United States - AI Research Resource (H.R. 2385)

Creating Resources for Every American To Experiment with Artificial Intelligence (CREATE AI Act / H.R. 2385)

United States

RAI-US-NA-CREAEXX-2025
Proposed(Officially filed for action)
BillGovernance and OversightCybersecurity and Model SecurityAccountability and Documentation
Export PDF

H.R. 2385 (CREATE AI Act of 2025) proposes to codify and authorize the National Artificial Intelligence Research Resource (NAIRR), establishing governance, a Program Management Office through the National Science Foundation (NSF), an Operating Entity, and rules for provisioning computational resources, datasets, models, testbeds, and training for eligible U.S.-based researchers and educators. The bill defines institutional roles, user eligibility, security and privacy requirements, and reporting and oversight mechanisms.

Summary

H.R. 2385, the Creating Resources for Every American To Experiment with Artificial Intelligence (CREATE AI Act of 2025), seeks to give statutory form to the National Artificial Intelligence Research Resource (NAIRR) by amending existing statutory provisions and authorizing a governance framework to operate and scale the NAIRR. The bill amends sections added by the William M. (Mac) Thornberry National Defense Authorization Act for Fiscal Year 2021 and the National Artificial Intelligence Initiative Act to establish a NAIRR Steering Subcommittee within the existing Interagency Committee and to require the Office of Science and Technology Policy (OSTP) Director to chair that subcommittee. The bill instructs the National Science Foundation (NSF), acting as the Program Management Office, to oversee operations through a competitively selected nongovernmental Operating Entity that will provision resources, maintain a portal, manage staff, and continually modernize infrastructure.

The NAIRR is intended to federate computational resources (on-premises, cloud, hybrid), curated datasets, open-source software environments, APIs for models, AI testbeds, and educational/training materials. H.R. 2385 requires development of interoperability and data repository standards in coordination with the National Institute of Standards and Technology (NIST); establishes minimum cybersecurity requirements consistent with the NIST Cybersecurity Framework and the Cybersecurity and Infrastructure Security Agency (CISA); and mandates privacy, scientific integrity, and research security guidance consistent with existing presidential and federal research-security policy. The bill specifies eligible users (U.S.-based researchers, educators, students affiliated with higher education institutions, nonprofits, Executive agencies, federally funded research and development centers, and eligible small businesses with federal funding) and requires the Program Management Office to prioritize projects that advance the privacy, ethics, safety, security, risk mitigation, and trustworthiness of AI systems.

Operational features include a competitive, transparent selection of an Operating Entity, establishment of Advisory Committees drawing from government, academia, industry, and public-interest groups (exempting such committees from chapter 10 of title 5, U.S. Code), annual performance evaluation, and the ability to terminate the Operating Entity for unsatisfactory performance. The bill authorizes acceptance of donations and in-kind contributions to support NAIRR operations and allows a fee schedule that includes a free tier to sustain access while ensuring primary support for research. Reporting obligations include publicly available annual reports, publicly published policies for scientific integrity, and performance metrics. H.R. 2385 builds on the NAIRR Task Force final report (January 2023) and the NSF NAIRR pilot program (launched 2024), aligning statutory authority with ongoing federal pilot activities to create a more durable, scalable, and accountable national research infrastructure for AI.

Full article

Read full text ↗

Overview

The CREATE AI Act of 2025 (H.R. 2385) formally authorizes the National Artificial Intelligence Research Resource (NAIRR) by amending federal AI initiative statutes and establishing a permanent governance and operations model. The bill creates a NAIRR Steering Subcommittee chaired by the Director of the Office of Science and Technology Policy and clarifies the roles of the National Science Foundation (NSF) as the Program Management Office and of a competitively selected nongovernmental Operating Entity that will run the day-to-day portal, allocate resources, and manage staff. The statutory language closely follows recommendations from the NAIRR Task Force report, "Strengthening and Democratizing the U.S. Artificial Intelligence Innovation Ecosystem," and dovetails with the NSF-led NAIRR pilot activities. For the full bill text, see Text of H.R. 2385 (Congress.gov) and for background on ongoing pilot efforts see the NSF NAIRR pilot page at NSF: NAIRR Pilot.

Definitions

The bill provides definitions used throughout the title, including "NAIRR" or "National Artificial Intelligence Research Resource," "Operating Entity," "Program Management Office," and "resources of the NAIRR." "Resources" encompass computational (on-premises, cloud, hybrid), data repositories, open-source software environments, model APIs, testbeds, educational materials, and user support services. Eligibility definitions limit primary access to U.S.-based individuals affiliated with defined entities (institutions of higher education, nonprofits, Executive agencies, federally funded research and development centers, and certain small businesses with federal awards). The definitions also reference applicable definitions in underlying statutes such as the Stevenson-Wydler Technology Innovation Act and the Small Business Act to maintain statutory coherence.

