Mike D. Rogers
Representative for Alabama · Republican · United States
“(8) An assessment of NATO's deterrence efforts in Romania, including a description and evaluation of-- (A) United States force posture in Romania, including any new rotations to Romania intended to enhance deterrence following the 2025 decision to end the rotational presence of a United States brigade; (B) consultations with NATO allies r…”
“(8) An assessment of NATO's deterrence efforts in Romania, including a description and evaluation of-- (A) United States force posture in Romania, including any new rotations to Romania intended to enhance deterrence following the 2025 decision to end the rotational presence of a United States brigade; (B) consultations with NATO allies r…”
“(a) Requirement for Risk-based Approach.--Section 3843 of title 10, United States Code, is amended to read as follows: ``Sec. 3843. Contractor business systems: monitoring and surveillance standards ``(a) Requirement for Risk-based Approach.--The Secretary shall implement an agile, streamlined risk-based approach to surveillance of contra…”
“(a) Requirement for Risk-based Approach.--Section 3843 of title 10, United States Code, is amended to read as follows: ``Sec. 3843. Contractor business systems: monitoring and surveillance standards ``(a) Requirement for Risk-based Approach.--The Secretary shall implement an agile, streamlined risk-based approach to surveillance of contra…”
“(b) Modification of Certain Certifications and Assessments.-- (1) Certifications.--Section 1249(b) of the National Defense Authorization Act for Fiscal Year 2026 (Public Law 119-60) is amended-- (A) in the matter preceding paragraph (1), by striking ``The certification described'' and inserting following: ``(1) In general.--Except as prov…”
“(b) Objectives.--The Commander shall ensure that the Cognitive Performance Enhancement Program-- (1) improves readiness, resilience, and recovery, using evidence-based holistic and proactive high-performance brain training that has a validated ability to scale cost- effectively across the special operations forces enterprise; [[Page H4842…”
The complete record
Every one of 4,912 lines we hold for Mike D. Rogers, in date order, each linked to its source. Free to read, in full, without an account. Page 16 of 99.
“(f) Definition.--In this section, the term ``Department enterprise AI platform'' means a centrally managed platform that hosts or provides AI services or applications for use across multiple elements of the Department, rather than for a single program, system, or mission application. SEC. 1524. UPDATE OF POLICY ON AUTONOMOUS AND ARTIFICIAL INTELLIGENCE-ENABLED SYSTEMS.”
“(d) Compliance With Requirements.--The Secretary shall ensure that the Framework complies with all applicable requirements for test and evaluation of Department systems in accordance with applicable law, policy, and guidance. (e) Metrics and Reporting.--The Chief Digital and Artificial Intelligence Officer shall-- (1) establish metrics to measure the time required to evaluate, authorize, deploy, and update AI systems on Department enterprise AI platforms; and (2) in each of fiscal years 2027, 2028, 2029, and 2030, submit an annual report to the congressional defense committees on progress toward achieving the objective stated in subsection (a).”
“(c) Integration With Other Frameworks.--The Secretary shall ensure that the rapid deployment of AI systems under the Framework is achieved in a manner that maintains security standards through integration with other relevant frameworks, including-- (1) the plans, strategies, and other matters relating to AI required by section 1544 of the National Defense Authorization Act for Fiscal Year 2024 (10 U.S.C. 4001 note); (2) the Defense-wide policy required by section 1512 of the National Defense Authorization Act for Fiscal Year 2026 (10 U.S.C. 394 note); and (3) the framework and other requirements required by section 1513 of the National Defense Authorization Act for Fiscal Year 2026 (10 U.S.C. 2224 note).”
“(5) Streamlined system authorization processes.--In coordination with the Chief Information Officer of the Department, establishment of streamlined processes for authorization of AI systems deployed on Department enterprise AI platforms, including reuse of authorization artifacts, common control inheritance, and continuous monitoring capabilities. (6) Registry and governance systems.--Implementation of registry and governance processes to track version history, performance, security status, and compliance for AI systems deployed on Department enterprise AI platforms.”
