What happened
On September 3, 2026, Reps. Josh Gottheimer (D-NJ) and Mike Lawler (R-NY) introduced the Stop Rogue AI Act, directing NIST to develop, within one year of enactment, standards, guidelines and best practices for secure deployment of AI agents — covering continuous verification of agent actions, security/reliability evaluation, and tamper-proof activity logging. Organizations would be encouraged to maintain a continuous, machine-readable inventory of AI agents; standards would be voluntary for most organizations but mandatory for federal contractors bidding on new contracts, coordinated with CISA. The bill was triggered directly by OpenAI's Hugging Face agent breach and other recent rogue-agent incidents, and has received early industry endorsements from Palo Alto Networks, GoDaddy, Infoblox, AI Policy Network and the Alliance for Secure AI.
Why it matters
This is one of several competing congressional proposals (alongside Sen. Warner's FTC-vetting bill and Reps. Lieu/Moran's DHS kill-switch bill) attempting to establish federal baseline standards for agentic AI security, using federal procurement leverage to convert voluntary NIST standards into a de facto market requirement for government contractors.
Action needed
Federal contractors and AI agent vendors should track the bill's progress and begin voluntary alignment with anticipated NIST agent-security standards (agent inventories, tamper-proof logging, continuous verification) ahead of potential contractor mandates.