Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →Bipartisan Bill to Stop Rogue AI Agents and Keep People in Control
Issued by
United States House of Representatives, Office of Representative Josh Gottheimer
This bipartisan federal bill directs the National Institute of Standards and Technology to develop national standards, guidelines, and best practices for governing autonomous AI agents. It applies to organizations that deploy or develop AI agent systems capable of acting with limited human intervention. Core requirements center on agent discovery, verification testing, and maintaining meaningful human control over autonomous system behavior.
Applies To
Overview
Introduced in the House on September 9, 2026, this bill tasks NIST with creating a formal framework for identifying, verifying, and controlling AI agents operating in commercial and government environments. The legislation responds to growing enterprise deployment of autonomous AI systems that can execute multi-step tasks, access external tools, and make consequential decisions without per-action human approval. Key provisions require NIST to define standards for agent identity verification, behavioral monitoring, and human override mechanisms. Enforcement pathways have not yet been specified in the introduced text, but the NIST mandate would produce standards that federal procurement rules and sector regulators could subsequently adopt. The bill's bipartisan sponsorship suggests moderate legislative momentum, though committee assignment and floor scheduling remain pending.
Key Requirements
- •Directs NIST to develop national standards and guidelines specifically for AI agent governance, with no deadline specified in the introduced text.
- •Requires standards to address agent discovery: the ability to identify and inventory autonomous AI agents operating within a system or network.
- •Mandates verification testing protocols to confirm that AI agents behave within defined parameters before and during deployment.
- •Requires guidelines for human control mechanisms, including override and shutdown capabilities for autonomous agents.
- •Calls for best practices around enterprise monitoring of AI agent activity on an ongoing basis.
- •Penalty and enforcement provisions have not been detailed in the introduced bill; downstream regulatory adoption would determine consequence structures.
What Your Organization Must Do
- →Inventory all AI agent deployments across the enterprise now, before NIST standards are finalized, to identify governance gaps early.
- →Assign ownership of AI agent oversight to a designated function, such as a responsible AI team or existing AI governance committee.
- →Review vendor contracts for any third-party AI agents integrated into business workflows and require disclosure of agent capabilities and control mechanisms.
- →Implement or document existing human override and shutdown procedures for autonomous AI systems in use today.
- →Monitor NIST's rulemaking process and public comment periods, as resulting standards may be incorporated into federal procurement requirements.
- →Engage legal and compliance counsel to assess whether sector-specific regulators, such as those covering finance or healthcare, may adopt NIST agent standards once published.
Playbook Guidance
Step-by-step implementation guidance for compliance teams.
Frequently Asked Questions
- Does the ROGUE-AI bill currently impose compliance obligations on private companies deploying AI agents?
- Not directly. The introduced bill tasks NIST with developing standards but does not itself impose obligations on private organizations. Compliance requirements would flow from downstream adoption by federal procurement rules or sector regulators once NIST publishes its framework.
- What is the compliance deadline for NIST to publish AI agent governance standards under this bill?
- No deadline is specified in the introduced text. Organizations should monitor NIST's rulemaking activity and public comment periods, as the timeline will depend on committee progress, floor scheduling, and NIST's internal development process after enactment.
- What does agent discovery mean under the ROGUE-AI bill and what would it require operationally?
- Agent discovery refers to the capability to identify and inventory all autonomous AI agents operating within a system or network. Operationally, this would require organizations to maintain current records of deployed agents, including third-party agents embedded in business workflows.
- How does the ROGUE-AI bill compare to the EU AI Act for companies managing agentic AI systems?
- The EU AI Act applies risk-based obligations directly to deployers and providers now, with enforcement already underway. ROGUE-AI is a draft US bill that delegates standard-setting to NIST, meaning binding obligations for agentic systems are further away and less prescriptive at this stage.
- Will federal contractors face additional AI agent requirements if ROGUE-AI becomes law?
- Federal contractors are a likely early target, as NIST standards frequently flow into federal procurement and acquisition rules. Contractors deploying autonomous AI agents in government workflows should treat NIST's eventual framework as probable contract compliance criteria.
- What human control requirements does the ROGUE-AI bill mandate for autonomous AI agents?
- The bill directs NIST to develop guidelines covering override and shutdown capabilities for autonomous agents. Organizations should document existing intervention procedures now, since those records will be directly relevant when NIST standards define what constitutes meaningful human control.
