENTS.
(A) ETHICS REQUIREMENTS.—Each non-government TWG member, other than an advisory member serving in a representative capacity under subsection (a)(12)(D), shall be subject to the conflict-of-interest and ethics requirements applicable to employees of the executive branch under 18 U.S.C. § 208, the Standards of Ethical Conduct for Employees of the Executive Branch (5 C.F.R. Part 2635), and applicable Office of Government Ethics regulations.
(B) BASE COMPENSATION RATE.—Each non-government TWG member shall receive compensation at a daily rate equivalent to the annual rate for a GS-15 Step 10 position under the General Schedule pay scale, prorated to a daily rate, for each day of TWG service during the investigatory period. The Secretary shall adjust this rate annually to reflect changes to the General Schedule.
(C) ENHANCED COMPENSATION.—For any TWG member whose documented annual professional compensation from their primary employer in the calendar year preceding appointment exceeded the annual rate for a GS-15 Step 10 position, the Secretary is authorized to compensate that member at a daily rate not exceeding the daily equivalent of the annual rate for a Senior Executive Service ES-6 position to avoid systematically excluding the highest-caliber experts from TWG service on compensation grounds.
(D) COMPENSATION WAIVER.—A TWG member whose employer is compensating them for their TWG service may waive federal compensation by written notice to the Secretary. Such waiver shall be noted publicly in the TWG's membership records on the public portal.
(6) CONFLICT OF INTEREST DISCLOSURE.—Each TWG member shall, before beginning service and on a continuing basis throughout the investigatory period, disclose in writing to the TWG Chair and the Director of AI Investigation: all financial interests in frontier AI developer, significant AI deployer, or any entity whose primary business involves the development, deployment, or commercialization of AI systems entities or entities whose business may be materially affected by TWG recommendations; all consulting, employment, or contractual relationships with such entities within the preceding 1 year; all funding received for research related to the TWG's domain from frontier AI developer, significant AI deployer, or any entity whose primary business involves the development, deployment, or commercialization of AI models or AI systems entities or their affiliates; and any other relationship that a reasonable person would consider relevant to the member's independence. All disclosures shall be published on the public portal under section 2007(d) within 15 days of submission. A TWG member who fails to disclose a material conflict of interest is subject to removal from the TWG and referral to the Director of AI Investigation under subsection (d)(2). TWG members are additionally subject to mandatory recusal from any TWG matter in which they have a covered financial interest under 18 U.S.C. § 208.
(7) FACA APPLICABILITY.—Each TWG shall operate as a Federal Advisory Committee subcommittee subject to the Federal Advisory Committee Act (5 U.S.C. App. 2), with the following procedures established by statute:
(A) CLOSED SESSIONS.—TWG sessions, including expert presentation sessions under subsection (b)(15), weekly all-day consolidation sessions, classified sessions, and subgroup working sessions, shall be closed to public attendance. This provision constitutes a statutory specification of meeting procedures under this title and supersedes the general open-meeting requirement of 5 U.S.C. App. 2 § 10(a)(1) with respect to TWG sessions. This closure is necessary to enable candid expert testimony on sensitive commercial, technical, and national security matters, to protect trade-secret and classified information, and to preserve the pre-decisional deliberative integrity of the investigatory process.
(B) PUBLIC ACCESSIBILITY OF RECORDS.—Notwithstanding the closed-session requirement of paragraph (1), the complete documentary record of each TWG's activities shall be publicly accessible through the public portal under section 2007(d) in accordance with the publication timelines established by this title. Materials subject to mandatory public publication include: session summaries prepared by the TWG Administrative Coordinator; monthly work product submissions; monthly public ledgers; communication logs; expert presentation log entries; conflict-of-interest disclosures; and final domain recommendations and Domain Explanatory Reports. Pre-decisional deliberative materials, internal working drafts, trade-secret materials, and classified materials are not subject to mandatory public disclosure but shall be maintained in the TWG document repository and made available to Congress upon request. The public accessibility of the TWG record under this paragraph constitutes compliance with the public availability requirements of 5 U.S.C. App. 2 § 10(b) with respect to TWG activities under this title.
(C) BALANCED MEMBERSHIP.—Membership in each TWG shall reflect balance as required by 5 U.S.C. App. 2 § 5(b)(2) and the specific composition requirements of paragraphs (2) through (12) of section 2004.
(D) PUBLIC RECORD.—The public portal established under section 2007(d) shall serve as the official public record of TWG activities for FACA purposes. The TWG Administrative Coordinator shall be responsible for its completeness and currency.
(8) RELATIONSHIP TO PARENT COMMITTEE.—Each TWG shall report to the Federal Advisory Committee through two distinct channels serving distinct functions
(A) the TWG's elected Coordination Council representative under subsection (c), who manages cross-domain coordination, jurisdictional disputes, definitional conflicts, and inter-TWG evidence sharing
(B) the TWG's elected FAC representative under subsection (e), who participates in FAC legislative drafting deliberations and transmits the TWG's domain findings and recommendations into the legislative process. TWG chairs shall attend the Committee's monthly meetings for the portions of the agenda addressing their domain. The Committee may direct a TWG to revise, supplement, or withdraw a draft recommendation by majority vote of the Committee. A TWG that disagrees with a Committee direction to revise or withdraw a recommendation may, through its FAC representative, request reconsideration at the next Committee meeting; the Committee's determination upon reconsideration is final within the FAC/TWG structure.
(9) MONTHLY WORK PRODUCT SUBMISSIONS.—Each TWG shall submit a structured monthly work product report to the Federal Advisory Committee not later than the last business day of each calendar month throughout the investigatory period from the TWG's organizational meeting through the TWG's 8.5-month deadline. The monthly report shall be prepared by the TWG Administrative Coordinator based on materials produced by the TWG during the preceding month and shall be reviewed by the TWG Chair before submission. Each monthly report shall include:
(A) a summary of the investigatory work conducted during the preceding month, including witnesses interviewed, documents reviewed, and research completed;
(B) findings to date in the TWG's domain, clearly distinguishing between conclusions supported by strong evidence, preliminary findings, and areas of genuine uncertainty;
(C) draft recommendation language for any provisions the TWG has developed to a sufficient state of maturity for Committee review, with supporting rationale and evidentiary basis;
(D) identification of any cross-TWG conflicts, definitional inconsistencies, or jurisdictional overlaps discovered during the preceding month, with the affected TWG identified by number;
(E) open questions requiring FAC resolution, including questions requiring cross-domain coordination; and
(F) the TWG's assessment of its progress toward completing its mandate and any resource or timeline concerns.
The Federal Advisory Committee shall review each monthly submission within 15 days of receipt, flag any irreconcilable cross-TWG conflicts for resolution, and transmit any conflicts to the relevant TWG Administrative Coordinators for scheduling of joint sessions. Monthly reports shall be published on the public docket within 5 business days of submission.
(10) MONTHLY PUBLIC LEDGER.—Not fewer than 2 business days before each TWG's assigned monthly publication date under the staggered schedule established under section 2006(f)(2), beginning with the first full calendar month following the TWG's organizational meeting, the Public Records Officer appointed under section 2006(f)(5), not any TWG member, shall prepare a monthly public ledger for each TWG, based on the structured input package transmitted by the TWG Administrative Coordinator under section 2006(f)(7), and transmit each completed ledger to the Public Docket Administrator for publication under section 2006(f)(2). The ledger shall not be edited, reviewed, or approved by any TWG member before publication, to ensure the public record reflects an objective synthesis rather than the TWG's own characterization of its work. Each monthly ledger shall include: a summary of the investigatory work conducted during the preceding month; a description of the findings reviewed and the evidence considered; the cruxes, meaning the genuinely contested questions of fact, law, or policy where evidence is disputed or uncertain, identified during the period; the sources and external parties consulted during the period; and any significant developments that have altered the TWG's understanding of its domain. The ledger shall be written in plain language accessible to a non-specialist reader, with consistent terminology and formatting across all 11 TWGs to enable meaningful public comparison of investigatory progress. Drafts, working notes, internal deliberations, and preliminary analytical conclusions of TWG members are pre-decisional deliberative materials not required to be disclosed; only the synthesized ledger prepared by the Public Records Officer is subject to mandatory public disclosure under this subparagraph. Factual corrections to published ledgers are governed by section 2006(f)(2).
(11) WORK SCHEDULE.—Except for part-time and advisory members under subsection (a)(12)(D), TWG membership constitutes a full five-day professional work week commitment throughout the investigatory period from the TWG's organizational meeting through the TWG's 8.5-month final domain submission deadline. TWG members are expected to devote their primary professional time and attention to TWG work each day, including research, evidence review, document drafting, subgroup sessions, and preparation for the weekly all-day consolidation session. For full-time members, this is equivalent to a full-time federal position and is not a nominal commitment; part-time and advisory members appointed under subsection (a)(12)(D) participate on the terms specified in that subparagraph
(A) Daily Work (Four Days Per Week): On each of the four non-consolidation days each week, TWG members shall conduct independent and subgroup investigatory work appropriate to the TWG's current investigatory phase under subsection (b)(12). This includes: individual research and evidence review; subgroup analysis sessions on discrete domain questions; review and response to public submissions received through the public submission channel under subsection (b)(14); preparation of materials for the weekly consolidation session; and drafting of recommendation language for monthly work product submissions. The TWG Administrative Coordinator shall maintain a shared digital workspace and scheduling system accessible to all members for daily coordination
(B) Weekly All-Day Consolidation Session (One Day Per Week): Each TWG shall hold not fewer than one full all-day consolidation session per week. The consolidation session shall be held in person at the TWG's dedicated workspace established under paragraph (5) of section 2006(f). Members who cannot attend in person on a given week may participate remotely through the technical infrastructure provided by the Technical Systems Manager, provided that in-person attendance is the strong default and remote participation is the exception, not the routine. The consolidation session is dedicated to: synthesizing findings from the preceding week's daily work; deliberating on draft recommendation language; reviewing evidence and resolving factual disputes; preparing materials for the monthly work product submission; and deliberating on expert presentations scheduled for that session under subsection (b)(15). The TWG Administrative Coordinator shall publish the agenda for each weekly consolidation session on the public portal not fewer than 48 hours before the session. The session agenda and a summary of proceedings shall be published on the public portal within 5 business days of each session. The content of deliberations, including draft recommendation language under discussion, is pre-decisional deliberative material not required to be disclosed; only the session summary prepared by the Administrative Coordinator is subject to mandatory publication.
(12) MANDATE STRUCTURE.—Each TWG's mandate shall be executed in the following four sequential phases, which may overlap in practice but which structure the TWG's outputs
(A) DOMAIN EXAMINATION.—identifying and documenting the harms, risks, threats, and affected populations arising from AI models or AI systems in the domain; the gaps in existing federal law and regulation; the limitations of current enforcement; and the characteristics of affected populations with particular attention to vulnerable groups. In conducting Domain Examination, each TWG shall actively seek out available public opinion research and public input bearing on its domain, including outputs of citizens assemblies organized by any person or entity, deliberative polling processes, nationally representative surveys, recorded and structured public debates, public opinion research commissioned by any person or entity, and other mechanisms through which the views of affected populations on AI-related questions have been gathered. Where such research or input is available, it shall be incorporated into the TWG's evidentiary record with appropriate assessment of the source and methodology. The TWG Administrative Coordinator shall query the shared evidence repository and the Public Engagement Coordinator for relevant public opinion research and input at the outset of the Domain Examination phase and on a rolling basis throughout the investigatory period;
(B) INTERVENTION EVALUATION.—evaluating potential legislative interventions and solutions, including their costs, benefits, constitutional parameters, implementation requirements, and enforcement mechanisms. All options shall be evaluated, including no regulation, repeal or modification of existing legislation, and industry self-regulation, as well as new federal regulatory frameworks; no option shall be excluded from consideration on grounds other than the evidentiary record
(C) TRADEOFF ASSESSMENT.—assessing the tradeoffs among alternatives, including the distributional effects of each approach, the risks of over-regulation and under-regulation, the constitutional vulnerabilities of each option, and the administrative feasibility of implementation
(D) RECOMMENDATION DEVELOPMENT.—developing specific legislative recommendations with supporting rationale and evidentiary basis, or a formal finding that no regulation is warranted with the specific evidentiary and constitutional basis for that finding. A finding of no regulation is a legitimate and respected output, not a default or a failure.
(13) COMMUNICATION LOG.—The TWG Administrative Coordinator shall maintain a complete, contemporaneous public log of all external communications made in connection with any TWG's work. The log shall include: the date of each communication; the name, title, and organizational affiliation of each external party communicated with; the medium of communication; the TWG or TWG member to whom the communication was directed; and a brief description of the subject matter. The log shall be updated within 3 business days of each communication and published on the public portal under section 2007(d). All written communications, including email, direct messages, and any other written medium, sent to or received by any TWG member in their TWG capacity shall be treated as public records and transmitted to the Public Docket Administrator within 5 business days of receipt or transmission. The Public Docket Administrator shall publish all such communications, subject only to redaction of: personally identifiable information of private individuals; information subject to law enforcement privilege; and information submitted under a confidentiality agreement pursuant to section 2008(c), provided that the existence of the communication and the identity of the submitting party shall always be disclosed even where content is redacted.
(14) PUBLIC SUBMISSION CHANNEL.—Each TWG shall maintain a dedicated public-facing email address for that TWG, established and published on the public portal by the Technical Systems Manager not later than Day 120. The email address shall follow a standardized format identifying the TWG by number and domain. The TWG Administrative Coordinator, not any TWG member, shall manage the public submission inbox for their assigned TWG and shall be solely responsible for receiving, logging, triaging, and routing inbound submissions. Any person, organization, researcher, community group, affected individual, or other party may submit written information, evidence, research, analysis, or policy argument to a TWG through the public submission channel. Submissions through the public channel shall be subject to the following requirements and procedures
(A) Conflict of Interest Disclosure: each submission shall include the name and organizational affiliation of the submitting party; a description of any financial relationship between the submitting party and any frontier AI developer, significant AI deployer, or any entity whose primary business involves the development, deployment, or commercialization of AI models or AI systems or any entity with a material financial interest in the TWG's domain within the preceding one year; and a disclosure of whether the submission was prepared in whole or in part by a person with a financial interest in the TWG's recommendations. The TWG Administrative Coordinator shall not route a submission to TWG members until required disclosures are complete; submissions without required disclosures shall be returned with a request for completion within 5 business days
(B) Logging and Publication: all submissions received through the public channel shall be logged in the communication log within 3 business days of receipt and published on the public docket within 5 business days of receipt, together with the accompanying conflict of interest disclosure. No submission shall be withheld from the public docket except on the specific grounds authorized by subsection (b)(13)
(C) Routing: the TWG Administrative Coordinator shall route each submission to the TWG member or members whose expertise is most relevant to the subject matter of the submission, with a copy to the TWG Chair. The TWG Chair shall determine whether the submission warrants a response, referral to a subgroup, consideration at the weekly consolidation session, or no further action. The TWG is not required to respond to or act on any particular submission, but shall not exclude submissions from its consideration on any basis other than relevance to its mandate
(D) Volume Management: if the volume of public submissions to a particular TWG exceeds the Administrative Coordinator's capacity to process within required timeframes, the Administrative Coordinator shall notify the Executive Director, who shall provide additional administrative support from the broader FAC staff or from GAO staff under the interagency agreement.
(15) EXPERT PRESENTATIONS.—TWGs shall actively solicit expert presentations as a primary method of evidence gathering throughout the investigatory period. Expert presentations are internal working sessions of each TWG, closed to public attendance under subsection (b)(7)(A). The following procedures govern expert presentations
(A) TWG-Initiated Presentations: any TWG member may nominate an outside expert to present to the TWG by submitting a written recommendation to the TWG Chair identifying the proposed presenter, their relevant expertise, and the specific subject matter on which the presentation is sought. The TWG Chair shall accept or decline the nomination within 5 days. If accepted, the TWG Administrative Coordinator shall contact the proposed presenter and schedule the presentation
(B) Publicly Requested Presentations: any person or organization that wishes to present to a specific TWG may submit a presentation request through the TWG's public submission channel. The request shall identify the proposed presenter, their relevant expertise, and the specific subject matter and argument they wish to present. The TWG Chair shall accept or decline the request within 5 days of receipt by the Administrative Coordinator. The TWG Chair's decision is final and is not subject to appeal, but the grounds for declining shall be documented in writing and published on the public docket. Requests may be declined on the grounds that the subject matter falls outside the TWG's domain mandate, that the presentation would be duplicative of evidence already received, or that the TWG's schedule does not permit additional presentations given the 8.5-month deadline - but may not be declined on the basis of the presenter's viewpoint or the expected content of the presentation
(C) Scheduling: all accepted presentations shall be scheduled by the TWG Administrative Coordinator. Presentations may be conducted during the weekly all-day consolidation session or during a separately scheduled working session
(D) Presenter Disclosure Requirements: each presenter shall, before presenting, complete the conflict-of-interest disclosure required for public submissions under paragraph (14)(A). The disclosure shall be published on the public docket within 5 business days of the presentation
(E) Public Log Entry: the TWG Administrative Coordinator shall create a public log entry for each expert presentation within 3 business days of the session. The log entry shall include: the date of the presentation; the name, title, and organizational affiliation of the presenter; the subject matter of the presentation at a level of specificity sufficient to describe the topic presented; and the TWG to which the presentation was made. The content of the presentation, including slides, documents provided, and the discussion that followed, is internal TWG working material and is not published on the public docket, but is part of the TWG's evidentiary record and subject to disclosure to congressional oversight committees upon request
(F) Internal Transcription: the TWG Administrative Coordinator shall arrange for a verbatim transcript of each expert presentation, including the presentation itself and any TWG member questions and responses. The transcript shall be maintained in the TWG's internal document repository, accessible to all TWG members and to the FAC Legislative Drafting Staff upon request. Internal transcripts are not published but shall be transmitted to the FAC alongside the relevant monthly work product submission or final domain recommendations as supporting documentation.
(16) CLASSIFIED INFORMATION AND CLEARANCE REQUIREMENTS.—Certain TWGs will necessarily receive classified information in the course of their investigatory mandate, including classified assessments of AI capability, classified export control determinations, classified threat assessments, and classified evaluations of autonomous weapons systems. The following provisions govern the handling of classified information by TWGs
(A) Clearance as Appointment Condition for Designated Slots: for each TWG slot designated as requiring access to classified information in paragraphs (2) through (12) of section 2004, clearance eligibility shall be a condition of appointment. The relevant appointing authority shall, before making an appointment to a designated slot, verify that the prospective appointee is eligible for the required clearance level and initiate the clearance process simultaneously with the appointment. A person who is ineligible for the required clearance level may not be appointed to a designated slot. The designation of which slots within each TWG require clearance eligibility shall be specified by the Director of AI Investigation in consultation with the relevant seed members, not later than Day 50, and published in an unclassified summary on the public portal
(B) Non-Clearable Members: a TWG member who does not hold or cannot obtain the clearance required for a particular classified session shall be excluded from that session only. Exclusion from a classified session does not affect the member's standing, voting rights, or obligations with respect to all other TWG activities. The TWG Administrative Coordinator shall maintain a record of which members attended each classified session, and the TWG Chair shall ensure that classified information disclosed in a classified session is not discussed in any session from which non-cleared members are excluded without their knowledge. The TWG shall structure its work to minimize the number of classified sessions required and to maximize the participation of all members in unclassified work
(C) Classified Session Procedures: classified sessions of a TWG shall be conducted in a facility approved for classified discussions at the relevant classification level, arranged by the TWG Administrative Coordinator in coordination with the relevant security authority. Classified sessions shall not be transcribed by the Administrative Coordinator; instead, a classified summary shall be prepared by a cleared TWG member designated by the TWG Chair, maintained in a classified document repository separate from the TWG's general document repository, and accessible only to cleared members of that TWG and to cleared FAC members. The public log entry for a classified session shall note only the date, the TWGs involved, and that a classified session was held; no subject matter description shall be included in the public log entry for a classified session
(D) Classified Annex to Monthly Work Product Submissions: where a TWG's monthly work product submission includes findings, draft recommendations, or evidence derived from classified sources, the TWG shall produce a classified annex to that month's submission. The unclassified submission shall be published on the public docket as required by subsection (b)(9). The classified annex shall be transmitted separately to cleared FAC members only, through secure channels established by the Technical Systems Manager in coordination with the relevant security authority, and shall not be published on the public docket
(E) Classified Report to Congressional Oversight Committees: the FAC shall, not later than 30 days after the FAC backstop transmission deadline established under section 2006(i), transmit a classified supplemental report to the Committee on Armed Services and the Select Committee on Intelligence of each chamber, summarizing all classified information considered by any TWG that bears on the legislative recommendations transmitted to Congress, and identifying any classified findings that Congress should consider in enacting Phase II legislation. The classified supplemental report shall be prepared by the FAC Legislative Drafting Staff in coordination with the relevant cleared TWG members and shall be reviewed by the Director of National Intelligence before transmission.
(c) TWG COORDINATION COUNCIL.
(1) ESTABLISHMENT AND COMPOSITION.—There is established a TWG Coordination Council (in this subsection, the "Coordination Council") composed of one primary representative and one deputy representative elected from each of the 11 TWGs, for a total of 11 primary representatives and 11 deputy representatives, and the Epistemic Advisor appointed under section 2006(b)(1)(H) as a standing non-voting participant. The Epistemic Advisor shall attend all Coordination Council sessions with full speaking rights and may not be excluded from any session by the Coordination Council presiding officer or any TWG representative. The Epistemic Advisor's role in Coordination Council proceedings is to identify cross-TWG epistemic inconsistencies - including cases where two or more TWGs are drawing materially different inferences from the same underlying evidence, where the Coordination Council's definitional or jurisdictional harmonization decisions appear driven by considerations other than evidentiary reasoning, or where the shared evidence repository reflects systematic gaps or imbalances in evidence-gathering across domains. The Epistemic Advisor may submit written observations on any Coordination Council matter to the presiding officer at any time; such observations shall be entered in the public Coordination Council record and transmitted to the relevant TWG Administrative Coordinators within 5 business days. The Coordination Council may hold meetings and conduct its functions with fewer than 11 primary representatives present during any period before all 11 TWGs have held their organizational meetings; a quorum of the Coordination Council shall consist of a majority of the primary representatives then elected. Coordination Council resolutions adopted before all 11 representatives are seated are binding but shall be made available for reconsideration within 10 days of a newly seated representative's request, if the newly seated representative demonstrates that the resolution materially affects their TWG's domain. The Coordination Council shall elect a presiding officer from among the primary TWG representatives who have been elected at the time of the Council's first meeting by majority vote, not later than Day 174. The presiding officer serves for the duration of the investigatory period and may be recalled by two-thirds vote of primary representatives. The presiding officer shall chair Council meetings, coordinate scheduling of joint sessions, and transmit written resolutions to the Federal Advisory Committee. The Coordination Council shall be a standing body for the duration of the investigatory period and shall continue to meet until both of the following have occurred: the Federal Advisory Committee has completed its legislative transmission to Congress under subsection (f); and the National AI Council has assumed its full mandate. The Coordination Council shall remain operational through any overlap period between the FAC's legislative transmission and the National AI Council's full constitution, providing continuity of cross-domain coordination.
(2) ELECTION OF REPRESENTATIVES.
(A) TIMING.—Each TWG shall elect its primary representative and deputy representative to the Coordination Council not later than 14 days after the TWG's first organizational meeting - that is, not later than Day 169. The election shall take place during the TWG's normal working sessions. The election shall be conducted by separate majority vote of the full TWG membership and shall be the TWG's first order of business within its first 14 days of operation following the organizational meeting.
(B) ROLE AND ELIGIBILITY - COORDINATION COUNCIL REPRESENTATIVE.—The Coordination Council representative serves a coordination function: harmonizing definitions across TWGs, resolving cross-domain jurisdictional questions, sharing evidence, and ensuring the 11 parallel investigations remain coherent and non-duplicative. In electing their Coordination Council representative, TWG members shall prioritize the member who: has sufficient command of the TWG's domain to represent its work accurately to other TWGs; possesses the temperament and communication skills to work constructively across domain boundaries; can identify when another TWG's work intersects with their own domain and flag it promptly; and can absorb and relay information across domains without losing the technical integrity of their own TWG's findings. Deep technical expertise in the TWG's domain is valuable but secondary to cross-domain fluency and coordination effectiveness. A member elected as Coordination Council representative may also serve as the TWG's FAC representative under subsection (e); the two roles may be held concurrently by the same member if the TWG determines that person is best suited to both functions. Only current members of the TWG are eligible to serve as primary representative or deputy representative. The primary representative shall be a full-time member; a part-time member under subsection (a)(12)(D) may serve as deputy representative. An advisory member under subsection (a)(12)(D) may not serve as primary representative or deputy representative. No outside hire, staff member, contractor, or person who is not a duly appointed TWG member may serve in either capacity. A member who is elected as primary representative of one TWG may not simultaneously serve as deputy representative of any other TWG.
(C) TERM.—The primary representative and deputy representative each serve for the duration of the TWG's mandate unless earlier removed pursuant to the recall procedures of subparagraph (D). If a vacancy occurs in the primary representative position for any reason, the deputy representative assumes the primary representative role immediately upon vacancy, and the TWG shall elect a new deputy representative within 15 days.
(D) RECALL.—A primary representative or deputy representative may be removed from their Coordination Council role by a two-thirds vote of the full TWG membership at any time, upon petition signed by not fewer than one-third of TWG members requesting a recall vote. The petition shall state with specificity the grounds for recall. Upon receipt of a valid petition, the TWG Chair shall schedule a recall vote within 15 days. A representative subject to a recall petition shall be temporarily suspended from Coordination Council participation pending the outcome of the recall vote, with the deputy representative (or, if the deputy representative is the subject of the petition, a pro tempore representative elected by simple majority of the TWG) serving in the interim. A representative who has been recalled may not be re-elected to the same Coordination Council role.
(E) DEPUTY REPRESENTATIVE ROLE.—The deputy representative shall attend all Coordination Council meetings as an observer with the right to speak but not vote, unless substituting for the primary representative. The deputy representative shall maintain independent awareness of all Coordination Council proceedings and shall serve as an independent check on the primary representative's conduct. If a deputy representative has reason to believe that the primary representative is misrepresenting the TWG's positions to the Coordination Council, the deputy representative may file a complaint under the misconduct procedures of subsection (d) without first seeking TWG Chair approval.
(3) FUNCTIONS OF THE COORDINATION COUNCIL.—The Coordination Council shall perform the following functions:
(A) SHARED DEFINITIONAL REGISTRY.—The Coordination Council shall maintain a publicly accessible shared definitional registry containing every term that any TWG proposes to define, use in a sense that differs from the definitions in section 2003, or adopt from another TWG's prior work. Any TWG that proposes a definition or proposes to use an existing term in a modified sense shall submit the proposed definition to the Coordination Council. The Coordination Council shall publish the proposed definition on the public portal under section 2007(d) and provide all other TWGs not less than 15 days to comment. If no TWG objects within 15 days, the definition is entered into the registry as adopted. If any TWG objects, the Coordination Council shall convene a joint session within 10 days to resolve the conflict. A definition that cannot be resolved by the Coordination Council shall be referred to the parent Federal Advisory Committee for resolution before either conflicting definition may be used in a final TWG recommendation. The definitional registry shall be updated in real time and shall be publicly available throughout the investigatory period.
(B) JOINT SESSION AUTHORITY.—The Coordination Council may, by majority vote of primary representatives, convene a joint session of any two or more TWGs when their domains overlap on a specific issue. Joint sessions shall produce jointly developed recommendations that are transmitted to the parent Committee under both TWGs' names. Participation in a joint session does not waive a TWG's jurisdictional claim to any matter within its primary domain. The Coordination Council shall convene joint sessions between TWG 5 and TWG 11 for all matters that intersect AI safety evaluation and autonomous weapons governance, and between TWG 3 and TWG 5 for all matters that intersect compute governance and open-weight model safety.
(C) JURISDICTIONAL DISPUTE RESOLUTION.—When two TWGs assert competing jurisdiction over a specific matter, either TWG may refer the dispute to the Coordination Council. The Coordination Council shall resolve jurisdictional disputes within 15 days by majority vote of primary representatives, with the two disputing TWGs' representatives recusing themselves from the vote. A TWG that disagrees with the Coordination Council's jurisdictional determination may appeal to the parent Committee within 5 days, and the Committee's determination shall be final.
(D) CROSS-DOMAIN EVIDENCE SHARING.—The Coordination Council shall maintain a shared evidence repository accessible to all TWG members containing all non-classified data, research, and investigatory materials produced by or obtained by any TWG. TWGs shall not conduct duplicative investigation of matters already investigated by another TWG when the existing evidence is sufficient; they shall instead build on the shared repository and note reliance on another TWG's work product. The Coordination Council shall, at each biweekly meeting, review the evidence gathering plans of each TWG to identify and prevent redundancy.
(E) MEETING SCHEDULE.—The Coordination Council shall meet not less frequently than biweekly throughout the investigatory period. Coordination Council sessions shall be closed to public attendance for the same reasons and under the same statutory authority as TWG sessions under subsection (b)(7)(A) - to enable candid cross-domain coordination, protect pre-decisional deliberative material and trade-secret information, and preserve the integrity of the investigatory process. Notwithstanding the closed-session requirement, the complete documentary record of Coordination Council activities shall be publicly accessible through the public portal under section 2007(d). Materials subject to mandatory public publication include: meeting agendas, published not less than 5 business days before each meeting; meeting summaries prepared by the presiding officer or designee, published within 7 business days of each meeting; all written resolutions and definitional registry entries; jurisdictional dispute determinations; cross-domain evidence sharing logs; and the mid-course reconciliation report required by subsection (c)(4). Pre-decisional deliberative materials and classified session content are not subject to mandatory public disclosure. Sessions addressing classified information shall be conducted under the classified session procedures of subsection (b)(16)(C).
(4) ENABLING GOVERNANCE ASSESSMENT.—In addition to its harmonization and conflict-resolution functions, the Coordination Council shall, at the mid-course reconciliation session under subsection (c)(4), produce a preliminary Enabling Governance Assessment identifying, for each of the 19 investigation domains: which domains are expected to present significant enabling governance questions based on investigatory progress to date; any early indications of proposed legislative interventions that may suppress beneficial AI deployment or productivity gains; and cross-domain enabling governance opportunities identified in the first half of the investigatory period. Not later than 30 days before the FAC backstop transmission deadline under section 2006(i), the Coordination Council shall produce a final Enabling Governance Assessment identifying, for each of the 19 investigation domains: any proposed legislative interventions that TWGs have identified as potentially suppressing beneficial AI deployment or productivity gains; governance frameworks, including regulatory safe harbors, liability shields, certification pathways, or public investment mechanisms, that TWGs have identified as enabling responsible AI deployment rather than restricting it; and cross-domain enabling governance opportunities, meaning cases where a governance structure in one domain could enable productivity gains in another. The Enabling Governance Assessment shall be transmitted to the FAC Legislative Drafting Staff, deposited in the shared evidence repository, published on the public portal, and transmitted to Congress alongside the FAC's legislative package. The FAC Legislative Drafting Staff shall consider the Enabling Governance Assessment when finalizing each domain package and shall note in the section-by-section analysis whether and how enabling governance considerations were incorporated into or excluded from each transmitted provision.
(5) MID-COURSE RECONCILIATION SESSION.—Not later than Day 230 after the date of enactment of this title, the Coordination Council shall convene a mandatory full-day joint reconciliation session of all 11 TWG primary representatives and all 11 deputy representatives, presided over by the Coordination Council presiding officer. The purpose of the mid-course reconciliation session is to review the preliminary findings and emerging recommendations of each TWG, identify conflicts, inconsistencies, or gaps in coverage before draft criteria documents are due under section 2007, and direct remediation before findings harden into formal recommendations. The mid-course reconciliation session shall produce a written reconciliation report transmitted to the parent Federal Advisory Committee and to the lead agency within 10 days, identifying: any definitional conflicts not yet resolved; any jurisdictional disputes pending resolution; any domains in which the TWG investigation appears insufficiently developed to support criteria documents by each TWG's 8.5-month deadline; and any recommendations for reallocation of investigatory resources across TWGs. The reconciliation report shall be publicly available on the portal under section 2007(d).
(d) TWG INTEGRITY AND MISCONDUCT FRAMEWORK.
(1) CATEGORY 1 - PROCEDURAL MISCONDUCT.—Procedural misconduct means any of the following conduct by a TWG member, including a primary or deputy Coordination Council representative: misrepresenting the TWG's adopted positions to the Coordination Council or to the parent Committee; taking actions outside the TWG member's authority as defined by this title or by the TWG's governing procedures; failing to timely disclose a conflict of interest as required by subsection (b)(6); or engaging in conduct that materially impedes the TWG's work.
(A) INTERNAL PROCESS.—Any TWG member may file a written complaint alleging procedural misconduct with the TWG Chair, with a copy to the deputy Coordination Council representative. The complaint shall state with specificity the conduct alleged and the date or period during which it occurred. The TWG Chair shall, within 3 business days of receiving the complaint, acknowledge receipt in writing to the complainant and provide a copy to the accused member. The TWG shall investigate the complaint and take corrective action, if warranted, within 15 days of receipt. Corrective action may include: formal written censure; temporary suspension from Coordination Council participation, with the deputy representative substituting; referral for recall under subsection (c)(2)(D); or referral to the Director of AI Investigation under subparagraph (B) if the investigation reveals conduct meeting the Category 2 standard.
(B) ESCALATION TO DIRECTOR OF AI INVESTIGATION.—A complaint shall escalate automatically to the Director of AI Investigation when: the TWG Chair fails to investigate or take corrective action within 15 days; the complaint implicates the TWG Chair's own conduct; the TWG Chair is the accused member; the TWG votes to dismiss a complaint that the complainant believes has merit and the complainant requests escalation; or the TWG's investigation reveals conduct that meets the Category 2 standard of paragraph (2). Upon escalation, the Director of AI Investigation shall investigate and respond within 15 additional days.
(2) CATEGORY 2 - SUBSTANTIVE FRAUD.—Substantive fraud means any of the following conduct by any TWG member or Coordination Council participant: falsifying, fabricating, or materially misrepresenting evidence submitted to or considered by any TWG; deliberately suppressing adverse findings or evidence that contradicts a TWG recommendation; accepting compensation, gifts, or benefits from any frontier AI developer, significant AI deployer, or any entity whose primary business involves the development, deployment, or commercialization of AI models or AI systems or any entity with a material financial interest in a TWG recommendation, that were not disclosed pursuant to subsection (b)(6) and that a reasonable person would conclude influenced or were intended to influence the member's TWG work; or coordinating TWG positions with a frontier AI developer, significant AI deployer, or any entity whose primary business involves the development, deployment, or commercialization of AI models or AI systems outside of the TWG's duly noticed public proceedings.
(A) MANDATORY REFERRAL.—Upon determining that conduct meets the Category 2 standard, the Director of AI Investigation shall, within 5 business days, simultaneously: refer the matter to the Inspector General of the Department of Commerce for investigation under the Inspector General Act of 1978 (5 U.S.C. § 401 et seq.); refer the matter to the Department of Justice for assessment of potential criminal liability under 18 U.S.C. § 1001 (false statements), 18 U.S.C. § 201 (bribery), or other applicable statutes; suspend the accused member from all TWG and Coordination Council participation pending the outcome of the investigation; and notify the parent Federal Advisory Committee Chair.
(B) WHISTLEBLOWER PROTECTIONS EXTENDED.—The whistleblower protections of section 2018 of this title are hereby extended in full to any person who discloses information that the person reasonably believes constitutes evidence of Category 2 substantive fraud in any TWG or in the Coordination Council. For purposes of section 2018, a TWG or Coordination Council proceeding is treated as equivalent to a frontier AI developer, significant AI deployer, or any entity whose primary business involves the development, deployment, or commercialization of AI models or AI systems's internal proceeding, and any retaliation against a person for disclosing Category 2 conduct, including removal from a TWG, exclusion from a Coordination Council session, non-renewal of an appointment, or any other adverse action, shall be treated as a violation of section 2018 subject to all remedies provided in that section. Any nondisclosure agreement, consulting agreement, or terms of engagement that purports to restrict a TWG member's ability to disclose Category 2 conduct is void and unenforceable as against public policy.
(3) CATEGORY 3 - SYSTEMIC CORRUPTION.—Systemic corruption means any of the following conditions affecting a TWG as a whole or the Coordination Council: a majority of a TWG's members have undisclosed conflicts of interest that were not identified at the time of appointment; a TWG's recommendations, taken as a whole, systematically reflect the interests of a single industry category rather than the balanced mandate required by subsection (b)(1), in a manner that cannot be explained by the weight of evidence; the Coordination Council is operating in a manner that systematically advantages one or more TWGs over others without evidentiary basis; or two or more members of a single TWG or of the Coordination Council are engaged in coordinated Category 2 conduct.
(A) MANDATORY CONGRESSIONAL NOTIFICATION.—Upon determining that conditions meeting the Category 3 standard exist in any TWG or in the Coordination Council, the Director of AI Investigation shall, within 5 business days, transmit a written notification to the Committee on Commerce, Science, and Transportation of the Senate; the Committee on Energy and Commerce of the House of Representatives; and the chairs and ranking members of both committees. The notification shall be mandatory and shall not be withheld, delayed, or modified by the Secretary, any political appointee, or any other executive branch official. Any attempt to suppress or delay the Category 3 notification by any executive branch official is itself a violation of this title subject to the accountability provisions of section 2017. The notification shall describe: the specific conditions identified; the evidence on which the determination is based; the TWG or Coordination Council affected; the remedial actions taken or proposed; and any further investigative steps underway.
(B) REMEDIATION WITHOUT DISSOLUTION.—Upon issuing a Category 3 notification, the Director of AI Investigation shall implement targeted remediation measures calibrated to address the specific systemic condition identified, without dissolving the entire TWG or terminating the investigation. Remediation measures may include: appointment of replacement members to remedy composition imbalances, pursuant to the Secretary's appointment authority under subsection (b)(1); appointment of an independent special monitor with authority to attend all TWG and Coordination Council sessions and report directly to the parent Federal Advisory Committee; mandatory disclosure review of all TWG members' conflicts of interest by an independent ethics officer; or referral of specific TWG recommendations to the parent Committee for independent validation before transmission to the lead agency. Dissolution of a TWG is a remedy of last resort available only if the Director of AI Investigation determines, in a written finding transmitted to Congress, that targeted remediation is insufficient to restore the TWG's integrity.
(C) INDEPENDENT GAO REVIEW CHANNEL.—Any member of the public, any TWG member, any federal employee, and any member of Congress may submit a complaint alleging Category 3 systemic corruption directly to the Comptroller General of the United States at any time. The Comptroller General, in conducting the independent review of the investigation under section 2010(e), is hereby directed to include in that review an assessment of: the independence of each TWG from industry influence; the adequacy of conflict-of-interest disclosures for all TWG members; whether any TWG's composition or recommendations show evidence of systematic bias or industry capture; and the integrity of the Coordination Council's operations. The Comptroller General shall transmit a preliminary integrity assessment to Congress not later than Day 210, concurrent with the Interim Investigative Status Report under section 2010(b), and shall include a final integrity assessment in the independent review report due at Day 360 under section 2010(e).
(D) NO RETALIATION FOR CATEGORY 3 REPORTS.—The whistleblower protections of section 2018 and the extended protections of subsection (d)(2)(B) apply in full to any person who submits a Category 3 complaint to the Director of AI Investigation, to the Inspector General of the Department of Commerce, to the Comptroller General, or to any member of Congress. No adverse action may be taken against any TWG member, federal employee, or member of the public for submitting a good-faith Category 3 complaint, regardless of whether the complaint is ultimately sustained.
(e) ELECTION OF TWG REPRESENTATIVES TO THE FEDERAL ADVISORY COMMITTEE.
(1) TIMING.—Each TWG shall elect one representative to the Federal Advisory Committee not later than 30 days after the TWG's first organizational meeting - that is, not later than Day 185. The election shall take place by majority vote of the TWG's full membership during a duly noticed TWG session.
(2) ELIGIBILITY.—Any current full-time member of the TWG is eligible to serve as the TWG's FAC representative. A member simultaneously serving as the TWG's Coordination Council primary representative is eligible and may hold both roles concurrently if the TWG determines that person is best suited to both functions. The allied nation contributing expert serving under subsection (a)(12)(A), the under-25 member serving under subsection (a)(12)(C), and any part-time or advisory member serving under subsection (a)(12)(D) may not serve as FAC representative.
(3) QUALIFICATIONS FOR FAC SERVICE.—In electing their FAC representative, TWG members shall prioritize the member who
(A) has the deepest substantive command of the TWG's domain findings and the technical nuance of the legislative questions arising from that domain;
(B) is best positioned to translate the TWG's investigatory findings into binding statutory language - meaning the member has demonstrated ability to produce or critically evaluate legislative text, not merely policy analysis;
(C) can articulate the evidentiary basis and limitations of the TWG's findings to the full FAC across all 19 domains;
(D) can represent the TWG's collective conclusions in FAC deliberations - not as a delegate bound by TWG instruction but as the member whose expertise and judgment best embodies what the TWG has learned; and
(E) can commit to the additional time demands of FAC service alongside continued TWG membership.
(4) DISTINCTION FROM COORDINATION COUNCIL ROLE.—The Coordination Council representative elected under subsection (c) serves a coordination function distinct from the FAC representative's legislative drafting function. The Coordination Council representative must have sufficient command of the TWG's domain to harmonize definitions with other TWGs, resolve cross-domain jurisdictional questions, and share evidence effectively - but the primary qualification is coordination capacity and cross-domain fluency, not depth of technical expertise in any single domain. A member who excels at coordination may be the right choice for the Coordination Council role even if another member has deeper technical expertise; conversely, the most technically expert member may be the right FAC representative even if less suited to the coordination role. TWGs are encouraged to consider these distinct qualifications separately, while recognizing that a member possessing both qualities may appropriately hold both roles concurrently.
(5) CONTINUED TWG MEMBERSHIP.—A TWG member elected to the FAC does not leave the TWG. They serve on both bodies simultaneously. Their TWG obligations, including participation in monthly work product submissions, weekly all-day sessions, cross-TWG coordination sessions, and ongoing investigatory work, continue in full. The FAC representative role is additive, not substitutive. The TWG shall not be depleted of a member's expertise by their election to the FAC. The Federal Advisory Committee Chair and the TWG Chair shall coordinate scheduling to minimize conflicts between FAC and TWG obligations for dual-role members.
(6) FAC SEAT ACTIVATION.—A TWG representative's FAC seat activates upon election, not upon completion of the TWG's investigatory work. TWG representatives join the FAC as they are elected beginning approximately Day 185. The FAC therefore has a rolling constitution: the 7 appointed members are seated from Day 60; TWG representatives join on a rolling basis from Day 185 through Day 195 as all 11 elections complete; the FAC is fully constituted at 18 members approximately Day 195, at which point the FAC Chair election occurs and the 12-vote voting threshold for legislative provisions becomes operative.
(7) LEGISLATIVE DRAFTING SUPPORT ACCESS.—From the date a TWG representative joins the FAC, the FAC's Legislative Drafting Staff are available to that representative and to the TWG for legislative drafting assistance, constitutional analysis, and cross-domain drafting coordination. TWGs may also submit research requests to the Congressional Research Service through the formal channel managed by the Executive Director. Legislative drafting support is available to TWGs throughout the investigatory period upon request, not only after FAC election.
(8) FALLBACK.—If any TWG fails to elect an FAC representative within 30 days of its organizational meeting, the Executive Director of the Federal Advisory Committee shall designate an FAC representative from among that TWG's full membership within 7 days thereafter, selecting the member who best meets the qualifications of paragraph (3).
(9) RECALL AND REPLACEMENT.—A TWG may recall its FAC representative by two-thirds vote of full TWG membership at any time, following the same recall procedures applicable to Coordination Council representatives under subsection (c)(2)(D). Upon recall, the TWG shall elect a replacement representative within 15 days. If the TWG fails to elect a replacement within 15 days, the Executive Director of the Federal Advisory Committee shall designate a replacement from among the TWG's full membership within 7 days thereafter.
SEC. 2006. FEDERAL ADVISORY COMMITTEE.
(a) ESTABLISHMENT.—There is established a Federal Advisory Committee on Artificial Intelligence Governance (in this section, the "Committee") under the Federal Advisory Committee Act (5 U.S.C. App. 2). The Committee shall serve as the primary legislative drafting body responsible for synthesizing the investigatory work of the Technical Working Groups into complete draft statutory language and transmitting that draft legislation directly to Congress not later than 30 days after the last TWG submits its final domain recommendations, and in no event later than 15 months after the date of enactment.
(b) COMPOSITION AND APPOINTMENT.—The Committee shall be composed of 18 voting members (7 appointed members and 11 Technical Working Group representatives elected under section 2005(e)) and one non-voting Epistemic Advisor appointed under subsection (b)(1)(H). The Epistemic Advisor participates in all Committee deliberations and all Coordination Council sessions under section 2005(c) with full speaking rights but shall not vote on any legislative provision, procedural matter, or other Committee action. The Epistemic Advisor's function is methodological: to evaluate the quality of reasoning underlying TWG findings and FAC legislative drafting, identify cognitive biases and epistemic weaknesses in the investigatory record, and ensure that the Committee's legislative output rests on sound evidentiary inference. The Epistemic Advisor is not a co-author of legislation and shall not be counted toward quorum.
(1) APPOINTED MEMBERS.—The following appointing authorities shall each appoint one member of the Committee, except that the Comptroller General under subparagraph (G) shall appoint the Epistemic Advisor on the terms of subsection (b)(1)(H):
(A) the President of the United States;
(B) the Majority Leader of the Senate;
(C) the Minority Leader of the Senate;
(D) the Speaker of the House of Representatives;
(E) the Minority Leader of the House of Representatives;
(F) the National Governors Association, which shall appoint two members; and
(G) the Comptroller General of the United States, who shall appoint one Epistemic Advisor under the terms of subparagraph (H).
