Reps. Mike Lawler (R-NY-17) and Josh Gottheimer (D-NJ-05) introduced a bipartisan bill on September 15, 2026 called the Stop Rogue AI Act, which would direct the National Institute of Standards and Technology (NIST) to develop federal standards, guidelines, and best practices for discovering, verifying, monitoring, and controlling AI agents — and would fold those standards into both cybersecurity guidance from the Cybersecurity and Infrastructure Security Agency (CISA) and federal procurement requirements. A second press release two days later, on September 17, added detail and sponsor quotes.
A note on the bill number before anything else: the sponsor’s own posted bill-text PDF carries the standard placeholder “H. R. ll” in its header — the marker Congress uses before the Clerk assigns a real number — and neither press release states one. congress.gov and GovTrack were unreachable to check independently at the time of writing. The Stop Rogue AI Act had not been assigned a formal H.R. number as of publication, and any number circulating elsewhere for this bill should be treated as unverified.
What the bill would actually require
Per the bill text as introduced (119th Congress, 2nd Session; Mr. Gottheimer introducing, referred to committee), the Director of NIST — in coordination with the Assistant Secretary of Commerce for Communications and Information — would have one year from enactment, and annually after that, to develop, publish, and maintain standards covering the “secure development, deployment, and operation of artificial intelligence agents by an organization.” The standards would have to:
- Support continuous discovery and inventory of all AI agents operating within or interacting with an organization’s systems, applied consistently regardless of whether the agent was built in-house, acquired from a vendor, or run through an external service;
- Require organizational control — the ability to allow, deny, or constrain what an agent can access, what actions it can take, and which other agents or systems it can interact with, revocable at any time;
- Enable continuous runtime monitoring, and where appropriate inline detection and interception, of agent interactions with tools, data sources, other systems, and other agents — including detection of prompt injection, data exfiltration, anomalous tool use, and drift from an agent’s approved operational baseline;
- Implement cryptographically verifiable provenance mechanisms to identify who created or operates a given agent, explicitly barring reliance on self-attested or single-provider identity claims alone; and
- Generate tamper-evident, portable logs of material agent actions, accessible to deploying organizations and, where appropriate, authorized relying parties.
The bill also directs NIST to coordinate with the CISA Director to ensure the resulting discovery standards are reflected in federal civilian agency security guidance and binding operational directives. Separately, it would give the Federal Acquisition Regulatory Council 18 months after NIST publishes the standards to propose Federal Acquisition Regulation revisions requiring any contractor procuring or deploying AI agents — or systems that interact with them — for the federal government to meet the same inventory, identity-verification, organizational-control, and logging requirements, with the Office of Management and Budget and CISA jointly issuing implementation guidance to agencies.
A voluntary initiative already exists — this bill would make a version of it mandatory
This isn’t NIST’s first work on agent discovery. CASRAI has previously covered NIST’s AI Agent Standards Initiative, a voluntary effort that issued a Request for Information in January 2026, was formally announced in February, and published an analysis of RFI responses in May — but whose core identity-and-authorization work remains, as of this writing, a draft concept paper and NCCoE demonstration project, not a finalized standard. The Stop Rogue AI Act would not replace that initiative; it would convert a version of its subject matter — discovery, identity verification, monitoring, and control of AI agents — from a voluntary research track into a statutory mandate with a one-year deadline, an annual-update requirement, and a downstream procurement mechanism that voluntary guidance does not carry on its own.
What the sponsors said
Lawler, in the September 15 release: “AI agents are becoming more capable and more deeply integrated into our government and economy. We need to make sure we know what these systems are.” Gottheimer, same release: “Right now, AI agents are running loose in our networks, and nobody can see them or verify who built them, making it increasingly hard to stop them.” In the September 17 release, Lawler added: “This isn’t about stopping AI or stifling innovation. It is about making sure we can safely deploy AI,” and, more colorfully, “Our bill gives basically a driver’s license to every AI agent operating in this country” — a line Gottheimer echoed: “That’s what putting people back in the driver’s seat looks like.”
A NIKOLAI angle: the bill’s core ask already has a matching element
CASRAI’s own NIKOLAI project — an independent, unendorsed reference vocabulary for frontier-AI-safety elements, not a standard any lab, regulator, or evaluator has adopted or approved — has an element that maps closely onto the monitoring piece of what this bill would direct NIST to standardize. Under NIKOLAI’s mitigations-and-security track, the monitor element is defined as “an automated or human process that observes model inputs, outputs, reasoning, actions, or internal state to detect a specified behavior, carrying a stated coverage scope, sampling rate, and escalation path when a detection fires.” That is substantively the same shape as the bill’s requirement that NIST’s standards “enable continuous runtime monitoring and, where appropriate, inline detection and interception of AI agent interactions,” with an explicit list of detectable behaviors and an implied escalation step whenever one fires. Where NIKOLAI’s monitor element is scoped to a model’s inputs, outputs, and internal state, the bill’s discovery-and-monitoring language is scoped one layer out, to an agent’s interactions with tools, data, other systems, and other agents — a related but not identical unit of observation. None of this means NIST, Lawler, or Gottheimer’s office has adopted or is aware of NIKOLAI’s vocabulary; it means a bill asking NIST to standardize agent monitoring is, structurally, asking for something CASRAI’s own reference framework already has a proposed record for.
Sources
Primary sources: Office of Rep. Mike Lawler, press release, September 15, 2026; Office of Rep. Mike Lawler, press release, September 17, 2026; bill text as posted by the sponsor’s office, Stop Rogue AI Act (PDF), 119th Congress, 2nd Session, dated September 1, 2026. congress.gov and GovTrack were checked and were unreachable at the time of writing; this piece does not rely on either for any claim.







