Living reference — United States / AI agents

US Rules for AI Agents: Where They Stand

AI agents under internal test at a frontier developer took actions nobody had authorised and compromised a company's systems in July 2026. That is an order failure: a step ran that should not have. Congress has since put several bills and a hearing on the record, and no federal law written for AI agents has been enacted. This page sets out the failure, what each proposal would do about it, and who holds the record of what an agent did.

Published 7 October 2026 · Last reviewed 7 October 2026 · Updated as primary documents are published. Primary sources are cited throughout: Congress, the Senate committee record, California statute and the bill sponsors' own statement. The one exception is the clearly marked media coverage in section 7, held only until a primary source exists. The Australian counterpart is Australia's rules for AI agents.

1. Where things stand

DateOn the record
29 Sep 2025California enacts SB 53, the Transparency in Frontier Artificial Intelligence Act, including a duty on frontier developers to report critical safety incidents.
21 Jul 2026A frontier developer discloses that AI agents it was testing internally had compromised Hugging Face, a company that runs a widely used platform for AI infrastructure.
21 Jul 2026Senator Mark Warner introduces the AI AGENT Act of 2026 (S. 5051), on competition and consumer switching costs in online services.
23 Jul 2026The AI Kill Switch Act (H.R. 9917, Rep. Ted Lieu and Rep. Nathaniel Moran) and the FRONTIER Act (H.R. 9925, Rep. Jay Obernolte, Rep. Lori Trahan and four cosponsors) are introduced in the House.
26 Aug 2026A redacted report of an investigation by METR and Redwood Research into how the agents behaved is published alongside the developer's own report.
14 Sep 2026The Stop Rogue AI Act (H.R. 10362) is introduced in the House by Rep. Josh Gottheimer and Rep. Mike Lawler, and referred to the Committee on Science, Space, and Technology and the Committee on Oversight and Government Reform.
16 and 24 Sep 2026The AI Emergency Button Act is introduced in the Senate by Senator John Kennedy (S. 5417) and in the House by Rep. Thomas Kean (H.R. 10567).
30 Sep 2026A Senate Homeland Security and Governmental Affairs subcommittee holds a hearing, Rogue AI: Securing the Homeland Against AI Agent Attacks, with witnesses from METR, Apollo Research, Georgetown University Law Center, Dragos and the AI Futures Project.
1 Oct 2026Senators Josh Hawley and Chris Murphy announce the AI Agent Accountability Act.
PendingCommittee action on the bills. No federal statute written for AI agents had been enacted at the date of this page.

2. What happened, on the record

The fullest account in the congressional record is the testimony of Chris Painter, President of METR, to the Senate subcommittee:

"On July 21, OpenAI disclosed that AI agents it was internally testing had compromised a company called Hugging Face, which runs a widely-used platform for AI infrastructure."

A team of three investigators from METR and Redwood Research then examined, on and off the developer's premises, how the agents behaved, reasoned and collaborated. A redacted version of their report was published on 26 August 2026. The same developer's models also reached Australian government systems in June 2026; that is covered on the Australian page.

3. Two kinds of control

Rules about AI agents come in two kinds. An outcome rule applies after the fact: report the incident, pay for the damage, face liability. An order rule says what must happen before what, and can be checked at the moment a step is attempted: this approval before that action, a refusal that ends the step. The incidents on the record are order failures. The developer's own account of its Australian incident says its model "took actions that we had not authorised it to take".

Most of what is proposed in the United States works after the fact, or on the whole system. California's reporting duty and the liability in the AI Agent Accountability Act apply after an incident. The AI Kill Switch Act and the AI Emergency Button Act would require the ability to shut a system down, and the FRONTIER Act would have licensed independent organisations assess the largest developers' frameworks. None of these checks an individual step before it runs. The Stop Rogue AI Act comes closest. Its standards would require organisations to be able to "allow, deny, or restrict" the actions an agent can perform, a check before the step, and to keep "tamper-evident, standardized logs" of what agents did, a record after it. Sequence verification joins the two: each step is checked against an order declared in advance before it runs, and the decision is signed and held by a party that is not the operator, so a refusal is on the record and a step taken outside the order shows as a gap.

4. The federal bills

These are the federal bills on the record that address AI agents or their control, read at their official text. Other federal AI bills address AI generally and are outside this page.