Governance and Institutional Framework

Governance is a central focus: the NAIRR Steering Subcommittee is established within the interagency committee created by prior statute and chaired by OSTP's Director to set strategic direction and approve operating plans. The National Science Foundation acts as the Program Management Office responsible for developing the solicitation, selecting the Operating Entity, overseeing compliance, evaluating performance, and coordinating multiagency funding and resource contributions. The Operating Entity—selected by competitive bid—may be a single nongovernmental organization or a consortium (including federally funded research and development centers) and is contractually bound to deliver operations, staff, a public portal, policies, and annual reports. Advisory Committees comprised of government, academic, private sector, and public-interest representatives provide input; the bill exempts these advisory bodies from chapter 10 of title 5 to allow flexible composition. Relevant official sources include the bill text at Congress.gov and the NAIRR Task Force final report at NAIRR Task Force Final Report (Jan 2023).

Key Focus Areas

The statutory NAIRR focuses on several interlocking areas: (1) resource federation—integrating public and private computational and data resources and offering cloud, on-premises, and hybrid options; (2) curated data repositories and interoperability—NIST coordination to define data repository standards and selecting data repositories by competition; (3) secure and privacy-preserving research pathways—coordinating with NIH, DOE and other agencies for sensitive-data access and creating a NAIRR Secure pathway; (4) testbeds and evaluation tools to support trustworthy AI research, including methodologies contributed by agencies such as FDA and DOE; (5) education and workforce development—NAIRR Classroom resources, training and broad outreach to expand participation; and (6) governance, scientific integrity, and research security—explicit procedures for scientific integrity reporting, research security conformance with National Security Presidential Memoranda, and security baselines consistent with the NIST Cybersecurity Framework. See NSF descriptions of operational focus areas at NSF: NAIRR Pilot for examples of pilot focus areas and partnerships.

Implementation Framework

Implementation is staged through statutory directives: the Program Management Office (NSF) shall develop the solicitation, select an Operating Entity via transparent competition, and define policies for resource procurement, in-kind contributions, and user access. The Operating Entity manages provisioning, the portal, staff, KPIs, annual public reporting, user training, and testbed connections. The bill requires coordination with NIST on data standards, OMB on cross-agency consistency, and consultation with CISA for security. A fee schedule is permitted, including a free tier funded by appropriations, while allowing cost-based charges for extended resource use. Donations and private contributions are authorized for operational support. For operational pilots and awards that inform the statute, see the NSF announcement at NSF News: NAIRR Pilot Awards (May 6, 2024).

Monitoring and Evaluation

The bill mandates annual evaluation of the Operating Entity and public annual reports discussing performance, resource usage, and governance. The NAIRR Steering Subcommittee and an external independent evaluation entity (identified by the Program Management Office) are responsible for performance oversight; the Program Management Office may terminate the Operating Entity if performance is unsatisfactory and re-procure operations. The statute also calls for publication of KPIs, summaries of resources, and transparency regarding inclusion or retirement of resources. Scientific integrity policies and confidential reporting mechanisms for violations must be published on the NAIRR website, consistent with presidential guidance on scientific integrity.

Penalties, Liability, and Appeals

H.R. 2385 primarily leverages administrative and contractual remedies rather than creating a new enforcement regime of civil fines. The primary enforcement mechanisms include oversight by the Steering Subcommittee and the Program Management Office, contractual compliance reviews for the Operating Entity, termination of agreements for poor performance, and withholding or reallocation of appropriations. The bill requires that the head of the Program Management Office oversee compliance with privacy law and OMB policy and coordinate with legal counsel—administrative remedies, debarment under federal contracting rules, or referral to other agencies for enforcement may apply where statutory or regulatory violations are identified. The statutory emphasis is on governance enforcement and contractual accountability rather than new private-rights-of-action; this should be read alongside existing federal privacy, research integrity, and contract law remedies.

Relationship to Other Instruments

The CREATE AI Act builds on the National Artificial Intelligence Initiative Act of 2020, the NAIRR Task Force final report (Jan 2023), and prior provisions added by the William M. (Mac) Thornberry NDAA FY2021. It complements executive actions and federal guidance such as the AI Executive Order and OMB/OSTP policies on AI and scientific integrity, and references NIST guidance such as the AI Risk Management Framework. It also aligns with the existing NSF NAIRR pilot program and the NAIRR Operations Center solicitation (NAIRR-OC) that transition pilot activities into sustained operations; see NSF materials at NSF: NAIRR Pilot. The statute is not intended to supersede agency-specific regulatory authorities (e.g., FDA, FTC) but to provide national research infrastructure and governance for shared resources.

