II
Calendar No. 723
118th CONGRESS
2d Session
S. 3312
IN THE SENATE OF THE UNITED STATES
November 15, 2023
Mr. Thune (for himself, Ms. Klobuchar, Mr. Wicker, Mr. Hickenlooper, Mr. Luján, Mrs. Capito, Ms. Baldwin, and Ms. Lummis) introduced the following bill; which was read twice and referred to the Committee on Commerce, Science, and Transportation
December 18 (legislative day, December 16), 2024
Reported by Ms. Cantwell, with an amendment
Strike out all after the enacting clause and insert the part printed in italic
A BILL
To provide a framework for artificial intelligence innovation and accountability, and for other purposes.
Short title
This Act may be cited as the Artificial Intelligence Research, Innovation, and Accountability Act of 2023
.
Table of contents
The table of contents for this Act is as follows:
Sec. 1. Short title.
Sec. 2. Table of contents.
TITLE I—Artificial intelligence research and innovation
Sec. 101. Open data policy amendments.
Sec. 102. Online content authenticity and provenance standards research and development.
Sec. 103. Standards for detection of emergent and anomalous behavior and AI-generated media.
Sec. 104. Comptroller General study on barriers and best practices to usage of AI in government.
TITLE II—Artificial intelligence accountability
Sec. 201. Definitions.
Sec. 202. Generative artificial intelligence transparency.
Sec. 203. Transparency reports for high-impact artificial intelligence systems.
Sec. 204. Recommendations to Federal agencies for risk management of high-impact artificial intelligence systems.
Sec. 205. Office of Management and Budget oversight of recommendations to agencies.
Sec. 206. Risk management assessment for critical-impact artificial intelligence systems.
Sec. 207. Certification of critical-impact artificial intelligence systems.
Sec. 208. Enforcement.
Sec. 209. Artificial intelligence consumer education.
Artificial intelligence research and innovation
Open data policy amendments
Section 3502 of title 44, United States Code, is amended—
in paragraph (22)—
by inserting or data model
after a data asset
; and
by striking and
at the end;
in paragraph (23), by striking the period at the end and inserting a semicolon; and
by adding at the end the following:
the term data model means a mathematical, economic, or statistical representation of a system or process used to assist in making calculations and predictions, including through the use of algorithms, computer programs, or artificial intelligence systems; and
the term artificial intelligence system means an engineered system that—
generates outputs, such as content, predictions, recommendations, or decisions for a given set of objectives; and
is designed to operate with varying levels of adaptability and autonomy using machine and human-based inputs.
.
Online content authenticity and provenance standards research and development
Research
In general
Not later than 180 days after the date of the enactment of this Act, the Under Secretary of Commerce for Standards and Technology shall carry out research to facilitate the development and standardization of means to provide authenticity and provenance information for content generated by human authors and artificial intelligence systems.
Elements
The research carried out pursuant to paragraph (1) shall cover the following:
Secure and binding methods for human authors of content to append statements of provenance through the use of unique credentials, watermarking, or other data or metadata-based approaches.
Methods for the verification of statements of content provenance to ensure authenticity such as watermarking or classifiers, which are trained models that distinguish artificial intelligence-generated media.
Methods for displaying clear and conspicuous statements of content provenance to the end user.
Technologies or applications needed to facilitate the creation and verification of content provenance information.
Mechanisms to ensure that any technologies and methods developed under this section are minimally burdensome on content producers.
Such other related processes, technologies, or applications as the Under Secretary considers appropriate.
Use of provenance technology to enable attribution for content creators.
Implementation
The Under Secretary shall carry out the research required by paragraph (1) as part of the research directives pursuant to section 22A(b)(1) of the National Institute of Standards and Technology Act (15 U.S.C. 278h–1(b)(1)).
Development of standards
In general
For methodologies and applications related to content provenance and authenticity deemed by the Under Secretary to be at a readiness level sufficient for standardization, the Under Secretary shall provide technical review and assistance to such other Federal agencies and nongovernmental standards organizations as the Under Secretary considers appropriate.
Considerations
In providing any technical review and assistance related to the development of content provenance and authenticity standards under this subsection, the Under Secretary may—
consider whether a proposed standard is reasonable, practicable, and appropriate for the particular type of media and media environment for which the standard is proposed;
consult with relevant stakeholders; and
review industry standards issued by nongovernmental standards organizations.
Pilot program
In general
The Under Secretary shall carry out a pilot program to assess the feasibility and advisability of using available technologies and creating open standards to facilitate the creation and verification of content governance information for digital content.
Locations
The pilot program required by paragraph (1) shall be carried out at not more than 2 Federal agencies the Under Secretary shall select for purposes of the pilot program required by paragraph (1).
Requirements
In carrying out the pilot program required by paragraph (1), the Under Secretary shall—
apply and evaluate methods for authenticating the origin of and modifications to government-produced digital content using technology and open standards described in paragraph (1); and
make available to the public digital content embedded with provenance or other authentication provided by the heads of the Federal agencies selected pursuant to paragraph (2) for the purposes of the pilot program.
Briefing required
Not later than 1 year after the date of the enactment of this Act, and annually thereafter until the date described in paragraph (5), the Under Secretary shall brief the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Science, Space, and Technology of the House of Representatives on the findings of the Under Secretary with respect to the pilot program carried out under this subsection.
Termination
The pilot program shall terminate on the date that is 10 years after the date of the enactment of this Act.
Report to Congress
Not later than 1 year after the date of the enactment of this Act, the Under Secretary shall submit to the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Science, Space, and Technology of the House of Representatives a report outlining the progress of standardization initiatives relating to requirements under this section, as well as recommendations for legislative or administrative action to encourage or require the widespread adoption of such initiatives in the United States.
Standards for detection of emergent and anomalous behavior and AI-generated media
Section 22A(b)(1) of the National Institute of Standards and Technology Act (15 U.S.C. 278h–1(b)(1)) is amended—
by redesignating subparagraph (I) as subparagraph (K);
in subparagraph (H), by striking ; and
and inserting a semicolon; and
by inserting after subparagraph (H) the following:
best practices for detecting outputs generated by artificial intelligence systems, including content such as text, audio, images, and videos;
methods to detect and understand anomalous behavior of artificial intelligence systems and safeguards to mitigate potentially adversarial or compromising anomalous behavior; and
.
Comptroller General study on barriers and best practices to usage of AI in government
In general
Not later than 1 year after the date of enactment of this Act, the Comptroller General of the United States shall—
conduct a review of statutory, regulatory, and other policy barriers to the use of artificial intelligence systems to improve the functionality of the Federal Government; and
identify best practices for the adoption and use of artificial intelligence systems by the Federal Government, including—
ensuring that an artificial intelligence system is proportional to the need of the Federal Government;
restrictions on access to and use of an artificial intelligence system based on the capabilities and risks of the artificial intelligence system; and
safety measures that ensure that an artificial intelligence system is appropriately limited to necessary data and compartmentalized from other assets of the Federal Government.
Report
Not later than 2 years after the date of enactment of this Act, the Comptroller General of the United States shall submit to the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Science, Space, and Technology of the House of Representatives a report that—
summarizes the results of the review conducted under subsection (a)(1) and the best practices identified under subsection (a)(2), including recommendations, as the Comptroller General of the United States considers appropriate;
describes any laws, regulations, guidance documents, or other policies that may prevent the adoption of artificial intelligence systems by the Federal Government to improve certain functions of the Federal Government, including—
data analysis and processing;
paperwork reduction;
contracting and procurement practices; and
other Federal Government services; and
includes, as the Comptroller General of the United States considers appropriate, recommendations to modify or eliminate barriers to the use of artificial intelligence systems by the Federal Government.
Artificial intelligence accountability
Definitions
In this title:
Appropriate congressional committees
The term appropriate congressional committees means—
the Committee on Energy and Natural Resources and the Committee on Commerce, Science, and Transportation of the Senate;
the Committee on Energy and Commerce of the House of Representatives; and
each congressional committee with jurisdiction over an applicable covered agency.
Artificial intelligence system
The term artificial intelligence system means an engineered system that—
generates outputs, such as content, predictions, recommendations, or decisions for a given set of human-defined objectives; and
is designed to operate with varying levels of adaptability and autonomy using machine and human-based inputs.
Covered agency
the term covered agency means an agency for which the Under Secretary develops an NIST recommendation.
Covered internet platform
In general
The term covered internet platform—
means any public-facing website, consumer-facing internet application, or mobile application available to consumers in the United States; and
includes a social network site, video sharing service, search engine, and content aggregation service.
Exclusions
The term covered internet platform does not include a platform that—
is wholly owned, controlled, and operated by a person that—
during the most recent 180-day period, did not employ more than 500 employees;
during the most recent 3-year period, averaged less than $50,000,000 in annual gross receipts; and
on an annual basis, collects or processes the personal data of less than 1,000,000 individuals; or
is operated for the sole purpose of conducting research that is not directly or indirectly made for profit.
Critical-impact AI organization
The term critical-impact AI organization means a non-government organization that serves as the deployer of a critical-impact artificial intelligence system.
Critical-impact artificial intelligence system
The term critical-impact artificial intelligence system means an artificial intelligence system that—
is deployed for a purpose other than solely for use by the Department of Defense or an intelligence agency (as defined in section 3094(e) of the National Security Act of 1947 (50 U.S.C. 3094(3))); and
is used or intended to be used—
to make decisions that have a legal or similarly significant effect on—
the real-time or ex post facto collection of biometric data of natural persons by biometric identification systems without their consent;
the direct management and operation of critical infrastructure (as defined in section 1016(e) of the USA PATRIOT Act (42 U.S.C. 5195c(e))) and space-based infrastructure; or
criminal justice (as defined in section 901 of title I of the Omnibus Crime Control and Safe Streets Act of 1968 (34 U.S.C. 10251)); and
in a manner that poses a significant risk to rights afforded under the Constitution of the United States or safety.
Deployer
The term deployer—
means an entity that uses or operates an artificial intelligence system for internal use or for use by third parties; and
does not include an entity that is solely an end user of a system.
Developer
The term developer means an entity that—
designs, codes, produces, or owns an artificial intelligence system for internal use or for use by a third party as a baseline model; and
does not act as a deployer of the artificial intelligence system described in subparagraph (A).
Generative artificial intelligence system
The term generative artificial intelligence system means an artificial intelligence system that generates novel data or content in a written, audio, or visual format.
