S 5601: Insider Threat Reporting and Security Guidance Act of 2026
S 5601 in plain English: This bill would require reporting and security guidance related to insider threats, and involves contracts worth at least $100,000,000 for artificial intelligence systems with the Department of Defense, as well as at least $1,000,000,000 in AI-related research and development expenditures.
Stated purpose
The bill requires the Secretary of Defense to create reporting rules for large AI contractors working with the Pentagon, and to develop voluntary security guidance for those contractors, in order to protect Defense Department systems and missions from insider threats and other national security risks.
Key points
- Requires one or more contracts totaling at least $100,000,000 with the Department of Defense for an artificial intelligence system
- Involves at least $1,000,000,000 in AI-related research and development expenditures
- Addresses insider threat reporting and security guidance
Arguments supporters make
- AI systems used in national defense are high-value targets for foreign adversaries, and requiring contractors to report security incidents and insider threats helps the military catch problems before they damage operations or national security.
- Contractors handling billions of dollars in AI development already have security practices in place, so formalizing reporting requirements simply makes those practices visible and accountable to the government that relies on them.
- Early disclosure of AI vulnerabilities, model tampering, or supply chain compromises gives the Pentagon a better chance to respond before damage spreads across military systems.
Arguments opponents make
- Mandatory reporting of detailed security practices, model capabilities, and vulnerabilities could itself create a concentrated record that, if breached, gives adversaries a roadmap to exploit those same weaknesses.
- Compliance costs for documenting and reporting extensive technical details across AI models, training infrastructure, and third-party access could disadvantage smaller or newer AI firms, reducing competition for defense contracts.
- The broad and detailed scope of required disclosures may push contractors to over-report ambiguous incidents out of caution, flooding Pentagon reviewers with low-signal information and making it harder to focus on genuine threats.
Tradeoffs
Requiring detailed security disclosures improves the Pentagon's visibility into AI risks but also means sensitive contractor information must be shared with and stored by the government, creating its own security and competitive concerns. The rules also place new compliance burdens on contractors, which could be weighed against the national security benefit of earlier threat detection.
Current status in Congress: In committee.
NewsClear — neutral news & congressional tracking · Bill of the Week