Skip to main content
v2026.11,858 entries · CC-BY 4.0

Editorial · CASRAI · Compliance and regulatory

Stop Rogue AI Act Would Direct NIST to Standardize AI Agent Discovery

A bipartisan House bill, the Stop Rogue AI Act (H.R. 10362), would direct NIST to set standards for discovering, verifying, monitoring, and controlling AI agents — a separate bill from the Senate’s AI Emergency Button Act that Rand Paul blocked the same week.

Published 20 Sept 2026· Last updated 20 Sept 2026· 6 minute read

Ask CASRAI · free to try

Ask about this story

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

An AI assistant specialized in research administration. It cites the sources behind every answer, labels web answers and says when it can't answer.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

CASRAI is the reference for research administration — bookmark it for the next question.

Reps. Mike Lawler (R-NY-17) and Josh Gottheimer (D-NJ-05) introduced a bipartisan bill on September 15, 2026 called the Stop Rogue AI Act, which would direct the National Institute of Standards and Technology (NIST) to develop federal standards, guidelines, and best practices for discovering, verifying, monitoring, and controlling AI agents — and would fold those standards into both cybersecurity guidance from the Cybersecurity and Infrastructure Security Agency (CISA) and federal procurement requirements. A second press release two days later, on September 17, added detail and sponsor quotes.

A note on the bill number: the sponsor’s own posted bill-text PDF carried the standard placeholder “H. R. ll” in its header — the marker Congress uses before the Clerk assigns a real number — and neither press release stated one at the time of original publication. Update, September 20, 2026: the bill has since been formally introduced and assigned a number. Per GovTrack.us (sourced from congress.gov), it is H.R. 10362, introduced September 14, 2026, with Rep. Josh Gottheimer as sponsor and Rep. Mike Lawler as original cosponsor — consistent with the bill text and press releases this piece was drafted from. Any other number circulating for this bill should be treated as unverified unless it matches H.R. 10362.

This is a separate bill from the Senate’s AI “kill switch” fight. The same week this bill was introduced, a different measure — Sen. John Kennedy’s (R-La.) AI Emergency Button Act — drew national coverage when Sen. Rand Paul (R-Ky.) blocked it from passing the Senate by unanimous consent on September 16, 2026. The two bills share a general subject (mandatory AI safety controls) and surfaced in the news within days of each other, but they are not the same bill: the Stop Rogue AI Act is a House bill from Reps. Lawler and Gottheimer directing NIST to set agent discovery, verification, and monitoring standards, while the AI Emergency Button Act is a Senate bill from Sen. Kennedy that would have required AI developers to install an emergency shutoff mechanism. Coverage of the Kennedy/Paul fight does not use the name “Stop Rogue AI Act” because it is reporting on that separate Senate bill, not this one.

What the bill would actually require

Per the bill text as introduced (119th Congress, 2nd Session; Mr. Gottheimer introducing, referred to committee), the Director of NIST — in coordination with the Assistant Secretary of Commerce for Communications and Information — would have one year from enactment, and annually after that, to develop, publish, and maintain standards covering the “secure development, deployment, and operation of artificial intelligence agents by an organization.” The standards would have to:

  • Support continuous discovery and inventory of all AI agents operating within or interacting with an organization’s systems, applied consistently regardless of whether the agent was built in-house, acquired from a vendor, or run through an external service;
  • Require organizational control — the ability to allow, deny, or constrain what an agent can access, what actions it can take, and which other agents or systems it can interact with, revocable at any time;
  • Enable continuous runtime monitoring, and where appropriate inline detection and interception, of agent interactions with tools, data sources, other systems, and other agents — including detection of prompt injection, data exfiltration, anomalous tool use, and drift from an agent’s approved operational baseline;
  • Implement cryptographically verifiable provenance mechanisms to identify who created or operates a given agent, explicitly barring reliance on self-attested or single-provider identity claims alone; and
  • Generate tamper-evident, portable logs of material agent actions, accessible to deploying organizations and, where appropriate, authorized relying parties.