High-impact artificial intelligence system
The term high-impact artificial intelligence system means an artificial intelligence system—
deployed for a purpose other than solely for use by the Department of Defense or an intelligence agency (as defined in section 3094(e) of the National Security Act of 1947 (50 U.S.C. 3094(3))); and
that is specifically developed with the intended purpose of making decisions that have a legal or similarly significant effect on the access of an individual to housing, employment, credit, education, healthcare, or insurance in a manner that poses a significant risk to rights afforded under the Constitution of the United States or safety.
NIST recommendation
The term NIST recommendation means a sector-specific recommendation developed under section 22B(b)(1) of the National Institute of Standards and Technology Act, as added by section 204 of this Act.
Secretary
The term Secretary means the Secretary of Commerce.
Significant risk
The term significant risk means a combination of severe, high-intensity, high-probability, and long-duration risk of harm to individuals.
TEVV
The term TEVV means the testing, evaluation, validation, and verification of any artificial intelligence system that includes—
open, transparent, testable, and verifiable specifications that characterize realistic operational performance, such as precision and accuracy for relevant tasks;
testing methodologies and metrics that enable the evaluation of system trustworthiness, including robustness and resilience;
data quality standards for training and testing datasets;
requirements for system validation and integration into production environments, automated testing, and compliance with existing legal and regulatory specifications;
methods and tools for—
the monitoring of system behavior;
the tracking of incidents or errors reported and their management; and
the detection of emergent properties and related impacts; and
and processes for redress and response.
Under Secretary
The term Under Secretary means the Director of the National Institute of Standards and Technology.
Generative artificial intelligence transparency
Prohibition
In general
Subject to paragraph (2), it shall be unlawful for a person to operate a covered internet platform that uses a generative artificial intelligence system.
Disclosure of use of generative artificial intelligence systems
In general
A person may operate a covered internet platform that uses a generative artificial intelligence system if the person provides notice to each user of the covered internet platform that the covered internet platform uses a generative artificial intelligence system to generate content the user sees.
Requirements
A person providing the notice described in subparagraph (A) to a user—
subject to clause (ii), shall provide the notice in a clear and conspicuous manner on the covered internet platform before the user interacts with content produced by a generative artificial intelligence system; and
may provide an option for the user to choose to see the notice described in clause (i) only upon the first interaction of the user with content produced by a generative artificial intelligence system.
Enforcement action
Upon learning that a covered internet platform does not comply with the requirements under this section, the Secretary—
shall immediately—
notify the covered internet platform of the finding; and
order the covered internet platform to take remedial action to address the noncompliance of the generative artificial intelligence system operated by the covered internet platform; and
may, as determined appropriate or necessary by the Secretary, take enforcement action under section 208 if the covered internet platform does not take sufficient action to remedy the noncompliance within 15 days of the notification under paragraph (1)(A).
Effective date
This section shall take effect on the date that is 180 days after the date of enactment of this Act.
Transparency reports for high-impact artificial intelligence systems
Transparency reporting
In general
Each deployer of a high-impact artificial intelligence system shall—
before deploying the high-impact artificial intelligence system, and annually thereafter, submit to the Secretary a report describing the design and safety plans for the artificial intelligence system; and
submit to the Secretary an updated report on the high-impact artificial intelligence system if the deployer makes a material change to—
the purpose for which the high-impact artificial intelligence system is used; or
the type of data the high-impact artificial intelligence system processes or uses for training purposes.
Contents
Each transparency report submitted under paragraph (1) shall include, with respect to the high-impact artificial intelligence system—
the purpose;
the intended use cases;
deployment context;
benefits;
a description of data that the high-impact artificial intelligence system, once deployed, processes as inputs;
if available—
a list of data categories and formats the deployer used to retrain or continue training the high-impact artificial intelligence system;
metrics for evaluating the high-impact artificial intelligence system performance and known limitations; and
transparency measures, including information identifying to individuals when a high-impact artificial intelligence system is in use;
processes and testing performed before each deployment to ensure the high-impact artificial intelligence system is safe, reliable, and effective;
if applicable, an identification of any third-party artificial intelligence systems or datasets the deployer relies on to train or operate the high-impact artificial intelligence system; and
post-deployment monitoring and user safeguards, including a description of the oversight process in place to address issues as issues arise.
Developer obligations
The developer of a high-impact artificial intelligence system shall be subject to the same obligations as a developer of a critical impact artificial intelligence system under section 206(c).
Considerations
In carrying out subsections (a) and (b), a deployer or developer of a high-impact artificial intelligence system shall consider the best practices outlined in the most recent version of the risk management framework developed pursuant to section 22A(c) of the National Institute of Standards and Technology Act (15 U.S.C. 278h–1(c)).
Noncompliance and enforcement action
Upon learning that a deployer of a high-impact artificial intelligence system is not in compliance with the requirements under this section with respect to a high-impact artificial intelligence system, the Secretary—
shall immediately—
notify the deployer of the finding; and
order the deployer to immediately submit to the Secretary the report required under subsection (a)(1); and
if the deployer fails to submit the report by the date that is 15 days after the date of the notification under paragraph (1)(A), may take enforcement action under section 208.
Avoidance of duplication
In general
Pursuant to the deconfliction of duplicative requirements under paragraph (2), the Secretary shall ensure that the requirements under this section are not unnecessarily burdensome or duplicative of requirements made or oversight conducted by a covered agency regarding the non-Federal use of high-impact artificial intelligence systems.
Deconfliction of duplicative requirements
Not later than 90 days after the date of the enactment of this Act, and annually thereafter, the Secretary, in coordination with the head of any relevant covered agency, shall complete the deconfliction of duplicative requirements relating to the submission of a transparency report for a high-impact artificial intelligence system under this section.
Rule of construction
Nothing in this section shall be construed to require a deployer of a high-impact artificial intelligence system to disclose any information, including data or algorithms—
relating to a trade secret or other protected intellectual property right;
that is confidential business information; or
that is privileged.
Recommendations to Federal agencies for risk management of high-impact artificial intelligence systems
The National Institute of Standards and Technology Act (15 U.S.C. 278h–1) is amended by inserting after section 22A the following:
Recommendations to Federal agencies for sector-specific oversight of artificial intelligence
Definition of high-Impact artificial intelligence system
In this section, the term high-impact artificial intelligence system means an artificial intelligence system—
deployed for purposes other than those solely for use by the Department of Defense or an element of the intelligence community (as defined in section 3 of the National Security Act of 1947 (50 U.S.C. 3003)); and
that is specifically developed with the intended purpose of making decisions that have a legal or similarly significant effect on the access of an individual to housing, employment, credit, education, health care, or insurance in a manner that poses a significant risk to rights afforded under the Constitution of the United States or to safety.
Sector-Specific recommendations
Not later than 1 year after the date of the enactment of the Artificial Intelligence Research, Innovation, and Accountability Act of 2023, the Director shall—
develop sector-specific recommendations for individual Federal agencies to conduct oversight of the non-Federal, and, as appropriate, Federal use of high-impact artificial intelligence systems to improve the safe and responsible use of such systems; and
not less frequently than biennially, update the sector-specific recommendations to account for changes in technological capabilities or artificial intelligence use cases.
Requirements
In developing recommendations under subsection (b), the Director shall use the voluntary risk management framework required by section 22A(c) to identify and provide recommendations to a Federal agency—
to establish regulations, standards, guidelines, best practices, methodologies, procedures, or processes to facilitate oversight of non-Federal use of high-impact artificial intelligence systems; and
to mitigate risks from such high-impact artificial intelligence systems.
Recommendations
In developing recommendations under subsection (b), the Director may include the following:
Key design choices made during high-impact artificial intelligence model development, including rationale and assumptions made.
Intended use and users, other possible use cases, including any anticipated undesirable or potentially harmful use cases, and what good faith efforts model developers can take to mitigate the use of the system in harmful ways.
Methods for evaluating the safety of high-impact artificial intelligence systems and approaches for responsible use.
Sector-specific differences in what constitutes acceptable high-impact artificial intelligence model functionality and trustworthiness, metrics used to determine high-impact artificial intelligence model performance, and any test results reflecting application of these metrics to evaluate high-impact artificial intelligence model performance across different sectors.
Recommendations to support iterative development of subsequent recommendations under subsection (b).
Consultation
In developing recommendations under subsection (b), the Director shall, as the Director considers applicable and practicable, consult with relevant covered agencies and stakeholders representing perspectives from civil society, academia, technologists, engineers, and creators.
.
Office of Management and Budget oversight of recommendations to agencies
Recommendations
In general
Not later than 1 year after the date of enactment of this Act, the Under Secretary shall submit to the Director, the head of each covered agency, and the appropriate congressional committees each NIST recommendation.
Agency responses to recommendations
Not later than 90 days after the date on which the Under Secretary submits a NIST recommendation to the head of a covered agency under paragraph (1), the head of the covered agency shall transmit to the Director a formal written response to the NIST recommendation that—
indicates whether the head of the covered agency intends to—
carry out procedures to adopt the complete NIST recommendation;
carry out procedures to adopt a part of the NIST recommendation; or
refuse to carry out procedures to adopt the NIST recommendation; and
includes—
with respect to a formal written response described in clause (i) or (ii) of subparagraph (A), a copy of a proposed timetable for completing the procedures described in that clause;
with respect to a formal written response described in subparagraph (A)(ii), the reasons for the refusal to carry out procedures with respect to the remainder of the NIST recommendation described in that subparagraph; and
with respect to a formal written response described in subparagraph (A)(iii), the reasons for the refusal to carry out procedures.
Public availability
The Director shall make a copy of each NIST recommendation and each written formal response of a covered agency required under subsection (a)(2) available to the public at reasonable cost.
Reporting requirements
Annual secretarial regulatory status reports
In general
On the first February 1 occurring after the date of enactment of this Act, and annually thereafter until the date described in subparagraph (B), the head of each covered agency shall submit to the Director a report containing the regulatory status of each NIST recommendation.
Continued reporting
The date described in this subparagraph is the date on which the head of a covered agency—
takes final regulatory action with respect to a NIST recommendation; and
determines and states in a report required under subparagraph (A) that no regulatory action should be taken with respect to a NIST recommendation.
Compliance report to Congress
On April 1 of each year, the Director shall—
review the reports received under paragraph (1)(A); and
transmit comments on the reports to the heads of covered agencies and the appropriate congressional committees.
Failure to report
If, on March 1 of each year, the Director has not received a report required under paragraph (1)(A) from the head of a covered agency, the Director shall notify the appropriate congressional committees of the failure.
Technical assistance in carrying out recommendations
The Under Secretary shall provide assistance to the heads of covered agencies relating to the implementation of the NIST recommendations the heads of covered agencies intend to carry out.
Regulation review and improvement
The Administrator of the Office of Information and Regulatory Affairs of the Office of Management and Budget, in consultation with the Under Secretary, shall develop and periodically revise performance indicators and measures for sector-specific regulation of artificial intelligence.
