Compliance2026-09-209 min read

The First Federal Bill on Agent Security Tells You What Good Will Be Measured Against

H.R. 10362, the Stop Rogue AI Act, was introduced on 14 September 2026 and is the first federal bill to direct NIST to write specific technical standards for AI agent discovery and security, with a mandatory path that runs only through federal procurement. The enforcement path runs years into the future and the bill has not passed. The requirements it spells out, continuous machine-readable agent inventory, cryptographically verifiable provenance, tamper-evident portable logs, and an explicit refusal to accept self-attested agent identity, are a published specification you can build against now.

Representative Josh Gottheimer, for himself and Representative Mike Lawler, introduced H.R. 10362 in the House of Representatives on 14 September 2026. The short title is the Stop Rogue AI Act, the stated purpose is to provide for certain artificial intelligence agent discovery and security standards, and it was referred to the Committee on Science, Space, and Technology and in addition to the Committee on Oversight and Government Reform. It carries endorsements from Palo Alto Networks, GoDaddy, Infoblox, the AI Policy Network and the Alliance for Secure AI. What makes it worth reading is not the politics but the drafting. This is the first federal bill to direct an agency to write specific technical standards for AI agents, and the text is unusually concrete about what those standards would have to contain.

The timing is close enough to be worth stating carefully, because it is a coincidence rather than a cause. We wrote two days ago about NIST Interagency Report 8587, finalised on 15 September, which hardens identity tokens and assertions and then records that AI and AI agents create additional identity and access management challenges requiring further guidelines and, in some cases, new or expanded standards and protocols. This bill was introduced the day before that report was finalised, so neither document is a response to the other. They are two halves of the same admission arriving in the same week. One says the standard does not exist yet. The other is an instruction to write it, with a one year clock attached to enactment.

The substance sits in section 2(a)(1), which lists eight things the standards would have to do. Maintain the capability to continuously discover, inventory, verify and maintain organizational control over all AI agents operating within or interacting with your systems, networks, applications, services or digital environments. Integrate that discovery into broader cybersecurity and risk management, consistent with defense-in-depth. Apply the same discovery and verification controls whether an agent was built internally, bought from a third party vendor, or reached through an external service. Evaluate security, safety, correctness and reliability before deployment and continuously afterwards. Enable runtime monitoring and, where appropriate, inline detection and interception of agent interactions with tools, data sources, systems and other agents, explicitly including prompt injection, data exfiltration, anomalous tool invocation, and behavioral drift from an approved operational baseline. Implement cryptographically verifiable provenance sufficient to identify the entity responsible for creating or operating an agent. And generate and retain tamper-evident, standardized logs of material agent actions, portable and accessible to deploying organizations and authorized relying parties.

Paragraph (4), headed minimum organizational requirements, is the part that should stop anyone who has been buying agent governance on the strength of vendor documentation. Organizations deploying agents must maintain a continuous, machine-readable inventory of all AI agents using standardized, vendor-agnostic naming conventions. They must implement agent identity and trust verification that is independent and cryptographically verifiable at both the network and the application layers. And they must not rely solely on self-attested or single-provider assertions for establishing agent identity. That last clause is a direct strike at the trust model almost every agent platform runs on today. It is the same failure we covered when the OWASP agentic skills work showed declared behaviour and actual behaviour coming apart, and the same one behind the malicious skills found carrying backdoors in public registries. A declaration is not an identity, and this bill is the first federal text to say so in operative language. Paragraph (3) goes further and asks for open, vendor-agnostic, interoperable discovery built on existing internet infrastructure, including domain name system based approaches and cryptographically verifiable agent identity and registry frameworks, explicitly not dependent on proprietary or platform-specific registries.