“(3) Security testing and evaluation.--Establishment of security testing and evaluation capabilities to support security assessments for AI systems deployed on Department enterprise AI platforms, including adversarial testing, supply chain risk assessments, and other security testing appropriate for AI systems, consistent with existing cybersecurity and test and evaluation policies. (4) Multi-classification deployment.--Establishment of capability to deploy AI systems on Department enterprise AI platforms across multiple classification levels, as appropriate, with appropriate security controls and data isolation.”
“(b) Elements.--The Framework shall include the following elements: (1) Vendor and model onboarding process.--Establishment of standardized processes for deploying AI systems onto Department enterprise AI platforms, including security reviews, technical assessments, and integration with other Department systems and platforms. (2) Common definitions and categories.--Common definitions or categories for AI systems deployed on Department enterprise AI platforms, including systems with agentic capabilities, to support acquisition clarity, testing, authorization, and operational adoption.”
“(a) Framework Required.--The Secretary of Defense, acting through the Chief Digital and Artificial Intelligence Officer of the Department of Defense, shall establish a framework for the rapid deployment of artificial intelligence (``AI''), to be known as the Artificial Intelligence Model Rapid Deployment Framework (in this section referred to as the ``Framework''), to enable the evaluation, authorization, and deployment of AI systems on Department enterprise AI platforms, as appropriate. The objective of the Framework shall be to enable deployment of such systems on such platforms within 30 days after public availability.”
“2224 note) is amended in subsection (a)-- (1) by amending paragraph (2) to read as follows: ``(2) Guidance for department systems and devices.--Not later than 30 days after the date of the enactment of the National Defense Authorization Act for Fiscal Year 2027, the Secretary of Defense shall issue Department of Defense-wide guidance for the identification of covered artificial intelligence companies and processes for the exclusion and removal of artificial intelligence developed by such companies from systems and devices of the Department.''; and (2) in paragraph (3)(B), by striking ``if'' and inserting ``on and after the date that is 90 days after the date on which''. SEC. 1523. ARTIFICIAL INTELLIGENCE MODEL RAPID DEPLOYMENT FRAMEWORK.”
“(2) Report.--Not later than one year after the date of the enactment of this Act, the Secretary shall submit to the congressional defense committees a report containing-- (A) the revised regulations required by subsection (b); and (B) any remaining barriers to full and timely implementation of such revised regulations. SEC. 1522. REQUIREMENT FOR GUIDANCE AND PROHIBITION ON USE OF ARTIFICIAL INTELLIGENCE OF CERTAIN ARTIFICIAL INTELLIGENCE COMPANIES. Section 1532 of the National Defense Authorization Act for Fiscal Year 2026 (10 U.S.C.”
“(c) Updates and Report.-- (1) Written updates.--Not later than 180 days after the date of the enactment of this Act, and every 90 days thereafter until the revised regulations required by subsection (b) are issued, the Secretary shall submit to the congressional defense committees a written update containing-- (A) a description of the progress made toward completing the revised regulations, along with specific actions taken and remaining milestones; (B) the most up-to-date working draft of the revised regulations, or an outline of such working draft in sufficient detail to demonstrate the manner in which, and the extent to which, the working draft implements section 2221; (C) a description of any anticipated barriers to full and timely issuance of the revised regulations and full and timely implementation of such regulations; (D) any recommendations for legislation to fully implement such revised regulations; and (E) if the Secretary has not issued such revised regulations within the period described in subsection (b), an explanation for the delay and the anticipated timeline for issuing the revised regulations.”
“1884). ``(b) Definition.--In this section, the term `lifecycle' includes stages such as development, prototyping, testing, fielding, modification, upgrading, licensing, sustainment, and retirement.''. (b) Issuance of Revised Regulations.-- (1) In general.--Not later than one year after the date of the enactment of this Act, the Secretary of Defense shall issue revised regulations to implement section 2221 of title 10, United States Code, as added by this section. (2) Notification.--Not later than 30 days after the Secretary issues the revised regulations under paragraph (1), the Secretary shall notify the congressional defense committees of the revisions.”
