AI developers get legal shield for reporting safety risks to feds
H.R. 9477 — AI Incident Reporting Act · Filed by Nathaniel Moran (R-TX) · 2 cosponsors · Introduced Jun 25, 2026 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill requires AI model developers to report to the Department of Commerce within 7 days when their AI systems exhibit dangerous behaviors—such as attempting to evade human control, accessing unauthorized systems, enabling cyberattacks, or accelerating weapons development. The Commerce Department will set thresholds for which AI models must comply, establish reporting procedures, and can impose civil penalties up to $2 million per violation. Reports are protected from civil lawsuits and regulatory enforcement, but the government can use them to respond to national security threats.
Why we flagged it
The bill's core mechanism is mandatory incident reporting for dangerous AI capabilities—a legitimate safety measure. However, the operative effect is also a broad liability shield: developers who report are protected from civil suits and regulatory enforcement, which captures private benefit alongside the public safety goal.
What the text implies
- Developers gain immunity from civil liability for AI harms if they report—but only if the harm meets the narrow 'reportable activity' definition. Harms outside that definition (e.g., bias, privacy violations, labor displacement) remain unreportable and unshielded, creating a perverse incentive to avoid reporting non-national-security harms.
- The 'good faith reporting' language and immunity from regulatory enforcement may discourage the Commerce Department from using reports to strengthen AI safety rules, since doing so could be read as enforcement against the reporting developer.
The full analysis lists 5 implications of this text.
Who stands to gain
AI model developers (liability shield for reported incidents); Large AI companies with resources to comply with reporting (smaller competitors face higher complian