<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="HF1DC7CBD392147C08C23E81FE8A29F34" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>119 HR 10362 IH: Stop Rogue AI Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2026-09-14</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">119th CONGRESS</congress><session display="yes">2d Session</session><legis-num display="yes">H. R. 10362</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20260914">September 14, 2026</action-date><action-desc><sponsor name-id="G000583">Mr. Gottheimer</sponsor> (for himself and <cosponsor name-id="L000599">Mr. Lawler</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HSY00">Committee on Science, Space, and Technology</committee-name>, and in addition to the Committee on <committee-name committee-id="HGO00">Oversight and Government Reform</committee-name>, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned</action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To provide for certain artificial intelligence agent discovery and security standards, and for other purposes.</official-title></form><legis-body id="H9A111473E3CC4EED8D705424A7535589" style="OLC"> 
<section id="HED91E920E43A47E889021AA4BF5DC520" section-type="section-one"><enum>1.</enum><header>Short title</header>
 <text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Stop Rogue AI Act</short-title></quote>.</text></section> 
<section id="H3766C46737944A079D209A5E2B8AA71D"><enum>2.</enum><header>AI agent discovery and security standards</header> 
<subsection id="HF59B6598A04F4128B36F74AF836FCD7A"><enum>(a)</enum><header>AI agent discovery and security standards</header> 
<paragraph id="H74DBAACBE682485F825D280C3B997FA8" commented="no"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than 1 year after the date of the enactment of this Act and annually thereafter, the Director of the National Institute of Standards and Technology (in this section referred to as the <quote>Director</quote>), in coordination with the Assistant Secretary of Commerce for Communications and Information (in this section referred to as the <quote>Assistant Secretary</quote>), shall develop, publish, and maintain standards, guidelines, and best practices for the secure development, deployment, and operation of artificial intelligence agents by an organization. Such standards, guidelines, and best practices shall—</text> <subparagraph id="H14A3E61964114BB0BE6FA882243B1434" commented="no"><enum>(A)</enum><text>maintain the capability to continuously discover, inventory, verify, and maintain organizational control over all AI agents operating within or interacting with the information systems, networks, applications, services, or digital environments of such organizations;</text></subparagraph> 
<subparagraph id="HFCE528A1B94547269BD925E885ADBCE6"><enum>(B)</enum><text display-inline="yes-display-inline">maintain organizational control over AI agents deployed by such organization;</text> </subparagraph> <subparagraph id="HD67516F751DC4DDFBB7B89DE53CFAAB4"><enum>(C)</enum><text>integrate discovery mechanisms into broader cybersecurity and risk management processes, consistent with defense-in-depth;</text></subparagraph> 
<subparagraph id="HFC18A64C285E4E7D94912C925305DF1B"><enum>(D)</enum><text>apply discovery and verification controls consistently across AI agents regardless of whether such AI agents are developed internally, acquired from third-party vendors, or operated through external services;</text></subparagraph> <subparagraph id="HB88E32B174CB459696B0840C5A54E3DE" commented="no"><enum>(E)</enum><text>evaluate the security, safety, correctness, and reliability of AI agents before such AI agents are deployed by such organization and continuously after such deployment;</text></subparagraph> 
<subparagraph id="H90D907297D934512B6E244789FFE0091"><enum>(F)</enum><text display-inline="yes-display-inline">enable continuous runtime monitoring and, where appropriate, inline detection and interception of AI agent interactions with tools, data sources, information systems, and other AI agents, including detection of prompt injection, data exfiltration, anomalous tool invocation, and behavioral drift from an AI agent’s approved operational baseline;</text></subparagraph> <subparagraph id="H6EC2252EABC846DF9B045C70EFF42130"><enum>(G)</enum><text>implement cryptographically verifiable provenance mechanisms sufficient to identify the entity responsible for creating or operating an AI agent; and</text></subparagraph> 
<subparagraph id="H06121FBE04B74AD993262AE5FCF3E12A"><enum>(H)</enum><text>generate and retain tamper-evident, standardized logs of material AI agent actions, and ensure such logs are portable and accessible, as appropriate and consistent with law, to deploying organizations and authorized relying parties.</text></subparagraph></paragraph> <paragraph id="HFB64EEEA14024F04BD08DD0D3E730A12" commented="no"><enum>(2)</enum><header>AI agent discovery as a component of cybersecurity</header><text display-inline="yes-display-inline">In carrying out paragraph (1), the Director, in coordination with the Assistant Secretary, shall include in the standards, guidelines, and best practices described in such paragraph AI agent discovery as a necessary component of effective cybersecurity within applicable frameworks, profiles, and reference materials.</text> </paragraph> 
