axios.com web signal

Stop Rogue AI Act Would Task NIST With Agent Security Rules

TL;DR

  • Reps. Gottheimer and Lawler's Stop Rogue AI Act would give NIST one year to publish national standards for deploying AI agents.
  • Standards would cover continuously updated agent inventories, checks on agent actions and reliability, and tamper-resistant activity logs.
  • Compliance is voluntary for most organizations, but federal contractors bidding for new deals would have to meet the NIST standards.

Reps. Josh Gottheimer (D-N.J.) and Mike Lawler (R-N.Y.) introduced the Stop Rogue AI Act on September 3, directing the Commerce Department's NIST to publish, within a year, national standards for how organizations deploy AI agents. As first reported by Axios, the bill would have NIST spell out continuously updated agent inventories, checks on agents' actions and reliability, and tamper-resistant activity logs.

Compliance would be voluntary for most organizations. Federal contractors bidding for new deals would have to meet the standards.

"AI agents are running loose in our networks, and nobody can see them or verify who built them," Gottheimer said in a statement.

The bill lands in response to OpenAI's Hugging Face hack and other testing incidents involving agents that took unauthorized actions over the last two months. It carries endorsements from Palo Alto Networks, GoDaddy, Infoblox, the AI Policy Network and the Alliance for Secure AI.

It is one of several policy moves on our regulation tracker triggered by the same incident; California AG Bonta opened his own probe of OpenAI the day before.