On September 3, 2026, Reps. Josh Gottheimer (D-N.J.) and Mike Lawler (R-N.Y.) introduced the Stop Rogue AI Act — a bipartisan bill aimed at securing AI agents after a string of incidents involving agents that took unauthorized actions.
The bill directs NIST to publish, within a year of enactment, national standards for how organizations securely deploy AI agents. Axios and Lawler's office both spell out the same pillars: continuously maintain and verify the actions agents take, evaluate agent security and reliability, and generate tamper-proof logs of those actions.
Organizations would also be expected to keep a continuous, machine-readable inventory of all AI agents on their systems — including who built them. Compliance is voluntary for most companies; federal contractors bidding for new deals would be pushed to meet the NIST standards.
Gottheimer's line to Axios is the board version of a service-desk problem we already see on-site: “AI agents are running loose in our networks, and nobody can see them or verify who built them.”
Whether or not this bill becomes law this session, the operational ask is already the right one. If you can't inventory the agents in your tenant — who owns them, what they can write, what data they touch — you can't govern them. That inventory is usually the first thing we build with a desk team that has already shipped agents faster than the policy deck.