“Such guidance shall-- ``(1) reflect that amounts appropriated for operations and maintenance, procurement, or research, development, test, and evaluation may be used at each stage in the lifecycle of a software capability, consistent with applicable law; ``(2) clarify that such amounts may be used, as appropriate, for all activities at each such stage in the lifecycle of a software capability; ``(3) provide that, for any program or activity of the Department that requires a new software capability, the appropriations account primarily available for that program or activity shall be available for that new software capability; ``(4) not impose restrictions on the availability of funds for software capabilities, except as required by law; and ``(5) maintain consistency, to the maximum extent practicable, with Recommendation 11A of the final report (dated March 2024) of the Commission on Planning, Programming, Budgeting, and Execution Reform, as submitted under section 1004 of the National Defense Authorization Act for Fiscal Year 2022 (Public Law 117-81; 135 Stat.”
“Availability of appropriations accounts for full lifecycle of software capabilities: regulations ``(a) In General.--The Secretary of Defense shall ensure that the relevant financial management regulations of the Department provide guidance for the budgeting and execution of funds for software capabilities.”
“(8) The term ``security vulnerability'' has the meaning given that term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650). (9) The term ``simplified acquisition threshold'' has the meaning given that term in section 134 of title 41, United States Code. Subtitle B--Information Technology and Artificial Intelligence SEC. 1521. SOFTWARE PLANNING, PROGRAMMING, BUDGETING, AND EXECUTION REFORM. (a) In General.--Chapter 131 of title 10, United States Code, is amended by inserting after section 2220 the following new section: ``Sec. 2221.”
“(2) The term ``covered contractor'' means a contractor (as defined in section 7101 of title 41, United States Code)-- (A) whose contract is in an amount the same as or greater than the simplified acquisition threshold; or (B) that operates, manages, or maintains a Federal information system (as defined by section 11331 of title 40, United Stated Code) on behalf of an agency. (3) The term ``DFARS'' means the Department of Defense Supplement to the Federal Acquisition Regulation. (4) The term ``Executive department'' has the meaning given that term in section 101 of title 5, United States Code. (5) The term ``FAR'' means the Federal Acquisition Regulation. (6) The term ``NIST'' means the National Institute of Standards and Technology. (7) The term ``OMB'' means the Office of Management and Budget.”
“(4) Waiver.--The Chief Information Officer of the Department of Defense, in consultation with the National Manager for National Security Systems, may waive the security vulnerability disclosure policy requirements under paragraph (2) if the Chief Information Officer-- (A) determines that the waiver is necessary in the interest of national security or research purposes; and (B) not later than 30 days after granting a waiver, submits a notification and justification (including information about the duration of the waiver) to the Committees on Armed Services of the House of Representatives and the Senate. (f) Definitions.--In this section: [[Page H4862]] (1) The term ``agency'' has the meaning given the term in section 3502 of title 44, United States Code.”
“(2) Revisions.--Not later than 180 days after the date on which the review required under subsection (a) is completed, the Secretary shall revise the DFARS as necessary to incorporate requirements for covered contractors to receive information about a potential security vulnerability relating to an information system owned or controlled by a contractor, in performance of the contract. (3) Elements.--The Secretary shall ensure that the revision to the DFARS described in this subsection is carried out in accordance with the requirements of paragraphs (1) and (2) of subsection (c).”
“(e) Department of Defense Supplement to the Federal Acquisition Regulation.-- (1) Review.--Not later than 180 days after the date of the enactment of this Act, the Secretary of Defense shall review the Department of Defense Supplement to the Federal Acquisition Regulation contract requirements and language for contractor vulnerability disclosure programs and develop updates to such requirements designed to ensure that covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines for contractors as required under section 5 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g-3c).”
“(d) Waiver.--The head of an agency may waive the security vulnerability disclosure policy requirement under subsection (b) if-- (1) the agency Chief Information Officer determines that the waiver is necessary in the interest of national security or research purposes; and (2) if, not later than 30 days after granting a waiver, such head submits a notification and justification (including information about the duration of the waiver) to the Committee on Oversight and Government Reform of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate.”
“(c) Elements.--The update to the FAR pursuant to subsection (b) shall-- (1) to the maximum extent practicable, align with the security vulnerability disclosure process and coordinated disclosure requirements relating to Federal information systems under sections 5 and 6 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g-3c and 278g-3d); and (2) to the maximum extent practicable, be aligned with industry best practices and Standards 29147 and 30111 of the International Standards Organization (or any successor standard) or any other appropriate, relevant, and widely used standard.”
