{"check":null,"uid":"c64399e9f3699236","title":"AI Flaw Reporting and Security Enhancement Act","title_generated":false,"country":"США","organ":"Конгресс США","kind":"law","kind_name":"Законодательство","lang":"en","date":"2026-07-24","summary":"Создаёт при NIST программу добровольного сообщения о дефектах искусственного интеллекта (AI flaw) — условиях или поведении системы, нарушающих требования безопасности, причём злой умысел не обязателен. NIST вместе с CISA собирает промышленность, науку, НКО, органы стандартизации и гражданское общество, чтобы согласовать определения уязвимостей, отказов, инцидентов и злоупотреблений, таксономию дефектов безопасности и защищённости, меры серьёзности риска и нормы раскрытия. Появляется инфраструктура сбора и отслеживания сообщений — национальная база дефектов ИИ либо доработка существующей, с требованиями машиночитаемости и совместимости. Через три года после принятия закона NIST отчитывается перед Конгрессом.","snippet":"","topics":["Искусственный интеллект","Кибербезопасность"],"status":"ok","error":"","text_len":9173,"versions":1,"url":"https://www.congress.gov/bill/119-congress/hr/9333","first_seen":"2026-08-19","last_checked":"2026-09-17 01:58","relevance":"hit","score":38,"query":"","source_key":"congress_us","verdict":{"relevance":"hit","score":38,"topics":["Искусственный интеллект","Кибербезопасность"],"need_body":3,"authorities":[{"kind":"орган","name":"Cybersecurity and Infrastructure Security Agency","topic":"Кибербезопасность"},{"kind":"орган","name":"CISA","topic":"Кибербезопасность"}],"evidence":[{"topic":"Искусственный интеллект","term":"искусственн","weak":false,"pos":109,"ctx":"nd security enhancement act создаёт при nist программу добровольного сообщения о дефектах искусственного интеллекта (ai flaw) — условиях или поведении системы, нарушающих требования безопасности","zone":"название","weight":3},{"topic":"Искусственный интеллект","term":"artificial intelligence","weak":false,"pos":141,"ctx":"act this bill establishes a program to facilitate the voluntary reporting and tracking of artificial intelligence (ai) flaws, to be administered by the national institute of standards and technology (nis","zone":"текст","weight":1},{"topic":"Искусственный интеллект","term":"artificial intelligence","weak":false,"pos":1932,"ctx":"institute of standards and technology to develop a program for the voluntary reporting of artificial intelligence flaws and the acceleration of detection and monitoring of such flaws, and for other purpo","zone":"текст","weight":1},{"topic":"Искусственный интеллект","term":"artificial intelligence","weak":false,"pos":2544,"ctx":"institute of standards and technology to develop a program for the voluntary reporting of artificial intelligence flaws and the acceleration of detection and monitoring of such flaws, and for other purpo","zone":"текст","weight":1},{"topic":"Искусственный интеллект","term":"artificial intelligence","weak":false,"pos":2925,"ctx":"flaw reporting and security enhancement act''.  sec. 2. supporting voluntary reporting of artificial intelligence flaws.  (a) in general.--the director of the national institute of standards and technolo","zone":"текст","weight":1},{"topic":"Искусственный интеллект","term":"artificial intelligence","weak":false,"pos":3269,"ctx":"shall carry out a program to support the voluntary reporting, collection, and tracking of artificial intelligence flaws (in this section referred to as the ``program''). (b) activities.--in carrying out","zone":"текст","weight":1},{"topic":"Искусственный интеллект","term":"artificial intelligence","weak":false,"pos":3742,"ctx":": (1) establish common definitions and characterizations for relevant aspects relating to artificial intelligence flaws, including consideration of the following: (a) definitions of the following terms,","zone":"текст","weight":1},{"topic":"Кибербезопасность","term":"Cybersecurity and Infrastructure Security Agency","weak":false,"pos":3854,"ctx":"al Institute of Standards and Technology (NIST), in consultation with the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, shall carry out a program to support the voluntar","zone":"орган","weight":3},{"topic":"Кибербезопасность","term":"CISA","weak":false,"pos":263,"ctx":"темы, нарушающих требования безопасности, причём злой умысел не обязателен. NIST вместе с CISA собирает промышленность, науку, НКО, органы стандартизации и гражданское общество, чтобы","zone":"орган","weight":0}],"dropped":[{"topic":"Кибербезопасность","term":"cybersecurity","weak":false,"pos":1087,"ctx":"onal database to account for ai flaws. (nist currently administers a national database of cybersecurity vulnerabilities.) nist must consider certain topics when developing this infrastructure,","why":"одиночное упоминание (нужно 3)"},{"topic":"Кибербезопасность","term":"cybersecurity","weak":false,"pos":3090,"ctx":"al institute of standards and technology (nist), in consultation with the director of the cybersecurity and infrastructure security agency of the department of homeland security, shall carry ou","why":"одиночное упоминание (нужно 3)"}]},"last_changed":"2026-08-19","meta":{"congress":"119","billType":"HR","number":"9333","policyArea":"Science, Technology, Communications","subjects":["Computer security and identity theft","Computers and information technology","Consumer affairs","Data collection, sharing, protection","Performance measurement","Product safety and quality","Technology assessment"],"latestAction":"2026-06-25 Ordered to be Reported in the Nature of a Substitute by the Yeas and Nays: 35 - 0."