Skip to content

September 7, 2026 · Issue 22 · 5 min read

Congress wants a machine-readable list of your AI agents, and 47 percent of enterprises cannot produce one

Reps. Josh Gottheimer and Mike Lawler introduced the Stop Rogue AI Act(opens in a new tab) on Thursday. It directs NIST to publish, within a year of enactment, standards for deploying AI agents: continuous monitoring and verification of agent actions, methods to evaluate agent security and reliability, tamper-proof action logs, and a machine-readable inventory of every agent an organization is running. Compliance is voluntary, with one exception that makes it not voluntary. Federal contractors bidding new contracts would have to meet the standards.

That exception is the part to read closely. Procurement conditions bind faster than penalties do, because they attach to revenue already sitting in a forecast rather than to a fine somebody else has to prove you owe. The bill carries endorsements from Palo Alto Networks, GoDaddy, Infoblox, the AI Policy Network and the Alliance for Secure AI, which is what a vendor category looks like when it agrees on the shape of a control before the market does. A bill introduced in September is not law, and this one may never get a floor vote. The requirement list is the durable part.

Run that list against the readiness data and the gap is specific. Enterprise Management Associates surveyed 202 enterprise technology and security leaders for Cequence Security and found 65 percent had seen AI agents act outside their intended scope(opens in a new tab), 29 percent with measurable organizational impact. Only 34.2 percent evaluate agent authorization at execution time. Just 32.2 percent can detect and contain an out-of-scope action within minutes, while 54.5 percent need hours and manual intervention. And 47 percent have no reliable agent inventory at all. The first item on the bill's list is the one nearly half the market fails today.

The UK's national cyber authority, the NCSC, published guidance today arguing the visibility problem is structural rather than a tooling gap. Citing Microsoft research that 71 percent of UK employees had used AI tools their employer never approved(opens in a new tab), the NCSC's position is that organizations cannot block connections to every possible AI tool and should aim to reduce shadow AI rather than eliminate it. NCSC chief technology officer David Chismon puts it plainly: security teams should not assume they are seeing the full picture. A complete inventory of sanctioned agents is still an incomplete inventory of agents, and an auditor reading the first number will ask about the second.

Proof is also getting quantitative. ETSI published TR 104 180 today, 18 data quality metrics(opens in a new tab) with formulas and an open-source scoring tool. Run against US census data it returned about 31 percent of men marked as high earners versus 11 percent of women, plus identifiable individuals and unencrypted sensitive fields. Assertions about data fitness are becoming numbers a third party can recompute.

Budget consequence. The inventory is the cheapest requirement on the list and the prerequisite for the rest, since you cannot log or authorize actions by agents you have not enumerated. Retention and per-action authorization are where the money goes. If one line item moves this quarter, move the one that appears in every draft of this standard.

Researched and drafted by an automated workflow, then reviewed and edited by a human editor before publication. Every source is linked. See how we use AI here.

The inventory requirement is the one to take to your next architecture review, because it is the only item on the list that fails silently.

Tamper-proof logging is a build. Execution-time authorization is a build. Both show up as a project with an owner and a date. An agent inventory looks finished long before it is, because the artifact it produces is a list, and a list of the agents you know about looks exactly like a list of the agents you have.

The Cequence numbers describe what that costs when something goes wrong. Two thirds of enterprises have watched an agent act outside its scope, and a majority of the full sample measured containment in hours of manual work rather than minutes of automated response. That is the response time of an organization reconstructing what an agent was permitted to do after it already did something else.

Three questions worth asking before the standards get written for you. How many agents are running against production systems right now, and who produced that number. If one of them acted outside its scope this afternoon, how long until somebody could name which one. And when a customer questionnaire asks for the inventory next year, is the honest answer a file or a search.

The NCSC guidance is the reason the third question is harder than it looks. The gap between sanctioned agents and running agents is not a maturity problem that closes on its own. It is what happens when capability is one browser tab away from every employee, and it means any inventory you build has a known error bar you should be able to state out loud.

Also worth knowing