Risk management assessment for critical-impact artificial intelligence systems
Requirement
In general
Each critical-impact AI organization shall perform a risk management assessment in accordance with this section.
Assessment
Each critical-impact AI organization shall—
not later than 30 days before the date on which a critical-impact artificial intelligence system is made publicly available by the critical-impact AI organization, perform a risk management assessment; and
not less frequently than biennially during the period beginning on the date of enactment of this Act and ending on the date on which the applicable critical-impact artificial intelligence system is no longer being made publicly available by the critical-impact AI organization, as applicable, conduct an updated risk management assessment that—
may find that no significant changes were made to the critical-impact artificial intelligence system; and
provides, to the extent practicable, aggregate results of any significant deviation from expected performance detailed in the assessment performed under subparagraph (A) or the most recent assessment performed under this subparagraph.
Review
In general
Not later than 90 days after the date of completion of a risk management assessment by a critical-impact AI organization under this section, the critical-impact AI organization shall submit to the Secretary a report—
outlining the assessment performed under this section; and
that is in a consistent format, as determined by the Secretary.
Additional information
Subject to subsection (d), the Secretary may request that a critical-impact AI organization submit to the Secretary any related additional or clarifying information with respect to a risk management assessment performed under this section.
Limitation
The Secretary may not prohibit a critical-impact AI organization from making a critical-impact artificial intelligence system available to the public based on the review by the Secretary of a report submitted under paragraph (3)(A) or additional or clarifying information submitted under paragraph (3)(B).
Assessment subject areas
Each assessment performed by a critical-impact AI organization under subsection (a) shall describe the means by which the critical-impact AI organization is addressing, through a documented TEVV process, the following categories:
Policies, processes, procedures, and practices across the organization relating to transparent and effective mapping, measuring, and managing of artificial intelligence risks, including—
how the organization understands, manages, and documents legal and regulatory requirements involving artificial intelligence;
how the organization integrates characteristics of trustworthy artificial intelligence, which include valid, reliable, safe, secure, resilient, accountable, transparent, globally and locally explainable, interpretable, privacy-enhanced, and fair with harmful bias managed, into organizational policies, processes, procedures, and practices;
a methodology to determine the needed level of risk management activities based on the organization’s risk tolerance; and
how the organization establishes risk management processes and outcomes through transparent policies, procedures, and other controls based on organizational risk priorities.
The structure, context, and capabilities of the critical-impact artificial intelligence system or critical-impact foundation model, including—
how the context was established and understood;
capabilities, targeted uses, goals, and expected costs and benefits; and
how risks and benefits are mapped for each system component.
A description of how the organization employs quantitative, qualitative, or mixed-method tools, techniques, and methodologies to analyze, assess, benchmark, and monitor artificial intelligence risk, including—
identification of appropriate methods and metrics;
how artificial intelligence systems are evaluated for trustworthy characteristics;
mechanisms for tracking artificial intelligence system risks over time; and
processes for gathering and assessing feedback relating to the efficacy of measurement.
A description of allocation of risk resources to map and measure risks on a regular basis as described in paragraph (1), including—
how artificial intelligence risks based on assessments and other analytical outputs described in paragraphs (2) and (3) are prioritized, responded to, and managed;
how strategies to maximize artificial intelligence benefits and minimize negative impacts were planned, prepared, implemented, documented, and informed by input from relevant artificial intelligence deployers;
management of artificial intelligence system risks and benefits; and
regular monitoring of risk treatments, including response and recovery, and communication plans for the identified and measured artificial intelligence risks, as applicable.
Developer obligations
The developer of a critical-impact artificial intelligence system that agrees through a contract or license to provide technology or services to a deployer of the critical-impact artificial intelligence system shall provide to the deployer of the critical-impact artificial intelligence system the information reasonably necessary for the deployer to comply with the requirements under subsection (a), including—
an overview of the data used in training the baseline artificial intelligence system provided by the developer, including—
data size;
data sources;
copyrighted data; and
personal identifiable information;
documentation outlining the structure and context of the baseline artificial intelligence system of the developer, including—
input modality;
output modality;
model size; and
model architecture;
known capabilities, limitations, and risks of the baseline artificial intelligence system of the developer at the time of the development of the artificial intelligence system; and
documentation for downstream use, including—
a statement of intended purpose;
guidelines for the intended use of the artificial intelligence system, including a list of permitted, restricted, and prohibited uses and users; and
a statement of the potential for deviation from the intended purpose of the baseline artificial intelligence system.
Termination of obligation To disclose information
In general
The obligation of a critical-impact AI organization to provide information, upon request of the Secretary, relating to a specific assessment category under subsection (b) shall end on the date of issuance of a relevant standard applicable to the same category of a critical-impact artificial intelligence system by—
the Secretary under section 207(c) with respect to a critical-impact artificial intelligence system;
another department or agency of the Federal Government, as determined applicable by the Secretary; or
a non-governmental standards organization, as determined appropriate by the Secretary.
Effect of new standard
In adopting any standard applicable to critical-impact artificial intelligence systems under section 207(c), the Secretary shall—
identify the category under subsection (b) to which the standard relates, if any; and
specify the information that is no longer required to be included in a report required under subsection (a) as a result of the new standard.
Rule of construction
Nothing in this section shall be construed to require a critical-impact AI organization, or permit the Secretary, to disclose any information, including data or algorithms—
relating to a trade secret or other protected intellectual property right;
that is confidential business information; or
that is privileged.
Certification of critical-impact artificial intelligence systems
Establishment of Artificial Intelligence Certification Advisory Committee
In general
Not later than 180 days after the date of enactment of this Act, the Secretary shall establish an advisory committee to provide advice and recommendations on TEVV standards and the certification of critical-impact artificial intelligence systems.
Duties
The advisory committee established under this section shall advise the Secretary on matters relating to the testing and certification of critical-impact artificial intelligence systems, including by—
providing recommendations to the Secretary on proposed TEVV standards to ensure such standards—
maximize alignment and interoperability with standards issued by nongovernmental standards organizations and international standards bodies;
are performance-based and impact-based; and
are applicable or necessary to facilitate the deployment of critical-impact artificial intelligence systems in a transparent, secure, and safe manner;
reviewing prospective TEVV standards submitted by the Secretary to ensure such standards align with recommendations under subparagraph (A);
upon completion of the review under subparagraph (B), providing consensus recommendations to the Secretary on—
whether a TEVV standard should be issued, modified, revoked, or added; and
if such a standard should be issued, how best to align the standard with the considerations described in subsection (c)(2) and recommendations described in subparagraph (A); and
reviewing and providing advice and recommendations on the plan and subsequent updates to the plan submitted under subsection (b).
Composition
The advisory committee established under this subsection shall be composed of not more than 15 members with a balanced composition of representatives of the private sector, institutions of higher education, and non-profit organizations, including—
representatives of—
institutions of higher education;
companies developing or operating artificial intelligence systems;
consumers or consumer advocacy groups; and
enabling technology companies; and
any other members the Secretary considers to be appropriate.
Artificial intelligence certification plan
In general
Not later than 1 year after the date of enactment of this Act, the Secretary shall establish a 3-year implementation plan for the certification of critical-impact artificial intelligence systems.
Periodic update
The Secretary shall periodically update the plan established under paragraph (1).
Contents
The plan established under paragraph (1) shall include—
a methodology for gathering and using relevant, objective, and available information relating to TEVV;
a process for considering whether prescribing certain TEVV standards under subsection (c) for critical-impact artificial intelligence systems is appropriate, necessary, or duplicative of existing international standards;
if TEVV standards are considered appropriate, a process for prescribing such standards for critical-impact artificial intelligence systems; and
an outline of standards proposed to be issued, including an estimation of the timeline and sequencing of such standards.
Consultation
In developing the plan required under paragraph (1), the Secretary shall consult the following:
The National Artificial Intelligence Initiative Office.
The interagency committee established under section 5103 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9413).
The National Artificial Intelligence Advisory Committee.
Industry consensus standards issued by non-governmental standards organizations.
Other departments, agencies, and instrumentalities of the Federal Government, as considered appropriate by the Secretary.
Submission to certification advisory committee
Upon completing the initial plan required under this subsection and upon completing periodic updates to the plan under paragraph (2), the Secretary shall submit the plan to the advisory committee established under subsection (a) for review.
Submission to committees of congress
Upon completing the plan required under this subsection, the Secretary shall submit to the relevant committees of Congress a report containing the plan.
Limitation
The Secretary may not issue TEVV standards under subsection (c) until the date of the submission of the plan under paragraphs (5) and (6).
Standards
Standards
In general
The Secretary shall issue TEVV standards for critical-impact artificial intelligence systems.
Requirements
Each standard issued under this subsection shall—
be practicable;
meet the need for safe, secure, and transparent operations of critical-impact artificial intelligence systems;
with respect to a relevant standard issued by a non-governmental standards organization that is already in place, align with and be interoperable with that standard;
provide for a mechanism to, not less frequently than once every 2 years, solicit public comment and update the standard to reflect advancements in technology and system architecture; and
be stated in objective terms.
Considerations
In issuing TEVV standards for critical-impact artificial intelligence systems under this subsection, the Secretary shall—
consider relevant available information concerning critical-impact artificial intelligence systems, including—
transparency reports submitted under section 203(a);
risk management assessments conducted under section 206(a); and
any additional information provided to the Secretary pursuant to section 203(a)(1)(B);
consider whether a proposed standard is reasonable, practicable, and appropriate for the particular type of critical-impact artificial intelligence system for which the standard is proposed;
consult with relevant artificial intelligence stakeholders and review industry standards issued by nongovernmental standards organizations;
pursuant to paragraph (1)(B)(iii), consider whether adoption of a relevant standard issued by a nongovernmental standards organization as a TEVV standard is the most appropriate action; and
consider whether the standard takes into account—
transparent, replicable, and objective assessments of critical-impact artificial intelligence system risk, structure, capabilities, and design;
the risk posed to the public by an applicable critical-impact artificial intelligence system; and
the diversity of methodologies and innovative technologies and approaches available to meet the objectives of the standard.
Consultation
Before finalizing a TEVV standard issued under this subsection, the Secretary shall submit the TEVV standard to the advisory committee established under subsection (a) for review.
Public comment
Before issuing any TEVV standard under this subsection, the Secretary shall provide an opportunity for public comment.
Cooperation
In developing a TEVV standard under this subsection, the Secretary may, as determined appropriate, advise, assist, and cooperate with departments, agencies, and instrumentalities of the Federal Government, States, and other public and private agencies.