},"source_url":"https://www.congress.gov/bill/119-congress/hr/9333","text":"SUMMARY\nAI Flaw Reporting and Security Enhancement Act\nThis bill establishes a program to facilitate the voluntary reporting and tracking of artificial intelligence (AI) flaws, to be administered by the National Institute of Standards and Technology (NIST).\nIn carrying out this program, NIST must seek to convene various stakeholders to establish common definitions for terms related to AI flaws and criteria for the classification of AI flaws (e.g., security-related flaws and safety-related flaws). The group must also support the development of technical standards and guidance related to detecting, managing, and disclosing AI flaws and prioritizing the remediation of such flaws.\nFurther, NIST must develop, or enter into cooperative agreements with institutions of higher education or research institutions to develop, infrastructure for the voluntary reporting, collection, and tracking of AI flaws. This must include a national database of AI flaws or the modification of an existing national database to account for AI flaws. (NIST currently administers a national database of cybersecurity vulnerabilities.) NIST must consider certain topics when developing this infrastructure, including the interoperability of the infrastructure with relevant existing systems, standards, and best practices.\nWithin three years of the bill’s enactment, NIST must report to Congress on the implementation of these provisions.\nUnder the bill, an AI flaw is a set of conditions or behaviors that allow for the violation of certain policies (e.g., safety or security policies) and is not necessarily associated with malicious intent.\n\nFULL TEXT\n[Congressional Bills 119th Congress]\n[From the U.S. Government Publishing Office]\n[H.R. 9333 Introduced in House (IH)]\n\n<DOC>\n\n119th CONGRESS\n2d Session\nH. R. 9333\n\nTo direct the Director of the National Institute of Standards and\nTechnology to develop a program for the voluntary reporting of\nartificial intelligence flaws and the acceleration of detection and\nmonitoring of such flaws, and for other purposes.\n\n_______________________________________________________________________\n\nIN THE HOUSE OF REPRESENTATIVES\n\nJune 18, 2026\n\nMs. Ross (for herself, Mr. Hurd of Colorado, and Mr. Beyer) introduced\nthe following bill; which was referred to the Committee on Science,\nSpace, and Technology\n\n_______________________________________________________________________\n\nA BILL\n\nTo direct the Director of the National Institute of Standards and\nTechnology to develop a program for the voluntary reporting of\nartificial intelligence flaws and the acceleration of detection and\nmonitoring of such flaws, and for other purposes.\n\nBe it enacted by the Senate and House of Representatives of the\nUnited States of America in Congress assembled,\n\nSECTION 1. SHORT TITLE.\n\nThis Act may be cited as the ``AI Flaw Reporting and Security\nEnhancement Act''.\n\nSEC. 2. SUPPORTING VOLUNTARY REPORTING OF ARTIFICIAL INTELLIGENCE\nFLAWS.\n\n(a) In General.--The Director of the National Institute of\nStandards and Technology (NIST), in consultation with the Director of\nthe Cybersecurity and Infrastructure Security Agency of the Department\nof Homeland Security, shall carry out a program to support the\nvoluntary reporting, collection, and tracking of artificial\nintelligence flaws (in this section referred to as the ``program'').\n(b) Activities.--In carrying out the program, the Director of the\nNIST shall seek to convene appropriate representatives of industry,\nacademia, nonprofit organizations, standards development organizations,\ncivil society groups, and appropriate Federal departments and agencies\nto carry out the following:\n(1) Establish common definitions and characterizations for\nrelevant aspects relating to artificial intelligence flaws,\nincluding consideration of the following:\n(A) Definitions of the following terms, as such\nterms relate to artificial intelligence:\n(i) Vulnerabilities.\n(ii) Failure modes.\n(iii) Accidents.\n(iv) Failures.\n(v) Hazards.\n(vi) Catastrophes.\n(vii) Misuse.\n(viii) Incidents.\n(ix) Adverse events.\n(B) Taxonomies to classify such artificial\nintelligence flaws based on relevant characteristics,\nimpacts, or other appropriate criteria to enable the\nmanagement and prioritization of such flaws, including\nthe following:\n(i) Artificial intelligence security-\nrelated flaws.