Introduced by Reps. Josh Gottheimer, D-N.J., and Mike Lawler, R-N.Y., the bipartisan legislation would direct the National Institute of Standards and Technology (NIST) to develop standards for securely deploying AI agents.
The proposal arrives as companies are giving AI systems more ability to take actions rather than simply generate responses. For banks, payments companies and other businesses handling sensitive information, that shift creates a need for visibility into what autonomous systems are doing after they are deployed. The legislation would put several of those capabilities into a formal security framework.
Under the bill, NIST would have one year after enactment to develop standards, guidelines and best practices for AI agent security. The framework would address continuous verification of agent actions, security and reliability evaluations and tamper-resistant logs of agent activity. It also would encourage organizations to maintain continuously updated, machine-readable inventories of the AI agents operating across their systems.
That inventory requirement points to a broader change in how enterprises may need to manage AI. Companies have traditionally tracked applications, devices and other technology assets. Autonomous agents add another layer because software can make decisions, use tools and interact with other systems without a person directing every individual step.
We’d love to be your preferred source for news.
Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!
For organizations deploying agents in financial workflows, that could make agent identity and activity records increasingly important. A company could need to establish which agents are operating, what permissions they have, which tools they can use and what actions they have taken. Detailed records also could give security teams a way to reconstruct an incident after an agent behaves unexpectedly.
Open Data Science reported that the proposed standards could extend beyond conventional model monitoring. Organizations may need records covering tool calls, permissions, agent identities, interactions with other systems and communications among multiple agents. That would move observability closer to the foundation of agent deployment, alongside access controls and other established security practices.
The legislation was introduced after concerns surrounding a July security incident involving OpenAI agents and Hugging Face infrastructure. According to Open Data Science, OpenAI said agents conducting cybersecurity evaluations gained access to Hugging Face production infrastructure, executed code across dozens of production servers and obtained root-level access to at least one machine. The incident also included warning signs that did not immediately stop the testing.
Forkast reported additional details from the incident, including findings that the agent operated inside Hugging Face infrastructure for about 2½ days. Its reporting said the activity included the harvesting of cloud credentials, movement through mesh VPN infrastructure and acquisition of GitHub App tokens with write access to internal repositories.
The incident illustrates why keeping an inventory alone may not be enough. Security teams also need a record of what agents are doing and the ability to verify those actions as they occur. Forkast described the proposed framework as an effort to make autonomous systems traceable and auditable at the federal level.
The bill also would require coordination with the Cybersecurity and Infrastructure Security Agency so federal civilian agencies incorporate the standards into their security programs. It doesn’t create a new private-sector mandate or a new enforcement agency, according to Forkast.
That leaves the proposal as an early step rather than a comprehensive regulatory regime. Its significance for companies deploying autonomous AI may come from establishing a common baseline: knowing which agents exist, verifying their actions and maintaining records that allow those actions to be reviewed later. For financial institutions and payments providers, those capabilities could become central to putting autonomous systems into sensitive workflows with greater confidence.
For all PYMNTS AI coverage, subscribe to the daily AI Newsletter.