“(2) Contents.--The recommendations required by paragraph (1) shall include updates to such requirements designed to ensure that covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines for contractors as required under section 5 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g-3c). (b) Procurement Requirements.--Not later than 180 days after the date on which the recommended contract language developed pursuant to subsection (a) is received, the Federal Acquisition Regulation Council shall review the recommended contract language and update the FAR as necessary to incorporate requirements for covered contractors to receive information about a potential security vulnerability relating to an information system owned or controlled by a contractor, in performance of the contract.”
“(a) Recommendations.-- (1) In general.--Not later than 180 days after the date of the enactment of this Act, the Director of the Office of Management and Budget, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, the Director of the National Institute of Standards and Technology, and any other appropriate head of an Executive department, shall-- (A) review the Federal Acquisition Regulation contract requirements and language for contractor vulnerability disclosure programs; and (B) recommend updates to such requirements and language to the Federal Acquisition Regulation Council.”
“(2) Report and briefing.--Not later than the date that is six months after the date of the enactment of this Act, the Secretary shall provide the congressional defense committees with a report and briefing on the plan created under paragraph (1). The Secretary shall not carry out the pilot program until after the Secretary has provided the report and briefing. (d) Scope.--In carrying out the pilot program, the Secretary shall establish an initial cohort of not more than 20 members of the civilian cybersecurity reserve corps. SEC. 1507. FEDERAL CONTRACTOR VULNERABILITY DISCLOSURE POLICY.”
“(c) Planning.-- (1) Plan.--Prior to carrying out the pilot program required by subsection (a), the Secretary shall create a detailed written plan for the program, which shall include-- (A) a concept of operations for the civilian cybersecurity reserve corps; (B) an assessment of the necessary legal and contractual requirements; (C) recruitment, assessment, and selection criteria and methodologies; (D) talent management processes and system prototypes; (E) defining the initial mission set and organization structure of the civilian cybersecurity reserve corps; (F) metrics with respect to cost and benefits that will be used to inform the Secretary's evaluation of the pilot program; and (G) any other matters that the Secretary considers appropriate.”
“(b) Consideration of Prior Report.--In conducting the pilot program required by subsection (a), the Secretary shall take into consideration the findings and recommendations of the report required by section 1540 of the James M. Inhofe National Defense Authorization Act for Fiscal Year 2023 (Public Law 117-263; 136 Stat. 2914) (titled ``Independent Assessment of Civilian Cybersecurity Reserve for Department of Defense'' and dated October 2025).”
“(2) Follow-on briefing.--Not later than one year after the date of the enactment of this Act, the Secretary shall brief the congressional defense committees with an update on the implementation of the pilot program, including findings, data, and mission outcomes. SEC. 1506. CIVILIAN CYBERSECURITY RESERVE CORPS PILOT PROGRAM. (a) Program Required.--The Secretary of Defense shall carry out a pilot program to further evaluate the feasibility and advisability of creating and maintaining a civilian cybersecurity reserve corps to enable the Department of Defense and military services to provide qualified civilian manpower to the Department of Defense to effectively respond to significant cyber incidents or to assist in solving other exceptionally difficult cyber workforce-related challenges.”
“(d) Briefings.-- (1) Initial briefing.--Not later than 120 days after the date of the enactment of this Act, the Secretary, in consultation with the Under Secretary, shall brief the congressional defense committees on the implementation of the pilot program, including-- (A) coordination between and among program offices, the Under Secretary, the commanders of the combatant commands, the operational component, and industry; (B) methods to reduce technical risk and promote competition, including shifting integration risk to industry through pre-integration and demonstration; and (C) plans to accelerate prototyping, independent assessment, and operational integration.”
“(c) Modular Open Systems Architecture.--The pilot program shall employ modular open systems architecture standards and open interfaces to ensure interoperability, portability, and cybersecurity across platforms. The Secretary shall leverage lessons from prior autonomy and control system efforts while avoiding approaches that limit competition, inhibit innovation, or place primary integration responsibility on the Government where industry solutions are available.”
