As ordered reported by the House Committee on Science, Space, and Technology on June 25, 2026
By Fiscal Year, Millions of Dollars | 2026 | 2026-2031 | 2026-2036 | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
Direct Spending (Outlays) | 0 | 0 | 0 | ||||||||
Revenues | 0 | 0 | 0 | ||||||||
Increase or Decrease (-) in the Deficit | 0 | 0 | 0 | ||||||||
Spending Subject to Appropriation (Outlays) | 0 | 36 | not estimated | ||||||||
Increases net direct spending in any of the four consecutive 10-year periods beginning in 2037? | No | Statutory pay-as-you-go procedures apply? | No | ||||||||
Mandate Effects | |||||||||||
Increases on-budget deficits in any of the four consecutive 10-year periods beginning in 2037? | No | Contains intergovernmental mandate? | No | ||||||||
Contains private-sector mandate? | No | ||||||||||
H.R. 9333 would require the National Institute of Standards and Technology (NIST), in consultation with the Cybersecurity and Infrastructure Security Agency (CISA), to establish a program for voluntary reporting, collection, and tracking of flaws in artificial intelligence (AI) systems. The bill would direct NIST to develop or support a national database to track and monitor AI flaws and convene representatives from relevant organizations, such as industry, academia, and other federal agencies, to establish common definitions of and classification criteria for AI flaws. NIST also would develop technical standards, disclosure norms, and guidance for detecting, managing, and remediating flaws. The bill would direct the agency to convene panels that would assess voluntary reporting and tracking of AI security incidents and develop definitions, classification criteria, and reporting practices for such incidents. Within three years of enactment, NIST would report to the Congress on the program’s implementation.
The estimated budgetary effects of the legislation are shown in Table 1. The costs of the legislation fall within budget functions 050 (national defense) and 370 (commerce and housing credit).
Table 1. Estimated Budgetary Effects of H.R. 9333 | |||||||
By Fiscal Year, Millions of Dollars | |||||||
2026 | 2027 | 2028 | 2029 | 2030 | 2031 | 2026-2031 | |
Increases in Spending Subject to Appropriation | |||||||
Estimated Authorization | 0 | 4 | 7 | 10 | 10 | 10 | 41 |
Estimated Outlays | 0 | 3 | 6 | 8 | 9 | 10 | 36 |
Using information about NIST’s National Vulnerability Database (NVD), which could be a model for the database required by the bill, and considering the cost of similar activities, CBO estimates that, in total, implementing H.R. 9333 would cost $36 million over the 2026-2031 period; any related spending would be subject to the availability of appropriated funds.
CBO estimates that the database and reporting program would account for $32 million of that total over the 2026‑2031 period and that the program would ramp up over the course of three years. The costs of identifying AI flaws and security incidents, reporting to the Congress, and covering CISA’s related costs would make up the remaining $4 million over the 2026-2031 period.
CBO based its estimates on the costs of collecting, analyzing, and tracking reports of software vulnerabilities from a community of contributors. Because the bill would allow NIST to modify an existing database, CBO expects that the agency would build on the NVD or a similar database rather than construct a new system. CBO expects that the effort would require NIST to establish cooperative agreements and hire staff to manage the database.
This estimate is subject to uncertainty. The number of reports received cannot be predicted but would affect staffing and other costs. If actual reporting exceeds or falls below the amounts anticipated in this estimate, the costs could be higher or lower than CBO estimates. The program’s costs also would depend on how NIST develops the reporting infrastructure. CBO’s estimate reflects projected staffing by federal employees and nonfederal personnel under cooperative agreements. Building and operating the infrastructure entirely in-house would cost more and agreements that draw on existing systems or nonfederal resources would cost less than CBO estimates.
The CBO staff contact for this estimate is David Hughes. The estimate was reviewed by Chad Chirico, Director of Budget Analysis.

Phillip L. Swagel
Director, Congressional Budget Office