(1)
Artificial intelligence— The term artificial intelligence has the meaning given that term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (
15 U.S.C. 9401).
(2)
Autonomous weapon system— The term autonomous weapon system means a weapon system that, once activated, can select and engage targets without further intervention by an operator, including operator-supervised autonomous weapon systems that, after activation, can select and engage targets without further operator input.
(3)
Covered contract— The term covered contract means a contract, task order, delivery order, or other agreement for the development, training, fine-tuning, evaluation, hosting, integration, or provision of an artificial intelligence model or artificial intelligence system for use by the Department.
(4)
Covered contractor— The term covered contractor means an entity that develops or provides a frontier artificial intelligence model to the Department under a covered contract.
(5)
Covered incident— The term covered incident means any of the following:
(A)
Theft, unauthorized access, unauthorized acquisition, or exfiltration of model weights for an artificial intelligence model, including—
(i)
instances in which a model autonomously attempts to exfiltrate such model weights or acquire unauthorized access to systems containing such model weights; and
(ii)
credible evidence indicating attempts or material vulnerabilities, relating to any such theft, access, acquisition, or exfiltration.
(B)
Attempts by a foreign adversary or individual acting on behalf of a foreign adversary to obtain unauthorized access to, acquire, influence, or exfiltrate sensitive information, systems, or intellectual property related to an artificial intelligence model or artificial intelligence system, including through insider threats, compromised personnel, covert affiliations, or other deceptive means.
(C)
A compromise of the software, hardware, cloud, data, or other supply chain used to develop, train, fine-tune, evaluate, secure, or deploy an artificial intelligence model or artificial intelligence system, where such compromise could reasonably affect the confidentiality, integrity, availability, reliability, or security of the model or system provided to the Department.
(D)
Poisoning, corruption, manipulation, or unauthorized alteration of training data, fine-tuning data, retrieval corpora, model checkpoints, system prompts, safety filters, monitoring systems, evaluation pipelines, or model-update mechanisms.
(E)
The discovery of a material vulnerability, exploit, backdoor, or failure of access controls that could permit unauthorized modification, extraction, degradation, or misuse of an artificial intelligence model or artificial intelligence system.
(F)
Any materially concerning model behavior, including materially increased capability for cyber offense, exploitation, exploitation or evasion of safeguards, deceptive behavior, capabilities related to chemical or biological weapons, automated research and development in national security domains, automated research and development toward increasingly powerful artificial systems, unauthorized autonomous action, or other behavior that poses a significant risk to national security or the operations, personnel, or systems of the Department, when such behavior was not previously disclosed to the Department.
(G)
Any incident for which the Secretary determines that timely notice is necessary to protect national security or operations of the Department.
(6)
Department— The term Department means the Department of Defense.
(7)
Frontier artificial intelligence model— The term frontier artificial intelligence model means a general-purpose model, foundation model, or other large-scale model designated by the Secretary, in consultation with the Chief Digital and Artificial Intelligence Officer and the Secretary of Commerce, as appropriate, as presenting significant national security relevance due to scale, capability, operational use, or potential for misuse.
(8)
High-consequence artificial intelligence application— The term high-consequence artificial intelligence application means any use by the Department of artificial intelligence that the Secretary designates under section 3 as presenting heightened national security, operational, safety, legal, or civil liberties risk, including any use relating to nuclear command, control, and communications, intelligence support to lethal targeting, cyber operations, autonomous weapon systems, military decision support in time-sensitive operations, homeland-facing surveillance or monitoring, or mission-critical logistics and sustainment.
(9)
Individual— The term individual means a natural person.
(10)
Local defense— The term local defense means defense within a specifically defined geographic defensive area (commonly referred to as point defense) or of a high-value physical asset (commonly referred to as platform defense) and for a specifically defined period of operation approved for the system concerned.
(11)
Materiel target— The term materiel target —
(A)
means a weapon, munition, military vehicle, military vessel, military aircraft, unmanned system, or other military object; and
(B)
does not include an individual.
(12)
Pattern-of-life analysis— The term pattern-of-life analysis means the use of data over time to infer or map the habits, movements, associations, or routines of an individual or a group of individuals.
(13)
Persistent person-centric analytic product— The term persistent person-centric analytic product means a dossier, watchlist, score, profile, targeting package, or other record organized primarily around an identified or identifiable individual.
(14)
Operational deployment— The term operational deployment means use of an artificial intelligence system in support of, or as part of, an operational military mission, contingency, or real-world military activity other than testing, training, evaluation, or experimentation conducted in a controlled environment.
(15)
Operator-supervised autonomous weapon system— The term operator-supervised autonomous weapon system means an autonomous weapon system that is designed to provide operators with the ability to intervene and terminate engagements, including in the event of a weapon system failure, before unacceptable levels of damage occur.
(16)
Secretary— The term Secretary means the Secretary of Defense.
(17)
Semi-autonomous weapon system—
(A)
In general— The term semi-autonomous weapon system means a weapon system that, once activated, is intended to only engage single targets or specific target groups that have been selected by an operator.
(B)
Inclusions— The term semi-autonomous weapon system includes weapon systems that employ autonomy for engagement-related functions, including—
(i)
acquiring, tracking, and identifying potential targets;
(ii)
cuing potential targets to operators;
(iii)
prioritizing selected targets;
(iv)
timing of when to fire;
(v)
providing terminal guidance to home in on selected targets, provided that operator control is retained over the decision to select single targets and specific target groups for engagement; and
(vi)
“fire and forget” or lock-on-after-launch homing munitions that rely on tactics techniques and procedures to maximize the probability that the only targets within the seeker’s acquisition basket when the seeker activates are those individual targets or specific target groups that have been selected by an operator.
(18)
United States person— The term United States person has the meaning given that term in section 101 of the Foreign Intelligence Surveillance Act of 1978 (
50 U.S.C. 1801).