Effective date of standards
In general
The Secretary shall specify the effective date of a TEVV standard issued under this subsection in the order issuing the standard.
Limitation
Subject to subparagraph (C), a TEVV standard issued under this subsection may not become effective—
during the 180-day period following the date on which the TEVV standard is issued; and
more than 1 year after the date on which the TEVV standard is issued.
Exception
Subparagraph (B) shall not apply to the effective date of a TEVV standard issued under this section if the Secretary—
finds, for good cause shown, that a different effective date is in the public interest; and
publishes the reasons for the finding under clause (i).
Rule of construction
Nothing in this subsection shall be construed to authorize the Secretary to impose any requirements on or take any enforcement actions under this section or section 208 relating to a critical-impact AI organization before a TEVV standard relating to those requirements is prescribed.
Exemptions
Authority to exempt and procedures
In general
The Secretary may exempt, on a temporary basis, a critical-impact artificial intelligence system from a TEVV standard issued under subsection (c) on terms the Secretary considers appropriate.
Renewal
An exemption under subparagraph (A)—
may be renewed only on reapplication; and
shall conform to the requirements of this paragraph.
Proceedings
In general
The Secretary may begin a proceeding to grant an exemption to a critical-impact artificial intelligence system under this paragraph if the critical-impact AI organization that deployed the critical-impact artificial intelligence systems applies for an exemption or a renewal of an exemption.
Notice and comment
The Secretary shall publish notice of the application under clause (i) and provide an opportunity to comment.
Filing
An application for an exemption or for a renewal of an exemption under this paragraph shall be filed at such time and in such manner and contain such information as the Secretary may require.
Actions
The Secretary may grant an exemption under this paragraph upon finding that—
the exemption is consistent with the public interest and this section; and
the exemption would facilitate the development or evaluation of a feature or characteristic of a critical-impact artificial intelligence system providing a safety and security level that is not less than the TEVV standard level.
Disclosure
Not later than 30 days after the date on which an application is filed under this subsection, the Secretary may make public information contained in the application or relevant to the application, unless the information concerns or is related to a trade secret or other confidential information not relevant to the application.
Notice of decision
The Secretary shall publish in the Federal Register a notice of each decision granting or denying an exemption under this subsection and the reasons for granting or denying that exemption, including a justification with supporting information for the selected approach.
Self-Certification of compliance
In general
Subject to paragraph (2), with respect to each critical-impact artificial intelligence system of a critical-impact AI organization, the critical-impact AI organization shall certify to the Secretary that the critical-impact artificial intelligence system complies with applicable TEVV standards issued under this section.
Exception
A critical-impact AI organization may not issue a certificate under paragraph (1) if, in exercising reasonable care, the critical-impact AI organization has constructive knowledge that the certificate is false or misleading in a material respect.
Noncompliance findings and enforcement action
Finding of noncompliance by secretary
Upon learning that a critical-impact artificial intelligence system deployed by a critical-impact AI organization does not comply with the requirements under this section, the Secretary shall—
immediately—
notify the critical-impact AI organization of the finding; and
order the critical-impact AI organization to take remedial action to address the noncompliance of the artificial intelligence system; and
may, as determined appropriate or necessary by the Secretary, and if the Secretary determines that actions taken by a critical-impact AI organization are insufficient to remedy the noncompliance of the critical-impact AI organization with this section, take enforcement action under section 208.
Actions by critical-impact AI organization
If a critical-impact AI organization finds that a critical-impact artificial intelligence system deployed by the critical-impact AI organization is noncompliant with an applicable TEVV standard issued under this section or the critical-impact AI organization is notified of noncompliance by the Secretary under paragraph (1)(A)(i), the critical-impact AI organization shall—
without undue delay, notify the Secretary by certified mail or electronic mail of the noncompliance or receipt of the notification of noncompliance;
take remedial action to address the noncompliance; and
not later than 10 days after the date of the notification or receipt under subparagraph (A), submit to the Secretary a report containing information on—
the nature and discovery of the noncompliant aspect of the critical-impact artificial intelligence system;
measures taken to remedy such noncompliance; and
actions taken by the critical-impact AI organization to address stakeholders affected by such noncompliance.
Enforcement
In general
Upon discovering noncompliance with a provision of this Act by a deployer of a high-impact artificial intelligence system or a critical-impact AI organization if the Secretary determines that actions taken by the critical-impact AI organization are insufficient to remedy the noncompliance, the Secretary shall take an action described in this section.
Civil penalties
In general
The Secretary may impose a penalty described in paragraph (2) on deployer of a high-impact artificial intelligence system or a critical-impact AI organization for each violation by that entity of this Act or any regulation or order issued under this Act.
Penalty described
The penalty described in this paragraph is the greater of—
an amount not to exceed $300,000; or
an amount that is twice the value of the transaction that is the basis of the violation with respect to which the penalty is imposed.
Violation with intent
In general
If the Secretary determines that a deployer of a high-impact artificial intelligence system or a critical-impact AI organization intentionally violates this Act or any regulation or order issued under this Act, the Secretary may prohibit the critical-impact AI organization from deploying a critical-impact artificial intelligence system.
In addition
A prohibition imposed under paragraph (1) shall be in addition to any other civil penalties provided under this Act.
Factors
The Secretary may by regulation provide standards for establishing levels of civil penalty under this section based upon factors such as the seriousness of the violation, the culpability of the violator, and such mitigating factors as the violator’s record of cooperation with the Secretary in disclosing the violation.
Civil action
In general
Upon referral by the Secretary, the Attorney General may bring a civil action in a United States district court to—
enjoin a violation of section 207; or
collect a civil penalty upon a finding of noncompliance with this Act.
Venue
A civil action may be brought under paragraph (1) in the judicial district in which the violation occurred or the defendant is found, resides, or does business.
Process
Process in a civil action under paragraph (1) may be served in any judicial district in which the defendant resides or is found.
Rule of construction
Nothing in this section shall be construed to require a developer of a critical-impact artificial intelligence system to disclose any information, including data or algorithms—
relating to a trade secret or other protected intellectual property right;
that is confidential business information; or
that is privileged.
Artificial intelligence consumer education
Establishment
Not later than 180 days after the date of enactment of this Act, the Secretary shall establish a working group relating to responsible education efforts for artificial intelligence systems.
Membership
In general
The Secretary shall appoint to serve as members of the working group established under this section not more than 15 individuals with expertise relating to artificial intelligence systems, including—
representatives of—
institutions of higher education;
companies developing or operating artificial intelligence systems;
consumers or consumer advocacy groups;
public health organizations;
marketing professionals;
entities with national experience relating to consumer education, including technology education;
public safety organizations;
rural workforce development advocates;
enabling technology companies; and
nonprofit technology industry trade associations; and
any other members the Secretary considers to be appropriate.
Compensation
A member of the working group established under this section shall serve without compensation.
Duties
In general
The working group established under this section shall—
identify recommended education and programs that may be voluntarily employed by industry to inform—
consumers and other stakeholders with respect to artificial intelligence systems as those systems—
become available; or
are soon to be made widely available for public use or consumption; and
submit to Congress, and make available to the public, a report containing the findings and recommendations under subparagraph (A).
Factors for consideration
The working group established under this section shall take into consideration topics relating to—
the intent, capabilities, and limitations of artificial intelligence systems;
use cases of artificial intelligence applications that improve lives of the people of the United States, such as improving government efficiency, filling critical roles, and reducing mundane work tasks;
artificial intelligence research breakthroughs;
engagement and interaction methods, including how to adequately inform consumers of interaction with an artificial intelligence system;
human-machine interfaces;
emergency fallback scenarios;
operational boundary responsibilities;
potential mechanisms that could change function behavior in service; and
consistent nomenclature and taxonomy for safety features and systems.
Consultation
The Secretary shall consult with the Chair of the Federal Trade Commission with respect to the recommendations of the working group established under this section, as appropriate.
Termination
The working group established under this section shall terminate on the date that is 2 years after the date of enactment of this Act.
Short title
This Act may be cited as the Artificial Intelligence Research, Innovation, and Accountability Act of 2024
.
Table of contents
The table of contents for this Act is as follows:
Sec. 1. Short title.
Sec. 2. Table of contents.
TITLE I—Artificial intelligence research and innovation
Sec. 101. Open data policy amendments.
Sec. 102. Online content authenticity and provenance standards research and development.
Sec. 103. Standards for detection of anomalous behavior and artificial intelligence-generated media.
Sec. 104. Comptroller general study on barriers and best practices to usage of AI in government.
TITLE II—Artificial intelligence accountability
Sec. 201. Definitions.
Sec. 202. Generative artificial intelligence transparency.
Sec. 203. Transparency reports for high-impact artificial intelligence systems.
Sec. 204. Guidelines for Federal agencies and plans for oversight of high-impact artificial intelligence systems.
Sec. 205. Office of Management and Budget Oversight guidelines and agency oversight plans.
Sec. 206. Risk management assessment for critical-impact artificial intelligence systems.
Sec. 207. Certification of critical-impact artificial intelligence systems.
Sec. 208. Enforcement.
Sec. 209. Developer and deployer overlap.
Sec. 210. Artificial intelligence consumer education.
Sec. 211. Severability.
Artificial intelligence research and innovation
Open data policy amendments
Section 3502 of title 44, United States Code, is amended—
in paragraph (22)—
by inserting or data model
after a data asset
; and
by striking and
at the end;
in paragraph (23), by striking the period at the end and inserting a semicolon; and
by adding at the end the following:
the term data model means a mathematical, economic, or statistical representation of a system or process used to assist in making calculations and predictions, including through the use of algorithms, computer programs, or artificial intelligence systems; and
the term artificial intelligence system means a machine-based system that, for explicit or implicit objectives, infers from the input the system receives how to generate outputs, such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.
.
Online content authenticity and provenance standards research and development
Research
In general
Not later than 180 days after the date of the enactment of this Act, the Under Secretary of Commerce for Standards and Technology shall carry out research to facilitate the development and promote the standardization of means to provide authenticity and provenance information for digital content generated by human authors and artificial intelligence systems.
Elements
The research carried out pursuant to paragraph (1) shall cover the following:
Secure and mandatory methods for human content to append statements of provenance information through the use of unique credentials, watermarking, or other data or metadata-based approaches.
Methods for the verification of statements of digital content provenance to ensure authenticity such as watermarking or classifiers, which are trained models that distinguish artificial intelligence-generated content.
Methods for displaying clear and conspicuous labels of digital content provenance to users.
Technologies, applications, or infrastructure needed to facilitate the creation and verification of digital content provenance information.
