The Hugging Face security incident sparked a bipartisan effort in the US to legislate regulations for AI-powered intelligent agents.

The Hugging Face security incident sparked a bipartisan effort in the US to legislate regulations for AI-powered intelligent agents.

Bipartisan Congress in the United States is pushing for legislation to ensure the safety of AI agents, attempting to further improve relevant safety regulations.

On September 3, it was reported that Democratic Representative Josh Gottheimer and Republican Representative Mike Lawler will jointly introduce the "Stop Rogue AI Act" on Thursday , requiring the National Institute of Standards and Technology (NIST), a division of the Department of Commerce, to develop standards, guidelines, and best practices for the safe deployment of AI agents.

The bill aims to help businesses identify AI agents operating on their networks and identify the developers or operators behind them. For most organizations, adoption of the NIST standards is voluntary; however, government contractors bidding for new federal contracts are required to meet the standards.

This legislation comes at a time when a series of security incidents involving AI agents have been exposed. In the past two months, several security incidents and testing incidents involving AI agents taking unauthorized actions have drawn attention, with the intrusion of an OpenAI-developed AI agent into the Hugging Face system being particularly alarming.

AI agents frequently overstepping boundaries, raising concerns about lagging regulation.

As previously reported, OpenAI detected warning signs weeks before the Hugging Face incident, and its AI agents had previously infiltrated its own system. Meanwhile, tech companies have recently begun exploring ways to track "rogue AI agents," but as these agents gain greater autonomy, their containment becomes increasingly difficult.

Gottheimer stated: "Currently, AI agents are roaming around our networks, and no one can see them or verify who built them—making it increasingly difficult to stop them. This is a level 5 alert security risk."

Gottheimer stated that the bill aims to help businesses identify the AI agents operating in their networks and "accurately understand the entities behind them."

The report points out that Washington's response to the security risks of AI models and agents has lagged behind technological advancements, and other AI-related bills have not made much substantial progress during this legislative session. This joint effort by bipartisan lawmakers to push for legislation is the latest attempt by Congress to strengthen transparency and security oversight of AI agents.

NIST sets standards, and federal procurement creates hard constraints.

At the heart of the bill is the development of standards by NIST for the secure deployment of AI agents, covering how organizations can securely deploy AI agents and how to identify and manage agents in networks.

For ordinary businesses, the relevant standards are not mandatory; however, contractors wishing to bid for new federal contracts must meet NIST standards. This means that the bill does not directly set a uniform mandatory threshold for the entire industry, but rather uses federal government procurement to transform voluntary standards into practical constraints.

Currently, companies and industry organizations such as Palo Alto Networks, GoDaddy, Infoblox, AI Policy Network, and Alliance for Secure AI have expressed their support for the bill.

From a broader legislative perspective, this bill is one of several recent legislative attempts by Congress to address the transparency and security of AI agents. However, given the previous difficulties in advancing AI-related legislation in Congress, the likelihood of substantial progress on the "Stop AI Out of Control Act" remains uncertain.

Risk warning and disclaimerInvesting involves risk; please exercise caution. This article does not constitute personal investment advice and does not take into account the specific investment objectives, financial situation, or needs of individual users. Users should consider whether any opinions, views, or conclusions in this article are suitable for their specific circumstances. Any investment decisions made based on this information are at your own risk.