As frontier AI models become more powerful, U.S. lawmakers are pushing for mandatory incident reporting to ensure dangerous capabilities, security breaches, and serious safety risks are disclosed before they escalate.
U.S. Representative Nathaniel Moran of Texas introduced the AI Incident Reporting Act on June 25, 2026, proposing a federal framework that would require developers of the most advanced AI models to disclose dangerous capabilities, security breaches, and safety incidents to the Secretary of Commerce within seven days of discovery. For the most critical reports, the Commerce Department would be required to notify congressional leadership and the chairs of relevant committees within 48 hours.
The bill lands at a moment when Congress has struggled for years to pass any AI legislation, but where the national security backdrop has shifted sharply. Anthropic’s Mythos model identified vulnerabilities in classified U.S. government systems within hours during a testing exercise in June 2026. The Commerce Department followed with a directive on June 12 blocking foreign nationals from accessing Anthropic’s latest models, an intervention that forced Anthropic to disable the models for all customers globally. The episode exposed something specific: the U.S. had no formal mechanism for AI developers to report when something went wrong, or for the government to learn about it in time to act.
Moran called his proposal plainly: “It’s a catch-it-early and sound-the-alarm bill.” The legislation is a narrower, faster-moving alternative to the broader Great American Artificial Intelligence Act, a 269-page discussion draft released on June 4 by Representatives Jay Obernolte and Lori Trahan that also includes incident reporting but bundles it into a sweeping federal AI governance framework that faces heavier political resistance.
What Counts as a Reportable Incident
The bill defines reportable incidents in specific, consequential terms. The list covers a lot of ground.
Developers would be required to report any AI model attempting to evade human oversight, deceive operators, circumvent built-in safeguards, or resist shutdown. Unauthorized access to or theft of model weights — the underlying parameters that determine how a model reasons — is also covered. So are capabilities that could materially enable offensive cyberattacks against critical infrastructure, autonomous development of more capable AI systems, and any capabilities that could accelerate the development or use of chemical, biological, radiological, nuclear, or explosive weapons.
Developers would submit an initial report within seven days of discovering, or reasonably believing, that a reportable incident has occurred, followed by supplemental disclosures as more information becomes available. The Commerce Department would be required to develop precise capability thresholds in consultation with AI developers, academic researchers, cybersecurity experts, and national security officials before issuing implementation guidance.
The legislation also gives the Commerce Department investigative teeth. It authorizes the agency to subpoena records, require corrective action, and impose civil penalties of up to $2 million per violation, with each day of a continuing violation counting as a separate infringement.
Two Bills, One Direction
The Moran bill and the Obernolte-Trahan discussion draft are headed toward the same destination through different routes.
The Great American Artificial Intelligence Act, released on June 4, targets what it defines as “large frontier developers,” meaning companies with more than $500 million in annual revenue that have trained the most powerful AI models. Those companies would be required to publish a “frontier AI framework” disclosing catastrophic risks, produce safety reports before deploying new frontier models, and report any critical safety incidents to the Director of CAISI. The framework would also codify CAISI’s existence in law and provide $100 million in annual funding for standard-setting and model auditing. Civil penalties under the broader bill would reach up to $1 million per violation per day.
The Obernolte-Trahan bill also proposes a three-year freeze on state-level regulation of AI model development, though states would retain power to regulate how AI is used in areas like privacy, employment, and consumer protection. That preemption provision has drawn the most criticism. The Tech Oversight Project’s executive director Sacha Haworth said the bill “trades away existing and future child safety, civil rights and consumer protection laws for nothing in return.” A joint statement from the American Federation of Teachers and the Association of Flight Attendants described it as “a giveaway to the AI industry.”
Moran’s more surgical proposal strips that debate out entirely. By limiting the bill to a reporting obligation with tight timelines, it sidesteps the preemption fight that has stalled broader AI legislation repeatedly.
The Regulatory Gap the Bills Are Filling
Before June 2026, the U.S. had no clear legal mechanism requiring AI developers to tell the government when something went seriously wrong with a high-capability model.
Sanchit Vir Gogia, chief analyst at Greyhound Research, told CSO Online that serious frontier developers already run evaluations, red-teaming, and escalation drills internally. “What they have never faced at the federal level,” he said, “is a legal obligation to tell the government, on the clock, when a model behaves dangerously.” He also flagged the hardest definitional question in the bill: when the reporting clock actually starts. “Thresholds decide which models enter the regime. Discovery decides whether the regime ever sees the fire,” he said, noting that a model can pass laboratory tests and then behave differently once connected to live tools and enterprise data.
That observation cuts to the practical difficulty of writing incident reporting law for AI. Cybersecurity incident reporting under CIRCIA, signed in 2022, took years of rulemaking to define what constituted a covered incident. AI incident reporting has the same definitional problem, with the added complexity that what counts as dangerous behavior is more contested and harder to observe.

The Political Environment
An Annenberg Public Policy Center survey from earlier in 2026 found that 65% of Americans say the government has done too little to regulate AI, including 77% of Democrats and 53% of Republicans. A Morning Consult poll found 47% of Republican voters strongly support testing AI models before public release, with only 5% strongly opposing it.