Now the cold water, because the headlines have been loose about this. Nothing here binds anyone yet, and the enforcement path is long even if everything goes smoothly. NIST would publish not later than one year after enactment, and annually thereafter. The Federal Acquisition Regulatory Council would then have up to 18 months after that publication to propose revisions to the Federal Acquisition Regulation, and proposing is not issuing. The Office of Management and Budget, coordinating with CISA, would issue agency guidance not later than 180 days after those revisions are proposed. There is also a saving provision excluding contracts entered into before enactment. Add those together and a bill that passed tomorrow would reach federal contracts around 2029. For most organizations the standards would be voluntary regardless, with the sharp edge landing on contractors bidding for new federal work. Treating this as a compliance deadline would be a mistake. Treating it as a published specification of what auditors, customers and procurement teams will be asking for in two years is the correct read, and that is the version worth acting on.

Two definitions in subsection (c) do more work than the operative text and are worth lifting verbatim into your own policies. An AI agent is defined as a software-based system that uses an AI model to perceive, plan or make decisions, that autonomously interacts with other software systems, digital services, users, external environments or other agents on behalf of a person or organization, and that involves minimal or no human interaction beyond its initial direction. That is a scoping test you can apply to your estate this afternoon, and it catches a great deal of tooling that nobody has been calling an agent. Organizational control is defined as the technical and organizational ability to allow, deny or restrict agent access to specific data, the actions an agent can perform, and the tools, systems and other agents it can interact with, plus the ability to revoke or change any of those at any time. That is a kill switch written into a definitions section, and the phrase at any time rules out a control that only takes effect at the next token refresh.

The framework mapping is easier than usual because nearly all of this already has a home. ISO 27001 carries the asset inventory, identity and access management, logging and monitoring, and supplier relationship families, and the honest question for most statements of applicability is not whether the control exists but whether anyone extended it to a non human identity that was onboarded by a product team. ISO 42001 is where the operational baseline and the lifecycle evaluation belong, because a management system for AI is supposed to define the boundary a system runs inside and reassess it when behaviour changes, and behavioral drift from an approved baseline is precisely that artefact. SOC 2 asks the period question, which is the hard one here: not whether an inventory existed on the day of the walkthrough, but whether it stayed continuous and accurate across twelve months while engineers added agents. PCI DSS enters the moment any of these agents can reach cardholder data, since an unenumerated autonomous process in scope is a finding on its own. The EU AI Act angle is Article 12, where automatically generated logs are a legal duty for high risk systems, and tamper-evident portable logs of material actions is a notably better answer to that duty than whatever your platform writes by default. Vanta, Drata, Secureframe, Sprinto, Thoropass and Hyperproof will all hold the policy and collect evidence that you have one, and not one of them will discover an undeclared agent running in your environment, so discovery is a control you build and then evidence rather than one you buy.

The work that survives whatever happens to this bill is short and none of it is speculative. Build the inventory first, because every other requirement in the text depends on it and you cannot verify, monitor or revoke something you have not enumerated. Give every agent its own identity rather than a shared service account, and record who built it, who operates it and which business owner accepts the risk, since provenance is the requirement most likely to be unanswerable today. Make your logs tamper-evident and portable, and check that they attribute an action to one specific agent rather than to a gateway. Test revocation rather than documenting it, on the understanding that an untested kill switch is a diagram. And stop accepting self-attestation as identity, which mostly means asking vendors how an agent proves what it is at the network and application layers, and writing down the answer when there is not one. The ISO 27001 and ISO 42001 guides on this site cover the inventory, identity, logging and lifecycle control families this belongs in, the compliance readiness assessment will show you which of them you can currently evidence, and the policy templates library has the asset management, access control, acceptable use and AI governance clauses to hang it on.

Stop Rogue AI ActH.R. 10362NISTCISAAI agentsagent inventoryfederal procurementFARISO 27001ISO 42001SOC 2provenance

Editorial note: AES Tech reviews are independent. Some outbound links are affiliate links and are marked sponsored; they never change our rankings. See our disclosure.

// Signal, not noise

Get the next post by email

One short email when something worth knowing ships. No spam, unsubscribe anytime.

Loading comments...

Add a comment

Corrections and first-hand experience are the most useful things you can leave. Comments are screened automatically and reviewed by a human; see the moderation policy.

0/4000 · plain text · links are held for review

More from the blog