A bill on tracking attacks and incidents against AI — defining adversarial AI in statute
S.5061, the Secure A.I. Development Act of 2026, improves the tracking and processing of security and safety incidents and risks associated with artificial intelligence. It defines adversarial artificial intelligence as techniques or procedures to extract information about an AI system behavior or characteristics, or to learn how to manipulate it, in order to subvert the confidentiality, integrity or availability of that system or an adjacent one.
Bill overview (primary data)
- Bill numberS. 5061
- TypeSenate Bill
- Congress119th Congress
- Latest actionRead twice and referred to the Committee on Commerce, Science, and Transportation.(2026-07-21)
Key points
- S.5061 improves the tracking and processing of security and safety incidents and risks associated with AI.
- It defines adversarial AI as techniques or procedures to extract information about an AI system or learn to manipulate it.
- What gets subverted is expressed as confidentiality, integrity or availability — the classic triad of information security.
- The definition reaches not only the AI system itself but adjacent systems.
- It neither prohibits nor imposes new duties, building machinery to record and handle what happens instead.
1AI as the thing being attacked
Debate about AI safety tends to gather around risks that AI creates. This bill addresses the other side, where AI is what gets attacked. The adversarial artificial intelligence it defines means techniques for extracting information about the behavior or characteristics of an AI system, or procedures for learning how to manipulate it.
Probing what is inside a model, or finding how to make it behave unintendedly — in the older vocabulary of security, reconnaissance and compromise.
2Three properties in the definition
- 1What it doesExtracts information about an AI system behavior or characteristics, or learns how to manipulate the system
- 2What it subvertsConfidentiality, integrity or availability — the classic triad of information security
- 3How far it reachesNot only the AI system itself but adjacent systems
That the definition uses the classic triad of information security stands out. Rather than erecting a new framework peculiar to AI, it situates the subject on established vocabulary. Reaching adjacent systems also matters, capturing cases where the model itself is not compromised but serves as the route to what surrounds it.
3Improving tracking and processing
The stated aim is improving the tracking and processing of incidents and risks. Neither prohibiting anything nor imposing new duties, but building the machinery to record and handle what happens. Another bill this site covers has NIST build a voluntary reporting program for AI flaws, so the same problem is being worked from the security side and the standards side in parallel.
4Two ways of citing it
The bill supplies a second citation name alongside its formal title: Secure Artificial Intelligence Development Act of 2026 and Secure A.I. Development Act of 2026, the latter using the abbreviation. Providing two citation names is not unusual, and either refers to the same bill. Of the 120 bills this site holds as of 2026-09-02, 94 (78 percent) remain referred to committee.
Why it matters
Viewing AI as something attacked prompts a reexamination of how far internal security covers the model and its surroundings. Because the definition sits on the information security triad, it connects readily to existing controls.
FAQ
What is adversarial AI here?
Why include adjacent systems?
Sources (primary)
Source: Congress.gov (Library of Congress; U.S. legislative materials, public domain). Links go to the official site.
- Congress.gov (bill page, original)
- S. 5061(119th Congress)