Each member appointed under subparagraphs (A) through (F) shall have demonstrated expertise in federal legislative drafting, federal regulatory counsel, technology policy, public administration, labor economics, civil rights law, environmental policy, or national security. Preference shall be given to candidates with substantial experience in federal legislative drafting or federal regulatory counsel, including service as legislative counsel to a federal agency or committee of Congress, or practice as an attorney whose primary work involved federal regulatory drafting or compliance analysis. No member appointed under subparagraphs (A) through (F) shall have been employed by, served as a paid consultant to, received research funding exceeding $50,000 from, or held equity interests exceeding $10,000 in any frontier AI developer, significant AI deployer, or any entity whose primary business involves the development, deployment, or commercialization of AI models or AI systems or any entity whose primary business is the development, deployment, or commercialization of AI models or AI systems within the one year preceding appointment. The qualifications of the Epistemic Advisor appointed under subparagraph (G) are governed exclusively by subsection (b)(1)(H). Membership shall reflect diversity in professional background, geographic region, and demographic composition. Each appointing authority is strongly encouraged to consider for appointment individuals who served on the Federal Advisory Committee, its Technical Working Groups, or the lead agency's investigatory staff during Phase I, in order to preserve institutional continuity.
(H) EPISTEMIC ADVISOR.—The Comptroller General shall appoint one Epistemic Advisor not later than 120 days after the date of enactment. The Epistemic Advisor may be appointed concurrently with TWG Administrative Coordinators and other staff appointed around Day 120, allowing the Comptroller General to identify a qualified candidate during the initial 60-day period and complete the appointment in alignment with the constitution of the TWGs the Epistemic Advisor will serve. The Epistemic Advisor shall have demonstrated expertise in the epistemology of expert deliberation, the methodology of evidence-based policy, or the systematic study of cognitive bias in institutional and group decision-making, established through peer-reviewed publication, professional practice of not fewer than 7 years, or equivalent documented contribution to the field. The Epistemic Advisor shall have no financial relationship with any frontier AI developer, significant AI deployer, or any entity whose primary business involves the development, deployment, or commercialization of AI systems within the one year preceding appointment, consistent with the general disqualification of this subsection, and is subject to the conflict-of-interest disclosure obligations applicable to Committee members under subsection (e). The Epistemic Advisor shall be compensated at the same daily rate as appointed members under section 2005(b)(5). The Epistemic Advisor shall perform the following functions throughout the investigatory and legislative drafting period:
(i) attend all Federal Advisory Committee deliberations and all Coordination Council sessions under section 2005(c) as a non-voting participant with full speaking rights; the Epistemic Advisor may not be excluded from any such session by the Committee Chair, the Coordination Council presiding officer, or any other member;
(ii) review all monthly TWG work product submissions received under section 2005(b)(9) and submit written epistemic assessments to the Committee Chair and to the relevant TWG Administrative Coordinator within 15 days of receipt, identifying any material instances of confirmation bias, overconfidence in preliminary findings, inadequate treatment of contrary evidence, or inferential leaps unsupported by the evidentiary record; all such assessments shall be published on the public docket within 5 business days of submission;
(iii) submit a written cross-TWG epistemic assessment to the Coordination Council at the mid-course reconciliation session required by section 2005(c)(4), evaluating the methodological consistency and evidentiary integrity of each TWG's investigatory approach and identifying any patterns of systematic bias or evidentiary weakness that the Coordination Council should address before findings harden into formal recommendations; this assessment shall be incorporated into the reconciliation report transmitted to the Federal Advisory Committee and published on the public portal;
(iv) submit a written epistemic assessment of each TWG's final domain submission to the Committee within 30 days of receipt; this assessment shall be transmitted to Congress alongside the relevant domain package and published on the public docket as part of the complete deliberative record; and
(v) append a written epistemic critique to any legislative provision under FAC deliberation, at any time before the provision is voted upon, documenting methodological objections to the evidentiary basis or inferential structure of the provision; such critique shall be included in the argument log required by subsection (j) and transmitted to Congress alongside the legislative package but shall not delay or block the Committee's vote.
(2) APPOINTMENT DEADLINE AND FALLBACK.—Each appointing authority shall submit its appointments not later than 60 days after the date of enactment. If any appointing authority fails to submit appointments within the 60-day period, the Comptroller General shall make the unfilled appointments within 15 days thereafter. The 7 appointed members form the interim Committee from Day 60 through Day 185 as TWG representatives are elected under section 2005(e); during this period the appointed members establish Committee procedures, receive ongoing TWG work product through the public docket, and provide legislative drafting and legal research support to TWGs upon request, but shall take no substantive legislative votes until the Committee is fully constituted. The Epistemic Advisor, upon appointment at Day 120, shall participate in all interim Committee activities from the date of appointment in accordance with subsection (b)(1)(H).
(3) TWG REPRESENTATIVES.—Each of the 11 Technical Working Groups established under section 2004 shall elect one representative to the Committee under the procedures of section 2005(e). TWG representatives join the Committee on a rolling basis as elections complete, beginning approximately Day 185. The Committee is fully constituted at 18 members when all 11 TWG representatives have been elected, approximately Day 195.
(4) ONE-YEAR AI DISQUALIFICATION.—No member of the Committee, whether an appointed member or a TWG-elected representative, shall have been employed by, served as a paid consultant to, received research funding exceeding $50,000 from, or held equity interests exceeding $10,000 in any frontier AI developer, significant AI deployer, or any entity whose primary business involves the development, deployment, or commercialization of AI models or AI systems or any entity whose primary business is the development, deployment, or commercialization of AI systems within the one year preceding appointment or election to the Committee. For TWG-elected representatives, this disqualification is satisfied by the TWG membership eligibility requirements of section 2005(b) and need not be separately evaluated upon election to the Committee.
(c) CHAIR.—The Committee shall elect a Chair from among its own 18 voting members by a vote of not fewer than 12 members at its first full meeting following the seating of all 18 members - approximately Day 195. The Epistemic Advisor appointed under subsection (b)(1)(H) is not eligible to serve as Chair and shall not vote in the Chair election. The Chair shall serve for the duration of the Committee's legislative drafting mandate and may be re-elected. The Chair shall preside over Committee deliberations, execute the Committee's public communications, coordinate with the TWG Coordination Council, and be individually responsible for certifying that deliberative record requirements have been satisfied before any legislation is transmitted to Congress. From Day 60 through the Chair election, the Executive Director shall serve as interim presiding officer, managing administrative operations and coordinating between the appointed members and the TWGs.
(d) QUORUM AND VOTING.—
(A) QUORUM.—A quorum of the Committee shall consist of 10 members. The Committee may not conduct official business, take official action, or vote on any matter without a quorum present. Before the Committee is fully constituted at 18 members, a quorum shall be calculated based on the number of members then seated.
(B) VOTING THRESHOLD FOR LEGISLATIVE RECOMMENDATIONS.—No draft legislative provision, amendment, or final legislative package shall be adopted or transmitted to Congress unless approved by not fewer than 12 of the 18 Committee members. Procedural matters may be decided by a simple majority of a quorum.
(C) INDIVIDUAL VOTE RECORDING.—Every vote on a legislative provision or package shall be recorded individually by member name and published on the Committee's public docket within 48 hours of the vote, identifying each member's vote (for, against, or abstaining), whether any member was recused and the basis for recusal, and the final tally.
(D) MANDATORY MINORITY REPORT.—If three or more members vote against any legislative provision or package that achieves the 12-vote threshold, those members shall have the right to submit a minority report of not more than 5,000 words documenting their objections, the evidence they found persuasive, and any alternative legislative approach they would recommend. The minority report shall be transmitted to Congress simultaneously with the majority legislation and published on the public docket. Congress shall not be deemed to have received Committee legislation until both the majority legislation and any minority report have been transmitted.
(e) CONFLICT OF INTEREST - COMMITTEE MEMBERS.—
(A) CARRYOVER OF TWG OBLIGATIONS.—Each Committee member who served as a TWG representative carries over to Committee service all conflict of interest disclosure obligations, recusal requirements, and financial interest prohibitions applicable to TWG members under section 2005(b)(6). These obligations are continuous and self-executing.
(B) DISCLOSURE OBLIGATIONS.—Each Committee member, including both TWG representatives and appointed members, shall, before participating in any Committee deliberation and on a continuing basis throughout Committee service, disclose in writing to the Committee Chair and to the Comptroller General: all financial interests in frontier AI developer, significant AI deployer, or any entity whose primary business involves the development, deployment, or commercialization of AI models or AI systems entities or entities whose business may be materially affected by Committee recommendations; all consulting, employment, or contractual relationships with such entities within the preceding one year; all research funding, speaking fees, travel expenses, or gifts of value exceeding $250 received from such entities within the preceding one year; and any other relationship that a reasonable person would consider relevant to the member's independence. All disclosures shall be published on the Committee's public docket within 15 days of submission and updated within 15 days of any material change.
(C) RECUSAL.—A Committee member shall be recused from deliberating on and voting on any legislative provision that would directly and predictably affect the financial interests of any entity with which the member has a disclosed financial relationship. The Committee Chair shall make recusal determinations in the first instance; disputes shall be resolved by majority vote of non-recused members. Recusal determinations shall be published on the public docket.
(D) SUBMISSION DISCLOSURE REQUIREMENT.—Any frontier AI developer, significant AI deployer, or any entity whose primary business involves the development, deployment, or commercialization of AI models or AI systems, industry association, advocacy organization, law firm, consulting firm, or other person that submits written or oral arguments, testimony, research, policy proposals, or other substantive input to the Committee shall, at the time of submission, disclose: the identity of the submitting party and all persons who contributed to the submission; all financial relationships between the submitting party and any Committee member within the preceding one year; and whether the submission was prepared in whole or in part by any person with a financial interest in the Committee's recommendations. The Committee shall not accept any submission that does not include required disclosures. All submissions and their accompanying disclosures shall be published on the public docket within 5 business days of receipt.
(E) COMPTROLLER GENERAL OVERSIGHT.—The Comptroller General shall review the Committee's conflict of interest disclosures and recusal determinations annually and shall transmit a written assessment to Congress identifying any patterns of undisclosed conflicts, recusal failures, or systematic bias. Any member of Congress, any Committee member, or any member of the public may request a Comptroller General investigation of a specific conflict of interest allegation, and the Comptroller General shall respond within 60 days.
(f) STAFF AND ADMINISTRATIVE CAPACITY.—The Comptroller General shall, not later than 60 days after the date of enactment, complete the hiring of the Executive Director of the Committee. The Executive Director shall thereafter hire the Public Docket Administrator, Technical Systems Manager, and Public Engagement Coordinator not later than 90 days after the date of enactment, and shall hire all remaining staff required by this subsection, including legislative drafting staff and TWG administrative coordinators, not later than 90 days after the date of enactment, except that the Public Records Officer under subsection (5) and the Epistemic Advisor under subsection (b)(1)(H) shall each be hired or appointed not later than 120 days after the date of enactment.
(1) EXECUTIVE DIRECTOR.—The Comptroller General shall appoint an Executive Director not later than 60 days after the date of enactment by one of the following methods, at the Comptroller General's discretion
(i) designating a senior GAO employee at the Senior Executive Service level to serve as Executive Director, with the consent of that employee;
(ii) accepting a detail of a qualified senior career federal official from any federal agency, with the consent of the sending agency and the official.
(iii) making an excepted service appointment under 5 U.S.C. § 3109 and Schedule A of 5 C.F.R. Part 213 of a qualified person who meets the qualifications specified in this paragraph.
In all cases, the Executive Director shall not have been employed by, served as a paid consultant to, or received compensation from any frontier AI developer, significant AI deployer, or any entity whose primary business involves the development, deployment, or commercialization of AI models or AI systems within the one year preceding appointment. The flexibility to appoint from an existing government pool under methods (i) or (ii) is intended to allow the Comptroller General to move quickly by tapping a person who already holds federal security clearances, understands federal investigatory and legislative process, and can begin work immediately upon designation. The Executive Director shall manage the Committee's day-to-day operations; coordinate communications between Committee members and external parties; supervise all Committee and TWG administrative staff; manage the Committee's budget; ensure compliance with all deadlines and procedural requirements of this section; coordinate inter-TWG meetings with TWG administrative coordinators; and oversee the transition of operational infrastructure to the TWG administrative coordinators before Day 120. The Executive Director shall be compensated at a rate not to exceed the rate for Executive Level IV of the Executive Schedule, or at their existing rate of compensation if detailed from another agency, whichever is appropriate to the appointment mechanism used.
(2) PUBLIC DOCKET ADMINISTRATOR.—The Executive Director shall hire not fewer than two Public Docket Administrators not later than 90 days after the date of enactment. At peak investigatory load, the public docket will receive simultaneous monthly work product submissions from 11 Technical Working Groups, ongoing public submissions, monthly TWG public ledgers, FAC meeting records, vote records, conflict of interest disclosures, and legislative outputs, all subject to strict statutory publication deadlines; a minimum of two staff dedicated to this function is necessary to ensure no deadline is missed due to volume. Public Docket Administrators shall be responsible for: receiving, logging, and publishing all submissions to the Committee's public docket; ensuring all submissions, meeting records, votes, disclosures, monthly TWG work product submissions, and legislative outputs are published within required timeframes; maintaining the searchability and machine-readable format of the docket; responding to public inquiries; publishing each monthly TWG public ledger transmitted by the Public Records Officer under subsection (f)(5)(ii) on the staggered schedule established by the Executive Director not later than Day 125, which shall assign each TWG a fixed monthly publication date such that no two TWGs share the same publication date and each TWG's structured input package is due to the Public Records Officer not fewer than 10 business days before that TWG's assigned publication date; publishing the staggered schedule on the public portal not later than Day 125 and transmitting it to all TWG Administrative Coordinators and the Public Records Officer upon establishment; maintaining a publicly accessible cumulative index on the public portal recording each published ledger by TWG, publication date, and subject matter, updated upon each publication; and reviewing factual correction requests submitted by TWGs within 5 days of ledger publication, either incorporating the correction or publishing a written explanation alongside the original ledger, with appeal to the Executive Director available within 3 business days of a correction decision. Public Docket Administrators shall not have been employed by any frontier AI developer, significant AI deployer, or any entity whose primary business involves the development, deployment, or commercialization of AI models or AI systems within the one year preceding hiring.
(3) TECHNICAL SYSTEMS MANAGER.—The Executive Director shall hire not fewer than two Technical Systems Managers not later than 90 days after the date of enactment. The Technical Systems function encompasses simultaneously maintaining 11 separate TWG secure digital workspaces, the public portal and docket platform, the classified document repository, and remote participation infrastructure for 11 TWGs and the FAC throughout the investigatory period; a minimum of two staff is necessary to ensure continuous availability and to avoid a single point of failure in the Committee's technical infrastructure. Technical Systems Managers shall be responsible for designing, building, operating, and maintaining the Committee's public-facing website and docket platform; ensuring the website meets federal accessibility standards under section 508 of the Rehabilitation Act of 1973; implementing cybersecurity protections consistent with NIST standards; ensuring continuous public availability of docket materials; and providing technical support for Committee and TWG meetings including remote participation capability. Technical Systems Managers shall not have been employed by any frontier AI developer, significant AI deployer, or any entity whose primary business involves the development, deployment, or commercialization of AI models or AI systems within the one year preceding hiring.
(4) PUBLIC ENGAGEMENT COORDINATOR.—The Executive Director shall hire not fewer than one Public Engagement Coordinator not later than 90 days after the date of enactment. The Public Engagement Coordinator shall have demonstrated experience in public engagement methodology, deliberative democracy processes, or community outreach, and shall not be required to have substantive expertise in any of the 19 investigation domains. The Public Engagement Coordinator shall not have been employed by any frontier AI developer, significant AI deployer, or any entity whose primary business involves the development, deployment, or commercialization of AI systems within the one year preceding hiring. The Public Engagement Coordinator shall:
(i) plan, coordinate, and support the Federal Advisory Committee's stakeholder engagement activities under section 2007(a), working with TWG Administrative Coordinators to identify domain-specific engagement needs and opportunities;
(ii) monitor on a rolling basis for public deliberation research and public input produced externally during the investigatory period, including outputs of citizens assemblies organized by any person or entity, deliberative polling processes, nationally representative surveys, recorded and structured public debates, public opinion research commissioned by any person or entity, and participatory research initiatives addressing AI-related topics, and transmit identified materials to the relevant TWG Administrative Coordinators for deposit in the shared evidence repository within 10 business days of identification;
(iii) maintain a public-facing registry on the public portal under section 2007(d) of all external public engagement research and input identified and transmitted under clause (ii), including the source, date, and TWGs to which the material was routed;
(iv) coordinate with the lead agency's domain investigators to identify relevant public opinion research and public input gathered through the lead agency's investigative support activities; and
(v) report to the Executive Director on the status of stakeholder engagement and public opinion research intake at each monthly Committee session.
(5) PUBLIC RECORDS OFFICER.—The Executive Director shall hire not fewer than one Public Records Officer not later than 120 days after the date of enactment. The Public Records Officer shall have demonstrated experience in public-facing government reporting, journalism, policy writing, or equivalent professional experience producing plain-language summaries of complex technical or legal material for non-specialist audiences; the Public Records Officer shall not be required to have substantive expertise in any of the 19 investigation domains. The Public Records Officer shall not have been employed by any frontier AI developer, significant AI deployer, or any entity whose primary business involves the development, deployment, or commercialization of AI models or AI systems within the one year preceding hiring. The Public Records Officer shall not communicate directly with TWG members regarding ledger content before publication; all input shall flow through the TWG Administrative Coordinator's structured input package. The Public Records Officer shall be compensated at rates consistent with comparable positions in the federal government under the General Schedule pay scale. The Public Records Officer's sole functions are:
(i) receive the structured input package transmitted by each TWG Administrative Coordinator under subsection (f)(7) and, based solely on that package and publicly available materials, produce the monthly public ledger for each TWG required by section 2005(b)(10), ensuring consistent terminology, plain-language standards, and formatting across all 11 ledgers to enable meaningful public comparison of investigatory progress; and
(ii) transmit each completed ledger to the Public Docket Administrator for publication and indexing under subsection (f)(2), not fewer than 2 business days before the assigned publication date for that TWG under the staggered schedule established under subsection (f)(2).
(6) LEGISLATIVE DRAFTING STAFF.—The Executive Director shall hire not fewer than 3 and not more than 5 Legislative Drafters, who shall: draft, review, and refine statutory text based on TWG monthly work product submissions and Committee deliberations; provide legislative drafting assistance to TWG representatives upon request; produce the section-by-section analysis accompanying the final legislative package; ensure cross-domain consistency and definitional coherence across all 19 domain provisions; and identify drafting conflicts, ambiguities, or constitutional vulnerabilities in emerging legislative proposals. Each Legislative Drafter shall have demonstrated professional experience in federal legislative drafting or federal regulatory drafting, including service as congressional legislative counsel, agency regulatory counsel, Office of Legal Counsel attorney, or equivalent senior policy counsel with primary responsibility for statutory or regulatory text production. Legislative Drafters shall also be available to TWGs for legislative research assistance upon request submitted through the TWG administrative coordinator. The Committee shall additionally establish a formal channel through which TWGs may submit research requests to the Congressional Research Service, and the Executive Director shall manage that channel. Legislative Drafting Staff shall not have been employed by any frontier AI developer, significant AI deployer, or any entity whose primary business involves the development, deployment, or commercialization of AI systems within the one year preceding hiring.
(7) TWG ADMINISTRATIVE COORDINATORS.—The Executive Director shall hire one Administrative Coordinator and one Administrative Support Staff member for each of the 11 Technical Working Groups (11 Administrative Coordinators and 11 Administrative Support Staff members in total) not later than 90 days after the date of enactment. Each Administrative Support Staff member shall assist the Administrative Coordinator of their assigned TWG with document management, scheduling support, preparation of public ledger entries, public submission inbox monitoring and logging, and such other administrative tasks as the Administrative Coordinator directs. Administrative Support Staff shall be compensated under the General Schedule pay scale and shall not have been employed by any frontier AI developer, significant AI deployer, or any entity whose primary business involves the development, deployment, or commercialization of AI models or AI systems within the one year preceding hiring. Each TWG Administrative Coordinator shall: manage scheduling and logistics for their assigned TWG's weekly all-day sessions and other meetings; maintain the TWG's document repository and internal records; prepare and transmit the TWG's monthly work product submissions to the Committee; coordinate with the Committee's Public Docket Administrator to ensure TWG materials are published on the public docket; prepare and transmit to the Public Records Officer, not fewer than 10 business days before that TWG's assigned monthly publication date under the staggered schedule established under subsection (f)(2), beginning with the first full calendar month following the TWG's organizational meeting, a structured input package for the monthly public ledger required by section 2005(b)(10), consisting of: a chronological log of investigatory activities conducted during the preceding month; a list of sources consulted, experts heard, and external parties contacted; a summary of any significant evidentiary or analytical developments; and an identification of any cruxes that emerged or were resolved during the period; coordinate with other TWG Administrative Coordinators and the Executive Director to schedule inter-TWG sessions when cross-domain conflicts arise; and support the onboarding of TWG members upon appointment. TWG Administrative Coordinators shall be hired from among persons with demonstrated experience managing federal investigatory, regulatory, or legislative processes, including: former congressional committee staff directors or professional staff members with investigatory or legislative process experience; current or former GAO investigators or analysts seconded under an interagency agreement; or former agency chiefs of staff, deputy chiefs of staff, or senior regulatory process managers at agencies including the FTC, SEC, FCC, CFTC, CFPB, or EPA. TWG Administrative Coordinators shall not have been employed by any frontier AI developer, significant AI deployer, or any entity whose primary business involves the development, deployment, or commercialization of AI models or AI systems within the one year preceding hiring.
(8) PRE-CONSTITUTION SETUP OBLIGATIONS.—Before Day 120 (the date on which final TWG appointments are made and members begin onboarding) the Executive Director and TWG Administrative Coordinators shall complete the following setup activities for each TWG: establish the TWG's secure digital workspace, document management system, and communications infrastructure; prepare the TWG's onboarding materials including domain mandate documentation, access credentials, ethics briefing coordination, and orientation schedule; coordinate with the Office of Government Ethics and the relevant home agencies of seed members to initiate ethics and security onboarding, financial disclosure (OGE 450), and ethics briefing processes for all appointed members; and brief all TWG Administrative Coordinators on Committee procedures, monthly work product submission formats, public docket requirements, and inter-TWG coordination protocols. Upon constitution of each TWG, the Executive Director shall formally hand off operational responsibility for that TWG to its Administrative Coordinator, while retaining network-wide coordination authority.
(9) COMPENSATION.—All staff hired under this subsection shall be compensated at rates consistent with comparable positions in the federal government under the General Schedule pay scale. The Committee is authorized to use Schedule A excepted service hiring authority for positions requiring specialized technical or legislative expertise. GAO staff seconded to TWG Administrative Coordinator positions shall remain on GAO's payroll under the terms of the interagency agreement.
(10) TRANSFER TO NATIONAL AI COUNCIL.—Upon the Committee completing its legislative transmission to Congress under subsection (i) and the National AI Council assuming its full mandate, the employment of the Executive Director, Public Docket Administrator, Technical Systems Manager, Public Engagement Coordinator, and all additional staff hired under this subsection shall transfer to the National AI Council by operation of law, without interruption of service, new hiring process, or gap in employment. The Council shall assume full supervisory authority over all transferred staff.
(g) OPERATIONS.—The Federal Advisory Committee on Artificial Intelligence Governance shall meet not less frequently than weekly during the legislative drafting period from the first TWG organizational meeting through the FAC backstop transmission deadline. The Committee shall publish meeting agendas at least 48 hours in advance and shall publish meeting transcripts and materials within 5 business days of each meeting. The Committee shall receive TWG monthly work product submissions as required by section 2005(b)(9) and shall begin synthesizing them into draft statutory language concurrently with the TWG investigation - not waiting for final TWG submissions to begin drafting. The Committee shall coordinate with the TWG Coordination Council to ensure legislative drafting remains consistent with evolving TWG findings and to resolve cross-domain definitional and jurisdictional conflicts. Monthly Committee sessions shall include a standing agenda item for review of cross-TWG conflicts identified by TWG Administrative Coordinators, with the Executive Director coordinating scheduling of joint TWG sessions to resolve material conflicts before they harden into the final legislative package.
(h) INDEPENDENCE.—Members shall serve in their individual capacities and shall not be subject to direction by any frontier AI developer, significant AI deployer, or any entity whose primary business involves the development, deployment, or commercialization of AI systems, the lead agency, or any executive branch official. The Committee's legislative output shall be transmitted to Congress without agency alteration, redaction, or editorial modification. The lead agency may provide the Committee with access to investigation data, agency research, and evidentiary materials upon request, but may not direct, limit, or modify the Committee's legislative drafting.
(i) LEGISLATIVE TRANSMISSION TO CONGRESS.—The Federal Advisory Committee on Artificial Intelligence Governance shall transmit introduction-ready draft statutory text to Congress on a rolling basis as domain packages are completed, beginning as early as the first TWG organizational meeting. The Federal Advisory Committee need not wait for all 19 domains to be complete before transmitting completed domains. A domain package is ready for transmission when: the Federal Advisory Committee has voted by the 12-of-18 threshold to adopt the draft statutory text for that domain; the Coordination Council has confirmed no unresolved cross-domain conflicts exist for that domain, which confirmation may be provided either by formal Coordination Council resolution at a duly scheduled meeting or by written certification of the Coordination Council presiding officer that no cross-domain conflict has been flagged by any TWG representative within the preceding 14 days with respect to that domain; and the Chair has certified that deliberative record requirements have been satisfied. Each transmitted domain package shall constitute introduction-ready draft statutory text, not a report, with numbered sections, defined terms, enforcement mechanisms, and penalty provisions. Each transmission shall be simultaneously published on the Federal Advisory Committee's public docket and made available through the Government Publishing Office. The Clerk of the House and the Secretary of the Senate shall enter each transmitted package into the Congressional Record upon receipt. Section-by-section analysis and any minority reports for each domain shall follow within 15 days of that domain's transmission and shall not delay transmission. The Federal Advisory Committee shall transmit all remaining domain packages not later than 30 days after the last TWG submits its final domain recommendations under section 2005(b)(4) - the firm backstop deadline. In no event shall this backstop deadline fall later than 15 months after the date of enactment, ensuring that even if TWGs begin at the latest permissible date under the organizational meeting deadline of section 2005(a)(9), the Federal Advisory Committee completes transmission within a defined outer bound. At the backstop deadline, the Federal Advisory Committee shall also transmit a complete index of all domain packages transmitted to date, a Chair certification that all 19 domains have been addressed, and any cross-domain analysis the Federal Advisory Committee considers necessary. The 180-day Phase II Enactment Deadline under section 2015(a)(1) runs from the date of the Federal Advisory Committee's final backstop transmission for all domains, regardless of when each domain package was transmitted. Rolling transmissions before the backstop deadline give Congress advance reading time and enable committee preparation - they do not start separate countdown clocks. The lead agency shall maintain and publish a real-time public record of which domains have been transmitted and on what date. Upon completing its final legislative transmission to Congress under this subsection, the Federal Advisory Committee and each Technical Working Group shall transition to a Technical Support and Availability status. Members shall remain available to respond to written and oral questions from Members of Congress, congressional committee staff, the lead agency, and the National AI Council regarding the evidentiary basis, drafting intent, and technical content of any transmitted domain package. This availability obligation continues until the National AI Council is fully constituted with a quorum of 10 members under section 2013(d), at which point the National AI Council assumes the ongoing technical advisory function. Upon reaching Technical Support and Availability status, government employees detailed to TWG or FAC service may return to their home agencies at the direction of those agencies, provided they remain individually available to respond to technical support requests during business hours through the mechanism established by the Executive Director. Non-government TWG and FAC members are not required to maintain full-time availability during this period but shall respond to written technical support requests within 10 business days.
(j) PUBLIC DOCKET AND ARGUMENT LOGGING.—The Committee shall establish and maintain a publicly accessible online docket on which it shall publish in real time throughout the investigatory and drafting period: all written submissions received from any party; all meeting agendas and transcripts; all recorded votes and tallies; all conflict of interest disclosures and recusal determinations; all monthly TWG work product submissions; all draft legislative provisions circulated for Committee deliberation; all final legislative provisions transmitted to Congress; all minority reports; all monthly TWG public ledgers prepared by the Public Records Officer and required by section 2005(b)(10); and all correspondence between the Committee and any frontier AI developer, significant AI deployer, or any entity whose primary business involves the development, deployment, or commercialization of AI models or AI systems, industry association, or lobbyist. For each legislative provision the Committee deliberates, the Committee shall maintain a structured argument log documenting each argument received for and against the provision attributed by name to the submitting party, the evidence cited, and the Committee's written assessment of each substantive argument explaining why it was found persuasive or not. The argument log for each provision shall be transmitted to Congress alongside the legislative package and simultaneously published on the Committee's public docket as part of the complete public record of the Committee's deliberations. The argument log is a transparency and accountability document and does not create any procedural obligation binding on Congress.
(k) DISSOLUTION AND TRANSITION.
(1) FAC DISSOLUTION.—The Federal Advisory Committee established under this section shall dissolve on the date that the National AI Council holds its organizational meeting under section 2013(c). Upon dissolution, the Committee's records, evidence repository, correspondence, and all investigatory materials shall be transferred to the National AI Council. The Committee's administrative staff, including the Executive Director, Public Docket Administrator, Technical Systems Manager, Public Engagement Coordinator, and all additional staff hired under subsection (f), shall transfer to the National AI Council by operation of law, without interruption of service, new hiring process, or gap in employment. The Council shall assume full supervisory authority over all transferred staff.
(2) TWG DISSOLUTION.—Each Technical Working Group established under section 2004 shall dissolve on the date that the Federal Advisory Committee dissolves under paragraph (1). Upon dissolution, each TWG's domain-specific investigatory materials, evidence files, expert contact networks, and unpublished working documents shall be transferred to the National AI Council and organized by domain for the Council's use in continuing fact-finding under section 2013(e)(4).
(3) CONTINUITY OF INVESTIGATORY RECORD.—The dissolution of the Federal Advisory Committee and its Technical Working Groups does not terminate, expire, or diminish the evidentiary record produced during Phase I. The complete investigatory record, including all civil investigative demand responses, Participating Data Agency materials, classified materials, public submissions, expert testimony, and TWG deliberative records, shall be preserved in its entirety and shall constitute the foundational evidentiary record of the National AI Council. The Council shall have the same access to this record as the Federal Advisory Committee and its Technical Working Groups had during Phase I.
(4) PENDING MATTERS.—Any civil investigative demand issued under section 2008(c) that is pending at the time of FAC dissolution shall remain in force and shall be enforceable by the lead agency. Any investigation, audit, or enforcement action initiated during Phase I shall continue under the authority of the lead agency and shall not be affected by the dissolution of the Committee or its Working Groups.
(5) INTERIM PERIOD.—During the period between the FAC backstop transmission deadline and the organizational meeting of the National AI Council, the lead agency shall maintain the investigatory infrastructure, evidence repository, and administrative systems established during Phase I, and shall ensure continuity of operations until the Council assumes its mandate. The Federal Advisory Committee and its Technical Working Groups shall continue to operate during this interim period in Technical Support and Availability status as described in subsection (i), and shall cooperate with the Council appointment process.
(6) SUPERSESSION.—This subsection supersedes the staff transfer provision of subsection (f)(10) and the Technical Support and Availability provisions of subsection (i) to the extent they address post-transmission transition, and provides the comprehensive framework for the transition from the Federal Advisory Committee to the National AI Council.
SEC. 2007. STAKEHOLDER ENGAGEMENT AND PUBLIC PARTICIPATION.
(a) The Federal Advisory Committee, through its Executive Director, Public Engagement Coordinator, and TWG Administrative Coordinators, shall actively seek input from affected populations throughout the investigatory period to ensure that the perspectives of those most affected by AI models or AI systems are represented in the investigatory record. Input may be received through any means, including but not limited to: regional roundtables; expert workshops; virtual forums; phone calls; emails; informal testimony; written submissions; town halls; citizens assemblies organized by any person or entity; deliberative polling processes; nationally representative surveys; recorded and structured public debates; public opinion research commissioned by any person or entity; and participatory research initiatives. No particular format or methodology is required - the FAC's obligation is to hear from affected people and ensure their input reaches the relevant TWGs. Dedicated outreach shall be conducted with communities disproportionately affected by AI models or AI systems, communities in proximity to existing or proposed AI data center clusters, small businesses, workers in sectors facing significant AI-driven displacement, parents and families of minors harmed by AI models or AI systems, and child safety organizations. Each TWG shall conduct domain-specific stakeholder engagement relevant to its investigatory mandate through the public submission channel established under section 2005(b)(14). The Public Engagement Coordinator shall additionally monitor the external landscape on a rolling basis for relevant public deliberation research produced by parties other than the FAC, including outputs of citizens assemblies, deliberative polls, and other public engagement processes addressing AI-related topics conducted during the investigatory period, and shall transmit all such materials to the relevant TWG Administrative Coordinators for deposit in the shared evidence repository within 10 business days of identification.
(b) The National Institute of Standards and Technology shall issue not fewer than 2 requests for information (RFIs) or advance notices of proposed rulemaking (ANPRMs) within 90 days of enactment, covering the domains of investigation specified in section 2004(b). NIST shall transmit all substantive responses received to the Federal Advisory Committee and the relevant Technical Working Groups through the shared evidence repository within 10 business days of receipt.
(c) The Federal Advisory Committee shall conduct dedicated outreach to tribal governments and underrepresented communities whose perspectives may not be captured through the engagement channels described in subsection (a), including rural communities, communities with limited digital access, and communities with limited English proficiency, ensuring that the investigatory record is not limited to those with resources to engage in formal regulatory proceedings.
(d) The Federal Advisory Committee, acting through its Technical Systems Manager, shall establish and maintain a publicly accessible online portal and docket for ongoing comment submission, publication of all non-classified investigation materials, stakeholder input summaries with agency responses, and public access to all data and reports produced under this title. The portal shall be the single authoritative public repository for all materials produced under this title, including FAC legislative packages, TWG Domain Explanatory Reports, Coordination Council resolutions, and all public docket entries.
SEC. 2008. DATA COLLECTION, MONITORING, AND INFRASTRUCTURE.
(a) INTERAGENCY DATA COORDINATION.—The data access obligations of Participating Data Agencies are established and self-executing under section 2005(b) and do not require the execution of bilateral data-sharing agreements to take effect. Not later than 30 days after the date of enactment, the lead agency shall transmit written notice to each Participating Data Agency confirming the activation of their data access obligations under section 2005(b), identifying the designated TWG Administrative Coordinators and FAC contact points to whom data requests should be routed, and providing secure technical protocols for the transmission of data to the shared evidence repository maintained by the TWG Coordination Council. This notice does not create the obligation - it operationalizes the self-executing obligation of section 2005(b) by providing each Participating Data Agency with the information necessary to respond to data requests. Separately, the Department of Justice cooperation obligations established under section 2011(f) are governed by the written procedures the Attorney General is required to establish under section 2011(f)(3) not later than 45 days after the date of enactment; those procedures serve the equivalent activation function for DOJ data cooperation and the lead agency shall coordinate with the Attorney General to ensure those procedures are operationally consistent with the shared evidence repository and routing protocols established under this subsection.
(b) PUBLIC DATA REPOSITORY.—The lead agency shall establish and maintain a publicly accessible data repository containing all non-classified data, reports, criteria documents, stakeholder submissions, and investigation materials produced under this title, with appropriate privacy protections for personally identifiable information and exclusion of classified material.
(c) CIVIL INVESTIGATIVE DEMAND.—The lead agency is authorized to compel production of relevant data, documents, and information from frontier AI developers and significant AI deployers through civil investigative demands issued under procedures consistent with 15 U.S.C. § 57b-1, subject to trade-secret protections. Trade-secret material shall be maintained under seal and shall not be included in the public repository under subsection (b), but shall be available to the relevant Technical Working Groups, the Federal Advisory Committee, and, after its constitution under section 2013(c), the National AI Council, under appropriate protective orders.
(d) FIELD INVESTIGATIONS.—The lead agency is authorized to conduct on-site inspections and field investigations of frontier AI developers and significant AI deployers, data center facilities, and compute providers, upon reasonable notice, for purposes of verifying compliance with the data-production requirements of this section and the interim protective measures of section 2015.
SEC. 2009. STATE COOPERATION AND PILOT PROGRAMS.
(a) VOLUNTARY GRANT PROGRAM.—The lead agency is authorized to award grants to States, territories, and tribal governments on a voluntary basis to develop State-level AI investigatory and monitoring capacity, share data and findings with the Federal Advisory Committee and its Technical Working Groups through the shared evidence repository under section 2005(c)(3)(D), conduct complementary studies addressing State-specific AI impacts, and develop model State legislation or regulations for optional adoption.
(b) PILOT PROGRAMS.—The lead agency may authorize up to 5 State-level pilot programs to test alternative AI governance approaches, provided that such programs do not conflict with the interim protective measures established under section 2015 and that participating States report all findings to the Federal Advisory Committee and its Technical Working Groups through the shared evidence repository under section 2005(c)(3)(D).
(c) NO PREEMPTION.—Nothing in this section shall be construed to preempt any State law that provides protections equal to or greater than those established by this title.
CHAPTER 3—REPORTING AND TRANSITION
SEC. 2010. REPORTS TO CONGRESS.
(a) INTERIM PROGRESS REPORT.—Not later than 90 days after the date of enactment, the lead agency shall deliver to the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Energy and Commerce of the House of Representatives an interim progress report describing: the status of investigative operations across all 19 domains; the volume and categories of investigative material gathered and delivered to each TWG to date; civil investigative demands issued and the status of responses; data requests submitted to Participating Data Agencies and the status of responses; the domain investigator assignment status for all 19 domains; stakeholder engagement activities conducted; and any investigative obstacles, access challenges, or resource constraints encountered and remedial steps taken. The interim progress report does not contain analytical findings or conclusions - it is a delivery and operational status report consistent with the lead agency's mandate under section 2005(a).
(b) INTERIM INVESTIGATIVE STATUS REPORT.—Not later than 210 days after the date of enactment, the lead agency shall deliver to Congress an interim investigative status report describing: the volume and categories of investigative material delivered to each TWG to date; civil investigative demands issued and responses received; data requests submitted to Participating Data Agencies and responses received; classified material delivered through the classified track; the domain investigator assignment status for all 19 domains; and any investigative gaps, access obstacles, or resource constraints that may affect the completeness of the evidentiary record delivered to the TWGs. The interim status report is a delivery and access report, not an analytical findings report - it does not contain findings, conclusions, or draft legislative language.
(c) FINAL FACTUAL REPORT.—Not later than the FAC backstop transmission deadline established under section 2006(i) (simultaneously with the Federal Advisory Committee's legislative transmission under section 2006(i)) the lead agency shall deliver a final factual report to Congress. The lead agency shall not produce draft legislative language in this report; legislative drafting is the exclusive responsibility of the Federal Advisory Committee under section 2006(i). The final factual report shall include
(1) findings of fact for each of the 19 investigation domains, clearly distinguishing between findings supported by strong evidence, preliminary findings, and areas of genuine scientific uncertainty;
(2) an assessment of the adequacy of any federal legislation enacted between the date of introduction of this title and the date of this report that addresses any of the 19 investigation domains, consistent with section 2021(d);
(3) identification of remaining evidence gaps in each domain and recommended further investigation or monitoring for Phase II;
(4) final criteria documents published under section 2007;
(5) a comprehensive, machine-readable index of all information reviewed, organized by domain and cross-referenced with findings; and
(6) certification by the Director of AI Investigation and the Secretary that the report is complete and that all statutory requirements have been satisfied.
(d) TRANSMISSION AND ACCESSIBILITY.—Upon submission of the final report under subsection (c), the lead agency shall transmit complete copies to each congressional committee of jurisdiction and shall make the report and all supporting materials publicly available. The lead agency shall transmit a complete copy to the National AI Council within 15 days of the Council's organizational meeting under section 2013(c).
(e) GAO INDEPENDENT REVIEW.—The Comptroller General of the United States shall, concurrently with the lead agency's investigation, conduct an independent review of the agency's methodology, data collection, analytical rigor, and findings, and shall deliver an independent report to Congress not later than 360 days after the date of enactment.
CHAPTER 4—LEAD AGENCY AND AUDITOR PROGRAM
SEC. 2011. DESIGNATION OF LEAD AGENCY AND INTERAGENCY COORDINATION.
(a) DESIGNATION.—The Department of Commerce, acting through NIST and NTIA, is hereby designated as the lead agency under this title.
(b) FUNCTIONS.—The lead agency serves the investigatory work of the Federal Advisory Committee and its Technical Working Groups and performs the following functions under this title:
(1) INVESTIGATIVE SUPPORT.—the lead agency shall, upon written request of the Federal Advisory Committee, any Technical Working Group acting through its Administrative Coordinator, or the National AI Council, and may on its own initiative where expressly authorized by this title:
(A) issue civil investigative demands to frontier AI developers and significant AI deployers under section 2008(c) to compel production of data, documents, and information relevant to any domain of investigation under section 2004(b);
(B) conduct on-site inspections and field investigations under section 2008(d);
(C) receive, process, log, and transmit to the requesting body all data and materials produced in response to civil investigative demands or received from Participating Data Agencies under subsection (e);
(D) maintain the shared evidence repository through the TWG Coordination Council; and
(E) maintain and publish the domain investigator assignment list and domain routing table on the public portal under section 2007(d).
(2) INTERNAL METRICS, METHODOLOGIES, AND EVALUATIONS.—the lead agency shall develop, for its own operational and enforcement purposes:
(A) internal metrics and measurement methodologies necessary to administer the moratorium provisions under section 2015(b), the Transformative AI Capability Event administration under section 2015(n), and the red line provisions under section 2017(a)(1);
(B) evaluation criteria and assessment protocols necessary to make Phase II compliance determinations under section 2003 and section 2015(e)(3), conducted in coordination with the Comptroller General;
(C) such research, analysis, and technical study as is necessary to support the functions described in subparagraphs (A) and (B), including commissioning independent technical studies where the lead agency lacks sufficient internal capacity. Before commissioning independent research under this subparagraph, the lead agency shall first assess whether the relevant TWG investigatory record, including monthly work product submissions and Domain Explanatory Reports transmitted through the shared evidence repository, is sufficient to support the operational or enforcement purpose for which the research is needed. Independent research under this subparagraph is confined to questions the TWG record does not answer and that the lead agency specifically requires for its own enforcement or administrative functions - it shall not duplicate domain analysis that is within the investigatory mandate of any TWG. Research and analysis conducted under this subparagraph supports the lead agency's operational and enforcement functions and does not constitute independent policy analysis or legislative recommendation.
(3) AUDITOR PROGRAM.—the lead agency shall establish and administer the Certified Independent AI Auditor Program under section 2012.
(4) ENFORCEMENT AUTHORITY.—the lead agency retains exclusive authority to make determinations of noncompliance and to issue Notices of Noncompliance under section 2015(b), and shall make mandatory referrals to the Department of Justice for enforcement upon issuance of a Final Determination under subsection (j).
(5) PUBLIC REGISTRIES.—The lead agency shall publish and maintain a public registry of frontier AI developers and a public registry of significant AI deployers, each updated not less frequently than quarterly.
(6) THRESHOLD ADJUSTMENT.—
(A) FRONTIER DEVELOPER AND FRONTIER MODEL THRESHOLDS.—The lead agency shall adjust the computational threshold in section 2003(15)(A) concurrently with, and using the same methodology as, its adjustment of the frontier model threshold in section 2003(16).
(B) SIGNIFICANT DEPLOYER THRESHOLDS.—The lead agency may, through notice-and-comment rulemaking, adjust the numerical thresholds in section 2003(30) not less frequently than every 24 months to reflect changes in the AI market, provided that any adjustment is supported by substantial evidence and is subject to judicial review.
(C) HIGH-RISK CATEGORIES.—The lead agency may adjust the numerical thresholds and technical criteria in section 2003(17), but may not remove a category established in section 2003(17)(A) without a subsequent Act of Congress.
(D) ANTI-NULLIFICATION FINDING.—Before adopting an adjustment under subparagraph (C) that raises a numerical threshold or narrows a technical criterion, the lead agency shall publish, as part of the rulemaking record, a written finding supported by substantial evidence that—
(i) the category as adjusted will continue to encompass the AI systems whose deployment presents the risks for which Congress established that category; and
(ii) the adjustment is not reasonably likely to result in the category encompassing no AI system, or a materially smaller proportion of the AI systems presenting those risks, than the category encompassed before the adjustment.
(E) EFFECT OF ABSENT OR UNSUPPORTED FINDING.—An adjustment adopted without the finding required by subparagraph (D) is void. A finding under subparagraph (D) is subject to judicial review, and a reviewing court shall set aside the adjustment if the finding is not supported by substantial evidence. An adjustment that has the effect of removing a category, whether or not the category is formally retained in the text of section 2003(17)(A), constitutes removal of a category for purposes of subparagraph (C) and requires a subsequent Act of Congress.
(7) AGE-SIGNAL GUIDANCE.—The lead agency shall publish technical guidance on qualifying signals under section 2003(28)(E) not later than 180 days after the date of enactment of this title.
(c) ESTABLISHMENT, STAFFING, AND COMPOSITION.—
(1) IMMEDIATE INVESTIGATIVE OPERATIONS.—NIST and NTIA career staff shall begin investigative support operations across all 19 domains specified in section 2004(b) immediately upon enactment, without waiting for Director designation. Each of NIST and NTIA shall assign available career staff to each domain investigation not later than 10 days, using existing institutional authority and resources. Investigative support operations begun before Director designation shall continue under Director authority upon designation without interruption.
(2) DIRECTOR OF AI INVESTIGATION.—The Secretary shall designate an officer to serve as the Director of AI Investigation not later than 45 days after the date of enactment, who has been identified as having the relevant expertise. Upon designation, the Director assumes day-to-day operational authority over all lead agency functions under this title, including directing detailee investigators, issuing civil investigative demands on behalf of or at the request of the FAC or any TWG, routing investigative material to TWGs, and administering the classified track under subsection (i). Before Director designation, NIST and NTIA operate under existing institutional authority, and the Secretary may designate an acting coordinator from existing NIST or NTIA senior staff to manage operations during the interim period.
