Cybersecurity Policy Report, Senate Intelligence Bill Would Encourage Prerelease Testing of AI Hacking Capabilities, (May 26, 2026)
Organizations Mentioned:Director of National Intelligence

U.S. intelligence agencies would be given “opportunities” to conduct prerelease testing of AI (artificial intelligence) models capable of hacking critical infrastructure under legislation that cleared the Senate Intelligence Committee last week by a vote of 14-3.
The Intelligence Authorization Act (IAA) for fiscal year 2027 (S.B. 4615, 119th Cong. (2026)) would direct the National Security Agency’s Artificial Intelligence Security Center to provide “a research test-bed to private sector and academic researchers, on a subsidized basis, to engage in artificial intelligence security research,” according to the IAA’s text.
The center’s work would examine, among other things, foreign adversaries’ attempts to use AI to “develop and manage computer network exploitation campaigns, design or develop weapons systems, or enhance surveillance capabilities in ways that undermine the privacy or threaten the security of citizens of the United States,” the bill says.
The Trump administration is considering whether to conduct prerelease testing of some frontier AI models following disclosures by Anthropic and OpenAI that their most advanced models were capable of quickly identifying and exploiting cybersecurity vulnerabilities. President Trump last week was scheduled to sign an executive order on AI testing but decided the order needed further work (CPR, May 21).
The IAA, however, would provide “opportunities” for the IC to conduct “pre-deployment testing of AI models, helping U.S. firms protect against potential misuse of their models for foreign hacking or weapons proliferation activity,” Sen. Tom Cotton (R., Ark.), the Intelligence Committee’s chairman, said in a news release.
“This year’s IAA enhances support to and oversight of the Intelligence Community’s use of artificial intelligence to ensure that this powerful technology keeps America safe without creating unexpected vulnerabilities,” according to Sen. Mark Warner (D., Va.), the committee’s vice chairman.
The legislation would also direct the IC to target “foreign malicious cybercriminal organizations” and “treat collection, analysis, and disruption toward hostile foreign cyber actors as a national intelligence priority.”
Sen. Ron Wyden (D., Ore.), a member of the committee, said in a news release that he voted against the bill because of its “multiple troubling provisions,” including the elimination of a Senate confirmation requirement for the general counsels of the Central Intelligence Agency and the Office of the Director of National Intelligence.
“The bill is a dramatic retreat for congressional oversight, at precisely the moment when scrutiny of Intelligence Community activities is needed most,” Sen. Wyden said. “This bill would deny the U.S. Senate any opportunity to scrutinize and vet key Intelligence Community leaders.”
The IAA is one of a handful of annual bills viewed by members of Congress as “must-pass” legislation. In recent years it has passed as part of the annual National Defense Authorization Act.
MainStory: TopStory FederalLegislation DataSecurity AINews