VECTOR WIREAI INTELLIGENCE
UTC
Refresh Models Deals Regulatory Sources

Stop Rogue AI Act Directs NIST to Set AI Agent Security Standards

Bipartisan bill from Reps. Gottheimer and Lawler tasks NIST with publishing AI agent security standards, requiring tamper-proof logs and agent inventories.

Reps. Josh Gottheimer (D-N.J.) and Mike Lawler (R-N.Y.) are introducing the Stop Rogue AI Act on Thursday, a bipartisan bill that would direct NIST to develop standards for the secure deployment of AI agents2. The legislation follows OpenAI's Hugging Face breach and what the bill's sponsors describe as a growing number of safety incidents involving rogue agents over the preceding two months.

The bill tasks the Commerce Department's National Institute of Standards and Technology with publishing standards, guidelines, and best practices covering three areas: continuous verification of actions agents take on organizational systems, evaluation of agent security and reliability, and generation of tamper-proof logs of agent actions. NIST would have one year after enactment to produce the standards.

Organizations deploying AI agents would be called on to maintain a "continuous, machine-readable inventory of all AI agents". The bill would also require coordination with the Cybersecurity and Infrastructure Security Agency to ensure federal civilian agencies apply the standards in their security programs.

The standards are voluntary for most organizations, but the bill would push federal contractors bidding for new deals to meet the NIST requirements. Gottheimer said the bill is designed to help companies identify agents running on their networks and know exactly who is behind them.

The legislation has the backing of Palo Alto Networks, GoDaddy, Infoblox, the AI Policy Network, and the Alliance for Secure AI.

The Stop Rogue AI Act enters a field of competing proposals. Sen. Mark Warner has introduced a separate bill directing the Federal Trade Commission to create independent bodies that vet AI agent vendors and assess their security practices. Reps. Ted Lieu and Nathaniel Moran introduced a bill in July 2026 that would give the Department of Homeland Security authority to order top AI firms to shut down or slow AI models deemed too dangerous.

ANALYSIS The Gottheimer-Lawler bill takes a standards-and-inventory approach rather than granting shutdown authority, placing it on a different regulatory track from the Lieu-Moran proposal. The voluntary-for-private, mandatory-for-contractors structure mirrors a familiar federal playbook: using procurement leverage to drive adoption without imposing direct mandates on the broader market.

The bill arrives as AI agent security incidents have drawn attention from both industry and government. Palo Alto Networks, one of the bill's supporters, recently published research through its Unit 42 team documenting a ransomware attack in which frontier AI agents compressed a two-week intrusion timeline to under 10 hours ctx.

ANALYSIS Palo Alto Networks' dual role as both a bill supporter and a publisher of agent-threat research positions the company at the intersection of the policy and technical debates around agent security.