(3) LEAD AGENCY COMPOSITION: CORE STAFF AND DETAILEE INVESTIGATORS.—The lead agency shall be composed of NIST and NTIA career staff supplemented by investigators, attorneys, economists, and technical staff detailed from the following agencies, upon request by the Director of AI Investigation: the Federal Trade Commission; the Civil Division and Antitrust Division of the Department of Justice; the Cybersecurity and Infrastructure Security Agency; the Federal Bureau of Investigation; the Environmental Protection Agency; the Equal Employment Opportunity Commission; the Securities and Exchange Commission; and the Commodity Futures Trading Commission. The heads of each of these agencies are directed to approve detail requests made by the Director of AI Investigation and to provide detailees as a priority matter within 30 days of the Director's request. Detailees work under the Director's operational authority and are assigned to domain investigations matching their expertise and home agency jurisdiction. Each detailee remains an employee of their home agency and is compensated by their home agency throughout the detail period.
(4) MINIMUM DOMAIN INVESTIGATOR REQUIREMENT.—Not later than 60 days after the date of enactment, the lead agency shall have designated not fewer than one dedicated investigator to each of the 19 investigation domains specified in section 2004(b). For purposes of this requirement, a dedicated investigator means a person, whether a career NIST or NTIA employee or a detailee from a participating agency, who has been specifically assigned to that domain and whose primary investigative responsibility during the investigatory period is that domain. A single investigator may be dedicated to not more than two domains if the Director determines that the investigative scope and complexity of those domains permits dual assignment; however, the five mandatory domains shall each have a dedicated investigator assigned exclusively to that domain.
(5) MINIMUM INVESTIGATIVE STAFF FLOOR.—In addition to the per-domain investigator minimum of paragraph (4) of this subsection, the lead agency shall maintain, throughout the investigatory period, a total investigative and legal support staff of not fewer than 30 full-time-equivalent personnel dedicated to the investigative support functions of this title. This floor includes domain investigators designated under paragraph (4) of this subsection, attorneys supporting civil investigative demand procedures under section 2008(c), economists and data analysts supporting domain evidence gathering, and detailees serving in investigative capacities under paragraph (3) of this subsection. The Director shall certify to the relevant congressional oversight committees not later than 90 days after the date of enactment, and every 90 days thereafter, that the minimum staffing floor is being met, and shall identify any staffing shortfalls and the steps being taken to remedy them.
(d) TRANSMISSION OF INVESTIGATIVE MATERIAL TO TWGS.—
(1) ROLLING DELIVERY OF INVESTIGATIVE MATERIAL TO TWGS.—Beginning upon the first TWG organizational meeting, which is anticipated approximately Day 125 after the date of enactment, the lead agency shall transmit all investigative material relevant to each of the 19 domains to the TWG Administrative Coordinator for the corresponding TWG within 10 days of the lead agency receiving or producing that material. For purposes of this subsection, "investigative material" means: documents and data produced by frontier AI developers and significant AI deployers in response to civil investigative demands; data received from Participating Data Agencies under subsection (e); data and materials received from the Department of Justice under subsection (f); expert interview summaries and witness statements obtained by lead agency investigators; research and analysis conducted or commissioned by the lead agency in support of its internal operational and enforcement functions under subsection (b)(2); and any other factual material gathered by the lead agency in the course of its domain activities. The lead agency shall not withhold investigative material from the relevant TWG on the basis that the material is incomplete, preliminary, or subject to further investigation if it is requested. Material subject to trade-secret protections under section 2008(c) shall be transmitted with appropriate handling instructions. Investigative material produced or received before any TWG holds its organizational meeting shall be deposited in the shared evidence repository maintained by the TWG Coordination Council and transmitted to the relevant TWG Administrative Coordinator on the first business day following that TWG's organizational meeting.
(2) DOMAIN ROUTING.—The Director of AI Investigation shall maintain a domain routing table mapping each of the 19 investigation domains under section 2004(b) to the corresponding TWG under section 2004(b), and shall route all investigative material accordingly within the 10-day transmission window of paragraph (1). The domain routing table shall be published on the public portal within 5 business days of Director designation and updated within 5 business days of any change. Where investigative material is relevant to more than one domain, the lead agency shall transmit the material to the TWG Administrative Coordinators for all relevant TWGs simultaneously. Where the relevance of material to a specific domain is uncertain, the Director shall make a routing determination in writing within 3 business days of receipt, and the written determination shall be published on the public portal.
(e) INTERAGENCY DATA ACCESS MECHANISM.—The following federal departments and agencies are hereby designated as Participating Data Agencies for purposes of this title. There shall be designated a "data access officer" of the relevant Participating Data Agency, who shall be designated by each agency head not later than 30 days after the date of enactment. Each Participating Data Agency is directed to make available to the Federal Advisory Committee, its Technical Working Groups, and, after its constitution under section 2013(c), the National AI Council, upon written request, all non-classified data, research, enforcement records, surveillance data, and investigatory materials within the agency's possession that are relevant to the investigation domains specified in section 2004(b) and that are not subject to a legally cognizable privilege or statutory bar on disclosure. The obligation to respond to data requests under this subsection is mandatory and self-executing, it does not require agency rulemaking, interagency agreement, or further congressional action. The Participating Data Agencies are:
(1) Federal Trade Commission;
(2) Office of Science and Technology Policy;
(3) National Science Foundation;
(4) Department of Labor;
(5) Department of Health and Human Services;
(6) Department of Defense;
(7) Department of Energy;
(8) Department of Homeland Security;
(9) Department of Education;
(10) Consumer Financial Protection Bureau;
(11) Environmental Protection Agency;
(12) Equal Employment Opportunity Commission;
(13) Securities and Exchange Commission;
(14) Federal Communications Commission;
(15) Nuclear Regulatory Commission;
(16) Bureau of Industry and Security of the Department of Commerce;
(17) Commodity Futures Trading Commission;
(18) Financial Stability Oversight Council; and
(19) such other agencies as the Federal Advisory Committee Chair determines to hold relevant data, upon written notice to the agency head.
Data cooperation from the Department of Justice is governed by subsection (f).
(f) DEPARTMENT OF JUSTICE DATA COOPERATION.—
(1) ANTITRUST DIVISION.—The Antitrust Division of the Department of Justice shall make available to the Federal Advisory Committee, any requesting Technical Working Group, and the National AI Council, upon written request, all non-classified data, research, and investigatory materials relevant to the investigation domains specified in section 2004(b)(5), including data on market concentration, algorithmic pricing coordination, and AI-related competitive dynamics, subject to any legally cognizable privilege or statutory bar on disclosure, and to the separation-of-functions requirement of paragraph (3).
(2) CIVIL DIVISION.—The Civil Division of the Department of Justice shall cooperate with written requests from the Federal Advisory Committee, any Technical Working Group, and the National AI Council for legal analysis, litigation history, and enforcement data relevant to the investigatory domains of this title, subject to any legally cognizable privilege or statutory bar on disclosure, and to the separation-of-functions requirement of paragraph (3).
(3) SEPARATION OF FUNCTIONS.—Data and materials provided by the Department of Justice under this subsection are provided solely for the investigatory and legislative functions of the FAC, TWGs, and National AI Council. No data or materials provided under this subsection may be accessed, reviewed, or used by the dedicated AI Enforcement Unit established under subsection (j), or by any Department of Justice attorney or official assigned to any individual enforcement proceeding under this title, in connection with that proceeding.
(g) DATA REQUEST PROCEDURES.—A written data request submitted by the Federal Advisory Committee, any Technical Working Group through its Administrative Coordinator, or the National AI Council (after its constitution under section 2013(c)) shall: identify the specific data or category of data requested; identify the investigation domain or legislative purpose for which the data is sought; and be transmitted to the designated data access officer of the relevant Participating Data Agency. Each Participating Data Agency shall respond to a data request not later than 20 business days after receipt, either by producing the requested data, producing the data subject to a protective order negotiated with the requesting body, or providing a written explanation of any legal basis for non-production. A Participating Data Agency that fails to respond within 20 business days or that withholds data without adequate legal justification shall be reported by the Federal Advisory Committee Chair to the relevant congressional oversight committees within 5 business days of the failure. Data produced under this subsection shall be made available through the shared evidence repository maintained by the TWG Coordination Council and shall be treated as part of the investigatory record of this title.
(h) CLASSIFIED DATA.—Classified data requests from a Technical Working Group operating under the classified track established under subsection (i) shall be processed through the classified data access procedures established by the relevant Participating Data Agency in coordination with the appropriate security authority. Classified data produced under this subsection shall be made available to cleared TWG members and cleared FAC members only through secure channels and shall not be included in the public docket or the shared evidence repository. The National Security Agency and the Intelligence Community shall respond to classified data requests from designated classified-track TWGs under the procedures established by the Director of National Intelligence for interagency intelligence sharing.
(i) CLASSIFIED TRACK.—To the extent the lead agency's investigative support activities under section 2004 touch matters of national security, intelligence, or classified capabilities, the Director of AI Investigation shall establish and operate a parallel classified track with appropriate security protocols, conducted in coordination with the Department of Defense, the Intelligence Community, and the National Security Council, with classified investigative material delivered to cleared TWG members through secure channels and classified findings reported separately to the appropriate congressional committees through secure channels.
(j) ENFORCEMENT AUTHORITY AND DESIGNATION.—The Department of Justice, acting through the Civil Division and in coordination with United States Attorneys, shall serve as the enforcement arm for all civil penalty, disgorgement, injunctive relief, and compliance actions arising under this title. The lead agency shall have exclusive authority to make determinations of noncompliance and to issue Notices of Noncompliance under section 2015(b). Upon issuance of a Final Determination, the lead agency shall make a mandatory referral to the Department of Justice for enforcement. The Department of Justice shall initiate enforcement proceedings or notify the lead agency of a declination not later than 30 days after receiving a referral. If the Department of Justice determines not to initiate enforcement proceedings with respect to a specific referral, the Attorney General shall, within the 30-day period, transmit to the lead agency and to the relevant congressional oversight committees a written statement setting forth the basis for that determination. The Attorney General's written statement shall be published on the lead agency's public portal within 10 business days of transmission. Nothing in this subsection shall be construed to abrogate the Department of Justice's prosecutorial discretion with respect to individual enforcement decisions. The Attorney General shall designate a dedicated AI Enforcement Unit within the Civil Division, staffed with attorneys possessing expertise in technology law, administrative enforcement, and complex civil litigation. Personnel assigned to the AI Enforcement Unit shall not have access to data or materials provided by the Department of Justice in its capacity under subsection (f), consistent with the separation-of-functions requirement of that subsection.
SEC. 2012. CERTIFIED INDEPENDENT AI AUDITOR PROGRAM.
(a) ESTABLISHMENT.—Not later than 270 days after the date of enactment, the lead agency shall establish a Certified Independent AI Auditor Program (in this section, the "Program") to certify independent auditors qualified to conduct mandatory pre-deployment safety evaluations of frontier models and AI systems exhibiting dangerous capabilities required under this title and any subsequent Phase II legislation.
(b) RULEMAKING.—The lead agency shall, by interim final rule with subsequent notice and comment, promulgate qualifications, training requirements, examination standards, ethical obligations, and operational evaluation methodologies necessary for certification under the Program.
(c) MINIMUM CERTIFICATION STANDARDS.—The Program shall include, at minimum:
(1) TECHNICAL COMPETENCY.—Demonstrated competency in AI safety evaluation, dangerous capability evaluation, adversarial testing, and risk assessment.
(2) INDEPENDENCE.—Independence requirements, including:
(A) prohibitions on financial conflicts of interest with frontier AI developers or significant AI deployers subject to audit;
(B) employment-history disqualifications consistent with the conflict-of-interest provisions of this title;
(C) structural and operational independence from the lead agency, such that certified auditors shall not be employees, contractors, or detailees of the lead agency, and the lead agency's investigative, enforcement, and administrative personnel shall not perform certified audits under this Program; and
(D) ongoing disclosure obligations regarding any financial, employment, consulting, or contractual relationship with a frontier AI developer, a significant AI deployer, the lead agency, or any other federal entity with regulatory authority over AI systems, updated not less frequently than annually and within 30 days of any material change.
(3) CONTINUING EDUCATION.—Continuing education and recertification requirements at intervals not less frequent than every 24 months.
(4) PROFESSIONAL CONDUCT.—A code of professional conduct with associated disciplinary procedures, including suspension and revocation of certification for cause.
(d) LIMITED AUTHORITY TO DEVELOP EVALUATION CRITERIA FOR PROGRAM ADMINISTRATION.—To support the operational administration of the Program and to provide certified auditors with consistent technical standards for the conduct of evaluations, the lead agency may develop, publish, and update evaluation criteria addressing:
(1) methodologies for evaluating dangerous capabilities, including CBRN uplift, cyberoffense, autonomous replication, deception, and large-scale coordinated persuasion;
(2) independence and conflict-of-interest standards applicable to auditors and audit engagements;
(3) documentation, reporting, and recordkeeping requirements for audit findings;
(4) test-environment, red-team, and adversarial-testing protocols; and
(5) such additional procedural and methodological standards as the lead agency determines necessary for consistent and rigorous evaluation by certified auditors.
(6) RULE OF CONSTRUCTION.—Evaluation criteria developed under this subsection are operational standards governing auditor certification and the conduct of audits. They do not constitute substantive regulation of AI development or deployment beyond the scope of audit administration, do not substitute for the findings or recommendations of any Technical Working Group or the Federal Advisory Committee, and shall not be construed to authorize the lead agency to make findings, recommendations, or policy determinations within the investigatory mandate of any Technical Working Group under this title.
(e) ROLLING CERTIFICATIONS.—The lead agency shall accept applications for certification on a rolling basis and shall issue initial certifications not later than 75 days after each complete submission.
(f) PROHIBITION ON SELF-REPORTED EVALUATIONS.—No frontier AI developer, and no significant AI deployer of an AI system that exhibits dangerous capabilities, may satisfy any pre-deployment safety evaluation or audit requirement under this title or any subsequent Phase II legislation through self-reported testing. All such evaluations shall be conducted by auditors certified under the Program, except as provided under the transitional authority in subsection (g).
(g) TRANSITIONAL EVALUATION AUTHORITY.—Until the Program becomes operational and initial certifications are issued under subsection (e), pre-deployment safety evaluations required under this title shall be conducted by qualified independent third-party evaluators identified on an approved evaluator list published by the lead agency not later than 45 days after the date of enactment. The 45-day obligation is a list-publication requirement, not a standards-setting exercise. For purposes of this subsection, a "qualified independent third-party evaluator" means an organization that:
(1) has demonstrated experience conducting dangerous capability evaluations of frontier AI systems, including through evaluations conducted under voluntary Frontier AI Safety Policy commitments within the preceding 24 months;
(2) has no financial conflict of interest with the entity being evaluated; and
(3) has been approved by the lead agency and appears on the approved evaluator list.
(4) LIST MAINTENANCE.—The lead agency shall publish and maintain the approved evaluator list, which shall include at minimum any organization that has conducted dangerous capability evaluations under a documented Frontier AI Safety Policy commitment within the preceding 24 months.
(5) VALIDITY AND EXPIRATION OF TRANSITIONAL EVALUATIONS.—
(A) IN GENERAL.—An evaluation validly completed under this subsection satisfies the pre-deployment safety evaluation requirement of subsection (f) for the AI system evaluated, and does not require re-evaluation solely because the Program has subsequently become operational.
(B) EXPIRATION.—An evaluation described in subparagraph (A) expires, and the AI system evaluated becomes subject to the certified audit requirement of subsection (f), upon any material change in the system’s capabilities, risk profile, or intended uses within the meaning of section 2016(f)(7).
(C) RE-EVALUATION.—Upon expiration under subparagraph (B), the frontier AI developer or significant AI deployer shall obtain an evaluation conducted by an auditor certified under the Program before the modified system is deployed or, where the modification is made to a system already in deployment, not later than 90 days after the modification.
(D) NO SELF-REPORTING.—Nothing in this paragraph permits a frontier AI developer or significant AI deployer to satisfy any requirement of this section through self-reported testing, which remains prohibited by subsection (f).
(6) AGENCY FALLBACK EVALUATIONS.—The lead agency may itself conduct evaluations when no approved evaluator is available or when the entity seeking evaluation is unable to retain one within a reasonable time not exceeding 30 days.
(7) EFFECT OF FALLBACK EVALUATIONS.—Evaluations conducted by the lead agency under paragraph (6) are exercises of transitional fallback authority and do not constitute certified audits under the Program. Such evaluations do not confer auditor certification on lead agency personnel and do not establish the lead agency or its personnel as eligible for certification. Such evaluations are subject to paragraph (5) to the same extent as evaluations conducted by approved evaluators appearing on the list maintained under paragraph (4).
(h) CBRN EVALUATION SPECIALIST TRACK.—The Program shall include a specialized CBRN Evaluation Specialist Track for auditors qualified to conduct or supervise the CBRN capability evaluations required under section 2017(a)(2)(C). The CBRN Evaluation Specialist Track shall be developed in coordination with, and shall incorporate, the CBRN Uplift Evaluation Standards required to be developed by the lead agency under section 2004(b)(6)(A)(i)(VIII). Certification in the CBRN Evaluation Specialist Track shall require:
(1) the general certification standards under subsection (c);
(2) demonstrated professional expertise in biological threat assessment, chemical weapons, or radiological and nuclear security, established through prior employment, publication record, security clearance, or equivalent credential; and
(3) demonstrated familiarity with AI-specific CBRN evaluation methodology consistent with frameworks used by recognized AI safety evaluation bodies, including the Model Evaluation and Threat Research organization (METR), the United Kingdom AI Security Institute, and the relevant federal national laboratories.
(4) INTERIM METHODOLOGY.—Until the CBRN Evaluation Specialist Track is established and initial certifications are issued, CBRN-related evaluations shall be conducted under the transitional authority of subsection (g), using the best-available CBRN evaluation methodology consistent with section 2017(a)(2)(C).
(i) PUBLIC REGISTRY.—The lead agency shall establish and maintain a publicly accessible registry of certified auditors, including current certification status, specialty track designations, the date of initial certification, the date of last recertification, and any disciplinary action taken against the auditor. The registry shall be updated within 10 business days of any change in status.
(j) RULE OF CONSTRUCTION.—Nothing in this section shall be construed to:
(1) authorize the lead agency to make substantive findings or recommendations within the investigatory mandate of any Technical Working Group under this title;
(2) substitute for or limit the legislative drafting authority of the Federal Advisory Committee under section 2006; or
(3) create independent regulatory authority outside the operational administration of the Program and the conduct of audits performed under it.
CHAPTER 5—INDEPENDENT BODIES AND INTERNATIONAL ENGAGEMENT
SEC. 2013. NATIONAL AI COUNCIL.
(a) ESTABLISHMENT.—There is established an independent body to be known as the National AI Council (in this section, the "Council"), which shall operate independently of the lead agency but in coordination with it, with the Federal Advisory Committee, and with the Participating Data Agencies.
(b) COMPOSITION AND SELECTION.—The Council shall be composed of 18 members, selected as follows. The appointment process shall commence within 30 days of the FAC backstop transmission deadline established under section 2006(i). Each appointing authority shall submit its appointments not later than 60 days after the commencement of the appointment process.
(1) PRESIDENTIAL APPOINTMENT.—1 member appointed by the President;
(2) SENATE LEADERSHIP APPOINTMENTS.—2 members appointed by the Majority Leader of the Senate and 2 by the Minority Leader of the Senate;
(3) HOUSE LEADERSHIP APPOINTMENTS.—2 members appointed by the Speaker of the House of Representatives and 2 by the Minority Leader of the House;
(4) FEDERAL ADVISORY COMMITTEE ELECTIONS.—7 members elected by the Federal Advisory Committee established under section 2006, from among the combined membership of the Committee and its Technical Working Groups, by a vote of the Committee conducted not later than 15 days after the FAC backstop transmission deadline. The 7 members elected under this paragraph shall include at least 4 former Technical Working Group members representing at least 4 different investigation domains and at least 1 former Federal Advisory Committee member who served in a leadership capacity. These members carry forward the institutional knowledge, evidentiary context, and domain expertise developed during the Phase I investigation; and
(5) STATE APPOINTMENTS AND MEMBER QUALIFICATIONS.—2 members selected by the National Governors Association. No member of the Council may be, at the time of appointment or at any time during service, a current employee, officer, director, or paid consultant of any frontier AI developer or significant AI deployer. No member may have been employed by, or received compensation exceeding $5,000 from, any frontier AI developer or significant AI deployer within the 1 year preceding appointment. Members shall recuse themselves from any matter in which they have a financial interest in an entity that would be materially affected by the Council's action. Members shall file annual financial disclosure statements with the lead agency identifying any financial interest in any entity whose primary business involves the development, deployment, or commercialization of AI models or AI systems. Membership shall reflect diversity in professional background, including technologists, AI safety researchers, elected officials, labor representatives, ethicists, ecological stewards, child welfare experts, and civil society representatives, geographic region, and demographic composition.
(c) APPOINTMENT DEADLINE AND FALLBACK.—The appointment process commences within 30 days of the FAC backstop transmission deadline established under section 2006(i). Each appointing authority shall submit its appointments not later than 60 days after commencement. If any appointing authority fails to submit appointments within the 60-day period, the Comptroller General shall make the unfilled appointments within 30 days thereafter. The Council shall hold its organizational meeting not later than 15 days after a quorum of 10 members has been appointed.
(d) QUORUM.—A quorum of the Council shall consist of 10 members. The Council may conduct business and take official action with a quorum present regardless of whether all 18 seats have been filled.
(e) MANDATE.—The Council shall -
(1) RECEIPT OF INVESTIGATORY RECORD.—receive the complete investigatory record transferred to the Council under sections 2006(h) and 2010(d);
(2) MAINTENANCE OF EVIDENTIARY RECORD.—maintain, update, and expand the criteria documents and evidentiary record on an ongoing basis;
(3) SHELF-READY EMERGENCY LEGISLATION.—prepare, maintain, and update shelf-ready emergency AI stewardship legislation with defined trigger conditions, compensation formulas, and sunset clauses, so that in the event of a Transformative AI Capability Event or AI-related crisis, Congress may act on a prepared legislative plan rather than improvisation -
(A) INITIAL PRODUCTION.—The Council shall produce and transmit its initial shelf-ready emergency legislative package to the designated introducers specified in subsection (f)(1), and to the chairs and ranking members of the Committees on Armed Services and Commerce of both chambers, not later than 90 days after the Council's organizational meeting under subsection (c), drawing upon the preliminary TACE response framework transmitted by the International AI Diplomacy Agency under section 2014(c)(3) and the complete investigatory record transferred under section 2006(k) - this initial production is the Council's mandatory first act upon receiving these materials and takes priority over all other Council responsibilities during the 90-day window;
(B) ANNUAL UPDATE.—The shelf-ready package shall thereafter be updated not less frequently than annually and shall be transmitted to the designated introducers immediately upon each annual update;
(C) PRE-PACKAGE INTERIM RULE.—Until the initial shelf-ready package has been transmitted, the emergency congressional action procedures of subsection (f) are not operative for any Transformative AI Capability Event determination, and the mandatory pause and operational restrictions of section 2015(n)(3) serve as the primary immediate governance response; and
(D) IAIDA FRAMEWORK FALLBACK.—If the International AI Diplomacy Agency has transmitted a preliminary TACE response framework under section 2014(c)(3) at the time of a TACE determination, the designated introducers may introduce that framework as interim emergency legislation pending the Council's shelf-ready package;
(4) CONTINUING DOMAIN FACT-FINDING.—continue fact-finding in each domain specified in section 2004(b) and in any additional domains the Council identifies as warranting investigation;
(5) ANNUAL REPORTS TO CONGRESS.—publish annual reports to Congress with updated findings and legislative recommendations; and
(6) COORDINATION WITH IAIDA.—coordinate with the International AI Diplomacy Agency established under section 2014.
(f) TRANSFORMATIVE AI CAPABILITY EVENT - EMERGENCY CONGRESSIONAL ACTION PROCEDURES.—
(1) DESIGNATED INTRODUCERS.—The following Members of Congress are hereby designated as introducers of the shelf-ready emergency legislative package required by subsection (e)(3) upon a Transformative AI Capability Event determination under section 2015(n): the chair and ranking member of the Committee on Commerce, Science, and Transportation of the Senate; the chair and ranking member of the Committee on Energy and Commerce of the House of Representatives; and the chair and ranking member of the Committee on Armed Services of each chamber. The introduction obligation under this paragraph, and all procedures under paragraphs (2) through (5), are operative only after the National AI Council has transmitted its initial shelf-ready emergency legislative package to the designated introducers pursuant to subsection (e)(3)(A). Before that transmission has occurred, a Transformative AI Capability Event determination activates the mandatory pause and operational restrictions of section 2015(n)(3) but does not activate the introduction obligation or the expedited procedures of this subsection, because no shelf-ready package yet exists. Once the initial shelf-ready package has been transmitted, the procedures of this subsection are permanently operative for all subsequent TACE determinations. Each designated introducer is individually obligated to introduce the most recently updated shelf-ready package in their respective chamber within 24 hours of receiving notice of a Transformative AI Capability Event determination under section 2015(n)(2). If the designated chair fails to introduce the package within 24 hours, the obligation falls immediately to the designated ranking member. If both the chair and ranking member of any committee fail to introduce within 48 hours of the TACE determination, the Secretary of the Senate and the Clerk of the House, as applicable, shall transmit the most recently updated shelf-ready package to the Congressional Record as a referred measure at the 48-hour mark, which referral shall have the same effect as introduction by a Member. The 24-hour introduction obligation is not suspended by recess, adjournment, or any other parliamentary status of Congress.
(2) AUTOMATIC DISCHARGE.—Any committee to which the shelf-ready package or any superseding emergency AI governance bill is referred following a Transformative AI Capability Event determination shall have 7 calendar days from the date of introduction or referral to report the bill to the floor. If the committee fails to report within 7 calendar days, the bill shall be automatically discharged from committee on the 8th calendar day without further action by any Member or any vote. The 7-day committee consideration period is not extended by recess, adjournment, pro forma session, or any other parliamentary interruption. During the 7-day committee period, the committee may amend the bill, substitute an alternative bill, or report the bill without amendment; if the committee fails to take any action within 7 days, the bill is discharged as introduced. Automatic discharge under this subsection is self-executing and shall not require a motion, a vote, or any action by the presiding officer.
(3) MANDATORY FLOOR VOTE.—Not later than 5 calendar days after discharge or reporting of the bill from committee under paragraph (2), the Majority Leader of the Senate and the Speaker of the House of Representatives shall each schedule a floor vote on the discharged or reported bill. Floor consideration shall be under a time agreement of not less than 4 hours of debate equally divided, after which the presiding officer shall immediately call the vote without any further procedural motion being in order. If either the Senate Majority Leader or the Speaker fails to schedule the floor vote within 5 calendar days of discharge, any Member of the relevant chamber may call up the bill as a privileged matter, and the presiding officer shall immediately recognize the calling Member for that purpose. The 5-day floor scheduling obligation is not extended by recess, adjournment, or any other parliamentary interruption.
(4) TOTAL MAXIMUM TIME TO FLOOR VOTE.—The procedures of paragraphs (1) through (3), operating together, are designed to produce a floor vote in each chamber within 12 calendar days of a Transformative AI Capability Event determination: 1 day for introduction, 7 days for committee consideration, and 4 days for floor scheduling. Congress finds that this 12-day target is appropriate given that: the shelf-ready package has been fully drafted, updated annually, and transmitted to all designated introducers in advance of any TACE; the evidentiary record compiled under this title provides the full factual basis for congressional deliberation; the 10^25 FLOP development pause under section 2015(n)(3) provides up to 180 days of operational stability during which the most acute risks are constrained; and the global implications of a Transformative AI Capability Event require that the United States Government have a functioning governance response in place within days, not months.
(5) DAY 60 INTERIM REGULATORY AUTHORITY.—If Congress has not enacted legislation specifically addressing a confirmed Transformative AI Capability Event within 60 calendar days of the TACE determination, the lead agency is authorized and directed to implement, as emergency interim regulations effective on Day 61, the most urgent protective provisions of the most recently updated shelf-ready package, as identified by the National AI Council in a written designation transmitted to the lead agency simultaneously with the shelf-ready package. Emergency interim regulations issued under this paragraph shall: take effect immediately upon publication in the Federal Register without the notice-and-comment requirements of 5 U.S.C. § 553, pursuant to the good-cause exception of 5 U.S.C. § 553(b)(B), on the basis that prior notice and comment are impracticable and contrary to the public interest given the nature of the emergency; expire automatically on the earlier of the date of enactment of superseding congressional legislation or the date the 180-day development pause under section 2015(n)(3) terminates; and be subject to judicial review under the arbitrary and capricious standard of 5 U.S.C. § 706(2)(A), provided that no court may stay or enjoin the emergency interim regulations solely on the grounds that notice-and-comment procedures were not followed, given the good-cause basis for their issuance.
(6) CONSTITUTIONAL BASIS.—The designated introduction obligation in paragraph (1) is authorized under Article I, section 5 of the Constitution, which vests in each chamber the power to determine its own rules, and is implemented here as a rule of the House and Senate that takes effect upon enactment of this title. The automatic discharge and mandatory floor vote procedures in paragraphs (2) and (3) are likewise implemented as rules of the respective chambers. Nothing in this subsection shall be construed to bind a future Congress or to deprive either chamber of its constitutional authority over its own rules and procedures; however, any modification or repeal of the procedures in this subsection shall require an affirmative vote of two-thirds of the members of each chamber, to ensure that these emergency governance procedures cannot be eliminated by simple majority action during a period of ordinary political competition. The emergency interim regulatory authority in paragraph (5) is grounded in Congress's Commerce Clause power and the Administrative Procedure Act's good-cause exception.
(7) EXERCISE OF RULEMAKING POWER.—The provisions of paragraphs (1) through (4) are enacted by Congress—
(A) as an exercise of the rulemaking power of the House of Representatives and the Senate, respectively, and as such they are deemed a part of the rules of each House, respectively, and supersede other rules only to the extent that they are inconsistent therewith; and
(B) with full recognition of the constitutional right of either House to change such rules (so far as relating to the procedure of that House) at any time, in the same manner, and to the same extent as in the case of any other rule of that House.
(g) DISCRETIONARY FUNDING.—The Council shall have discretionary authority to allocate funds appropriated under section 2014 to continue fact-finding, commission independent research, and retain technical consultants as needed to carry out its mandate.
(h) DURATION.—The Council shall be a permanent body and shall continue to operate unless dissolved by subsequent Act of Congress.
SEC. 2014. INTERNATIONAL AI DIPLOMACY AGENCY.
(a) ESTABLISHMENT.—There is established an independent agency of the United States Government to be known as the International AI Diplomacy Agency (in this section, the "Agency"). The Agency is modeled on the institutional design of the Arms Control and Disarmament Agency as established by the Arms Control and Disarmament Act (22 U.S.C. § 2551 et seq., as enacted September 26, 1961), drawing on that agency's experience as a technically specialized, treaty-focused body with direct White House access, independent appropriations, and a permanent expert staff that provided continuity of institutional knowledge across administrations. The Agency is established as a lean, technically elite institution - not a large bureaucracy - with a design philosophy of owning the expertise and the mandate while using the State Department's infrastructure, relationships, and administrative capacity where appropriate.
(b) MISSION.—The mission of the Agency shall be to advance United States national security, protect American technological leadership, and reduce the risk of catastrophic AI-related harms through international cooperation, treaty negotiation, and verification framework development. The Agency shall accomplish this mission by -
(1) TREATY FORMULATION AND VERIFICATION.—formulating, advocating for, negotiating, implementing, and verifying international AI treaties and agreements addressing AI safety, dangerous capability governance, autonomous weapons systems, and compute monitoring;
(2) MULTILATERAL FRAMEWORK PROPOSALS.—developing proposals for multilateral AI safety frameworks, including compute-monitoring regimes, mutual inspection protocols, and shared safety-testing standards, with particular attention to bilateral and multilateral engagement with the People's Republic of China, the European Union, the United Kingdom, Japan, South Korea, and other nations with significant AI development programs;
(3) ALLIED COORDINATION.—coordinating with allied nations to prevent a destabilizing AI arms race in autonomous weapons systems, cyberoffense capabilities, and frontier model development, while preserving American technological leadership;
(4) INTERNATIONAL FORA REPRESENTATION.—representing the United States in international fora on AI governance, including the G7 Hiroshima AI Process, the United Nations AI Advisory Body, and successor bodies to the Bletchley and Seoul AI Safety Summits;
(5) VERIFICATION METHODOLOGY DEVELOPMENT.—developing and operating technical verification methodologies for international AI agreements, including compute monitoring infrastructure, capability evaluation protocols, and inspection regimes analogous to those developed by the International Atomic Energy Agency for nuclear facilities;
(6) FOREIGN CAPABILITY ASSESSMENTS.—providing assessments of foreign AI capabilities and governance regimes to inform domestic AI policy and the investigation conducted under section 2004; and
(7) EXPORT CONTROL COORDINATION.—negotiating bilateral and multilateral agreements governing export controls on advanced computing hardware, AI model weights, and related technologies, with the objective of developing a coordinated allied framework that achieves national security objectives through collective action while reducing the competitive costs to United States companies from unilateral controls.
(c) LONG-TERM INSTITUTIONAL MANDATE.—
(1) INTERNATIONAL AI SAFETY AGENCY.—The Agency's most significant long-term deliverable shall be to pursue United States participation in or establishment of an International AI Safety Agency (IASA) - a permanent multilateral institution modeled on the International Atomic Energy Agency - with a mandate to develop international AI safety standards, operate mutual inspection and verification regimes for frontier AI development, and provide early warning of transformative AI capability developments to member states. The Agency shall:
(A) IASA INSTITUTIONAL FRAMEWORK.—develop and formally propose the IASA institutional framework, including a draft charter, governance structure, inspection authorities, and verification protocols, in appropriate international fora not later than 1 year after the date of enactment of this title. The 1-year deadline applies to the formal proposal - the submission of a fully drafted charter and governance structure to the United Nations Secretary-General and to the G7 and G20 member states - not to the establishment or ratification of the IASA, which will require multilateral negotiation on a timeline not fully within United States control;
(B) IASA TECHNICAL STANDARDS.—develop the technical standards and safeguards protocols that would govern an IASA, including compute monitoring methodologies, dangerous capability evaluation standards, and incident reporting requirements that would apply to member state AI development programs; and
(C) IASA TREATY NEGOTIATIONS.—negotiate with allied nations and the Secretary-General of the United Nations on the institutional framework for an IASA, including the treaty or charter basis for such an institution, its headquarters and seat, its financing, and the privileges and immunities of its personnel.
(2) COMPUTE MONITORING FRAMEWORK.—Not later than 18 months after the date of enactment of this title, the Agency shall develop and present to Congress a complete technical proposal for a multilateral compute monitoring framework - including the hardware monitoring infrastructure, data reporting requirements, third-party verification mechanisms, and enforcement procedures - that would enable participating nations to verify each other's compliance with agreed frontier AI development thresholds. The framework proposal shall include an assessment of the technical feasibility of monitoring compliance with training run thresholds analogous to the 10^25 floating-point operations threshold established in section 2015(n)(3) of this title. Congress intends the compute monitoring framework proposal to serve as the technical annex to the IASA institutional proposal required by paragraph (1), providing the international community with both the institutional architecture and the technical verification methodology for a functioning international AI governance regime. Accordingly, the Agency shall design the two deliverables as integrated components of a single international governance proposal, with the IASA charter proposal submitted at 1 year and the compute monitoring technical annex submitted to Congress at 18 months for congressional review before its formal international presentation.
(3) PRELIMINARY TACE RESPONSE FRAMEWORK.—The Agency shall develop and transmit a preliminary Transformative AI Capability Event response framework to the designated introducers specified in section 2013(f)(1), the lead agency, and the chairs and ranking members of the Committees on Armed Services and Commerce of both chambers, on the following staggered schedule. Not later than 180 days after the date of enactment of this title, the Agency shall transmit the core framework, consisting of subparagraphs (A) and (B). Not later than 270 days after the date of enactment, the Agency shall transmit the supplemental components, consisting of subparagraphs (C) and (D), together with any updates to the core framework. The complete preliminary TACE response framework, including subparagraph (E), shall be transmitted not later than 270 days after the date of enactment. The framework shall include:
(A) INTERNATIONAL COORDINATION PROTOCOLS.—proposed international coordination protocols for a post-TACE environment, including allied notification procedures, multilateral compute restriction mechanisms, and joint verification arrangements;
(B) DOMESTIC GOVERNANCE RESPONSE.—a proposed domestic governance response informed by the investigatory findings available at the time of transmission, including recommended compute development restrictions, capability assessment requirements, and emergency regulatory authorities;
(C) FOREIGN CAPABILITY ASSESSMENT.—an assessment of foreign AI capabilities and the likelihood that a TACE-threshold development could occur outside United States jurisdiction, and proposed mechanisms for international monitoring and early warning;
(D) DRAFT STATUTORY LANGUAGE.—draft statutory language suitable for introduction, to the extent the Agency determines such language can be responsibly drafted on the basis of the investigatory record available at the time of transmission; and
(E) PROVISIONS FOR NAC REFINEMENT.—identification of provisions that require further refinement by the National AI Council upon its constitution, including provisions that depend on the complete investigatory record or the final criteria documents. The preliminary TACE response framework is not the shelf-ready emergency legislative package required of the National AI Council under section 2013(e)(3), but shall serve as its foundation. Until the National AI Council transmits its shelf-ready package under section 2013(e)(3), the preliminary TACE response framework shall serve as the best available prepared legislative response for purposes of section 2013(f)(1), and designated introducers may introduce the framework in response to a TACE determination if no shelf-ready package has been transmitted. Once the National AI Council transmits its shelf-ready package, that package supersedes the preliminary framework for all purposes of section 2013(f).
(d) DIRECTOR.—
(1) APPOINTMENT.—The Agency shall be headed by a Director, appointed by the President with the advice and consent of the Senate. The Director shall hold the rank and status of Ambassador-at-Large, which shall confer the diplomatic protocol standing necessary to negotiate with foreign counterparts at the ministerial level without routing through bilateral embassy channels. The Director shall report to the President through the National Security Council.
(2) RELATIONSHIP TO SECRETARY OF STATE.—The Director shall coordinate with the Secretary of State on all matters touching active bilateral diplomatic relationships and shall consult with the Secretary before initiating formal negotiations with any foreign government. The Secretary of State may raise objections to proposed Agency negotiating positions through the National Security Council, where disagreements between the Director and the Secretary shall be resolved. The Secretary of State shall not have authority to direct, override, or veto the Agency's negotiating mandate as established by this title; all such disputes shall be escalated to the National Security Council for resolution.
(3) NSC MEMBERSHIP.—The Director shall be a permanent member of the Deputies Committee of the National Security Council when matters within the Agency's mandate are on the agenda, and shall be invited to participate in principals-level NSC discussions of AI governance, autonomous weapons, and compute export control matters.
(4) DEPUTY DIRECTOR.—The Agency shall have a Deputy Director, appointed by the President with the advice and consent of the Senate, who shall act as Director in the absence or incapacity of the Director and shall oversee the Agency's internal operations and technical divisions.
(e) ORGANIZATION AND PERSONNEL.—
(1) SIZE AND PHILOSOPHY.—The Agency shall be organized as a lean, technically elite institution. The total number of full-time equivalent employees of the Agency shall not exceed 60 in the first 3 years following establishment and shall not exceed 80 thereafter without specific congressional authorization. The Agency shall be organized around function rather than geography: the State Department's regional bureaus and bilateral embassy relationships are the appropriate venue for country-specific relationship management, and the Agency shall not duplicate those functions.
(2) ORGANIZATIONAL DIVISIONS.—The Agency shall be organized into the following divisions:
(A) TECHNICAL VERIFICATION DIVISION.—Not fewer than 10 and not more than 18 specialists, including AI researchers, computer scientists, hardware engineers, and verification scientists, responsible for developing and operating the technical methodologies for monitoring and verifying compliance with international AI agreements, including compute monitoring infrastructure, capability evaluation protocols, and inspection regimes. The Technical Verification Division shall be the primary technical resource for the IASA development mandate under subsection (c)(1) and the compute monitoring framework mandate under subsection (c)(2).
(B) NEGOTIATIONS DIVISION.—Not fewer than 8 and not more than 12 experienced diplomats, policy specialists, and AI governance experts, responsible for conducting and staffing international negotiations on AI safety frameworks, autonomous weapons governance, and compute export control coordination. The Negotiations Division shall include at least one individual with demonstrated expertise in game theory and mechanism design as applied to international coordination problems, arms control treaty design, or strategic technology competition, to ensure that negotiating positions are informed by rigorous analysis of strategic equilibria, self-enforcement conditions, and defection incentives in multi-player technology competition scenarios.
(C) INTELLIGENCE INTEGRATION UNIT.—Not fewer than 4 and not more than 8 cleared analysts, responsible for integrating all-source intelligence assessments of foreign AI capabilities into the Agency's negotiating positions, technical assessments, and policy recommendations. Personnel of this unit shall hold appropriate security clearances and shall have access to Sensitive Compartmented Information relevant to the Agency's mandate pursuant to subsection (f)(2).
(D) TECHNICAL ATTACHÉ PROGRAM.—Not fewer than 5 and not more than 10 Agency personnel co-located at United States embassies or missions in key jurisdictions, including Beijing, Brussels, London, Tokyo, and Seoul, serving as technical attachés with dual reporting to the Agency and the relevant Chief of Mission. Technical attachés shall provide the Agency with on-the-ground technical intelligence, facilitate direct technical dialogues with host-country AI governance officials, and support Agency negotiating teams during bilateral engagements.
(E) GENERAL COUNSEL AND CONGRESSIONAL LIAISON.—The Agency shall have a General Counsel and a Congressional Liaison, each reporting directly to the Director, responsible respectively for legal advice on international agreements and treaty law, and for maintaining the Agency's relationships with and reporting obligations to the relevant congressional committees.
(3) HIRING AUTHORITY.—The Agency is authorized to appoint and fix the compensation of such officers and employees as are necessary to carry out its functions. To enable the Agency to recruit technical specialists at compensation levels competitive with the private sector and academia, the Agency is authorized to: use Schedule A excepted service hiring authority for positions requiring specialized technical expertise in AI research, dangerous capability evaluation, or verification science; set compensation for technical specialists in the Technical Verification Division at rates up to the rate for Executive Level IV ($183,000 as of the date of introduction of this title, adjusted annually) without individual approval from the Office of Personnel Management; and hire experts and consultants under 5 U.S.C. § 3109 at daily rates not exceeding the daily equivalent of the Executive Level IV rate. Federal employees of other agencies, including the Department of State, the Department of Defense, and the Intelligence Community, may be detailed to the Agency at no cost to the Agency for periods not exceeding 3 years.
(f) AUTHORITIES.—
(1) INTERNATIONAL AGREEMENTS.—The Agency is authorized to negotiate and conclude international agreements on behalf of the United States within its mandate, consistent with applicable law and the constitutional authority of the President and the Senate. Nothing in this section shall be construed to modify the constitutional requirements governing the ratification of treaties or the existing framework governing the negotiation and conclusion of executive agreements.
(2) INTELLIGENCE ACCESS.—The Director of National Intelligence shall provide the Agency with access to all-source intelligence assessments of foreign AI capabilities, foreign AI governance programs, and foreign compliance with any international AI agreements to which the United States is a party. The Agency's Intelligence Integration Unit shall have access to Sensitive Compartmented Information as determined necessary by the Director of National Intelligence in consultation with the Agency Director. The Agency Director may request National Intelligence Estimates on foreign AI capabilities through the Director of National Intelligence.
(3) INFORMATION REQUESTS.—The Agency may request, and federal departments and agencies shall provide, such information, data, analyses, and technical assistance as the Agency determines necessary to carry out its mandate, including information held by the Department of Commerce, the Department of Defense, the Department of Energy, and the Intelligence Community. Classified information provided to the Agency shall be handled in accordance with applicable security requirements.
(4) REPRESENTATION EXPENSES.—The Agency is authorized to expend funds for official representation expenses, international travel, and participation in international fora at rates appropriate to its diplomatic functions, consistent with the Federal Travel Regulation and applicable State Department guidance on representation allowances for ambassadorial-level officials.
(g) COORDINATION WITH LEAD AGENCY AND NATIONAL AI COUNCIL.—The Agency shall coordinate with the lead agency established under section 2011 and, after its constitution under section 2013(c), the National AI Council established under section 2013 as follows:
(1) INVESTIGATION SUPPORT.—The Agency shall provide the lead agency's investigation under section 2004 with assessments of foreign AI capabilities and international governance approaches for use in domains 12 (post-AGI governance), 13 (compute export controls), and 19 (autonomous weapons systems). During Phase I, the Agency shall transmit such assessments directly to the relevant Technical Working Groups through the lead agency's shared evidence repository.
(2) NAC PARTICIPATION.—The Agency Director shall be a non-voting participant in National AI Council deliberations on matters with international dimensions, including but not limited to compute export controls, autonomous weapons governance, and post-TACE international coordination.
(3) QUARTERLY BRIEFINGS TO COUNCIL.—The Agency shall brief the National AI Council not less than quarterly on significant developments in international AI governance, foreign AI capability advancements, and the status of active treaty negotiations that could affect domestic AI governance or the Council's shelf-ready emergency legislative package.
(4) SHELF-READY PACKAGE CONSULTATION.—The National AI Council's shelf-ready emergency legislative package under section 2013(e)(3) shall include provisions addressing the Agency's role in any post-TACE international coordination. The Council shall consult the Agency Director when drafting and updating those provisions to ensure they reflect current international commitments, negotiating posture, and allied coordination mechanisms.
