Warner's AI security bill wants models 45 days before release

Share
Warner's AI security bill wants models 45 days before release

Washington produced two AI-governance signals on Thursday: a bill with actual numbers in it, and a state regulator deciding that the AI inside a sportsbook is now its business.

Senators Mark Warner, Brian Schatz and Andy Kim introduced the Artificial Intelligence Risk Management and Security Act of 2026 on Thursday and went to the Senate floor the same day to demand it pass by unanimous consent. The bill creates a permanent AI Safety Board inside the Commerce Department — NIST, CISA, the NSA and Treasury, plus outside technical experts — and would require developers of frontier models to hand over model weights, configuration files, runtimes and the libraries needed to run them at least 45 days before public release. Companies would also have to file Model Safety Plans naming the capabilities they are worried about, the mitigations they have chosen and the corporate officer responsible for carrying them out.

The enforcement numbers are the part to remember. Violations of the Board's standards carry civil penalties of up to $250,000 per violation, per day. Serious safety and security incidents must be reported within 30 days, compressed to 72 hours when an incident poses an imminent threat to national security, critical infrastructure or public safety. And one section is written specifically for AI agents: standards covering identity, authentication, authorization and data access, plus standardized documentation listing an agent's intended uses, authority boundaries and known limitations. Warner's framing ties it directly to this month's incidents — "If a model is capable of finding and exploiting vulnerabilities in a bank, a water system, or our electric grid, we ought to know that before it is released to the public."

Read the bill as a draft of the regime, not as law. It is a Democratic-only bill arriving in a Senate where the House Speaker's stated position is that safety is the companies' job, and unanimous consent fails the moment one senator objects — which, for a bill this sweeping, is close to certain. But the text is the first concrete US answer to the question the September pacing debate left open: what would independent evaluation of frontier models actually require? Forty-five days, the weights, a named officer, and a penalty with a daily meter. Compare that with the voluntary-access arrangements in place now, or with the duty-of-care draft that was still being negotiated in private two weeks ago — Senate weighs a duty-of-care law that could block unsafe AI models — and the gap is the point: the earlier proposal gave regulators a veto over a release, this one gives them the model first.


Massachusetts' gaming regulator ordered its staff to evaluate how sports betting operators use AI and machine learning, after a New York Times investigation into DraftKings. Commission chairman Jordan Maynard said he had asked executive director Dean Serpa to engage with DraftKings "to understand the specifics that were reported" and to look at how every licensed operator in the state uses these systems. "These technologies are evolving rapidly across our society and we share the concern over their application," Maynard said. Commissioner Paul Brodeur called the reporting "troubling" but added that regulators need to establish the facts on the ground, noting Massachusetts is one of the only states whose rules even mention artificial intelligence.

The precise verb matters here, and the Commission chose a soft one: it is reviewing, not investigating, and no enforcement action has opened. Maynard has the machinery for it — the Commission commissioned a first-of-its-kind study on AI in gaming from UNLV's International Gaming Institute and formed a standing AI task force on its recommendation. That this arrives four days after the reporting, from a state whose rules already bar promotions that target players in ways the platform knows or should know are addictive, is the more interesting signal. Massachusetts built the rule first; it is now the first to go looking for the AI that breaks it. We covered what the Times found in the algorithms themselves — DraftKings built AI to find losing bettors, shelved the addiction model.

What to watch: whether any Republican senator engages with the 45-day access requirement now that the text exists, and whether the Massachusetts review produces a rule change or a report nobody acts on.

Should a state gaming commission have to prove an AI system was aimed at problem gamblers before it can act — or should deploying one be enough? Tell us in the comments.

Sources: Sen. Mark Warner — AI Risk Management and Security Act press release · Bill text (PDF) · MLex · CDC Gaming · The New York Times · Legal Sports Report · EFF