<paragraph id="H65251C6D6F964348BD288CCE5FD4613C" commented="no"><enum>(3)</enum><header>Open and interoperable discovery standards</header><text>The Director, in coordination with the Assistant Secretary, shall support the development and adoption of open, vendor-agnostic, and interoperable standards for AI agent discovery mechanisms. In carrying out this paragraph, the Director and the Assistant Secretary shall—</text> <subparagraph id="H921FF55D9DBE49B8A7171F318D71FA3D" commented="no"><enum>(A)</enum><text>promote the use of existing internet infrastructure and identity-based discovery mechanisms, including domain name system-based approaches, cryptographically verifiable AI agent identity and registry frameworks, or functionally equivalent mechanisms, to enable secure and scalable AI agent discovery and AI agent identity verification;</text></subparagraph> 
<subparagraph id="H61B64507351A4DCC918E43C207945B8C" commented="no"><enum>(B)</enum><text>ensure that such standards are globally interoperable, distributed, and not dependent on proprietary or platform-specific registries; and</text></subparagraph> <subparagraph id="H966C38857433473899026DE3B92D6441" commented="no"><enum>(C)</enum><text>engage with multistakeholder processes, including industry, civil society, and technical standards bodies, to support broad adoption and international coordination.</text></subparagraph> </paragraph> 
<paragraph id="H8F34876004BD4D35927F9C3E24E73086" commented="no"><enum>(4)</enum><header>Minimum organizational requirements</header><text>Standards, guidelines, and best practices developed under this subsection shall provide that organizations deploying AI agents—</text> <subparagraph id="HA249288F6E374D898FDB3725F955FAFD" commented="no"><enum>(A)</enum><text display-inline="yes-display-inline">maintain a continuous, machine-readable inventory of all AI agents, using standardized, vendor-agnostic naming conventions;</text></subparagraph> 
<subparagraph id="H0CE085DF19094FFB90F367C57B8DFABD" commented="no"><enum>(B)</enum><text>implement AI agent identity verification and trust verification mechanisms that are independent and cryptographically verifiable at both the network and application layers; and</text></subparagraph> <subparagraph id="H902CAD3FCFFC41739EA4E7A0BAD75B29" commented="no"><enum>(C)</enum><text>do not rely solely on self-attested or single-provider assertions for establishing AI agent identity.</text></subparagraph></paragraph> 
<paragraph id="H56560E7C1CFA4CA78E849233FA35E00A"><enum>(5)</enum><header>Guidance, coordination, and demonstration projects</header><text>The Director, in coordination with the Assistant Secretary, shall—</text> <subparagraph id="HC332F44570ED4B5481244490EA2700EE" commented="no"><enum>(A)</enum><text display-inline="yes-display-inline">incorporate the standards, guidelines, and best practices developed under this subsection into existing National Institute of Standards and Technology frameworks and guidance;</text></subparagraph> 
<subparagraph id="H10836CB39046419DA6D7D2871A51C17C"><enum>(B)</enum><text display-inline="yes-display-inline">ensure that standards, guidelines, and best practices developed under this subsection are consistent with and not duplicative of other efforts by National Institute of Standards and Technology to establish standards related to AI agents;</text></subparagraph> <subparagraph id="H9D3663B01C594D709AC7D0EBE66A455E"><enum>(C)</enum><text>conduct or support demonstration projects, including through the National Cybersecurity Center of Excellence, to evaluate the effectiveness of open agent discovery mechanisms;</text></subparagraph> 
<subparagraph id="H810D460EE7DE444F89D1FBC890B181B0"><enum>(D)</enum><text>coordinate with the Administrator of the National Telecommunications and Information Administration to promote outreach and adoption through multistakeholder processes and international engagement, as appropriate; and</text></subparagraph> <subparagraph id="HC0D6DE81DCB14FCB8090BEB9819372DA"><enum>(E)</enum><text>coordinate with the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security to ensure AI agent discovery standards are reflected in applicable Federal civilian agency security guidance and binding operational directives, as appropriate.</text></subparagraph></paragraph></subsection> 
<subsection id="H6BF6F71BACBD4A35B63286C271685EA3"><enum>(b)</enum><header>Federal procurement requirements for AI agent security</header> 
<paragraph id="HB4DC2EBBB5A747F381632C8A8BA5E021" commented="no"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than 18 months after the publication of standards, guidelines, and best practices under subsection (a) and annually thereafter, the Federal Acquisition Regulatory Council shall propose revisions to the Federal Acquisition Regulation to require contractors and Federal agencies procuring or deploying, as the case may be, AI agents or information systems that interact with AI agents to comply with such standards, guidelines, and best practices.</text></paragraph> <paragraph id="H54981F57745946FA99C69135E18C7A03" commented="no"><enum>(2)</enum><header>Required contract elements</header><text display-inline="yes-display-inline">Revisions proposed under paragraph (1) shall ensure contracts for the procurement or deployment of AI agents include requirements that the contractor—</text> 
