AI Flaw Reporting and Security Enhancement Act
This bill establishes a program to facilitate the voluntary reporting and tracking of artificial intelligence (AI) flaws, to be administered by the National Institute of Standards and Technology (NIST).
In carrying out this program, NIST must seek to convene various stakeholders to establish common definitions for terms related to AI flaws and criteria for the classification of AI flaws (e.g., security-related flaws and safety-related flaws). The group must also support the development of technical standards and guidance related to detecting, managing, and disclosing AI flaws and prioritizing the remediation of such flaws.
Further, NIST must develop, or enter into cooperative agreements with institutions of higher education or research institutions to develop, infrastructure for the voluntary reporting, collection, and tracking of AI flaws. This must include a national database of AI flaws or the modification of an existing national database to account for AI flaws. (NIST currently administers a national database of cybersecurity vulnerabilities.) NIST must consider certain topics when developing this infrastructure, including the interoperability of the infrastructure with relevant existing systems, standards, and best practices.
Within three years of the bill’s enactment, NIST must report to Congress on the implementation of these provisions.
Under the bill, an AI flaw is a set of conditions or behaviors that allow for the violation of certain policies (e.g., safety or security policies) and is not necessarily associated with malicious intent.