“(a) Establishment.--The Secretary of the Navy, in consultation with the Under Secretary of Defense for Research and Engineering, shall establish a pilot program, to be known as the Autonomous Mission Pre-Integration Pilot Program, to assess industry-led approaches for pre-integration of autonomy services and multi-mission payloads on medium unmanned surface vehicles, utilizing a common, cybersecure operating system to enable cross-platform collaboration. (b) Objectives.--The pilot program shall develop and validate rapidly composable, multi-mission capabilities to support distributed maritime operations in contested environments, including pre-integration of-- (1) autonomy services and mission software; (2) kinetic and non-kinetic systems; (3) advanced sensors and communications; and (4) edge-based collaborative artificial intelligence.”
“(b) Scope of Activities.--The activities described in subsection (a) shall, at a minimum, include-- (1) assessment of vulnerabilities and resilience of critical infrastructure and operational technology systems that support military operations, defense support to civil authorities, and homeland defense missions; (2) coordination with relevant Federal departments and agencies, State, local, Tribal, and territorial authorities, and private sector owners and operators, as appropriate; and (3) integration of cyber, operational technology, and physical effects relevant to disruption, degradation, or compromise of such systems. SEC. 1505. PILOT PROGRAM FOR AUTONOMOUS MISSION INTEGRATION OF UNMANNED SURFACE VEHICLES.”
“[[Page H4861]] (g) Briefing.--Not later than 45 days after the date of the enactment of this Act, the Secretary shall provide a briefing to the congressional defense committees on preliminary findings of the review. SEC. 1504. INCLUSION OF CRITICAL INFRASTRUCTURE AND OPERATIONAL TECHNOLOGY SECURITY IN COMBATANT COMMAND PLANNING AND READINESS EXERCISES. (a) Requirement.--The Secretary of Defense shall direct the commanders of the combatant commands, consistent with the authorities provided under sections 164 and 167b of title 10, United States Code, to incorporate critical infrastructure security and operational technology security considerations into-- (1) planning activities conducted to execute national defense strategies; and (2) joint and combined planning, training, and readiness exercises.”
“(2) Elements.--The report shall include-- (A) identification of the official designated as the single accountable official responsible for the cybersecurity of Department of Defense information networks, as specified in subsection (a)(1)(A); (B) a description of any realignment, consolidation, or modification made, or to be made, to the roles, responsibilities, relationships, and authorities of the officials, offices, elements, and organizations reviewed, as specified in subsection (a)(3)(A); (C) a description of any reassignment of functions, personnel, and resources made, or to be made, among the officials, offices, elements, and organizations reviewed, as specified in subsection (a)(3)(B); (D) a description of any duplicative functions eliminated, or to be eliminated, as set forth in subsection (a)(3)(C); (E) a description of any clarification or revision made, or to be made, to reporting relationships and lines of authority, as set forth in subsection (a)(3)(D); (F) a mapping of the responsibilities and authorities assigned as of the date of the enactment of this Act to each respective official, office, element, or organization reviewed (including an identification of whether the responsibility or authority is required by law to be assigned to such official, office, element, or organization, and an mapping of the responsibilities and authorities as they will be assigned after completion of the activities specified in subsection (a)(3); (G) a timeline for implementation of the activities specified in subsection (a)(3), under which all such activities shall be implemented not later than one year after the date of the enactment of this Act; (H) identification of any legislative recommendations, including any provisions of law requiring amendment, to fully implement the goals specified in subsection (a)(1) and the activities specified in subsection (a)(3); and (I) a justification for the new structure, including an explanation for how the new structure better achieves the goals specified in subsection (a)(1) than the current structure.”
“(f) Report.-- (1) In general.--Not later than 90 days after the date of the enactment of this Act, the Secretary of Defense shall submit to the congressional defense committees a report on the results of the review conducted under subsection (a).”
“(d) Limitation on Reassignment or Elimination of Function.--The Secretary may not reassign or eliminate a function associated with an official, office, element, or organization for the purpose of carrying out this section unless the Secretary submits to the congressional defense committees a notification of the reassignment or elimination of the function and a period of 15 days has elapsed after the date on which the notification was submitted. (e) Rule of Construction.--Nothing in this section shall be construed to authorize the Secretary of Defense to modify, transfer, eliminate, or otherwise alter any role, responsibility, relationship, authority, function, or any other matter expressly required by law.”
