Brian Schatz

09/24/2026 | Press release | Distributed by Public on 09/24/2026 13:15

Schatz, Warner To Take To Senate Floor To Demand Passage Of New AI Security Legislation

Published: 09.24.2026

Schatz, Warner To Take To Senate Floor To Demand Passage Of New AI Security Legislation

New bill comes amid stark warnings from leading AI companies and cybersecurity researchers about rapidly advancing cyber capabilities and real-world security incidents

WASHINGTON - Today, U.S. Senators Brian Schatz (D-Hawai'i) and Mark R. Warner (D-Va.), Vice Chairman of the Senate Select Committee on Intelligence, introduced sweeping legislation to establish enforceable safety and security standards for the most advanced artificial intelligence systems. Later today, Warner and Schatz will speak about the legislation on the Senate floor.

The Artificial Intelligence Risk Management and Security Act of 2026 comes as leading AI companies and cybersecurity researchers have issued increasingly urgent warnings about the rapidly advancing capabilities of frontier AI systems. Leading AI companies such as OpenAI, Anthropic, Google Deepmind, Meta, and Microsoft have issued warnings about the rapidly advancing cybersecurity capabilities of their models, warning that the newest frontier models can identify and exploit previously unknown vulnerabilities without human guidance. Recent incidents have also highlighted alarming deficiencies in frontier labs' security practices. The combination of these factors underscores a rapidly emerging challenge: AI systems are becoming increasingly capable of performing sophisticated cybersecurity tasks that can be enormously valuable to defenders but could also pose serious risks if misused or inadequately secured.

"Every day, we're seeing new reports of AI models going rogue and hacking systems without our knowledge or oversight. The risks of AI are not theoretical - they are happening in real-time," said Sen. Schatz. "Our bill is about making sure humans remain in control of AI models and preventing future breaches with rigorous standards, testing, and oversight. Immediate risk requires immediate action."

"The companies building the most powerful AI systems in the world are sounding the alarm: the step-change increase in AI models' capacity for cyber-offense, combined with clear failures to securely host and deploy these capabilities, could pose serious risks to our national security, our critical infrastructure, and the systems Americans rely on every day," said Sen. Warner. "I remain enormously optimistic about the potential of AI, but optimism cannot be an excuse for inaction, nor can we normalize these kinds of concerning incidents. If a model is capable of finding and exploiting vulnerabilities in a bank, a water system, or our electric grid, we ought to know that before it is released to the public - not after something goes catastrophically wrong. This legislation establishes basic, enforceable rules of the road to make sure the most powerful models are tested, secured, and responsibly deployed."

The Warner-Schatz legislation would establish a permanent Artificial Intelligence Safety Board within the Department of Commerce, bringing together representatives from the National Institute of Standards and Technology (NIST), Department of Commerce, Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and Department of the Treasury, along with independent technical experts, to evaluate emerging AI risks and establish technical safety and security standards.

Critically, developers of frontier AI models would be required to provide the Board access to their models at least 45 days before public release, including model weights, configuration files, runtimes, and software libraries necessary to operate the model, allowing experts to evaluate powerful models before deployment.

The legislation would also require AI developers to create and follow Model Safety Plans identifying the capabilities and risks of their systems, the specific steps they will take to mitigate those risks, and the corporate officer responsible for implementing the plan.

Under the legislation, the AI Safety Board would develop enforceable standards for evaluating frontier models and securing testing environments, including safeguards and monitoring procedures for models capable of discovering and exploiting software vulnerabilities without direct human prompting. Developers would be legally required to comply with applicable standards, with violations subject to civil penalties of up to $250,000 per violation, per day.

The bill would also:

  1. Create a secure reporting process and a national AI incident database to track AI safety and security incidents, recurring flaws, and near misses so researchers, government agencies, and developers can learn from failures across different systems. The database would be established by the National Institute of Standards and Technology in coordination with the Cybersecurity and Infrastructure Security Agency.
  2. Require frontier AI companies to report serious safety and security incidents, generally within 30 days, and within 72 hours when an incident poses an imminent threat to national security, critical infrastructure, or public safety. Critical infrastructure operators using AI to manage industrial control systems or other operational technologies would also be covered.
  3. Establish secure federal testing environments that can use resources at the National Security Agency and Department of Energy National Laboratories to conduct sensitive pre-deployment testing of frontier models.
  4. Develop new standards specifically for autonomous AI agents, including risks involving identity, authentication, authorization, access to data and systems, and differing levels of autonomy.
  5. Require standardized documentation for AI agents, including their intended uses, authority boundaries, access to data and tools, known limitations, and results of independent evaluations where applicable.

The legislation specifically focuses on advanced artificial intelligence models - systems that exhibit, or could be modified to exhibit, high levels of performance on tasks posing serious risks to national security, national economic security, or public health and safety.

The legislation is designed to address a range of risks associated with increasingly capable AI systems, including their potential to facilitate cyberattacks, evade the control of their developers or operators, assist in the development of chemical, biological, radiological, nuclear or other weapons, or have their model weights stolen or maliciously modified.

Text of the Artificial Intelligence Risk Management and Security Act of 2026 is available here.

###

  • Print
  • Email
  • Share
  • Tweet
Brian Schatz published this content on September 24, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on September 24, 2026 at 19:15 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]