AI Threat Output and Monitoring Incident Containment Act (H.R.9965) — national laboratories testing AI against practical jailbreaking techniques and recommending containment and loss-of-control planning
A House bill directing the Secretary of Energy, within 90 days of enactment and acting through the national laboratories, to establish an Advanced Artificial Intelligence Nuclear Evaluation Program. It tests and evaluates AI for the likelihood of an AI nuclear incident, builds in protocols addressing practical jailbreaking techniques, and provides for red-teaming by entities with expertise comparable to sophisticated malicious actors.
Bill overview (primary data)
- Bill numberH.R. 9965
- TypeHouse Bill
- Congress119th Congress
- Latest actionReferred to the House Committee on Science, Space, and Technology.(2026-07-27)
Key points
- Within 90 days of enactment the Secretary of Energy, acting through the national laboratories, establishes an Advanced Artificial Intelligence Nuclear Evaluation Program.
- Testing implements protocols addressing practical jailbreaking techniques, with red-teaming by entities of expertise comparable to sophisticated malicious actors.
- Independent third-party assessments and blind model evaluations are facilitated to the extent practicable.
- Each participant receives a report on the outcomes and an identification of the risks and safety measures tested.
- Recommendations on containment protocols, contingency planning and mitigation strategies go to large advanced AI developers and the national laboratories.
- Testing incorporates jailbreak techniques used in practice, with red teaming by parties comparable to sophisticated malicious actors.
1Placing the testing side at the national laboratories
Where to place the body that evaluates the danger of an AI system is a fork in institutional design. What this bill picks is the national laboratories of the Department of Energy, using places where knowledge and facilities bearing on nuclear matters already sit.
A deadline is set as well: the programme is to be established within 90 days of enactment, so building the arrangement is not to take long. The object of evaluation is the likelihood of an AI nuclear incident, and narrowing the scope settles what is being looked for.
2Testing with the techniques actually used
Worth noting is how far the text reaches into the content of the testing. Implementing protocols that address practical jailbreaking techniques, and red-teaming by entities the Secretary determines to have expertise comparable to sophisticated malicious actors, are both written into the provision.
Testing only the intended uses will not reveal the possibilities of misuse. The thinking is to test with force equal to those who would actually break it. Alongside that, independent third-party assessments and blind model evaluations are to be facilitated to the extent practicable, a device for holding distance between those who evaluate and those who build.
3Handing back results and recommending preparation
The programme provides each participant with a report on the outcomes of the testing and an identification of the risks and safety measures tested. It further develops, for large advanced AI developers and the national laboratories, recommendations on containment protocols, contingency planning and mitigation strategies.
Finding danger is not the end; what to do once it is found is inside the scope. That loss of control appears in the text indicates the breadth of situation the programme contemplates. Of the 114 AI-related bills this site holds as of 2026-09-01, among the 44 not yet covered, six carry titles beginning with direct.
4Testing with the same strength as those who would break it
What draws attention here is that the bill goes into the substance of the testing. Testing only the intended uses, the premise runs, does not reveal the possibility of misuse.
- 1Place it at a national laboratoryUse a Department of Energy laboratory where nuclear expertise and facilities already exist
- 2Test with the actual methodsIncorporate procedures corresponding to jailbreak techniques used in practice
- 3Test at equal strengthConduct red teaming by parties the Secretary determines have expertise comparable to sophisticated malicious actors
- 4Keep the distancePromote independent third-party evaluation and blinded evaluation to the extent practicable
A plan is to be established within 90 days of enactment, presupposing that building the arrangement does not take long. The plan delivers to participants a report on test results and on the risks and safety measures identified, and develops recommendations on containment procedures, contingency plans and mitigations for large advanced AI developers and the national laboratories.
Why it matters
Safety evaluation means little if only intended uses are tried. Testing with the techniques that would actually be used, and holding distance between evaluator and builder, both become statutory words here. For a developer it could create a need to be ready for blind third-party evaluation.
FAQ
Why the national laboratories?
What is red-teaming?
What is a blind model evaluation?
Sources (primary)
Source: Congress.gov (Library of Congress; U.S. legislative materials, public domain). Links go to the official site.
- Congress.gov (bill page, original)
- H.R. 9965(119th Congress)