U.S. advances CIRCIA and AI bills
CIRCIA could take effect in late 2026 or early 2027, while Congress weighs bills that would require AI reporting
The final CIRCIA rule, the U.S. critical infrastructure reporting law, is scheduled for September 2026 and could begin taking effect by late that year or early 2027. At the same time, Congress is moving the FRONTIER Act and a bipartisan Senate draft that would require reporting, audits, and powers to block unsafe AI models.
The final CIRCIA rule, the U.S. critical infrastructure reporting law, is scheduled for September 2026 and could begin taking effect by late that year or early 2027. At the same time, Congress is moving the FRONTIER Act and a bipartisan Senate draft that would require reporting, audits, and authority to block AI models deemed unsafe. The regulatory push creates a two-sided compliance burden for companies with U.S. operations, including Latin American subsidiaries and groups exposed to critical infrastructure or advanced AI development.
What changes with CIRCIA?
CIRCIA requires covered entities to report significant cyber incidents to CISA within 72 hours of reasonably believing they occurred, and ransomware payments within 24 hours of making the payment. CISA published the proposed rule in April 2024, and the OMB regulatory agenda places the final rule in September 2026, with enforcement starting at least 60 days after publication.
That timeline gives many organizations limited room to adjust internal processes. Federal News Network said that, although the deadlines look straightforward, companies need stronger detection, incident classification, and reporting channels before the rule starts to apply. The scope also reaches foreign operators with critical assets under U.S. jurisdiction.
Who does it apply to?
The final rule is aimed at incidents in the 16 critical infrastructure sectors defined by U.S. policy, not at developers of frontier AI models. That sector-based boundary appears both in the regulatory agenda and in the technical explanations tied to PPD-21 and CIRCIA, which connect the obligation to Title 6 of the U.S. Code, section 681b.
Under that reading, foreign operators of assets in those sectors, including those serving Latin American markets from U.S. territory, would be subject to reporting deadlines when they are covered entities. The scope matters for companies in energy, telecom, transportation, finance, and other critical activities with a presence or assets in the United States.
What is happening on AI meanwhile?
The FRONTIER Act is moving in the House of Representatives. Introduced on July 23, 2026, it would require certain developers of frontier AI systems to publish safety frameworks, report critical incidents to the Commerce Department, undergo recurring third-party audits, and face an emergency suspension authority for models that pose catastrophic risk. The bill also sets 72-hour reporting for critical safety incidents and 24-hour reporting for events that pose an imminent risk of death or serious physical harm.
The proposal also gives the Commerce Secretary the power to suspend or restrict the development, deployment, or internal use of a model when there is an imminent catastrophic risk. That intervention power could reach foreign groups' subsidiaries under U.S. jurisdiction.
In the Senate, the bipartisan bloc led by John Thune, Ted Cruz, and Amy Klobuchar is working on a proposal that would impose a legal duty of care on developers of highly capable models and allow unsafe systems to be blocked before they reach the public. Reuters reported that negotiators are weighing compliance testing for the duty of care, government auditors, and access to federal courts to stop launches.
Legislative and political coverage agrees that no federal AI safety law has been enacted yet. Takeoff.watch, Politico, Santage AI, and Yahoo News describe a landscape of drafts still under negotiation, with no final text or vote schedule, while other reviews show multiple federal bills moving on transparency, safety, and accountability in AI.
Sources
- PPD-21 Explained: Sectors, CIRCIA Reporting, and NSM-22fedlaws.org· FedLaws.org
- Trust Issues: September 2026dwt.com· Davis Wright Tremaine LLP – Privacy & Security Law Blog
- US federal frontier-AI regulationtakeoff.watch· Takeoff.watch
- AI Bills Tracked — Restore the Firstrestorethe1st.com· Restore the First
- The Senate Wants Power to Block Unsafe Frontier AIsantageai.com· Santage AI
- 25 Principles: U.S. Critical Infrastructure Cybersecurity Polist25.com· List25
- CIRCIA's Looming Deadline Puts Corporate Counsel on the Clocklaw.com· Law.com (Corporate Counsel)
- US senators weigh requiring AI giants to commit to preventing catastrophereuters.com· ReutersUnverified URL
- Lawmakers push for AI safety legislation amid extinction fearscryptobriefing.com· CryptoBriefing
- CISA Cyber Storm exercise offers blueprint for enterprise CISOstechtarget.com· TechTarget – Cybersecurity
- Thune, Cruz, And Klobuchar Move AI Safety From Voluntary ...techtimes.com· TechTimes
- H.R.9925 - 119th Congress (2025-2026): FRONTIER Actcongress.gov· Congress.govUnverified URL
- The Regulatory Gap: Agentic AI Outpaces Federal Oversightyahoo.com· Yahoo News
- Beyond the town halls: Getting ready for CIRCIA before the clock starts tickingfederalnewsnetwork.com· Federal News Network
- Senate AI safety bill's path forward remains unclearpolitico.com· PoliticoUnverified URL



