H.R. 6106House118th Congress (2023-2025)In Committee

BAD APPS Act

Introduced October 26, 2023

AI-Generated Summary

Updated January 20, 2026 at 12:34 PM UTC

The BAD APPS Act directs the Department of Defense to set up a risk‑assessment system for foreign mobile apps that could threaten DoD personnel or operations. It requires the Secretary of Defense to define categories of such apps and evaluate them based on data collection, influence potential, foreign ownership, government ties, malicious code, past impacts, and where the apps are used. The goal is to identify and mitigate security risks from apps originating in countries of concern.

Key Provisions

  • The Secretary of Defense must create categorical definitions for foreign mobile apps of concern and develop a risk framework to assess each app or groups of apps.
  • The framework evaluates apps on factors such as data collection practices, ability to influence users, foreign ownership or control, associated foreign government interests, presence of malicious code, prior impacts on DoD, and whether the app is on a government or personal device used in DoD contexts.
  • The risk assessment must cover apps from countries engaged in activities detrimental to U.S. national security or listed in the Export Administration Regulations, and may include additional apps or countries as the Secretary deems appropriate.
  • The Secretary must issue guidance to all DoD personnel on the categories and mitigation steps, update the definitions and framework at least annually, and, if feasible, issue regulations to reduce risks on DoD‑provided devices or during DoD activities.

Legislative Activity

Stay on top of the latest movement without scrolling through every action

1 earlier action
HouseIntro Referral Latest Action

Referred to the House Committee on Armed Services.

October 26, 2023

View full timeline
HouseIntro Referral

Introduced in House

October 26, 2023

HouseIntro Referral

Referred to the House Committee on Armed Services.

October 26, 2023

Bill Text

Latest available legislative text

Reading Mode
Latest
Introduced in HouseIssued October 26, 2023

I

118th CONGRESS

1st Session

H. R. 6106

IN THE HOUSE OF REPRESENTATIVES

October 26, 2023

Ms. Sherrill (for herself, Mr. Bergman, Mr. Krishnamoorthi, Mrs. Hinson, Mr. Newhouse, Mr. Garamendi, Mr. Crow, Mr. Finstad, Mr. Carson, and Ms. Tokuda) introduced the following bill; which was referred to the Committee on Armed Services

A BILL

To create a risk framework to evaluate foreign mobile applications of concern, and for other purposes.

1.

Short title

This Act may be cited as the Bolstering America’s Defenses Against Potentially Perilous Software Act or the BAD APPS Act.

2.

Risk framework for foreign mobile applications of concern

(a)

In general

The Secretary of Defense shall—

(1)

create categorical definitions of foreign mobile applications of concern with respect to personnel or operations of the Department of Defense, distinguishing among categories such as applications for shopping, social media, entertainment, or health; and

(2)

create a risk framework with respect to Department personnel or operations that assesses each foreign mobile application (or, if appropriate, grouping of similar such applications) that is from a country of concern for any potential impact on Departmental personnel and Departmental operations, incorporating considerations of—

(A)

the manner and extent of data collection by the application;

(B)

the ability of the application to influence the user with the applications content to the detriment of the United States;

(C)

the manner and extent of foreign ownership or control of the application or data collected by the application;

(D)

any foreign government interests associated with the applications;

(E)

a software bill of materials with a focus on known or assessed malicious software embedded in the application, including in prior versions of the application or in other applications created by the owners of such application;

(F)

any known impact from prior use of the application to Department personnel or operations; and

(G)

the foreign mobile application of concern residing on a United States Government device or a personally owned device while in proximity to Department operations or activities or in the personal custody of personnel during Department sanctioned activities.

(b)

Considerations

In developing the categorical definitions and risk framework described in subsection (a), the Secretary of Defense—

(1)

shall include in the risk framework foreign mobile applications of concern—

(A)

from countries that the Secretary determines to be engaged in consistent, unauthorized conduct that is detrimental to the national security or foreign policy of the United States;

(B)

that are accessible to be downloaded from major mobile device application marketplaces by Department personnel; and

(C)

originating from, authored in, owned by, or otherwise associated with countries or entities that are designated on the list maintained and set forth in Supplement No. 4 to part 744 of the Export Administration Regulations;

(2)

may include additional countries or individual foreign mobile applications with malicious and banned capabilities from other countries to the extent the Secretary determines appropriate; and

(3)

shall consider distinguishing within the risk framework the particular interests of a country described in paragraph (1) or (2) in the use of a foreign mobile application of concern of such country (regardless of device or owner) by—

(A)

users located at facilities of the Department of Defense of varying levels of sensitivity;

(B)

users conducting authorized operations or movements of Department of Defense materiel; or

(C)

specific civilian employees of the Department or contractors whom the Secretary determines likely to be a target of a foreign actor.

(c)

Guidance and updates

The Secretary of Defense shall—

(1)

issue guidance to all Department personnel incorporating the categories of foreign mobile applications of concern and advising how to mitigate the risks identified by the risk framework with respect to such applications;

(2)

routinely update the categorical definitions and risk framework promulgated pursuant to subsection (a), at least on an annual basis; and

(3)

prescribe, if feasible, regulations that appropriately mitigate risks from applications on devices provided by the Department of Defense or on any device used during an activity described in subsection (b)(3)(B) or at locations described under (b)(3)(A).