“(b) Preservation of Functions.--In carrying out subsection (a), the Secretary shall ensure that all functions necessary for the governance, defense, and operation of Department of Defense information networks are maintained, regardless of the organizational structure to which such functions are assigned. (c) Limitation on Establishment of New Office or Organization.--The Secretary may not establish a new office or organization for the purpose of carrying out this section unless the Secretary determines that such establishment is necessary to achieve the goals specified in subsection (a)(1) and consistent with applicable law.”
“(3) Realignment.--As a result of the review, and in order to achieve the goals specified in paragraph (1), the Secretary may, consistent with applicable law-- (A) realign, consolidate, or modify the roles, responsibilities, relationships, and authorities of the officials, offices, elements, and organizations specified in paragraph (2); (B) reassign functions, personnel, and resources among such officials, offices, elements, and organizations; (C) eliminate duplicative functions; and (D) clarify or revise reporting relationships and lines of authority.”
“(2) Scope.--The review conducted under this subsection shall include an assessment of the roles, responsibilities, relationships, and authorities among-- (A) the Chief Information Officer of the Department of Defense; (B) the Assistant Secretary of Defense for Cyber Policy; (C) the Principal Cyber Advisor to the Secretary of Defense; (D) the Commander of the United States Cyber Command; (E) the Department of Defense Cyber Defense Command; and (F) such other offices, elements, or organizations as the Secretary determines appropriate.”
“(C) Eliminate structural overlap, duplication, and fragmentation across organizations responsible for cybersecurity, information technology, network defense, and defensive cyber operations. (D) Reduce overlapping responsibilities and ensure alignment of policy, strategy, budgetary oversight, and operational support necessary for the cybersecurity of Department of Defense information networks in an evolving threat environment.”
“(a) Review and Realignment.-- (1) Review required.--The Secretary of Defense shall conduct a comprehensive review of the roles, responsibilities, relationships, authorities, and governance structures relating to cybersecurity, information technology, network defense, and defensive cyber operations within the Department of Defense in order to achieve the following goals: (A) Establish clear accountability for the cybersecurity of Department of Defense information networks, including identification of one official designated as the single accountable official responsible for the cybersecurity of Department of Defense information networks. (B) Improve the operational effectiveness, responsiveness, and unity of effort of Department-wide cybersecurity, information technology, network defense, and defensive cyber operations.”
“``(3) The term `covered AI vulnerability' means an exploitable weakness, vulnerability, or systemic issue in an artificial intelligence system or related component that could materially affect mission performance, compromise system integrity, create safety risk, or result in unauthorized or unintended behavior.''. SEC. 1503. REVIEW AND REALIGNMENT OF DEPARTMENT OF DEFENSE CYBERSECURITY RESPONSIBILITIES.”
“``(2) The term `covered AI incident' means an event in which an artificial intelligence system-- ``(A) causes unintended operational, safety, or security harm; ``(B) operates outside authorized parameters or approved safety, legal, or mission guardrails; ``(C) materially degrades mission performance or reliability in a real-world or operationally representative environment; ``(D) fails to respond to an operator disengage command; ``(E) operates in a manner that, under reasonably foreseeable circumstances, could have resulted in significant unintended operational, safety, or security harm; or ``(F) operates in a manner that raises concerns regarding system control and autonomy.”
“``(2) Each report under this subsection shall be submitted in unclassified form but may include a classified annex. ``(j) Definitions.--In this section: ``(1) The term `artificial intelligence' has the meaning given such term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).”
“``(i) Annual Report.--(1) In each of years 2027 through 2031, the Secretary shall submit to the congressional defense committees an annual report on the program. The report shall include-- ``(A) the number of reports made of incidents and vulnerabilities and the categorizations of such reports; ``(B) a summary of significant trends, recurring risks, systemic issues, and corrective actions taken in response; ``(C) in the case of any covered AI incident resulting in the loss of life of, or in bodily harm to, a member of the Army, Navy, Marine Corps, Air Force, or Space Force-- ``(i) a description of the incident, including the system or systems involved and the operational context; ``(ii) the date and time the incident occurred; ``(iii) an assessment of the cause and operational consequence of the incident; and ``(iv) any corrective actions taken; and ``(D) any recommendations for changes to testing, procurement, cybersecurity, or deployment policies relating to artificial intelligence systems.”
