Exclusive: New bill cracks down on AI agents after Hugging Face breach
Add Axios as your preferred source to
see more of our stories on Google.

Illustration: Aïda Amer/Axios
Reps. Josh Gottheimer (D-N.J.) and Mike Lawler (R-N.Y.) are introducing a new bill Thursday, first shared with Axios, aimed at securing AI agents amid a growing number of safety incidents involving rogue agents.
Why it matters: Washington has been slow to respond to the safety and security concerns raised by OpenAI's Hugging Face hack and other testing incidents involving agents that took unauthorized actions over the last two months.
Driving the news: The Stop Rogue AI Act directs Commerce's National Institute of Standards and Technology to develop and publish standards, guidelines and best practices for how organizations can securely deploy AI agents.
- The standards should cover how organizations can continuously maintain and verify the actions that agents take on their systems; evaluate the security and reliability of AI agents; and generate tamper-proof logs of the actions that agents take.
- Organizations deploying AI agents would also call on companies to maintain a "continuous, machine-readable inventory of all AI agents" and work with the Cybersecurity and Infrastructure Security Agency to ensure that federal civilian agencies apply the standards in their security programs.
- NIST would have a year after the bill's enactment, if it becomes law, to create the new standards.
Between the lines: Gottheimer told Axios in a statement that the bill is designed to help companies identify agents running on their networks and "know exactly who's behind them."
The intrigue: While the standards are voluntary for most organizations, the bill would push for federal contractors bidding for new deals to meet the NIST standards.
The big picture: Gottheimer and Lawler's bill joins a growing number of legislative attempts on Capitol Hill to bring transparency and security to AI agents' actions.
- Sen. Mark Warner (D-Va.), vice chair of the Senate Intelligence Committee, introduced a bill directing the Federal Trade Commission to create independent bodies that vet AI agent vendors and assess their security practices.
- Reps. Ted Lieu (D-Calif.) and Nathaniel Moran (R-Texas) introduced a bill in July that would give the Department of Homeland Security the authority to order top AI firms to shut down or slow AI models that are deemed too dangerous.
What they're saying: "Right now, AI agents are running loose in our networks, and nobody can see them or verify who built them — making it increasingly hard to stop them," Gottheimer told Axios. "That's a five-alarm security risk."
Reality check: Washington has struggled to keep up with the security advancements — and subsequent concerns — of AI models and agents, and other AI bills haven't gained much traction in Congress this session.
- U.S. officials pressed members of the G20 during this week's gathering to take a hands-off approach to regulating AI and avoid creating rules that could hinder profits and change how these products work due to security concerns.
Yes, but: Gottheimer and Lawler's bill has the support of several U.S. companies and industry trade groups, including Palo Alto Networks, GoDaddy, Infoblox, the AI Policy Network and the Alliance for Secure AI.