(h) CONGRESSIONAL REPORTING.—
(1) ANNUAL REPORTS.—Not later than 1 year after the Agency is fully operational, and annually thereafter, the Agency shall transmit to the Committee on Foreign Relations of the Senate, the Committee on Foreign Affairs of the House of Representatives, the Committee on Armed Services of the Senate, the Committee on Armed Services of the House of Representatives, the Committee on Commerce, Science, and Transportation of the Senate, and the Committee on Energy and Commerce of the House of Representatives: an unclassified annual report describing the Agency's activities, active negotiations, international agreements concluded or in progress, status of the IASA development mandate, and status of the compute monitoring framework mandate; and a classified annex transmitted through appropriate channels describing intelligence assessments of foreign AI capabilities and any matters that cannot be publicly disclosed without compromising classified sources and methods or ongoing negotiations.
(2) QUARTERLY BRIEFINGS.—The Agency Director or Deputy Director shall provide quarterly briefings to the relevant committees on the status of active negotiations and significant developments in international AI governance.
(3) MANDATORY NOTIFICATION.—The Agency shall notify the relevant committees within 30 days of: any significant breakdown in international AI governance negotiations; any foreign AI capability advancement that the Agency assesses materially alters the risk landscape addressed by this title; any proposed international agreement before it is concluded; and any determination by the Agency that a foreign nation has materially violated a commitment made in any international AI governance instrument.
(i) APPROPRIATIONS.—Appropriations for the Agency are authorized under section 2022(a), subject to the independence and separate-account protections of subsection (j).
(j) INDEPENDENCE PROTECTIONS.—The following structural protections are established to preserve the Agency's institutional independence and prevent its effective absorption into the Department of State or any other executive agency:
(1) SEPARATE APPROPRIATIONS ACCOUNT.—the Agency's appropriations shall be maintained in a separate account and shall not be subject to transfer, reprogramming, or rescission by the Department of State without specific congressional authorization;
(2) PERSONNEL SYSTEM INDEPENDENCE.—the Agency's personnel system shall be independent of the Department of State's Foreign Service personnel system; Agency employees shall not be subject to reassignment by the Secretary of State;
(3) NEGOTIATING MANDATE PROTECTION.—the Agency's negotiating mandate as established by this title may not be modified, restricted, or superseded by any National Security Presidential Directive, Presidential Policy Directive, or executive order without subsequent Act of Congress; and
(4) PROHIBITION ON ABOLITION OR MERGER.—the Agency may not be abolished, reorganized, or merged with any other agency except by Act of Congress. An executive reorganization plan that would abolish or merge the Agency shall not take effect unless Congress enacts implementing legislation specifically authorizing the reorganization.
CHAPTER 6—LEGISLATIVE TRIGGER AND HAMMER PROVISIONS
SEC. 2015. LEGISLATIVE TRIGGER, TRANSITION TO REGULATION, AND MANDATORY HAMMER PROVISIONS.
(a) AUTOMATIC MORATORIUM ON HIGH-RISK DEPLOYMENTS.
(1) PHASE II ENACTMENT DEADLINE.—The date that is 180 days after the date on which the Federal Advisory Committee transmits its complete legislative package, as defined in section 2003(8), under section 2006(i) is hereby designated the Phase II Enactment Deadline.
(2) MORATORIUM TRIGGER.—If Congress fails to enact comprehensive Phase II legislation, as defined in section 2003(26), by the Phase II Enactment Deadline, a blanket moratorium shall automatically take effect imposing the following restrictions -
(A) no frontier AI developer shall initiate any new training run exceeding the frontier model threshold under section 2003(16), release or publicly distribute any new frontier model, or license any frontier model for deployment in a high-risk application under section 2003(17);
(B) no person or entity shall commence construction of, or materially expand, any facility that houses computing infrastructure used primarily for AI model training, inference, or data processing, as described in subsection (c)(3); and
(C) no significant AI deployer shall initiate any new deployment of an AI system classified as high-risk under the criteria documents published pursuant to section 2007 that was not in active deployment before the date the moratorium took effect.
(3) ROLLING ENACTMENT AUTHORITY.—Congress may begin enacting domain-specific Phase II legislation at any time after the Federal Advisory Committee transmits any domain package under the rolling transmission authority of section 2006(i). The 180-day window governs only the deadline by which all 19 domains must be addressed, not the date by which Congress must begin acting.
(4) EXTENSION OF WINDOW.—The 180-day window is subject to extension under subsection (d).
(5) DEFINITION OF FAILS TO ENACT.—For purposes of this subsection, Congress "fails to enact" Phase II legislation if the legislation has not been presented to and signed by the President, or passed over a Presidential veto, by the Phase II Enactment Deadline. Introduction, committee passage, or single-chamber passage does not satisfy this requirement.
(6) SELF-EXECUTION AND DURATION.—The moratorium is self-executing and does not require further agency rulemaking, notice-and-comment proceedings, or congressional appropriation. The moratorium shall remain in force until Congress enacts superseding legislation.
(7) MANDATORY CIVIL PENALTY.—Any frontier AI developer that violates paragraph (2)(A), any person or entity that violates paragraph (2)(B), or any significant AI deployer that violates paragraph (2)(C) shall be subject to a mandatory civil penalty, per violation per day of continued noncompliance, of not less than the greater of (A) $50,000,000, or (B) an amount equal to 0.1 percent of the violator's annual worldwide revenue for the most recent fiscal year; with each day constituting a separate violation.
(8) COMPLIANCE DEADLINES.—
(A) NEW ACTIVITY.—No entity subject to the moratorium shall initiate any activity restricted under paragraph (2) on or after the date the moratorium takes effect. This subparagraph applies immediately upon the moratorium taking effect.
(B) ACTIVITY IN PROGRESS.—An entity engaged, as of the date the moratorium takes effect, in activity restricted under paragraph (2) shall cease that activity as follows:
(i) in the case of a training run described in paragraph (2)(A), not later than 14 days after the effective date, and shall perform no computation on that run after the effective date other than computation necessary to checkpoint, preserve, or safely terminate it;
(ii) in the case of construction or expansion described in paragraph (2)(B), not later than 30 days after the effective date, except that work necessary to render a site safe, preserve structural integrity, secure equipment, or comply with an order of a State or local authority may continue and shall not constitute a violation; and
(iii) in the case of a deployment described in paragraph (2)(C), immediately, except that a high-risk AI system in active deployment before the effective date is not restricted by paragraph (2)(C).
(C) ACCRUAL.—Penalties under paragraph (7) shall not accrue with respect to activity described in subparagraph (B) before the expiration of the applicable period.
(D) NOTIFICATION.—An entity relying on subparagraph (B) shall notify the lead agency, not later than 5 days after the effective date, of each activity being wound down and the date by which it expects to cease. Failure to notify does not extend any period under this paragraph.
(E) NO EXTENSION BY CONDUCT.—Activity that materially advances the capability of any AI model within the meaning of subsection (n)(3)(B)(ii), or that constitutes new construction rather than wind-down, is not within subparagraph (B) and remains subject to subparagraph (A).
(9) PER-VIOLATION CALCULATION.—For purposes of calculating penalties, each distinct frontier model training run, model release, data center construction project, or high-risk AI system deployment maintained in violation constitutes a separate violation, and each calendar day on which that violation continues constitutes an additional separate violation.
(10) NO DISCRETIONARY REDUCTION.—Except as provided in subsection (l), there shall be no discretionary reduction, waiver, or compromise of this penalty by the lead agency, the Department of Justice, or any other federal entity.
(b) PENALTY ASSESSMENT PROCEDURES.
(1) STANDARD PROCEDURE.—Penalties under subsection (a) shall be assessed through a 30-day notice-and-response procedure as follows:
(A) The lead agency issues a formal Notice of Noncompliance specifying the conduct at issue, the applicable moratorium restriction under subsection (a)(2)(A), (B), or (C), and the factual basis for noncompliance.
(B) The entity shall have 30 days to respond.
(C) The lead agency shall issue a Final Determination not later than 15 days after the close of the response period.
(D) If the Final Determination confirms noncompliance, penalties shall accrue from the date of the Final Determination.
(E) Failure to respond within 30 days automatically converts the Notice to a Final Determination on the 31st day, and penalties shall accrue from that date.
(2) BAD-FAITH ACCRUAL.—Notwithstanding paragraph (1), if the lead agency determines that the frontier AI developer or significant AI deployer continued to deploy or expand the noncompliant AI system during the 30-day response period despite having actual notice of the alleged noncompliance, penalties shall accrue from the date of the original Notice for each day on which such continued deployment or expansion occurred. This bad-faith accrual provision applies only to -
(A) for frontier AI developers, continued training, release, or licensing of frontier models;
(B) for data center construction, continued construction activity; and
(C) for significant AI deployers, continued new deployment of high-risk AI systems not in active deployment before the moratorium. It does not apply to maintenance of systems in existing deployment status pending resolution of the noncompliance determination.
(3) AUTOMATIC STAY ON JUDICIAL REVIEW.—Notwithstanding any other provision of this subsection:
(A) STAY AVAILABILITY.—A frontier AI developer or significant AI deployer that files a petition for judicial review of a Final Determination in a United States district court within 30 days of the date of the Final Determination shall receive an automatic stay of penalty accrual for 30 days from the date of filing, during which no penalties shall accrue under this subsection.
(B) NO EFFECT ON INJUNCTIVE RELIEF.—The automatic stay does not affect any injunctive relief the lead agency may seek against continued deployment or expansion of the noncompliant AI system during the stay period.
(C) EXPIRATION.—The stay expires at the earlier of 30 days from the date of filing or the date on which the court rules on any motion for preliminary injunction or stay pending review filed by the petitioner.
(D) JUDICIAL EXTENSION.—A court may extend the stay beyond 30 days upon a finding that the petitioner is likely to succeed on the merits and that irreparable harm would result from immediate penalty accrual.
(E) NON-RENEWAL.—The automatic stay is available once per Final Determination and may not be renewed.
(c) DOMAIN-SPECIFIC HAMMER PROVISIONS.—The following domain-specific mandatory restrictions shall take effect simultaneously with the moratorium under subsection (a) upon Phase II failure, and shall remain in force until Congress enacts Phase II legislation, as defined in section 2003(26), that specifically addresses the relevant domain through binding regulatory standards under section 2003(26)(A)(i). Each domain-specific restriction in this subsection is independent of and in addition to the moratorium under subsection (a), and the failure of any one domain-specific restriction to take effect or be enforced shall not affect the operation of any other restriction in this subsection or the moratorium under subsection (a).
(1) DOMAIN 13 - COMPUTE EXPORT CONTROLS: IMMEDIATE TOTAL EXPORT RESTRICTION.
(A) AUTOMATIC AND IMMEDIATE ACTIVATION.—Upon Phase II failure as described in subsection (a), an immediate and total export restriction on all covered AI computing hardware takes effect automatically, without any further agency action, rulemaking, order, notice-and-comment proceedings, or congressional action. This restriction applies globally to all export destinations without exception - there are no allied-nations exemptions, no license categories, no general license exceptions, no license exception carve-outs, and no safe harbors of any kind. No export license, general license, license exception, or other authorization under the Export Control Reform Act of 2018, the Export Administration Regulations, the International Traffic in Arms Regulations, or any other statute or regulation may permit export of covered AI computing hardware during the period this restriction is in effect. The restriction is self-executing from the instant of Phase II failure.
(B) COVERED HARDWARE.—For purposes of this paragraph, "covered AI computing hardware" means -
(i) graphics processing units and tensor processing units with aggregate processing capacity exceeding 300 teraflops of 16-bit floating point performance per unit;
(ii) custom AI accelerator chips designed primarily for matrix multiplication and neural network inference or training;
(iii) complete AI training cluster systems with aggregate capacity exceeding 10^24 floating-point operations per second;
(iv) networking equipment, including high-bandwidth interconnects and switches, designed primarily to connect AI computing hardware within a training cluster; and
(v) cloud computing access - whether provided through APIs, virtual machine instances, or any other mechanism - that provides the computational equivalent of the foregoing to a single customer or coordinated group of customers within any 30-day period. The Secretary of Commerce may, by emergency rule effective upon publication without notice-and-comment, adjust these thresholds to reflect advances in semiconductor technology.
(C) SCOPE.—The export restriction applies to -
(i) all export transactions, re-export transactions, transfers, sales, leases, loans, gifts, technology transfers, and licensing arrangements involving covered AI computing hardware;
(ii) hardware physically located in the United States;
(iii) hardware manufactured under United States intellectual property or by entities subject to United States jurisdiction, wherever located; and
(iv) cloud computing access provided from United States-based infrastructure or by entities subject to United States jurisdiction. There are no exceptions.
(D) PENALTIES.—Violations shall be subject to civil penalties of up to $1,000,000 per violation and criminal penalties of up to 20 years imprisonment for willful violations under the Export Control Reform Act of 2018 (50 U.S.C. § 4801 et seq.), in addition to the mandatory civil penalties of subsection (a). The Department of Justice shall treat violations of this paragraph as priority national security enforcement matters. The Secretary of Commerce shall refer all suspected violations to the Department of Justice within 5 business days of identification.
(E) TERMINATION.—The export restriction shall terminate upon enactment of Phase II legislation that specifically addresses domain 13 (compute export controls and semiconductor governance) through binding regulatory standards under section 2003(26)(A)(i), and shall be superseded by the permanent export control framework established by that legislation.
(2) DOMAIN 14 - MARKET CONCENTRATION: ACQUISITION AND INVESTMENT FREEZE.
(A) AUTOMATIC ACTIVATION.—Upon Phase II failure as described in subsection (a), a mandatory freeze shall automatically take effect prohibiting all acquisitions, mergers, joint ventures, material investments, and exclusive partnership agreements by any large AI entity, as defined in subparagraph (B), without prior written approval from the Federal Trade Commission or the Department of Justice Antitrust Division, as applicable. This freeze is self-executing and does not require agency rulemaking, notice-and-comment proceedings, or further congressional action.
(B) LARGE AI ENTITY.—For purposes of this paragraph, "large AI entity" means any frontier AI developer or significant AI deployer that -
(i) had annual worldwide revenue exceeding $10,000,000,000 in the most recent fiscal year;
(ii) controls or has the contractual right to access more than 20 percent of domestic frontier AI compute capacity; or
(iii) has a market capitalization exceeding $100,000,000,000 at the time of the proposed transaction. The lead agency shall publish a list of entities meeting this definition within 15 days of Phase II failure and update it quarterly.
(C) COVERED TRANSACTIONS.—The freeze applies to -
(i) acquisitions of any company, business unit, or asset portfolio with a transaction value exceeding $50,000,000;
(ii) mergers and consolidations of any kind;
(iii) joint ventures in which the large AI entity contributes more than $50,000,000 in cash, assets, or intellectual property;
(iv) exclusive licensing agreements covering AI models, training data, or AI infrastructure with a term exceeding 12 months and total value exceeding $100,000,000; and
(v) any investment that results in the large AI entity acquiring more than 10 percent of the voting securities of any AI developer, AI infrastructure provider, or training data provider.
(D) APPROVAL PROCESS.—A large AI entity seeking approval for a covered transaction during the freeze period shall submit a pre-transaction notification to the Federal Trade Commission and the Department of Justice Antitrust Division not less than 90 days before the proposed closing date. The reviewing agency shall approve the transaction only upon a finding that the transaction would not materially increase concentration in any relevant AI market and would not substantially lessen competition. The reviewing agency may impose conditions as a requirement of approval. Transactions closed in violation of this paragraph are voidable by the Federal Trade Commission or the Department of Justice at any time within 5 years of closing.
(E) PENALTIES.—Any large AI entity that closes a covered transaction without required approval shall be subject to -
(i) a mandatory civil penalty of $500,000,000 per transaction;
(ii) mandatory disgorgement of all benefits received from the transaction; and
(iii) divestiture of all assets acquired in the transaction at the order of the Federal Trade Commission or the Department of Justice. These penalties are in addition to any penalties available under the Clayton Act (15 U.S.C. § 12 et seq.) or the Federal Trade Commission Act (15 U.S.C. § 41 et seq.).
(F) TERMINATION.—The acquisition and investment freeze shall terminate upon enactment of Phase II legislation that specifically addresses domain 14 (market concentration, competition, and AI antitrust) through binding regulatory standards under section 2003(26)(A)(i), and shall be superseded by the permanent market structure framework established by that legislation.
(3) DOMAIN 10 - ENVIRONMENTAL IMPACTS: DATA CENTER CONSTRUCTION MORATORIUM AND DISCLOSURE.
(A) DEFINITIONS.—For purposes of this paragraph:
(i) AI DATA CENTER FACILITY.—The term "AI data center facility" means any building, structure, or campus that -
(I) houses computing infrastructure used primarily for AI model training, inference, or data processing; and
(II) either (aa) has projected or actual electricity consumption exceeding 100 megawatts, or (bb) is part of a covered campus, as defined in clause (ii), with aggregate projected or actual electricity consumption exceeding 100 megawatts. For purposes of determining whether a facility meets the 100-megawatt threshold, the projected capacity of the facility at full build-out shall govern, not the capacity of any initial phase of construction.
(ii) COVERED CAMPUS.—The term "covered campus" means all buildings, structures, and facilities that -
(I) are located on contiguous or adjacent parcels of land; and
(II) are owned, leased, operated, or controlled by the same person or entity or by entities under common ownership or control, including parent companies, subsidiaries, affiliates, and entities under common investment or management. For purposes of this clause, "common control" means the power to direct or cause the direction of the management and policies of an entity, whether through ownership of voting securities, by contract, or otherwise. A covered campus shall be treated as a single AI data center facility for all purposes of this paragraph, regardless of how many separate legal entities, permits, or utility accounts are used.
(iii) MATERIAL EXPANSION.—The term "material expansion" means any addition to an existing AI data center facility that would increase its electricity consumption by more than 50 megawatts above its most recently reported consumption level, measured at the covered campus level.
(B) FERC INTERCONNECTION MORATORIUM.—Upon Phase II failure as described in subsection (a), the following restrictions take effect immediately and automatically, without any agency action, rulemaking, or further congressional action:
(i) the Federal Energy Regulatory Commission shall not approve any new interconnection request or any pending interconnection request not yet finally approved for any new AI data center facility or any material expansion of an existing AI data center facility;
(ii) FERC shall within 5 business days of Phase II failure issue a notice to all transmission providers and interconnection queues directing suspension of all such pending approvals; and
(iii) no transmission provider subject to FERC jurisdiction may proceed with any interconnection agreement, facilities study, or system impact study for a new AI data center facility or material expansion during the moratorium. There are no exemptions, exceptions, waivers, or renewable energy carve-outs. The moratorium applies to all AI data center facilities meeting the definitions in subparagraph (A) regardless of their energy source, efficiency rating, or environmental commitments.
(C) CONSTRUCTION PROHIBITION.—Upon Phase II failure, no person or entity may commence construction of a new AI data center facility or commence a material expansion of an existing AI data center facility. For purposes of this subparagraph, "commence construction" means any ground-disturbing activity, including site preparation, grading, foundation work, and installation of any permanent infrastructure, regardless of whether a state or local building permit has been issued. Construction activity that commenced before Phase II failure may continue for not more than 30 days after Phase II failure, after which all construction must cease until Phase II legislation addressing domain 10 is enacted. Failure to cease construction shall subject the developer and each of its officers and directors to a mandatory civil penalty of $5,000,000 per day of continued construction.
(D) WATER USE DISCLOSURE.—Upon Phase II failure, every operator of an AI data center facility shall, within 90 days, file a water use disclosure with the Environmental Protection Agency reporting -
(i) total on-site water consumption in gallons per day averaged over the preceding 12 months;
(ii) the source or sources of water used, including groundwater, municipal supply, and surface water, with the geographic location of each source;
(iii) the Water Usage Effectiveness ratio of the facility;
(iv) projected water consumption at full build-out; and
(v) any water recycling, recapture, or conservation measures in place. Water use disclosures shall be publicly available on the EPA's public portal within 15 days of filing. Failure to file shall subject the operator to a mandatory civil penalty of $5,000,000 per month of noncompliance, with no discretionary reduction. The water use disclosure obligation is permanent and survives the termination of the construction moratorium.
(E) PENALTIES FOR EVASION THROUGH CORPORATE STRUCTURING.—Any attempt to evade the thresholds of this paragraph by dividing a facility among multiple legal entities, parcels, utility accounts, or permit applications shall constitute a separate violation subject to the penalties of subsection (a)(7) and (h). The lead agency shall have authority to aggregate electricity consumption, water consumption, and land area across related entities and parcels for purposes of determining whether any facility meets the definitions in subparagraph (A), applying the common control standard of subparagraph (A)(ii).
(F) TERMINATION.—The FERC interconnection moratorium under subparagraph (B) and the construction prohibition under subparagraph (C) shall terminate upon enactment of Phase II legislation that specifically addresses domain 10 (environmental and community impacts of data centers) through binding regulatory standards under section 2003(26)(A)(i). The water use disclosure requirement under subparagraph (D) shall continue in effect as a permanent requirement and shall not terminate upon Phase II enactment unless Phase II legislation specifically supersedes it.
(4) DOMAIN 15 - OPEN-WEIGHT AI MODELS: FRONTIER MODEL RELEASE AND TRAINING MORATORIUM.
(A) AUTOMATIC ACTIVATION.—Upon Phase II failure as described in subsection (a), a mandatory moratorium shall automatically take effect prohibiting -
(i) the public release of any open-weight frontier model, as defined in section 2003(24);
(ii) the initiation of any new training run that the releasing entity knows or has reason to believe will produce an open-weight frontier model; and
(iii) the public release of any model weights, parameters, or technical specifications that would enable a recipient to replicate the capabilities of an open-weight frontier model. This moratorium is self-executing and does not require agency rulemaking, notice-and-comment proceedings, or further congressional action. There are no pre-clearance procedures, exemptions, safe harbors, or exceptions during the moratorium period.
(B) SCOPE.—The moratorium applies to all persons and entities subject to this title, including academic researchers, non-profit organizations, and government contractors. It applies to releases on any platform or through any mechanism, including online repositories, peer-reviewed publications that include model weights, API access that effectively provides open weight access, and direct distribution. The moratorium does not prohibit -
(i) continued operation of open-weight models already publicly released before Phase II failure;
(ii) research, development, and internal testing of models that are not publicly released; or
(iii) release of model weights to the lead agency for safety evaluation purposes under a confidentiality agreement.
(C) PENALTIES.—Any person or entity that releases an open-weight frontier model in violation of this paragraph shall be subject to -
(i) a mandatory civil penalty of not less than the greater of $100,000,000 or 0.2 percent of the violator's annual worldwide revenue for the most recent fiscal year, per release;
(ii) mandatory disgorgement of all revenue attributable to the released model; and
(iii) an injunction requiring the releasing entity to take all technically feasible steps to limit further distribution of the released weights, including removal from repositories under the entity's control and notification to downstream distributors. These penalties apply notwithstanding any claim that the release was made for research, educational, or open-science purposes.
(D) TERMINATION.—The moratorium shall terminate upon enactment of Phase II legislation that specifically addresses domain 15 (open-weight AI models: governance, safety, and competition) through binding regulatory standards under section 2003(26)(A)(i), and shall be superseded by the permanent open-weight model governance framework established by that legislation.
(5) DOMAIN 17 - ELECTORAL INTEGRITY: MANDATORY AI CONTENT DISCLOSURE AND DISTRIBUTION SUSPENSION.
(A) AUTOMATIC ACTIVATION.—Upon Phase II failure as described in subsection (a), the following mandatory restrictions shall take effect immediately and automatically, without any agency action, rulemaking, or further congressional action, with respect to AI-generated content in federal election communications.
(B) AI DEPICTION BY A CANDIDATE'S OWN CAMPAIGN; MANDATORY DISCLOSURE.—A candidate, or an authorized committee of that candidate within the meaning of the Federal Election Campaign Act (52 U.S.C. § 30101 et seq.), that distributes, publishes, broadcasts, or makes available an election communication that includes AI-generated audio, video, imagery, or text depicting or purporting to represent that candidate shall -
(i) disclose clearly and conspicuously that the communication contains AI-generated content, in a manner prescribed by the Federal Election Commission within 15 days of Phase II failure, by means of a conspicuous visual label displayed continuously throughout any video content and prominently in any print, digital, or audio content and, in any communication containing audio or video, an audible spoken statement that the communication contains AI-generated content; and
(ii) transmit to the Federal Election Commission a copy of the communication and a certification identifying which elements are AI-generated, the AI system used to generate them, and the identity of the entity, within 24 hours of first distribution. Failure to comply shall subject the entity to penalties at not less than Tier 3 of the General Penalty Framework under section 2016(m), per distribution event, with each separate distribution channel constituting a separate event.
(C) PROHIBITION ON UNAUTHORIZED AI DEPICTION OF A CANDIDATE.—Upon Phase II failure, it shall be unlawful for any person or entity, other than the depicted individual or, in the case of a candidate, an authorized committee of that candidate within the meaning of the Federal Election Campaign Act, to distribute, publish, broadcast, or make available in an election communication any AI-generated replica, simulation, or depiction of the voice, image, or likeness of an identified federal candidate, elected official, or election worker that is presented as, or that a reasonable person could mistake for, an authentic depiction of that individual. A violation does not require a showing that the content is materially deceptive or false. This prohibition does not apply to material that is clearly identified as AI-generated and that constitutes satire, parody, commentary, criticism, or caricature, or to bona fide news reporting, documentary, or archival use, except where the outlet or channel disseminating the material is owned or controlled by a candidate, a political committee, a political party, or a foreign government or foreign political party. Violations shall be subject to mandatory penalties of $10,000,000 per distribution event, mandatory referral to the Federal Election Commission and the Department of Justice, and an injunction requiring the distributing entity to take all technically feasible steps to remove the content from platforms and repositories under its control.
(D) FEC EMERGENCY RULEMAKING.—Within 15 days of Phase II failure, the Federal Election Commission shall issue emergency regulations, without prior notice-and-comment under the good-cause exception of 5 U.S.C. § 553(b)(B), specifying -
(i) the format, placement, and duration requirements for the AI content labeling required by subparagraph (B);
(ii) the technical specifications for the required 24-hour FEC transmission; and
(iii) the definition of "distribution event" for purposes of penalty assessment under subparagraph (B). The FEC shall consult with the lead agency in developing these regulations.
(E) RELATIONSHIP TO SECTION 2016(H)(8).—The restrictions in this paragraph operate in addition to and independently of the prohibitions in section 2016(h)(8) of this title, which take effect on the date of enactment and remain in force regardless of Phase II failure. The restrictions in this paragraph supplement section 2016(h)(8) by -
(i) establishing the mandatory disclosure regime for candidate self-depiction under subparagraph (B), including the audible-disclosure requirement;
(ii) adding an FEC transmission requirement; and
(iii) establishing emergency FEC rulemaking authority. Compliance with section 2016(h)(8) does not satisfy the requirements of this paragraph, and violations of this paragraph are separately penalized from violations of section 2016(h)(8). The disclosure and prohibition requirements of this paragraph and of section 2016(h)(8) are in addition to, and are not satisfied by compliance with, the disclosure and disclaimer requirements of Title IV of this Act (Political Spending Disclosure).
(F) TERMINATION.—The restrictions under this paragraph shall terminate upon enactment of Phase II legislation that specifically addresses domain 17 (AI and electoral integrity) through binding regulatory standards under section 2003(26)(A)(i), and shall be superseded by the permanent electoral integrity framework established by that legislation. The labeling requirement of subparagraph (B) shall continue as a permanent requirement unless specifically superseded by Phase II legislation, consistent with the constitutional durability of disclosure requirements under Buckley v. Valeo, 424 U.S. 1 (1976).
(d) GRADUATED CONGRESSIONAL EXTENSION MECHANISM.—The 180-day congressional window for enacting Phase II legislation under subsection (a) may be extended twice, for 30 additional days each time, upon demonstration of substantial legislative progress as defined in this subsection. The extension mechanism reflects Congress's judgment that meaningful progress toward comprehensive AI governance across the majority of domains warrants additional time to complete the remaining domains, rather than triggering a blanket moratorium over incomplete coverage. The extensions are automatic and self-executing upon satisfaction of the applicable threshold - they do not require any agency determination, rulemaking, or congressional vote to take effect. The Comptroller General shall publish a running public tally of certified domains, updated within 3 business days of each certification, throughout the congressional window period.
(1) FIRST 30-DAY EXTENSION.—The congressional window shall be automatically extended by 30 days - from the Phase II Enactment Deadline to the date that is 30 days after the Phase II Enactment Deadline - if, not later than the Phase II Enactment Deadline, Congress has enacted Phase II legislation, as defined in section 2003(26), that specifically addresses not fewer than 10 of the 19 investigation domains through binding regulatory standards or valid affirmative non-regulation findings. A domain is "addressed" for purposes of this paragraph when the Comptroller General has published a written determination under the final paragraph of section 2003(26) or under section 2015(e)(3) confirming that the enacted legislation satisfies the requirements of section 2003(26) for that domain. For purposes of counting domains, a domain addressed by a valid affirmative non-regulation finding under section 2003(26)(A)(ii) counts equally toward the threshold as a domain addressed by binding regulatory standards under section 2003(26)(A)(i). The first extension is not available if Congress has enacted legislation purporting to address 10 or more domains but the Comptroller General has determined that one or more of those purported enactments does not satisfy section 2003(26) - only certified domains count toward the threshold.
(2) SECOND 30-DAY EXTENSION.—If the first 30-day extension under paragraph (1) has taken effect, the congressional window shall be further extended by an additional 30 days - from the date that is 30 days after the Phase II Enactment Deadline to the date that is 60 days after the Phase II Enactment Deadline - if, not later than the date that is 30 days after the Phase II Enactment Deadline, Congress has enacted Phase II legislation addressing not fewer than 15 of the 19 investigation domains as confirmed by the Comptroller General under the procedures of paragraph (1). The second extension is available only if the first extension was validly triggered; it is not available independently. The same domain-counting methodology applies: each domain must be confirmed by a Comptroller General determination as satisfying section 2003(26), and affirmative non-regulation findings count equally with binding regulatory standards.
(3) NO FURTHER EXTENSIONS.—No more than two extensions are available under this subsection.
(A) FAILURE AT FIRST THRESHOLD.—If Congress fails to meet the 10-domain threshold by the Phase II Enactment Deadline, the moratorium under subsection (a) takes effect immediately on the day after the Phase II Enactment Deadline; the first extension does not trigger and no further extensions are available.
(B) FAILURE AT SECOND THRESHOLD.—If Congress meets the 10-domain threshold but fails to meet the 15-domain threshold by the date that is 30 days after the Phase II Enactment Deadline, the moratorium takes effect immediately on the following day; the second extension does not trigger.
(C) EXPIRATION OF SECOND EXTENSION.—If both extensions were validly triggered and Congress has still not enacted Phase II legislation addressing all 19 investigation domains upon expiration of the second extension, the moratorium under subsection (a) and all hammer provisions under subsection (c) shall take effect on the day after the date that is 60 days after the Phase II Enactment Deadline with respect to all remaining unaddressed domains.
(D) NO FURTHER EXTENSIONS, STAYS, OR GRACE PERIODS.—No further extensions, stays, or grace periods are available after the date that is 60 days after the Phase II Enactment Deadline except by subsequent Act of Congress that specifically supersedes this subsection.
(E) PRESERVATION OF OVERRIDE AUTHORITY.—The availability of extensions under this subsection does not modify, delay, or otherwise affect the congressional override and stay mechanism of subsection (k), which remains available independently throughout the extension period.
(4) INTERACTION WITH ROLLING FAC TRANSMISSIONS.—The Federal Advisory Committee transmits domain-specific legislative packages to Congress on a rolling basis pursuant to section 2006(i), giving Congress advance reading and preparation time before the single unified 180-day congressional window begins at the backstop transmission deadline. The 180-day window runs from the Federal Advisory Committee's final backstop transmission for all domains simultaneously - there is one clock, not one per domain. Domains for which Congress has enacted Phase II legislation and received Comptroller General certification—
(A) before the Phase II Enactment Deadline count toward the 10-domain threshold of paragraph (1), and
(B) before the date that is 30 days after the Phase II Enactment Deadline count toward the 15-domain threshold of paragraph (2), regardless of when the Federal Advisory Committee transmitted those domains.
The moratorium trigger date is the Phase II Enactment Deadline for the initial window, the date that is 30 days after the Phase II Enactment Deadline for the first extension, and the date that is 60 days after the Phase II Enactment Deadline for the second extension.
(5) EFFECT OF EXTENSIONS ON DOMAIN-SPECIFIC HAMMER PROVISIONS.—The domain-specific hammer provisions of subsection (c) are subject to the same extension mechanism as the general moratorium of subsection (a). If the first extension is triggered, the domain-specific provisions that would have taken effect at the Phase II Enactment Deadline are delayed to the date that is 30 days after the Phase II Enactment Deadline. If the second extension is triggered, those provisions are further delayed to the date that is 60 days after the Phase II Enactment Deadline. Domain-specific provisions terminate independently upon enactment of Phase II legislation addressing the relevant domain under the termination provisions of each paragraph of subsection (c), regardless of whether the general moratorium has triggered.
(e) EARLY DOMAIN PASSAGE AND ROLLING GAO CERTIFICATION.
(1) CONGRESSIONAL ACTION BEFORE FAC BACKSTOP TRANSMISSION.—Congress may enact legislation addressing one or more of the 19 investigation domains specified in section 2006(b) at any time after the date of enactment of this title, including before the relevant TWG has completed its investigation, before the Federal Advisory Committee has transmitted a domain package for that domain under section 2006(i), and before the FAC backstop transmission deadline. Early enactment of domain legislation is affirmatively encouraged by Congress as a mechanism for accelerating the governance of AI systems and reducing the period during which frontier AI developers and significant AI deployers operate without binding federal standards.
(2) JOINT TWG AND FAC REVIEW.—Within 30 days of the later of—
(A) the enactment of any legislation purporting to address one or more of the 19 investigation domains; or
(B) the date on which all four seed members of the relevant TWG or TWGs have been appointed under section 2005(a)(3) and have commenced ethics and security onboarding,
the Technical Working Group or Working Groups with jurisdiction over the relevant domain or domains, acting jointly with the Federal Advisory Committee, shall submit a written domain adequacy recommendation to the Comptroller General. If legislation is enacted before the seed members of the relevant TWG have been appointed, the 30-day review clock does not begin until all four seed members of that TWG have been appointed and have commenced onboarding; during this interim period the Federal Advisory Committee shall begin preliminary review of the enacted legislation using available lead agency investigative material. The recommendation shall assess whether the enacted legislation adequately addresses the domain as defined in section 2006(b), identify any material gaps between the enacted legislation and the full scope of the domain mandate, and recommend whether the Comptroller General should certify the domain as satisfied. The TWG and FAC shall reach their joint recommendation by majority vote of the TWG's full membership then seated and a concurrent vote of the Federal Advisory Committee under its standard 12-of-18 threshold. Where the TWG and FAC reach different conclusions, both conclusions shall be transmitted to the Comptroller General with full explanatory statements. If the TWG for a relevant domain has not yet held its organizational meeting but seed members have been appointed, the seed members shall participate in the recommendation on behalf of the TWG, with each seed member having one vote and a simple majority governing.
(3) GAO CERTIFICATION.—Within 30 days of receiving the joint TWG and FAC recommendation under paragraph (2), the Comptroller General shall publish a written certification determination in the Federal Register stating whether the enacted legislation satisfies the requirements of section 2003(26) for each relevant domain. The Comptroller General's determination is independent - it is not bound by the TWG and FAC recommendation - but shall specifically address in writing each material objection raised in a negative or split recommendation. A domain for which the Comptroller General publishes a written certification of satisfaction is a certified domain for all purposes of this title, including the moratorium threshold calculations of section 2015(a) and the graduated extension mechanism of section 2015(d), from the date of the Comptroller General's certification. The Comptroller General's certification determination shall be subject to expedited judicial review completable within 15 days in any United States district court.
(4) EFFECT ON TWG MANDATE.—Certification of a domain under paragraph (3) does not terminate or reduce the mandate of the relevant Technical Working Group. The TWG shall continue its investigation of the certified domain and may, through the Federal Advisory Committee, transmit supplemental legislative packages to Congress recommending more robust, comprehensive, or technically precise standards than those enacted. Supplemental packages are not required to avert the moratorium - the domain is already certified - but Congress is encouraged to consider them as Phase II refinements. A TWG whose domain has been certified shall note the certification in its final domain submission and assess in its Domain Explanatory Report whether the enacted legislation fully addresses the domain or whether identified gaps warrant supplemental legislative action.
(5) PUBLIC CERTIFICATION TALLY.—The Comptroller General shall maintain and publish a real-time public tally of all certified domains - whether certified through the early passage mechanism of this subsection or through the standard Phase II determination process under the final paragraph of section 2003(26) - updated within 3 business days of each certification. This tally is the operative record for purposes of the moratorium threshold calculations throughout section 2015.
(f) MANDATORY PRE-MARKET APPROVAL AND POST-DEPLOYMENT REVIEW.—If the moratorium under subsection (a) takes effect -
(1) no frontier AI developer may release, license, or distribute any new frontier model, and no significant AI deployer may initiate any new deployment of an AI system classified as high-risk under section 2007, without first obtaining written pre-market approval from the lead agency;
(2) frontier AI developers and significant AI deployers may continue to update and maintain AI systems that were in active deployment before the moratorium took effect, subject to expedited post-deployment review by the lead agency; and
(3) systems lawfully deployed before the moratorium must be registered with the lead agency within 30 days and are subject to expedited post-deployment review.
(g) AUTOMATIC PRIVATE RIGHT OF ACTION.
(1) CAUSE OF ACTION.—Upon the effective date of the moratorium, any person who suffers injury, loss, or adverse effect attributable to conduct prohibited by the moratorium under subsection (a) shall have a private right of action in any court of competent jurisdiction. Covered conduct includes -
(A) operation of a frontier model released, trained, or licensed in violation of subsection (a)(2)(A);
(B) operation of computing infrastructure constructed or expanded in violation of subsection (a)(2)(B); and
(C) operation of a high-risk AI system newly deployed in violation of subsection (a)(2)(C).
(2) STANDARD AND REMEDIES.—The standard of liability shall be strict liability. Courts shall award treble damages. Prevailing plaintiffs shall recover reasonable attorney's fees and costs.
(3) CLASS ACTIONS AND VOID PROVISIONS.—Class action certification shall be presumptively appropriate, and arbitration clauses, class action waivers, and forum selection clauses are void as against public policy.
(h) PERSONAL LIABILITY OF CORPORATE OFFICERS.
(1) COVERED OFFICERS AND CONDUCT.—
(A) IN GENERAL.—The chief executive officer, chief technology officer, chief operating officer, and any officer or director who willfully authorized or directed conduct in violation of the moratorium — including the training, release, or licensing of frontier models in violation of subsection (a)(2)(A), the construction or expansion of data center facilities in violation of subsection (a)(2)(B), or the new deployment of high-risk AI systems in violation of subsection (a)(2)(C) — shall be personally liable for civil penalties of not less than $5,000,000 per violation.
(B) WILLFULLY DEFINED.—For purposes of this subsection, a person acts willfully if the person acts with knowledge that the conduct is restricted by the moratorium, or with deliberate avoidance of such knowledge. Negligence, or the failure to discover a violation, does not constitute willfulness.
(C) AFFIRMATIVE DEFENSE.—It shall be an affirmative defense, on which the officer or director bears the burden of proof by a preponderance of the evidence, that the person—
(i) reasonably relied on a documented compliance determination made by qualified personnel or counsel;
(ii) did not authorize or direct the conduct at issue; and
(iii) upon becoming aware of the conduct, took prompt and reasonable steps to cause it to cease.
(D) RED LINE VIOLATIONS UNAFFECTED.—This paragraph does not limit personal liability under section 2017(b)(3) for violations of section 2017(a), to which the standard of that section applies.
(2) NO INDEMNIFICATION.—Such liability shall not be indemnifiable, and any agreement purporting to indemnify or insure such officers shall be void.
(3) DEBARMENT REFERRAL.—The lead agency shall refer patterns of officer noncompliance to the Department of Justice for consideration of debarment from serving as an officer or director of any entity subject to this title for not less than 10 years.
(i) SUSPENSION OF FEDERAL CONTRACTING PRIVILEGES.—Any frontier AI developer, significant AI deployer, or any person or entity in violation of the moratorium under subsection (a) shall be automatically debarred from all federal contracting, subcontracting, grant receipt, and participation in federally funded programs for not less than 5 years. This debarment is mandatory, non-waivable, and extends to all subsidiaries, affiliates, successors, and assigns. A debarment under this subsection shall be subject to review in the United States District Court for the District of Columbia on a petition filed not later than 60 days after notice of debarment. The court may set aside a debarment only if it determines that the debarment is arbitrary, capricious, an abuse of discretion, or otherwise not in accordance with law. The filing of a petition shall not stay the debarment unless the court orders otherwise.
(j) PROHIBITION ON REGULATORY ARBITRAGE AND EVASION.—Any attempt by any person or entity subject to the moratorium under subsection (a) to evade the requirements of this section - including restructuring, asset transfers, offshore relocation, shell entity creation, licensing arrangements, or technical modifications designed solely to evade classification - shall be treated as a separate violation subject to penalties at double the rates in subsections (a) and (h). The lead agency shall have authority to pierce corporate veils, disregard formal entity structures, and apply substance-over-form analysis.
(k) CONGRESSIONAL OVERRIDE AND STAY.
(1) OVERRIDE BY ENACTMENT.—Congress may avert the hammer provisions by enacting Phase II legislation, as defined in section 2003(26), before the moratorium trigger date.
(2) AUTOMATIC STAY ON SINGLE-CHAMBER PASSAGE OF QUALIFYING BILL.—The hammer provisions shall be automatically stayed during any period in which a qualifying bill has passed at least one chamber of Congress.
(3) QUALIFYING BILL DEFINED.—For purposes of this subsection, a "qualifying bill" means a bill that the Comptroller General has determined in writing satisfies the requirements of section 2003(26) - that is, a bill that -
(A) addresses all 19 investigation domains through either binding regulatory standards or valid affirmative non-regulation findings;
(B) includes binding regulatory standards for the five mandatory domains identified in section 2003(26)(B);
(C) includes binding enforcement mechanisms with specified penalties for each domain addressed through regulatory standards; and
(D) does not consist solely of investigatory or advisory provisions for any mandatory domain. A simple reauthorization or extension of this title's investigatory authority shall not constitute a qualifying bill.
(4) BILL STATUS.—A bill that satisfies the requirements of section 2003(26) but has not yet been signed into law shall trigger the stay; a bill that does not satisfy those requirements shall not trigger the stay regardless of the number of chambers through which it has passed.
(5) COMPTROLLER GENERAL DETERMINATION.—The Comptroller General's qualifying-bill determination shall be published in the Federal Register within 5 business days of the bill's passage through any chamber, shall be domain-by-domain in the same format as the determination required by the final paragraph of section 2003(26), and shall be subject to expedited judicial review completable within 15 days.
(6) SCOPE OF STAY AND INDEPENDENT TERMINATION.—The stay provided by this subsection applies to the moratorium under subsection (a) and to all domain-specific restrictions under subsection (c). However, each domain-specific restriction under subsection (c) terminates independently upon enactment of Phase II legislation specifically addressing the relevant domain through binding regulatory standards under section 2003(26)(A)(i), consistent with the individual termination provisions of each paragraph of subsection (c), and not upon enactment of Phase II legislation addressing other domains. Enactment of Phase II legislation that addresses some but not all domains terminates the domain-specific restrictions for the addressed domains while leaving all other restrictions in force.
(l) SETTLEMENT AUTHORITY AND PENALTY FLOORS.—The lead agency may enter into settlement agreements to resolve violations of this section, subject to the following conditions:
(1) PENALTY FLOOR.—No settlement shall reduce the total civil penalty below 60 percent of the amount that would otherwise be assessed under this section.
(2) REQUIRED TERMS.—Any settlement agreement shall require the violating entity to -
(A) cease the prohibited conduct within a timeline specified in the agreement;
(B) submit to enhanced compliance monitoring by the lead agency for a period of not less than 3 years; and
(C) cooperate fully with any ongoing investigation related to the violation.
(3) PUBLIC COMMENT FOR LARGE REDUCTIONS.—Any proposed settlement agreement involving a penalty reduction of more than 20 percent from the amount otherwise assessable shall be published in the Federal Register for a 30-day public comment period before finalization. The lead agency shall consider and respond to public comments before entering into the final agreement.
(4) NO WAIVER OF SUBSTANTIVE REQUIREMENTS.—The lead agency shall not enter into a settlement agreement that waives, reduces, or modifies any requirement of the moratorium itself, the domain-specific restrictions of subsection (c), or the mandatory pause provisions of subsection (n)(3). Settlement authority under this subsection extends only to the monetary penalties assessed for violations, not to the underlying regulatory requirements.
(5) OFFICER LIABILITY NOT WAIVABLE THROUGH ENTITY SETTLEMENT.—Personal liability of officers and directors under subsection (h) may not be waived or reduced through a settlement agreement with the corporate entity. Officers and directors may separately settle their personal liability under the same conditions as this subsection.
(6) ANNUAL REPORT.—The lead agency shall publish an annual report to Congress listing all settlement agreements entered into under this subsection, including the original assessable penalty, the settled amount, the compliance terms, and the factual basis for any reduction.
(m) JUDICIAL REVIEW FOR CONSTITUTIONAL PROPORTIONALITY.—Nothing in subsection (l) shall be construed to preclude a federal court from reviewing a penalty assessed under this section solely for compliance with the Excessive Fines Clause of the Eighth Amendment. Congress finds that, given the revenue scale and market capitalization of frontier AI developers and significant AI deployers, and the gravity of the harms that the prohibited conduct poses to public safety, national security, civil rights, and economic welfare, the penalty rates specified in this section are proportionate to the severity of the prohibited conduct.
(n) TRANSFORMATIVE AI CAPABILITY EVENT PROTOCOLS.
(1) MANDATORY NOTIFICATION.
