HR 10189 · Federal · introduced Aug 31, 2026In Committee

HR 10189

To amend title 10, United States Code, to direct the Secretary of Defense to establish an artificial intelligence incident and vulnerability reporting program, and for other purposes.

Low RiskInformational. No immediate compliance impact.

TL;DR

Rep. Sara Jacobs (D-CA) introduced this bill to require the Department of Defense to create a formal program for tracking and reporting AI incidents and vulnerabilities in military AI systems. It's essentially a bug bounty and incident reporting framework for the Pentagon's AI tools, similar to what already exists for cybersecurity.

How This Might Impact Your Business

Defense contractors selling AI systems to the Pentagon would need to participate in a new incident and vulnerability reporting program, likely including disclosure timelines and documentation standards.

AI vendors working with DoD (companies like Palantir, Anduril, Scale AI, and traditional primes like Lockheed and Raytheon) should expect new contract clauses requiring vulnerability disclosure and post-incident cooperation.

Cybersecurity and AI red-teaming firms may see new business opportunities as DoD builds out the reporting infrastructure and needs third-party testing capacity.

No direct impact on commercial (non-defense) AI companies, though the reporting standards developed here often become de facto benchmarks that spread to civilian agencies and private sector.

No specific penalties, fines, or dollar thresholds are set in the bill text; enforcement would come through DoD contracting mechanisms rather than regulatory fines.

Timeline is uncertain: the bill is still in the House Armed Services Committee with no hearing scheduled, and would likely be folded into the annual National Defense Authorization Act (NDAA) if it advances.

Small and mid-sized AI startups pursuing DoD contracts through vehicles like SBIR or the Defense Innovation Unit should prepare for added compliance overhead.

What Should You Do

1

If you sell AI to DoD or plan to, ask your government affairs team to track this bill and any NDAA amendments that could absorb it.

2

Have your engineering leads inventory how you currently detect, log, and report AI model failures or vulnerabilities, since a formal DoD program will likely require standardized documentation.

3

Defense contractors should review existing cyber incident reporting processes (DFARS 252.204-7012) and plan for parallel AI-specific reporting workflows.

4

AI security and testing vendors should monitor DoD RFIs and RFPs tied to this program for potential new contract opportunities.

5

Watch the House Armed Services Committee calendar and the FY2025/FY2026 NDAA markup process, which is the most likely path for this bill to become law.

Who It Affects

Defense ContractingAI/ML Software VendorsCybersecurityGovernment IT ServicesAerospaceAI Red-Teaming and Testing

Sponsors

Status Timeline

  1. committee

    Referred to the House Committee on Armed Services.

    August 31, 2026

AI-generated analysis for informational purposes only. Not legal advice. Always consult a qualified attorney for legal guidance.Last action Aug 31, 2026

Need help preparing your team for AI compliance?

Talk to LaunchReady about AI Training

Get the Weekly AI Law Roundup

Plain-English summaries of the AI laws that matter for your business. Every Monday. Free.

No spam. Unsubscribe anytime.