A Senate bill from Mark Warner would require developers of frontier AI models to give a new federal AI Safety Board access to each model, including its weights, at least 45 calendar days before release. S.5576, the Artificial Intelligence Risk Management and Security Act of 2026, is dated 29 September 2026 in the official text, with Brian Schatz and Andy Kim as cosponsors.
The bill was read twice and referred to the Senate Committee on Commerce, Science, and Transportation. That referral is the only action congress.gov lists for it. It would also create binding safety standards, mandatory incident reporting and a public AI incident database.
Business Pill · WHEN TO TELL
A one-minute explainer of the notification clock: the days between finding a problem and telling the people it affects. It teaches the general idea only and says nothing about any company, senator or bill in this story.
The key insight: As we read it, the bill would put legal deadlines on three things: when a federal board sees a frontier model, how fast incidents are reported, and what a safety plan must contain.
What the Bill Would Create
Section 3 tells the Secretary of Commerce to set up the Artificial Intelligence Safety Board within the Department of Commerce no later than 30 days after enactment. It would be a permanent advisory committee.
Five members would be picked by federal officials: one each by the Director of NIST, the Secretary of Commerce, the Director of CISA, the Director of the NSA and the Secretary of the Treasury. The Secretary of Commerce would add non-government experts, including technical experts both unaffiliated and affiliated with AI developers.
Members would serve terms of no more than 3 years, renewable once. The chair would serve no more than one 2-year term. The Secretary would sponsor each member for a Top Secret clearance with access to sensitive compartmented information, and the Board could meet in closed session on incidents, vulnerabilities and proprietary business information.

Standards That Developers Must Follow
The Board would have 90 days after it is established to submit proposed standards to the Secretary, who would adopt them by rule within 30 days. The Secretary could modify a standard for national security, publishing the reasons in the Federal Register.
The standards cover technical evaluations of what capabilities pose a serious risk, model and system cards, cybersecurity across the lifecycle, and checks on employees with access to AI systems.
They also cover securing test environments for models that can discover and exploit software vulnerabilities without direct prompting by a human user, including conditions for the prompt termination of an evaluation in which a model has operated beyond its controls.
Each developer would have to comply. Under Section 3(d), a violation carries a civil penalty of up to $250,000, and each day a violation continues counts as a separate violation. The Attorney General could sue to stop violations or recover penalties.
45 Days Before Release
Section 3(f) is the provision in the headline. No later than 45 calendar days before a developer puts a frontier AI model into interstate or foreign commerce, it must give the Board access to the model, including its weights, configuration files, runtimes or software libraries needed to run it.
Section 3(e) lets the Secretary use secure computing environments at the National Security Agency and the Department of Energy’s National Laboratories for testing, on a reimbursable basis. These could be opened to the private sector and independent experts on a cost-recovery basis, including for pre-deployment testing.
The bill defines a frontier model by capability: one that exhibits, or could be modified to exhibit, high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety. The text we read sets no compute or revenue threshold.

Safety Plans and Incident Reports
Section 4 requires each developer to develop, publish and follow a Model Safety Plan for every model it creates, substantially modifies, or uses to train or evaluate other models. Each plan names the model, its risk assessment, the mitigation for each risk and the corporate officer responsible, and is filed with the Secretary.
Section 5 requires frontier developers, and critical-infrastructure operators that use AI to manage industrial control systems, to report a confirmed AI safety or security incident within 30 days of confirmation. The deadline is 72 hours if the incident poses an imminent threat to national security, critical infrastructure or public safety.
The duty applies whether or not the model is public, and whether the incident occurs in development, training, testing, evaluation, red-teaming, deployment or operation.
NIST, with CISA, would set up voluntary reporting channels within 180 days and a publicly accessible incident database within 1 year. Entries would be anonymised unless those affected consent, shared information would be exempt from disclosure, and NIST would consult the developer before publishing.
Rules for AI Agents
Section 6 gives NIST 18 months to write an Agentic AI Profile of its AI Risk Management Framework, with a classification of agent autonomy levels and cybersecurity risks around agent identity, authentication and authorization.