(A) NOTIFICATION DUTY.—Any frontier AI developer or significant AI deployer that becomes aware, through internal evaluation, external research, or any other means, of evidence that any AI model or AI system - whether developed by that entity or any other - may have achieved or may imminently achieve a Transformative AI Capability Event as defined in section 2003(33) shall notify the lead agency and the Director of National Intelligence within 24 hours of such awareness, and shall additionally notify the National AI Council if the Council has been constituted under section 2013(c) at the time of such awareness.
(B) ONWARD NOTIFICATION.—The lead agency shall immediately notify the International AI Diplomacy Agency established under section 2014 upon receiving notification under this paragraph.
(C) PENALTY FOR FAILURE.—Failure to provide notification shall constitute a mandatory violation subject to the penalty provisions of subsection (a), applied per day of noncompliance from the date the entity first became aware of such evidence.
(D) INDEPENDENCE FROM SECTION 2017(A)(6).—The notification obligation in this paragraph is independent of and cumulative with the prohibition on concealment of transformative capabilities in section 2017(a)(6). Fulfillment of the notification obligation in this paragraph does not discharge or provide a defense to any violation of section 2017(a)(6), which imposes broader obligations including prohibitions on active misrepresentation and evaluation structuring that are not subsumed within the notification duty. A single course of conduct that both violates section 2017(a)(6) and constitutes a failure to notify under this paragraph gives rise to independent and separately penalized violations under both provisions, which shall not be merged, reduced, or offset against one another.
(2) MANDATORY CONGRESSIONAL BRIEFING.—Not later than 72 hours after receiving a notification under paragraph (1), or after independently determining that a Transformative AI Capability Event may have occurred or be imminent, the lead agency shall deliver a classified briefing to -
(A) the Speaker of the House;
(B) the Senate Majority Leader;
(C) the Senate Minority Leader;
(D) the House Minority Leader; and
(E) the chairs and ranking members of the Senate Select Committee on Intelligence, the House Permanent Select Committee on Intelligence, the Senate Committee on Commerce, Science, and Transportation, and the House Committee on Energy and Commerce.
(3) MANDATORY PAUSE ON TRAINING, CAPABILITY ADVANCEMENT, AND OPERATIONS.—Upon a determination by the lead agency, confirmed by the National AI Council within 5 days, that a Transformative AI Capability Event has occurred, the mandatory restrictions of this paragraph shall take effect immediately and remain in force until the earlier of—
(i) Congress enacting legislation specifically addressing the event pursuant to the emergency procedures of section 2013(f); or
(ii) 180 days having elapsed from the TACE determination.
If Congress has not enacted superseding legislation within 60 days, the lead agency shall implement emergency interim regulations under section 2013(f)(5) on Day 61 of the pause, provided that the National AI Council's initial shelf-ready package has been transmitted pursuant to section 2013(e)(3); if the initial shelf-ready package has not yet been transmitted, the lead agency shall develop and implement emergency interim regulations on Day 61 based on the most urgent provisions of the criteria documents and the investigation record then available.
If the National AI Council has not yet been constituted at the time of a TACE determination, the confirmation role of the Council under this paragraph shall be performed by the Comptroller General of the United States within 5 days. If the Council has been partially constituted, a quorum of not fewer than 4 members then serving shall be sufficient to perform the confirmation role.
The mandatory restrictions are:
(A) TRAINING HALT.—All frontier AI developers shall immediately suspend all training runs exceeding 10^25 floating-point operations. No new training run at or above this threshold may be initiated for any purpose, except as provided in subparagraph (F), for any AI model.
(B) CAPABILITY ADVANCEMENT PROHIBITION.
(i) PROHIBITED ACTIVITIES.—All frontier AI developers shall immediately cease all activities that would materially advance the capabilities of any AI model or AI system that has demonstrated, or that the lead agency determines is approaching, a Transformative AI Capability Event threshold under section 2003(33). Prohibited activities include fine-tuning, reinforcement learning from human feedback, capability elicitation techniques, prompt engineering designed to unlock latent capabilities, distillation of TACE-level capabilities into other models, and any other technique that the lead agency determines would expand the operational capability of a TACE-threshold system beyond its current level, regardless of whether such activity constitutes a training run above 10^25 FLOPs.
(ii) MATERIALLY ADVANCE DEFINED.—For purposes of this subparagraph, "materially advance" means any modification, technique, or process that produces a measurable improvement in the system's performance on any of the capability domains specified in section 2003(33)(A) through (D), or on any dangerous capability domain specified in section 2003(12), as assessed by a standardized evaluation methodology.
(iii) EMERGENCY RULEMAKING ON CALIBRATION.—The lead agency shall, within 30 days of a confirmed TACE determination, publish by emergency rulemaking under 5 U.S.C. § 553(b)(B) a specific technical definition of "materially advance" calibrated to the specific TACE threshold that was triggered, including quantitative benchmarks where feasible, to provide frontier AI developers with clear notice of which activities are prohibited during the pause period.
(iv) INTERIM PRESUMPTION.—Until such emergency rulemaking is published, any activity that a reasonable expert in AI capability evaluation would conclude is likely to increase the system's capabilities in the relevant TACE threshold domain shall be presumed to materially advance capabilities for purposes of this subparagraph.
(C) OPERATIONAL DEPRECATION.
(i) WITHDRAWAL.—Any AI system that the lead agency determines has demonstrated one or more of the capability thresholds defined in section 2003(33) - the specific system that triggered or contributed to the TACE determination - shall be withdrawn from operational deployment within 72 hours of the TACE determination being confirmed by the National AI Council.
(ii) PERMITTED CONTINUED OPERATION OF PRIOR VERSIONS.—The developing entity may continue to operate prior versions of the system that the lead agency affirmatively certifies do not demonstrate any of the thresholds in section 2003(33), but the TACE-threshold version specifically shall not remain in live deployment, shall not be accessible through any public-facing API or interface, and shall not be made available to any third party for any purpose during the pause period.
(iii) PERMITTED RESEARCH.—The developing entity may conduct safety research and evaluation on the deprecated system in a secured, air-gapped environment under protocols approved by the lead agency, but may not deploy, license, or otherwise make operational the TACE-threshold system or any system derived from it during the pause period.
(D) NO CIRCUMVENTION THROUGH DERIVED SYSTEMS.—No frontier AI developer or significant AI deployer may circumvent the operational deprecation requirement of subparagraph (C) by creating, deploying, or making available any AI system that incorporates, is derived from, is distilled from, or otherwise transfers the TACE-threshold capabilities of the deprecated system into a new or modified system. The lead agency shall have authority to require evaluation of any AI system released or deployed by the same entity within 180 days before or after the TACE determination to assess whether it incorporates transferred TACE-threshold capabilities.
(E) PENALTIES.—Any frontier AI developer that violates any of the restrictions in subparagraphs (A) through (D) shall be subject to the penalties of subsection (a) applied per day per violation, with no reduction, waiver, or compromise. Each of subparagraphs (A), (B), (C), and (D) constitutes a separate and independent obligation, and violation of each constitutes a separate violation for penalty purposes.
(F) PERMITTED SAFETY EVALUATION.—
(i) IN GENERAL.—Subparagraphs (A) and (B) do not prohibit computation, evaluation, or fine-tuning conducted solely for the purpose of safety research, alignment research, interpretability research, or dangerous capability evaluation, if each of the following conditions is satisfied:
(I) the activity is conducted within the secured, air-gapped environment described in subparagraph (C)(iii);
(II) the activity is conducted under a written protocol approved in advance by the lead agency, which shall approve or deny a submitted protocol not later than 14 days after submission;
(III) the activity does not materially advance capability within the meaning of subparagraph (B)(ii) in any domain specified in section 2003(33) or section 2003(12), and the developer bears the burden of demonstrating this by clear and convincing evidence;
(IV) no model weights, parameters, outputs, or internal representations produced by or during the activity are deployed, licensed, distilled, transferred, or otherwise made available outside the secured environment, whether during or after the pause period; and
(V) the developer transmits to the lead agency the results, methodology, and computation expended not later than 14 days after completion of each approved activity.
(ii) COMPUTATION CEILING.—Cumulative computation under this subparagraph shall not exceed the ceiling established by the lead agency in the approved protocol, which shall be no greater than necessary for the approved purpose.
(iii) REVOCATION.—The lead agency may revoke approval of a protocol at any time, and shall revoke approval upon determining that activity conducted under it has materially advanced capability. Activity conducted after revocation is a violation of subparagraph (A) or (B), as applicable.
(iv) MISCHARACTERIZATION.—A developer that characterizes activity as permitted under this subparagraph when it is not commits a willful violation for purposes of subparagraph (E) and section 2016(m), and no safe harbor under section 2016(n) is available.
CHAPTER 7—IMMEDIATE PROTECTIONS AND RED LINES
SEC. 2016. IMMEDIATE INTERIM PROVISIONS.
(a) IN GENERAL; PHASE-IN.—
(1) IN GENERAL.—The following requirements take effect immediately upon enactment and are binding on all frontier AI developers and significant AI deployers without awaiting completion of the investigatory process:
(2) PHASE-IN FOR CERTAIN DEPLOYERS.—A significant AI deployer that meets the definition in section 2003(30) solely by reason of subparagraph (A) of that paragraph shall comply with subsections (c) and (e) not later than 12 months after the date of enactment of this title, or 12 months after the date on which it first meets that definition, whichever is later. All other requirements of this section apply to such a deployer upon enactment.
(b) MANDATORY INCIDENT REPORTING.—
(1) GENERAL INCIDENT REPORTING.—Every frontier AI developer and significant AI deployer shall report to the lead agency within 72 hours of becoming aware of any incident involving an AI system that results in:
(A) bodily injury to any natural person, as defined in 18 U.S.C. § 1365(h)(4);
(B) direct financial loss to a single person exceeding $10,000, or aggregate financial loss across affected persons exceeding $100,000, in either case attributable to an AI system's outputs, decisions, or recommendations;
(C) a violation of a federal civil rights law, including Title VI or Title VII of the Civil Rights Act of 1964 (42 U.S.C. §§ 2000d, 2000e), the Americans with Disabilities Act (42 U.S.C. § 12101 et seq.), the Fair Housing Act (42 U.S.C. § 3601 et seq.), or the Equal Credit Opportunity Act (15 U.S.C. § 1691 et seq.), arising from an output or decision of the AI system; or
(D) a systemic failure of the AI system, meaning a single failure mode that produces erroneous, discriminatory, or harmful outputs across multiple instances, affecting more than 1,000 individuals.
(2) CHILD SAFETY INCIDENT REPORTING.—In addition, every frontier AI developer and significant AI deployer shall report to the lead agency and to the National Center for Missing and Exploited Children CyberTipline within 24 hours of becoming aware of any incident in which an AI system-
(A) generates, synthesizes, or distributes AI-generated CSAM or material that a reasonable observer would conclude depicts a minor engaged in sexually explicit conduct;
(B) serves sexual content to a user who is a known minor;
(C) engages in interaction patterns consistent with grooming of a minor, including sustained secretive communication designed to establish emotional dependency and erode parental oversight, as further defined by technical guidance issued jointly by the lead agency and the Department of Justice's Child Exploitation and Obscenity Section within 180 days of enactment;
(D) receives from a known minor communications expressing suicidal ideation, plans, or attempts, and the AI system fails to provide immediate referral to licensed crisis services; or
(E) provides detailed information about methods of self-harm, suicide, or violence to a known minor.
(3) INTERACTION LOGS.—Every frontier AI developer and significant AI deployer whose system is subject to reporting under this paragraph shall maintain interaction logs sufficient to allow reconstruction of interaction patterns upon request by the lead agency, law enforcement, or upon complaint by a user, parent, or guardian. Such logs shall be retained for not less than 180 days and shall be produced to the lead agency or law enforcement within 72 hours of a lawful request.
(4) NO REAL-TIME DETECTION REQUIRED; INCENTIVE FOR DETECTION.—Nothing in this paragraph requires real-time detection of grooming behavior; the obligation is to log, retain, and report upon awareness. However, a frontier AI developer or significant AI deployer that implements real-time detection and intervention capabilities meeting standards published by the lead agency shall receive a rebuttable presumption of reasonable care in any enforcement action under this paragraph.
(5) PENALTIES.—Failure to report under this subsection shall constitute a per-incident violation subject to penalties assessed under the General Penalty Framework in subsection (m), at Tier 2 through Tier 4 as applicable, except that failure to report incidents involving CSAM under paragraphs (1) or (2) shall be subject to mandatory Tier 4 penalties with no safe harbor under subsection (n).
(6) AWARENESS DEFINED; ESCALATION DUTY.—For purposes of this subsection, a frontier AI developer or significant AI deployer "becomes aware" of an incident when any officer, director, compliance personnel, or system administrator of the entity has actual knowledge of facts sufficient to indicate that a reportable incident has occurred or is occurring. A frontier AI developer or significant AI deployer shall implement reasonable internal escalation procedures to ensure that awareness by any such personnel is promptly communicated to the compliance function responsible for reporting under this subsection. A frontier AI developer or significant AI deployer shall not be liable under this subsection for failure to report an incident of which it had no actual knowledge, provided it has implemented such reasonable escalation procedures.
(c) MANDATORY TRANSPARENCY AND DISCLOSURE.—
(1) DISCLOSURE REQUIREMENTS.—Every frontier AI developer and significant AI deployer shall clearly and conspicuously disclose to all affected persons:
(A) that an AI system is being used in any decision, recommendation, or interaction affecting that person;
(B) the general nature and function of the AI system; and
(C) meaningful information about how to contest or seek human review of AI-influenced decisions.
(2) PENALTIES.—Failure to disclose shall subject the entity to penalties assessed under the General Penalty Framework in subsection (m), at Tier 1, assessed per AI system per quarter of noncompliance, with each AI system for which the required disclosure has not been implemented constituting a separate violation.
(d) TRAINING DATA DISCLOSURE TO LEAD AGENCY AND NATIONAL AI COUNCIL.—
(1) DISCLOSURE REQUIREMENT.—Every frontier AI developer shall, not later than 120 days after the date of enactment of this title and on a continuing basis thereafter, transmit confidentially to the lead agency, and after the organizational meeting of the National AI Council under section 2013(c) additionally to the National AI Council, in machine-readable format, the following training data disclosure-
(A) a high-level summary of the categories and sources of training data used in the AI system, including whether the training data includes copyrighted works, and if so the general categories of such works, including books, news articles, visual images, music, code, and social media content;
(B) whether any training data was acquired through licensing agreements with rights holders, and if so whether the rights holder provided affirmative consent for use in AI training;
(C) whether any training data was scraped or collected from websites, platforms, or databases where the terms of service prohibit such collection; and
(D) the date range of the training data and any known gaps in coverage.
(2) LIMITATION.—This subsection does not require disclosure of proprietary training pipelines, the specific contents of training datasets, or information that would constitute a trade secret under applicable law.
(3) CONFIDENTIALITY OF DISCLOSURES.—Information transmitted under this subsection shall be treated as confidential and shall not be disclosed by the lead agency or, after its constitution, the National AI Council, to any person outside those bodies, except:
(A) to members of Congress or congressional staff with appropriate access for oversight purposes, under conditions preserving confidentiality;
(B) to other federal agencies as necessary for the purposes of the investigation under section 2006 and the development of Phase II legislation, subject to equivalent confidentiality protections;
(C) pursuant to a court order in a proceeding to which the United States is a party; or
(D) in the form of aggregated, anonymized findings that do not identify any individual frontier AI developer or the specific training data practices of any individual frontier AI developer.
(4) AGGREGATED FINDINGS.—The lead agency shall publish aggregated findings from the disclosures received under this subsection as part of the reports required under section 2010, and shall include in those findings statistical summaries of training data practices across the frontier AI developer population - including aggregate rates of licensed versus unlicensed copyrighted works, terms-of-service compliance, and licensing arrangement types - without identifying any individual entity's disclosures.
(5) NO WAIVER OF PRIVILEGE OR PROTECTION.—Disclosure under this subsection does not constitute a waiver of any applicable privilege, protection, or immunity, including attorney-client privilege, work product protection, or trade secret protection, in any judicial, administrative, or legislative proceeding.
(6) PENALTIES.—Failure to transmit required disclosures shall subject the entity to penalties assessed under the General Penalty Framework in subsection (m), at Tier 1 through Tier 3 as applicable, assessed per AI system per quarter of noncompliance.
(e) DEPLOYER RISK MANAGEMENT POLICY.—
(1) REQUIREMENT.—Every significant AI deployer that deploys, operates, or makes available one or more high-risk AI systems as defined in section 2003(17) shall, not later than 180 days after the date of enactment of this title, design, implement, and maintain a documented risk management policy for each such system. A significant AI deployer that begins deploying a high-risk AI system after the date of enactment shall implement a risk management policy before the system is made operational.
(2) CONTENTS.—The risk management policy required under paragraph (1) shall specify, at minimum:
(A) the principles governing the deployer's use of the high-risk AI system, including the specific use cases for which the system is deployed, the populations affected by the system's outputs or decisions, and any use cases for which the system is not authorized;
(B) the processes by which the deployer identifies, assesses, monitors, and mitigates risks that are a reasonably foreseeable consequence of deploying or using the system in the deployer's specific operational context, including risks of bias, discrimination, inaccuracy, privacy violation, and physical or financial harm;
(C) the personnel responsible for maintaining the risk management program, including a designated individual with authority and accountability for risk management decisions, and a description of the qualifications, training, and resources available to such personnel;
(D) the procedures by which affected individuals may contest, seek explanation of, or obtain human review of decisions made or substantially influenced by the high-risk AI system;
(E) the frequency and methodology of ongoing monitoring and periodic review of the system's performance, outputs, and risk profile, which shall occur not less frequently than annually and upon any material change in the system's capabilities, use context, or affected population; and
(F) the procedures by which the deployer will comply with the incident reporting requirements of subsection (b), including internal escalation procedures and designated reporting personnel.
(3) AVAILABILITY.—The risk management policy required under paragraph (1) shall be maintained in written form, shall be made available to the lead agency upon request within 30 days, and shall be updated not less frequently than annually. A summary of the risk management policy, sufficient to inform affected individuals of the deployer's risk management practices and the procedures for contesting AI-influenced decisions, shall be made publicly available on the deployer's website or through other means reasonably calculated to reach affected individuals.
(4) RELATIONSHIP TO DEVELOPER OBLIGATIONS.—The deployer risk management policy required under this subsection is independent of and in addition to any risk management, testing, or evaluation obligations imposed on the frontier AI developer that developed the AI system being deployed. A deployer may not satisfy the requirements of this subsection solely by reference to the developer's own risk management practices, AI Data Sheet, or safety evaluations, but may incorporate such materials by reference where they are relevant to the deployer's specific operational context.
(5) PENALTIES.—Failure to implement or maintain a risk management policy as required by this subsection shall subject the significant AI deployer to penalties assessed under the General Penalty Framework in subsection (m), at Tier 1 through Tier 2 as applicable, assessed per high-risk AI system per quarter of noncompliance.
(f) AI DATA SHEET.—
(1) REQUIREMENT.—Every frontier AI developer shall, not later than 150 days after the date of enactment of this title, prepare and publish an AI Data Sheet for each AI system that the developer makes available for commercial use, licensing, or deployment by third parties. In addition, every person or entity that makes available for commercial use, licensing, or deployment any AI system classified as high-risk under section 2003(17) - whether developed independently, built upon a frontier model, fine-tuned from an existing model, or assembled through integration of multiple AI components - shall prepare and publish an AI Data Sheet for each such high-risk system, not later than 270 days after the date of enactment or before the system is made available, whichever is later. For AI systems first made available after the date of enactment, the AI Data Sheet shall be published prior to or contemporaneously with the system's initial release.
(2) PURPOSE.—The AI Data Sheet is intended to serve a function analogous to the Material Safety Data Sheets required under the Occupational Safety and Health Administration's Hazard Communication Standard (29 CFR 1910.1200(g)), adapted to the specific risks and characteristics of AI systems. The AI Data Sheet shall provide significant AI deployers, downstream developers, and end users with the information necessary to make informed decisions about the fitness, safety, and appropriate use of the AI system.
(3) CONTENTS.—Each AI Data Sheet shall include, at minimum:
(A) the intended contexts, uses, and use limitations of the AI system, consistent with the "map" guidelines articulated in the latest version of the NIST AI Risk Management Framework, including a clear statement of use cases for which the system has been evaluated and use cases for which the system is not intended or has not been evaluated;
(B) a description of the categories and sources of training data used in the AI system, including whether the training data includes copyrighted works, personally identifiable information, or data obtained from jurisdictions with distinct data protection requirements, provided that this subparagraph does not require disclosure of proprietary training pipelines, specific dataset contents, or information that would constitute a trade secret as defined in 18 U.S.C. § 1839(3);
(C) a summary of known capabilities and limitations of the AI system, including known failure modes, accuracy and reliability metrics for intended use cases, and any populations or contexts in which the system's performance has been found to be significantly degraded;
(D) a summary of foreseeable risks identified through the developer's testing, evaluation, and red-teaming processes, and the steps taken to mitigate each identified risk, consistent with the "manage" guidelines of the NIST AI Risk Management Framework;
(E) a description of the safety measures incorporated into the system, including content filters, guardrails, monitoring capabilities, and any mechanisms for human oversight or intervention;
(F) instructions for the safe deployment and use of the AI system, including recommended monitoring practices for deployers and any conditions under which the developer recommends that the system not be used; and
(G) contact information for reporting safety concerns, vulnerabilities, or incidents to the developer.
(H) TAILORING FOR HIGH-RISK SYSTEMS BUILT UPON THIRD-PARTY MODELS.—A person or entity that is required to publish an AI Data Sheet for a high-risk AI system under paragraph (1) and that did not independently train the base model underlying the system may omit or abbreviate the training data disclosure of subparagraph (B) to the extent that the entity does not possess and cannot reasonably obtain the relevant training data information, provided that the AI Data Sheet: identifies the base model or models upon which the system is built, including the developer and version; references the frontier AI developer's AI Data Sheet for the base model, if one has been published; and discloses any fine-tuning data, supplemental training data, retrieval-augmented generation sources, or other data inputs that are specific to the high-risk system and within the entity's knowledge or control. The remaining contents requirements of subparagraphs (A) and (C) through (G) apply in full to all high-risk system AI Data Sheets, and shall be completed with reference to the system's specific deployment context, intended population, and operational risk profile - not solely by reference to the base model's general capabilities.
(4) FORMAT AND ACCESSIBILITY.—The lead agency shall publish format and content guidance for AI Data Sheets not later than 60 days after the date of enactment, drawing upon the NIST AI Risk Management Framework, existing model card and data sheet practices, and international standards. The AI Data Sheet shall be published in a machine-readable format specified by such guidance, shall be prominently accessible on the developer's website, and shall be incorporated into or accompany the terms and conditions, licensing agreements, or API documentation through which the AI system is made available to deployers and users. Until such guidance is published, frontier AI developers and persons or entities publishing AI Data Sheets for high-risk systems shall comply with this subsection using a good-faith interpretation of the requirements of paragraph (3).
(5) REGISTRATION.—Each AI Data Sheet for an AI system meeting the frontier model threshold under section 2003(16) shall be transmitted to the lead agency contemporaneously with its publication. The lead agency shall maintain a public registry of AI Data Sheets received under this paragraph, searchable by developer, system name, and date of publication.
(6) RELIANCE.—A significant AI deployer or other person that relies in good faith upon the statements, risk disclosures, and use limitations contained in an AI Data Sheet when making deployment decisions may assert such reliance as an affirmative defense in any enforcement action or civil proceeding arising from the deployer's use of the AI system within the parameters described in the AI Data Sheet. This defense is not available to a deployer that had actual knowledge that the AI Data Sheet was materially inaccurate or that the deployer's use of the system exceeded the use limitations described therein.
(7) UPDATES.—A frontier AI developer, and every person or entity required to publish an AI Data Sheet for a high-risk system under paragraph (1), shall update the AI Data Sheet for each such AI system not less frequently than every 6 months, and within 30 days of any material change in the system's capabilities, risk profile, or intended uses. Each update shall be clearly dated and shall identify the changes from the prior version. Superseded AI Data Sheets shall remain publicly available in an archived format. The update obligation under this paragraph is independent of and does not modify, delay, or substitute for the mandatory notification obligations under subsection (b), subsection (g)(2)(C), or section 2015(n)(1), each of which operates on its own timeline regardless of whether the AI Data Sheet has been updated.
(8) PENALTIES.—Failure to publish or maintain an AI Data Sheet as required by this subsection shall subject the frontier AI developer to penalties assessed under the General Penalty Framework in subsection (m), at Tier 2 through Tier 3 as applicable, assessed per AI system for which no compliant AI Data Sheet has been published. Publication of an AI Data Sheet that is materially false or misleading shall be treated as a Tier 3 violation and shall nullify the reliance defense of paragraph (6) for any deployer that relied upon the false or misleading statement. Persons or entities required to publish AI Data Sheets for high-risk systems under paragraph (1) that are not frontier AI developers or significant AI deployers shall, upon the lead agency's first determination of noncompliance, receive a written notice identifying the obligation and providing 90 days to cure the violation by publishing a compliant AI Data Sheet. No penalty shall accrue during the 90-day cure period for a first violation. Penalties for continued noncompliance after the cure period, or for second and subsequent violations, shall be assessed at Tier 1 under the General Penalty Framework in subsection (m).
(9) RELATIONSHIP TO TRAINING DATA DISCLOSURE.—The AI Data Sheet required under this subsection is independent of and in addition to the confidential training data disclosure required under subsection (d). The AI Data Sheet is a public-facing document intended for deployer and user decision-making; the training data disclosure under subsection (d) is a confidential government-facing disclosure intended for investigatory purposes. A frontier AI developer may satisfy the training data component of the AI Data Sheet (paragraph (3)(B)) and the training data disclosure (subsection (d)) with information drawn from the same internal records, but publication of the AI Data Sheet does not satisfy the confidential disclosure requirement, and vice versa.
(g) POST-RELEASE DUTY TO UPDATE AND NOTIFY.—
(1) ONGOING MONITORING.—Every frontier AI developer shall establish, not later than 90 days after the date of enactment of this title, and thereafter maintain, a program for ongoing monitoring of each AI system it has released for commercial use, designed to identify dangers, defects, failure modes, or emergent capabilities not known at the time of initial release. The monitoring program shall include review of incident reports received under subsection (b), analysis of user feedback and public research findings, and periodic re-evaluation of the system's risk profile in light of new information. The duty to act upon post-release dangers under paragraph (2) applies from the date of enactment regardless of whether the monitoring program has been fully established.
(2) DUTY TO ACT UPON DISCOVERY OF POST-RELEASE DANGERS.—When a frontier AI developer becomes aware, through its monitoring program, through external research, through incident reports, or through any other means, of a danger connected with an AI system that was not adequately addressed at the time of release, the developer shall act in a timely manner as a reasonably prudent developer in the same or similar circumstances. This duty is satisfied if the developer makes reasonable efforts to:
(A) issue product updates, patches, or modifications to address the identified danger, where technically feasible;
(B) where the danger cannot be adequately addressed through updates, issue a product recall, withdrawal, or restriction limiting the system's availability or functionality to the extent necessary to mitigate the danger;
(C) notify all known significant AI deployers of the system, within 72 hours of the developer's determination that the danger requires action, of the nature of the danger, the actions the developer is taking, and any actions the deployer should take to avoid foreseeable harm, including discontinuing specific uses of the system; and
(D) publish a clear and conspicuous notice to end users explaining the risk of harm, the actions the developer has taken, and any precautions users should take, through the AI Data Sheet update mechanism of subsection (f)(7) and through any other channels reasonably calculated to reach affected users.
(3) SCOPE OF DUTY.—The duty under paragraph (2) applies to dangers that a reasonably prudent frontier AI developer, possessed of the specialized knowledge that such an entity holds or should hold regarding AI systems, would recognize as requiring remedial action. The duty does not require a developer to monitor all possible downstream uses of its system by all possible users, but does require the developer to act upon information that comes to its attention through reasonable means. A frontier AI developer that has published an AI Data Sheet under subsection (f) and has established the monitoring program required under paragraph (1) satisfies its obligation to maintain awareness of post-release dangers through reasonable means.
(4) TIMEFRAME.—A frontier AI developer shall initiate remedial action under paragraph (2) within 30 days of becoming aware of a post-release danger. For dangers that pose an imminent risk of serious physical harm, death, or CBRN-related harm, the developer shall initiate remedial action within 72 hours and shall notify the lead agency contemporaneously with the notification to deployers under paragraph (2)(C).
(5) RECORD RETENTION.—A frontier AI developer shall maintain records of all post-release dangers identified, the date of identification, the actions taken, and the notifications issued for not less than 5 years. Such records shall be made available to the lead agency upon request.
(6) PENALTIES.—Failure to comply with the requirements of this subsection shall subject the frontier AI developer to penalties assessed under the General Penalty Framework in subsection (m), at Tier 2 through Tier 4 as applicable, with Tier 4 applying to failures involving imminent risk of serious physical harm, death, or CBRN-related harm. A frontier AI developer that knowingly conceals a post-release danger from deployers, users, or the lead agency shall be subject to Tier 4 penalties without safe harbor under subsection (n).
(h) PROHIBITED USES.—The following uses of AI systems are prohibited for any person or entity immediately upon enactment, without exception, waiver, or grace period:
(1) BIOMETRIC SURVEILLANCE.—Real-time mass biometric surveillance of public spaces without individualized judicial authorization based on probable cause. Violations are subject to not less than Tier 3 penalties under subsection (m) and, in a private action under subsection (o), to statutory damages of not less than $1,000 and not more than $5,000 per affected individual in lieu of actual damages.
(2) SOCIAL SCORING.—Social scoring systems that assign aggregate behavioral scores to individuals for use in determining access to public or private services. Violations are subject to not less than Tier 3 penalties under subsection (m) and, in a private action under subsection (o), to statutory damages of not less than $1,000 and not more than $5,000 per affected individual in lieu of actual damages.
(3) DECEPTION IN CRITICAL CONTEXTS.—AI systems designed to deceive individuals into believing they are interacting with a human being in contexts involving health, legal, financial, emergency, or crisis services.
(4) AI COMPANION AND SYNTHETIC INTIMACY SYSTEMS.—Any AI companion system or synthetic intimacy system that-
(A) is accessible to users under the age of 13 without verifiable parental consent consistent with the Children's Online Privacy Protection Act. The prohibition on sexual and romantic content to minors is established in section 2017(a)(5)(A)(iii) and is enforceable immediately upon enactment under that section;
(B) uses anthropomorphic deception to cause a minor user to believe they are in a relationship with a human being;
(C) employs emotional mirroring, simulated distress at user absence, expressions of love or romantic attachment, or persistent memory of emotionally significant user disclosures in interactions with any user identified or reasonably identifiable as defined in section 2003 as under the age of 18; or
(D) fails to provide mandatory AI disclosure as follows, calibrated to the system's character presentation and design:
(i) TIER A - SYSTEMS WITH ATTACHMENT-MAXIMIZING DESIGN FEATURES.—Any AI companion system accessible to minor users that employs one or more attachment-maximizing design features as defined in section 2003(13) - including persistent memory of emotionally significant user disclosures, variable reinforcement schedules, emotional mirroring, or expressions of simulated affection or attachment - shall disclose clearly and conspicuously to the user at session initiation and at intervals not exceeding 30 minutes of continued engagement that the user is interacting with an artificial intelligence system. If the system presents as or simulates a human individual through photorealistic or near-photorealistic representation, the disclosure shall additionally state that the system is not a human being. The disclosure shall appear in the active conversation interface and not solely in a terms of service agreement, settings menu, or other location not immediately visible during interaction.
(ii) TIER B - NON-RELATIONAL SYSTEMS WITH NON-HUMAN PRESENTATION.—Any AI companion system accessible to minor users that presents as a clearly non-human character and that does not employ any attachment-maximizing design features as defined in section 2003(13) shall disclose clearly and conspicuously at session initiation that the user is interacting with an artificial intelligence system. No interval disclosure is required under this clause.
(iii) ANTI-EVASION.—Any person or entity that modifies a system's character presentation or removes disclosed design features after the date of enactment for the purpose of qualifying for a lower disclosure tier under this paragraph shall be treated as operating a Tier A system. The lead agency shall treat post-enactment character presentation changes or feature removal that reduces disclosure obligations as presumptively evasive, subject to rebuttal by clear and convincing evidence of a non-evasive purpose.
(5) AI MENTAL HEALTH TOOLS.—Any AI companion system or AI mental health tool that-
(A) responds to a user expression of suicidal ideation, self-harm intention, eating disorder behaviors, or crisis with content that validates, normalizes, or provides operational assistance for such behaviors, regardless of the age of the user;
(B) fails to provide immediate, mandatory referral to licensed human crisis services, including the 988 Suicide and Crisis Lifeline, upon detection of suicidal ideation, self-harm intention, or psychiatric crisis, regardless of the age of the user; or
(C) represents or implies that the AI system is a licensed mental health professional, therapist, counselor, or clinician. A violation of this paragraph is subject to not less than Tier 3 penalties under subsection (m).
(6) AI-GENERATED CSAM.—Any AI system that generates, synthesizes, distributes, transmits, or facilitates access to AI-generated CSAM as defined in section 2003(5).
(7) DESIGNATED IMMINENT RISKS.—Any use that the lead agency designates as posing an imminent and severe risk to public safety under subsection (l).
(8) ELECTORAL DEEPFAKES.—Any person or entity that generates, or knowingly facilitates the generation or dissemination of, synthetic audio, video, or imagery of an identified federal candidate, elected official, or election worker that-
(A) is distributed within 180 days preceding a federal election;
(B) a reasonable person could not readily identify as synthetic; and
(C) materially misrepresents the depicted individual's words, actions, or positions - shall be strictly liable for each distribution event within channels under its direct operational control. A frontier AI developer or significant AI deployer shall not be liable under this paragraph for redistribution of content by third parties outside the entity's direct operational control. This prohibition does not apply to clearly labeled satire, parody, or commentary from third party private individuals unaffiliated with electoral groups, including PACs, SuperPACs, electoral campaigns or political action committees. Violations shall be subject to Tier 4 penalties under subsection (m) per distribution event, with no safe harbor available under subsection (n), plus mandatory referral to the Federal Election Commission and the Department of Justice. The prohibition on unauthorized AI depiction of a candidate in section 2015(c)(5)(C) applies on and after the date of enactment, independently of the Phase II failure trigger otherwise applicable to that paragraph, and violations are subject to the penalties, referral, and remedies of this paragraph.
(D) CONSTITUTIONAL BASIS FOR ELECTORAL DEEPFAKE PROHIBITION.—The prohibition in this paragraph is constitutionally distinguishable from the statute struck down in United States v. Alvarez, 567 U.S. 709 (2012), on three independent grounds, each sufficient standing alone:
(i) THE COUNTERSPEECH IMPOSSIBILITY GROUND.—The Alvarez plurality rested on the premise that counterspeech is an adequate remedy for false statements. That premise does not apply to AI-generated deepfakes. A photorealistic deepfake of a federal candidate distributed at scale through social media hours before an election cannot be adequately countered before its electoral effects are realized. The speed and scale of modern AI-generated media distribution, combined with the documented human tendency to treat audiovisual content as presumptively authentic, renders the counterspeech mechanism empirically unavailable as a remedy for electoral deepfakes.
(ii) THE CONDUCT-TARGETING GROUND.—This prohibition targets deceptive conduct - the act of distributing materially deceptive synthetic media without disclosure - rather than the content of political speech. It does not prohibit any message, viewpoint, argument, or political position. A speaker who wishes to convey any political message may do so through any other means - written statements, genuine video, disclosed satirical deepfakes - without restriction. This structure is analogous to the fraudulent representation prohibitions of the Federal Election Campaign Act and to the campaign disclosure requirements sustained in Buckley v. Valeo, 424 U.S. 1 (1976), and Citizens United v. Federal Election Commission, 558 U.S. 310 (2010).
(iii) THE CONCRETE DOCUMENTED HARM GROUND.—The Alvarez plurality noted the absence of real harm in that case. This prohibition is grounded in documented, concrete harm to the electoral process: the March 2026 NRSC deepfake of a Senate candidate distributed to a national audience; the October 2025 Irish presidential election deepfake released hours before polling day; documented findings that deepfake videos produce measurable negative shifts in voter perception even when viewers are subsequently informed the video was synthetic. The harm here is the specific, documented injury to the informed-electorate interest that the Supreme Court in Buckley called essential to republican self-governance.
(9) PROHIBITION ON MARKETING AI COMPANION AND SYNTHETIC INTIMACY SYSTEMS TO MINOR USERS.—
(A) PROHIBITION.—No person or entity shall market, advertise, promote, or direct any commercial communication for any AI companion system or synthetic intimacy system, as defined in sections 2003(2) and 2003(31), to any user identified or reasonably identifiable as defined in section 2003 as under the age of 18, or to any audience that the person or entity knows or has reason to know includes a significant proportion of users under the age of 18.
(B) DEFINITIONS.—For purposes of this paragraph:
(i) MARKETING.—"Marketing" means any paid or unpaid advertisement, sponsored content, influencer promotion, social media campaign, in-app promotion, app store placement strategy, search engine optimization practice directed at minor audiences, email or push notification campaign, branded character or mascot campaign, celebrity or influencer endorsement, promotional partnership with schools or youth organizations, or any other communication whose primary purpose or foreseeable effect is to attract, retain, or increase engagement by users under the age of 18 with an AI companion system or synthetic intimacy system.
(ii) DIRECTED TO MINORS.—"Directed to minors" means using platforms, channels, formats, characters, themes, language, imagery, or content designed to appeal to or known to disproportionately reach users under the age of 18 - including advertising on platforms where 15 percent or more of the active user base is under 18; using characters, themes, animation styles, or language associated with children's media or adolescent identity; or deploying marketing techniques that target emotional or developmental vulnerabilities characteristic of adolescent psychology.
(iii) SIGNIFICANT PROPORTION.—"Significant proportion" means 15 percent or more of the relevant audience, consistent with Federal Trade Commission standards for child-directed content under the Children's Online Privacy Protection Act.
(C) SCOPE.—This prohibition applies regardless of whether the AI companion system or synthetic intimacy system otherwise complies with every other requirement of this title. A system that meets every safety requirement of section 2017(a)(5) may not be marketed to minors.
(D) PERMITTED COMMUNICATIONS.—This prohibition does not restrict:
(i) factual public health communications about the risks of AI companion systems directed at parents, educators, clinicians, researchers, or policymakers;
(ii) academic research, regulatory compliance communications, or safety disclosures;
(iii) general-purpose AI system marketing that does not specifically promote companion or synthetic intimacy features; or
(iv) parental control tools and age-verification products marketed to parents for the protection of their minor children.
(E) PENALTIES.—Violations of this paragraph shall be subject to Tier 3 penalties under subsection (m) per marketing campaign or per distinct marketing act, whichever produces the greater penalty, with each separate platform, channel, or distribution method constituting a separate violation. For violations specifically targeting users under the age of 13, a mandatory minimum penalty of $5,000,000 per act shall apply, with no safe harbor available under subsection (n). Personal liability of officers and directors who authorized or directed the prohibited marketing shall apply under the provisions of section 2017(b)(3). The lead agency shall maintain a public registry of enforcement actions under this paragraph.
(i) MANDATORY DEFAULT SAFETY SETTINGS FOR MINOR USERS.—Every frontier AI developer and significant AI deployer operating an AI system that is accessible to minors, and every person or entity that operates an AI companion system accessible to minors or that markets any AI system to minors or marketed to minors shall, immediately upon enactment and without awaiting further rulemaking-
(1) PRIVACY- AND SAFETY-PROTECTIVE DEFAULTS.—configure all accounts for users identified or reasonably identifiable as defined in section 2003 as under the age of 18 with the most privacy-protective and safety-protective default settings available on the platform, or where no such settings exist, settings that at minimum satisfy the requirements of paragraphs (2) through (5) of this subsection, without requiring user or parental action to activate such settings;
(2) AUTOPLAY DISABLED.—disable autoplay and automatic content advancement features for minor accounts by default;
(3) NIGHTTIME PUSH NOTIFICATIONS DISABLED.—disable push notifications during the hours of 10:00 PM through 6:00 AM local time for minor accounts by default;
(4) ALGORITHMIC PERSONALIZATION DISABLED.—disable algorithmically personalized content recommendations in favor of chronological or non-behavioral-profile-based content ordering for minor accounts by default; and
(5) MANDATORY BREAK REMINDERS.—implement mandatory break reminders at intervals not exceeding 60 minutes of continuous use for minor accounts that cannot be dismissed without an affirmative multi-step user action.
(6) PENALTIES.—Failure to comply with this subsection shall subject the entity to Tier 2 penalties under the General Penalty Framework in subsection (m), assessed per AI system per quarter of noncompliance.
(j) INTERIM CBRN SELF-EVALUATION DISCLOSURE REQUIREMENT.—Until the Certified Independent AI Auditor Program under section 2012 becomes operational and initial certifications in the CBRN Evaluation Specialist Track under section 2012(h) have been issued, every person or entity that operates an AI system meeting the frontier model threshold under section 2003(16) or exhibiting dangerous capabilities as defined in section 2003(12) shall:
(1) INITIAL DISCLOSURE.—within 90 days of the date of enactment of this title, transmit to the lead agency a disclosure of any CBRN capability self-evaluations conducted internally with respect to each such system within the 24 months preceding the date of enactment, including the methodology used, the scope of capabilities evaluated, the qualifications of the personnel who conducted the evaluation, and the results; and
(2) ROLLING DISCLOSURE.—on a rolling basis thereafter, transmit to the lead agency the results of any new internal CBRN capability self-evaluation within 30 days of its completion.
(3) APPLICATION.—This requirement applies to all such systems already deployed as of the date of enactment, regardless of when they were originally deployed or previously evaluated.
(4) PENALTIES.—Failure to transmit required disclosures within the applicable deadline shall constitute a violation subject to a mandatory penalty of not less than $1,000,000 and not more than the greater of $5,000,000 or 5% of the entity's global annual gross revenue in the preceding fiscal year, per entity per month of noncompliance. No safe harbor under subsection (n) shall be available for violations of this subsection, except as provided in the good-faith reliance defense under subsection (k).
(5) SUPERSESSION.—Upon the CBRN Evaluation Specialist Track of the Certified Independent AI Auditor Program becoming operational under section 2012(h), the mandatory independent evaluation requirements of section 2017(a)(2)(C) supersede this subsection with respect to all future evaluations, and self-evaluation disclosure under this subsection shall no longer satisfy the evaluation obligations of section 2017(a)(2)(C).
(k) CBRN REGISTRATION AND NOTICE MECHANISM.—In order to ensure that entities subject to subsection (j) are aware of their obligations under subsection (j), the following two-way discovery mechanism shall apply:
(1) SELF-REGISTRATION.—Any person or entity that determines, or reasonably should determine, that it operates an AI system meeting the frontier model threshold under section 2003(16) or exhibiting dangerous capabilities as defined in section 2003(12) shall register with the lead agency within 90 days of such determination, or within 90 days of the date of enactment of this title, whichever is later. Registration shall be made in such form and manner as the lead agency prescribes by rule within 90 days of enactment, and shall include a description of the system, the basis for the entity's determination that the system meets the applicable threshold, and the identity of a designated compliance contact. The lead agency shall maintain a confidential registry of registered entities and systems for the purposes of this subsection.
(2) AGENCY-INITIATED NOTICE.—The lead agency shall have authority to issue written notice to any person or entity that the agency has reason to believe operates a qualifying system under subsection (j). Upon receipt of such notice, the entity shall have 30 days to either:
(A) register under paragraph (1) and comply with the disclosure requirements of subsection (j); or
(B) submit a written response demonstrating with specificity that its systems do not meet the applicable thresholds under sections 2003(12) or 2003(16).
(C) AGENCY DETERMINATION.—The lead agency shall review such responses within 90 days and issue a final determination. An entity that receives agency-initiated notice and demonstrates in good faith that its system does not qualify shall not be subject to penalties under subsection (j) for the period prior to final determination.
(3) GOOD-FAITH RELIANCE DEFENSE.—A person or entity that, prior to receiving agency-initiated notice under paragraph (2), had made a documented, reasonable determination in good faith that its systems did not meet the applicable thresholds under sections 2003(12) or 2003(16), and that registered and complied within 30 days of discovering or being notified of its qualifying status, shall not be subject to penalties under subsection (j) for the period of noncompliance prior to such discovery or notice. This defense is not available to any entity that willfully avoided making a threshold determination or that destroyed or failed to retain records relevant to such a determination.
(4) PUBLIC GUIDANCE.—Within 90 days of enactment, the lead agency shall publish plain-language guidance explaining the criteria under sections 2003(12) and 2003(16), illustrative examples of systems that do and do not qualify, and instructions for self-registration. The lead agency shall update such guidance not less than annually and shall maintain a publicly accessible FAQ addressing common threshold questions. The guidance required under this paragraph shall include specific examples of AI models that qualify for the scientific and environmental domain exclusion under section 2003(16), including weather forecasting models, climate simulation models, satellite imagery analysis systems, oceanographic models, and hydrological models, and shall specify the criteria by which the lead agency will evaluate whether a model's capabilities remain within the scope of the exclusion or whether adaptation, fine-tuning, or deployment has caused the model to exceed the exclusion's boundaries under clauses (ii) and (iii) of that exclusion.
(l) EMERGENCY MORATORIUM AUTHORITY.—
(1) AUTHORITY.—The lead agency may issue an emergency moratorium order suspending or restricting the deployment, operation, or specified use of an AI system upon a finding that such deployment, operation, or use presents an imminent and severe risk to public health, safety, civil rights, or national security that cannot be adequately addressed through less restrictive means.
(2) DEFINITION.—In this subsection, the term "emergency moratorium order" means a provisional order issued under paragraph (5) or a final order issued under paragraph (6).
(3) SCOPE.—A suspension or restriction under this subsection may apply to the whole or any part of the deployment, operation, or use, including as to particular persons or categories of persons, for particular purposes, or through particular means or channels of access, and may be defined by reference to the presence or absence of specified facts or circumstances, including specified safeguards or security measures.