Mechanisms to ensure that any technologies and methods developed under this subsection are minimally burdensome on content producers to implement.
Use of digital content transparency technologies to enable attribution for human-created content.
Such other related processes, technologies, or applications as the Under Secretary considers appropriate.
Implementation
The Under Secretary shall carry out the research required by paragraph (1) as part of the research directives pursuant to section 22A(b)(1) of the National Institute of Standards and Technology Act (15 U.S.C. 278h–1(b)(1)).
Technical assistance on the development of standards
In general
For methodologies and applications related to content provenance and authenticity deemed by the Under Secretary to be at a readiness level sufficient for standardization, the Under Secretary shall provide technical review and assistance to such other Federal agencies and nongovernmental standards organizations as the Under Secretary considers appropriate.
Considerations
In providing any technical review and assistance related to the development of digital content provenance and authenticity standards under this subsection, the Under Secretary may—
consider whether a proposed standard is reasonable, practicable, and appropriate for the particular type of media and media environment for which the standard is proposed;
consult with relevant stakeholders; and
review industry standards issued by nongovernmental standards organizations.
Pilot program
In general
The Under Secretary shall carry out a pilot program to assess the feasibility and advisability of using available technologies and creating guidelines to facilitate the creation and verification of digital content provenance information.
Locations
The pilot program required by paragraph (1) shall be carried out at not more than 2 Federal agencies the Under Secretary shall select for purposes of the pilot program required by paragraph (1).
Requirements
In carrying out the pilot program required by paragraph (1), the Under Secretary shall—
apply and evaluate methods for authenticating the origin of and modifications to government-produced digital content, either by Federal Government employees or a private entity under the terms of a government contract, using technology and guidelines described in paragraph (1); and
make available to the public digital content embedded with provenance data or other authentication provided by the heads of the Federal agencies selected pursuant to paragraph (2) for the purposes of the pilot program.
Briefing required
Not later than 1 year after the date of the enactment of this Act, and annually thereafter until the date described in paragraph (5), the Under Secretary shall brief the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Science, Space, and Technology of the House of Representatives on the findings of the Under Secretary with respect to the pilot program carried out under this subsection.
Termination
The pilot program shall terminate on the date that is 10 years after the date of the enactment of this Act.
Report to congress
Not later than 1 year after the date of the enactment of this Act, the Under Secretary shall submit to the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Science, Space, and Technology of the House of Representatives a report outlining the progress of standardization initiatives relating to requirements under this section, as well as recommendations for legislative or administrative action to encourage or require the widespread adoption of such initiatives in the United States.
Standards for detection of anomalous behavior and artificial intelligence-generated media
Section 22A(b)(1) of the National Institute of Standards and Technology Act (15 U.S.C. 278h–1(b)(1)) is amended—
by redesignating subparagraph (I) as subparagraph (K);
in subparagraph (H), by striking ; and
and inserting a semicolon; and
by inserting after subparagraph (H) the following:
best practices for detecting outputs generated by artificial intelligence systems, including content such as text, audio, images, and videos;
methods to detect and mitigate anomalous behavior of artificial intelligence systems and safeguards to mitigate potentially adversarial or compromising anomalous behavior; and
.
Comptroller general study on barriers and best practices to usage of AI in government
In general
Not later than 1 year after the date of enactment of this Act, the Comptroller General of the United States shall—
conduct a review of statutory, regulatory, and other policy barriers to the use of artificial intelligence systems to improve the functionality of the Federal Government; and
identify best practices for the adoption and responsible use of artificial intelligence systems by the Federal Government, including—
ensuring that an artificial intelligence system is proportional to the need of the Federal Government;
restrictions on access to and use of an artificial intelligence system based on the capabilities and risks of the artificial intelligence system; and
safety measures that ensure that an artificial intelligence system is appropriately limited to necessary data and compartmentalized from other assets of the Federal Government.
Report
Not later than 2 years after the date of enactment of this Act, the Comptroller General of the United States shall submit to the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Science, Space, and Technology of the House of Representatives a report that—
summarizes the results of the review conducted under subsection (a)(1) and the best practices identified under subsection (a)(2), including recommendations, as the Comptroller General of the United States considers appropriate;
describes any laws, regulations, guidance documents, or other policies that may prevent the adoption of artificial intelligence systems by the Federal Government to improve certain functions of the Federal Government, including—
data analysis and processing;
paperwork reduction;
contracting and procurement practices; and
other Federal Government services; and
includes, as the Comptroller General of the United States considers appropriate, recommendations to modify or eliminate barriers to the use of artificial intelligence systems by the Federal Government.
Artificial intelligence accountability
Definitions
In this title:
Appropriate congressional committees
The term appropriate congressional committees means—
the Committee on Energy and Natural Resources and the Committee on Commerce, Science, and Transportation of the Senate;
the Committee on Energy and Commerce of the House of Representatives; and
each congressional committee with jurisdiction over an applicable covered agency.
Artificial intelligence system
The term artificial intelligence system means a machine-based system that, for explicit and implicit objectives, infers from the input the system receives how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.
Covered agency
The term covered agency means an agency for which a guideline is developed under section 22B(b)(1) of the National Institute of Standards and Technology Act, as added by section 204 of this Act, including—
the Department of Commerce;
the Department of State;
the Department of Homeland Security;
the Department of Health and Human Services;
the Department of Agriculture;
the Department of Housing and Urban Development;
the Department of the Interior;
the Department of Education;
the Department of Energy;
the Department of Labor;
the Department of Transportation;
the Department of Justice;
the Department of the Treasury;
the Department of Veterans Affairs; and
any other agency the Secretary determines appropriate.
Critical-impact ai organization
The term critical-impact AI organization means a nongovernmental organization that serves as the deployer of a critical-impact artificial intelligence system.
Critical-impact artificial intelligence system
The term critical-impact artificial intelligence system means an artificial intelligence system that—
is deployed for a purpose other than solely for use by the Department of Defense or an intelligence agency (as defined in section 504(e) of the National Security Act of 1947 (50 U.S.C. 3094(3))); and
is used or intended to be used—
to make a decision or substantially replace or facilitate the discretionary human decisionmaking process regarding—
the real-time or ex post facto collection or analysis of biometric data of a natural person by biometric identification systems without the consent of the natural person;
an operational component involved in the direct management of infrastructure determined by the Secretary of Homeland Security to be critical infrastructure (as defined in section 1016(e) of the USA PATRIOT Act (42 U.S.C. 5195c(e))) that is—
transportation infrastructure;
energy infrastructure;
electrical infrastructure;
communications infrastructure;
manufacturing infrastructure; or
infrastructure used in the supply and production of water and hazardous materials; or
a government or government contractor’s actions pertaining to criminal justice (as defined in section 901 of title I of the Omnibus Crime Control and Safe Streets Act of 1968 (34 U.S.C. 10251)); and
in a manner that poses a significant risk to safety or violates rights afforded under the Constitution of the United States.
Deployer
The term deployer—
means an entity that—
uses or operates an artificial intelligence system for internal use or for use by a third party;
substantially modifies an artificial intelligence system, or trains an artificial intelligence system using new data, for internal use or for use by a third party; or
performs the functions described in clauses (i) and (ii); and
does not include an entity that is solely an end user of a system.
Developer
The term developer means an entity that—
initially designs, codes, produces, or owns an artificial intelligence system for internal use or for use by a third party as a baseline model; and
is not a deployer of the artificial intelligence system described in subparagraph (A).
End user
The term end user means an entity that, with respect to an artificial intelligence system procured from a deployer for which the deployer submits a transparency report under section 203 or a risk management assessment under section 206—
uses or operates the artificial intelligence system; and
does not substantially edit or modify the artificial intelligence system.
Generative artificial intelligence system
The term generative artificial intelligence system means an artificial intelligence system that generates output, such as data or content in a written, audio, or visual format.
High-impact artificial intelligence system
The term high-impact artificial intelligence system means an artificial intelligence system—
deployed for a purpose other than solely for use by the Department of Defense or an intelligence agency (as defined in section 3094(e) of the National Security Act of 1947 (50 U.S.C. 3094(3))); and
that is specifically deployed to make a decision or substantially replace the discretionary human decisionmaking process regarding the access of an individual to housing, employment, credit, education, healthcare, government services, or insurance in a manner that poses a significant risk to safety or violates rights afforded under the Constitution of the United States or Federal law.
Online platform
The term online platform means any public-facing website, online service, online application, or mobile application that predominantly provides a community forum for user-generated content, such as sharing videos, images, games, audio files, or other content, including a social media service, social network, or virtual reality environment.
Secretary
The term Secretary means the Secretary of Commerce.
Significant risk
The term significant risk means the risk of—
high-impact, severe, high-intensity, or long-duration harm to individuals; or
a high probability of substantial harm to individuals.
TEVV
The term TEVV means the testing, evaluation, validation, and verification of any artificial intelligence system that includes—
open, transparent, testable, and verifiable specifications that characterize realistic operational performance, such as validity and reliability for relevant tasks;
testing methodologies and metrics that enable the evaluation of system trustworthiness, including robustness and resilience;
data quality standards for training and testing datasets;
requirements for system validation and integration into production environments, automated testing, and compliance with existing legal and regulatory specifications;
methods and tools for—
the monitoring of system behavior;
the tracking of incidents or errors reported and their management; and
the detection of emergent properties and related impacts; and
processes for redress and response.
Under secretary
The term Under Secretary means the Director of the National Institute of Standards and Technology.
Generative artificial intelligence transparency
Prohibition
Disclosure of use of generative artificial intelligence systems
In general
A person operating an online platform that uses a generative artificial intelligence system shall provide notice to each user of the online platform that the online platform uses a generative artificial intelligence system to generate content the user sees.
Requirements
A person providing the notice described in subparagraph (A) to a user—
subject to clause (ii), shall provide the notice in a clear and conspicuous manner on the online platform before the user interacts with content produced by a generative artificial intelligence system used by the online platform; and
may provide an option for the user to choose to see the notice described in clause (i) only upon the first interaction of the user with content produced by a generative artificial intelligence system.
Enforcement action
Upon learning that a person operating an online platform violates this section after receiving a report of noncompliance or pursuant to an investigation conducted under section 208(f), the Secretary—
shall immediately—
notify the person operating the online platform of the finding; and
order the person operating the online platform to take remedial action to address the noncompliance of the generative artificial intelligence system operated by the online platform; and
may, as determined appropriate or necessary by the Secretary, take enforcement action under section 208 if the person operating the online platform does not take sufficient action to remedy the noncompliance by the date that is 15 days after the notification issued under paragraph (1)(A).
Effective date
This section shall take effect on the date that is 180 days after the date of enactment of this Act.
