RELEASE: Gottheimer Introduces Bipartisan Bill to Stop Rogue AI Agents and Keep People in Control

Sets Federal Standards for AI Agents and Protect Networks

Sep 09, 2026
Press

WASHINGTON, D.C. — Today, Wednesday, September 9, 2026, U.S. Congressman Josh Gottheimer (NJ-5) and Congressman Mike Lawler (NY-17) introduced the bipartisan Stop Rogue AI Act to ensure businesses and federal agencies have the ability to see rogue and dangerous AI agents operating inside their own networks, and stop them before they cause real damage.

Right now, most organizations have no reliable way to know how many unauthorized AI agents are running in their systems, who built them, or what they have access to. AI agents can be activated by employees, embedded in third-party software, or deployed by vendors — often with little to no visibility for the organization whose networks they’re operating on to know that they are there. That blind spot is becoming more dangerous by the day. The recent Hugging Face incident and other autonomous cyberattacks have shown AI systems are being used to hack organizations at scale, without a person ever watching or stepping in.

“Right now, AI agents are running loose in our networks, and nobody can see them or verify who built them — making it increasingly hard to stop them,” said Congressman Josh Gottheimer (NJ-5). “That’s a five-alarm security risk. We’ve already seen AI systems hack organizations on autopilot, with no person at the wheel. My bipartisan bill with Congressman Lawler puts humans back in the driver’s seat so we can find agents and know exactly who’s behind them so that organizations can effectively protect their systems.”

“AI agents are becoming more capable and more deeply integrated into our government and economy. We need to make sure we know what these systems are, what they can access, and who is responsible for them. We can harness the benefits of AI while making sure these systems don’t operate in the shadows of the networks they have access to,” said Congressman Mike Lawler (NY-17).

The Stop Rogue AI Act would direct the National Institute of Standards and Technology (NIST), to develop national standards, guidelines, and best practices for discovering, verifying, and controlling AI agents. 

Under the bill, those standards will provide guidance to organizations on how to:

  • Find and track every AI agent operating on their systems, in a continuous, easily readable inventory;
  • Verify who built and operates each agent, using verifiable identity and provenance — not just a vendor’s word;
  • Monitor agents in real time, including detecting prompt injection, data theft, and agents behaving outside their approved limits; and
  • Allow, deny, or revoke an agent’s access, actions, and interactions at any time – so people have the final say over what it can access or do. 

The bill also requires federal contractors and agencies to build these safeguards into how they buy and deploy AI agents, and directs NIST and the Cybersecurity and Infrastructure Security Agency (CISA) to fold the standards into existing federal cybersecurity guidance.

The bipartisan legislation has already earned support from a broad coalition spanning network security, internet infrastructure, and AI governance, including:

  • Palo Alto Networks
  • GoDaddy
  • Infoblox
  • AI Policy Network
  • Alliance for Secure AI

“As AI agents become more capable of acting and transacting on our behalf, identity and accountability are foundational. We need open, interoperable standards that make it possible to know which agent is acting, who stands behind it, and whether its credentials are valid. Representatives Gottheimer and Lawler’s bipartisan effort is an important step toward establishing those standards and putting them to work through federal adoption. GoDaddy is pleased to support an approach that can strengthen security while keeping the agentic web open to businesses and innovators of every size,” said Jared Sine, Chief Strategy & Legal Officer, GoDaddy.

“Securing AI agents starts with knowing they exist and being able to trust who they are. This bill rightly treats agent discovery as foundational cybersecurity, giving agencies the ability to continuously find, verify, and control the AI agents interacting with their systems. We’re especially encouraged that this legislation promotes open, vendor-agnostic, and interoperable discovery standards built on existing internet infrastructure like the domain name system, rather than locking agencies into proprietary platforms. That approach is scalable, resilient, and the right foundation for agent security. Reps. Gottheimer and Lawler are doing commendable work, and we look forward to supporting the bill’s advancement,” said Wei Chen, Chief Legal Officer and EVP, Regulatory Strategy, Infoblox

“As AI agents rapidly scale across government and enterprise systems, security and governance must evolve to address the novel risks of agentic decision-making. Palo Alto Networks applauds Representatives Josh Gottheimer and Mike Lawler for their bipartisan leadership in introducing the AI Agent Standardization and Security Act. This legislation provides a strong foundation for organizations to safely adopt agentic AI while maintaining continuous visibility, runtime monitoring, identity verification and control,” said Daniel Kroese, Vice President, Public Policy and Government Affairs, Palo Alto Networks

The Stop Rogue AI Act builds on Gottheimer’s work as Co-Chair of the House AI Commission  and his bipartisan track record on AI safety and consumer protections. It comes as Congress and federal regulators face growing pressure to keep pace with the rapid development and deployment of autonomous AI systems.

###

Recent Posts


Sep 9, 2026
Press


Sep 9, 2026
Press


Sep 8, 2026
Press