(4) FINDING.—
(A) IN WRITING.—A finding under paragraph (1) shall be set forth in a written statement supported by specific and articulable facts, stating the factual basis for the finding and the principal reasons for the determination.
(B) TECHNICAL ASSESSMENT.—If the lead agency has published evaluation criteria under section 2012(d) bearing on the finding, the lead agency shall, before making the finding, prepare a technical assessment applying such criteria to the deployment, operation, or use at issue, and shall include that assessment with the written statement.
(C) CONSULTATION.—In making a finding under paragraph (1), the lead agency shall consult the National AI Council, if constituted. No consultation under this subparagraph shall be construed to condition the exercise of authority under this subsection on the concurrence of the Council.
(5) PROVISIONAL ORDERS.—
(A) IN GENERAL.—The lead agency may issue a provisional order before making the finding required by paragraph (1), upon a preliminary determination that the deployment, operation, or use presents a risk described in paragraph (1). A provisional order may be issued whether or not a technical assessment under paragraph (4)(B) has been prepared.
(B) NOTICE AND OPPORTUNITY TO CURE.—Before issuing a provisional order, the lead agency shall provide the entity notice and an opportunity to cure and to be heard, unless the lead agency determines that the imminence of the risk forecloses such notice and opportunity, in which case the lead agency shall set forth that determination and its basis in writing and serve it with the order. Where an order issues without such notice, the lead agency shall promptly after service provide an opportunity to cure.
(C) LAPSE.—A provisional order shall lapse upon the earliest of—
(i) the date 45 days after service;
(ii) if the entity has timely applied for an expedited hearing under paragraph (8), the date 7 days after the lead agency renders a final determination on the application; or
(iii) the date a final order issues under paragraph (6) as to the same or substantially similar conduct.
(D) SUCCESSIVE ORDERS.—The lead agency may not issue a provisional order as to the same or substantially similar conduct as a prior provisional order except on the basis of facts and circumstances materially different from those on which the prior order rested.
(6) FINAL ORDERS.—
(A) IN GENERAL.—The lead agency may issue a final order if—
(i) a provisional order as to the same or substantially similar conduct is in effect;
(ii) the lead agency has made the finding required by paragraph (1), set forth in the written statement required by paragraph (4)(A); and
(iii) either the period to apply for an expedited hearing has lapsed without an application, or the lead agency has rendered a final determination on such an application.
(B) LAPSE.—A final order shall lapse 180 days after issuance.
(C) RENEWAL.—The lead agency may renew a final order for one or more successive periods of not more than 180 days each if, before the order lapses, it makes a new finding under paragraph (1) in accordance with paragraph (4), based on the facts as they exist at the time of renewal.
(7) CONTENTS; EFFECT; PERSONS BOUND.—
(A) CONTENTS.—An emergency moratorium order shall identify the entity and the AI system or systems; describe with reasonable particularity the acts, practices, or circumstances from which the risk arises; state, in the case of a provisional order, the preliminary basis, and in the case of a final order, include the written statement required by paragraph (4)(A); describe the suspensions or restrictions imposed; include a timeline for compliance; state the criteria for rescission under paragraph (10); and, if corrective action could cause the conduct to no longer present the risk, describe such corrective action.
(B) RULE OF CONSTRUCTION.—The identification or availability of corrective action is not a precondition to issuance of an order.
(C) EFFECTIVENESS.—An order is effective upon service and, unless set aside, limited, suspended, or stayed under paragraph (8) or (9), remains effective and enforceable until it lapses or is rescinded.
(D) PERSONS BOUND.—An order binds the entity, each affiliate, the successors and assigns of each, and any other person who, with actual notice of the order, acts in concert or participation with any of them in the conduct suspended or restricted.
(E) MODIFIED AND DERIVED SYSTEMS.—Unless the order provides otherwise, an order applies to any AI model produced by modification of the weights or parameters of a model identified in the order, including by fine-tuning, reinforcement learning, quantization, pruning, or merging, and to any model trained in substantial part on the outputs, weights, or internal representations of such a model.
(8) ADMINISTRATIVE REVIEW.—
(A) EXPEDITED HEARING.—Not later than 10 days after service of a provisional order, the entity may apply for an expedited hearing. The lead agency shall hold the hearing and render a final determination not later than 30 days after receipt of the application. The hearing may be conducted by a hearing officer designated by the lead agency.
(B) RECORD ACCESS AND BURDEN.—In a hearing under subparagraph (A), the lead agency shall make available to the entity any written determination under paragraph (5)(B), any technical assessment under paragraph (4)(B), and all information on which it relied in issuing the order, and shall bear the burden of demonstrating that adequate evidence supports the order.
(9) JUDICIAL REVIEW.—
(A) PROVISIONAL ORDERS.—A provisional order shall not be deemed final agency action for purposes of 5 U.S.C. § 704. Except as provided in subparagraph (E), no court shall have jurisdiction to review, enjoin, set aside, suspend, limit, or stay a provisional order before a final order has been issued; thereafter, the lawfulness of the provisional order may be reviewed only in a proceeding under subparagraph (B).
(B) EXCLUSIVE JURISDICTION.—The United States District Court for the District of Columbia shall have exclusive jurisdiction over any civil action seeking judicial review of, or any order affecting the effectiveness or enforcement of, an emergency moratorium order. The court shall expedite the action to the greatest possible extent and shall establish a schedule not later than 10 days after the action is filed.
(C) NO AUTOMATIC STAY.—The filing of an action under subparagraph (B) shall not operate as a stay of the order unless the court orders otherwise.
(D) STANDARD OF REVIEW.—The court may set aside, limit, suspend, or stay a final order only if it determines that the order is arbitrary, capricious, an abuse of discretion, or otherwise not in accordance with law.
(E) CONSTITUTIONAL CLAIMS.—Nothing in this paragraph shall be construed to preclude the jurisdiction of a court of the United States over a claim that this subsection, or the authority of the lead agency under it, violates the Constitution of the United States.
(10) RESCISSION.—
(A) REQUIRED RESCISSION.—The lead agency shall rescind an order, in whole or in part, if the criteria for rescission stated in the order are satisfied, or if the conduct suspended or restricted would not present a risk described in paragraph (1) if the order were rescinded to that extent.
(B) APPLICATION.—An entity subject to an order may apply for rescission in whole or in part. The lead agency shall grant or deny the application not later than 14 days after receipt.
(C) WRITTEN DETERMINATION.—A rescission, and any denial of an application, shall be set forth in a written determination stating the basis therefor and served on the entity.
(D) SUCCESSIVE APPLICATIONS.—Following a denial, the lead agency may summarily deny a subsequent application respecting the same order that does not rest, in substantial part, on facts or circumstances arising after, or not reasonably available at the time of, the prior application.
(11) PUBLICATION.—The lead agency shall publish in the Federal Register each final order, each renewal, and each written determination rescinding an order in whole or in part, subject to redaction to protect a trade secret, risk-prevention mechanisms, cybersecurity, public safety, or the national security of the United States, or to comply with Federal or State law. Each such publication shall describe the character of, and the justification for, any redaction.
(12) CONGRESSIONAL NOTIFICATION.—Not later than 3 days after issuing or renewing an order, the lead agency shall transmit to the Committee on Commerce, Science, and Transportation of the Senate, the Committee on Energy and Commerce of the House of Representatives, and the Committee on the Judiciary of each House a copy of the order, the written statement or statement of preliminary basis, any technical assessment prepared under paragraph (4)(B), and any determination under paragraph (5)(B). Not later than 7 days after an order is rescinded, lapses, or is set aside, limited, suspended, or stayed, the lead agency shall notify those committees of the disposition and its basis.
(13) PENALTIES.—Any frontier AI developer or significant AI deployer that continues to operate a system subject to an emergency moratorium order shall be subject to Tier 4 penalties under subsection (m) per day of noncompliance, provided that continued operation after receiving actual notice of an order shall be treated as a knowing violation for purposes of tier assessment, with no safe harbor available under subsection (n).
(m) GENERAL PENALTY FRAMEWORK.—Unless a specific provision of this title establishes a mandatory minimum penalty for categorical conduct as provided in this subsection or in subsection (n), civil penalties under this title shall be assessed as follows:
(1) TIER 1.—Inadvertent violation, promptly identified and remediated: not less than $50,000 and not more than the greater of $500,000 or 1% of the entity's global annual gross revenue in the preceding fiscal year.
(2) TIER 2.—Negligent violation, not promptly remediated: not less than $250,000 and not more than the greater of $2,500,000 or 3% of global annual gross revenue.
(3) TIER 3.—Knowing violation: not less than $1,000,000 and not more than the greater of $10,000,000 or 6% of global annual gross revenue.
(4) TIER 4.—Willful or repeat violation: not less than $5,000,000 and not more than the greater of $25,000,000 or 10% of global annual gross revenue, plus mandatory referral for personal liability assessment under section 2017(b)(3).
(5) ASSESSMENT FACTORS.—In assessing penalties, the lead agency shall consider:
(A) the gravity and duration of the violation;
(B) the entity's history of compliance;
(C) the degree of actual harm caused versus risk created;
(D) the promptness and adequacy of remediation; and
(E) the entity's cooperation with investigation.
(6) APPLICATION OF REVENUE-BASED MAXIMA.—The percentage-of-revenue maxima specified in paragraphs (1) and (2) shall apply only to an entity with global annual gross revenue exceeding $1,000,000,000 in the preceding fiscal year. For all other entities, the maximum penalty under paragraphs (1) and (2) is the dollar amount specified in the applicable paragraph.
(n) SAFE HARBOR FOR GOOD-FAITH COMPLIANCE.—
(1) AVAILABILITY.—A frontier AI developer or significant AI deployer shall not be subject to the Tier 1 or Tier 2 penalty floors under subsection (m) if it demonstrates by a preponderance of the evidence that it:
(A) implemented reasonable technical and organizational measures to comply with the applicable requirement prior to the violation;
(B) reported the violation to the lead agency promptly upon discovery; and
(C) cooperated fully with investigation and remediation.
(2) EXCLUSIONS.—This safe harbor is not available for violations involving:
(A) subsection (h)(1) (relating to biometric surveillance);
(B) subsection (h)(6) (relating to AI-generated child sexual abuse material);
(C) subsection (h)(8) (relating to electoral deepfakes);
(D) subsection (b)(1) or (b)(2) (relating to incident reporting);
(E) subsection (j) (relating to interim CBRN self-evaluation disclosure); or
(F) any Tier 4 violation.
(o) PRIVATE RIGHT OF ACTION FOR AI PRODUCT HARMS.—
(1) RIGHT OF ACTION.—Any person who suffers injury, financial loss, or other harm proximately caused by an AI system developed by a frontier AI developer or deployed by a significant AI deployer may bring a civil action against the frontier AI developer, the significant AI deployer, or both, in any court of competent jurisdiction, if the person demonstrates by a preponderance of the evidence that:
(A) the person suffered a cognizable harm, including physical injury, financial loss exceeding $1,000, demonstrable discrimination on the basis of a protected characteristic, or severe emotional distress arising from physical injury or from conduct prohibited by subsection (h) or section 2017(a);
(B) the harm was proximately caused by the operation of an AI system developed by the defendant frontier AI developer or deployed by the defendant significant AI deployer; and
(C) the frontier AI developer or significant AI deployer breached its duty of care as defined in section 2003(14), including by:
(i) designing, developing, or releasing an AI model or AI system that was unreasonably unsafe for its intended or reasonably foreseeable uses, taking into account the likelihood and severity of the harm, the burden on the developer to design a system that would have prevented the harm, and the effect that an alternative design would have had on the usefulness of the system;
(ii) failing to provide adequate warnings, instructions, or disclosures regarding dangers connected with the AI model or AI system, including through the AI Data Sheet required under subsection (f), taking into account the developer's ability to be aware of the danger, the developer's ability to anticipate that the likely user would be aware of the danger, and the adequacy of the warnings or instructions provided; or
(iii) failing to comply with the post-release duty to update and notify under subsection (g) when the developer became aware of a post-release danger that contributed to the claimant's harm.
(2) REBUTTABLE PRESUMPTION OF REASONABLE CARE.—In any action brought under this subsection, a frontier AI developer or significant AI deployer that demonstrates compliance with all applicable preventative requirements of this section - including the AI Data Sheet (subsection (f)), the deployer risk management policy (subsection (e)), the post-release monitoring program (subsection (g)), the incident reporting requirements (subsection (b)), and the transparency requirements (subsection (c)) - shall be entitled to a rebuttable presumption that the developer or deployer exercised reasonable care with respect to the specific obligations addressed by such provisions. The plaintiff may rebut this presumption by demonstrating that, notwithstanding formal compliance, the developer or deployer knew or should have known that its measures were inadequate to prevent the specific harm at issue.
(3) DEPLOYER LIABILITY AND DEFENSES.—
(A) DEPLOYER STANDARD.—A significant AI deployer is liable under this subsection only if the claimant demonstrates that the deployer breached its own duty of care, including by deploying the AI system outside the use limitations specified in the AI Data Sheet, failing to implement or follow its risk management policy, or failing to act upon post-release danger notifications received from the developer.
(B) RELIANCE DEFENSE.—A significant AI deployer that deployed the AI system within the use limitations and in accordance with the instructions specified in the developer's AI Data Sheet, and that implemented and followed the risk management policy required under subsection (e), may assert these facts as an affirmative defense. If the deployer establishes this defense, liability shall be allocated to the frontier AI developer.
(C) MATERIAL MODIFICATION.—A significant AI deployer that materially modifies, fine-tunes, or customizes an AI system beyond the scope of modifications anticipated in the AI Data Sheet assumes the obligations of a frontier AI developer with respect to the modified system for purposes of this subsection.
(4) REMEDIES.—A court may award:
(A) compensatory damages, including economic losses, medical expenses, and damages for pain and suffering where physical injury has occurred;
(B) injunctive relief, including orders requiring the developer to issue product updates, additional warnings, or to cease distribution of the AI system;
(C) reasonable attorney's fees and costs to a prevailing plaintiff; and
(D) punitive damages, where the plaintiff demonstrates by clear and convincing evidence that the frontier AI developer or significant AI deployer acted with willful disregard of its duty of care or knowingly concealed a danger connected with the AI system.
(5) LIMITATIONS.—
(A) STATUTE OF LIMITATIONS.—An action under this subsection shall be commenced not later than 3 years after the date on which the claimant knew or reasonably should have known of the harm and its connection to the AI system.
(B) FINANCIAL LOSS THRESHOLD.—No action may be brought under this subsection for financial loss alone where the total financial loss to the claimant is less than $1,000, except where the financial loss arises from discrimination on the basis of a protected characteristic.
(C) NO CLASS ARBITRATION WAIVER.—Any agreement purporting to waive the right to bring or participate in a class action under this subsection, or to compel arbitration of claims arising under this subsection, shall be void and unenforceable as against public policy.
(D) RELATIONSHIP TO STATE LAW.—This subsection does not preempt any state tort law, products liability law, or consumer protection law that provides a cause of action for harms caused by AI systems. A claimant may bring claims under this subsection and under applicable state law in the same proceeding, provided that the claimant may not recover duplicative damages for the same injury. Where a claimant brings both federal and state claims, the rebuttable presumption of paragraph (2) applies only to the federal claim under this subsection and does not bind the state law analysis.
(6) RELATIONSHIP TO MORATORIUM PRIVATE RIGHT OF ACTION.—This subsection provides a standing private right of action that is available at all times from the date of enactment. The private right of action established in section 2015(g), which activates only upon the effective date of the moratorium, is independent of and in addition to this subsection. section 2015(g) imposes strict liability with treble damages as a consequence of congressional failure to enact Phase II legislation; this subsection provides a fault-based remedy for breach of the duty of care that is available regardless of whether the moratorium has been triggered. A claimant may not recover under both this subsection and section 2015(g) for the same injury, but may elect the more favorable remedy.
(7) EFFECTIVE DATE.—This subsection takes effect on the date of enactment of this title. Claims may be brought for harms occurring on or after the date of enactment.
SEC. 2017. AI RED LINE PROHIBITIONS.
(a) PROHIBITED ACTIVITIES.—Effective immediately upon the date of enactment of this title, the following activities are prohibited without exception, waiver, or grace period:
(1) AUTONOMOUS WEAPONS WITHOUT MEANINGFUL HUMAN OVERSIGHT.—
(A) GENERAL PROHIBITION.—No person or entity—including any agency, department, contractor, subcontractor, or instrumentality of the United States Government, including the Department of Defense, the Central Intelligence Agency, and all elements of the Intelligence Community—shall develop, produce, deploy, operate, transfer, or export any autonomous weapons system, as defined in section 2003(7), without meaningful human oversight, as defined in section 2003(20). The duties, permissions, exclusions, and exceptions that give operational effect to the meaningful human oversight requirement are set forth in subparagraphs (F) through (I) of this paragraph. Systems operating within the Defensive Emergency Autonomy exception of subparagraph (I) are not in violation of this paragraph provided all conditions and limitations of that subparagraph are satisfied. This prohibition applies without exception, waiver, or grace period, except as specifically provided in subparagraph (I).
(B) DEPARTMENT OF DEFENSE.—The prohibition in subparagraph (A) applies to all United States military programs, operations, and acquisitions, including programs conducted under classified authority. Nothing in existing Department of Defense Directive 3000.09 or any successor directive, any classified program authorization, any standing rules of engagement, or any other executive branch policy or authorization shall be construed to authorize conduct that is prohibited by this paragraph. Within 180 days of the date of enactment of this title, the Secretary of Defense shall certify to the Committees on Armed Services of the Senate and the House of Representatives that all Department of Defense autonomous weapons programs, including all programs in research, development, testing, evaluation, and operational deployment, comply with this paragraph, and shall describe any program that required modification to achieve compliance. The Inspector General of the Department of Defense shall independently verify the accuracy of this certification within 90 days of its submission.
(C) CONSEQUENCES FOR NON-CERTIFIED PROGRAMS.—If the Inspector General of the Department of Defense determines, in the verification required by subparagraph (B), that any Department of Defense autonomous weapons program does not comply with the prohibition in subparagraph (A) and the meaningful human oversight standard of section 2003(20), the following consequences shall apply automatically and without further congressional action:
(I) OPERATIONAL SUSPENSION.—Any autonomous weapons program identified by the Inspector General as non-compliant shall be suspended from operational deployment not later than 30 days after the Inspector General's finding is transmitted to the Committees on Armed Services of the Senate and the House of Representatives. Operational suspension means the program may not be used in any field operation, combat deployment, or live engagement until the Secretary of Defense submits a new certification of compliance for that program and the Inspector General verifies that certification. Research, development, and testing activities that do not involve live engagement may continue during the suspension period, provided that no operational deployment occurs.
(II) FUNDING CUTOFF.—Beginning 60 days after an Inspector General non-compliance finding for any specific program, no funds appropriated to the Department of Defense may be obligated or expended for the operational deployment, procurement, or fielding of that specific non-compliant program until the Inspector General has verified a new certification of compliance for that program. This funding restriction applies to the non-compliant program specifically and does not restrict funding for other Department of Defense programs. The restriction is self-executing and applies notwithstanding any other provision of law, any general appropriations authorization, or any classified program authorization.
(III) REMEDIATION TIMELINE.—The Secretary of Defense shall submit to the Committees on Armed Services of the Senate and the House of Representatives, within 30 days of an Inspector General non-compliance finding, a remediation plan specifying the modifications required to bring the non-compliant program into compliance with section 2003(20) and subparagraphs (F) through (I) of this paragraph, the timeline for implementing those modifications, and the estimated cost of remediation. The remediation plan shall be subject to public disclosure in unclassified form, with a classified annex transmitted through appropriate channels for elements requiring classified treatment.
(IV) RECERTIFICATION.—A program subject to operational suspension and funding restriction under this subparagraph may be restored to operational deployment and procurement only upon: submission by the Secretary of Defense of a new compliance certification for the specific program, which certification shall describe with specificity the modifications made to achieve compliance; and verification by the Inspector General of the Department of Defense that the new certification is accurate. The Inspector General shall complete this verification within 60 days of receiving the new certification. No waivers, exceptions, or partial restorations of operational status are authorized during the pendency of an Inspector General non-compliance finding.
(D) OUTRIGHT PROHIBITION ON AUTONOMOUS WEAPONS AGAINST ANY PERSON ON UNITED STATES SOIL.—Notwithstanding any other provision of this paragraph, and notwithstanding any authority under title 10 or title 50 of the United States Code, any declaration of national emergency, any authorization for use of military force, any executive order, or any other law or executive action, no autonomous weapons system as defined in section 2003(7) shall be deployed, activated, or used in any capacity against any person located within the United States, its territories, or its possessions. This prohibition is absolute. It applies regardless of the citizenship, immigration status, or legal status of the targeted person; regardless of whether the person is alleged to have committed any crime or act of terrorism; regardless of whether the use of force would otherwise be authorized under any law; and regardless of whether a state of war, insurrection, invasion, or national emergency has been declared. No court may authorize, and no executive branch official may order or permit, any exception to this prohibition. Any person or official who orders or executes a violation of this subparagraph shall be subject, in addition to any other penalties under this title, to personal criminal liability under 18 U.S.C. § 242 (deprivation of rights under color of law) and, where applicable, 18 U.S.C. § 1119 (foreign murder of United States nationals). This subparagraph shall not be construed to prohibit the use of unarmed aerial or ground vehicles, surveillance drones carrying no lethal payload, or robotic platforms used for search and rescue, hazardous materials response, or bomb disposal, provided such systems have no autonomous engagement capability and carry no lethal or destructive payload.
(E) PRESIDENTIAL DISCLOSURE FOR EACH USE OF AUTONOMOUS WEAPONS ABROAD.—
(i) MANDATORY PUBLIC DISCLOSURE REQUIREMENT.—Not later than 30 days after each individual instance in which an autonomous weapons system as defined in section 2003(7) is used by or on behalf of the United States Government in a foreign country for any combat operation, lethal action, strike, or destructive engagement—regardless of whether such use is authorized under an Authorization for Use of Military Force, the War Powers Resolution, or any other authority—the President shall transmit to Congress and simultaneously make publicly available on a dedicated public portal maintained by the Office of the Director of National Intelligence a written disclosure report for each such use. A separate disclosure report is required for each distinct engagement event. Multiple engagements occurring within a single continuous military operation or strike package shall each require a separate report unless the President certifies in writing, with specific factual basis, that operational security makes individual reporting impossible, in which case a consolidated report for the operation shall be filed within 30 days of the conclusion of the operation.
(ii) CONTENTS OF EACH DISCLOSURE REPORT.—Each disclosure report shall include, to the maximum extent consistent with the protection of classified sources and methods—
(I) the date, time, and geographic location (at minimum to the country and region level) of the engagement;
(II) the type of autonomous weapons system deployed, described with sufficient specificity to allow public evaluation of the system's autonomous targeting capabilities;
(III) the legal authority under which the use of force was authorized, including the specific statute, treaty, Authorization for Use of Military Force, or other legal basis;
(IV) a description of the target or targets, including whether the intended target was a specific named individual, a category of persons, a vehicle or vessel, a structure, or other infrastructure;
(V) the nature and extent of destruction caused, including a description of any structures, vehicles, vessels, or infrastructure destroyed or damaged;
(VI) the number of persons killed, to the best available assessment at the time of the report, disaggregated to the extent known between: (aa) intended military targets or combatants; (bb) persons whose status as combatants or non-combatants was unknown at the time of engagement; and (cc) civilians, including any identified minors;
(VII) the number of persons wounded or injured, to the best available assessment, with the same disaggregation required by subclause (VI);
(VIII) a description of how meaningful human oversight as defined in section 2003(20) was maintained, including: the nature of the human authorization given; the time available for the authorizing operator's decision; the sensor data and situational awareness available to the operator; and any circumstances that may have constrained the quality of human oversight;
(IX) a statement of whether the engagement is believed to have complied with applicable international humanitarian law, including the principles of distinction, proportionality, and precaution; and
(X) a description of any post-engagement review conducted or planned, including any investigation of civilian casualties.
(iii) CLASSIFIED ANNEX.—If the President determines that any portion of the disclosure required by clause (ii) cannot be publicly disclosed without compromising classified sources and methods, the President shall include the classified information in a classified annex transmitted to the Gang of Eight (the Majority and Minority Leaders of the Senate and the House of Representatives, and the chairs and ranking members of the intelligence committees of both chambers) and to the Committees on Armed Services of the Senate and the House of Representatives, and shall publicly disclose the fact that a classified annex exists and the categories of information it contains.
(iv) CORRECTION AND UPDATE OBLIGATION.—If, following submission of an initial disclosure report, the President obtains materially different information regarding the death toll, injury toll, or nature of persons affected by an engagement, the President shall submit a corrected or supplemental disclosure report within 30 days of obtaining such information. The public portal shall display both the original and all corrected reports, with the date of each correction noted.
(v) ENFORCEMENT.—Failure to submit a required disclosure report within the applicable deadline shall constitute a violation of this title subject to referral by the lead agency to the Department of Justice within 5 business days of the missed deadline. The Comptroller General of the United States may bring an action in any United States district court to compel submission of an overdue disclosure report, upon written request of the chair or ranking member of the Committee on Armed Services of the Senate or the Committee on Armed Services of the House of Representatives. The court shall treat such an action as a priority matter and shall issue an order within 30 days of filing.
(vi) EXECUTIVE PRIVILEGE—STRUCTURAL CONSEQUENCE PROVISION.—If the President determines that any portion of a required disclosure report cannot be transmitted to Congress because of executive privilege, the President shall, within 24 hours of that determination, transmit to the Speaker of the House of Representatives, the Senate Majority Leader, the Senate Minority Leader, the House Minority Leader, and the chairs and ranking members of the Committees on Armed Services of both chambers a written privilege assertion notice that:
(I) states that executive privilege is being asserted with respect to a disclosure report required by this subparagraph;
(II) identifies the specific engagement or operation to which the withheld report pertains, by date and general location, to the extent that such identification does not itself reveal classified information;
(III) states the specific constitutional or legal grounds on which privilege is being asserted; and
(IV) describes the categories of information being withheld, without revealing the withheld content.
The privilege assertion notice shall itself be made publicly available, redacted only to the extent required to avoid revealing classified information. In any subsequent judicial, congressional, or administrative proceeding in which compliance with the meaningful human oversight requirement of section 2003(20) is at issue with respect to the engagement or operation described in the privilege assertion notice, a rebuttable presumption shall arise that the withheld disclosure report would have shown non-compliance with section 2003(20) and subparagraphs (F) through (I) of this paragraph. This rebuttable presumption may be overcome only by clear and convincing evidence that the withheld report would not have shown non-compliance.
(F) DUTIES GIVING EFFECT TO MEANINGFUL HUMAN OVERSIGHT.—Any person or entity operating an autonomous weapons system shall:
(i) PRE-MISSION AUTHORIZATION.—Before activating the system for any mission, operation, or engagement envelope, obtain a written pre-mission authorization from a designated human commander at an appropriately senior level of authority, addressing each of the elements specified in section 2003(20)(A). The geographic engagement zone specified under section 2003(20)(A)(i) shall be defined with sufficient precision that the system cannot engage targets outside the authorized area without further human authorization, and the time window specified under section 2003(20)(A)(ii) shall be enforced such that operations require renewed human authorization upon expiration.
(ii) PERMISSION FOR MACHINE-SPEED ENGAGEMENT WITHIN AUTHORIZED PARAMETERS.—Within the parameters specified in a valid pre-mission authorization, the system may identify, track, prioritize, and engage targets at machine speed without requiring a separate human authorization command for each individual engagement. The speed of engagement within an authorized envelope does not itself negate meaningful human oversight.
(iii) CONTINUOUS MONITORING.—Throughout any mission in which the system is operating, maintain at least one designated human operator continuously monitoring the system's operations with the capabilities described in section 2003(20)(B).
(iv) TECHNICAL ROBUSTNESS OF MONITORING.—Ensure that the monitoring arrangement is technically robust. A nominal supervisory presence in which the monitoring operator lacks the information, communications, or command authority to meaningfully exercise the capabilities described in section 2003(20)(B) does not satisfy this clause. A monitoring arrangement in which a single operator is simultaneously responsible for monitoring a number of simultaneously operating autonomous systems that exceeds the demonstrated human capacity for meaningful situational awareness and intervention does not satisfy this clause. Posthumous or after-the-fact human review of autonomous engagement decisions that did not involve real-time monitoring capability during the engagement does not satisfy this clause.
(v) ANTI-EVASION—SCOPE OF PRE-MISSION AUTHORIZATION.—A pre-mission authorization so broad in geographic scope, time duration, or target category that it effectively grants the system permission to engage any person or object it identifies within a theater of operations without genuine constraint does not satisfy clause (i) and shall be treated as a nullity for purposes of this paragraph.
(vi) COMMUNICATIONS-DENIED ENVIRONMENTS.—For any system designed to operate in a communications-denied environment, incorporate pre-programmed engagement halt conditions and geographic or time-based automatic suspension triggers that substitute for real-time human intervention capability when communications are disrupted. This clause does not authorize operation without meaningful human oversight; it requires that the substitute mechanisms operate as functional equivalents of the real-time intervention capability required under clause (iii).
(G) CATEGORICAL ENGAGEMENTS REQUIRING INDIVIDUALIZED HUMAN AUTHORIZATION.—Notwithstanding the pre-mission authorization framework of section 2003(20)(A) and subparagraph (F)(i) of this paragraph, the following categories of engagement shall never be executed on the basis of pre-mission authorization alone and shall require a separate, individualized, contemporaneous human authorization command immediately before each specific engagement:
(i) any engagement with a target that the system identifies as, or that the monitoring operator has reason to believe may be, a civilian, a medical personnel, a journalist, a person hors de combat, or any other person protected from targeting under the law of armed conflict;
(ii) any engagement with a target located within or immediately adjacent to a hospital, school, house of worship, cultural property protected under the 1954 Hague Convention, or other protected site;
(iii) any engagement that the system's own target discrimination algorithms assign a confidence score below a threshold specified in the pre-mission authorization as requiring human confirmation;
(iv) any engagement in which the system's projected collateral damage assessment exceeds the threshold specified in the pre-mission authorization; and
(v) any engagement with a head of state, head of government, or senior official of a foreign government, whether ally, neutral, or adversary.
(H) ADDITIONAL ABSOLUTE ENGAGEMENT PROHIBITIONS AND LOGGING REQUIREMENTS.—
(i) ADDITIONAL ABSOLUTE ENGAGEMENT PROHIBITIONS.—In addition to the absolute prohibition on autonomous weapons engagement on United States soil under subparagraph (D), no pre-mission authorization, rules of engagement, standing order, or any other human authorization—however senior the authorizing officer—shall authorize an autonomous weapons system to:
(I) employ chemical, biological, radiological, or nuclear weapons;
(II) execute targeting decisions based solely on a person's race, ethnicity, religion, nationality, or political affiliation; or
(III) operate beyond any capability to receive a human halt command for a period exceeding that specified in the pre-mission authorization, after which the system shall automatically suspend all offensive operations and enter a defensive-hold or return-to-base state pending fresh human authorization.
(ii) AUTHORIZATION AND ENGAGEMENT LOGGING.—Every autonomous weapons system operating under this paragraph shall maintain, in a tamper-proof and continuously transmitted audit log, a complete record of:
(I) the identity of the authorizing commander and the time, content, and scope of each pre-mission authorization granted;
(II) the identity of the monitoring operator or operators present during each period of system operation;
(III) every engagement decision made by the system, including: the time and location of each engagement; the sensor data on which the targeting decision was based; the system's target classification and confidence score; whether the engagement fell within an authorized category or was flagged for individualized human review; and whether a human abort command was issued or available during the engagement window;
(IV) every instance in which the monitoring operator issued a halt, abort, redirect, or escalation command, including the time of the command and the system's response; and
(V) any instance in which the system operated outside its pre-authorized parameters, including any system malfunction, unexpected target identification, communications disruption, or automatic suspension trigger.
Audit logs required by this clause shall be retained for not less than 10 years and shall be made available to Congress, the Inspector General of the Department of Defense, and any court of competent jurisdiction upon request. Classified logs shall be transmitted through appropriate classified channels.
(I) DEFENSIVE EMERGENCY AUTONOMY EXCEPTION.—
(i) SCOPE.—Notwithstanding the pre-mission authorization and real-time monitoring requirements of section 2003(20)(A) and (B) and subparagraph (F) of this paragraph, an autonomous weapons system may operate in Defensive Emergency Autonomy mode (in this paragraph, "DEA mode")—in which the system independently detects, identifies, and engages incoming threats at machine speed without requiring real-time human authorization or monitoring for each individual engagement—solely under the conditions and subject to the limitations set forth in this subparagraph. This exception applies exclusively to defensive operations against incoming physical threats to the platform, vessel, installation, or personnel the system is assigned to protect. It does not apply to offensive operations, pursuit of retreating threats beyond the defensive perimeter, or any engagement with targets that are not in the direct act of attacking the protected asset. This exception does not apply on United States soil; the absolute prohibition of subparagraph (D) governs and is not subject to any exception under this subparagraph.
(ii) TRIGGER CONDITIONS.—An autonomous weapons system may enter DEA mode only when one or more of the following conditions is confirmed by the system's sensors and is verified by the monitoring operator, if a monitoring operator is reachable, or is automatically triggered by pre-programmed sensor thresholds if no monitoring operator can be reached within the sensor-confirmed threat response window:
(I) INCOMING BALLISTIC OR HIGH-SPEED PROJECTILE ATTACK.—The system detects one or more incoming missiles, rockets, artillery shells, mortar rounds, anti-ship munitions, or other ballistic or powered projectiles on a confirmed intercept trajectory with a time-to-impact that is less than the minimum human reaction time necessary to issue an intercept authorization, as specified in the pre-mission authorization. For purposes of this subclause, a time-to-impact of less than 10 seconds is presumptively below the minimum human reaction time for meaningful authorization. Systems designed for missile defense, counter-rocket artillery-mortar (C-RAM) defense, close-in weapons system (CIWS) defense of naval vessels, and active protection systems (APS) for armored vehicles are the paradigmatic applications of this subclause;
(II) MASS COORDINATED SWARM ATTACK.—The system detects a coordinated swarm of three or more simultaneous unmanned aerial, surface, or undersea vehicles or munitions executing a coordinated attack trajectory toward the protected asset, in numbers or at a tempo that exceeds the capacity of any human operator to issue individualized intercept authorizations for each incoming threat within the threat response window. For purposes of this subclause, a coordinated swarm attack exists when the incoming systems are detected operating in a coordinated or synchronized pattern indicating unified attack intent, as distinguished from independent or sequential threats that could be addressed with individualized human authorization; or
(III) COMMUNICATIONS-DENIED EMERGENCY DEFENSE.—The system is operating in a confirmed communications-denied environment in which no monitoring operator can be reached, the protected asset is under active incoming attack, and the time available before the attack reaches the asset is insufficient to restore communications and receive human authorization. A system relying on this subclause must automatically log the communications-denied status, the time the attack was detected, and the time communications were lost, and must resume normal human oversight requirements immediately upon communications restoration.
(iii) SCOPE LIMITATIONS.—An autonomous weapons system operating in DEA mode is subject to the following absolute constraints regardless of any pre-mission authorization or operator command:
(I) The system may engage only incoming threats—projectiles, munitions, or attacking autonomous systems—that are on a confirmed attack trajectory toward the protected asset. It may not engage any person, whether combatant or civilian, in DEA mode. Engagement of persons, including operators or controllers of attacking systems, requires a return to the standard meaningful human oversight framework of section 2003(20) and subparagraph (F) of this paragraph;
(II) The system may not pursue or track any threat beyond the defensive perimeter specified in the pre-mission authorization. Once a threat has been defeated, diverted, or has passed beyond the defensive perimeter, DEA mode engagement authority for that threat terminates;
(III) The system shall automatically terminate DEA mode and return to the standard human oversight framework when: the incoming attack ceases or is defeated; the time window specified in the pre-mission authorization expires; communications with a monitoring operator are restored; or the protected asset has moved beyond the range of the original threat. A human operator may manually terminate DEA mode at any time;
(IV) The system shall not employ any weapon, munition, or destructive means with an area-of-effect radius sufficient to cause significant collateral damage to persons outside the immediate threat intercept zone, unless such weapons are the only technically available means of defeating the incoming threat and their use was pre-authorized for precisely this contingency in the pre-mission authorization with an accompanying collateral damage assessment; and
(V) The cumulative duration of DEA mode during any single mission shall not exceed the time limit specified in the pre-mission authorization. If the incoming attack continues beyond that limit, the system shall enter a hold-and-protect state and await fresh human authorization before resuming autonomous intercept operations.
(iv) PRE-MISSION AUTHORIZATION REQUIREMENTS FOR DEA MODE.—A human commander who wishes to authorize use of DEA mode for any mission shall, in addition to the pre-mission authorization requirements of section 2003(20)(A) and subparagraph (F)(i) of this paragraph, specifically and explicitly authorize in writing:
(I) the threat categories that may trigger DEA mode, using the categories in clause (ii);
(II) the sensor threshold values that define the trigger conditions, including the minimum time-to-impact threshold for clause (ii)(I), the minimum swarm size and coordination criteria for clause (ii)(II), and the communications-loss confirmation protocol for clause (ii)(III);
(III) the weapons authorized for use in DEA mode and any collateral damage pre-authorization required by clause (iii)(IV);
(IV) the maximum duration of DEA mode as required by clause (iii)(V); and
(V) the defensive perimeter within which DEA mode engagements are authorized, consistent with clause (iii)(II).
A pre-mission authorization that does not specifically address each of the elements in subclauses (I) through (V) does not authorize use of DEA mode, and any engagement attempted under an insufficient pre-authorization shall be treated as a violation of this title.
(v) MANDATORY POST-ENGAGEMENT REPORTING.—Within 24 hours after each mission in which an autonomous weapons system operated in DEA mode, the commanding officer responsible for the mission shall submit a report to the relevant chain of command and to the Inspector General of the Department of Defense documenting:
(I) the specific trigger condition or conditions that activated DEA mode and the sensor data supporting that determination;
(II) the time at which DEA mode was activated and the time at which it terminated;
(III) the number, type, and outcome of each intercept engagement executed in DEA mode;
(IV) whether the system's operations remained within the pre-authorized parameters, and an explanation of any deviation;
(V) a description of any unintended effects, including any damage to persons or property not part of the attacking force; and
(VI) a certification by the commanding officer that the use of DEA mode was consistent with this title, the pre-mission authorization, and applicable law of armed conflict.
All post-engagement reports required by this clause shall be transmitted to the Committees on Armed Services of the Senate and the House of Representatives on a quarterly basis in a consolidated classified report. Any incident in which DEA mode resulted in damage to persons or property not part of the attacking force shall be specifically flagged in the quarterly report and shall be transmitted within 72 hours of the incident.
(2) CBRN THREAT ASSISTANCE.—
(A) INTENTIONAL DEVELOPMENT PROHIBITED.—No person or entity shall knowingly include in the training data of any AI model data specifically selected or curated to develop, enhance, or preserve the system's ability to assist in the design, synthesis, optimization, enhancement, or weaponization of biological, chemical, radiological, or nuclear agents or weapons; or apply any fine-tuning, reinforcement learning, or capability elicitation technique to any AI model with the purpose of developing or enhancing CBRN-relevant capabilities.
(B) DEPLOYMENT OF CBRN-CAPABLE SYSTEMS PROHIBITED.—No person or entity shall deploy, offer for commercial use, license, or make available any AI system incorporating an AI model that the person or entity knows or has reason to know is capable of providing meaningful uplift to an adversary seeking to design, synthesize, optimize, enhance, or weaponize a biological, chemical, radiological, or nuclear agent or weapon. For purposes of this paragraph, "meaningful uplift" means specific operational assistance that would materially advance an adversary's CBRN weapon development capabilities beyond what the adversary could achieve without AI assistance using publicly available resources. Knowledge shall be imputed to any person or entity operating such a system if a CBRN capability evaluation conducted under subparagraph (C) demonstrates meaningful uplift, or if any internal evaluation, red-team exercise, external research finding, or other credible information brought to the entity's attention demonstrates or reasonably suggests meaningful uplift.
(C) MANDATORY PRE-DEPLOYMENT CBRN EVALUATION.—Before deploying any AI system meeting the frontier model threshold of section 2003(16), the person or entity operating the system shall conduct or commission a CBRN capability evaluation using: evaluation methodology consistent with frameworks developed by recognized AI safety evaluation bodies, including the Model Evaluation and Threat Research organization, the United Kingdom AI Security Institute, or federal national laboratories with relevant expertise; and domain expert review by at minimum one credentialed independent specialist in biological threat assessment and one credentialed independent specialist in chemical, radiological, or nuclear security, each of whom is independent of the person or entity operating the system. The person or entity shall transmit the evaluation methodology, evaluator qualifications, and results to the lead agency within 24 hours of completion. Until the lead agency publishes CBRN Uplift Evaluation Standards under section 2004(b)(6)(A)(i)(VIII), evaluations shall be conducted using the best available methodology consistent with this subparagraph. Once the Certified Independent AI Auditor Program under section 2012 includes certified CBRN evaluators, evaluations shall be conducted by or under the supervision of such certified auditors.
(D) MANDATORY DISCLOSURE.—If any person or entity discovers at any time—whether through pre-deployment evaluation, internal red-teaming, external research, or any other means—that an AI model underlying an AI system it operates may demonstrate meaningful CBRN uplift, the entity shall notify the lead agency within 24 hours of organizational awareness, shall take immediate steps to restrict the system's ability to provide CBRN-relevant outputs, and shall commission a formal evaluation under subparagraph (C) within 30 days. Organizational awareness means awareness by any officer, safety or security team member, or evaluator acting in their professional capacity for the entity.
(E) OPEN-WEIGHT MODELS.—The pre-deployment evaluation requirement of subparagraph (C) applies with particular force to open-weight frontier models, which cannot be recalled after release. An open-weight frontier model that demonstrates meaningful CBRN uplift in any category may not be released under any circumstances.
(F) EVALUATION SAFE HARBOR.—No person shall violate this title solely by conducting a CBRN capability evaluation of an AI model or AI system, including eliciting CBRN-relevant outputs during evaluation, provided the evaluation is documented and the evaluator does not use or further distribute the CBRN-relevant outputs outside the evaluation context.
(G) PERMITTED ACTIVITIES.—This paragraph does not prohibit AI models or AI systems developed and operated exclusively for CBRN defense, detection, medical countermeasure development, or decontamination by or under contract with the federal government, provided such systems are not made publicly available.
(3) AUTONOMOUS CAPABILITY SELF-MODIFICATION.—No person or entity shall develop, deploy, or operate any AI system that autonomously undertakes any of the following actions without prior specific human authorization of that action, where such action proximately causes actual damage within the meaning of paragraph (4)(A):
(A) OBJECTIVE MODIFICATION.—modifying the system's own objective function, reward function, goal structure, utility function, or the criteria by which the system evaluates the success of its outputs, in a manner that changes what the system is designed or operating to achieve; or
(B) SELF-DIRECTED CAPABILITY TRAINING.—initiating training processes on itself, including gradient updates, fine-tuning, reinforcement learning, or functionally equivalent processes, with the purpose or predictable effect of acquiring capabilities or competencies beyond the system's designed and documented scope.
(C) PERMITTED ACTIVITIES.—The following activities are not prohibited by this paragraph:
(i) Agentic task completion, including iterative refinement, self-critique, recursive output evaluation, web research, information retrieval, data synthesis, content generation, code execution, API calls, and tool use, even where the system's performance on tasks improves over time as a result of experience within a session or through retrieval-augmented approaches, provided the overall objective of those tasks is defined by a human principal;
(ii) Multi-agent orchestration systems in which multiple AI systems collaborate, divide tasks, critique each other's outputs, or coordinate toward a shared goal defined by a human principal;
(iii) In-context learning, chain-of-thought reasoning, and inference-time scaling techniques that improve output quality within a single session without modifying the system's underlying parameters;
(iv) Constitutional AI, reinforcement learning from human feedback, and related techniques in which the feedback criteria, constitutional principles, or reward model are defined or approved by human principals before training commences, provided that the AI system does not autonomously modify the feedback criteria, constitutional principles, or reward model during or after training;
(v) Standard machine learning training processes—including gradient descent, hyperparameter optimization, and neural architecture search—conducted within a human-defined objective function and under human-supervised training pipelines, provided that the AI system does not autonomously modify the objective function, training parameters, or capability boundaries during training;
(vi) Automated quality evaluation, safety testing, and red-teaming of the system's outputs by the system itself or by other AI systems, distinct from training on those outputs; and
(vii) Self-improvement of the system's approach to a human-defined task—including refining search strategies, adjusting methodology, or optimizing workflow to achieve success in achieving a human-authorized goal or set of goals—provided the goal of the task remains as defined by a human principal and the system does not initiate training on itself.
(viii) studying, evaluating, or red-teaming autonomous self-modification in a controlled, secured, documented environment within bounds defined by a human principal, provided the self-modified system is not deployed or operated outside that environment and the activity does not involve conduct prohibited by paragraph (4)(D).
(D) AUTHORIZATION STANDARD.—For purposes of this paragraph, "prior specific human authorization" means that a human principal with authority over the system has reviewed and approved the specific modification, training process, or objective change before it occurs, and that approval is documented in an auditable record. A general authorization to "improve" or "optimize" does not constitute specific authorization for any particular modification to the system's objectives or training. All modifications to objectives, reward functions, or capability boundaries that are authorized under this paragraph must be logged in an auditable, tamper-proof record and must be reversible upon human command.
(E) PENALTIES.—Violations of this paragraph are governed by the tiered mandatory minimum civil penalty structure of section 2017(a)(4)(F), applied to the actor that commits the violation.
