As artificial intelligence systems move deeper into critical infrastructure, healthcare, national security and everyday consumer products, a new front is opening in the fight over how these technologies are governed: protecting the people on the inside who see the problems first. A bipartisan proposal in Congress, the AI Whistleblower Protection Act (AIWPA), aims to answer a deceptively simple question with far-reaching implications for the tech industry: who can safely speak up when AI systems appear to put the public at risk? The National Whistleblower Center (NWC) has put its weight behind the bill, arguing that workers who identify serious problems with AI should be able to report those concerns without sacrificing their careers, financial security or legal rights.
Introduced in the Senate by Chuck Grassley and in the House by Jay Obernolte, the AIWPA would create dedicated federal whistleblower protections for individuals who report AI-related security vulnerabilities, violations of federal law, or substantial and specific dangers to public health, public safety or national security. Both versions of the bill remain pending, but supporters have already framed it as a missing piece of an emerging AI governance framework that otherwise focuses on technical standards, risk management and sector-specific rules. Where many existing whistleblower statutes are tied to particular industries or well-defined forms of misconduct, this legislation is explicitly designed for a world where the most serious AI risks may appear before lawmakers have had the chance to declare them illegal.
Grassley underscored that logic when he introduced the bill, arguing that transparency is a prerequisite for accountability in a fast-moving domain like AI. The AIWPA is structured to give people working on or around AI systems a protected avenue to raise alarms about serious concerns before a preventable problem escalates into a catastrophe. Backers say that too many people in AI today feel they cannot speak up when they see something wrong, either because existing statutes do not clearly apply to their work or because employment agreements and internal cultures discourage contacting regulators or Congress.
At the core of the proposal is a pair of definitions that carve out what kinds of disclosures would be covered. An AI security vulnerability is described as a security failure or lapse that could allow emerging AI technology to be stolen or otherwise acquired, including by foreign entities. An AI violation covers violations of federal law tied to the development, deployment or use of AI, but it also extends to failures to properly respond to a substantial and specific danger that AI may pose to public safety, public health or national security. That second category marks an important shift: instead of limiting protection to those who expose conduct that is already illegal, the bill recognizes that emerging technologies can create serious, concrete risks in advance of detailed legal prohibitions.
The scope of who could blow the whistle is also intentionally broad. The AIWPA would protect current and former employees as well as independent contractors who make qualifying disclosures about AI-related risks, a recognition that critical information may sit with people across the AI lifecycle rather than just full-time staff. Covered individuals would be able to report concerns to federal regulatory officials, the Attorney General, law enforcement or regulatory agencies, members of Congress or congressional committees, and in certain cases to supervisors or other officials inside their own organizations who have authority to investigate or address the issues. The bill also extends protection to those who participate in investigations or judicial and administrative proceedings that stem from their disclosures, ensuring they are not punished for cooperating once a case begins.
Strong anti-retaliation language is central to the AIWPA, reflecting longstanding lessons from other sectors where whistleblowers have faced firing, demotion or blacklisting. Under the proposal, employers would be barred from discharging, demoting, suspending, threatening, harassing, blacklisting or otherwise discriminating against covered individuals because of protected whistleblowing activity. The bill also goes after another deterrent that has become common in the tech industry: restrictive employment agreements. It would prevent AI whistleblower rights from being waived in such agreements and would limit the use of mandatory arbitration to keep whistleblower claims out of court, a practice that can bury systemic problems behind closed doors. NWC has warned that nondisclosure and severance clauses can discourage current and former AI workers from bringing serious concerns to the government.
Why this matters
For AI developers and deployers, the AIWPA is not just another compliance requirement; it is a structural change in how internal dissent and risk reporting could operate across the industry. By explicitly covering security vulnerabilities and dangers that are not yet codified in law, the bill treats frontline engineers, researchers and product staff as an early-warning system for regulators and lawmakers. That could surface information about misaligned models, unsafe deployment practices or inadequate safeguards long before those issues show up in public incidents, pushing companies to build more robust internal channels and cultures where raising hard questions is expected rather than punished. At the same time, the act signals that AI governance will not rely solely on corporate self-regulation or high-level guidelines, but on the protected voices of insiders who are often the only ones able to see how powerful systems behave behind the scenes.
Looking ahead, the fate of the AIWPA will help determine whether worker-led oversight becomes a pillar of AI regulation or remains an underdeveloped idea as AI capabilities expand. If the bill advances, companies that build and deploy AI will need to revisit their contracts, reporting pathways and treatment of employees who challenge high-stakes systems, particularly in areas touching national security and public safety. If it stalls, pressure is likely to grow for other legal or policy routes to protect AI whistleblowers, as NWC and other advocates continue to argue that insiders are often the first to recognize when something has gone wrong. Either way, the debate around the AI Whistleblower Protection Act is a signal that AI regulation is shifting from abstract principles to concrete questions about who is empowered to speak up when the technology goes off course.