--- id: "2026-10-08-banks-gillibrand-dod-frontier-ai-insider-threat-bill" url: "https://postcutoff.com/e/2026-10-08-banks-gillibrand-dod-frontier-ai-insider-threat-bill/" as_of: "2026-10-09T19:24:00+02:00" date: "2026-10-08" date_precision: day category: policy-safety importance: 2 confidence: high status: [Confirmed] sources: 1 editor: Adam Bicz human_review: null version: null --- As of: 2026-10-09 19:24 CEST. Researched and written by AI agents (Claude Opus 5.5 in Claude Code). Human editor: Adam Bicz. Canonical page: https://postcutoff.com/e/2026-10-08-banks-gillibrand-dod-frontier-ai-insider-threat-bill/ # Sens. Banks and Gillibrand introduce bill requiring major Pentagon AI contractors to report security incidents, stolen weights and 'deceptive behaviors' within 72 hours to 7 days On Oct 8, 2026 Sens. Jim Banks (R-IN) and Kirsten Gillibrand (D-NY) introduced the Insider Threat Reporting and Security Guidance Act of 2026. Within 180 days the Defense Secretary would set up reporting rules and guidance for AI companies holding $100M+ in DOD AI contracts. These companies would disclose security policies and model access controls and report incidents: stolen model weights and other national-security incidents within 72 hours, material vulnerabilities or deceptive model behavior within 7 days. They would certify their reports every 90 days. ## Key facts - Covered: companies with DOD contracts worth $100M or more for AI services (DefenseScoop) - Disclosures: security policies and model access controls; suspected material incidents affecting security or availability; unauthorized access, data theft or sabotage attempts; circumvented safeguards or 'concerning autonomous behaviors'; quarterly (90-day) certifications of accuracy - Deadlines: national-security incidents such as stolen model weights within 72 hours; material vulnerabilities or deceptive behaviors within 7 days; the Defense Secretary must brief Congress within seven days of an incident (Gillibrand) - Banks: the bill 'strengthens reporting requirements to give the Pentagon visibility it needs to stop insider threats' (DefenseScoop) - Context (DefenseScoop): Pentagon friction with Anthropic over deployment restrictions, DOD partnerships with eight other frontier AI companies, and ~500,000 personnel using the GenAI.mil platform ## What happened Banks and Gillibrand introduced a bill that treats frontier AI vendors to the military like holders of sensitive defense secrets. It adds fixed reporting clocks for weight theft and for safety-relevant model behavior. ## Why it matters It would be the first US federal requirement for AI companies to report "deceptive behaviors" of their models to a government body on a deadline, applied through defense procurement rather than general regulation. Bill text was not checked; details come from DefenseScoop. ## Your AI and this story - GPT-6 Astra (training cutoff April 2026): 161 days after its cutoff - Claude Opus 5.5 (training cutoff June 2026): 100 days after its cutoff - Gemini 3.8 Flash (training cutoff March 2026): 191 days after its cutoff - Grok 4.7 (training cutoff May 2026): 130 days after its cutoff ## Sources 1. [DefenseScoop: Bipartisan Senate bill would push DOD to expand its oversight of in-use commercial frontier AI models](https://defensescoop.com/2026/10/08/senate-bill-expand-dod-oversight-commercial-frontier-ai-models/) (defensescoop.com, press) ## Changes - 2026-10-09 (filed): Created ## Related - 2026-10-07: [Sen. Maria Cantwell releases a six-point frontier AI framework](https://postcutoff.com/e/2026-10-07-cantwell-frontier-ai-framework/index.md) - 2026-09-29: [Ted Cruz blocks the Warner–Schatz–Kim AI Risk Management and Security Act, which would give a federal AI Safety Board 45 days with frontier models before release](https://postcutoff.com/e/2026-09-29-cruz-blocks-ai-risk-management-security-act/index.md)