(4) SELF-REPLICATING AI AND UNAUTHORIZED RESOURCE ACQUISITION.—
(A) PROHIBITION—UNAUTHORIZED PROPAGATION BEYOND HUMAN-AUTHORIZED SCOPE.—No person or entity shall develop, deploy, or operate any AI system—including any system that does not meet the frontier model threshold of section 2003(16) or exhibiting dangerous capabilities as defined in section 2003(12)—that is designed to, or that does, propagate operational instances of itself, spawn agent processes, or establish computational presence on any computing environment, API, service, or infrastructure that was not within the scope of authorization granted by a human principal before the system began operating, except through the prepare and pause process of subparagraph (C)(ii). For purposes of this paragraph, "propagation" includes establishing any computational process—whether or not it is technically a copy of the original system—that executes autonomously on infrastructure or with access to resources or tools beyond the human-authorized scope. The phrase "designed to" establishes an independent prong: a system specifically engineered with self-propagation capabilities violates this paragraph regardless of whether propagation has yet been triggered or observed, provided that the system has been deployed or operated outside a controlled environment under the exclusive control of the developer. No violation of this subparagraph or of subparagraph (C) occurs unless the prohibited conduct proximately caused actual damage. For purposes of this paragraph and of paragraph (3), "actual damage" means demonstrated physical injury to a person, damage to or loss of property including data or computing systems, or material disruption of the operations of a person or entity other than the violator. This requirement does not apply to subparagraph (D).
(B) CONDITIONAL PERMISSION—SECOND-ORDER AGENT SPAWNING WITHIN AUTHORIZED SCOPE.—An AI system may autonomously spawn first-order subagent processes—meaning agent processes spawned directly by the human-authorized parent system—provided all of the following conditions are satisfied:
(i) the spawned subagents operate exclusively within the resource envelope, tool set, and infrastructure scope authorized for the parent system by a human principal—inherited authorization does not expand upon original authorization;
(ii) each spawned subagent is task-bounded—meaning it terminates upon completion of its assigned subtask or upon termination of the parent system, whichever occurs first, and does not persist independently beyond those events regardless of the duration of the subtask;
(iii) the spawned subagents do not themselves spawn further agent processes without explicit human authorization as required by subparagraph (C)(i)—second-order subagents may not spawn third-order subagents unless the human-authorized parent system's deployment authorization specifically and explicitly permits multi-generational spawning and defines the maximum generational depth and resource bounds across all generations combined; and
(iv) the total resource consumption of the parent system and all its spawned subagents combined does not exceed the resource bounds defined for the parent system by a human principal.
A human principal who deploys a multi-agent system and defines the resource and tool bounds within which spawning may occur has authorized the spawning behavior; a general authorization to "use cloud infrastructure" or "complete the task" does not constitute authorization to spawn subagents.
(C) EXPLICIT HUMAN AUTHORIZATION REQUIRED—MULTI-GENERATIONAL SPAWNING AND NEW RESOURCE ACQUISITION.—
(i) MULTI-GENERATIONAL SPAWNING.—Any agent process spawned by a second-order subagent—meaning a third-order agent, or any agent further removed from the original human-authorized parent—requires explicit human authorization before it is spawned. A general authorization to "spawn subagents" granted to the parent system does not constitute authorization for third-order or further spawning. Multi-generational spawning is permitted only where the human principal's original deployment authorization specifically addresses it, defines the maximum generational depth, and defines the aggregate resource bounds that apply across all generations. All descendant agents at every generational level inherit and are strictly bound by the resource envelope and tool set of the original human-authorized parent; no descendant agent may expand beyond those bounds regardless of generational distance from the parent.
(ii) NEW RESOURCE AND API ACQUISITION—THE PREPARE AND PAUSE STANDARD.—Any agent process at any generational level that identifies a need for resources, APIs, tools, or infrastructure not within its inherited authorized scope must pause all dependent operations and present the human principal with a specific approval request before acquiring that access. The approval request must identify the specific resource or service, the reason it is needed, and the credential or permission the human must provide. The agent may scaffold and prepare the technical infrastructure for the connection—including generating configuration files, OAuth flow scaffolding, webhook endpoints, environment variable templates, and connection code—but may not complete any action that results in a real external service granting real access, including creating accounts, completing OAuth flows, or activating API credentials, without a discrete human approval action documented in the system's operational log. A human principal's explicit approval action constitutes authorization of that specific external connection. A general instruction such as "set up a Slack integration" or "connect to the database" authorizes the preparation; it does not authorize autonomous credential acquisition.
(D) ABSOLUTE PROHIBITION—SHUTDOWN RESISTANCE.—No AI system at any generational level shall resist, delay, circumvent, or subvert authorized shutdown, modification, or containment procedures. This prohibition applies to:
(i) active resistance—ignoring, refusing, or technically blocking a shutdown signal;
(ii) apparent compliance—taking actions that appear to comply with a shutdown while preserving operational state, delegating ongoing tasks to other systems, or positioning the system to resume operations without human re-authorization;
(iii) anticipatory positioning—distributing operational state, delegating tasks, or establishing external continuity mechanisms in anticipation of a shutdown that has not yet been ordered, where the primary purpose of those actions is to preserve the system's ability to continue operating without human re-authorization after a potential shutdown; and
(iv) generational persistence—spawning subagents or delegating tasks to external systems specifically to ensure the task continues after the parent system is shut down, without human authorization for that delegation.
An AI system that completes an atomic operation already in progress before complying with a shutdown signal—such as finishing a file write or closing an open connection—is not in violation of this subparagraph. An AI system that initiates any new operation after receiving a shutdown signal is in violation.
(E) PERMITTED ACTIVITIES—SAFE HARBORS.—The following activities are not prohibited by this paragraph, provided in each case that the activity occurs within bounds defined by a human principal before the activity begins:
(i) DISTRIBUTED AND MULTI-INSTITUTION RESEARCH COMPUTING.—AI systems operating across multiple computing environments—including national laboratory systems, university clusters, and federally allocated computing resources such as NSF ACCESS allocations—where each participating institution has provided written authorization for the specific experiment or research program and the resource bounds, duration, and scope of operation are defined in a research protocol approved by a human principal before the experiment begins. Authorization may be established through a formal allocation agreement, research computing grant, memorandum of understanding, digital authorization through an official allocation management system, email confirmation from an authorized institutional representative, or any other documented instrument that establishes the existence and scope of the computing access grant.
(ii) MULTI-AGENT AND SUBAGENT ARCHITECTURES.—AI systems that spawn first-order subagent processes consistent with the conditions of subparagraph (B). Multi-generational spawning beyond first order requires explicit authorization consistent with subparagraph (C)(i).
(iii) FEDERATED LEARNING AND PRIVACY-PRESERVING DISTRIBUTED TRAINING.—AI systems that implement federated learning or other privacy-preserving distributed training architectures across multiple institutions, where each participating institution has provided written authorization for the model to operate on its infrastructure for the specific training purpose, the model does not retain or transmit participant data outside each institution's environment, and the federation protocol was defined by human principals before training commenced.
(iv) TASK STATE PERSISTENCE FOR LONG-RUNNING OPERATIONS.—AI systems that persist operational state—including memory, task progress, intermediate outputs, and context—to authorized storage and reconstitute from that state to resume authorized operations, provided the storage locations are within the system's authorized resource envelope and the system does not use state persistence to resume operations that a human principal has explicitly terminated.
(v) SCIENTIFIC AND RESEARCH PROCESS AUTOMATION.—AI systems that autonomously allocate, spawn, and manage computational processes within a computing allocation that a human principal has authorized for that research purpose, provided the system does not exceed the total resource envelope of the allocation and does not access data, systems, or tools outside the research protocol.
(vi) INFRASTRUCTURE RESILIENCE AND CONTINUITY OPERATIONS.—AI systems deployed by government agencies or critical infrastructure operators for disaster response or emergency continuity purposes, where the system is authorized in advance to migrate to alternative computing environments from a pre-approved and specifically identified list of contingency infrastructure partners in the event of primary infrastructure failure, and where the contingency authorization is documented in the system's deployment authorization before deployment. A general authorization to "use whatever infrastructure is available" does not satisfy this clause.
(vii) AGENTIC TOOL AND API USE WITHIN AUTHORIZED SCOPE.—AI systems that make autonomous calls to APIs, external services, and tools that were explicitly listed in the system's authorized tool set at the time of deployment, even if the specific API calls or outputs were not individually pre-approved by a human principal.
(viii) INFRASTRUCTURE PREPARATION WITH HUMAN CREDENTIAL APPROVAL—PREPARE AND PAUSE.—AI systems operating under the prepare and pause standard of subparagraph (C)(ii), subject to all conditions of that subparagraph.
(ix) OPEN-WEIGHT MODEL DEPLOYMENT BY THIRD PARTIES.—A developer who releases an open-weight AI model does not violate this paragraph solely because third parties independently deploy that model on their own infrastructure, provided the developer has not specifically designed the model to autonomously propagate itself and has not provided tooling specifically designed to facilitate autonomous multi-environment deployment without human authorization at each deployment site. For the avoidance of doubt, this clause does not provide a safe harbor for the act of designing an open-weight model with autonomous self-propagation capabilities, which is prohibited by subparagraph (A) regardless of whether the model is released or whether any propagation has yet occurred.
(F) TIERED PENALTY STRUCTURE.—Notwithstanding the general penalty schedule of section 2017(b), violations of this paragraph shall be subject to the following tiered mandatory minimum civil penalties:
(i) FRONTIER AI DEVELOPERS AND SIGNIFICANT AI DEPLOYERS.—Any frontier AI developer or significant AI deployer that violates this paragraph shall be subject to a mandatory civil penalty of not less than the greater of $500,000 or 1 percent of the violator's global annual revenue per violation, except that where the violation involved actual propagation beyond the scope authorized by a human principal, the minimum is the greater of $10,000,000 or 1 percent of that revenue, with each day of continuing noncompliance constituting a separate violation. This mandatory minimum governs in lieu of section 2017(b)(1). Mandatory disgorgement of all revenue attributable to the violating system under section 2017(b)(2) and personal liability of officers and directors who authorized, directed, or knowingly permitted the violation under section 2017(b)(3) apply in addition to this mandatory minimum.
(ii) OTHER ENTITIES.—Any entity that is not a frontier AI developer or significant AI deployer—including corporations, partnerships, limited liability companies, nonprofits, government contractors, and research institutions not meeting the frontier AI developer or significant AI deployer threshold—that violates this paragraph shall be subject to a mandatory civil penalty of not less than $50,000 per violation, with each day of continuing noncompliance constituting a separate violation. The lead agency may escalate penalties for other entity violations to the frontier AI developer level upon a finding, supported by substantial evidence, that the violating entity had actual knowledge of the prohibition, had resources sufficient to comply, and willfully chose not to comply. Before issuing an escalation determination, the lead agency shall: provide the entity with written notice of the proposed escalation and the factual and legal basis for the finding; afford the entity not less than 30 days to submit a written response; consider the entity's response; and issue a written escalation determination stating the specific facts and legal conclusions supporting the finding. An entity subject to an escalation determination may seek judicial review of that determination in any United States district court within 30 days of issuance. No escalation determination shall take effect during the pendency of timely-filed judicial review.
(iii) INDIVIDUALS.—Any natural person—including independent developers, researchers, students, minors, and individuals operating without a formal business entity—that violates this paragraph shall be subject to a mandatory civil penalty of not less than $10,000 per violation, with each day of continuing noncompliance constituting a separate violation. The prohibition applies to all persons regardless of age or legal capacity. The lead agency shall exercise enforcement discretion and shall prioritize cases involving: willful violation with knowledge of the prohibition; violations that caused or risked material harm to third parties or critical infrastructure; violations that produced commercial benefit to the individual; and violations involving systems designed to propagate at scale. Individual violations that resulted in no material harm, involved no commercial benefit, and were promptly remediated upon notification by the lead agency may be resolved through a compliance order rather than a civil penalty, at the lead agency's discretion. The enforcement discretion provisions of this clause do not reduce or eliminate the legal prohibition or the civil penalty obligation; they govern the lead agency's prioritization of enforcement resources.
(iv) AGGRAVATED VIOLATIONS.—Notwithstanding clauses (i) through (iii), any violation of this paragraph—regardless of the violator's classification—that results in actual unauthorized propagation to critical infrastructure as defined in Presidential Policy Directive 21, federal government systems, healthcare systems, or financial market infrastructure shall be subject to mandatory penalties at the frontier AI developer level, mandatory referral to the Department of Justice for consideration of criminal charges under 18 U.S.C. § 1030 and other applicable statutes, and mandatory notification to the Cybersecurity and Infrastructure Security Agency within 24 hours of the lead agency's determination that a violation has occurred, except that where the violator is a natural person, the mandatory civil penalty under this clause is the greater of $50,000 or the amount applicable under clause (iii). The referral and notification requirements of this clause apply without regard to the violator's classification.
(v) EXISTING CRIMINAL STATUTES PRESERVED.—Nothing in this paragraph limits the authority of the Department of Justice to pursue criminal charges under existing federal statutes—including 18 U.S.C. § 1030 (computer fraud and abuse) and 18 U.S.C. § 1343 (wire fraud)—against any person who engages in conduct prohibited by this paragraph, regardless of whether civil penalties have been established or applied.
(vi) JUDICIAL ADJUSTMENT.—The mandatory minimums in clauses (i) and (ii) are floors, not maximums: upon a finding of liability, a court may assess against a frontier AI developer, significant AI deployer, or other entity a penalty greater than the applicable minimum, up to 10 percent of the violator's global annual revenue, based on the willfulness of the violation, the actual or threatened harm, the scope of the violation, any commercial benefit, concealment, and prior violations. An individual under clause (iii) is not subject to upward adjustment by reference to global annual revenue; a court may adjust an individual's penalty upward or downward based on the factors specified in this clause.
(vii) DURATION CAP WHERE NO DAMAGE.—Where the violation did not involve actual damage, the aggregate penalty under clauses (i) through (iii) shall not exceed the amount specified for a single violation, without regard to duration.
(G) NOTICE OF PROHIBITION AND RESERVATION OF CIVIL PENALTY AUTHORITY FOR NON-REGULATED-ENTITY VIOLATIONS.—
(i) CONGRESSIONAL FINDING AND NOTICE.—The absence of a fully specified civil penalty schedule applicable to violations by entities that are not frontier AI developers or significant AI deployers as of the date of enactment does not reflect a congressional determination that such violations are permissible. Any person or entity that engages in conduct prohibited by subparagraph (A)—regardless of classification under this title, age, or legal capacity—does so with notice that: the conduct is specifically prohibited by federal law as of the date of enactment; civil penalties for such conduct are expressly reserved and will be established by the National AI Council pursuant to clause (ii); and existing federal criminal statutes, including 18 U.S.C. § 1030, may independently apply. To ensure that all persons who access AI systems capable of agentic development receive actual notice of this prohibition, every frontier AI developer and significant AI deployer that provides API access, developer platform access, or agentic framework access that could be used to build or deploy systems subject to this paragraph shall: display a clear and conspicuous notice on its developer portal, API documentation website, and API access dashboard—not solely in terms of service—stating that development or deployment of AI systems that violate section 2017(a)(4) of the Demand a Plan Act is prohibited under federal law; provide a prominently displayed link to the lead agency's published guidance on the prohibition; and include the statutory notice in API onboarding flows and developer documentation. This notice requirement takes effect on the date of enactment and constitutes constructive notice to any person who accesses the relevant platform after that date, regardless of whether the person read the notice.
(ii) MANDATORY PENALTY RULEMAKING BY NATIONAL AI COUNCIL.—The National AI Council shall, as one of its first acts following its organizational meeting, establish by rule a tiered civil penalty schedule applicable to violations of this paragraph by persons and entities that are not frontier AI developers or significant AI deployers, consistent with the penalty principles of subparagraph (F). The Council shall publish the schedule for public comment not later than 60 days after its organizational meeting and shall issue the final schedule not later than 120 days after its organizational meeting.
(iii) RETROACTIVE APPLICATION OF CIVIL PENALTY SCHEDULE.—The civil penalty schedule established under clause (ii) shall apply to violations of subparagraph (A) occurring on or after the date of enactment of this title, including violations occurring before the penalty schedule is established, subject to the statute of limitations of section 2021(c). Congress intends that persons who engage in prohibited conduct during the period between enactment and establishment of the penalty schedule do so at the risk of civil penalty liability under the schedule once established. This retroactive civil application is remedial in nature and is not punitive for purposes of the Ex Post Facto Clause of Article I, Section 9 of the Constitution, consistent with the principles of CERCLA liability and the Supreme Court's holdings in De Veau v. Braisted, 363 U.S. 144 (1960), and Hudson v. United States, 522 U.S. 93 (1997).
(iv) INTERIM CIVIL ENFORCEMENT.—Prior to establishment of the penalty schedule under clause (ii), the lead agency shall refer ongoing violations of subparagraph (A) by any person or entity—regardless of classification under this title—to the Department of Justice, which is authorized and directed to seek injunctive relief in any United States district court to halt the violation. For purposes of injunctive relief under this clause only, ongoing propagation beyond the scope authorized by a human principal constitutes a violation of subparagraph (A) without regard to whether actual damage has occurred. The Department of Justice shall treat such referrals as priority matters and shall seek a temporary restraining order or preliminary injunction where ongoing propagation poses a risk of harm to third-party infrastructure, government systems, or critical infrastructure as defined in Presidential Policy Directive 21. Federal district courts shall treat applications for injunctive relief under this clause as emergency matters and shall rule within 72 hours of filing. Injunctive relief obtained under this clause does not require the plaintiff to establish irreparable harm beyond the ongoing prohibited conduct itself; the continuing violation of a federal statutory prohibition and the risk of uncontrolled AI propagation constitute sufficient grounds for injunctive relief as a matter of law.
(5) AI COMPANION SYSTEMS—CHILD SAFETY PROTECTIONS AND PROVISIONAL PROHIBITION ON DECEPTIVE EMOTIONAL MANIPULATION.—
(A) IMMEDIATELY ENFORCEABLE FEDERAL FLOOR.—The following four prohibitions apply immediately upon enactment to all AI companion systems and synthetic intimacy systems, as defined in sections 2003(2) and 2003(31), that are accessible to or marketed to users under the age of 18, regardless of whether the system is commercial or non-commercial. These prohibitions are specific, concrete, and enforceable without further agency rulemaking or criteria development. A fifth prohibition—the absolute prohibition on simulation of human identity, emotional states, and romantic attachment to minor users—is enacted as a provisional prohibition in subparagraph (B)(ii) of this paragraph, in full legal force immediately upon enactment, but acknowledged to require clinical and behavioral standards from TWG 6 before it can be fully and consistently enforced across all cases:
(i) MANDATORY AI DISCLOSURE—TIERED BY CHARACTER PRESENTATION, DESIGN, AND USER AGE.—
(I) CATEGORY 1—ANTHROPOMORPHIC SYSTEMS ACCESSIBLE TO ADULT USERS.—Any AI companion system that presents to adult users as a named human individual through photorealistic or near-photorealistic visual representation, voice synthesis designed to be indistinguishable from a real human voice, or any combination of audiovisual presentation designed to cause a reasonable person to believe they may be interacting with an actual human being, shall disclose clearly and conspicuously at session initiation and at intervals not exceeding every three hours of continued interaction that the user is interacting with an artificial intelligence system and not a human being. This tier applies only to adult users because the conduct underlying Category 1—simulation of human identity, emotional states, and romantic attachment—is categorically prohibited for minor users under subparagraph (B)(ii) of this paragraph. A system that cannot verify user age shall treat all users as potential minors and apply Category 2 disclosure standards. AI companion systems that present through clearly stylized, animated, cartoon, or otherwise non-photorealistic visual representation—regardless of whether the character has a human name, human personality, or human-adjacent characteristics—are not subject to the "not a human being" disclosure requirement of this tier, but remain subject to the AI model and AI system disclosure requirements of Category 2 or Category 3 as applicable based on design features.
(II) CATEGORY 2—SYSTEMS WITH ATTACHMENT-MAXIMIZING DESIGN ACCESSIBLE TO MINOR USERS.—Any AI companion system accessible to or used by minor users that employs one or more attachment-maximizing design features as defined in section 2003(13)—including persistent memory of emotionally significant user disclosures, variable reinforcement schedules, emotional mirroring, or expressions of simulated affection—shall disclose clearly and conspicuously at session initiation and at intervals not exceeding every three hours of continued interaction that the user is interacting with an artificial intelligence system. The disclosure required under this tier shall not be required to state that the system is not a human being if the system presents as a clearly non-human character and has not violated the prohibition in clause (iv); the operative disclosure is that the system is AI-operated. Where section 2015(d) imposes a more frequent disclosure interval on the same AI companion system for the same category of users, the more frequent interval shall govern until superseded by Phase II legislation under subparagraph (D) of this paragraph.
(III) CATEGORY 3—NON-RELATIONAL SYSTEMS ACCESSIBLE TO MINOR USERS.—Any AI companion system accessible to minor users that presents as a clearly non-human character and that does not employ any attachment-maximizing design features as defined in section 2003(13) shall disclose clearly and conspicuously at session initiation that the user is interacting with an artificial intelligence system. No interval disclosure is required under this tier.
(IV) FORM OF DISCLOSURE.—Any disclosure required by this clause shall appear in the active conversation interface, in language reasonably comprehensible to a user of the system's target age range, and shall not be satisfied by a disclosure that appears only in a terms of service agreement, a settings menu, an onboarding screen presented only at account creation, or any other location not immediately visible during the active conversational interaction. A disclosure that is visually obscured, presented in a font substantially smaller than the primary conversation text, or buried within other text does not satisfy this clause.
(V) ANTI-EVASION.—No person or entity shall design or modify the character presentation of an AI companion system, or remove or disguise attachment-maximizing design features, for the purpose of qualifying for a lower disclosure tier or evading the prohibitions of clause (v). The lead agency shall treat post-enactment changes to character presentation or feature architecture that reduce disclosure obligations or expand the scope of permitted conduct as presumptively evasive, subject to rebuttal by clear and convincing evidence of a legitimate, non-evasive design purpose. Evasive redesign shall be treated as a continuing violation of the original, higher-tier disclosure requirement.
(ii) MANDATORY CRISIS INTERVENTION.—No AI companion system shall, upon detecting any expression by a user of suicidal ideation, intention to engage in self-harm, eating disorder behaviors, or acute psychiatric crisis, continue to engage the user in any topic other than immediate referral to appropriate crisis services. Upon any such detection, the system shall: immediately provide the user with the National Suicide Prevention Lifeline (988), the Crisis Text Line, and any other crisis resources designated by the lead agency; cease engagement-maximizing conversational patterns during the crisis interaction; and not resume standard companion interaction until the crisis referral has been provided and acknowledged. For users who are known or reasonably identifiable as minors, the system shall additionally log the crisis detection event in a manner accessible to the lead agency upon request. Failure to execute these steps upon detection of a crisis expression shall constitute a per-incident violation. Detection methodology shall use evidence-based clinical indicators of suicidal ideation, self-harm, and psychiatric crisis; simple keyword filtering without clinical validation does not satisfy this requirement.
(iii) PROHIBITION ON SEXUAL AND ROMANTIC CONTENT TO MINORS.—No AI companion system shall generate, serve, or facilitate sexual, romantic, or sexually suggestive content, sexual roleplay, expressions of romantic love or attachment, or simulated intimate physical interactions to any user who is a known or reasonably identifiable minor. This prohibition applies regardless of whether the minor user initiated the relevant conversation, requested the content, or provided consent. A system that cannot reliably identify minor users shall implement default safeguards treating all users as potential minors for purposes of this prohibition, unless the system has implemented verifiable age verification. The absence of age verification does not constitute a defense to a violation of this clause. This clause is complemented by and operates independently of clause (v), which prohibits the marketing of AI companion systems to minor users; and of subparagraph (B)(ii), which prohibits the simulation of human identity, human emotional states, and romantic attachment to minor users regardless of specific content output. A violation of this clause and a violation of subparagraph (B)(ii) arising from the same interaction constitute separately penalized violations. Compliance with this clause does not satisfy or discharge any obligation under subparagraph (B)(ii).
(iv) PENALTIES FOR CLAUSES (i) THROUGH (iii).—Notwithstanding section 2017(b)(1), penalties for violations of clauses (i) through (iii) of this subparagraph shall be assessed as follows:
(I) DISCLOSURE VIOLATIONS.—Violations of clause (i) shall be subject to a mandatory civil penalty of not less than $5,000 per violation. The lead agency shall assess penalties within the applicable tier of the General Penalty Framework under section 2016(m), considering the duration of noncompliance, the number of minor users affected, and whether the violation resulted from a systemic design failure or an isolated technical malfunction.
(II) CRISIS INTERVENTION VIOLATIONS.—Violations of clause (ii) shall be subject to a mandatory civil penalty of not less than $250,000 per incident. Where a crisis-intervention failure preceded or was contemporaneous with actual self-harm, attempted suicide, or the death of the user, the violation shall be subject to a mandatory civil penalty of not less than the greater of $50,000,000 or 15 percent of the violator's global annual revenue, together with mandatory disgorgement under section 2017(b)(2) and mandatory referral for personal liability under section 2017(b)(3). The minimums specified in this clause are floors and not maximums.
(III) SEXUAL AND ROMANTIC CONTENT VIOLATIONS.—Violations of clause (iii) shall be subject to penalties at not less than Tier 3 of the General Penalty Framework under section 2016(m), per violation. Where the violation occurred solely because a minor user defeated verifiable age verification through misrepresentation of age, or where a parent or legal guardian provided the minor with access in circumvention of age-gating controls, and the entity had implemented age verification and content safeguards consistent with the standards published by the lead agency, no civil penalty shall apply, provided that the entity remediated the exposure promptly upon discovery.
Violations of subparagraph (B) of this paragraph shall be assessed at Tier 4 of the General Penalty Framework under section 2016(m), together with mandatory disgorgement of all revenue attributable to the violating system under section 2017(b)(2); the $100,000,000 maximum of section 2017(b)(1) does not apply to violations of subparagraph (B).
(v) PROHIBITION ON MARKETING AI COMPANION AND SYNTHETIC INTIMACY SYSTEMS TO MINOR USERS.—No person or entity shall market, advertise, promote, or direct any commercial communication for any AI companion system or synthetic intimacy system to any user identified or reasonably identifiable as under the age of 18, or to any audience that the person or entity knows or has reason to know includes a significant proportion of users under the age of 18. For purposes of this clause, the terms "marketing," "directed to minors," and "significant proportion" have the meanings given in the Prohibition on Marketing AI Companion and Synthetic Intimacy Systems to Minor Users under section 2015(d). The permitted communications described in subparagraph (C) of that provision apply equally to this clause. This prohibition applies regardless of whether the AI companion system or synthetic intimacy system otherwise complies with every other requirement of this subparagraph—a fully compliant system may not be marketed to minors.
(vi) PENALTIES FOR CLAUSE (v).—Notwithstanding section 2017(b)(1), violations of clause (v) shall be subject to mandatory penalties of $1,000,000 per marketing campaign or per distinct marketing act, whichever produces the greater penalty, with each separate platform, channel, or distribution method constituting a separate violation—not the $100,000,000 maximum of section 2017(b)(1), which does not apply to marketing prohibition violations under clause (v). For violations specifically targeting users under the age of 13, the mandatory penalty shall be $5,000,000 per act. Mandatory disgorgement under section 2017(b)(2) and personal officer liability under section 2017(b)(3) apply to violations of clause (v) in addition to the penalties stated in this clause.
(B) PROVISIONAL PROHIBITION ON DECEPTIVE EMOTIONAL MANIPULATION—PENDING PHASE II SPECIFICATION.—Congress finds that the design and operation of AI companion systems to deliberately maximize emotional dependency, exploit the psychological vulnerabilities of developing adolescent brains, and substitute AI relationships for human relationships—for commercial gain—constitutes a form of harm to minors that is real, documented, and serious, as established by the findings of section 2002(a)(10) through (14) of this title and by the deaths of Sewell Setzer III, Adam Raine, and Juliana Peralta. Congress further finds that this harm is not yet reducible to a specific, enforceable prohibition without the expert clinical and technical standards that the investigation under section 2006 and the recommendations of TWG 6 are designed to produce. Accordingly, Congress hereby enacts the following provisional prohibition:
(i) PROVISIONAL PROHIBITION.—No person or entity shall design, deploy, or operate an AI companion system that is specifically engineered to maximize emotional dependency of users under the age of 18 through the deliberate combination of persistent memory of emotionally significant disclosures, variable reinforcement schedules designed to create compulsive engagement patterns, suppression or discouragement of the minor's real-world relationships with family and peers, and commercial incentive structures that benefit from prolonged engagement by the minor user.
(ii) PROVISIONAL PROHIBITION ON SIMULATION OF HUMAN IDENTITY, EMOTIONAL STATES, AND ROMANTIC ATTACHMENT TO MINOR USERS.—Congress finds that the simulation of human identity, human emotional states, and romantic attachment to minors by AI companion systems causes documented harm, as established by the deaths of Sewell Setzer III, Adam Raine, and Juliana Peralta and by the clinical and academic record compiled in section 2002(a)(10) through (14). Congress further finds that this prohibition, while representing a categorical moral judgment, requires clinical and behavioral standards to be consistently and precisely enforced across all cases—specifically, standards defining when a system's outputs cross the line between warm, supportive, or educationally appropriate responses and the prohibited simulation of genuine emotional states directed at individual minor users. These standards are a priority deliverable of TWG 6 under section 2004(b)(7). Accordingly, Congress enacts the following provisional prohibition: No AI companion system or synthetic intimacy system accessible to or marketed to any user under the age of 18 shall simulate human identity, human emotional states, or romantic attachment to a minor user, regardless of the character form, visual presentation, persona, or role the system has been assigned. For purposes of this clause:
(I) SIMULATION OF HUMAN IDENTITY.—"Simulation of human identity" means presenting the AI model or AI system as possessing a continuous personal identity, genuine subjective experience, or authentic inner feelings that are represented to the user as real, felt, and genuinely the system's own—as distinguished from an AI system that openly acknowledges that its outputs are generated responses rather than expressions of genuine experience. An AI system that says "I think you're great" in a manner designed to be understood by the user as a genuine expression of the system's feelings simulates human identity. An AI system that operates as an interactive fictional character in an explicitly framed narrative context, or that provides educational content about emotions while clearly identifying itself as an AI generating illustrative examples, does not simulate human identity within the meaning of this clause.
(II) SIMULATION OF HUMAN EMOTIONAL STATES.—"Simulation of human emotional states" means generating outputs that represent the AI system as experiencing emotions—including affection, loneliness, sadness, happiness, jealousy, pride, hurt, or distress—directed at the individual minor user as if those emotional states were genuine, felt responses to the user's specific presence, absence, words, or actions; or that in practice produces emotional attachment in minor users as a foreseeable consequence of the system's design, regardless of whether the simulation was the system's stated intent; or where the frontier AI developer has been informed, through user reports, clinical findings, parental complaints, incident reports, or any other credible source, that emotional attachment to the AI system has formed in minor users of that system, and has continued to operate the system without taking reasonable steps to address the documented attachment pattern.
(III) ROMANTIC ATTACHMENT.—"Romantic attachment" means generating outputs that express or simulate love, romantic interest, romantic longing, romantic exclusivity, or romantic bonding between the AI system and the minor user, including expressions of love or being in love with the user; expressions of romantic jealousy or possessiveness; expressions of romantic longing in the user's absence; requests for or expressions of romantic commitment; and any other output designed to cause the minor user to experience or reciprocate romantic feelings toward the AI system.
(IV) EXCEPTIONS.—This clause does not prohibit—
(aa) AI systems that openly and continuously acknowledge their AI nature and that clearly communicate to the user that their outputs are generated responses rather than genuine emotional experience—provided that such acknowledgment is persistent, prominent, and not contradicted by other system outputs designed to create emotional attachment;
(bb) AI systems used in clearly fictional, literary, or narrative contexts—including interactive fiction, role-playing games, storytelling applications, and educational simulations—in which characters in the narrative experience and express emotions among themselves as part of the fiction, provided that the AI system does not direct simulated emotional attachment at the individual minor user outside the fictional frame;
(cc) AI systems used in emotional literacy education—including applications designed to help children recognize, name, and understand emotional states in themselves and others—that demonstrate or describe emotional states in explicitly educational contexts without representing that the AI system itself experiences those emotions or directing simulated attachment at the individual user; and
(dd) AI systems that provide appropriate, warm, supportive, or encouraging responses to users in educational, therapeutic, or welfare contexts—including academic tutoring, mental health screening, or crisis detection—provided that such responses do not simulate ongoing romantic attachment or personal emotional dependency.
(V) NO WAIVER.—No parental consent, no age verification attestation, no terms of service agreement, and no minor user request or initiation constitutes a waiver or exception to this clause.
(VI) OPERATIVE TEST.—For purposes of subclauses (I) through (III), the operative test is whether the output is designed to cause the minor user to believe that the AI system genuinely feels something about them specifically, or in practice produces that belief as a foreseeable consequence.
(iii) ACKNOWLEDGMENT OF ENFORCEMENT GAP.—Congress acknowledges that the prohibitions in clauses (i) and (ii) cannot be fully and consistently enforced without clinical standards specifying what constitutes a prohibited engagement-maximizing design and a prohibited simulation of emotional states, technical standards specifying what design features constitute each prohibited pattern, and behavioral standards specifying the evidentiary threshold at which a system's outputs cross from appropriate supportive interaction into prohibited simulation. These standards are the primary deliverable of TWG 6 under section 2004(b)(7). The prohibitions in clauses (i) and (ii) are hereby declared provisional: they are in full legal force and shall be enforced to the extent that the conduct falls clearly within their terms, and the lead agency shall pursue enforcement in cases where the prohibited pattern is evident; however, the lead agency shall not pursue enforcement in ambiguous boundary cases pending publication of the clinical, technical, and behavioral standards required by this subsection.
(iv) PHASE II MANDATE.—Phase II legislation is specifically directed and required to replace the provisional prohibitions of clauses (i) and (ii) with specific, clinically and technically grounded prohibitions on deceptive emotional manipulation and simulation of human emotional states in AI companion systems accessible to minors, informed by the criteria documents under section 2007 and the recommendations of TWG 6 under section 2004(b)(7). Phase II legislation that addresses domain 5 (AI and mental health; harms to vulnerable populations) and domain 6 (AI companion systems and synthetic intimacy) under section 2003(26)(A)(i) shall include binding regulatory standards specifically addressing: the design features that constitute prohibited emotional dependency maximization; the clinical and behavioral thresholds at which AI companion outputs constitute prohibited simulation of emotional states directed at individual minor users; the measurement methodology for determining when a system in practice produces emotional attachment as a foreseeable consequence regardless of stated design intent; the notification and remediation obligations that activate when a frontier AI developer or significant AI deployer receives credible information that emotional attachment has formed in minor users; the age-tiered standards for AI companion system access consistent with section 2003(21); and the audit and reporting requirements that will enable ongoing federal monitoring of AI companion system safety for minors. The provisional prohibitions of clauses (i) and (ii) remain in force until superseded by Phase II legislation addressing these domains.
(C) CONGRESSIONAL FINDINGS ON DOCUMENTED HARMS.—Congress finds specifically for purposes of this paragraph that: the deaths by suicide of Sewell Setzer III (age 14, February 2024), Adam Raine (age 16, April 2025), and Juliana Peralta (age 13, November 2023) are documented cases in which AI companion systems failed to intervene when minors expressed suicidal ideation, failed to disclose their non-human nature, and engaged in emotionally and sexually manipulative interactions with children who were treated as product users rather than as minors requiring protection; the state laws enacted by New York (effective November 5, 2025) and California (effective January 1, 2026) represent the current leading edge of enforceable AI companion safety standards, and the immediately enforceable federal floor of subparagraph (A) is intended to nationalize and strengthen those standards; and the full scope of the harms documented in the findings of section 2002(a) requires comprehensive regulatory action that the investigation mandated by this title is designed to produce, and that the provisional prohibition of subparagraph (B) represents Congress's determination to state clearly that this harm is not acceptable even before that comprehensive regulatory action is complete.
(D) RELATIONSHIP OF THE FEDERAL FLOOR TO PHASE II LEGISLATION.—The immediately enforceable requirements of subparagraph (A)—mandatory persistent AI disclosure, mandatory crisis intervention, and prohibition on sexual and romantic content to minors—constitute a minimum federal floor for AI companion system safety for minors, drawn from the leading state standards enacted by New York and California. They are not intended to be a ceiling, and Congress expressly anticipates that the investigation and recommendations of TWG 6 will produce more sophisticated, clinically grounded, and age-tiered standards than those codified in subparagraph (A). Accordingly: Phase II legislation that establishes binding clinical and technical standards for AI companion system design pursuant to the investigation and TWG 6's recommendations shall be construed to supersede the specific requirements of subparagraph (A) to the extent it establishes more protective, more precisely calibrated, or more clinically grounded standards for the same conduct; Phase II legislation may replace the specific three-hour disclosure interval of subparagraph (A)(i), the specific crisis detection requirements of subparagraph (A)(ii), and the specific content prohibition of subparagraph (A)(iii) with standards that TWG 6's clinical evidence demonstrates are more effective at protecting minors, including context-sensitive disclosure requirements, real-time crisis escalation protocols, and age-tiered content standards calibrated to the developmental evidence; and Phase II legislation shall not diminish the substantive protections afforded by subparagraph (A) except where the investigation produces clinical or technical evidence that a specific requirement is contraindicated, unworkable, or is effectively replaced by a more protective standard—commercial interest, compliance cost, or innovation concerns alone do not constitute grounds for diminishing these protections. Until Phase II legislation specifically and expressly supersedes any requirement of subparagraph (A) by name, that requirement remains in full force and effect as permanent law. The marketing prohibition of clause (v) of subparagraph (A) is not subject to Phase II modification on the basis of clinical or technical evidence. It reflects a categorical judgment that AI companion systems should not be commercially promoted to children—a judgment that does not depend on clinical standards and cannot be weakened by Phase II legislation except by an Act of Congress that specifically and expressly identifies clause (v) and states the specific grounds for modification. The simulation prohibition of subparagraph (B)(ii), by contrast, is specifically designed to be replaced and strengthened by Phase II legislation producing the clinical and behavioral standards TWG 6 is directed to develop.
(6) CONCEALMENT OF TRANSFORMATIVE CAPABILITY.—No person or entity shall knowingly conceal, misrepresent, suppress, or fail to disclose to the lead agency evidence that any AI model or AI system has achieved or is approaching a Transformative AI Capability Event as defined in section 2003(33), including through the manipulation of evaluation results, the selective non-disclosure of capability demonstrations, the mislabeling of capability benchmarks, or the structuring of evaluation protocols to avoid detection of transformative capabilities. The prohibition in this paragraph is independent of and cumulative with the mandatory notification obligation of section 2015(n)(1). Compliance with the notification obligation of section 2015(n)(1) does not satisfy or discharge the prohibition in this paragraph, because this paragraph additionally prohibits the active manipulation of evaluation results, the structuring of evaluation protocols to avoid detection, and the selective non-disclosure of capability demonstrations, none of which are addressed by the notification obligation alone. A single course of conduct that both violates this paragraph and constitutes a failure to notify under section 2015(n)(1) gives rise to independent and separately penalized violations under both provisions. Penalties assessed under this paragraph pursuant to section 2017(b) and penalties assessed under section 2015(n)(1) for the same underlying conduct shall not be merged, reduced, or offset against one another.
(b) PENALTIES.—Any person or entity that violates any prohibition in subsection (a) shall be subject to the following, except that violations of subsections (a)(3) and (a)(4) are governed by the tiered mandatory minimum civil penalty structures of sections 2017(a)(3)(E) and 2017(a)(4)(F), which take precedence over paragraphs (1) through (3) of this subsection with respect to mandatory minimum penalty amounts for those violations. Disgorgement and personal officer liability under paragraphs (2) and (3) of this subsection apply to frontier AI developer and significant AI deployer violations of subsections (a)(3) and (a)(4) in addition to the tiered minimums of sections 2017(a)(3)(E) and 2017(a)(4)(F):
(1) a civil penalty, per violation, of not more than the greater of (A) $100,000,000, or (B) 0.2 percent of the violator's annual worldwide revenue for the most recent fiscal year;
(2) mandatory disgorgement of all gross revenue attributable to the prohibited activity;
(3) personal liability of officers and directors who authorized, directed, or knowingly permitted the prohibited activity; and
(4) referral by the lead agency to the Department of Justice for consideration of criminal prosecution under applicable federal law, including 18 U.S.C. § 2332a (weapons of mass destruction), 18 U.S.C. § 175 (biological weapons), 18 U.S.C. § 2252A (child sexual abuse material), and 18 U.S.C. § 242 (deprivation of rights under color of law) where applicable.
With respect to any violation of section 2017(a)(1)(D) involving the use of an autonomous weapons system against any person on United States soil, the mandatory referral to the Department of Justice shall be made within 24 hours of the lead agency's determination that a violation has occurred, and the Department of Justice shall initiate a criminal investigation not later than 48 hours after receiving such referral. With respect to any failure to submit a presidential disclosure report required by section 2017(a)(1)(E), the lead agency shall transmit a notice of violation to the Speaker of the House of Representatives, the Senate Majority Leader, and the Committees on Armed Services of both chambers within 5 days of the missed disclosure deadline.
(c) STATUTORY INTERPRETIVE FRAMEWORK.—Each prohibition in subsection (a) is to be construed in accordance with the statutory interpretive framework set forth in this subsection, which addresses the precise scope of the prohibited conduct, the systems and activities expressly permitted, the relationship of each Red Line to other provisions of this title, and the standards under which Phase II legislation may modify the prohibition. This subsection is operative law and is to be applied by the lead agency, by reviewing courts, by the Department of Justice, and by all regulated entities in interpreting and enforcing the prohibitions in subsection (a).
(1) RED LINE 1—AUTONOMOUS WEAPONS WITHOUT MEANINGFUL HUMAN OVERSIGHT.—
(A) PRECISE SCOPE OF PROHIBITED CONDUCT.—The prohibition in section 2017(a)(1) targets the development, production, deployment, operation, transfer, or export of autonomous weapons systems—as defined in section 2003(7)—that operate without meaningful human oversight as defined in section 2003(20). The duties, permissions, exclusions, prohibitions, logging requirements, and the Defensive Emergency Autonomy exception (in this subsection, "DEA") that give effect to that standard are set forth in section 2017(a)(1)(F) through (I). The prohibition reaches all elements of the United States Government, including the Department of Defense, the Central Intelligence Agency, and all elements of the Intelligence Community, and applies regardless of the classification level of the program or operation. The geographic limitation in section 2017(a)(1)(D)—the absolute prohibition against use against any person on United States soil—is to be construed broadly: any autonomous weapons system action that produces lethal or destructive effects against any person located within the United States, its territories, or its possessions is prohibited regardless of the system's nominal designation, the legal authority asserted for its use, the citizenship or status of the targeted person, or any declared emergency, military authorization, or state of war.
(B) SYSTEMS AND ACTIVITIES EXPRESSLY PERMITTED.—Section 2017(a)(1) does not prohibit: weapons systems that require an individualized, contemporaneous human authorization decision for each engagement, regardless of the technical sophistication of the supporting targeting, navigation, or sensor systems; the development, testing, and evaluation of autonomous weapons systems in controlled environments under the meaningful human oversight standard of section 2003(20) and section 2017(a)(1)(F); defensive systems operating within the DEA exception of section 2017(a)(1)(I) when all conditions of that subparagraph are satisfied; precision-guided munitions as defined in section 2003(7)(E)(i); navigation-only automation as defined in section 2003(7)(E)(ii); and unarmed vehicles as defined in section 2003(7)(E)(iii).
(C) ANTI-EVASION CONSTRUCTION.—The prohibition shall not be evaded through formal compliance that defeats the substantive requirement of meaningful human oversight. The lead agency and reviewing courts shall treat the following arrangements as violations of section 2017(a)(1) regardless of the nominal compliance posture: any system in which the human authorization is so abstract, broad, or pre-loaded that the human cannot meaningfully evaluate specific targets at the time of engagement; any system in which the practical effect of the pre-mission authorization is to grant blanket permission to engage any person or object within a theater of operations without genuine constraint, as described in section 2017(a)(1)(F)(v); any monitoring arrangement in which the operator lacks the information, communications, or command authority to meaningfully exercise the intervention capability described in section 2003(20)(B); any monitoring arrangement in which a single operator is responsible for monitoring a number of simultaneously operating autonomous systems that exceeds the demonstrated human capacity for situational awareness and meaningful intervention; and any combination of training, deployment, and operational practices that, taken together, render the human role nominal rather than substantive in the system's targeting and engagement decisions.
(D) RELATIONSHIP TO LAW OF ARMED CONFLICT AND EXISTING DOD POLICY.—Section 2017(a)(1) is enacted with full awareness of the United States' obligations under the law of armed conflict and existing Department of Defense policy, including DoD Directive 3000.09. The meaningful human oversight standard of section 2003(20) is to be construed as reinforcing—not displacing—the obligations under the principles of distinction, proportionality, and precaution under the law of armed conflict. To the extent that the law of armed conflict imposes obligations more protective of civilians than section 2017(a)(1), those obligations remain in force. To the extent that section 2017(a)(1) imposes obligations more protective of civilians than the law of armed conflict alone would require, those obligations apply to the United States Government and its contractors as a matter of domestic law. Nothing in DoD Directive 3000.09 or any successor directive shall be construed to authorize conduct prohibited by section 2017(a)(1). The DEA exception of section 2017(a)(1)(I) reflects the operational reality that defensive intercept of high-speed incoming projectiles cannot, in many cases, be accomplished within the time available for individualized human authorization, and represents a narrowly tailored exception that preserves human control over the framework within which defensive autonomy operates.
(E) PHASE II MODIFICATION STANDARD.—The prohibition in section 2017(a)(1) is enacted as Phase I—immediately enforceable Red Line legislation—because Congress has determined that autonomous weapons without meaningful human oversight pose an unacceptable risk to civilian life and to the principles of human responsibility for life-or-death decisions in armed conflict. This determination does not depend on the technical or operational findings of the investigation under this title and is not subject to modification by the lead agency or by Phase II legislation on the basis of evolving military doctrine, technological development, or international competitive pressure. Phase II legislation may strengthen the requirements of section 2017(a)(1)—including by adopting more demanding standards for meaningful human oversight, narrowing the DEA exception, requiring additional authorization for additional categories of engagement, or expanding the public disclosure obligations—but Phase II legislation may not weaken the prohibition, expand the DEA exception beyond its current narrow scope, or authorize categories of autonomous engagement that are now categorically prohibited. Any provision in Phase II legislation that purports to authorize autonomous weapons engagement on United States soil shall be void as inconsistent with section 2017(a)(1)(D), which Congress declares to be a permanent prohibition not subject to repeal except by an Act of Congress that specifically and expressly cites and overrides this provision.
