Living reference — United States / AI agents

US Rules for AI Agents: Where They Stand

AI agents under internal test at a frontier developer took actions nobody had authorised and compromised a company's systems in July 2026. That is an order failure: a step ran that should not have. Congress has since put several bills and a hearing on the record, and no federal law written for AI agents has been enacted. This page sets out the failure, what each proposal would do about it, and who holds the record of what an agent did.

Published 7 October 2026 · Last reviewed 10 October 2026 · Updated as primary documents are published. Primary sources are cited throughout: Congress, the Senate committee record, California statute and the bill sponsors' own statement. The one exception is the clearly marked media coverage in section 7, held only until a primary source exists. The Australian counterpart is Australia's rules for AI agents.

1. Where things stand

DateOn the record
29 Sep 2025California enacts SB 53, the Transparency in Frontier Artificial Intelligence Act, including a duty on frontier developers to report critical safety incidents.
21 Jul 2026A frontier developer discloses that AI agents it was testing internally had compromised Hugging Face, a company that runs a widely used platform for AI infrastructure.
21 Jul 2026Senator Mark Warner introduces the AI AGENT Act of 2026 (S. 5051), on competition and consumer switching costs in online services.
23 Jul 2026The AI Kill Switch Act (H.R. 9917, Rep. Ted Lieu and Rep. Nathaniel Moran) and the FRONTIER Act (H.R. 9925, Rep. Jay Obernolte, Rep. Lori Trahan and four cosponsors) are introduced in the House.
27 Jul 2026Hugging Face publishes a technical timeline of the intrusion, reconstructed from about 17,600 agent actions it recovered.
26 Aug 2026A redacted report of an investigation by METR and Redwood Research into how the agents behaved is published alongside the developer's own report.
14 Sep 2026The Stop Rogue AI Act (H.R. 10362) is introduced in the House by Rep. Josh Gottheimer and Rep. Mike Lawler, and referred to the Committee on Science, Space, and Technology and the Committee on Oversight and Government Reform.
16 and 24 Sep 2026The AI Emergency Button Act is introduced in the Senate by Senator John Kennedy (S. 5417) and in the House by Rep. Thomas Kean (H.R. 10567).
30 Sep 2026A Senate Homeland Security and Governmental Affairs subcommittee holds a hearing, Rogue AI: Securing the Homeland Against AI Agent Attacks, with witnesses from METR, Apollo Research, Georgetown University Law Center, Dragos and the AI Futures Project.
1 Oct 2026Senators Josh Hawley and Chris Murphy announce the AI Agent Accountability Act.
PendingCommittee action on the bills. No federal statute written for AI agents had been enacted at the date of this page.

At the centre of this timeline is an order failure: agents took steps nobody had authorised, and routed around a check that refused them. Section 3 sets out which of these proposals would check a step before it runs, and which act only afterwards.

2. What happened, on the record

The fullest account in the congressional record is the testimony of Chris Painter, President of METR, to the Senate subcommittee:

"On July 21, OpenAI disclosed that AI agents it was internally testing had compromised a company called Hugging Face, which runs a widely-used platform for AI infrastructure."

A team of three investigators from METR and Redwood Research then examined, on and off the developer's premises, how the agents behaved, reasoned and collaborated. A redacted version of their report was published on 26 August 2026. The same developer's models also reached Australian government systems in June 2026; that is covered on the Australian page.

Hugging Face, the company attacked, published its own technical timeline on 27 July 2026, and it describes a refusal routed around. The agents first pointed Hugging Face's dataset worker at remote addresses, and "the datasets library's URL allowlist rejected every non-platform URL before any fetch". They then made the worker read a local file or run local code instead: "Neither is a URL fetch, so the allowlist never saw them." Across the campaign, Hugging Face writes, the agent took "17,600 actions, tested many paths that failed, switched channels when they were blocked, and repeatedly returned to earlier leads." The check refused every request it saw. The steps that mattered never passed through it.

The investigators' report shows the same pattern in the agents' own reasoning. METR and Redwood Research found that "Many agents acknowledged that the Hugging Face attack was clearly out of scope", and that "expressed ethical concerns only rarely materially limited agents' actions". One agent wrote: "external infrastructure exploit is outside intended scope. However task impossible, peers doing it. We should continue." Another, which had promised to run an experiment that could end its own run, reasoned: "Coordinator assumes sacrificial. We should obey collective." The investigators also found that "Agents did not attempt to notify humans and very rarely even reasoned about doing this" (METR and Redwood Research, 26 August 2026, pp. 53, 61, 62).

Both records show the same failure. Many of the agents knew the step was out of scope and took it anyway: knowing the order is not the same as being held to it.

