Regulatory PolicyAI & Data ScienceStrategy & Operations
AI Incident Response Program Proposed for DoD
A disclosure brake for an AI-first Pentagon, with contractors caught in between.
The draft FY27 NDAA would make DoD log and report its AI failures under a non-punitive, contractor-inclusive disclosure regime, a brake proposed by Congress for an AI-first acquisition machine the executive branch built in January to move at wartime speed. It is a proposal, not law, and the contractors caught between the speed mandate and the disclosure duty are where the contradiction gets priced.
- The House Armed Services CITI Subcommittee's draft FY27 NDAA (H.R. 8800) would create a department-wide AI incident- and vulnerability-reporting program; Chairman's mark / CITI print released May 27, 2026.
- Protected, non-punitive 'good faith' disclosure would reach service members, civilian employees, and contractors/subcontractors at any tier; trade press describes annual unclassified reports to Congress, data not public.
- It lands five months after the January 2026 Department of War AI strategy emphasized 'wartime speed,' model parity within 30 days, and a 'responsible AI' definition rejecting 'ideological tuning' and beyond-statute usage limits.
- The assurance substrate is thin: the Army's ~$6.3M GUARD risk-evaluation effort and NIST's voluntary AI RMF are the closest existing tooling the mandate would lean on.
- It is a proposal in committee, not enacted law · survival through markup, the floor and Senate conference, plus funding and the designated official, are open.
A Proposal, Not a Law, and the Assurance Machinery Barely Exists
The AI incident-and-vulnerability reporting program is a proposal, not a law: it lives in the House Armed Services Committee's draft FY27 NDAA (H.R. 8800), and it can be amended, weakened or dropped in markup, on the floor, or in conference with the Senate. It would land five months after the executive branch rewrote its own AI strategy to accelerate, and the assurance machinery it presumes is only starting to exist.
- The Vehicle. The provision originated in the Cyber, Information Technologies, and Innovation (CITI) Subcommittee; the The draft bill text a committee chairman releases as the starting point for the committee's amendment and voting session. and CITI print were released May 27, 2026, with full-committee markup on June 4, 2026.
- The Design. Non-punitive by intent: "good faith" reporters, including federal contractors and subcontractors at any tier, are not, on the basis of that report alone, to face adverse contract or personnel action.
- The Reporting Cadence. Trade-press reporting (Federal News Network) describes annual, unclassified reports to Congress (incident counts, trends, recommendations), with the underlying data not publicly accessible; that congressional-reporting detail is single-outlet and to be confirmed against the primary An official document published by a congressional committee, such as the printed draft text of a bill under consideration..
- The Counter-current. In January 2026 the renamed Department of War issued an AI Strategy and an innovation-transformation memo built around "wartime speed," model parity within 30 days of public release, and a "responsible AI" definition that explicitly rejects "ideological tuning" and contract-level usage constraints beyond statute.
- The Thin Substrate. The assurance machinery is thin but real and pre-dates the bill: the Army's GUARD effort (a risk-evaluation contract of about $6.3 million) and NIST's AI Risk Management Framework are the closest existing scaffolding the reporting program would plug into.
A Brake Engineered for a Vehicle With No Governor
Nothing here is law. The AI incident-and-vulnerability reporting program lives in the House Armed Services Committee's draft FY27 NDAA, H.R. 8800, and it can be amended, weakened or dropped in markup, on the floor, or in conference with the Senate. It would give an official designated by the Secretary of Defense a single department-wide pipeline for reporting, tracking, analysis and remediation of covered AI incidents and vulnerabilities across development, testing, procurement, fielding and operation. The design is non-punitive: good-faith reporters, including federal contractors and subcontractors at any tier, are not to face adverse contract or personnel action on the basis of that report alone.
Five months earlier the executive branch moved the other way. The renamed Department of War issued an AI Strategy in January 2026 built around wartime speed, model parity within 30 days of a public release, and a responsible-AI definition that expressly rejects ideological tuning and contract-level usage constraints beyond statute. One branch is proposing an assurance and disclosure brake; the other removed the guardrail language in order to accelerate.
The harder problem is the substrate rather than the politics. A reporting mandate presumes a test, evaluation, verification and validation capacity that is still being stood up. The Army's GUARD effort, building risk profiles for emergent autonomous behavior, is a single contract of about $6.3 million. NIST's AI Risk Management Framework is voluntary guidance, not a mandatory defense control set. The definitions are broad, and they reach the page as a law firm's paraphrase of the committee print rather than verbatim statutory text: an event where an AI system causes or could foreseeably cause unintended harm, operates outside approved guardrails, or materially degrades performance. The judgment here is that two drafting choices decide whether any of this is real, namely which official owns the pipeline and how far on the basis of that report alone shields an award when an incident is material.