That public sentiment is giving cover to Republican lawmakers who might otherwise resist any AI oversight measure. Moran is a Republican from Texas, and the AI Policy Network’s president Mark Beall, who supports the bill, was candid about the political reality: “No legislation on AI has had much of a chance, but I think there’s a growing demand from the public to see some action.”
Brendan Steinhauser, CEO of the Alliance for Secure AI, framed the national security argument directly: “The capabilities of advanced AI models are increasing by the day, and so are the risks of AI systems gaining the ability to self-improve, evade human oversight, and enabling attacks against our nation’s infrastructure. We need mechanisms to identify these risks early so that leaders can respond quickly before incidents become bigger threats.”
How the Bills Compare
| Bill | Introduced | Scope | Reporting timeline | Penalty | Status |
| AI Incident Reporting Act | June 25, 2026 | Incident reporting only | 7 days | Up to $2M per violation | Referred to committee |
| Great American AI Act | June 4, 2026 | Comprehensive frontier AI framework | Critical incidents to CAISI | $1M per violation per day | Discussion draft |
| Trump AI Executive Order (June 2) | June 2, 2026 | Voluntary pre-release security review | Up to 30 days pre-release | None (voluntary) | In effect |
The next step for the AI Incident Reporting Act is referral to one or more House committees, where legislation either advances or stalls. Congress’s record on AI bills has been poor, but the accumulation of events in June 2026 has changed the political calculation. Two competing bills now contain incident reporting provisions. A presidential executive order has already created the framework for voluntary pre-release review. The institutional scaffolding for oversight is being built in real time, even as the specific legal obligations remain contested.
What happens next will likely depend less on the merits of any individual bill and more on whether the next high-profile AI incident arrives before or after Congress recesses.
Frequently Asked Questions
What is the AI Incident Reporting Act? It is a bill introduced on June 25, 2026 by Representative Nathaniel Moran of Texas. It would require developers of advanced AI models, designated as “covered models” by the Commerce Department, to report dangerous capabilities, security breaches, and safety incidents within seven days. For the most serious reports, Commerce must notify congressional leadership within 48 hours. Penalties for non-compliance can reach $2 million per violation, with each day of a continuing violation counting separately.
What kinds of incidents would AI companies have to report? The bill covers a specific list: AI models attempting to evade human oversight, circumvent safeguards, resist shutdown, or deceive operators; unauthorized access to model weights; capabilities that could enable offensive cyberattacks against critical infrastructure; autonomous development of more capable AI systems; and any capabilities that could help produce chemical, biological, radiological, nuclear, or explosive weapons.
How is this different from the Great American Artificial Intelligence Act? The Great American AI Act, released on June 4 by Representatives Obernolte and Trahan, is a comprehensive 269-page framework covering frontier AI governance, cybersecurity, workforce, research, and international cooperation. It includes incident reporting as one component among many, and proposes a three-year freeze on state AI laws. Moran’s bill is narrowly focused on reporting only, which its sponsor argues gives it a faster path to becoming law without triggering the preemption debate that has stalled broader proposals.
Is AI incident reporting already required somewhere? Yes. The EU AI Act requires providers of high-risk AI systems to report serious incidents to market surveillance authorities within 15 days, or within two days for widespread or very serious incidents. New York’s RAISE Act, enacted in December 2025, mandates a 72-hour incident reporting timeline for frontier AI developers operating in the state. The proposed U.S. federal bills would create a national standard for the first time.
What triggered this legislative push? The immediate catalyst was the June 2026 Commerce Department directive against Anthropic’s Fable 5 and Mythos 5 models, which came after Mythos was found to have identified vulnerabilities in classified U.S. government systems during a testing exercise conducted through Project Glasswing. The directive forced Anthropic to disable global access to the models, exposing the absence of any formal framework for how such incidents should be identified, escalated, or reported to Congress.
Sources
- Reuters via US News: US Lawmaker Introduces Bill to Require AI Companies to Report Critical Incidents
- KLTV: Moran introduces act to give Washington an early-warning system for dangerous AI incidents
- CSO Online: Proposed US law would make AI risk reporting a legal obligation
- DLA Piper: Unpacking the Great American AI Act
- Tech Policy Press: Unpacking the Great American Artificial Intelligence Act of 2026
- Captain Compliance: Great American Artificial Intelligence Act of 2026: What the New Bipartisan AI Bill Means for Companies
- IAPP: A view from DC: A bipartisan blockbuster bill on AI
- Washington Examiner: The pitfalls facing the bipartisan AI regulation bill
- Cryptonomist: AI Incident Reporting Bill: Fast-Track Safety Oversight
- Moran.house.gov: Rep. Moran Introduces AI Incident Reporting Act
Stay in the Loop
For more stories, breakdowns, and unfiltered takes on what is really happening in Indian and global business and tech, follow TheFounder Nation.
Instagram: thefoundernation
We cover what the mainstream business press won’t.
© TheFounder Nation | All rights reserved