IC Oversight & Policy — 2026-10-10
Bipartisan Senate Bill Would Require Pentagon to Continuously Vet Frontier AI Contractors for Counterintelligence and Security Risks
BLUFThere is almost no chance this bill becomes law by year-end, but its disclosure terms could migrate into the NDAA and set the baseline for how the Pentagon regulates frontier AI vendors.
Sens. Jim Banks (R-Ind.) and Kirsten Gillibrand (D-N.Y.) proposed the 18-page Insider Threat Reporting and Security Guidance Act of 2026, DefenseScoop reported on October 8
Analysis
The bill willalmost no chance of being signed into law by the end of 2026. We have moderate confidence in that judgment, because reporting traces to a single outlet, DefenseScoop, and shows only an introduction, with no committee scheduling, House companion, or leadership endorsement. Its value is as a signal of the terms Banks and Gillibrand want imposed on frontier AI vendors: 72-hour theft notice, seven-day vulnerability notice, and 90-day certification. The sponsors may instead be seeking an NDAA amendment or leverage with the Pentagon, which would let the text shape policy without standalone passage. The $100 million threshold would reach the eight firms with classified-network agreements, and the Pentagon-Anthropic dispute sharpens the politics. Vendors need only watch NDAA text, while contracting officers keep setting security terms vendor by vendor.
The bill will