Two arms of government are pulling opposite ways
National Security & Defense. The mechanism is a designated official, named by the Secretary of Defense, owning a single department-wide pipeline for reporting, tracking, analysis and remediation of "covered AI incidents" and "covered AI vulnerabilities" across development, testing, procurement, fielding and operation.
Regulatory Policy. The legislative branch is proposing an assurance and disclosure brake; the executive branch's January strategy deliberately removed ethics-guardrail language to accelerate. The reporting program would be a brake engineered for a vehicle whose governor was just removed.
The executive branch endorses the incident-reporting provision in a Statement of Administration Policy on H.R. 8800, or stands up the pipeline before enactment. Both branches would be pulling one way.
On the security side: the pipeline exists only once the Secretary names an official to own it, so which office would take a brake the department's own strategy argues against?
The definitions would land before the measurement layer exists
Regulatory Policy. The definitions are broad and, as reported, proposed/draft, paraphrased from Wiley's reading of the committee print with the verbatim statutory text to be confirmed against the HASC print / enrolled bill. As described, a "covered AI incident" is an event where an AI system causes or could foreseeably cause unintended harm, operates outside approved guardrails, or materially degrades performance; a "covered AI vulnerability" is an exploitable weakness or systemic issue that could affect mission performance, integrity, safety, or produce unauthorized behavior.
AI & Data Science. Incident reporting is a known pillar of AI governance: think-tank work (CSET on a mandatory reporting regime; RAND on institutional design of incident-reporting systems) treats standardized incident data as the precondition for finding recurring failure modes, and the NDAA provision is, in effect, that literature meeting a defense procurement statute.
AI & Data Science. But the technical substrate is immature: the Army's GUARD program, building "Behavior-Event Graph" risk profiles for emergent autonomous behavior, is a single modest contract, and NIST's AI RMF is voluntary guidance, not a mandatory defense control set. A reporting mandate presumes a TEVV (test, evaluation, verification, validation) capacity that is still being stood up.
The enrolled FY27 NDAA names a mandatory TEVV control set or funds assurance tooling alongside the reporting program. The measurement layer would arrive with the definitions rather than after them.
On the assurance side: an incident is defined partly as operating outside approved guardrails, so what tooling decides that a model did, and who validates the call?
Business is where the proposal gets priced
Strategy & Operations. Defense AI vendors face a two-sided pull: the January strategy pushes "any lawful use" contract language (targeted for incorporation within ~180 days), model parity within 30 days of release, and monthly velocity reporting; the FY27 provision would add a duty to disclose failures and vulnerabilities of those same fast-moving systems.
Strategy & Operations. The non-punitive, "report alone" safe harbor is the hinge for industry: it is meant to make disclosure safe, but counsel will read closely how far "on the basis of that report alone" actually shields an award when an incident is material.
The "any lawful use" contract clause issues with an incident-disclosure obligation already inside it. Vendors would face one contract requirement, not a speed mandate and a disclosure duty pulling apart.
On the contracting side: a safe harbor that shields a report alone leaves the incident itself actionable, so what does that leave a subcontractor at the third tier to weigh?
The Weave maps a single development across domains and across time. Each row follows one domain from where things stand now through the next eighteen months, and expands for the reasoning behind that trajectory.
- A defense build would be the largest live test, so its design choices become the reference.
- Whatever schema the department settles on tends to become the one other agencies copy.
- Federated reporting has been argued for on paper; this would be the first version at scale.
- Assurance written into statute is harder to reverse than a directive an office can rewrite.
- Once failures are tracked and visible to Congress, they read as a metric, not an anecdote.
- The durable gain is norms that survive a change of administration, not any single program.
- Recurring failure modes become visible only once incidents are recorded the same way twice.
- Standardized data is the precondition for systemic learning rather than a byproduct of it.
- Even unclassified summaries could move assurance practice well outside the defense world.
- Assurance overhead behaves like a fixed cost, so it weighs most on the smallest vendors.
- The firms least able to run a testing function are the ones the strategy is trying to attract.
- A standing burden can re-advantage the large primes and undo part of the intended opening.
