AI Flaw Reporting and Security Enhancement Act (HR9333)
Current understanding
HR9333 would establish a mandatory AI vulnerability disclosure framework, creating structured reporting requirements for flaws and security weaknesses discovered in AI systems — importing the coordinated vulnerability disclosure model familiar from general cybersecurity into AI governance. The bill was ordered reported by the House committee 35-0, indicating strong bipartisan support at the committee stage. Practical implications include new compliance obligations for AI developers/deployers and a federal channel for flaw intake; fiscal implications depend on which agency is designated as coordinator. Status: ordered reported by committee.
Evidence log
- 2026-06-25 — AI Security and Innovation Act: cross-connection with ai-security-innovation-act-hr9363: Both bills advance the congressional framework for AI security; HR9363 addresses broader security/innovation governance while HR9333 focuses on vulnerability disclosure. (novelty: 3)
- 2025-11-20 — Generative AI Terrorism Risk Assessment Act: cross-connection with generative-ai-terrorism-risk-assessment-act: Both establish federal reporting/assessment mechanisms around AI system risks — one focused on terrorism threat assessment (DHS), the other on security flaw reporting. (novelty: 3)
- 2026-06-25 — AI Flaw Reporting and Security Enhancement Act: cross-connection with advanced-ai-innovation-security-eo: Both establish AI security governance infrastructure — the EO through executive direction on AI innovation/security posture, HR9333 through a statutory vulnerability disclosure regime. (novelty: 3)