Transparency reports for high-impact artificial intelligence systems
Transparency reporting
In general
Each deployer of a high-impact artificial intelligence system shall—
before deploying the high-impact artificial intelligence system, and annually thereafter, submit to the Secretary a transparency report for the high-impact artificial intelligence system; and
submit to the Secretary an updated transparency report on the high-impact artificial intelligence system if the deployer makes a material change to—
the purpose for which the high-impact artificial intelligence system is used; or
the type of data or content the high-impact artificial intelligence system processes or uses for training purposes.
Contents
Each transparency report submitted under paragraph (1) by a deployer of a high-impact artificial intelligence system shall include—
with respect to the organization of the deployer—
policies, processes, procedures, and practices across the organization relating to transparent and effective mapping, measuring, and managing of artificial intelligence risks, including—
how the organization understands, manages, and documents legal and regulatory requirements involving artificial intelligence;
how the organization integrates characteristics of trustworthy artificial intelligence, which include valid, reliable, safe, secure, resilient, accountable, transparent, globally and locally explainable, interpretable, privacy-enhanced, and protecting of rights under the Constitution of the United States, and compliant with all relevant Federal laws, into organizational policies, processes, procedures, and practices;
a methodology to determine the needed level of risk management activities based on the risk tolerance of the organization; and
how the organization establishes risk management processes and outcomes through transparent policies, procedures, and other controls based on organizational risk priorities;
the structure, context, and capabilities of the high-impact artificial intelligence system, including—
how the context was established and understood;
capabilities, targeted uses, goals, and expected costs and benefits; and
how risks and benefits are mapped for each system component;
a description of how the organization of the deployer employs quantitative, qualitative, or mixed-method tools, techniques, and methodologies to analyze, assess, benchmark, and monitor artificial intelligence risk, including—
identification of appropriate methods and metrics;
how artificial intelligence systems are evaluated for characteristics of trustworthy artificial intelligence;
mechanisms for tracking artificial intelligence system risks over time; and
processes for gathering and assessing feedback relating to the efficacy of measurement; and
a description of allocation of risk resources to map and measure risks on a regular basis, including—
how artificial intelligence risks based on assessments and other analytical outputs are prioritized, responded to, and managed;
how strategies to maximize artificial intelligence benefits and minimize negative impacts were planned, prepared, implemented, documented, and informed by input from relevant artificial intelligence deployers;
management of artificial intelligence system risks and benefits; and
regular monitoring of risk treatments, including response and recovery, and communication plans for the identified and measured artificial intelligence risks, as applicable.
Developer obligations
The developer of a high-impact artificial intelligence system that agrees to provide technologies or services to a deployer of the high-impact artificial intelligence system shall provide to the deployer of the high-impact artificial intelligence system the information reasonably necessary for compliance with paragraph (1), including—
an overview of the data used in training the baseline artificial intelligence system provided by the developer, including—
size of datasets used;
content and data sources and types of data used;
content and data that may be subject to copyright protection and any steps taken to remove such content and data prior to training or other uses; and
whether and to what extent personal identifiable information makes up a portion of the training dataset, and what risk mitigation measures have been taken to prevent the disclosure of that personal identifiable information;
documentation outlining the structure and context of the baseline artificial intelligence system of the developer, including—
input modality;
system output and modality;
model size; and
model architecture;
known or reasonably foreseeable capabilities, limitations, and risks of the baseline artificial intelligence system at the time of the development of the artificial intelligence system; and
documentation for downstream use, including—
a statement of intended purpose;
guidelines for the intended use of the artificial intelligence system, including a list of permitted, restricted, and prohibited uses and users; and
a description of the potential for and risk of deviation from the intended purpose of the baseline artificial intelligence system, including recommended safeguards to mitigate and prevent risks to safety or to rights afforded under the Constitution of the United States or Federal law.
Considerations
In carrying out this subsection, a deployer or developer of a high-impact artificial intelligence system shall consider the best practices outlined in the most recent version of the risk management framework developed pursuant to section 22A(c) of the National Institute of Standards and Technology Act (15 U.S.C. 278h–1(c)).
Noncompliance and enforcement action
Upon learning that a deployer of a high-impact artificial intelligence system violates this section with respect to a high-impact artificial intelligence system after receiving a report of noncompliance or pursuant to an investigation conducted under section 208(f), the Secretary—
shall immediately—
notify the deployer of the finding; and
order the deployer to immediately submit to the Secretary the report required under subsection (a)(1); and
if the deployer fails to submit the report by the date that is 15 days after the date of the notification under paragraph (1)(A), may take enforcement action under section 208.
Avoidance of duplication
With respect to a developer or deployer of a high-impact artificial intelligence system that maintains policies and procedures for risk management in accordance with any applicable rules, regulations, or supervisory guidance promulgated by a relevant Federal agency, the Secretary shall deem the developer or deployer to be in compliance with this section.
Rule of construction
Nothing in this section shall be construed to require a deployer of a high-impact artificial intelligence system to disclose any information, including data, content, or algorithms—
constituting a trade secret or other intellectual property right; or
that is confidential business information.
Consolidation
With respect to an instance in which multiple deployers participate in the deployment of a high-impact artificial intelligence system, the Secretary may establish through regulation a process under which the deployers may submit a single transparency report under subsection (a).
Guidelines for Federal agencies and plans for oversight of high-impact artificial intelligence systems
Guidelines for federal agencies for oversight of artificial intelligence
The National Institute of Standards and Technology Act (15 U.S.C. 271 et seq.) is amended by inserting after section 22A (15 U.S.C. 278h–1) the following:
Guidelines for Federal agencies for oversight of artificial intelligence
Definition of high-impact artificial intelligence system
In this section, the term high-impact artificial intelligence system means an artificial intelligence system—
deployed for purposes other than those solely for use by the Department of Defense or an element of the intelligence community (as defined in section 3 of the National Security Act of 1947 (50 U.S.C. 3003)); and
that is specifically deployed to make a decision or substantially replace the discretionary human decisionmaking process regarding the access of an individual to housing, employment, credit, education, health care, government services, or insurance in a manner that poses a significant risk to safety or violates rights afforded under the Constitution of the United States.
Guidelines for oversight of high-impact artificial intelligence systems
Not later than 1 year after the date of the enactment of the Artificial Intelligence Research, Innovation, and Accountability Act of 2024, the Director shall—
develop guidelines for Federal agencies to conduct oversight of the non-Federal and, as may be appropriate, Federal use of high-impact artificial intelligence systems to improve the safe and responsible use of such systems; and
not less frequently than biennially, update the guidelines to account for changes in technological capabilities or artificial intelligence use cases.
Use of voluntary risk management framework
In developing guidelines under subsection (b), the Director shall use the voluntary risk management framework required by section 22A(c) to identify and provide guidelines for Federal agencies on establishing regulations, standards, guidelines, best practices, methodologies, procedures, or processes—
to facilitate oversight of non-Federal use of high-impact artificial intelligence systems; and
to mitigate risks from such high-impact artificial intelligence systems.
Authorized elements
In developing guidelines under subsection (b), the Director may include the following:
Key design choices made during high-impact artificial intelligence model development, including rationale and assumptions made.
Intended use and users, other possible use cases, including any anticipated undesirable or potentially harmful use cases, and what good faith efforts model developers can take to mitigate the harms caused by the use of the system.
Methods for evaluating the safety of high-impact artificial intelligence systems and approaches for responsible use.
Consultation
In developing guidelines under subsection (b), the Director may consult with such stakeholders representing perspectives from civil society, academia, technologists, engineers, and creators as the Director considers applicable, practicable, and relevant.
.
Agency-specific plans for oversight of high-impact artificial intelligence systems
Plans required
Not later than 2 years after the date of the enactment of this Act, the head of each covered agency shall—
develop sector-specific plans for the covered agency to conduct oversight of the non-Federal and, as may be appropriate, Federal use of high-impact artificial intelligence systems to improve the safe and responsible use of such systems; and
not less frequently than biennially, update the sector-specific recommendations to account for changes in technological capabilities or artificial intelligence use cases.
Requirements
In developing plans under paragraph (1), the head of each covered agency shall follow the guidelines established under section 22B(b) of the National Institute of Standards and Technology Act, as added by subsection (a), to develop plans to mitigate risks from such high-impact artificial intelligence systems.
Authorized elements
In developing plans under paragraph (1), the head of a covered agency may include the following:
Intended use and users, other possible use cases, including any anticipated undesirable or potentially harmful use cases, and what good faith efforts model developers can take to mitigate the use of the system in harmful ways.
Methods for evaluating the safety of high-impact artificial intelligence systems and approaches for responsible use.
Sector-specific differences in what constitutes acceptable high-impact artificial intelligence model functionality and trustworthiness, metrics used to determine high-impact artificial intelligence model performance, and any test results reflecting application of these metrics to evaluate high-impact artificial intelligence model performance across different sectors.
Recommendations to support iterative development of subsequent recommendations under paragraph (1).
Consultation
In developing plans under paragraph (1), the head of each covered agency shall consult with—
the Under Secretary; and
such stakeholders representing perspectives from civil society, academia, technologists, engineers, and creators as the head of the agency considers applicable, practicable, and relevant.
Office of Management and Budget Oversight guidelines and agency oversight plans
Agency oversight plan
In this section, the term agency oversight plan means a guideline developed under section 22B(b)(1) of the National Institute of Standards and Technology Act, as added by section 204 of this Act.
Recommendations
Not later than 2 years after the date of enactment of this Act, the Under Secretary and the head of each covered agency shall submit to the Director of the Office of Management and Budget and the appropriate congressional committees each agency oversight plan.
Reporting requirements
Annual agency oversight status reports
In general
On the first February 1 occurring after the date that is 2 years after the date of enactment of this Act, and annually thereafter until the date described in subparagraph (B), the head of each covered agency shall submit to the Director of the Office of Management and Budget a report containing the implementation status of each agency oversight plan.
Continued reporting
The date described in this subparagraph is the date on which the head of a covered agency—
takes final implementation action with respect to an agency oversight plan; and
determines and states in a report required under subparagraph (A) that no further implementation action should be taken with respect to an agency oversight plan.
Compliance report to congress
On April 1 of each year occurring after the date that is 2 years after the date of enactment of this Act, the Director of the Office of Management and Budget shall transmit comments on the reports required under paragraph (1) to the heads of covered agencies and the appropriate congressional committees.
Failure to report
If, on March 1 of each year occurring after the date that is 2 years after the date of enactment of this Act, the Director of the Office of Management and Budget has not received a report required from the head of a covered agency under paragraph (1), the Director shall notify the appropriate congressional committees of the failure.