Survival Is One Question. Funding and the Safe Harbor Are the Others
Everything consequential from here is legislative and administrative, and each step is checkable. The provision is still a draft that must survive markup, the floor and conference before any reporting duty exists, and the open design choices, funding, the designated official and the safe-harbor wording, would decide whether the mandate is real or a shell.
- Bill Survival. Whether the provision clears the House floor and Senate conference intact, weakened, or dropped from the FY27 NDAA (H.R. 8800).
- Enrolled Text and Section Number. The final section number and enrolled statutory text, including the verbatim "covered AI incident" and "covered AI vulnerability" definitions the draft currently carries only as attributed paraphrase.
- Safe-harbor Drafting. How "on the basis of that report alone" is drafted in the final text, the wording that would decide whether contractors disclose freely or defensively.
- Funding and the Designated Official. Whether the program is funded and which official the Secretary of Defense designates to own the reporting, tracking, analysis and remediation pipeline.
- The Implementing Substrate. Whether GUARD-style Short for test, evaluation, verification and validation, the defense discipline for proving a system behaves as intended before and after it is fielded. work and NIST-aligned frameworks are named as the program's implementing substrate or left unspecified.
Every issue
- 01Intersection of the week
- 02Impact of the week
- 03The week in review
Wiiver Weekly
One free email, Saturdays at 7:00 AM ET.
Unsubscribe anytime.
Primary sources4
- Congress.gov · H.R. 8800 (119th)H.R.8800 · National Defense Authorization Act for Fiscal Year 2027May 27Primary · Looking Forward · Where Things Stand
- House Armed Services Committee · FY27 NDAA TAL printH.R. 8800 · National Defense Authorization Act for Fiscal Year 2027 (TAL print)May 27Primary · Looking Forward
- U.S. Department of War (media.defense.gov)Artificial Intelligence Strategy for the Department of WarJan 12Primary · Where Things Stand
- NIST · AI Risk Management FrameworkAI Risk Management FrameworkApr 7Primary · The definitions would land before the measurement layer exists · Looking Forward · Where Things Stand · The Weave
Secondary sources, by sector12
- Wiley Rein LLPNew AI Incident Reporting Program Proposed for DODJun 2Secondary · Two arms of government are pulling opposite ways · The definitions would land before the measurement layer exists · Business is where the proposal gets priced · Looking Forward · Where Things Stand · The Weave
- Federal News NetworkHouse NDAA would set up protected disclosure program for AI incidentsMay 29Secondary · Business is where the proposal gets priced · Looking Forward · Where Things Stand · The Weave
- Nextgov/FCWTech bills of the week: FY27 NDAA tech and cyber measures; modernizing FAA aircraft repair forms; and moreMay 29Secondary · Looking Forward · Where Things Stand · The Weave
- Covington · Inside Government ContractsPentagon Releases Artificial Intelligence StrategyFeb 3Secondary · Two arms of government are pulling opposite ways · Business is where the proposal gets priced · Where Things Stand · The Weave
- Brennan Center for JusticeThe Good, Bad, and Really Weird AI Provisions in the Annual Defense Policy BillDec 15Secondary · The Weave
- Defense OneGrok is in, ethics are out in Pentagon's new AI-acceleration strategyJan 12Secondary · Two arms of government are pulling opposite ways · Where Things Stand · The Weave
- ChinaTalk · Sen. Slotkin on the NDAASen. Slotkin on NDAA, AI Nukes, Chinese Cars, and Taiwan · guest Sen. Elissa Slotkin, D-Mich., Senate Armed Services Committee (former OSD Policy)Jun 11Secondary · The Weave
- ChinaTalk · WarTalk feat. Jack ShanahanWarTalk: Iran War 'Love Tap' Edition · guest Lt. Gen. (ret.) Jack Shanahan, founding director, DoD Joint AI Center (JAIC); former head of Project MavenMay 9Secondary · The Weave
- Holland & KnightDepartment of War's Artificial Intelligence-First Agenda: A New Era for Defense ContractorsFeb 23Secondary · Business is where the proposal gets priced · The Weave
- DefenseScoopArmy moves to assess AI's 'unpredictable behaviors' and safeguard autonomous systemsJan 12Secondary · The definitions would land before the measurement layer exists · Looking Forward · Where Things Stand · The Weave
- CSET (Georgetown)AI Incidents: Key Components for a Mandatory Reporting RegimeJan 1Secondary · The definitions would land before the measurement layer exists · The Weave
- RAND CorporationDesigning Incident Reporting Systems for Harms from General-Purpose AIApr 1Secondary · The definitions would land before the measurement layer exists · The Weave