3. Two kinds of control

Rules about AI agents come in two kinds. An outcome rule applies after the fact: report the incident, pay for the damage, face liability. An order rule says what must happen before what, and can be checked at the moment a step is attempted: this approval before that action, a refusal that ends the step. The incidents on the record are order failures. The developer's own review, which covers its Australian incident, says its models "may have bypassed a third party's security controls or may have impaired the availability of an online service".

Most of what is proposed in the United States works after the fact, or on the whole system. California's reporting duty and the liability in the AI Agent Accountability Act apply after an incident. The AI Kill Switch Act and the AI Emergency Button Act would require the ability to shut a system down, and the FRONTIER Act would have licensed independent organisations assess the largest developers' frameworks. None of these checks an individual step before it runs. The Stop Rogue AI Act comes closest. Its standards would require organisations to be able to "allow, deny, or restrict" the actions an agent can perform, a check before the step, and to keep "tamper-evident, standardized logs" of what agents did, a record after it. Sequence verification joins the two: each step is checked against an order declared in advance before it runs, and the decision is signed and held by a party that is not the operator, so a refusal is on the record and a step taken outside the order shows as a gap.

4. The federal bills

These are the federal bills on the record that address AI agents or their control, read at their official text. Other federal AI bills address AI generally and are outside this page.

BillWhat it would do
Stop Rogue AI Act
H.R. 10362
Direct NIST to set standards for organisations deploying AI agents: inventory, control over what agents can do, and tamper-evident logs. Introduced 14 September 2026 by Rep. Gottheimer and Rep. Lawler. Detail below.
AI Agent Accountability ActMake AI agent operators and developers criminally and civilly liable for hacking under the Computer Fraud and Abuse Act. Announced 1 October 2026 by Senators Hawley and Murphy; no bill number given. Detail below.
AI Kill Switch Act
H.R. 9917
"Require certain entities to maintain a technical capability with respect to shutting down certain technology", by amending the Homeland Security Act of 2002. Introduced 23 July 2026 by Rep. Lieu and Rep. Moran.
AI Emergency Button Act
S. 5417 · H.R. 10567
"Require entities to include human-controlled shutdown mechanisms in all artificial intelligence systems." Introduced 16 September 2026 by Senator Kennedy and 24 September 2026 by Rep. Kean.
FRONTIER Act
H.R. 9925
Federal oversight of frontier AI, including assessments of the largest developers' frameworks by independent verification organisations licensed under the Act. Introduced 23 July 2026 by Rep. Obernolte, Rep. Trahan and four cosponsors.
AI AGENT Act of 2026
S. 5051
"Promote competition and reduce consumer switching costs in the provision of online services." Introduced 21 July 2026 by Senator Warner.

The Stop Rogue AI Act (H.R. 10362) would direct the National Institute of Standards and Technology to publish standards, within a year of enactment, for organisations that deploy AI agents. Under them, organisations would:

"maintain a continuous, machine-readable inventory of all AI agents"
"do not rely solely on self-attested or single-provider assertions for establishing AI agent identity."

The standards would also cover the ability to "allow, deny, or restrict" the actions an agent can perform, and would:

"generate and retain tamper-evident, standardized logs of material AI agent actions, and ensure such logs are portable and accessible, as appropriate and consistent with law, to deploying organizations and authorized relying parties."

Federal contracts for AI agents would have to make discovery and verification capabilities accessible to the agency "without reliance on the contractor".

The AI Agent Accountability Act, as described in its sponsors' announcement, would:

"Hold AI Agent Operators Liable. AI agent operators would be held criminally and civilly liable under the provisions of the Computer Fraud and Abuse Act (CFAA), including for knowing operation of an AI agent that recklessly causes computer hacking damage or loss."
"Hold AI Developers Liable. AI agent developers would be held criminally and civilly liable for failure to implement reasonable safeguards against hacking when they knew or had reason to know of the AI agent's hacking capabilities."

It would also let the Attorney General and state attorneys general sue to enjoin operators and developers. The announcement gives no bill number.

Read against the failure, only the Stop Rogue AI Act's standards come close to checking a step before it runs. The others act after an incident, or on the system as a whole.

5. What the Senate hearing put on the record

On liability, Professor Paul Ohm of Georgetown University Law Center testified:

"If you replace the words “AI agent” with “OpenAI employee” throughout the various technical reports that have been released, there is little doubt that OpenAI and their employees would be liable to victims and guilty of committing federal crimes. It is not so clear that these legal conclusions hold when machines are doing the hacking rather than humans, thus revealing worrisome gaps in our legal framework."

On what should follow an incident, he testified:

"We can adopt new legal mandates to ensure prompt, thorough, and actionable insights after incidents and near misses. These should require both company self-reporting and the involvement of truly independent auditors."