\n(ii) Artificial intelligence safety-related\nflaws.\n(2) Support the development of technical standards and\nguidance related to artificial intelligence flaws and processes\nfor managing such flaws.\n(3) Support the development of methods, which may include\nmeasures of severity or risk associated with artificial\nintelligence flaws, to enable prioritization of remediation\nactivities of such flaws.\n(4) Support the development of technical approaches which\naccelerate detection and monitoring of artificial intelligence\nflaws.\n(5) Identify and provide guidelines, best practices,\nmethodologies, procedures, and processes for reporting,\ncollecting, and tracking artificial intelligence flaws across\ndifferent sectors and use cases.\n(6) Support the development of standardized reporting and\ndocumentation mechanisms, including automated mechanisms, that\nwould help provide information, including public information,\nregarding artificial intelligence flaws.\n(7) Support the development of norms for appropriate\ndisclosure and reporting of artificial intelligence flaws,\nincluding when it is appropriate to publicly disclose such\nflaws.\n(c) Development of Infrastructure for the Measurement and\nMonitoring of Artificial Intelligence Flaws.--\n(1) In general.--In carrying out the program, the Director\nof NIST shall, in consultation with representatives of\nindustry, academia, nonprofit organizations, standards\ndevelopment organizations, civil society groups, appropriate\npublic sector entities, and appropriate Federal departments and\nagencies, develop, or enter into cooperative agreements with\none or more eligible entity designated by the Director to\ndevelop, infrastructure for the voluntary reporting,\ncollection, and tracking of artificial intelligence flaws. Such\ninfrastructure shall include a national database of artificial\nintelligence flaws or the modification of an existing national\ndatabase to account for such flaws, as determined appropriate\nby the Director. Such database may be maintained by NIST or one\nor more eligible entities designated by the Director\n(2) Considerations.--In carrying out this subsection, the\nDirector shall consider the following:\n(A) Technical standards and best practices\nregarding machine-readability.\n(B) Interoperability of the infrastructure\ndescribed in paragraph (1) with relevant existing\nstandards, best practices, and systems.\n(C) Future updates to the infrastructure described\nin paragraph (1) that may include additional types of\ninformation and taxonomies relevant to new stakeholders\nand coordination mechanisms.\n(D) Relevant policies, procedures, and norms\nregarding dissemination of reported artificial\nintelligence flaws and public disclosures.\n(d) Report.--Not later than three years after the date of the\nenactment of this Act, the Director of NIST shall submit to Congress a\nreport on the implementation of this section. Such report shall include\nthe following:\n(1) Findings from the multi-stakeholder activities under\nsubsections (b) and (c).\n(2) A description of the infrastructure developed pursuant\nto subsection (c), including a description of the national\ndatabase referred to in such subsection.\n(3) An assessment of and recommendations for establishing\nreporting and collection mechanisms by which industry,\nacademia, nonprofit organizations, standards development\norganizations, civil society groups, and appropriate public\nsector entities may voluntarily share standardized information\nregarding artificial intelligence flaws.\n(e) Definitions.--In this section:\n(1) Artificial intelligence.--The term ``artificial\nintelligence'' has the meaning given such term in section 5002\nof the National Artificial Intelligence Initiative Act of 2020\n(15 U.S.C. 9401).\n(2) Artificial intelligence flaw.--The term ``artificial\nintelligence flaw'' means a set of conditions or behaviors that\nallow the violation of an explicit or implicit policy related\nto the safety, security, or other undesirable effects from use\nof an artificial intelligence system, including artificial\nintelligence vulnerabilities and artificial intelligence\nincidents, and which is not dependent on the presence of\nmalicious intent or related harm.\n(3) Artificial intelligence system.--The term ``artificial\nintelligence system'' has the meaning given such term in\nsection 7223 of the Advancing American AI Act (40 U.S.C. 11301\nnote; as enacted as part of title LXXII of division G of the\nJames M. Inhofe National Defense Authorization Act for Fiscal\nYear 2023; Public Law 117-263).\n(4) Eligible entity.--The term ``eligible entity'' means an\ninstitution of higher education (as such term is defined in\nsection 101(a) of the Higher Education Act of 1965 (20 U.S.C.\n1001)), a research institution (as such term is defined in\nsection 9 of the Small Business Act (15 U.S.C. 638(e)(8)), or\nconsortia thereof.