<subparagraph id="HA1ED2D8CCD694FD7B116CC990658223A" commented="no"><enum>(A)</enum><text display-inline="yes-display-inline">maintain a continuous, machine-readable inventory of all AI agents deployed under such contract, using standardized, vendor-agnostic naming conventions consistent with standards, guidelines, and best practices developed under subsection (a);</text></subparagraph> <subparagraph id="HA83860AC2BFB403A8C715E8EE37E844D" commented="no"><enum>(B)</enum><text>implement AI agent identity verification mechanisms that are cryptographically verifiable at both the network and application layers;</text></subparagraph> 
<subparagraph id="H010B3DBC6729480EAB4A16FBE0E48E8E" commented="no"><enum>(C)</enum><text>ensure AI agent discovery and verification capabilities are accessible to the Federal agency that has entered into such a contract without reliance on the contractor with which such Federal agency has so entered into such a contract;</text></subparagraph> <subparagraph id="HE9401F510B2F489EA0F569E02D307C2C" commented="no"><enum>(D)</enum><text display-inline="yes-display-inline">enable the Federal agency that has entered into such a contract to exercise organizational control over AI agent activity, including the ability to allow, deny, or constrain AI agent-to-AI agent and AI agent-to-information system interactions;</text></subparagraph> 
<subparagraph id="H70DC65491777486AB5316BBEDD51E547"><enum>(E)</enum><text>enable the Federal agency that has entered into such a contract to provide cryptographically verifiable provenance information to authorized entities interacting with the AI agent, consistent with the policies of such Federal agency; and</text></subparagraph> <subparagraph id="HD65CA438CAC74D3286313F33FA50FC21"><enum>(F)</enum><text display-inline="yes-display-inline">generate tamper-evident, standardized logs of material AI agent actions, and ensure such logs are portable and accessible to the Federal agency that has entered into such a contract and, where appropriate and consistent with law and such contract, authorized relying parties.</text></subparagraph></paragraph> 
<paragraph id="HE7F8796B20BD40339AF72DCA3974EA35"><enum>(3)</enum><header>Required contract elements for information systems interacting with AI agents</header><text>Revisions proposed under paragraph (1) shall ensure contracts for the procurement or deployment of information systems that AI agents interact with include requirements that the contractor—</text> <subparagraph id="H58EF22E67BDE4EAF861A00DAF004D4CF"><enum>(A)</enum><text>maintain a continuous, machine-readable inventory of all AI agents that interact with such an information system, using standardized, vendor-agnostic naming conventions consistent with standards, guidelines, and best practices developed under subsection (a);</text></subparagraph> 
<subparagraph id="HCA70AB44E08D4E2CBD73C99CF587E134"><enum>(B)</enum><text>implement identity verification mechanisms that are cryptographically verifiable for all AI agents that interact with such an information system;</text></subparagraph> <subparagraph id="H73F8CA9B7A654692BA99F0C01E585E02"><enum>(C)</enum><text>implement provenance verification mechanisms that are cryptographically verifiable for all AI agents that interact with such an information system;</text></subparagraph> 
<subparagraph id="H01F4B64F9BDC427CACCF263B81451F85"><enum>(D)</enum><text>ensure AI agent discovery and verification capabilities are accessible to the Federal agency that has entered into such a contract without reliance on the contractor with which such Federal agency has so entered into such a contract;</text></subparagraph> <subparagraph id="H66DF7A6802B14BAF84A2BC843EE3101D"><enum>(E)</enum><text>enable the Federal agency that has entered into such a contract to exercise organizational control over AI agents’ ability to interact with such an information system, including the ability to allow, deny, or constrain AI agent-to-AI agent interactions within such an information system; and</text></subparagraph> 
<subparagraph id="H3A65E909789A41B0A49C5364155451BD"><enum>(F)</enum><text display-inline="yes-display-inline">generate tamper-evident, standardized logs of material AI agent actions within such an information system and ensure such logs are portable and accessible to the Federal agency that has entered into such a contract and, where appropriate and consistent with law and such contract, authorized relying parties.</text></subparagraph></paragraph> <paragraph id="HBE059FBCD07F44289F52C798E1DE2824" commented="no"><enum>(4)</enum><header>Saving provision for certain contracts</header><text>This subsection shall not apply to contracts for the procurement or deployment, as the case may be, of AI agents or information systems that interact with AI agents entered into before the date of the enactment of this Act.</text></paragraph> 