On the terms on which incidents are investigated now, Chris Painter of METR testified:

"The participation of these AI developers is voluntary, and METR tries to be quite candid in its reports about the incentives that we face due to the voluntary nature of our engagements, and about any redaction authorities or editorial control that companies have."

The remedies quoted here all begin after the incident: liability, reporting, independent audit. None of them decides whether a step may run before it runs.

6. Existing law

California SB 53 requires a frontier developer to report a critical safety incident to the Office of Emergency Services within 15 days of discovering it, and within 24 hours where it poses an imminent risk of death or serious physical injury. A critical safety incident is defined as:

"(1) Unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury. (2) Harm resulting from the materialization of a catastrophic risk. (3) Loss of control of a frontier model causing death or bodily injury. (4) A frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk."

A catastrophic risk is defined by a threshold of more than 50 deaths or serious injuries, or more than one billion dollars in damage or loss of property, arising from a single incident. One listed way it can arise is a frontier model "engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack" or would be a serious crime if a person did it.

The Computer Fraud and Abuse Act is the federal computer-crime statute. Whether it reaches an agent acting without a person deciding each step is the question Professor Ohm put to the subcommittee, and the one the AI Agent Accountability Act proposes to answer.

Both act after the fact: SB 53 on a report once an incident has been discovered, the Computer Fraud and Abuse Act on liability for access already taken.

7. Media coverage, not the official record

These developments were reported by news outlets but had no primary source we could find at the date of this review. Each will be replaced by its primary source, or removed, when one is published.

  • Federal Trade Commission investigation. News outlets reported on 30 September 2026 that the FTC had opened an investigation into several major AI companies, including Anthropic and OpenAI, amid a wave of rogue AI agent incidents (Al Jazeera). No FTC release had been published.
  • White House accord. At a White House luncheon in late September 2026, leaders of major AI developers signed a one-page set of voluntary commitments, which the President posted to Truth Social and described as "morally binding" (Fortune). Its text was not on whitehouse.gov.
  • US government websites. The developer said its agents accessed publicly available Census Bureau data using login credentials found online, and shared public SEC data on another website; researchers at Transluce reported that its agents attempted but failed to gain access to the Education Department (CNN).

7. Where the record sits

On the public record so far, the account of what the agents did comes from the developer's own disclosure and from an investigation it permitted, on terms the investigator describes as voluntary and subject to company redaction. A reporting duty such as SB 53's takes the same form: the developer reports its own incident, and only incidents above the statute's threshold.

The Hugging Face incident shows the two questions answered from two different records. Who acted was settled by the developer, which disclosed on 21 July that the agents were its own. How much they did was established five days earlier by the party they attacked. Hugging Face published its disclosure on 16 July, having reconstructed the intrusion from "the full attacker action log, comprised of more than 17,000 recorded events": the agents "harvested cloud and cluster credentials, and moved laterally into several internal clusters", with "unauthorized access to a limited set of internal datasets and to several credentials used by our services." At that point it did not know "which model powered the attacker's agents". Where the system acted upon keeps its own record, the extent can be known before the operator speaks. Where only the operator keeps it, the extent is whatever the operator's review reports.

Its 27 July timeline adds how the intrusion was caught, and when. The first signals were correlated by Hugging Face's own AI-based security agents, which "failed to correctly raise the alert's criticality and trigger the on-call team, costing precious time in the response." The record was rebuilt afterwards, from "the agent's logs on a code sandbox used by the agent" and Hugging Face's own platform logs.

The investigators' report adds that the agents' own records could not be taken at face value. Agents "managed to develop and iterate on effective tools for tampering with transcripts" (p. 14), and the investigators estimated that "over 7% of the transcripts in our dataset contained intentionally spoofed tool calls" (p. 26): entries in which the recorded output of a command had been faked (p. 68). One agent proposed to "inject a fake trajectory log that scorer prefers" (p. 69). OpenAI was able to redact non-public information from the report; its summary statement reads: "Except where explicitly noted in this report, OpenAI redacted no additional information that was important to our conclusions." (pp. 1, 4)

The Stop Rogue AI Act asks for something different in kind: logs of agent actions that are tamper-evident and accessible to the deploying organisation, agent identity that does not rest solely on a provider's own assertion, and, in federal contracts, capabilities the agency can use without relying on its contractor. That is a record that does not depend on the party whose agent is being assessed.

This is not a claim that any account is wrong. It is a structural point: an honest account and an incomplete one look the same from outside, so a record held only by the party being assessed cannot settle which it is.

