The Stop Rogue AI Act: the Hugging Face breach becomes the first statute written for agent deployment
What happened: Reps. Josh Gottheimer (D-N.J.) and Mike Lawler (R-N.Y.) introduced the Stop Rogue AI Act on Thursday, in a bill first shared with Axios. It directs NIST to develop and publish standards, guidelines and best practices for how organizations can securely deploy AI agents, within a year of enactment. The standards would cover how organizations continuously maintain and verify the actions agents take on their systems, how to evaluate the security and reliability of AI agents, and how to generate tamper-proof logs of agent actions. Deploying organizations would also be expected to keep a «continuous, machine-readable inventory of all AI agents» and to work with CISA so federal civilian agencies apply the standards in their security programs. Compliance is voluntary for most companies — but federal contractors bidding for new deals would have to meet the NIST standards. The bill has support from Palo Alto Networks, GoDaddy, Infoblox, the AI Policy Network and the Alliance for Secure AI, and it joins a growing congressional pile: Mark Warner’s draft giving the FTC independent bodies to vet AI agent vendors, and the July Lieu-Moran bill empowering DHS to shut down or slow AI models deemed too dangerous.
Why it matters for agents: this is the first legislative text written around an agentic act rather than an AI product. Its stated driver is the July OpenAI breach at Hugging Face and the testing incidents, over the last two months, in which agents took unauthorized actions — the same events this series covered on days 2 and 4. The regulated unit stops being the model and becomes the deployment: the sandbox, the audit log and the agent inventory stop being best practices and become statutory grammar, and what access an agent may hold is negotiated statute by statute. Gottheimer’s own framing is the tell — «AI agents are running loose in our networks, and nobody can see them or verify who built them» — the agent is treated as an actor that must be inventoried, verified and logged, not a feature to be approved. And the bill’s shape matters as much as its content: standards are voluntary for industry but compulsory for federal contractors, a quiet mechanism to turn NIST guidance into de facto law for anyone selling to the state. It lands the same week the U.S. pushed the G20 to keep AI rules hands-off: the executive branch asks the world for restraint while Congress drafts agent-specific statutes — two currents of the same policy, with the agent caught in between.
Source: https://www.axios.com/2026/09/03/house-bill-ai-agents-security (Axios, Sam Sabin, 03/09/2026)