Amends the Intelligence Authorization Act for Fiscal Year 2025 to require the National Security Agency Director to develop security guidance to defend AI technologies from theft by nation-state adversaries. Requires identification of vulnerabilities in AI technologies, focusing on cybersecurity risks and security challenges unique to protecting such technologies from theft or sabotage by nation-state adversaries. Requires identification of AI supply chain elements that could benefit adversaries if accessed. Requires identification of supply chain, development, or product lifecycle elements that, if accessed by adversaries, would either accelerate their AI progress or provide opportunities to compromise the confidentiality, integrity, or availability of AI systems or associated supply chains. Requires identification of strategies for AI technologies to identify, protect, detect, respond to, and recover from cyber threats. Permits the NSA Director to collaborate, on a voluntary basis, with other U.S. government departments and agencies, research entities, and private sector entities on AI model safety and security. Permits the NSA Director to provide computing resources the Director deems appropriate in support of such collaboration. Requires the NSA Director to publish, and may update from time to time, AI security guidance to be shared with relevant public and private sector entities at unclassified or classified levels.
Paper
Full text
FY2026 NDAA, Section 6601 ("Artificial Intelligence security guidance")
ETO AGORA · NDAA provisions · 2025
Summary
Amends the Intelligence Authorization Act for Fiscal Year 2025 to require the National Security Agency Director to develop security guidance to defend AI technologies from theft by nation-state adversaries.
Requires identification of vulnerabilities in AI technologies, focusing on cybersecurity risks and security challenges unique to protecting such technologies from theft or sabotage by nation-state adversaries.
Requires identification of AI supply chain elements that could benefit adversaries if accessed.
Requires identification of supply chain, development, or product lifecycle elements that, if accessed by adversaries, would either accelerate their AI progress or provide opportunities to compromise the confidentiality, integrity, or availability of AI systems or associated supply chains.
Requires identification of strategies for AI technologies to identify, protect, detect, respond to, and recover from cyber threats.
Permits the NSA Director to collaborate, on a voluntary basis, with other U.S. government departments and agencies, research entities, and private sector entities on AI model safety and security.
Permits the NSA Director to provide computing resources the Director deems appropriate in support of such collaboration.
Requires the NSA Director to publish, and may update from time to time, AI security guidance to be shared with relevant public and private sector entities at unclassified or classified levels.
Requires the Director of the NSA to develop AI security guidance against nation-state adversaries.
SEC. 6601. ARTIFICIAL INTELLIGENCE SECURITY GUIDANCE. Section 6504 of the Intelligence Authorization Act for Fiscal Year 2025 (division F of Public Law 118-159) is amended-- (1) in subsection (c)-- (A) by redesignating paragraph (3) as paragraph (4); and (B) by inserting after paragraph (2) the following new paragraph (3): ``(3) In accordance with subsection (d), developing security guidance to defend artificial intelligence technologies from technology theft by nation-state adversaries.''; (2) by redesignating subsection (d) as subsection (e); and (3) by inserting after subsection (c) the following: ``(d) Artificial Intelligence Security Guidance.-- ``(1) Elements.--In developing the guidance pursuant to subsection (c)(3), the Director of the National Security Agency shall-- ``(A) identify vulnerabilities in advanced artificial intelligence technologies, with a focus on cybersecurity risks and security challenges unique to protecting such technologies from theft or sabotage by nation-state adversaries; ``(B) identify elements of the artificial intelligence supply chain or development or product lifecycle that, if accessed by nation-state adversaries, would contribute to progress made by nation-state adversaries on advanced artificial intelligence or would provide opportunities to adversaries to compromise the confidentiality, integrity, or availability of artificial intelligence systems or associated supply chains; and ``(C) identify strategies for artificial intelligence technologies to identify, protect, detect, respond, and recover from nation-state adversary cyber threats.
Allows the NSA Director to collaborate on AI model safety and publish related security guidance.
``(2) External collaboration.--In developing the guidance pursuant to subsection (c)(3), the Director of the National Security Agency may collaborate, on a voluntary basis, with other departments and agencies of the United States Government, research entities, and private sector entities, as determined appropriate by the Director, on artificial intelligence model safety and security, including through the provision of any computing resources the Director determines appropriate. ``(3) Security guidance form.--The Director of the National Security Agency shall publish, and may update from time to time, the security guidance developed under subsection (c)(3) to share with departments and agencies of the United States Government, research entities, and private sector entities, as determined appropriate by the Director, at unclassified or classified levels.''.