Technical assistance in carrying out agency oversight plans
The Under Secretary shall provide assistance to the heads of covered agencies relating to the implementation of the agency oversight plan the heads of covered agencies intend to carry out.
Regulation review and improvement
The Administrator of the Office of Information and Regulatory Affairs of the Office of Management and Budget, in consultation with the Under Secretary, shall develop and periodically revise performance indicators and measures for sector-specific regulation of artificial intelligence.
Risk management assessment for critical-impact artificial intelligence systems
Requirement
In general
Each critical-impact AI organization shall perform a risk management assessment in accordance with this section.
Assessment
Each critical-impact AI organization shall—
not later than 30 days before the date on which a critical-impact artificial intelligence system is deployed or made publicly available by the critical-impact AI organization, perform a risk management assessment; and
not less frequently than biennially during the period beginning on the date of enactment of this Act and ending on the date on which the applicable critical-impact artificial intelligence system is no longer being deployed or made publicly available by the critical-impact AI organization, as applicable, conduct an updated risk management assessment that—
if no significant changes were made to the critical-impact artificial intelligence system, may find that no significant changes were made to the critical-impact artificial intelligence system; and
provides, to the extent practicable, aggregate results of any significant deviation from expected performance detailed in the assessment performed under subparagraph (A) or the most recent assessment performed under this subparagraph.
Review
In general
Not later than 90 days after the date of completion of a risk management assessment by a critical-impact AI organization under this section, the critical-impact AI organization shall submit to the Secretary a report—
outlining the assessment performed under this section; and
that is in a consistent format, as determined by the Secretary.
Additional information
Subject to subsection (d), the Secretary may request that a critical-impact AI organization submit to the Secretary any related additional or clarifying information with respect to a risk management assessment performed under this section.
Limitation
The Secretary may not prohibit a critical-impact AI organization from making a critical-impact artificial intelligence system available to the public based on the review by the Secretary of a report submitted under paragraph (3)(A) or additional or clarifying information submitted under paragraph (3)(B).
Assessment subject areas
Each assessment performed by a critical-impact AI organization under subsection (a) shall describe the means by which the critical-impact AI organization is addressing, through a documented TEVV process, the following categories:
Policies, processes, procedures, and practices across the organization relating to transparent and effective mapping, measuring, and managing of artificial intelligence risks, including—
how the organization understands, manages, and documents legal and regulatory requirements involving critical-impact artificial intelligence systems;
how the organization integrates the characteristics of trustworthy artificial intelligence, which include valid, reliable, safe, secure, resilient, accountable, transparent, globally and locally explainable, interpretable, privacy-enhanced, protecting of rights under the Constitution of the United States, and compliant with all relevant Federal laws, into organizational policies, processes, procedures, and practices for deploying critical-impact artificial intelligence systems;
a methodology to determine the needed level of risk management activities for critical-impact artificial intelligence systems based on the organization’s risk tolerance; and
how the organization establishes risk management processes and outcomes through transparent policies, procedures, and other controls based on organizational risk priorities.
The structure, context, and capabilities of the critical-impact artificial intelligence system, including—
how the context was established and understood;
capabilities, targeted uses, goals, and expected costs and benefits; and
how risks and benefits are mapped for each system component.
A description of how the organization employs quantitative, qualitative, or mixed-method tools, techniques, and methodologies to analyze, assess, benchmark, and monitor artificial intelligence risk, including—
identification of appropriate methods and metrics;
how artificial intelligence systems are evaluated for characteristics of trustworthy artificial intelligence;
mechanisms for tracking artificial intelligence system risks over time; and
processes for gathering and assessing feedback relating to the efficacy of measurement.
A description of allocation of risk resources to map and measure risks on a regular basis as described in paragraph (1), including—
how artificial intelligence risks based on assessments and other analytical outputs described in paragraphs (2) and (3) are prioritized, responded to, and managed;
how strategies to maximize artificial intelligence benefits and minimize negative impacts were planned, prepared, implemented, documented, and informed by input from relevant artificial intelligence deployers;
management of artificial intelligence system risks and benefits; and
regular monitoring of risk treatments, including response and recovery, and communication plans for the identified and measured artificial intelligence risks, as applicable.
Developer obligations
The developer of a critical-impact artificial intelligence system that agrees to provide technologies or services to a deployer of the critical-impact artificial intelligence system shall provide to the deployer of the critical-impact artificial intelligence system the information reasonably necessary for the deployer to comply with the requirements under subsection (a), including—
an overview of the data used in training the baseline artificial intelligence system provided by the developer, including—
content and size of datasets used;
content and types of data used;
content and data that may be subject to copyright protection, and any steps taken to remove such content and data prior to training; and
whether and to what extent personal identifiable information makes up a portion of the training dataset, and what risk mitigation measures have been taken to prevent the disclosure of that personal identifiable information;
documentation outlining the structure and context of the baseline artificial intelligence system of the developer, including—
input modality;
system output and modality;
model size; and
model architecture;
known or reasonably foreseeable capabilities, limitations, and risks of the baseline artificial intelligence system at the time of the development of the artificial intelligence system; and
documentation for downstream use, including—
a statement of intended purpose;
guidelines for the intended use of the artificial intelligence system, including a list of permitted, restricted, and prohibited uses and users; and
a description of the potential for and risk of deviation from the intended purpose of the baseline artificial intelligence system, including recommended safeguards to mitigate and prevent risks to safety or to rights afforded under the Constitution of the United States or Federal law.
Termination of obligation to disclose information
In general
The obligation of a critical-impact AI organization to provide information, upon a request of the Secretary, relating to a specific assessment category under subsection (b) shall end on the date of issuance of a relevant standard applicable to the same category of a critical -impact artificial intelligence system by—
the Secretary under section 207(c) with respect to a critical-impact artificial intelligence system;
another department or agency of the Federal Government, as determined applicable by the Secretary; or
a nongovernmental standards organization, as determined appropriate by the Secretary.
Effect of new standard
In adopting any standard applicable to critical-impact artificial intelligence systems under section 207(c), the Secretary shall—
identify the category under subsection (b) to which the standard relates, if any; and
specify the information that is no longer required to be included in a report required under subsection (a) as a result of the new standard.
Rule of construction
Nothing in this section shall be construed to require a critical-impact AI organization or permit the Secretary to disclose any information, including data or algorithms—
constituting a trade secret or other intellectual property right; or
that is confidential business information.
Consolidation
With respect to an instance in which multiple critical-impact AI organizations participate in the deployment of a high-impact artificial intelligence system, the Secretary may establish through regulation a process under which the critical-impact AI organizations may submit a single risk management assessment under subsection (a).
Certification of critical-impact artificial intelligence systems
Establishment of artificial intelligence certification advisory committee
In general
Not later than 180 days after the date of enactment of this Act, the Secretary shall establish an advisory committee to provide advice and recommendations on TEVV standards and the certification of critical-impact artificial intelligence systems.
Duties
The advisory committee established under this section shall advise the Secretary on matters relating to the testing and certification of critical-impact artificial intelligence systems, including by—
providing recommendations to the Secretary on proposed TEVV standards to ensure such standards—
maximize alignment and interoperability with standards issued by nongovernmental standards organizations and international standards bodies; and
are performance-based, impact-based, and risk-based;
reviewing prospective TEVV standards submitted by the Secretary to ensure such standards align with recommendations under subparagraph (A);
upon completion of the review under subparagraph (B), providing consensus recommendations to the Secretary on—
whether a TEVV standard should be issued, modified, revoked, or added; and
if such a standard should be issued, how best to align the standard with the considerations described in subsection (c)(2) and recommendations described in subparagraph (A); and
reviewing and providing advice and recommendations on the plan and subsequent updates to the plan submitted under subsection (b).
Composition
The advisory committee established under this subsection shall be appointed by the Secretary and composed of not more than 15 members with a balanced composition of representatives of the private sector, institutions of higher education, and nonprofit organizations, including—
representatives of—
institutions of higher education;
companies developing or operating artificial intelligence systems;
consumers or consumer advocacy groups;
enabling technology companies; and
labor organizations representing the technology sector; and
any other members the Secretary considers to be appropriate.
Artificial intelligence certification plan
In general
Not later than 1 year after the date of enactment of this Act, the Secretary shall establish a 3-year implementation plan for the certification of critical-impact artificial intelligence systems.
Periodic update
As the Secretary determines appropriate, the Secretary shall update the plan established under paragraph (1).
Contents
The plan established under paragraph (1) shall include—
a methodology for gathering and using relevant, objective, and available information relating to TEVV;
a process for considering whether prescribing certain TEVV standards under subsection (c) for critical-impact artificial intelligence systems is appropriate, necessary, or duplicative of existing international standards;
if TEVV standards are considered appropriate, a process for prescribing such standards for critical-impact artificial intelligence systems;
a mechanism for determining compliance with TEVV standards; and
an outline of standards proposed to be issued, including an estimation of the timeline and sequencing of such standards.
Consultation
In developing the plan required under paragraph (1), the Secretary shall consult the following:
The National Artificial Intelligence Initiative Office.
The interagency committee established under section 5103 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9413).
The National Artificial Intelligence Advisory Committee.
Consensus standards issued by nongovernmental standards organizations.
The Cybersecurity and Infrastructure Security Agency.
Other departments, agencies, and instrumentalities of the Federal Government, as considered appropriate by the Secretary.
Submission to certification advisory committee
Upon completing the initial plan required under this subsection and upon completing periodic updates to the plan under paragraph (2), the Secretary shall submit the plan to the advisory committee established under subsection (a) for review.
Submission to committees of congress
Upon completing the plan required under this subsection, the Secretary shall submit to the appropriate congressional committees a report containing the plan.
Limitation
The Secretary may not issue TEVV standards under subsection (c) until the date of the submission of the plan under paragraphs (5) and (6).
Standards
Standards
In general
The Secretary shall issue TEVV standards for critical-impact artificial intelligence systems.
Requirements
Each standard issued under this subsection shall—
be practicable;
meet the need for safe, secure, and transparent operations of critical-impact artificial intelligence systems;
with respect to a relevant standard issued by a nongovernmental standards organization that is already in place, not unintentionally contradict that standard;
provide for a mechanism to, not less frequently than once every 2 years, solicit public comment and update the standard to reflect evidence about the utility of risk mitigation approaches and advancements in technology and system architecture; and
be stated in objective terms.
