What happened
On 8 October 2026 Sens. Jim Banks (R-IN) and Kirsten Gillibrand (D-NY) introduced the bipartisan Insider Threat Reporting and Security Guidance Act of 2026. It would direct the Secretary of Defense to issue regulations establishing reporting requirements for large frontier AI contractors — covering who can access model weights/training data, suspected security incidents, unauthorized access/exfiltration, and past evasions of safeguards or unprompted autonomous actions — with certification every 90 days, 72-hour reporting of national-security incidents (e.g. weight theft), and 7-day reporting of material model vulnerabilities or concerning conduct. It builds on Gillibrand's Secure and Accountable Military AI Act notification framework.
Why it matters
The Pentagon is the single largest buyer of frontier AI capability. This bill would use DOD procurement leverage to impose continuous, enforceable transparency and incident-reporting duties on OpenAI, Anthropic, Google, Microsoft, NVIDIA, SpaceX and other AI contractors — effectively mandatory AI-safety reporting for the defense supply chain ahead of broader federal AI law.
Action needed
Frontier AI labs with large DOD contracts should prepare mature security/governance documentation, weight-access-control records and 72-hour/7-day incident-notification processes in anticipation of the mandated reporting regime.