\n<all>","changes":[],"passport":{"data":{"act":{"jurisdiction":"США","title_official":"AI Flaw Reporting and Security Enhancement Act","title_short":"Закон о сообщении о недостатках ИИ и повышении уровня безопасности","level":"законопроект","date_adopted":"2026-06-18","date_in_force":"","date_version":"","phased":"","status":"законопроект: на рассмотрении","sunset":"","regulator":"Национальный институт стандартов и технологий (NIST)","related":""},"goal":{"problem":"Недостаточная прозрачность и координация в выявлении и устранении недостатков систем искусственного интеллекта","goal":"Создание инфраструктуры для добровольного выявления и устранения недостатков ИИ","targets":"","scope":"Искусственный интеллект, безопасность информационных технологий","exclusions":""},"subjects_note":{"protected":""},"subjects":[{"role":"Госорган","who":"NIST","criteria":"","count":"нет данных"}],"norms":[{"address":"Sec. 2(b)(1)","addressee":"Госорган","essence":"Установить общие определения и характеристики аспектов, связанных с недостатками ИИ","type":"обязанность","mechanism":"информирование","cost_channel":"административные","cost_kind":"разовые","trigger":"до начала деятельности","sanction":"","refs":"","form":"не установлена","in_force":"","ru_analog":"требует проверки"},{"address":"Sec. 2(b)(2)","addressee":"Госорган","essence":"Поддержать разработку технических стандартов и руководств, касающихся недостатков ИИ и процессов управления ими","type":"обязанность","mechanism":"информирование","cost_channel":"административные","cost_kind":"разовые","trigger":"до начала деятельности","sanction":"","refs":"","form":"не установлена","in_force":"","ru_analog":"требует проверки"},{"address":"Sec. 2(b)(3)","addressee":"Госорган","essence":"Поддержать разработку методов измерения серьезности рисков, связанных с недостатками ИИ, для приоритезации их исправления","type":"обязанность","mechanism":"информирование","cost_channel":"административные","cost_kind":"разовые","trigger":"до начала деятельности","sanction":"","refs":"","form":"не установлена","in_force":"","ru_analog":"требует проверки"},{"address":"Sec. 2(b)(4)","addressee":"Госорган","essence":"Поддержать развитие подходов, ускоряющих выявление и мониторинг недостатков ИИ","type":"обязанность","mechanism":"информирование","cost_channel":"административные","cost_kind":"разовые","trigger":"до начала деятельности","sanction":"","refs":"","form":"не установлена","in_force":"","ru_analog":"требует проверки"},{"address":"Sec. 2(b)(5)","addressee":"Госорган","essence":"Определить и предоставить рекомендации, лучшие практики, методологии, процедуры и процессы для отчетности, сбора и мониторинга недостатков ИИ","type":"обязанность","mechanism":"информирование","cost_channel":"административные","cost_kind":"разовые","trigger":"до начала деятельности","sanction":"","refs":"","form":"не установлена","in_force":"","ru_analog":"требует проверки"},{"address":"Sec. 2(b)(6)","addressee":"Госорган","essence":"Поддержать создание стандартных механизмов отчетности и документирования информации о недостатках ИИ, включая автоматизированные механизмы","type":"обязанность","mechanism":"информирование","cost_channel":"административные","cost_kind":"разовые","trigger":"до начала деятельности","sanction":"","refs":"","form":"не установлена","in_force":"","ru_analog":"требует проверки"},{"address":"Sec. 2(b)(7)","addressee":"Госорган","essence":"Поддержать разработку норм надлежащего раскрытия и отчетности о недостатках ИИ, включая случаи публичного раскрытия таких недостатков","type":"обязанность","mechanism":"информирование","cost_channel":"административные","cost_kind":"разовые","trigger":"до начала деятельности","sanction":"","refs":"","form":"не установлена","in_force":"","ru_analog":"требует проверки"},{"address":"Sec. 2(c)(1)","addressee":"Госорган","essence":"Разработать инфраструктуру для добровольной отчетности, сбора и мониторинга недостатков ИИ, включающую национальную базу данных недостатков ИИ","type":"обязанность","mechanism":"информирование","cost_channel":"административные","cost_kind":"разовые","trigger":"до начала деятельности","sanction":"","refs":"","form":"не установлена","in_force":"","ru_analog":"требует проверки"},{"address":"Sec. 2(c)(2)","addressee":"Госорган","essence":"Учесть технические стандарты и наилучшие практики относительно машинно-читаемой формы базы данных недостатков ИИ","type":"обязанность","mechanism":"информирование","cost_channel":"административные","cost_kind":"разовые","trigger":"до начала деятельности","sanction":"","refs":"","form":"не установлена","in_force":"","ru_analog":"требует проверки"},{"address":"Sec. 2(d)","addressee":"Госорган","essence":"Отчёт перед Конгрессом через три года после вступления закона в силу о реализации программы","type":"обязанность","mechanism":"информирование","cost_channel":"административные","cost_kind":"разовые","trigger":"по истечении трёх лет со дня вступления закона в силу","sanction":"","refs":"","form":"не установлена","in_force":"","ru_analog":"требует проверки"}]},"made_by":"GigaChat-2-Max","made_at":"2026-09-10 12:42:26","edited_at":null,"edited_by":null}}