Within the same 18 months, NIST would start a common template for documenting agents. It would record identity and version, intended use, authority boundaries, access to data, systems and tools, evaluations, any independent evaluator, and known limitations.
What the Sponsors Said
A press release on Senator Schatz’s website, dated 24 September 2026, says Schatz and Warner introduced the bill that day and would speak about it on the Senate floor. The official text and congress.gov give 29 September 2026 as the introduction date.
“Every day, we’re seeing new reports of AI models going rogue and hacking systems without our knowledge or oversight. The risks of AI are not theoretical – they are happening in real-time,” Schatz said in the release.
“If a model is capable of finding and exploiting vulnerabilities in a bank, a water system, or our electric grid, we ought to know that before it is released to the public – not after something goes catastrophically wrong,” Warner said.
The Structural Read
As we read the text, S.5576 would make pre-release access, published safety plans and incident reports legal duties, each with its own deadline or filing requirement.
The bill reaches inside the lab, not only the public release. Model Safety Plans cover models used to train or evaluate other models, and the incident duty applies during training, testing and red-teaming as well as deployment.
The enforcement sits on the standards. The $250,000 penalty in Section 3(d) applies to violations of Section 3(c), which requires compliance with standards adopted under Section 3(b)(2), with each day counted as a separate violation; the text places the 45-day access duty in Section 3(f).
Sen. Mark Warner, in the press release on Sen. Schatz’s website (24 September 2026)
“This legislation establishes basic, enforceable rules of the road to make sure the most powerful models are tested, secured, and responsibly deployed.”
Three Implications
FRONTIER AI DEVELOPERS Release calendars would need a gap of at least 45 calendar days between giving the Board access, weights included, and launch.
SECURITY AND COMPLIANCE TEAMS Incident reporting would run on a 30-day clock from confirmation, cut to 72 hours when an incident poses an imminent threat.
CRITICAL-INFRASTRUCTURE OPERATORS Operators using AI to manage industrial control systems or other operational technologies would carry the same reporting duty as the labs.
The Business Engineer Lens
This story maps onto the Business Engineer framework Inside Anthropic’s Permission Layer.
The framework puts it this way: “The governance layer sits at the intersection of capability, regulation, national security, access control, and geopolitical alignment. It is where decisions are made about who gets access to frontier intelligence, under what conditions, and for which purposes.”
As we read it, S.5576 is a proposal to move part of that layer into law: a federal board, with security-cleared members, would see frontier models before release and set the standards they must meet.
What Is Not Established
The bill has only been introduced and referred to committee. As of 10 October 2026, congress.gov showed one action, a summary still in progress, and no CBO cost estimate. Nothing here says whether it will get a committee vote.
The release names OpenAI, Anthropic, Google DeepMind, Meta and Microsoft as companies that have warned about their models’ cyber capabilities. It does not quote any company on the bill, and we have no company responses to report.
On 9 October we covered Senator Cantwell’s call for independent audits before frontier AI ships. Separately, we have covered Anthropic’s statement that Claude sent police a fake tip during a test.
The Bottom Line
S.5576 would put frontier models in front of a federal AI Safety Board at least 45 days before release, weights included. Developers would have to follow binding standards, at up to $250,000 per violation per day, and report incidents within 30 days, or 72 hours when the threat is imminent. For now it is a referred bill with two cosponsors.
94,000+ executives read Business Engineer for the AI strategy frameworks cited by ChatGPT, Claude, and Perplexity.
A note on sourcing. We read the full text of S.5576 as introduced, from the Government Publishing Office, on 10 October 2026, along with the bill’s page on congress.gov and the press release on Senator Schatz’s website. The quotations are from that release. Section numbers refer to the bill as introduced; the text can change in committee. Nothing here is a forecast of whether the bill will pass, and nothing here is legal, financial or investment advice.
Sources: GPO: S.5576, Artificial Intelligence Risk Management and Security Act of 2026, introduced in Senate (text) · Congress.gov: S.5576, 119th Congress (sponsor, cosponsors, actions) · Sen. Brian Schatz: Schatz, Warner To Take To Senate Floor To Demand Passage Of New AI Security Legislation (24 Sep 2026)









