II 118THCONGRESS 1 STSESSION S. 2502 To require the Chief Data and Artificial Intelligence Officer of the Depart- ment of Defense to develop a bug bounty program relating to dual- use foundational artificial intelligence models. IN THE SENATE OF THE UNITED STATES JULY26, 2023 Mr. R OUNDSintroduced the following bill; which was read twice and referred to the Committee on Armed Services A BILL To require the Chief Data and Artificial Intelligence Officer of the Department of Defense to develop a bug bounty program relating to dual-use foundational artificial intel- ligence models. Be it enacted by the Senate and House of Representa-1 tives of the United States of America in Congress assembled, 2 SECTION 1. SHORT TITLE. 3 This Act may be cited as the ‘‘Artificial Intelligence 4 Bug Bounty Act of 2023’’. 5 VerDate Sep 11 2014 01:06 Aug 10, 2023 Jkt 039200 PO 00000 Frm 00001 Fmt 6652 Sfmt 6201 E:\BILLS\S2502.IS S2502 kjohnson on DSK79L0C42PROD with BILLS 2 •S 2502 IS SEC. 2. ARTIFICIAL INTELLIGENCE BUG BOUNTY PRO-1 GRAMS. 2 (a) P ROGRAM FOR FOUNDATIONAL ARTIFICIALIN-3 TELLIGENCEPRODUCTSBEINGINCORPORATED BY DE-4 PARTMENT OFDEFENSE.— 5 (1) D EVELOPMENT REQUIRED .—Not later than 6 180 days after the date of the enactment of this Act, 7 the Chief Data and Artificial Intelligence Officer of 8 the Department of Defense shall develop a bug 9 bounty program for foundational artificial intel-10 ligence products being incorporated by the Depart-11 ment of Defense. 12 (2) C OLLABORATION.—In developing the pro-13 gram required by paragraph (1), the Chief may col-14 laborate with the heads of other government agen-15 cies that have expertise in cybersecurity and artifi-16 cial intelligence. 17 (3) I MPLEMENTATION AUTHORIZED .—The 18 Chief may carry out the program developed pursu-19 ant to subsection (a). 20 (4) C ONTRACTS.—The Secretary of Defense 21 shall ensure that whenever the Department of De-22 fense enters into any contract, the contract allows 23 for participation in the bug bounty program devel-24 oped pursuant to paragraph (1). 25 VerDate Sep 11 2014 01:06 Aug 10, 2023 Jkt 039200 PO 00000 Frm 00002 Fmt 6652 Sfmt 6201 E:\BILLS\S2502.IS S2502 kjohnson on DSK79L0C42PROD with BILLS 3 •S 2502 IS (5) RULE OF CONSTRUCTION .—Nothing in this 1 subsection shall be construed to require— 2 (A) the use of any foundational artificial 3 intelligence product; or 4 (B) the implementation of the program de-5 veloped pursuant to paragraph (1) in order for 6 the Department to incorporate a foundational 7 artificial intelligence product. 8 (b) B RIEFING.—Not later than one year after the 9 date of the enactment of this Act, the Chief shall provide 10 the congressional defense committees (as defined in sec-11 tion 101(a) of title 10, United States Code) a briefing 12 on— 13 (1) the development and implementation of bug 14 bounty programs the Chief considers relevant to the 15 matters covered by this section; and 16 (2) long-term plans of the Chief with respect to 17 such bug bounty programs. 18 Æ VerDate Sep 11 2014 01:06 Aug 10, 2023 Jkt 039200 PO 00000 Frm 00003 Fmt 6652 Sfmt 6301 E:\BILLS\S2502.IS S2502 kjohnson on DSK79L0C42PROD with BILLS