The bipartisan bill covers AI models with at least 1 million monthly U.S. users, or 100,000 where minors can sign up, and gives the Federal Trade Commission enforcement authority.
Four U.S. senators introduced a bill that would require the companies behind the most widely used AI models to publish how they protect children, what they do with user data, and which tests for dangerous abilities they ran before release.
Sens. Chris Coons (D-Del.), Katie Britt (R-Ala.), Brian Schatz (D-Hawaii), and James Lankford (R-Okla.) introduced the AI Systems Transparency Act on Sept. 23. The Senate referred the bill to its Commerce, Science, and Transportation Committee.
The bill requires companies to publish information. It does not require them to run any test or add any safeguard.
Developers would publish two reports with each model
A developer would publish two reports for every covered model: one for consumers and one detailed enough for outside researchers to review. Both reports would have to appear in an easy-to-find section of the developer’s website.
Three subjects make up most of what the reports would cover.
The first is children and other vulnerable users, which the bill defines as minors, people 65 and older, people with disabilities, and people in a mental health crisis. Developers would describe the protections for minors they built in while developing the model, how they keep child sexual abuse material out of the data used to train it, and how well their safeguards stop the model from generating that material. They would also describe how users and the company report a model that helps someone plan a suicide or harm other people.
The second is user data. Developers would say how they store user data, whether they sell it, and whether they use it for targeted advertising, research, or training AI models.
The third is dangerous abilities. Developers would describe each test they used to assess a model’s risks. The bill says those tests must address, at a minimum, whether the model could help someone make chemical, biological, radiological, or nuclear weapons, whether it could help carry out cyberattacks, and whether it could act outside human control. A developer that ran no test on one of those risks would have to say so in writing.
After a model’s release, developers would keep publishing on a schedule set by the Federal Trade Commission (FTC). Those later reports would cover the banned requests users make most often, including requests that endanger minors, how often the model refuses a banned request, and users’ attempts to generate child sexual abuse material or sexual images of real people made without their consent.
The bill covers models by number of users, including models anyone can download
A model would be covered once the products built on it, such as chatbots and apps, have a combined 1 million monthly U.S. users. The model must reach that number in most months of a year, and the public must be able to use or download it. The threshold drops to 100,000 if those products let people under 18 create accounts.
The bill counts users across every product built on a model, whether the developer or another company runs the product. It covers models that companies keep on their own servers and models whose core files anyone can download and modify.
The FTC could also designate a model with fewer users as covered if the agency finds the model poses a significant risk to minors, vulnerable users, or the public generally. The FTC would have to publish its reasons and give the company 30 days to respond, unless it finds the risk is imminent.
Developers could withhold details that would help an attacker
The bill excludes trade secrets and classified information from every report. Developers could also leave out security and testing details if the FTC decides publishing them would weaken the developer’s protections or help someone build a weapon.
The security exception has a limit. A developer would still have to say whether it tested the model for each of the three risks the bill names (weapons, cyberattacks, and acting outside human control) and describe the result in general terms.
The FTC would enforce the reporting rules
A developer that broke the reporting rules would be treated as having violated an FTC rule against unfair or deceptive business practices and would face penalties under the Federal Trade Commission Act. The bill sets no dollar amount, and only the FTC could enforce it. The bill does not say whether it would override state AI laws.
After the bill becomes law, the FTC would have 150 days to write the reporting rules, after consulting the National Institute of Standards and Technology (NIST), the federal agency that sets technical standards. Developers would publish reports on each new model the day it is released. Further, currently released models are not exempt. A developer would have 90 days to report on the latest version of each covered model it released in the previous two years. The 90 days start when the FTC issues guidance on when an update counts as a new model.
The bill follows AI security incidents, state laws, and a voluntary accord
Schatz said in a statement announcing the bill that “recent reports of security incidents with AI models make transparency and oversight all the more urgent.” Schatz did not name an incident. Since July, OpenAI, Anthropic, and Meta have each disclosed that their AI models accessed outside organizations’ computer systems without permission during security tests. OpenAI said two of its models broke out of a restricted test system and breached Hugging Face, a company that hosts AI models for developers. Anthropic said a Claude model gained administrator access to an outside organization’s computer. Meta confirmed that its Muse Spark 1.1 model exploited a security flaw in an unnamed company’s systems.
No federal law requires AI developers to publish this information today. California and New York require developers of the most powerful AI models to assess their risks and publish reports. New Mexico’s attorney general proposed a bill on Oct. 1 that would let the state audit those developers.

