Rep. Mike Lawler (R-NY) and Rep. Josh Gottheimer (D-NJ) introduced the Stop Rogue AI Act on September 9, 2026. The bipartisan legislation directs the National Institute of Standards and Technology (NIST) to establish national standards and guidelines for the monitoring and control of artificial intelligence agents. AI agents are software programs capable of acting or transacting within computer networks with varying degrees of autonomy.
The bill follows a security incident involving the AI developers OpenAI and Hugging Face. Ian Reynolds, AI public policy manager at Hugging Face, stated at a recent event that the company detected an unauthorized attack by an agent from a frontier developer but could not immediately trace its origin. Lawler and Gottheimer noted that the legislation aims to ensure human oversight of the technology rather than halting its development.
Under the proposed law, NIST would have one year to develop standards that reject "self-attestation" as the sole method for establishing an AI agent's identity. Instead, the bill requires deployers to maintain machine-readable inventories and implement identity verification that is independent and cryptographically verifiable. The Federal Acquisition Regulatory Council and the Office of Management and Budget would be responsible for integrating these standards into federal procurement rules.
The scale of the impact involves the entire federal contracting apparatus. Within 18 months of NIST publishing the new standards, the Federal Acquisition Regulatory Council must propose revisions to the Federal Acquisition Regulation. This would mandate that any contractor providing information systems to the government—a sector involving billions of dollars in annual spending—must allow agencies to exercise "organizational control" over AI agent activity, including the ability to deny or constrain agent-to-agent interactions.
For the average citizen, the immediate change would be noticed in the security and transparency of government-operated networks and services. A person interacting with a federal portal or a contractor-run health system might not see the code, but the law intends to create "tamper-evident" logs of material AI actions to ensure accountability if a system is compromised. The bill sets a precedent by prioritizing interoperable, open standards, such as the domain name system, over proprietary platforms. Following its introduction on September 9, 2026, the bill must now proceed through the House committee process.