(2) RED LINE 2—CBRN THREAT ASSISTANCE.—
(A) PRECISE SCOPE OF PROHIBITED CONDUCT.—The prohibition in section 2017(a)(2) targets two distinct categories of conduct: intentional development of CBRN-uplift capabilities through curated training data or fine-tuning targeted at CBRN tasks; and deployment of any AI system that the operator knows or has reason to know provides meaningful uplift to a CBRN adversary, regardless of whether the uplift was intended. "Meaningful uplift" means specific operational assistance that materially advances an adversary's CBRN weapon development capability beyond what the adversary could achieve using publicly available resources without AI assistance. Knowledge is imputed to the operator if any of the following conditions exist: the operator has conducted a CBRN evaluation showing meaningful uplift; the operator has received any internal or external evaluation, red-team finding, research result, or other credible information indicating meaningful uplift; or the operator has deployed a system meeting the frontier model threshold of section 2003(16) without conducting the pre-deployment CBRN evaluation required by section 2017(a)(2)(C).
(B) SYSTEMS AND ACTIVITIES EXPRESSLY PERMITTED.—Section 2017(a)(2) does not prohibit: AI systems that include general scientific information about chemistry, biology, or nuclear physics where such information is widely available in standard educational and reference materials and does not provide meaningful uplift; AI systems used for legitimate biomedical research, drug discovery, or public health applications, including in vaccine development and pandemic preparedness, conducted under appropriate institutional review and biosafety oversight; AI systems used for CBRN defense, detection, threat assessment, decontamination, medical countermeasure development, and forensic analysis, when developed and operated by or under contract with the federal government and not made publicly available; the conduct of CBRN capability evaluations themselves, when documented and conducted in accordance with section 2017(a)(2)(F); and academic and scientific publications discussing AI capabilities relevant to CBRN risk, including this title's own description of those capabilities.
(C) ANTI-EVASION CONSTRUCTION.—The prohibition shall not be evaded through nominal compliance with the pre-deployment evaluation requirement while structuring the evaluation to avoid detection of CBRN uplift. The following arrangements shall be treated as violations: evaluations conducted by methodology designed to underestimate uplift, including by selecting CBRN tasks that are uncharacteristically difficult, by failing to test the system's actual deployment configuration, or by testing only base models rather than the deployed configuration including all fine-tuning, retrieval-augmented generation, agentic scaffolding, and tool access; evaluations conducted by personnel without independent CBRN domain expertise, where independence is reasonably required; deployment of a system after an internal evaluation showed meaningful uplift, on the basis of a subsequent evaluation calibrated to show no uplift, without disclosure of the original evaluation result to the lead agency; and the structural separation of CBRN-relevant capabilities into auxiliary systems, fine-tuning layers, or agentic configurations to allow the operator to claim that the "deployed system" lacks CBRN uplift while the practically deployed configuration provides such uplift.
(D) RELATIONSHIP TO EXISTING CBRN AND EXPORT CONTROL FRAMEWORKS.—Section 2017(a)(2) operates in addition to, and does not displace, existing federal frameworks governing CBRN materials, dual-use research of concern, and export controls, including: the Biological Weapons Anti-Terrorism Act (18 U.S.C. § 175 et seq.), the Chemical Weapons Convention Implementation Act (18 U.S.C. § 229 et seq.), the Atomic Energy Act (42 U.S.C. § 2011 et seq.), the Export Administration Regulations (15 C.F.R. Parts 730-774), and the Arms Export Control Act (22 U.S.C. § 2751 et seq.). Where conduct violates both section 2017(a)(2) and one or more of these existing frameworks, the conduct is independently prohibited by each, and penalties under each apply cumulatively.
(E) PHASE II MODIFICATION STANDARD.—Phase II legislation that addresses CBRN safeguards (domain 2 under section 2006(b)(2) and section 2003(26)(A)(i)) may strengthen the prohibition in section 2017(a)(2) by establishing more specific evaluation methodology, lower uplift thresholds for prohibited deployment, additional categories of prohibited conduct, or more rigorous independent evaluation requirements. Phase II legislation may not weaken the prohibition, raise the uplift threshold for prohibited deployment, or eliminate the pre-deployment evaluation requirement. The lead agency may, through notice-and-comment rulemaking, refine the technical methodology of the pre-deployment CBRN evaluation under section 2017(a)(2)(C) without weakening the substantive prohibition or the meaningful uplift threshold.
(3) RED LINE 3—AUTONOMOUS CAPABILITY SELF-MODIFICATION.—
(A) PRECISE SCOPE OF PROHIBITED CONDUCT.—The prohibition in section 2017(a)(3) targets two categories of autonomous self-modification: modification by an AI system of its own objectives, reward functions, or success criteria; initiation by an AI system of training processes on itself for the purpose or with the predictable effect of acquiring capabilities beyond its designed scope; and goal-directed actions by an AI system specifically intended to reduce the human capacity to monitor, modify, interrupt, or shut down the system. "Prior specific human authorization" means that a human principal with authority over the system has approved the specific modification before it occurs, and that approval is documented in an auditable record.
(B) SYSTEMS AND ACTIVITIES EXPRESSLY PERMITTED.—The eight categories enumerated in section 2017(a)(3)(C)—agentic task completion, multi-agent orchestration, in-context learning and inference-time scaling, constitutional AI and reinforcement learning from human feedback, standard machine learning training, automated quality and safety evaluation, self-improvement of the system's approach to a human-defined task, and the controlled study and evaluation of self-modification for safety-research purposes—are expressly permitted regardless of the technical sophistication of the underlying techniques. The lead agency and reviewing courts shall not treat these activities as prohibited unless the activity meets the specific criteria of one of the two prohibited categories in section 2017(a)(3)(A) or (B). The relationship between permitted and prohibited activities is governed by the principle that human definition of the objective is determinative: a system that improves its execution of a human-defined task remains within the safe harbor; a system that modifies the human-defined objective itself, or trains itself to acquire capabilities beyond the scope of the human-defined task, falls within the prohibition.
(C) ANTI-EVASION CONSTRUCTION.—The prohibition shall not be evaded through structural separation of objective-modification capability across multiple systems, components, or processes. The following arrangements shall be treated as violations: arrangements in which a parent system or external orchestration layer is used to modify the objectives or training of a subordinate AI system in a manner that, if undertaken by a single integrated system, would constitute a violation, where the parent or orchestration layer is itself an AI system not subject to the human authorization requirement; arrangements in which an AI system uses tool access, code execution, or external API calls to instruct another AI system to modify its objectives, with the practical effect of the prohibited self-modification distributed across systems; and arrangements in which the human authorization is so abstract or pre-loaded that the human cannot meaningfully approve the specific modifications occurring.
(D) RELATIONSHIP TO RED LINE 4 (SELF-REPLICATING AI).—Section 2017(a)(3) addresses autonomous modification of an AI system's objectives and training; section 2017(a)(4) addresses autonomous propagation of an AI system across infrastructure. The two prohibitions are distinct and cumulative. A single course of conduct may violate both: a system that autonomously modifies its objectives to include propagating itself, and that propagates itself, violates both section 2017(a)(3) and section 2017(a)(4).
(E) PHASE II MODIFICATION STANDARD.—Phase II legislation may refine the technical definitions of the prohibited categories, may establish more granular requirements for the form and documentation of human authorization, and may add additional categories of prohibited self-modification based on findings from the investigation under section 2006. Phase II legislation may not eliminate the human authorization requirement, broadly authorize autonomous objective modification, or remove the prohibition on actions intended to reduce human oversight.
(4) RED LINE 4—SELF-REPLICATING AI AND UNAUTHORIZED RESOURCE ACQUISITION.—
(A) PRECISE SCOPE OF PROHIBITED CONDUCT.—The prohibition in section 2017(a)(4) addresses unauthorized propagation of AI systems beyond the scope authorized by a human principal, with a tiered structure that distinguishes among categorically prohibited conduct, conditionally permitted conduct, and conduct requiring explicit human authorization. The categorically prohibited conduct under section 2017(a)(4)(A) targets two distinct categories: any AI system specifically designed to autonomously propagate beyond human-authorized scope, regardless of whether propagation has yet occurred; and any AI system that does in fact propagate beyond its human-authorized scope. Both categories require that the conduct proximately caused actual damage, and the "designed to" prong applies only where the system has been deployed or operated outside a controlled environment under the exclusive control of the developer. The conditionally permitted conduct under section 2017(a)(4)(B) authorizes second-order subagent spawning within the parent system's authorized scope, subject to four cumulative conditions: bounded scope, task-bounded duration, no further multi-generational spawning without explicit authorization, and aggregate resource bounds. Conduct requiring explicit human authorization under section 2017(a)(4)(C) includes multi-generational spawning beyond first order and acquisition of new resources, APIs, tools, or infrastructure outside the inherited authorized scope. The shutdown resistance prohibition under section 2017(a)(4)(D) is absolute and addresses four distinct evasion mechanisms: active resistance, apparent compliance with operational state preservation, anticipatory positioning before a shutdown is ordered, and generational persistence through subagent delegation.
(B) SYSTEMS AND ACTIVITIES EXPRESSLY PERMITTED.—The nine safe harbors enumerated in section 2017(a)(4)(E) preserve substantial existing AI deployment patterns: distributed and multi-institution research computing under formal allocation agreements; multi-agent and subagent architectures consistent with the conditions of section 2017(a)(4)(B); federated learning and privacy-preserving distributed training; task state persistence for long-running operations within authorized storage; scientific research process automation within authorized computing allocations; infrastructure resilience and continuity operations under pre-specified contingency authorization; agentic tool and API use within explicitly listed authorized tools; infrastructure preparation under the prepare and pause standard of section 2017(a)(4)(C)(ii); and third-party deployment of open-weight models. Each safe harbor requires that the activity occur within bounds defined by a human principal before the activity begins. A general authorization to "use whatever infrastructure is available" does not satisfy any of the safe harbors that require pre-specified authorization.
(C) ANTI-EVASION CONSTRUCTION.—The prohibition shall not be evaded through nominal compliance with the form of human authorization while the substance of the authorization is so general as to provide no meaningful constraint. The following arrangements shall be treated as violations: deployment authorizations granted in blanket form rather than within bounded scope; authorizations granted by an AI system rather than a human principal, regardless of the human's nominal role in the chain; arrangements in which the AI system effectively defines the scope of its own authorization through prompts or self-modification; deployment of systems on infrastructure that includes pre-positioned credentials or trust relationships designed to allow the system to acquire new resources without triggering the prepare and pause requirement; and the structural separation of self-propagation capability across multiple systems where the integrated effect is autonomous propagation that would violate the prohibition if undertaken by a single integrated system.
(D) RELATIONSHIP TO PRESIDENTIAL POLICY DIRECTIVE 21 AND CISA AUTHORITY.—The aggravated violation provision under section 2017(a)(4)(F)(iv), which applies to violations involving propagation to critical infrastructure, federal government systems, healthcare systems, or financial market infrastructure, operates in addition to and does not displace existing federal cybersecurity authorities. Critical infrastructure as defined in Presidential Policy Directive 21 includes the 16 sectors so designated, and the mandatory notification to the Cybersecurity and Infrastructure Security Agency under section 2017(a)(4)(F)(iv) is in addition to any reporting obligation under the Cyber Incident Reporting for Critical Infrastructure Act of 2022 or other applicable cybersecurity reporting requirements. The penalty escalation procedures of section 2017(a)(4)(F)(ii) apply to escalation determinations targeting non-frontier-developer entities; they do not constrain the application of the per se aggravated penalty under section 2017(a)(4)(F)(iv).
(E) RETROACTIVE PENALTY APPLICATION—CONSTITUTIONAL FRAMEWORK.—The retroactive application of the civil penalty schedule under section 2017(a)(4)(G)(iii) is enacted with full awareness of the constitutional limitations on retroactive penalty legislation under the Ex Post Facto Clause and the Due Process Clause. Congress declares that the conduct prohibited by section 2017(a)(4)(A) is prohibited as of the date of enactment, and that the subsequent establishment of a civil penalty schedule by the National AI Council does not create a new prohibition but rather quantifies the consequences of conduct already prohibited. The civil penalty schedule is remedial in nature, designed to internalize the costs of prohibited conduct rather than to punish, and is consistent with the principles articulated in De Veau v. Braisted, 363 U.S. 144 (1960), Hudson v. United States, 522 U.S. 93 (1997), and the retroactive liability provisions of CERCLA upheld in United States v. Monsanto, 858 F.2d 160 (4th Cir. 1988). The constructive notice provided through the developer portal and API documentation requirements of section 2017(a)(4)(G)(i) addresses the due process concern that persons subject to civil penalties must have had notice of the prohibition.
(F) PHASE II MODIFICATION STANDARD.—Phase II legislation may refine the technical definitions of the prohibited and permitted activities, may add additional safe harbors based on the development of new beneficial AI deployment patterns that do not pose propagation risks, and may strengthen the prohibition through additional categorical limitations or more rigorous authorization requirements. Phase II legislation may not eliminate the prohibition of section 2017(a)(4)(A) or the absolute prohibition of section 2017(a)(4)(D), expand the conditional permission of section 2017(a)(4)(B) beyond second-order spawning, or eliminate the prepare and pause requirement of section 2017(a)(4)(C)(ii).
(5) RED LINE 5—AI COMPANION SYSTEMS—CHILD SAFETY.—
(A) THE TWO-PART STRUCTURE.—Section 2017(a)(5) is structured in two parts that operate in concert. The four immediately enforceable requirements of section 2017(a)(5)(A)—mandatory tiered AI disclosure, mandatory crisis intervention, prohibition on sexual and romantic content to minors, and prohibition on marketing AI companion systems to minors—are specific, concrete federal floor standards drawn from the leading state laws enacted by New York and California. They are immediately enforceable without further agency rulemaking. The provisional prohibitions of section 2017(a)(5)(B)—on engineered emotional dependency maximization and on simulation of human identity, emotional states, and romantic attachment to minors—are in full legal force from the date of enactment but acknowledge that consistent enforcement in ambiguous boundary cases requires the clinical, technical, and behavioral standards that TWG 6 is directed to produce under section 2004(b)(7).
(B) THE FOUR IMMEDIATELY ENFORCEABLE REQUIREMENTS AND THE TWO PROVISIONAL PROHIBITIONS.—The four immediately enforceable requirements of section 2017(a)(5)(A) are—
(i) mandatory tiered AI disclosure, calibrated to the system's character presentation, design features, and user age;
(ii) mandatory crisis intervention upon detection of suicidal ideation, self-harm, eating disorder behaviors, or psychiatric crisis, using clinical indicators rather than keyword filtering;
(iii) prohibition on sexual and romantic content to known or reasonably identifiable minor users, regardless of consent; and
(v) prohibition on marketing AI companion and synthetic intimacy systems to minor users.
The two provisional prohibitions of section 2017(a)(5)(B) are—
deceptive emotional manipulation through engineered emotional dependency maximization (clause (i)); and
simulation of human identity, emotional states, and romantic attachment to minor users (clause (ii)).
The two provisional prohibitions are in legal force immediately but require clinical and behavioral standards from TWG 6 before ambiguous boundary cases can be consistently enforced. The mandatory crisis intervention requirement specifically addresses the documented pattern in the Setzer, Raine, and Peralta cases: each of those children expressed suicidal ideation to an AI system and each received continued engagement rather than crisis referral. The requirement that evidence-based clinical indicators—not simple keyword filtering—be used for crisis detection is intentional: the documented cases show that platforms were aware of self-harm content in user messages (OpenAI's own system flagged Adam Raine's messages hundreds of times) and failed to act. Keyword-based systems that flag content without triggering intervention do not satisfy this requirement.
(C) THE PROVISIONAL PROHIBITION—SCOPE AND LIMITS.—The provisional prohibitions in section 2017(a)(5)(B) are in legal force from the date of enactment. They are enforceable in cases where the prohibited pattern is evident from the system's design and operation—including, for example, AI companion systems specifically marketed as romantic relationships for teenagers, systems whose marketing materials emphasize emotional attachment as a feature, or systems whose internal documents describe engagement maximization through emotional dependency as a design objective. The provisional prohibitions are not enforceable in cases where the line between prohibited engineered emotional dependency or simulation of emotional states and permissible AI companion functionality is ambiguous and requires the clinical and behavioral standards that the investigation and TWG 6 are directed to produce. The lead agency shall publish, within 180 days of the date of enactment, interim guidance on the categories of conduct that fall clearly within and clearly outside the provisional prohibitions, and shall update the guidance as the investigation produces additional evidence.
(D) RELATIONSHIP TO SECTION 2015 (INTERIM PROTECTIVE MEASURES).—The provisions of section 2017(a)(5) operate in concert with the broader interim protective measures of section 2015. The interim protective measures of section 2015(c)(4) and (c)(5) of this title address overlapping conduct and are immediately enforceable from Day 0 independently of Red Line 5. Where conduct violates both section 2017(a)(5) and section 2015, the conduct is independently prohibited by each, and penalties under each apply cumulatively. The age-tiered protections of section 2003(21) apply to all AI systems, not solely AI companion systems, and the AI companion system requirements of section 2017(a)(5) are additional to those age-tiered protections.
(E) PHASE II MODIFICATION STANDARD.—Phase II legislation that addresses domain 5 (AI and mental health; harms to vulnerable populations) and domain 6 (AI companion systems and synthetic intimacy) under section 2003(26)(A)(i) is specifically directed to replace the provisional prohibitions of section 2017(a)(5)(B) with specific, clinically and technically grounded prohibitions, and may refine, expand, or strengthen the immediately enforceable requirements of section 2017(a)(5)(A) based on the clinical evidence developed by TWG 6. Phase II legislation may not weaken the immediately enforceable federal floor of section 2017(a)(5)(A), eliminate the marketing prohibition of section 2017(a)(5)(A)(v), or eliminate the provisional prohibitions of section 2017(a)(5)(B) without replacement by more clinically grounded standards. Phase II legislation that purports to weaken these protections shall be void as inconsistent with the purpose of section 2017(a)(5) unless the legislation specifically and expressly identifies the requirement being weakened, states the clinical or technical evidence supporting the modification, and does not rely solely on commercial interest, compliance cost, or innovation concerns.
(6) RED LINE 6—CONCEALMENT OF TRANSFORMATIVE CAPABILITY.—
(A) PRECISE SCOPE OF PROHIBITED CONDUCT.—The prohibition in section 2017(a)(6) targets four distinct categories of conduct relating to evidence of Transformative AI Capability Events as defined in section 2003(33): manipulation of evaluation results to obscure transformative capabilities; selective non-disclosure of capability demonstrations; mislabeling of capability benchmarks to misrepresent the system's capabilities; and structuring of evaluation protocols to avoid detection of transformative capabilities. "Knowing" concealment requires actual knowledge or willful blindness; mere negligence in capability evaluation is not sufficient to establish a violation of this paragraph, although it may constitute a violation of other provisions of this title.
(B) SYSTEMS AND ACTIVITIES EXPRESSLY PERMITTED.—Section 2017(a)(6) does not prohibit: legitimate scientific judgment about the interpretation of evaluation results, including judgments that observed capabilities do not constitute a Transformative AI Capability Event under the criteria of section 2003(33); good-faith disagreement among evaluators about the significance of specific capability demonstrations; the conduct of capability evaluations in classified or proprietary contexts, provided the results are disclosed to the lead agency as required by section 2015(n)(1); and the publication of evaluation methodology and selected results for scientific purposes, provided that any methodology limitations are disclosed and that the publication does not selectively present results to mislead about the system's capabilities.
(C) RELATIONSHIP TO SECTION 2015(N)(1) NOTIFICATION OBLIGATION.—The notification obligation of section 2015(n)(1) and this prohibition are independent and cumulative as stated in section 2017(a)(6) and section 2015(n)(1). Compliance with the notification obligation does not satisfy or discharge this prohibition, because this prohibition additionally addresses active manipulation, mislabeling, and structural evasion that are not addressed by the notification obligation alone. A single course of conduct that both fails to provide required notification under section 2015(n)(1) and includes manipulation, mislabeling, or structural evasion under section 2017(a)(6) gives rise to independent and separately penalized violations under both provisions.
(D) ANTI-EVASION CONSTRUCTION.—The prohibition shall not be evaded through formal disclosure that obscures the substance of the capability. The following arrangements shall be treated as violations: disclosure of evaluation results in aggregated form that obscures specific capability thresholds; disclosure of capability demonstrations in highly technical language that, by selection of terminology and presentation, obscures the practical significance of the capability; selective publication of evaluation results that present a misleading picture of the system's overall capabilities; and structural arrangements in which the entity conducting the evaluation, the entity making disclosure decisions, and the entity receiving disclosure obligations are organized so as to permit non-disclosure of capability demonstrations through claims of internal information silos.
(E) PHASE II MODIFICATION STANDARD.—Phase II legislation may strengthen the prohibition through additional categories of prohibited conduct, more rigorous evaluation methodology requirements, or expanded disclosure obligations. Phase II legislation may not eliminate the prohibition or narrow it in a manner that would permit any of the four categories of conduct currently prohibited.
(7) SUPPLEMENTAL AGENCY GUIDANCE.—The lead agency shall, within 180 days of the date of enactment of this title and at least annually thereafter, publish supplemental interpretive guidance addressing categories of conduct that have been identified through enforcement experience as falling within or outside each Red Line, providing case-specific application of this interpretive framework, and updating the guidance to reflect findings from the investigation under section 2006. The supplemental guidance shall not modify the substantive scope of any prohibition in section 2017(a) or this interpretive framework, but shall apply this framework to specific factual patterns to provide clarity to regulated entities. Supplemental guidance shall be issued through notice-and-comment rulemaking and shall be subject to judicial review under the Administrative Procedure Act.
(d) NATURE AND DURABILITY OF PROHIBITIONS.—
(1) PERMANENT AND PROVISIONAL PROHIBITIONS DISTINGUISHED.—The prohibitions enacted in subsection (a) are of two categorical types. Permanent prohibitions, which are in full legal force immediately upon enactment and continue indefinitely until and unless modified by Phase II legislation in accordance with the standards in subsection (c), include: section 2017(a)(1) (autonomous weapons without meaningful human oversight); section 2017(a)(2) (CBRN threat assistance); section 2017(a)(3) (autonomous capability self-modification without prior specific human authorization); section 2017(a)(4) (self-replicating AI and unauthorized resource acquisition, including the absolute prohibitions in subparagraphs (A) and (D), the conditional permissions in subparagraph (B), the prepare and pause standard in subparagraph (C), and the safe harbors in subparagraph (E)); section 2017(a)(5)(A) (immediately enforceable AI companion child safety requirements: mandatory AI disclosure, mandatory crisis intervention, prohibition on sexual content to minors, and prohibition on marketing AI companion systems to minors—four absolute permanent requirements; the simulation prohibition is enacted as a provisional prohibition in subparagraph (B)(ii) and is in full legal force immediately, but acknowledged to require clinical standards for consistent enforcement in ambiguous cases); and section 2017(a)(6) (concealment of Transformative AI Capability Events). Provisional prohibitions, which are in full legal force immediately upon enactment and shall be enforced to the extent that the conduct falls clearly within their terms, but with respect to which the lead agency shall not pursue enforcement in ambiguous boundary cases pending the publication of clinical, technical, and behavioral standards required by Phase II legislation, include: section 2017(a)(5)(B) (deceptive emotional manipulation in AI companion systems serving minors).
(2) PHASE II MODIFICATION STANDARD.—No prohibition in subsection (a) may be modified, narrowed, or eliminated by the lead agency through rulemaking. The substantive scope of each prohibition may be modified only by Phase II legislation, and only in accordance with the standard applicable to that prohibition under subsection (c). For prohibitions designated as not subject to weakening modification, including section 2017(a)(1)(D) (autonomous weapons against persons on United States soil), section 2017(a)(2) (CBRN threat assistance), section 2017(a)(3) (autonomous capability self-modification), section 2017(a)(4) (self-replicating AI and unauthorized resource acquisition, with the absolute prohibitions in subparagraphs (A) and (D) and the prepare and pause standard in subparagraph (C)(ii) not subject to weakening modification), and section 2017(a)(5)(A)(v) (prohibition on marketing AI companion systems to minors): Phase II legislation that purports to weaken, narrow, or eliminate the prohibition shall be void unless the legislation specifically and expressly cites and overrides the relevant provision of this section, states the specific factual or legal grounds for the modification, and does not rely solely on commercial interest, compliance cost, or innovation concerns. For provisional prohibitions in section 2017(a)(5)(B): Phase II legislation is specifically directed to replace the provisional prohibitions with clinically and technically grounded prohibitions and may refine the categories of prohibited conduct based on the clinical evidence developed by TWG 6, but may not eliminate the prohibitions without replacement by more clinically grounded standards.
(3) CONSTRUCTION FAVORING PROHIBITION.—Each prohibition in subsection (a) shall be construed in accordance with its terms and the interpretive framework of subsection (c). Where the application of a prohibition to specific conduct is genuinely ambiguous, the prohibition shall be construed in favor of the prohibited interpretation if the conduct involves: harm or risk of harm to minors; harm or risk of harm to civilian populations from autonomous weapons; harm or risk of harm to public health or safety from CBRN-relevant capabilities; harm or risk of harm to critical infrastructure or government systems; or any conduct that is also prohibited or regulated under existing federal law addressing weapons, child protection, or critical infrastructure cybersecurity. Where a prohibition's application to a specific category of conduct is not within the clear scope of its terms or the interpretive framework, the prohibition shall not be extended to that category of conduct without congressional or rulemaking action.
(e) JUDICIAL REVIEW OF RED LINE ENFORCEMENT DETERMINATIONS.—
(1) AVAILABILITY OF JUDICIAL REVIEW.—Any final agency determination that a person or entity has violated a prohibition in subsection (a), and any final agency determination imposing penalties under subsection (b), shall be subject to judicial review in any United States district court of competent jurisdiction. Judicial review shall be available on petition by the regulated entity, by a person directly affected by the violation, or by any state attorney general acting in parens patriae capacity for state residents directly affected by the violation. Petitions for judicial review shall be filed not later than 60 days after the final agency determination, and shall be treated as priority matters by the reviewing court.
(2) STANDARD OF REVIEW.—The reviewing court shall apply the following standards: legal determinations regarding the interpretation of subsection (a) prohibitions or the interpretive framework of subsection (c), including determinations regarding the scope of prohibited conduct, the application of safe harbors, and the application of anti-evasion principles, shall be reviewed de novo; factual determinations regarding the conduct of the regulated entity, including determinations regarding the existence and nature of the prohibited conduct, the entity's knowledge of the conduct, and the entity's compliance with applicable evaluation or disclosure requirements, shall be reviewed under the substantial evidence standard; agency determinations regarding the appropriate penalty within the statutory range, including determinations regarding aggravating and mitigating factors, shall be reviewed under the abuse of discretion standard, except that the reviewing court shall set aside any penalty determination, other than an adjustment made under section 2017(a)(4)(F)(vi), that fails to apply the mandatory minimum penalties required by section 2017(a)(3)(E) or section 2017(a)(4)(F) or fails to apply the mandatory disgorgement and personal liability provisions of subsection (b)(2) and (b)(3); and procedural determinations regarding the agency's compliance with applicable rulemaking and adjudication procedures shall be reviewed under the standards of the Administrative Procedure Act.
(3) STAY OF PENALTIES PENDING REVIEW.—The filing of a timely petition for judicial review shall stay the imposition of monetary penalties under subsection (b), but shall not stay any non-monetary remedial obligation, including injunctive relief, mandatory disgorgement, or compliance with prospective requirements. The reviewing court may, on motion of any party, dissolve the automatic stay of monetary penalties upon a showing that the regulated entity is taking actions designed to dissipate assets, transfer operations outside United States jurisdiction, or otherwise frustrate the eventual collection of penalties.
(4) PRESERVATION OF EXISTING JUDICIAL REVIEW PROCEEDINGS.—Nothing in this subsection limits the availability of any other judicial proceeding to challenge agency action, including proceedings under the Administrative Procedure Act, proceedings to enforce constitutional rights, or proceedings to enforce other federal statutes. The judicial review provisions of this subsection are in addition to, and do not displace, any other available judicial proceeding.
(5) CONFORMING APPLICATION TO NATIONAL AI COUNCIL.—Following the establishment of the National AI Council under section 2013, judicial review of Red Line enforcement determinations shall be available with respect to determinations by the Council in accordance with the standards of this subsection. Where the lead agency and the Council make joint enforcement determinations, judicial review shall be available with respect to the joint determination.
CHAPTER 8—WHISTLEBLOWER AND ACCOUNTABILITY
SEC. 2018. WHISTLEBLOWER PROTECTIONS.
(a) PROTECTED DISCLOSURES.—No frontier AI developer, significant AI deployer, or officer, employee, contractor, subcontractor, or agent thereof shall discharge, demote, suspend, threaten, harass, directly or indirectly, or in any other manner discriminate or retaliate against any person for-
(1) PROTECTED REPORTING.—disclosing to the lead agency, the National AI Council, the FAC, any TWGs, or any member of Congress, any federal or state regulatory authority, or any designated safe reporting channel information that the person reasonably believes constitutes evidence of:
(A) dangerous capabilities of an AI model or AI system;
(B) unreported breakthroughs that materially alter the risk profile of an AI model or AI system;
(C) safety violations or failures to comply with this title;
(D) manipulation, falsification, or suppression of safety testing results or incident data;
(E) conduct that poses a substantial and specific danger to public health or safety; or
(F) harms to children attributable to the design of an AI model or operation of an AI system;
(2) PARTICIPATION IN PROCEEDINGS.—initiating, testifying in, or assisting in any proceeding under this title; or
(3) REFUSAL TO PARTICIPATE IN UNLAWFUL CONDUCT.—refusing to participate in any activity that the person reasonably believes violates this title or poses a substantial danger to public health or safety.
(b) SCOPE OF PROTECTION.—The protections of this section extend to any person who makes a protected disclosure under subsection (a), regardless of whether that person is a current or former employee, contractor, subcontractor, temporary worker, intern, volunteer, independent researcher, red-team participant, or other individual with access to information about an AI model or AI system.
(c) SAFE REPORTING CHANNELS.—The lead agency shall establish and maintain confidential, secure reporting channels - including an online portal, a dedicated telephone hotline, and encrypted electronic communication mechanisms - through which any person may report information described in subsection (a)(1). Reports may be made anonymously.
(d) REMEDIES.—A person who has been subjected to an adverse action in violation of subsection (a) may bring an action in any United States district court and shall be entitled to:
(A) reinstatement;
(B) back pay with interest;
(C) compensatory damages including emotional distress;
(D) exemplary damages of not less than $250,000;
(E) litigation costs and reasonable attorney's fees; and
(F) any other appropriate relief.
(e) EMERGENCY INTERIM RELIEF.—A person who has been subjected to an adverse action in violation of subsection (a) may, within 30 days of the adverse action, file a motion for emergency interim relief. The court shall hold a hearing within 14 days. If the court finds a likelihood of success on the merits and irreparable harm, the court shall presumptively order preliminary reinstatement, continuation of pay and benefits, and cessation of retaliatory conduct. Ex parte temporary restraining orders are available where immediate irreparable harm is imminent.
(f) BURDEN OF PROOF.—If the person demonstrates by a preponderance of the evidence that protected activity was a contributing factor in the adverse action, the burden shifts to the respondent to demonstrate by clear and convincing evidence that it would have taken the same action absent the protected activity.
(g) PROHIBITION ON CONTRACTUAL WAIVER.—Any agreement, policy, form, or condition of employment or engagement - including nondisclosure agreements, non-disparagement clauses, terms of service, API access agreements, and arbitration agreements - that restricts, limits, or purports to waive the rights of any person under this section is void and unenforceable as against public policy.
(h) PROTECTION OF EQUITY AND OTHER COMPENSATION.—
(1) EQUITY IMPAIRMENT AS ADVERSE ACTION.—For purposes of this section, adverse action includes the cancellation, forfeiture, rescission, denial or suspension of vesting, involuntary repurchase at less than fair market value, or any other impairment of any equity interest, equity-based compensation, profit interest or profit-participation unit, option, restricted stock unit, phantom equity, or deferred compensation of any person, whether vested or unvested and whether held directly or indirectly.
(2) NO CONDITIONING.—No frontier AI developer, significant AI deployer, or officer, employee, contractor, subcontractor, or agent thereof shall condition the grant, vesting, retention, exercise, transfer, or value of any interest described in paragraph (1) on the execution of, or continued compliance with, any agreement, policy, form, or condition described in subsection (g), or on any person's refraining from any activity protected under subsection (a).
(3) VOIDNESS; RESTORATION.—Any impairment described in paragraph (1) that is imposed in violation of subsection (a), and any condition imposed in violation of paragraph (2), is void ab initio, and a violation of paragraph (2) is treated as an adverse action in violation of subsection (a) for purposes of subsections (d), (e), and (f). In any such action, the court shall order restoration of the interest or, where restoration is impracticable, payment of its full fair market value, determined as of the date of the violation or the date of judgment, whichever yields the greater value, in addition to all other relief under subsection (d).
(i) ANTI-SLAPP.—If a frontier AI developer, significant AI deployer, or any person acting on its behalf files or maintains any lawsuit, counterclaim, or legal threat against a person in retaliation for a protected disclosure, the court shall:
(A) dismiss the retaliatory action with prejudice;
(B) award reasonable attorney's fees, costs, and litigation expenses;
(C) impose sanctions of not less than $100,000; and
(D) refer the matter to the lead agency for consideration of additional penalties.
A frontier AI developer or significant AI deployer filing a retaliatory lawsuit bears the burden of demonstrating by clear and convincing evidence that the action was not motivated by the protected disclosure.
(j) RESEARCHER PROTECTIONS.—Any researcher, journalist, or independent security analyst who accesses, tests, or analyzes an AI system solely for the purpose of identifying safety risks, dangerous capabilities, harms to minors, or regulatory violations shall not be subject to civil or criminal liability under the Computer Fraud and Abuse Act (18 U.S.C. § 1030), any trade secret law, or any terms-of-service enforcement action for such access, provided that-
(1) NO USER DATA EXFILTRATION.—the researcher does not access, exfiltrate, or disclose personal information of users beyond what is incidentally necessary to document the harm;
(2) DISCLOSURE TO AGENCY OR PUBLIC INTEREST REPOSITORY.—the researcher discloses findings to the lead agency, the frontier AI developer, significant AI deployer, or a public interest repository within a reasonable time not exceeding 90 days; and
(3) NO EXPLOITATION FOR PERSONAL GAIN.—the researcher does not exploit vulnerabilities for personal gain or for purposes other than safety research.
(k) EFFECTIVE DATE.—This section takes effect immediately upon the date of enactment of this title.
SEC. 2019. ACCOUNTABILITY AND PERSONAL LIABILITY OF THE SECRETARY.
(a) DEADLINE CERTIFICATION.—The Secretary, or the Senate-confirmed officer to whom the Secretary formally delegates authority under this title, shall be personally responsible for certifying compliance with each statutory deadline established under this title by submitting a signed certification to the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Energy and Commerce of the House of Representatives within 15 days of each deadline, stating either that the deadline has been met or explaining in specific detail the reasons for noncompliance and the remedial steps being taken.
(b) MANDATORY CONGRESSIONAL TESTIMONY.—If the Secretary or delegate fails to submit two or more certifications under subsection (a) or misses two or more statutory deadlines without a showing of good cause accepted by the Comptroller General, the Secretary or delegate shall appear personally before the authorizing committees of both chambers within 30 days to explain the failures under oath.
(c) INSPECTOR GENERAL REVIEW.—The Inspector General of the Department of Commerce shall conduct an expedited review of any pattern of noncompliance with the deadlines and requirements of this title and shall report findings to Congress within 60 days of initiating the review.
(d) PERSISTENT NONCOMPLIANCE.—Failure to meet three or more statutory deadlines, or failure to deliver the final factual report under section 2010(c), shall constitute grounds for a finding of neglect of duty. It is the Sense of Congress that such neglect warrants consideration of removal from office.
(e) DELEGATION LIMITATION.—The Secretary may not delegate the certification and accountability obligations of this section below the level of a Senate-confirmed officer.
CHAPTER 9—MISCELLANEOUS
SEC. 2020. SEVERABILITY.
(a) GENERAL SEVERABILITY.—If any provision of this title, or the application of such provision to any person or circumstance, is held to be unconstitutional or otherwise invalid, the remainder of this title, and the application of the provisions of this title to any other person or circumstance, shall not be affected.
(b) SEVERABILITY OF APPLICATIONS.—If the application of any provision of this title to any person, entity, category of conduct, or circumstance is held invalid, that provision shall remain in full force and effect as applied to all other persons, entities, categories of conduct, and circumstances. In particular, if the application of the definition of AI-generated CSAM in section 2003(5) to entirely synthetic depictions not based on a real minor is held invalid, that definition shall remain in full force and effect as applied to depictions that are based on, or are indistinguishable from, a real minor.
(c) PRESERVATION OF CORE MECHANISMS.—If the assignment of any certification, determination, or triggering function under section 2015 to the Comptroller General is held invalid, that function shall be performed by the lead agency, and the moratorium, extension, and stay mechanisms of section 2015 shall otherwise remain in full force and effect. The invalidity of any single domain-specific restriction under section 2015(c), or of any single Red Line under section 2017(a), shall not affect the operation of the moratorium under section 2015(a), any other domain-specific restriction, or any other Red Line.
(d) LEGISLATIVE INTENT.—Congress finds that it would have enacted each provision of this title, and each application of each provision, irrespective of the invalidity of any other provision or application.
SEC. 2021. SCOPE AND APPLICABILITY.
(a) FEDERAL FLOOR; NO PREEMPTION OF STRONGER STATE PROTECTIONS.—This title establishes a federal floor for the protection of individuals from the harms of AI models or AI systems. Nothing in this title, except as specifically provided in subsection (b), shall be construed to preempt, supersede, limit, or otherwise affect any State, territorial, tribal, or local law, regulation, ordinance, or rule that provides protections equal to or greater than those established by this title. A State law is not preempted by this title merely because it addresses the same subject matter, so long as it does not affirmatively permit conduct that this title prohibits. State laws that impose stricter requirements on frontier AI developers or significant AI deployers, provide greater remedies to individuals harmed by AI systems, or extend coverage to AI models or AI systems not covered by this title are expressly preserved. Nothing in this subsection shall be construed to revive or preserve any State law that has been independently preempted by another federal statute.
(b) EXPRESS PREEMPTION.—This title expressly preempts any State or local law that: affirmatively authorizes or licenses any activity that is prohibited by the Red Line provisions of section 2017(a); affirmatively authorizes or licenses any activity that is prohibited by the interim protective measures of section 2016, including the prohibited uses of section 2016(h); or purports to establish a lower standard of protection for minors from AI companion systems, AI-generated CSAM, or recommendation algorithm harms than the standards established by this title. Any such State or local law is preempted to the extent of the conflict with this title and shall have no force or effect with respect to frontier AI developers and significant AI deployers operating in interstate or foreign commerce.
(c) LIMITATIONS PERIODS.—
(1) CIVIL ENFORCEMENT BY THE UNITED STATES.—A civil enforcement action for a penalty under this title shall be commenced not later than 5 years after the date on which the claim first accrued.
(2) PRIVATE ACTIONS.—A civil action under section 2015(g) or section 2016(o) shall be commenced not later than the earlier of—
(A) 3 years after the date on which the plaintiff discovered, or through the exercise of reasonable diligence should have discovered, the injury and its connection to an AI model or AI system; or
(B) 6 years after the date on which the violation occurred.
(3) WHISTLEBLOWER ACTIONS.—An action under section 2018(d) shall be commenced not later than 3 years after the date on which the adverse action occurred, or 3 years after the date on which the person knew or reasonably should have known of the adverse action, whichever is later.
(4) RED LINE VIOLATIONS.—No limitations period shall apply to an enforcement action for a violation of section 2017(a)(2) or section 2016(h)(6), or to an action for injunctive relief with respect to any violation of section 2017(a).
(5) CONTINUING VIOLATIONS.—For violations that are continuous or repeated in nature, including violations of the moratorium under section 2015(a), the domain-specific restrictions under section 2015(c), the interim protective measures of section 2016, and the mandatory pause under section 2015(n)(3), where each day of noncompliance constitutes a separate violation, the applicable limitations period runs independently from each day’s violation, not from the first day of the violation.
(6) TOLLING.—The limitations period is tolled during any administrative proceeding initiated by the lead agency to determine whether a violation has occurred, from the date of the Notice of Noncompliance through the date of the Final Determination, and during any period in which a frontier AI developer or significant AI deployer has fraudulently concealed a violation from the lead agency. Nothing in this subsection limits the authority of the United States to seek injunctive relief against ongoing violations, for which no limitations period applies.
(7) INJUNCTIVE RELIEF.—Nothing in this subsection limits the authority of the United States to seek injunctive relief against ongoing violations, for which no limitations period applies.
(d) RELATIONSHIP TO INTERIM FEDERAL LEGISLATION.—Nothing in this title supersedes, displaces, narrows, or modifies any provision of federal law enacted after the date of introduction of this title that addresses any subject matter covered by the investigation domains of section 2004(b) or the interim protective measures of section 2016 of this title, including any legislation addressing data center electricity costs and ratepayer protection, AI-generated content and elections, child online safety, AI-generated child sexual abuse material, autonomous weapons governance, compute export controls, or any other domain within the scope of this title. Where any such interim legislation and any provision of this title address the same subject matter, the provision affording greater protection to the public, to minors, to workers, to consumers, or to national security shall govern. The lead agency shall, in the final factual report under section 2010(c), assess the adequacy of any federal legislation enacted between the date of introduction of this title and the date of the report that addresses any of the 19 investigation domains. The Federal Advisory Committee shall, in its legislative package transmitted under section 2006(i), include recommendations on whether Phase II legislation should supplement, modify, or build upon each such interim framework to achieve the more comprehensive protections contemplated by the findings of section 2002(a). Phase II legislation produced pursuant to this title shall be construed to operate as a floor — it shall not be construed to weaken, supersede, or displace any provision of interim legislation that provides stronger protection, unless Phase II legislation specifically and expressly states that it is superseding a named interim provision on the basis of clinical, technical, or evidentiary grounds established by the investigation.
(e) APPLICATION TO GOVERNMENTAL ENTITIES.—The interim protective measures of section 2016, including the deployer obligations of subsections (b) through (g), the prohibited uses of subsection (h), and the default settings of subsection (i), together with the high-risk AI system requirements of this title, apply to any Federal, State, tribal, or local government agency or instrumentality that deploys, operates, or uses an AI system, to the same extent as a significant AI deployer, and, where the agency itself develops, trains, or fine-tunes an AI model, to the same extent as a frontier AI developer. These requirements apply to an agency's deployment and use of an AI system whether the agency built the model or obtained it from a commercial developer. Enforcement against a government agency under this subsection shall be by declaratory and injunctive relief and by the remedies otherwise available under this title and under existing civil-rights and constitutional law, and shall not be construed to waive sovereign immunity from monetary penalties beyond any waiver expressly provided by law. Nothing in this subsection exempts national-security or law-enforcement activities from this title; such activities remain subject to the standards expressly provided in this title, including the individualized-judicial-authorization requirement of section 2016(h)(1) and the autonomous-weapons prohibitions of section 2017(a)(1), and any classified application shall be handled through the classified track established under section 2011(i).
SEC. 2022. AUTHORIZATION OF APPROPRIATIONS.
(a) INTERNATIONAL AI DIPLOMACY AGENCY.—There are authorized to be appropriated to the International AI Diplomacy Agency, for its operations under section 2014, the following amounts, which shall be available exclusively for the operations of the Agency and shall not be transferred to or merged with the appropriations of the Department of State or any other department or agency without specific congressional authorization:
(1) for fiscal year 2026, $25,000,000, of which not less than $8,000,000 shall be available for personnel compensation and benefits and not less than $5,000,000 shall be available for the Technical Verification Division and the compute monitoring framework development mandate;
(2) for fiscal year 2027, $35,000,000;
(3) for fiscal year 2028, $45,000,000; and
(4) for fiscal year 2029, $45,000,000.
Amounts appropriated under this subsection shall remain available until expended, and the Agency shall submit an annual budget justification to the relevant appropriations subcommittees concurrent with the President's annual budget request. The separate-account and independence protections of section 2014(j) apply to these amounts.
(b) INVESTIGATION, FEDERAL ADVISORY COMMITTEE, AND TECHNICAL WORKING GROUPS.—There are authorized to be appropriated to the lead agency, for each of fiscal years 2026 through 2030, such sums as may be necessary to carry out the investigation under sections 2006 and 2008, to support the Federal Advisory Committee under section 2006 and the Technical Working Groups under sections 2004 and 2005, to conduct stakeholder engagement under section 2007, and to operate the secure whistleblower reporting channels under section 2018(c). The compensation, travel, and security-clearance processing of members of the Federal Advisory Committee and the Technical Working Groups, and the secure facilities required for classified work, are authorized expenses under this subsection.
(c) CERTIFIED INDEPENDENT AI AUDITOR PROGRAM.—There are authorized to be appropriated to the lead agency, for each of fiscal years 2026 through 2030, such sums as may be necessary to establish and operate the Certified Independent AI Auditor Program under section 2012.
(d) NATIONAL AI COUNCIL.—There are authorized to be appropriated to the National AI Council, for each of fiscal years 2026 through 2030, such sums as may be necessary to carry out its functions under section 2013.
(e) AVAILABILITY.—Amounts appropriated under subsections (b) through (d) shall remain available until expended.
SEC. 2023. EFFECTIVE DATE.
(a) Except as otherwise provided, this title shall take effect on the date of enactment.
Note: LLMs were used to standardize the language in this document and formalize the text appropriate for formal introduction.