Bipartisan Senate bill would push DOD to expand its oversight of in-use commercial frontier AI models
A bipartisan bill proposed in the Senate would require the Pentagon to continuously vet the commercial tech giants from which it buys frontier AI for security vulnerabilities, algorithmic failures and other emerging risks accompanying the models that could compromise U.S. defense and national security.
Put forward by Sens. Jim Banks, R-Ind., and Kirsten Gillibrand, D-N.Y., the 18-page legislation would direct the secretary of defense to create new “reporting requirements and voluntary guidance for large” AI contractors.
Broadly, the bill would apply the Defense Department’s significant purchasing power to help enforce safety standards and transparency about the military’s AI use, ahead of Congress passing more sweeping industry-wide federal AI regulations.
“Right now, the Pentagon is moving toward deploying incredibly powerful AI technology without commonsense guardrails in place, which could have catastrophic consequences for our national security,” Gillibrand told DefenseScoop in an email on Tuesday.
Frontier AI refers to the most advanced and capable foundational models, which are rapidly pushing the boundaries of machine intelligence.
In the military realm, such capabilities present unique risks for potential technical, strategic and operational failures that are unmatched by standard commercial software and legacy computing hardware. For instance, research suggests that AI models performing as military decision-makers — often driven by tactical optimization over restraint — have demonstrated bias towards rapid escalation, preemptive strikes, or weapon deployment, under time pressures.
Still, defense officials have warned that AI must be applied to support and compress decision cycles against militaries opposing the U.S., so the DOD is increasingly hustling to fuse powerful models into real-world military operations.
In 2025, the Pentagon announced individual contracts with four frontier AI companies — each worth up to $200 million — for access to some of the most advanced commercial capabilities, including large language models, agentic workflows, cloud-based infrastructure and more.
Not long after that, the DOD revealed plans for a swift and expansive release of a generative AI tool, dubbed GenAI.mil, to millions of military members, civilian employees and contractors.
But tensions between the department and its frontier AI partner Anthropic escalated in early 2026, largely stemming from disagreements over restrictions on how the military could deploy the company’s Claude models, particularly for certain national surveillance and warfare operations. That dispute remains ongoing, with the relationship between DOD and Anthropic sharply fractured.
The department announced new formal AI agreements with SpaceX, OpenAI, Google, NVIDIA, Reflection, Microsoft, Amazon Web Services and Oracle — notably excluding Anthropic — in May. As part of those deals, the U.S. tech companies signed on to deploy their frontier AI capabilities on the Defense Department’s classified networks “for lawful operational use” in the near term.
“As the Pentagon rapidly expands its partnerships with frontier AI companies, our adversaries are working just as quickly to steal our most sensitive technology and exploit any weak link,” Banks told DefenseScoop in an email on Wednesday. “My bill strengthens reporting requirements to give the Pentagon the visibility it needs to stop insider threats and maintain America’s critical AI advantage.”
That legislation is called the Insider Threat Reporting and Security Guidance Act of 2026.
According to its text, if the bill is passed the defense secretary would be mandated to “issue regulations establishing reporting requirements for covered artificial intelligence contractors to support the protection of Department of Defense systems, missions, personnel, operations, and supply chains from counterintelligence, security, and other national security risks arising from the security practices of such contractors” within 180 days.
Those “covered” contractors would be companies that have entered into deals with DOD worth $100 million or more for AI, among other caveats listed in the bill.
The tech giants would need to share a wide range of information, including but not limited to: their policies, practices and security measures relating to their models; who has access to the model weights and training; suspected material incidents affecting the security, integrity, or availability of the technology; any unauthorized access, exfiltration, or sabotage to the data or models; and past evasions of safeguards, unprompted autonomous actions and other “concerning” AI behaviors.
The bill would also require the covered companies to certify that the information they submitted to Pentagon leadership continues to be accurate and a complete reflections of their assets, “not less frequently than once every 90 days.”
Further, it would also mandate the frontier AI contractors to report national security incidents (like theft of model weights) to the DOD within 72 hours of discovery, and report material vulnerabilities in the model or worrying conduct within seven days of discovering the issue is material.
The proposal for that notification system grew out of Gillibrand’s Secure and Accountable Military AI Act, which she introduced in June.
“I am proud to work across the aisle to put in place a rigorous notification framework that requires AI contractors to immediately alert the Pentagon to vulnerabilities or deceptive model behaviors, and mandates that the Secretary of Defense brief Congress within seven days of an incident,” Gillibrand said.