Considerations
In issuing TEVV standards for critical-impact artificial intelligence systems under this subsection, the Secretary shall—
consider relevant available information concerning critical-impact artificial intelligence systems, including—
transparency reports submitted under section 203(a);
risk management assessments conducted under section 206(a); and
any additional information provided to the Secretary pursuant to section 203(a)(1)(B);
consider whether a proposed standard is reasonable, practicable, and appropriate for the particular type of critical-impact artificial intelligence system for which the standard is proposed;
consult with stakeholders with expertise in addressing risks and design of artificial intelligence systems and review standards issued by nongovernmental standards organizations;
pursuant to paragraph (1)(B)(iii), consider whether adoption of a relevant standard issued by a nongovernmental standards organization as a TEVV standard is the most appropriate action; and
consider whether the standard takes into account—
transparent, replicable, and objective assessments of critical-impact artificial intelligence system risk, structure, capabilities, and design;
the risk posed to the public by an applicable critical-impact artificial intelligence system; and
the diversity of methodologies and innovative technologies and approaches available to meet the objectives of the standard.
Consultation
Before finalizing a TEVV standard issued under this subsection, the Secretary shall submit the TEVV standard to the advisory committee established under subsection (a) for review.
Public comment
Before issuing any TEVV standard under this subsection, the Secretary shall—
publish a notice describing the TEVV standard; and
provide an opportunity for public comment pursuant to section 553 of title 5, United States Code.
Cooperation
In developing a TEVV standard under this subsection, the Secretary may, as determined appropriate, advise, assist, and cooperate with departments, agencies, and instrumentalities of the Federal Government, States, and other public and private agencies.
Effective date of standards
In general
The Secretary shall specify the effective date of a TEVV standard issued under this subsection in the order issuing the standard.
Limitation
Subject to subparagraph (C), a TEVV standard issued under this subsection may not become effective—
during the 180-day period following the date on which the TEVV standard is issued; and
more than 1 year after the date on which the TEVV standard is issued.
Exception
Subparagraph (B) shall not apply to the effective date of a TEVV standard issued under this section if the Secretary—
finds, for good cause shown, that a different effective date is in the public interest; and
publishes the reasons for the finding under clause (i).
Rule of construction
Nothing in this subsection shall be construed to authorize the Secretary to impose any requirements on or take any enforcement actions under this section or section 208 relating to a critical-impact AI organization before a TEVV standard relating to those requirements is prescribed.
Exemptions
Authority to exempt and procedures
In general
The Secretary may exempt, on a temporary basis, a critical-impact artificial intelligence system from a TEVV standard issued under subsection (c) on terms the Secretary considers appropriate.
Renewal
An exemption under subparagraph (A)—
may be renewed only on reapplication; and
shall conform to the requirements of this paragraph.
Proceedings
In general
The Secretary may begin a proceeding to grant an exemption to a critical-impact artificial intelligence system under this paragraph if the critical-impact AI organization that deployed the critical-impact artificial intelligence system applies for an exemption or a renewal of an exemption.
Notice and comment
The Secretary shall publish notice of the application under clause (i) and provide an opportunity for public comment under section 553 of title 5, United States Code.
Filing
An application for an exemption or for a renewal of an exemption under this paragraph shall be filed at such time and in such manner and contain such information as the Secretary may require.
Actions
The Secretary may grant an exemption under this paragraph upon finding that—
the exemption is consistent with the public interest and this section; and
the exemption would facilitate the development or evaluation of a feature or characteristic of a critical-impact artificial intelligence system providing a safety and security level that is not less than the TEVV standard level.
Disclosure
Not later than 30 days after the date on which an application is filed under this subsection, the Secretary may make public information contained in the application or relevant to the application, unless the information concerns or constitutes a trade secret or other confidential information not relevant to the application.
Notice of decision
The Secretary shall publish in the Federal Register a notice of each decision granting or denying an exemption under this subsection and the reasons for granting or denying that exemption, including a justification with supporting information for the selected approach.
Certification of compliance
In general
Subject to paragraph (2), with respect to each critical-impact artificial intelligence system of a critical-impact AI organization, the critical-impact AI organization shall certify to the Secretary that the critical-impact artificial intelligence system complies with applicable TEVV standards issued under this section.
Exception
A critical-impact AI organization may not issue a certification under paragraph (1) if, in exercising reasonable care, the critical-impact AI organization has constructive knowledge that the certification is false or misleading in a material respect.
Developer obligations
The developer of a critical-impact artificial intelligence system that enters into a contractual or licensing agreement with a critical impact AI organization shall be subject to the same disclosure obligations as a developer of a critical impact artificial intelligence system under section 206(c).
Noncompliance findings and enforcement action
Finding of noncompliance by secretary
Upon learning that a critical-impact artificial intelligence system deployed by a critical-impact AI organization violates this section upon receiving a report of noncompliance pursuant to an investigation conducted under section 208(f) or through other means established through TEVV standards pursuant to this section, the Secretary shall—
immediately—
notify the critical-impact AI organization of the finding; and
order the critical-impact AI organization to take remedial action to address the noncompliance of the artificial intelligence system; and
may, as determined appropriate or necessary by the Secretary, and if the Secretary determines that actions taken by a critical-impact AI organization are insufficient to remedy the noncompliance of the critical-impact AI organization with this section, take enforcement action under section 208.
Actions by critical-impact ai organization
If a critical-impact AI organization finds that a critical-impact artificial intelligence system deployed by the critical-impact AI organization is noncompliant with an applicable TEVV standard issued under this section or the critical-impact AI organization is notified of noncompliance by the Secretary under paragraph (1)(A)(i), the critical-impact AI organization shall—
without undue delay, notify the Secretary by certified mail or electronic mail of the noncompliance or receipt of the notification of noncompliance;
take remedial action to address the noncompliance; and
not later than 10 days after the date of the notification or receipt under subparagraph (A), submit to the Secretary a report containing information on—
the nature and discovery of the noncompliant aspect of the critical-impact artificial intelligence system;
measures taken to remedy such noncompliance; and
actions taken by the critical-impact AI organization to address stakeholders affected by such noncompliance.
Enforcement
In general
The Secretary shall take an action described in this section—
upon discovering noncompliance with a provision of this Act by a deployer of a high-impact artificial intelligence system, a critical-impact AI organization, or a developer of a critical-impact artificial intelligence system; and
if the Secretary determines that actions taken by the deployer of a high-impact artificial intelligence system, a critical-impact AI organization, or the developer of a critical-impact artificial intelligence system are insufficient to remedy the noncompliance.
Civil penalties
In general
The Secretary may impose a penalty described in paragraph (2) on a deployer of a high-impact artificial intelligence system or a critical-impact AI organization for each violation by that entity of this Act or any regulation or order issued under this Act.
Penalty described
The penalty described in this paragraph is the greater of—
an amount not to exceed $300,000; or
an amount that is twice the value of the artificial intelligence system product deployed that is the basis of the violation with respect to which the penalty is imposed.
Violation with intent
In general
If the Secretary determines that a deployer of a high-impact artificial intelligence system or a critical-impact AI organization intentionally violates this Act or any regulation or order issued under this Act, the Secretary may prohibit the critical-impact AI organization or deployer, as applicable, from deploying a critical-impact artificial intelligence system or a high-impact artificial intelligence system.
In addition
A prohibition imposed under paragraph (1) shall be in addition to any other civil penalties provided under this Act.
Factors
The Secretary may by regulation provide standards for establishing levels of civil penalty under this section based upon factors, such as the seriousness of the violation, the culpability of the violator, and such mitigating factors as the violator’s record of cooperation with the Secretary in disclosing the violation.
Civil action
In general
Upon referral by the Secretary, the Attorney General may bring a civil action in a United States district court to—
enjoin a violation of section 207; or
collect a civil penalty upon a finding of noncompliance with this Act.
Venue
A civil action may be brought under paragraph (1) in the judicial district in which the violation occurred or the defendant is found, resides, or does business.
Process
Process in a civil action under paragraph (1) may be served in any judicial district in which the defendant resides or is found.
Authority to investigate
The Secretary may conduct an investigation—
that may be necessary to enforce this Act or a TEVV standard or regulation prescribed pursuant to this Act; or
related to a report of noncompliance with this Act from a third party, a deployer or developer of an artificial intelligence system subject to the requirements of this Act, or discovered by the Secretary.
Rule of construction
Nothing in this section shall be construed to require a deployer of a critical-impact artificial intelligence system to disclose any information, including data or algorithms—
constituting a trade secret or other protected intellectual property right; or
that is confidential business information.
Developer and deployer overlap
With respect to an entity that is a deployer and a developer, the entity shall be subject to the requirements of deployers and developers under this Act.
Artificial intelligence consumer education
Establishment
Not later than 180 days after the date of enactment of this Act, the Secretary shall establish a working group relating to responsible education efforts for artificial intelligence systems.
Membership
In general
The Secretary shall appoint to serve as members of the working group established under this section not more than 15 individuals with expertise relating to artificial intelligence systems, including—
representatives of—
institutions of higher education;
companies developing or operating artificial intelligence systems;
consumers or consumer advocacy groups;
public health organizations;
marketing professionals;
entities with national experience relating to consumer education, including technology education;
public safety organizations;
rural workforce development advocates;
enabling technology companies; and
nonprofit technology industry trade associations; and
any other members the Secretary considers to be appropriate.
Compensation
A member of the working group established under this section shall serve without compensation.
Duties
In general
The working group established under this section shall—
identify recommended education and programs that may be voluntarily employed by industry to inform—
consumers and other stakeholders with respect to artificial intelligence systems as those systems—
become available; or
are soon to be made widely available for public use or consumption; and
submit to Congress, and make available to the public, a report containing the findings and recommendations under subparagraph (A).
Factors for consideration
The working group established under this section shall take into consideration topics relating to—
the intent, capabilities, and limitations of artificial intelligence systems;
use cases of artificial intelligence applications that improve lives of the people of the United States, such as improving government efficiency, filling critical roles, and reducing mundane work tasks;
artificial intelligence research breakthroughs;
engagement and interaction methods, including how to adequately inform consumers of interaction with an artificial intelligence system;
human-machine interfaces;
emergency fallback scenarios;
operational boundary responsibilities;
potential mechanisms that could change function behavior in service;
consistent nomenclature and taxonomy for safety features and systems; and
digital literacy.
Consultation
The Secretary shall consult with the Chair of the Federal Trade Commission with respect to the recommendations of the working group established under this section, as appropriate.
Termination
The working group established under this section shall terminate on the date that is 2 years after the date of enactment of this Act.
Severability
If any provision of this title, or an amendment made by this title, or the application of such provision to any person or circumstance is held to be unconstitutional, the remainder of this title, or an amendment made by this title, and the application of the provisions of such to all other persons or circumstances shall not be affected thereby.
December 18 (legislative day, December 16), 2024
Reported with an amendment