International Alignment

The bill focuses on U.S. domestic infrastructure and U.S.-based users, but seeks interoperability and standards development (via NIST) that facilitate international scientific collaboration. The statute recognizes the need for alignment with global frameworks for trustworthy AI and supports participation in international standards dialogues. While the NAIRR is principally for U.S.-based researchers and organizations, its emphasis on open-source environments, standards-based data repositories, and transparent governance supports cross-border academic collaboration subject to applicable export-control and national-security constraints. See the NAIRR Task Force report for recommendations on global cooperation at NAIRR Task Force Final Report (Jan 2023).

Implementation Timeline

MilestoneTarget or Example Date
NAIRR Task Force Final Report2023-01-24
NSF NAIRR Pilot launch (pilot operational activities)2024-01-24 (pilot launch announcements in 2024)
H.R. 2385 introduced in House2025-03-26
Program Management Office solicitations (NAIRR-OC)Ongoing (e.g., NSF solicitations 2024–2025)
Operating Entity competitive selectionWithin 12–18 months of enactment (subject to appropriation)
Initial full-scale NAIRR operationsPhased over 1–4 years after enactment (dependent on funding)

Sources and References

SourceType
CREATE AI Act of 2025 (H.R. 2385) — Congress.gov (text)Primary Source
NAIRR Task Force Final Report: Strengthening and Democratizing the U.S. AI Innovation Ecosystem (Jan 2023)Primary Source
NSF: National Artificial Intelligence Research Resource PilotPrimary Source
NSF News: NAIRR Pilot awards first round access (May 6, 2024)Primary Source

Requirements for a company

What an organisation has to do under United States - AI Research Resource (H.R. 2385), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Proposed). These requirements apply once the instrument takes effect and may change before then.

Must do

12
  • Adhere to NAIRR user eligibility rules.Operating Entity and Program Management Office
  • Meet minimum cybersecurity and access control standards.Operating Entity and NAIRR resource providers
  • Implement privacy and research-security controls.Operating Entity and Program Management Office
  • Oversee compliance with privacy law and OMB policy.Head of the Program Management Office
  • Manage provisioning of resources, the public portal, and staff.Operating Entity
  • Develop the solicitation and select the Operating Entity via transparent competition.Program Management Office (NSF)
  • +6 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under United States - AI Research Resource (H.R. 2385), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Operating Entity and Program Management OfficeAdhere to NAIRR user eligibility rules.
Eligibility definitions limit primary access to U.S.-based individuals affiliated with defined entities.
Before granting access to NAIRR resourcesDefinitionsCritical
2Operating Entity and NAIRR resource providersMeet minimum cybersecurity and access control standards.
security baselines consistent with the NIST Cybersecurity Framework.
Before commencing operationsKey Focus AreasCritical
3Operating Entity and Program Management OfficeImplement privacy and research-security controls.
secure and privacy-preserving research pathways—coordinating with NIH, DOE and other agencies for sensitive-data access
Before commencing operationsKey Focus AreasCritical
4Head of the Program Management OfficeOversee compliance with privacy law and OMB policy.
The bill requires that the head of the Program Management Office oversee compliance with privacy law and OMB policy and coordinate with legal counsel
OngoingPenalties, Liability, and AppealsCritical
5Operating EntityManage provisioning of resources, the public portal, and staff.
The Operating Entity manages provisioning, the portal, staff, KPIs, annual public reporting, user training, and testbed connections.
Before commencing operationsImplementation FrameworkCritical
6Program Management Office (NSF)Develop the solicitation and select the Operating Entity via transparent competition.
the Program Management Office (NSF) shall develop the solicitation, select an Operating Entity via transparent competition
Within 18 months of enactmentImplementation FrameworkCritical
7Operating Entity and Program Management OfficeProvide a free tier of access to NAIRR resources.
A fee schedule is permitted, including a free tier funded by appropriations, while allowing cost-based charges for extended resource use.
Before commencing operationsImplementation FrameworkImportant
8Operating EntityPublish annual reports and key performance indicators (KPIs).
The bill mandates annual evaluation of the Operating Entity and public annual reports discussing performance, resource usage, and governance.
AnnuallyMonitoring and EvaluationImportant
9Operating Entity and Program Management OfficeCoordinate with NIST on data repository standards.
NIST coordination to define data repository standards and selecting data repositories by competition
OngoingKey Focus AreasImportant
10Operating Entity and Program Management OfficePublish scientific integrity policies and confidential reporting mechanisms.
Scientific integrity policies and confidential reporting mechanisms for violations must be published on the NAIRR website
Before commencing operationsMonitoring and EvaluationImportant
11Operating Entity and Program Management OfficeIntegrate public and private computational and data resources.
resource federation—integrating public and private computational and data resources and offering cloud, on-premises, and hybrid options
Phased over 4 years after enactmentKey Focus AreasImportant
12Operating EntityProvide educational materials, training, and user support services.
education and workforce development—NAIRR Classroom resources, training and broad outreach to expand participation
Before commencing operationsKey Focus AreasImportant

© Regulations.AI · updated on 13-Jun-2026