AI Flaw Reporting and Security Enhancement Act
Current understanding
HR9333, the AI Flaw Reporting and Security Enhancement Act, would establish mandatory AI vulnerability disclosure requirements — creating a coordinated flaw-reporting mechanism for AI systems analogous to established vulnerability disclosure regimes in cybersecurity. As of the most recent action, the House committee ordered the bill reported by a unanimous 35-0 vote, indicating strong bipartisan support at the committee stage. For developers, the bill would impose obligations to receive and act on flaw reports; for platforms deploying AI, it would formalize expectations around vulnerability handling; for users and researchers, it would create clearer channels to report AI defects and safety issues.
Evidence log
- 2026-06-25 — AI Incident Reporting Act: Parallel bill HR9477 (AI Incident Reporting Act) referred to House Energy and Commerce in June 2026, reinforcing the two-track model of pre-incident flaw disclosure (HR9333) plus post-incident mandatory reporting (HR9477). (novelty: 3)
- 2026-06-25 — AI Security and Innovation Act: cross-connection with ai-security-and-innovation-act: Both are AI security-focused bills advanced by unanimous committee votes in the 119th Congress, forming part of a coordinated AI security legislative package. (novelty: 3)
- 2026-06-25 — AI Flaw Reporting and Security Enhancement Act: cross-connection with ai-incident-reporting: Both bills build a federal AI safety reporting infrastructure — the Flaw Reporting Act addresses pre-incident vulnerability disclosure while the AI Incident Reporting Act addresses post-incident harm reporting; together they form parallel tracks of a proposed federal AI safety reporting stack. (novelty: 3)