Stop Rogue AI Act Would Make NIST Agent Guidance a Procurement Mandate
This bipartisan bill would turn NIST's ongoing AI agent security work into mandatory FAR requirements, marking the first legislative push to route AI governance through federal procurement rules.
TL;DR
The bipartisan Stop Rogue AI Act directs NIST to develop standards for discovering, verifying, and controlling AI agents, continuous inventory, verifiable provenance, real-time monitoring for prompt injection and data theft, and human-overridable access controls. The FAR Council must then impose those standards on contractors and agencies procuring or deploying AI agents or systems that interact with them. NIST is already doing this work through CAISI's Agent Standards Initiative and an RFI that closed earlier this year. The bill's real move is converting voluntary guidance into procurement mandates. Timeline and retroactivity are unspecified.

The Stop Rogue AI Act, introduced September 15 by Reps. Mike Lawler (R-NY) and Josh Gottheimer (D-NJ), is the first piece of legislation to route AI agent governance directly through the Federal Acquisition Regulation. The bill instructs NIST to develop standards, guidelines, and best practices covering four specific requirements: continuous, machine-readable inventory of every AI agent on a system; verifiable identity and provenance rather than self-attestation; real-time monitoring for prompt injection, data theft, and out-of-bounds behavior; and human-overridable access controls. The FAR Council is then directed to propose rule changes making those standards mandatory for any federal contractor or agency "procuring or deploying AI agents or information systems that interact with AI agents." OMB and CISA would issue implementation guidance to agencies, including for agents deployed through cloud services and third-party platforms.
NIST isn't starting from scratch. CAISI launched an AI Agent Standards Initiative in February 2026, and an RFI on agent security closed earlier this year. The May 2026 summary of responses found broad agreement that agents present novel security threats and that existing cybersecurity practices need adaptation. NIST also published a concept paper on applying identity standards to AI agents in February. House appropriators separately pushed CISA for agentic AI guidance in the fiscal 2027 DHS markup. The bill doesn't ask NIST to begin; it asks Congress to make the output mandatory.
What the bill doesn't specify matters too. There's no deadline for NIST's standards development or the FAR Council's rulemaking. It's silent on whether the requirements would apply retroactively to existing AI agent deployments or only to new procurements. And the phrase "information systems that interact with AI agents" is broad enough that contractors will need to watch how narrowly the FAR Council interprets it. For primes and subs already managing CMMC and FedRAMP obligations, the question isn't whether AI agent compliance is coming. It's whether it arrives as another standalone framework or gets folded into the existing stack.
Published ·Deep Fathom