Congress moves to set AI safety standards for federal agencies—with a big national security loophole
H.R. 8819 — Federal Artificial Intelligence Risk Management Act of 2026 · Filed by Ted Lieu (D-CA) · 3 cosponsors · Introduced May 14, 2026 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill directs the National Institute of Standards and Technology (NIST) to develop federal standards and guidelines for how government agencies use artificial intelligence systems—covering risk management, synthetic content labeling, and AI procurement testing. The standards would apply to civilian agencies but exempt national security systems, and NIST would help agencies implement them and periodically assess their effectiveness.
Why we flagged it
The bill's core function is establishing federal standards and risk-management guidelines for civilian government AI systems, with NIST as the lead agency. It is regulatory infrastructure, not a carve-out or subsidy.
What the text implies
- The exemption for 'national security systems' is broad and undefined in this text; it may allow DoD, intelligence agencies, and other national-security-classified AI to operate without the standards, creating a two-tier system where the most sensitive government AI faces no public oversight.
- NIST's standards are advisory until submitted to the Secretary of Commerce (SecDOC) for promulgation under 40 USC 11331; the actual binding force and timeline for adoption by agencies is unclear and may be slow or voluntary.
The full analysis lists 4 implications of this text.
Who stands to gain
AI infrastructure and software vendors (AMD, HPE, Cisco, Cognizant, Verisign); Consulting and systems integration firms advising agencies on AI compliance; Standards-development and testing organizations