A bill directing NIST to build voluntary reporting for AI flaws — starting with definitions of vulnerability, failure mode and accident
H.R.9333, the AI Flaw Reporting and Security Enhancement Act, directs the Director of the National Institute of Standards and Technology to carry out a program supporting the voluntary reporting, collection and tracking of artificial intelligence flaws, in consultation with the Director of CISA. The committee ordered it reported 35 to 0.
Bill overview (primary data)
- Bill numberH.R. 9333
- TypeHouse Bill
- Congress119th Congress
- Latest actionOrdered to be Reported in the Nature of a Substitute by the Yeas and Nays: 35 - 0.(2026-06-25)
Key points
- H.R.9333 directs the NIST Director to carry out a program supporting voluntary reporting, collection and tracking of AI flaws.
- The Director consults CISA and convenes industry, academia, nonprofits, standards bodies, civil society groups and federal agencies.
- The first task is establishing common definitions and characterizations, including vulnerabilities, failure modes and accidents.
- Reporting is designed as voluntary rather than mandatory.
- The committee ordered it reported 35 to 0; 15 of the 120 bills this site holds as of 2026-09-02 have reached that stage, with 94 still in committee.
1Agreeing on words before collecting reports
Software vulnerabilities have grown a reporting and sharing apparatus over many years: a numbering scheme, a way to score severity, conventions for disclosure. Nothing equivalent exists for AI flaws. What this bill asks for first is not the operation of a program but definitions. What counts as a vulnerability, a failure mode, an accident.
While the same words carry different meanings to different people, reports cannot be compared even once collected.
2Who gets convened
- 1LeadThe Director of the National Institute of Standards and Technology
- 2ConsultationThe Director of the Cybersecurity and Infrastructure Security Agency
- 3Who is convenedRepresentatives of industry, academia, nonprofit organizations, standards development organizations, civil society groups and appropriate federal departments and agencies
- 4First taskEstablish common definitions and characterizations for relevant aspects relating to AI flaws
That civil society groups appear explicitly among those convened is notable. An AI flaw can be more than a technical malfunction; it can be behavior that disadvantages particular people. Leaving the definition to builders and deployers alone would tilt it.
3Voluntary by design
The program supports voluntary reporting rather than compelling it. Mandating reports raises the count, but if reporting exposes the reporter to harm, little of substance arrives. In software vulnerability disclosure, information began flowing once mechanisms protecting reporters worked. Building a place to receive voluntary reports first, and settling shared language, reads as drawing on that experience.
4Unanimous in committee
The latest status is an order to report in the nature of a substitute, 35 to 0. Of the 120 bills this site holds as of 2026-09-02, 15 have reached the ordered-reported stage, while 94 (78 percent) remain referred to committee. Against that, reaching a report with no votes against suggests the subject is one that does not readily become contested.
Why it matters
Sharing AI failures across an industry is becoming a subject of legislation. Starting from unified definitions applies just as directly to setting up internal recording and classification of AI incidents.
FAQ
Why begin with definitions?
Why voluntary rather than mandatory?
Sources (primary)
Source: Congress.gov (Library of Congress; U.S. legislative materials, public domain). Links go to the official site.
- Congress.gov (bill page, original)
- H.R. 9333(119th Congress)