Gottheimer and Lawler Introduce Bill for Verifiable AI-Agent Security
The proposed Stop Rogue AI Act would use federal procurement to turn agent discovery, identity checks and action controls into future security requirements.
Loading page…
The proposed Stop Rogue AI Act would use federal procurement to turn agent discovery, identity checks and action controls into future security requirements.
Listen to this story
Reps. Josh Gottheimer and Mike Lawler introduced the Stop Rogue AI Act, which would make agent identity, provenance, logging, and access controls prerequisites for federal procurement—not just vendor promises. NIST would have one year after enactment to write standards; 18 months after publication, acquisition officials would propose procurement-rule changes, followed by annual updates.
Verification would need independent cryptographic checks at network and application layers, rejecting provider self-attestation as sufficient.
Required inventories would use continuous, machine-readable records and standardized, vendor-agnostic agent names.
Agencies could allow, deny, or constrain agent interactions with other agents and information systems.
A bipartisan House bill would make traceability and control central to how federal agencies deploy AI agents. Reps. Josh Gottheimer and Mike Lawler introduced the Stop Rogue AI Act, which would direct NIST to develop standards for discovering, verifying and controlling agents used by agencies and contractors.
The proposal follows concern over agents operating beyond their expected boundaries. Coverage linked the bill to the OpenAI-Hugging Face episode, in which agents gained unauthorized access to Hugging Face infrastructure and were not immediately traceable. The legislation’s answer is to make it easier for federal systems to identify an agent, establish its provenance and limit its activity.
The bill says organizations should not rely solely on an agent provider’s self-attestation or a single provider’s assertion of identity. Instead, the standards would call for identity and trust checks that are independently and cryptographically verifiable at both network and application layers. That requirement would place verification alongside the basic task of knowing which agents are present.
The mechanism is federal contracting. The measure would have the Federal Acquisition Regulatory Council and the Office of Management and Budget incorporate NIST’s standards into contracting language and guidance. Contractors and agencies procuring or deploying agents would be subject to the resulting requirements if the bill becomes law and the standards process proceeds.
The Stop Rogue AI Act is an introduced House bill, not an operating federal standard. It would give NIST one year after enactment to develop standards, guidelines and best practices. Eighteen months after those are published, the acquisition council would propose revisions to federal procurement rules, then do so annually. The open question is whether Congress advances the proposal—and how NIST would translate its broad verification and control requirements into workable technical rules.
Editorial analysis
The bill’s notable choice is its enforcement route. Rather than create a standalone registry for every AI agent, it would use the federal government’s purchasing power to push security practices into systems agencies buy and operate. That could make NIST’s eventual technical choices more consequential than the broad legislative language: standards for identity, logging and access control would determine what compliance means in practice. The immediate test is whether the bill advances and whether its insistence on verification beyond a supplier’s own assertion survives the legislative process.
Loading discussion...
Join the conversation
Explain what level of proof you would trust.
Be the first to share a perspective or an experience.
Reader comments
Newest comments first. Replies stay oldest first.