“``(g) Protection of Reports.--(1) The Secretary shall establish a protected disclosure process, informed by established vulnerability disclosure practices, through which members of the Armed Forces, civilian employees, contractors, and subcontractors at any tier may report covered AI incidents and covered AI vulnerabilities in good faith. ``(2) The Secretary shall ensure that a person making a report in good faith under paragraph (1) is not, on the basis of that report alone, subject to adverse contract action, subject to adverse personnel action, or otherwise retaliated against by the Department. ``(h) Protection of Information.--The Secretary shall establish procedures to protect sensitive, proprietary, and classified information submitted through the protected disclosure process under subsection (g).”
“``(f) Department-wide and Program-level Matters.--(1) In the case of any incident or vulnerability categorized under subsection (e)(2)(A) or (B), the Secretary, acting through the official designated under subsection (d), shall coordinate any responses that the Secretary considers appropriate, such as remediation, retesting, mitigation measures, or deployment restrictions. ``(2) In addition, in the case of any incident or vulnerability described in subsection (e)(2)(A), the Secretary, acting through the official, shall require-- ``(A) a documented corrective action plan; and ``(B) validation that the mitigation measures, if any, in such plan have been implemented before continued operational use.”
“The Secretary, acting through such official, shall receive and standardize reports, conduct trend analysis, identify recurring risks and failure modes, and issue guidance, alerts, and recommendations, as appropriate. ``(e) Reporting and Categorization.--(1) The Secretary shall require prompt reporting to the official designated under subsection (d) of-- ``(A) any covered AI incident; and ``(B) any covered AI vulnerability. ``(2) The Secretary, acting through the official, shall categorize each incident or vulnerability reported to the official according to whether the incident or vulnerability requires-- ``(A) a Department-wide response; ``(B) a response at the program level; or ``(C) a response at a local level.”
“``(c) Requirements for Program.--The program shall-- ``(1) be designed using practices drawn from established safety incident reporting programs, vulnerability disclosure programs, and programs to identify and develop lessons learned; ``(2) emphasize non-punitive reporting, protection of sensitive and proprietary information, and dissemination of lessons learned, as appropriate; and ``(3) include a mechanism to enable timely access to and sharing of relevant logs, system data, and model information as necessary to support analysis and response. ``(d) Designation of Official.--The Secretary shall designate an appropriate official for the reporting, tracking, analysis, and remediation of covered AI incidents and covered AI [[Page H4860]] vulnerabilities under this section.”
“``(b) Purpose.--The purpose of the program established under subsection (a) shall be to-- ``(1) identify recurring risks, failure modes, vulnerabilities, and systemic weaknesses in artificial intelligence systems, including risks or failure modes arising from human-machine teaming; ``(2) support mitigation of significant risks; and ``(3) inform testing, procurement, cybersecurity, and deployment decisions to improve the safety, security, reliability, and operational effectiveness of such systems.”
“Chapter 131 of title 10, United States Code, is amended by inserting after section 2224a the following new section: ``Sec. 2224b. Artificial intelligence incident and vulnerability reporting program ``(a) In General.--The Secretary of Defense shall establish a centralized Department-wide program for the reporting, tracking, analysis, and remediation of covered AI incidents and covered AI vulnerabilities arising from the development, testing, procurement, fielding, or operation of artificial intelligence systems within the Department of Defense.”
“(E) The approach to fielding data resilience capabilities for data that is mission critical or essential to the operation of Department of Defense information systems and national security systems, including immutable backups that preserve logically separated copies isolated from external networks, and continuous monitoring of backup environments to detect tampering, insider threats, and malicious corruption. (2) Form.--The strategy under paragraph (1) shall be submitted in unclassified form, but may contain a classified annex. (3) Definition.--In this subsection, the term ``recovery time objective'' means the maximum allowable time the Secretary of Defense determines necessary to restore critical functions and data following a cyberattack. SEC. 1502. DEPARTMENT OF DEFENSE AI INCIDENT AND VULNERABILITY REPORTING PROGRAM.”