HR 9965
AI Threat Output and Monitoring Incident Containment Act
TL;DR
Rep. Celeste Maloy (R-UT) introduced this bill to create a federal framework for tracking and responding to AI safety incidents, similar to how cybersecurity breaches are reported. It would establish monitoring and containment protocols when AI systems produce dangerous outputs or behave in unexpected ways.
How This Might Impact Your Business
AI developers and deployers would likely face new incident reporting requirements when their systems produce harmful, biased, or unexpected outputs, similar to existing cybersecurity breach disclosure rules.
Companies building or using large language models, autonomous systems, or generative AI tools would need internal monitoring capabilities to detect and document 'threat outputs.'
Cloud providers and AI platform companies (think AWS, Azure, OpenAI, Anthropic) would potentially need containment procedures ready to activate when incidents occur.
Financial services, healthcare, and critical infrastructure operators using AI would face heightened scrutiny given their sector risk profiles.
The bill is early stage (just referred to committee) so specifics on penalties, thresholds, and deadlines are not yet defined.
Small businesses using off-the-shelf AI tools would likely rely on their vendors for compliance, but should expect new contract terms around incident notification.
Federal contractors using AI should watch closely, as government procurement rules often adopt these frameworks first.
What Should You Do
Ask your CTO or head of AI to inventory where AI is deployed in your business and whether you currently log unusual outputs or model behavior.
Direct your legal team to review vendor contracts with AI providers for incident notification clauses; add them if missing.
Assign someone to track this bill through the House Science, Space, and Technology Committee and flag any markup sessions.
Benchmark your AI governance against NIST's AI Risk Management Framework now, since federal legislation typically builds on it.
If you operate in regulated sectors (finance, healthcare, infrastructure), start drafting an internal AI incident response playbook modeled on your cybersecurity IR plan.
Who It Affects
Sponsors
Status Timeline
committee
Referred to the House Committee on Science, Space, and Technology.
July 27, 2026
committee
Referred to the House Committee on Science, Space, and Technology.
July 27, 2026