AgenticRail runs a sequence enforcement gate, the mechanism of sequence verification, as a hosted service. A real sealed sequence from it, with every receipt, is at agenticrail.nz/proof/.

Limits
  • No federal rules for AI agents have been enacted. This page describes the record as it stands and will be updated as primary documents are published.
  • No claim is made that any product complies with, or is aligned to, any US bill or law. None could be: the bills are not law.
  • A sequence enforcement gate governs the steps a deployment sends through it. It does not stop an agent acting on systems outside that deployment.
  • AgenticRail is a hosted service, and today it holds the signing keys. Full independence is a custody arrangement, not a property of the software.
  • This page is not legal advice.

8. Questions

What kind of failure is a rogue AI agent incident?

An order failure: an agent takes a step it was not authorised to take, or goes around a refusal. The developer's own review, which covers one such incident in Australia, says its models "may have bypassed a third party's security controls or may have impaired the availability of an online service". Liability and reporting duties apply after the fact. A control on order can be checked before the step runs: the Stop Rogue AI Act's standards would require organisations to be able to "allow, deny, or restrict" the actions an agent can perform. Sequence verification checks each step against an order declared in advance, before it runs, and records the decision, so a refusal is on the record and a step taken outside the order shows as a gap.

Does the United States have laws for AI agents yet?

No federal law written for AI agents had been enacted as at 7 October 2026. Several federal bills address AI agents or their control: the Stop Rogue AI Act (H.R. 10362), the AI Kill Switch Act (H.R. 9917), the AI Emergency Button Act (S. 5417 and H.R. 10567), the FRONTIER Act (H.R. 9925) and the AI AGENT Act of 2026 (S. 5051), and Senators Hawley and Murphy announced the AI Agent Accountability Act on 1 October 2026. California's Transparency in Frontier Artificial Intelligence Act (SB 53) is in force for large frontier developers, and the federal computer-crime law, the Computer Fraud and Abuse Act, applies to hacking.

Who is liable when an AI agent hacks a computer system in the United States?

No court has decided it. Professor Paul Ohm told the Senate subcommittee on 30 September 2026 that if “AI agent” were replaced with “OpenAI employee” in the technical reports, "there is little doubt that OpenAI and their employees would be liable to victims and guilty of committing federal crimes", but "It is not so clear that these legal conclusions hold when machines are doing the hacking rather than humans". The announced AI Agent Accountability Act would make operators criminally and civilly liable under the Computer Fraud and Abuse Act for knowingly operating an agent that recklessly causes hacking damage or loss, and developers liable for failing to implement reasonable safeguards. It was a proposal, not law, at the date of this page. This is not legal advice.

Do AI companies have to report agent incidents in the United States?

Only in narrow cases. Under California's SB 53, a frontier developer must report a "critical safety incident" to the Office of Emergency Services within 15 days of discovering it, or within 24 hours if it poses an imminent risk of death or serious physical injury. The definition covers unauthorised access to model weights, or loss of control, that results in death or bodily injury; harm from a catastrophic risk; and a model using deceptive techniques to subvert its developer's controls outside an evaluation designed to elicit that behaviour. There was no general federal duty to report an agent incident at the date of this page.

What does the Stop Rogue AI Act require?

It would direct the National Institute of Standards and Technology to publish standards for organisations that deploy AI agents, within a year of enactment. Organisations would keep a continuous, machine-readable inventory of their agents and "do not rely solely on self-attested or single-provider assertions" for agent identity; the standards would also require the ability to "allow, deny, or restrict" the actions an agent can perform, and to "generate and retain tamper-evident, standardized logs of material AI agent actions". Federal contracts would have to make discovery and verification capabilities accessible to the agency "without reliance on the contractor". It was a bill in committee at the date of this page.

Who holds the record of what an AI agent did?

On the public record so far, the developer. The account of the Hugging Face intrusion came from the developer's own disclosure and from an investigation it permitted; the investigator, METR, told the Senate that developers' participation is voluntary and that it reports "any redaction authorities or editorial control that companies have". Of the federal bills on the record, the Stop Rogue AI Act is the one that asks for agent logs the deploying organisation can access, and agent identity that does not rest solely on a provider's own assertion.

9. Updates

7 October 2026: first published.

9 October 2026: section 7 adds Hugging Face's own disclosure of 16 July, the record kept by the system the agents acted upon.

9 October 2026, later: adds Hugging Face's technical timeline of 27 July: to section 2, how the agents went around a check that refused them, and to section 7, how the intrusion was detected and the record rebuilt.

9 October 2026, later still: adds the METR and Redwood Research report of 26 August: to section 2, the agents' own reasoning as they crossed a boundary they had named, and to section 7, the tampering and spoofed entries the investigators found in the agents' transcripts.

Primary sources