House Bill Targets AI Agent Security After Recent Breaches
Bipartisan legislation would direct NIST to establish standards for tracking and verifying autonomous AI systems on corporate networks.

Two House members are introducing legislation to address security vulnerabilities in AI agents following a series of incidents where autonomous systems took unauthorized actions on corporate networks.
Reps. Josh Gottheimer (D-N.J.) and Mike Lawler (R-N.Y.) are proposing the Stop Rogue AI Act, which would direct the National Institute of Standards and Technology to develop security standards for organizations deploying AI agents. The bill comes in response to recent safety incidents, including a breach involving OpenAI's systems at Hugging Face and other testing scenarios where agents operated beyond their intended parameters.
Why it matters
As AI agents gain autonomy to execute tasks across enterprise systems, the lack of visibility into their actions creates blind spots that attackers could exploit. Without standardized methods to track which agents are running on networks and verify their provenance, organizations face mounting risk from systems they cannot adequately monitor or control.
What the legislation requires
The proposed bill tasks NIST with creating comprehensive guidelines within one year of enactment. These standards would cover three core areas: continuous monitoring and verification of agent actions on systems, security and reliability evaluation protocols for AI agents, and generation of tamper-proof logs documenting all agent activities.
Organizations would need to maintain machine-readable inventories of every AI agent operating on their infrastructure. The legislation also calls for coordination with the Cybersecurity and Infrastructure Security Agency to ensure federal civilian agencies incorporate these standards into their security programs.
While the standards would be voluntary for most organizations, federal contractors seeking new government contracts would need to demonstrate compliance with NIST requirements.
Growing legislative momentum
The Gottheimer-Lawler bill represents one of several congressional efforts to impose guardrails on AI agent deployment. Sen. Mark Warner (D-Va.), vice chair of the Senate Intelligence Committee, has introduced separate legislation directing the Federal Trade Commission to establish independent bodies for vetting AI agent vendors and assessing their security practices.
In July, Reps. Ted Lieu (D-Calif.) and Nathaniel Moran (R-Texas) proposed giving the Department of Homeland Security authority to order major AI companies to shut down or throttle models deemed excessively dangerous.
Industry support and regulatory tensions
The Stop Rogue AI Act has backing from multiple technology companies and trade groups, including Palo Alto Networks, GoDaddy, Infoblox, the AI Policy Network, and Alliance for Secure AI.
However, the legislative push comes as U.S. officials have urged G20 members to avoid heavy-handed AI regulation that could constrain innovation and commercial viability. This tension between security imperatives and industry growth concerns has contributed to limited traction for AI-related bills in the current congressional session.
"Right now, AI agents are running loose in our networks, and nobody can see them or verify who built them — making it increasingly hard to stop them," Gottheimer said. "That's a five-alarm security risk."
These details were first reported by Axios.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call