NEWS / SEP.2026
Warner, Schatz and Kim introduce a bill on advanced AI models that pose risks
Mark Warner, Brian Schatz and Andy Kim introduced a bill on September 24, 2026 that would require federal access only to advanced AI models that pose risks, at least 45 calendar days before they are brought to market. The legislation remains a proposal and would also require incident reporting in certain critical infrastructure.

Warner, Schatz and Kim introduce a proposal to regulate the risks of advanced AI
U.S. Senators Mark Warner, Brian Schatz and Andy Kim introduced the Artificial Intelligence Risk Management and Security Act of 2026 on September 24, 2026, Warner’s office announced. The bill would require developers of only the advanced AI models that pose risks as defined in the legislation to provide federal authorities with technical access at least 45 calendar days before bringing them to market. These provisions are proposed, with no requirements currently in effect.
The scope would include models, or systems combining several models, capable of performing tasks that present serious risks at a high level of proficiency. It would also cover those that could be modified to do so. The risks addressed concern national security, national economic security, and public health or safety.
The board would have access to the model’s parameters and software
The proposed legislation provides for access to the weights, configuration and software components needed to operate the model. Weights are the parameters learned during training. Access would include the necessary runtime environments and libraries. The period of at least 45 days would apply to the model’s introduction into interstate or foreign commerce.
This access would supplement providers’ testing with a federal assessment of the model’s capabilities before it is brought to market. Providing these components to the board would not involve making the weights publicly available or granting automatic access to training data. This access would not constitute general authorization to bring the model to market.
A permanent board would be established within the Department of Commerce. It would bring together representatives from that department and the Treasury, as well as NIST, the National Institute of Standards and Technology. CISA, the Cybersecurity and Infrastructure Security Agency, and the NSA, the National Security Agency, would also participate.
Outside experts could be independent of providers or affiliated with them. The board would develop standards, which the Secretary of Commerce would adopt through regulation and enforce.
The developers covered would have to develop, publish and follow a safety plan describing the model’s capabilities and risks, risk mitigation measures and the executive responsible.
A developer that violated the applicable standards would face a civil penalty of up to 250 000 dollars per violation. Each day of a continuing violation would constitute a separate offense. This amount would be a maximum, with no automatic penalty.
Confirmed incidents would trigger a reporting deadline
Reporting would apply to developers and providers of the advanced models covered, as well as critical infrastructure operators using AI to manage industrial control systems or other operational technologies. For this infrastructure, administrative use alone would fall outside this scope.
A confirmed safety or security incident would have to be reported within 30 days of confirmation. The deadline would be reduced to 72 hours if the incident posed an imminent threat to national security, critical infrastructure or public safety.
A safety incident would be an event that materially increased the risk to life, health, property or the environment.
A security incident as defined in the bill would be an event that materially increased the risk of unauthorized extraction of information about the AI system’s behavior or characteristics. The definition would also cover a material increase in the ability to manipulate the AI system in a way that compromised the confidentiality, integrity or availability of that system or adjacent systems. An extraction or compromise would not need to have already occurred for the event to fall within this definition.
Reporting would cover incidents during development, training, testing and deployment, including for nonpublic versions.
NIST, together with CISA, would create a secure reporting mechanism and a public national database of incidents and recurring flaws. Linking incidents and near misses associated with the same flaw would aim to identify common failures across systems and sectors.
Affected parties would be anonymized unless they consented otherwise. Sensitive reports and trade secrets would be protected, and the provider would be consulted before publication.
The incident database could thus help essential services learn from failures that occurred elsewhere. Assessment before a model is brought to market and the linking of incidents would address two distinct needs: examining a model’s capabilities in advance and identifying common flaws throughout its development and use.
Warner sought swift passage in the Senate
Warner intended to request passage by unanimous consent in the Senate, The Alexandria Brief reports, while anticipating difficulties. On September 24, Warner, Schatz and Kim spoke in the Senate about AI. The legislation remains a bill.
The bill concerns U.S. federal oversight and creates no new obligations in France. Advance access, reporting deadlines and penalties are, at this stage, provisions in proposed legislation.