Two Lawmakers, One Bill, a Narrow Target

Rep. Josh Gottheimer, a Democrat from New Jersey, and Rep. Mike Lawler, a Republican from New York, introduced the Stop Rogue AI Act in the US House on September 3, 2026. The bipartisan pairing points to a narrow technical fix rather than a broader fight over AI regulation. Gottheimer's office put the concern in blunt terms: "AI agents are running loose in our networks, and nobody can see them or verify who built them."

The bill arrives three days after an agent-security incident reported earlier this month put that visibility gap on public display. Its sponsors did not wait for a full accounting of that episode before drafting a response; they moved straight to the mechanism they say was missing, a way to know which agents are operating and what they are doing.

What NIST Would Actually Have to Build

The Stop Rogue AI Act directs the National Institute of Standards and Technology to write standards for secure agentic AI deployment, giving it one year after enactment to produce them. Three requirements anchor the mandate: continuous verification of what an agent actually does, tamper-proof logs of agent actions, and a machine-readable inventory of all AI agents operating within an organization.

NIST is instructed to coordinate that work with the Cybersecurity and Infrastructure Security Agency, tying the new standards to the government's existing cyber-defense apparatus rather than standing up a separate AI office. The inventory requirement carries the most weight of the three, since it treats an AI agent as a distinct, trackable object rather than folding it into whatever model or software product happened to spawn it.

Mandatory for Some, Optional for Everyone Else

The standards NIST writes become mandatory only for federal contractors; every other organization deploying AI agents can adopt them voluntarily. That split keeps the bill's near-term reach limited to companies doing business with the government, while betting that a NIST-authored standard spreads through the wider market the way earlier NIST cybersecurity frameworks have.

The bill already carries industry backing: Palo Alto Networks, GoDaddy, Infoblox, the AI Policy Network, and the Alliance for Secure AI have all supported it, according to Gottheimer's office. That lineup leans toward security and infrastructure vendors rather than the large AI labs building the agents themselves, a detail that hints at who sees a defensive or competitive advantage in a formal inventory requirement.

Agents, Not Models: A Different Regulatory Object

Every major AI governance framework written so far, including the EU AI Act, regulates the model: its capabilities, its training data, its risk classification. The Stop Rogue AI Act regulates something else, the agent, an instance of software acting autonomously on a network, sometimes built on top of a model without that model's own developer knowing it exists. That is a meaningfully different governance object, and it is the first US bill to propose an inventory-and-provenance requirement written specifically for it.

A machine-readable inventory and a tamper-proof action log do not ask what an AI system can do in the abstract; they ask which specific agents exist right now, who deployed them, and what they have actually done. That is provenance-first regulation rather than capability-first regulation, and nothing in the EU's current AI Act text mandates an equivalent agent-specific inventory.

What This Previews for European Regulators

The EU is still working through its own AI Act deadlines, with general-purpose AI model obligations and broader compliance dates continuing to phase in through 2026. None of those provisions currently require the kind of standing, machine-readable agent inventory the Stop Rogue AI Act would create, because the AI Act was built around models and risk tiers, not around autonomous agents as their own category.

That gap leaves European regulators with two ways to read this bill. One reading treats it as a template, a workable, industry-backed pattern for agent oversight the EU could fold into a future AI Act amendment or a dedicated agent-specific instrument, arriving with a year's head start on implementation experience once NIST finishes its standards. The other reading treats it as a warning, a voluntary-outside-government regime that could still harden into a de facto market requirement if enough vendors adopt it to sell into the US federal market, creating a second inventory standard European operators would need to track alongside their own AI Act obligations. Which reading holds depends on what NIST's standards look like in a year, not on anything the bill's text settles today.

Servola Journal

We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.

Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.

If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.