<paragraph id="H51FD8DEA51B743DAABF817CABBD4FD8B" commented="no"><enum>(5)</enum><header>Agency guidance</header><text>Not later than 180 days after the proposal of revisions under paragraph (1) and annually thereafter, the Director of the Office of Management and Budget, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, shall issue guidance to Federal agencies regarding the following:</text> <subparagraph id="HA03D1BE2143546A998D0E658DF793ABB"><enum>(A)</enum><text>The implementation of procurement requirements under this subsection, including for AI agents deployed through cloud services, platform integrations, or third-party managed environments.</text></subparagraph> 
<subparagraph id="H0FE6CB5C212C41F598F1AF40A60D0107"><enum>(B)</enum><text display-inline="yes-display-inline">The effective usage of AI agents by such Federal agencies in accordance with the standards, guidelines, and best practices under subsection (a).</text></subparagraph></paragraph> </subsection> <subsection id="H011A189754E145F99F798FC43A2B7014"><enum>(c)</enum><header>Definitions</header><text>In this section:</text> 
<paragraph id="HBAAA936E13B44B5FA99409392735527F" commented="no"><enum>(1)</enum><header>AI agent discovery</header><text>The term <term>AI agent discovery</term> means the technical and organizational capability to identify, enumerate, verify, and maintain a current inventory of AI agents operating within, communicating with, or seeking access to an information system, network, application, service, or digital environment.</text></paragraph> <paragraph id="H8923D444A5474638B1B53529079B367C"><enum>(2)</enum><header>AI; Artificial intelligence</header><text>The terms <term>AI</term> and <term>artificial intelligence</term> have the meaning given the term <term>artificial intelligence</term> in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (<external-xref legal-doc="usc" parsable-cite="usc/15/9401">15 U.S.C. 9401</external-xref>).</text></paragraph> 
<paragraph id="H8077536342014995B39B0526348B6ABA"><enum>(3)</enum><header>AI model</header><text display-inline="yes-display-inline">The term <term>AI model</term> means a software component of an information system that implements artificial intelligence technology and uses computational, statistical, or machine-learning techniques to produce outputs from a defined set of inputs.</text></paragraph> <paragraph id="HBFC94FFCF73642239CFA74C433A9313D" commented="no"><enum>(4)</enum><header>Artificial intelligence agent; AI agent</header><text>The terms <term>artificial intelligence agent</term> and <term>AI agent</term> mean a software-based system that—</text> 
<subparagraph id="H2D8C8282445E4D5FB9519DCB07EEF90B" commented="no"><enum>(A)</enum><text>uses an AI model to perceive, plan, or make decisions;</text></subparagraph> <subparagraph id="HA63564D8DEFF4F91AC4BF95B4E832926" commented="no"><enum>(B)</enum><text display-inline="yes-display-inline">autonomously interacts with other software systems, digital services, users, external environments, or AI agents on behalf of a person or organization; and</text></subparagraph> 
<subparagraph id="H4225E9CC9351430880F0FB0971882826"><enum>(C)</enum><text>involves minimal or no human interaction beyond its initial direction.</text></subparagraph> </paragraph> <paragraph id="HDB805D972D7E40A7ACFBA31F4084B57A" commented="no"><enum>(5)</enum><header>Defense-in-depth</header><text display-inline="yes-display-inline">The term <term>defense-in-depth</term> means the protection of information systems by using multiple security measures, including policies, procedures, and physical security, such as antivirus software, firewalls, anti-spyware tools, strong password policies, intrusion detection systems, biometric verification, encryption, and multi-factor authentication, to reduce the risk of unauthorized access, data breach, or other successful attack.</text></paragraph> 
<paragraph id="H72CD6532B4A64186B98EF58B8BADDB9F"><enum>(6)</enum><header>Information system</header><text>The term <term>information system</term> has the meaning given such term in section 3502 of title 44, United States Code.</text></paragraph> <paragraph id="H60DADA5F26464F8BA83A8AFB376CECEB"><enum>(7)</enum><header>Organizational control</header><text>The term <term>organizational control</term> means the technical and organizational ability to—</text> 
<subparagraph id="H9AA5CC57594D49389405C4F67B48EFC2"><enum>(A)</enum><text>allow, deny, or restrict—</text> <clause id="H4A84D811CBA84DD990CB6259C12FD962"><enum>(i)</enum><text>an AI agent’s access to specific data;</text></clause> 
<clause id="H30363F258983463F91157B6911BD216D"><enum>(ii)</enum><text>the actions an AI agent can perform; and</text></clause> <clause id="H0A395A8E931E4F749910D465CAFD74F6"><enum>(iii)</enum><text>the tools, information systems, and AI agents which an AI agent can use or interact with; and</text></clause></subparagraph> 
<subparagraph id="HA2563956F8A9428AB1CCD6FCE9084E30"><enum>(B)</enum><text>revoke or change at any time any of the allowances, denials, or restrictions described in clauses (i) through (iii) of subparagraph (A).</text></subparagraph></paragraph></subsection> </section> </legis-body></bill>

