HR 10189
To amend title 10, United States Code, to direct the Secretary of Defense to establish an artificial intelligence incident and vulnerability reporting program, and for other purposes.
TL;DR
Rep. Sara Jacobs (D-CA) introduced this bill to require the Department of Defense to create a formal program for tracking and reporting AI incidents and vulnerabilities in military AI systems. It's essentially a bug bounty and incident reporting framework for the Pentagon's AI tools, similar to what already exists for cybersecurity.
How This Might Impact Your Business
Defense contractors selling AI systems to the Pentagon would need to participate in a new incident and vulnerability reporting program, likely including disclosure timelines and documentation standards.
AI vendors working with DoD (companies like Palantir, Anduril, Scale AI, and traditional primes like Lockheed and Raytheon) should expect new contract clauses requiring vulnerability disclosure and post-incident cooperation.
Cybersecurity and AI red-teaming firms may see new business opportunities as DoD builds out the reporting infrastructure and needs third-party testing capacity.
No direct impact on commercial (non-defense) AI companies, though the reporting standards developed here often become de facto benchmarks that spread to civilian agencies and private sector.
No specific penalties, fines, or dollar thresholds are set in the bill text; enforcement would come through DoD contracting mechanisms rather than regulatory fines.
Timeline is uncertain: the bill is still in the House Armed Services Committee with no hearing scheduled, and would likely be folded into the annual National Defense Authorization Act (NDAA) if it advances.
Small and mid-sized AI startups pursuing DoD contracts through vehicles like SBIR or the Defense Innovation Unit should prepare for added compliance overhead.
What Should You Do
If you sell AI to DoD or plan to, ask your government affairs team to track this bill and any NDAA amendments that could absorb it.
Have your engineering leads inventory how you currently detect, log, and report AI model failures or vulnerabilities, since a formal DoD program will likely require standardized documentation.
Defense contractors should review existing cyber incident reporting processes (DFARS 252.204-7012) and plan for parallel AI-specific reporting workflows.
AI security and testing vendors should monitor DoD RFIs and RFPs tied to this program for potential new contract opportunities.
Watch the House Armed Services Committee calendar and the FY2025/FY2026 NDAA markup process, which is the most likely path for this bill to become law.
Who It Affects
Sponsors
Status Timeline
committee
Referred to the House Committee on Armed Services.
August 31, 2026