Overview
Severity: MEDIUM | Affected: US Government | Category: policy
The U.S. government has enacted the 'AI System Resilience and Safety Act,' a landmark piece of legislation aimed at enhancing the security of critical AI systems. A key provision of the act mandates that companies deploying AI in critical infrastructure sectors—such as finance, energy, and healthcare—must undergo regular, mandatory third-party red teaming and vulnerability assessments. The new law establishes a certification framework to be overseen by the National Institute of Standards and Technology (NIST) and CISA. AI providers failing to comply will face significant fines and potential operational restrictions. This policy shift reflects growing concerns among lawmakers about the potential for systemic risks posed by insecure or brittle AI models. While praised by security advocates, some industry groups have expressed concerns about the potential for increased compliance costs and a slowdown in innovation.