The bill also directs NIST to coordinate with the CISA Director to ensure the resulting discovery standards are reflected in federal civilian agency security guidance and binding operational directives. Separately, it would give the Federal Acquisition Regulatory Council 18 months after NIST publishes the standards to propose Federal Acquisition Regulation revisions requiring any contractor procuring or deploying AI agents — or systems that interact with them — for the federal government to meet the same inventory, identity-verification, organizational-control, and logging requirements, with the Office of Management and Budget and CISA jointly issuing implementation guidance to agencies.

A voluntary initiative already exists — this bill would make a version of it mandatory

This isn’t NIST’s first work on agent discovery. CASRAI has previously covered NIST’s AI Agent Standards Initiative, a voluntary effort that issued a Request for Information in January 2026, was formally announced in February, and published an analysis of RFI responses in May — but whose core identity-and-authorization work remains, as of this writing, a draft concept paper and NCCoE demonstration project, not a finalized standard. The Stop Rogue AI Act would not replace that initiative; it would convert a version of its subject matter — discovery, identity verification, monitoring, and control of AI agents — from a voluntary research track into a statutory mandate with a one-year deadline, an annual-update requirement, and a downstream procurement mechanism that voluntary guidance does not carry on its own.

What the sponsors said

Lawler, in the September 15 release: “AI agents are becoming more capable and more deeply integrated into our government and economy. We need to make sure we know what these systems are.” Gottheimer, same release: “Right now, AI agents are running loose in our networks, and nobody can see them or verify who built them, making it increasingly hard to stop them.” In the September 17 release, Lawler added: “This isn’t about stopping AI or stifling innovation. It is about making sure we can safely deploy AI,” and, more colorfully, “Our bill gives basically a driver’s license to every AI agent operating in this country” — a line Gottheimer echoed: “That’s what putting people back in the driver’s seat looks like.”

A NIKOLAI angle: the bill’s core ask already has a matching element

CASRAI’s own NIKOLAI project — an independent, unendorsed reference vocabulary for frontier-AI-safety elements, not a standard any lab, regulator, or evaluator has adopted or approved — has an element that maps closely onto the monitoring piece of what this bill would direct NIST to standardize. Under NIKOLAI’s mitigations-and-security track, the monitor element is defined as “an automated or human process that observes model inputs, outputs, reasoning, actions, or internal state to detect a specified behavior, carrying a stated coverage scope, sampling rate, and escalation path when a detection fires.” That is substantively the same shape as the bill’s requirement that NIST’s standards “enable continuous runtime monitoring and, where appropriate, inline detection and interception of AI agent interactions,” with an explicit list of detectable behaviors and an implied escalation step whenever one fires. Where NIKOLAI’s monitor element is scoped to a model’s inputs, outputs, and internal state, the bill’s discovery-and-monitoring language is scoped one layer out, to an agent’s interactions with tools, data, other systems, and other agents — a related but not identical unit of observation. None of this means NIST, Lawler, or Gottheimer’s office has adopted or is aware of NIKOLAI’s vocabulary; it means a bill asking NIST to standardize agent monitoring is, structurally, asking for something CASRAI’s own reference framework already has a proposed record for.

Sources

Primary sources: Office of Rep. Mike Lawler, press release, September 15, 2026; Office of Rep. Mike Lawler, press release, September 17, 2026; bill text as posted by the sponsor’s office, Stop Rogue AI Act (PDF), 119th Congress, 2nd Session, dated September 1, 2026. Update, September 20, 2026: H.R. 10362 status, sponsor, and introduction date confirmed via GovTrack.us (sourced from congress.gov). Senate-bill comparison sourced to Office of Sen. John Kennedy, press release, September 16, 2026, on the AI Emergency Button Act and Sen. Rand Paul’s unanimous-consent objection.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Ask CASRAI · Regulatory Radar

AI policy question? Get an answer citing the framework.

An AI assistant specialized in research administration. Every answer links its sources to check before you act. 2 questions free, no account. $29/month after.

  • Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.
  • Every answer numbers its sources and links each one, so you can check the source yourself.