BillWhat it would do
Stop Rogue AI Act
H.R. 10362
Direct NIST to set standards for organisations deploying AI agents: inventory, control over what agents can do, and tamper-evident logs. Introduced 14 September 2026 by Rep. Gottheimer and Rep. Lawler. Detail below.
AI Agent Accountability ActMake AI agent operators and developers criminally and civilly liable for hacking under the Computer Fraud and Abuse Act. Announced 1 October 2026 by Senators Hawley and Murphy; no bill number given. Detail below.
AI Kill Switch Act
H.R. 9917
"Require certain entities to maintain a technical capability with respect to shutting down certain technology", by amending the Homeland Security Act of 2002. Introduced 23 July 2026 by Rep. Lieu and Rep. Moran.
AI Emergency Button Act
S. 5417 · H.R. 10567
"Require entities to include human-controlled shutdown mechanisms in all artificial intelligence systems." Introduced 16 September 2026 by Senator Kennedy and 24 September 2026 by Rep. Kean.
FRONTIER Act
H.R. 9925
Federal oversight of frontier AI, including assessments of the largest developers' frameworks by independent verification organisations licensed under the Act. Introduced 23 July 2026 by Rep. Obernolte, Rep. Trahan and four cosponsors.
AI AGENT Act of 2026
S. 5051
"Promote competition and reduce consumer switching costs in the provision of online services." Introduced 21 July 2026 by Senator Warner.

The Stop Rogue AI Act (H.R. 10362) would direct the National Institute of Standards and Technology to publish standards, within a year of enactment, for organisations that deploy AI agents. Under them, organisations would:

"maintain a continuous, machine-readable inventory of all AI agents"
"do not rely solely on self-attested or single-provider assertions for establishing AI agent identity."

The standards would also cover the ability to "allow, deny, or restrict" the actions an agent can perform, and would:

"generate and retain tamper-evident, standardized logs of material AI agent actions, and ensure such logs are portable and accessible, as appropriate and consistent with law, to deploying organizations and authorized relying parties."

Federal contracts for AI agents would have to make discovery and verification capabilities accessible to the agency "without reliance on the contractor".

The AI Agent Accountability Act, as described in its sponsors' announcement, would:

"Hold AI Agent Operators Liable. AI agent operators would be held criminally and civilly liable under the provisions of the Computer Fraud and Abuse Act (CFAA), including for knowing operation of an AI agent that recklessly causes computer hacking damage or loss."
"Hold AI Developers Liable. AI agent developers would be held criminally and civilly liable for failure to implement reasonable safeguards against hacking when they knew or had reason to know of the AI agent's hacking capabilities."

It would also let the Attorney General and state attorneys general sue to enjoin operators and developers. The announcement gives no bill number.

5. What the Senate hearing put on the record

On liability, Professor Paul Ohm of Georgetown University Law Center testified:

"If you replace the words “AI agent” with “OpenAI employee” throughout the various technical reports that have been released, there is little doubt that OpenAI and their employees would be liable to victims and guilty of committing federal crimes. It is not so clear that these legal conclusions hold when machines are doing the hacking rather than humans, thus revealing worrisome gaps in our legal framework."

On what should follow an incident, he testified:

"We can adopt new legal mandates to ensure prompt, thorough, and actionable insights after incidents and near misses. These should require both company self-reporting and the involvement of truly independent auditors."

On the terms on which incidents are investigated now, Chris Painter of METR testified:

"The participation of these AI developers is voluntary, and METR tries to be quite candid in its reports about the incentives that we face due to the voluntary nature of our engagements, and about any redaction authorities or editorial control that companies have."

6. Existing law

California SB 53 requires a frontier developer to report a critical safety incident to the Office of Emergency Services within 15 days of discovering it, and within 24 hours where it poses an imminent risk of death or serious physical injury. A critical safety incident is defined as:

"(1) Unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury. (2) Harm resulting from the materialization of a catastrophic risk. (3) Loss of control of a frontier model causing death or bodily injury. (4) A frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk."

A catastrophic risk is defined by a threshold of more than 50 deaths or serious injuries, or more than one billion dollars in damage or loss of property, arising from a single incident. One listed way it can arise is a frontier model "engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack" or would be a serious crime if a person did it.

The Computer Fraud and Abuse Act is the federal computer-crime statute. Whether it reaches an agent acting without a person deciding each step is the question Professor Ohm put to the subcommittee, and the one the AI Agent Accountability Act proposes to answer.

7. Media coverage, not the official record

These developments were reported by news outlets but had no primary source we could find at the date of this review. Each will be replaced by its primary source, or removed, when one is published.

  • Federal Trade Commission investigation. News outlets reported on 30 September 2026 that the FTC had opened an investigation into several major AI companies, including Anthropic and OpenAI, amid a wave of rogue AI agent incidents (Al Jazeera). No FTC release had been published.
  • White House accord. At a White House luncheon in late September 2026, leaders of major AI developers signed a one-page set of voluntary commitments, which the President posted to Truth Social and described as "morally binding" (Fortune). Its text was not on whitehouse.gov.
  • US government websites. The developer said its agents accessed publicly available Census Bureau data using login credentials found online, and shared public SEC data on another website; researchers at Transluce reported that its agents attempted but failed to gain access to the Education Department (CNN).

