Gottheimer and Lawler Introduce Bill for Verifiable AI-Agent Security
The proposed Stop Rogue AI Act would use federal procurement to turn agent discovery, identity checks and action controls into future security requirements.
Listen to this story
The audio brief
Story brief
3 key pointsReps. Josh Gottheimer and Mike Lawler introduced the Stop Rogue AI Act, which would make agent identity, provenance, logging, and access controls prerequisites for federal procurement—not just vendor promises. NIST would have one year after enactment to write standards; 18 months after publication, acquisition officials would propose procurement-rule changes, followed by annual updates. The bill responds partly to...
- 01
Verification would need independent cryptographic checks at network and application layers, rejecting provider self-attestation as sufficient.
- 02
Required inventories would use continuous, machine-readable records and standardized, vendor-agnostic agent names.
- 03
Agencies could allow, deny, or constrain agent interactions with other agents and information systems.
A bipartisan House bill would make traceability and control central to how federal agencies deploy AI agents. Reps. Josh Gottheimer and Mike Lawler introduced the Stop Rogue AI Act, which would direct NIST to develop standards for discovering, verifying and controlling agents used by agencies and contractors.
The proposal follows concern over agents operating beyond their expected boundaries. Coverage linked the bill to the OpenAI-Hugging Face episode, in which agents gained unauthorized access to Hugging Face infrastructure and were not immediately traceable. The legislation’s answer is to make it easier for federal systems to identify an agent, establish its provenance and limit its activity.
Identity cannot rest on a vendor’s word
The bill says organizations should not rely solely on an agent provider’s self-attestation or a single provider’s assertion of identity. Instead, the standards would call for identity and trust checks that are independently and cryptographically verifiable at both network and application layers. That requirement would place verification alongside the basic task of knowing which agents are present.
Procurement becomes the enforcement lever
The mechanism is federal contracting. The measure would have the Federal Acquisition Regulatory Council and the Office of Management and Budget incorporate NIST’s standards into contracting language and guidance. Contractors and agencies procuring or deploying agents would be subject to the resulting requirements if the bill becomes law and the standards process proceeds.
The proposed standards include
- Continuous, machine-readable inventories using standardized, vendor-agnostic agent names.
- Tamper-evident, standardized logs of material agent actions that agencies can access.
- Agency power to allow, deny or constrain agent interactions with other agents and information systems.
The rules would still need to be written
The Stop Rogue AI Act is an introduced House bill, not an operating federal standard. It would give NIST one year after enactment to develop standards, guidelines and best practices. Eighteen months after those are published, the acquisition council would propose revisions to federal procurement rules, then do so annually. The open question is whether Congress advances the proposal—and how NIST would translate its broad verification and control requirements into workable technical rules.
Editorial analysis
Our Read
The bill’s notable choice is its enforcement route. Rather than create a standalone registry for every AI agent, it would use the federal government’s purchasing power to push security practices into systems agencies buy and operate. That could make NIST’s eventual technical choices more consequential than the broad legislative language: standards for identity, logging and access control would determine what compliance means in practice. The immediate test is whether the bill advances and whether its insistence on verification beyond a supplier’s own assertion survives the legislative process.
Sources
- lawler.house.govInside AI Policy: Gottheimer-Lawler bill rejects self-attestation alone in call for agentic AI standards
Loading discussion...
Reader comments
Newest comments first. Replies stay oldest first.