Axios covered another bipartisan AI bill that was introduced today by U.S. Representatives Josh Gottheimer (D-NJ) and Mike Lawler (R-NY). Within a year of its passage, the Stop Rogue AI Act would direct the National Institute of Standards and Technology (NIST) “to develop and publish standards, guidelines and best practices for how organizations can securely deploy AI agents.”
Per Axios, the required standards would concern evaluating AI agents, monitoring and logging their actions, protecting those logs from tampering, and tracking agent populations.
I see this as a positive development. As I’ve previously written, the AI industry has long lacked the robust technical standards that characterize mature industries.
This bill is one of several introduced after news of the Hugging Face attack smacked into Washington’s AI complacency like a wrecking ball. Others include the AI Kill Switch Act and the Secure AI Development Act, which my colleague Donald covered in July, and the FRONTIER Act.
Together, these bills indicate to me that U.S. leaders are rapidly waking up to the threats posed by AI. Many of their provisions are worthwhile in their own right, although (with one notable exception) they fall short of a full-blown halt.
On a related note, in early August U.S. Representative Greg Casar (D-TX) sent a public letter to OpenAI demanding answers on the Hugging Face incident, including a detailed log of the attacks and the events that led to it. OpenAI responded with a letter mostly rehashing its blog post about the incident and promising to monitor its own AI systems, to record their actions, and to develop unspecified “additional automated shutdown capabilities.”
Casar, evidently unimpressed, replied yesterday citing many of the same concerns I mentioned last week:
Providing hand-picked investigators six days of supervised access is not public release, and those investigators themselves flagged that they could not rule out errors in their AI-assisted analysis. I am deeply concerned about the limited scope of that investigation.
Casar goes on to cite a long list of questions from the original letter that remain unanswered, like “How many times OpenAI models have obtained unauthorized access to the internet” or “What became of the credentials and data the models took.”
I am deeply glad to see more of our leaders taking the risks seriously. Unfortunately, the window they have to act is narrowing, partly because dangerous capabilities proliferate. For example, last week the Chinese AI company Z.ai released the weights of GLM-5.3, an open model with advanced cyber capabilities (though not quite, as the company would have us believe, a rival to Anthropic’s Fable). Z.ai delayed the release for two weeks (an unusual occurrence), to complete “safety evaluation and hardening.”
Within days of the release, a different company scrubbed the safeguards out of that same model and released a guardrail-free edition, boasting on social media about “offensive cyber” capabilities and their server’s lack of logging.
As I put the finishing touches on this dispatch, OpenAI announced the staggered release of its latest model Astra. Open models tend to lag behind American frontier AI by around four months. Whatever frightening capabilities we see from Astra, they may be present in a guardrails-free open model by spring.
If the “Stop Rogue AI Act” passed Congress and was signed into law this very day, we’d still have to wait an entire year for any standards to kick in. At the rate AI companies are currently racing towards an unseen brink, that’s practically a lifetime. For this and other reasons, the most urgently needed AI policy is to slow the heck down.
The analyses and opinions expressed on AI StopWatch reflect the views of the individual contributors and the sources they cover, and should not be taken as official positions of the Machine Intelligence Research Institute.