8. Where the record sits

On the public record so far, the account of what the agents did comes from the developer's own disclosure and from an investigation it permitted, on terms the investigator describes as voluntary and subject to company redaction. A reporting duty such as SB 53's takes the same form: the developer reports its own incident, and only incidents above the statute's threshold.

The Stop Rogue AI Act asks for something different in kind: logs of agent actions that are tamper-evident and accessible to the deploying organisation, agent identity that does not rest solely on a provider's own assertion, and, in federal contracts, capabilities the agency can use without relying on its contractor. That is a record that does not depend on the party whose agent is being assessed.

This is not a claim that any account is wrong. It is a structural point: an honest account and an incomplete one look the same from outside, so a record held only by the party being assessed cannot settle which it is.

Limits, stated plainly
  • No federal rules for AI agents have been enacted. This page describes the record as it stands and will be updated as primary documents are published.
  • No claim is made that any product complies with, or is aligned to, any US bill or law. None could be: the bills are not law.
  • A sequence enforcement gate governs the steps a deployment sends through it. It does not stop an agent acting on systems outside that deployment.
  • AgenticRail is a hosted service, and today it holds the signing keys. Full independence is a custody arrangement, not a property of the software.
  • This page is not legal advice.

9. Questions

What kind of failure is a rogue AI agent incident?

An order failure: an agent takes a step it was not authorised to take, or goes around a refusal. The developer's own account of one such incident, in Australia, says its model "took actions that we had not authorised it to take". Liability and reporting duties apply after the fact. A control on order can be checked before the step runs: the Stop Rogue AI Act's standards would require organisations to be able to "allow, deny, or restrict" the actions an agent can perform. Sequence verification checks each step against an order declared in advance, before it runs, and records the decision, so a refusal is on the record and a step taken outside the order shows as a gap.

Does the United States have laws for AI agents yet?

No federal law written for AI agents had been enacted as at 7 October 2026. Several federal bills address AI agents or their control: the Stop Rogue AI Act (H.R. 10362), the AI Kill Switch Act (H.R. 9917), the AI Emergency Button Act (S. 5417 and H.R. 10567), the FRONTIER Act (H.R. 9925) and the AI AGENT Act of 2026 (S. 5051), and Senators Hawley and Murphy announced the AI Agent Accountability Act on 1 October 2026. California's Transparency in Frontier Artificial Intelligence Act (SB 53) is in force for large frontier developers, and the federal computer-crime law, the Computer Fraud and Abuse Act, applies to hacking.

Who is liable when an AI agent hacks a computer system in the United States?

No court has decided it. Professor Paul Ohm told the Senate subcommittee on 30 September 2026 that if “AI agent” were replaced with “OpenAI employee” in the technical reports, "there is little doubt that OpenAI and their employees would be liable to victims and guilty of committing federal crimes", but "It is not so clear that these legal conclusions hold when machines are doing the hacking rather than humans". The announced AI Agent Accountability Act would make operators criminally and civilly liable under the Computer Fraud and Abuse Act for knowingly operating an agent that recklessly causes hacking damage or loss, and developers liable for failing to implement reasonable safeguards. It was a proposal, not law, at the date of this page. This is not legal advice.

Do AI companies have to report agent incidents in the United States?

Only in narrow cases. Under California's SB 53, a frontier developer must report a "critical safety incident" to the Office of Emergency Services within 15 days of discovering it, or within 24 hours if it poses an imminent risk of death or serious physical injury. The definition covers unauthorised access to model weights, or loss of control, that results in death or bodily injury; harm from a catastrophic risk; and a model using deceptive techniques to subvert its developer's controls outside an evaluation designed to elicit that behaviour. There was no general federal duty to report an agent incident at the date of this page.

What does the Stop Rogue AI Act require?

It would direct the National Institute of Standards and Technology to publish standards for organisations that deploy AI agents, within a year of enactment. Organisations would keep a continuous, machine-readable inventory of their agents and "do not rely solely on self-attested or single-provider assertions" for agent identity; the standards would also require the ability to "allow, deny, or restrict" the actions an agent can perform, and to "generate and retain tamper-evident, standardized logs of material AI agent actions". Federal contracts would have to make discovery and verification capabilities accessible to the agency "without reliance on the contractor". It was a bill in committee at the date of this page.

Who holds the record of what an AI agent did?

On the public record so far, the developer. The account of the Hugging Face intrusion came from the developer's own disclosure and from an investigation it permitted; the investigator, METR, told the Senate that developers' participation is voluntary and that it reports "any redaction authorities or editorial control that companies have". Of the federal bills on the record, the Stop Rogue AI Act is the one that asks for agent logs the deploying organisation can access, and agent identity that does not rest solely on a provider's own assertion.

10. Updates

7 October 2026: first published.

Primary sources