AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →
EmergingPendingUS

Artificial Intelligence Access, Gatekeeper Exchange, and Nondiscriminatory Transfer Act of 2026

Issued by

United States Senate (Senator Mark Warner)

liveAI AGENTVerified July 2026

The AI AGENT Act is a US Senate discussion draft that would require organizations deploying custodial AI agents on behalf of consumers to register those agents with the Federal Trade Commission before accessing large online platform interfaces. It defines covered agents as software authorized to act transparently and revocably on a user's behalf, and obligates large platforms to support approved third-party agents while prohibiting access for harmful activities. The bill imposes transparency and documentation requirements on both agent deployers and platform operators.

Applies To

Large enterpriseSMBAI developerAI deployer

Overview

Introduced as a discussion draft by Senator Mark Warner, the AI AGENT Act proposes a federal registration framework for consumer-facing AI agents in the United States, administered by the Federal Trade Commission. The bill establishes a legal definition of a custodial user agent as software that acts on a consumer's behalf with the consumer's explicit, revocable authorization and in a transparent manner. Large online platforms meeting specified thresholds would be required to provide interoperable access to FTC-approved third-party agents, preventing gatekeeping that could foreclose competition in the agent ecosystem. Agent deployers would face registration obligations, documentation requirements, and restrictions on use cases deemed harmful. Enforcement authority would rest with the FTC under its existing unfair and deceptive practices mandate, with potential for civil penalties. As a discussion draft, the bill has not yet been introduced for a floor vote, and its provisions remain subject to material revision.

Key Requirements

  • Register custodial AI agents with the FTC prior to accessing large online platform interfaces
  • Maintain documentation demonstrating that agents act transparently and with revocable user authorization
  • Large platforms above defined thresholds must provide nondiscriminatory access to FTC-approved third-party agents
  • Prohibit agent deployment for activities classified as harmful under the Act's provisions
  • Comply with FTC rulemaking on registration procedures, documentation standards, and approved agent categories
  • Penalties and enforcement mechanisms to be determined by FTC rulemaking and final legislative text

What Your Organization Must Do

  • Audit all consumer-facing AI agent deployments to determine whether they meet the bill's definition of a custodial user agent requiring FTC registration
  • Establish an internal tracking process to monitor the bill's progression from discussion draft to enacted law and respond to each rulemaking comment period
  • Engage legal counsel to assess whether the organization qualifies as a large online platform subject to mandatory third-party agent access obligations
  • Draft a registration readiness plan so that FTC submission can be executed promptly if the bill is enacted without a long lead-in period
  • Update AI agent product documentation to capture user authorization flows, revocability mechanisms, and transparency disclosures in anticipation of documentation requirements
  • Incorporate AI AGENT Act compliance requirements into vendor and partner agreements covering any third-party agent technology integrated into consumer-facing products

Playbook Guidance

Step-by-step implementation guidance for compliance teams.

Frequently Asked Questions

What is the FTC registration requirement under the AI AGENT Act and which organizations must comply?
Any organization deploying a custodial AI agent on behalf of consumers must register that agent with the FTC before it can access large online platform interfaces. This applies to both AI developers and deployers, regardless of company size, if their software meets the bill's definition of a custodial user agent acting with explicit, revocable user authorization.
How does the AI AGENT Act define a custodial user agent and does it cover enterprise agentic AI tools?
The bill defines a custodial user agent as software that acts on a consumer's behalf with explicit, revocable authorization and in a transparent manner. Enterprise tools that operate on behalf of employees rather than consumers may fall outside the definition, but organizations should have counsel analyze whether their specific deployment context triggers coverage.
What obligations does the AI AGENT Act impose on large online platforms and what thresholds trigger those duties?
Large platforms meeting unspecified numerical thresholds in the current draft must provide nondiscriminatory, interoperable access to FTC-approved third-party agents and cannot block or disadvantage approved agents. The precise thresholds are not yet defined, as the bill remains a discussion draft subject to material revision before introduction.
What are the penalties for noncompliance with the AI AGENT Act?
The discussion draft does not specify fixed penalty amounts, delegating enforcement authority and civil penalty structures to FTC rulemaking. The FTC would act under its existing unfair and deceptive practices mandate, meaning penalty exposure will depend on final legislative text and subsequent agency rules.
Is the AI AGENT Act in effect and what is its current legislative status?
No, the AI AGENT Act is a discussion draft introduced by Senator Mark Warner and has not been brought to a Senate floor vote. There is no effective date, and all provisions remain subject to significant revision, meaning compliance obligations are not yet legally operative.
How does the AI AGENT Act compare to EU AI Act requirements for high-risk AI systems?
The AI AGENT Act focuses narrowly on a federal registration and interoperability framework for consumer-facing AI agents enforced by the FTC, while the EU AI Act imposes broader risk-tiered conformity assessments, technical documentation, and human oversight obligations across AI application categories. Organizations operating in both jurisdictions will need to map requirements separately, as the two frameworks address different regulatory objectives.