H.R. 10189 House Bill 119th Congress

A bill directing the Defense Department to build an AI incident reporting programme - non-punitive reporting and department-wide trend analysis (H.R.10189)

U.S. House Latest update Aug 31, 2026

H.R.10189, the Defense AI Reliability and Reporting Act, would amend title 10 of the U.S. Code to direct the Secretary of Defense to establish a department-wide programme for reporting AI incidents and vulnerabilities. It was referred to the House Committee on Armed Services on 31 August 2026.

Bill overview (primary data)

  • Bill numberH.R. 10189
  • TypeHouse Bill
  • Congress119th Congress
  • Latest actionReferred to the House Committee on Armed Services.(2026-08-31)

Key points

  • The bill would have the Secretary of Defense establish a department-wide programme reporting, tracking, analysing and remediating AI incidents and vulnerabilities.
  • It covers incidents arising from development, testing, procurement, fielding or operation, including risks from human-machine teaming.
  • The programme is to be designed from established safety incident reporting, vulnerability disclosure and lessons-learned practice.
  • Non-punitive reporting, protection of sensitive and proprietary information and dissemination of lessons are written into the text.
  • It requires a mechanism for timely access to and sharing of logs, system data and model information to support analysis.
  • Of the 120 bills this site holds as of 2026-09-02, five were referred to the Armed Services committee.

1Applying to AI a mechanism for learning from accidents

Aviation and medicine have long had arrangements for reporting accidents and near misses, analysing causes and carrying the result forward. This bill applies that idea to AI systems. Rather than handling each fault inside the unit where it occurred, it gathers them department-wide in one place, finds the recurring shapes and returns them to decisions about testing and procurement.

2Non-punitive is the pivot

Reporting that carries penaltyNon-punitive reporting (what the bill requires)
The reporter may suffer for itThe premise is that reporting brings no disadvantage
Reports fall away and the picture disappearsWhat happened accumulates
Only serious events surfaceSmall signs can surface too

The bill directs that the programme be designed from established safety incident reporting, vulnerability disclosure and lessons-learned practice, and states an emphasis on non-punitive reporting, protection of sensitive and proprietary information, and dissemination of lessons learned.

Whether a reporting programme works depends on whether reporters believe they will not lose by it - knowledge built up in aviation safety appears here as a statutory requirement.

3The text also specifies what analysis needs

  1. 1ReportPrompt reporting of covered AI incidents and vulnerabilities is required
  2. 2StandardiseA designated official receives reports and aligns their form
  3. 3Analyse trendsRecurring risks and failure modes are identified
  4. 4Return itGuidance, alerts and recommendations inform testing, procurement and deployment

The text also requires a mechanism enabling timely access to and sharing of relevant logs, system data and model information as necessary to support analysis and response. AI faults often cannot be traced from the output alone, and whether training data and model information can be seen decides whether analysis is possible at all. That this premise is written into the design of the programme is what marks it.

4Where it stands, and the shape of bills in this field

Of the 120 congressional bills this site holds as of 2026-09-02, 94 sit at committee referral, 17 have been ordered reported by a committee, five have been received in the other chamber and two are on a calendar. This bill is at the first of those stages. Referrals divide across 23 committees, five of them to Armed Services.

Why it matters

For suppliers of AI, an incident reporting programme translates directly into what must be produced when something goes wrong. That the text requires access to logs, system data and model information bears on delivery terms and on design. Non-punitive reporting sits alongside protection of proprietary information, making the line of what is disclosed the practical question.

FAQ

What would the bill require?
That the Secretary of Defense establish a centralized department-wide programme to report, track, analyse and remediate AI incidents and vulnerabilities.
Why does the text specify non-punitive reporting?
Because reports do not accumulate where reporters expect to suffer for them, and the picture disappears. The design follows safety reporting practice built up in fields such as aviation.
Where does it stand?
Referred to the House Committee on Armed Services on 31 August 2026. Bills change in substance and status while under deliberation.

Sources (primary)

Source: Congress.gov (Library of Congress; U.S. legislative materials, public domain). Links go to the official site.

#congressional bills#AI#Department of Defense#incident reporting#vulnerabilities#House
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.