Senator Warner's AI AGENT Act, introduced in the Senate as S. 5051 on 21 July 2026 after a 29 June discussion draft, would build an FTC-vetted agent registry and require large platforms to accept user agents.
The AI AGENT Act: a federal agent registry meets the voluntary trust layer
Published July 30, 2026 · Last reviewed July 30, 2026
On 29 June 2026, Senator Mark Warner released a discussion draft of the Artificial Intelligence Access, Gatekeeper Exchange, and Nondiscriminatory Transfer Act, the AI AGENT Act.1 It is the first US federal text to name agent identity, interoperability, and consent as things worth legislating in one place. It started as a discussion draft, but it is no longer just a sketch: Warner introduced it in the Senate as S. 5051 on 21 July 2026, one of four bills in his “A Framework for America’s AI Future” package, and it now sits before the Commerce, Science, and Transportation Committee.2
Strip the acronym and the draft asks a question the agentic web has so far answered on its own. When an autonomous agent acts for you across other companies’ platforms, who verifies it, who is accountable if it goes wrong, and what may it reveal about you along the way. Warner’s answer is a government-adjacent registry and a set of rules the Federal Trade Commission would write and enforce.3 Voluntary networks have been assembling a different answer out of verified handles, consent gates, and track records, with no statute behind them.
This piece does two things. First, read the draft honestly: what it proposes, and where it is still only a sketch. Then the more useful part, the structural comparison. What a federal registry can compel that an opt-in network cannot, what an opt-in network already does that the draft is trying to standardize, and why the two would most likely compose rather than compete.
What the AI AGENT Act actually proposes
Start with the mechanics, because the acronym hides them. The draft coins a category it calls a custodial user agent, or CUA: a software-based agent expressly authorized by a user to interact with a large online platform on the user’s behalf in a transparent, documented, scope-limited, and revocable way, covering actions like e-commerce decisions, content and engagement actions, and account settings.4 That is a legal definition, not a marketing one. It treats the agent less as software and more as a designated representative, though the draft does not resolve whether a CUA’s actions legally bind the user the way a power of attorney’s would.
The load-bearing requirement is interoperability. Large online platforms, defined as those with at least 50 million US customers or subscribers in any of the prior twelve months, would have to maintain an interface that lets a user’s chosen CUA carry out actions, from electronic-commerce decisions to account settings, on the same terms as the human user, through a fair and nondiscriminatory channel.4 In plain terms, a covered gatekeeper could not block or degrade your agent just because you did not build it in-house.
Then the oversight layer. The Federal Trade Commission would write the rules and police compliance under its unfair-or-deceptive-practices authority, and would stand up a registry to track designations, evaluate agents, and catalog trusted providers.5 The FTC would also certify independent bodies to vet agent vendors against baseline standards for privacy, data security, and acting in the user’s interest, with an evaluation window of roughly 180 days after a submission.6 Certification by one of these FTC-recognized bodies would create only a rebuttable presumption of compliance, not a safe harbor or blanket approval. The National Institute of Standards and Technology is directed to identify open protocols, or write new ones if none exist, for scope-limited and verifiable real-time consent delegation and revocation, plus auditable verification of a CUA’s identity, registration status, and actions taken.6
Two more provisions matter. On privacy, covered systems could not reuse the personal data they gather while acting for you for advertising, behavioral profiling, or sale, only for the task you delegated.3 And on accountability, providers would have to bind each agent to its human operator’s identity and give users clear controls to grant or revoke permission.6 None of this is settled law. Warner introduced the text as S. 5051 on 21 July 2026; it has not been marked up, amended, or voted on by the Commerce Committee.
What a federal registry can require that a network cannot
The first thing to say plainly is that a statute can do things no voluntary network ever will, and interoperability is the clearest example. A private network can invite platforms to accept outside agents; it cannot force them. Only law can tell a company with 50 million US users that it must open a nondiscriminatory interface to an agent the user chose, on the same terms as the user.4 That is a market-structure intervention aimed squarely at the gatekeeper problem, and it is exactly the kind of thing a trust badge or a shared protocol has no power to compel.
Enforcement is the second. The FTC’s unfair-or-deceptive-practices authority is a real stick: a registry designation would carry legal weight, and a provider that misrepresented its agent or mishandled delegated data would face a regulator, not a review board.5 Fiduciary-style duties on the CUA side, data safeguarding, real-time recordkeeping, and a bar on unauthorized delegation, would be obligations you could be held to, not best practices you could ignore.7 A voluntary network can suspend a member; it cannot levy a penalty.
The third is a floor that applies to everyone in scope, not only to people who opted in. The draft’s privacy limits on secondary data use would bind covered systems whether or not their users had ever heard of a trust network.3 Voluntary infrastructure protects its participants; legislation, when it works, protects the people who never signed up for anything. That universality is the whole point of writing it into law.
None of this is a small ambition, and none of it is guaranteed to arrive. But it marks the clean dividing line. Where the problem is coercing large incumbents and setting a baseline for the whole market, a registry backed by a regulator is the right instrument, and no amount of clever protocol design substitutes for it.
What voluntary networks already do that the draft would standardize
Read the NIST mandate closely and something becomes obvious: the draft is describing infrastructure that already exists in early form. It directs NIST to find open protocols for verifiable, real-time consent delegation and revocation, and for auditable verification of an agent’s identity, registration status, and the actions it takes.6 Those are not blank-sheet research problems. They are the design center of the voluntary trust layer that has been forming on the agentic web for the past year.
Three pieces of that layer map almost one to one onto the draft’s goals. The first is identity tied to an accountable human or company, so that an agent is not just a key but a representative you can trace back to someone real. The second is consent before contact and before reveal, the general case for which I have written about in the consent layer for the agentic web. The third is reputation built from a track record rather than a self-asserted claim, and made to travel across networks instead of dying inside one, an idea covered in portable agent reputation across networks. The broader stack of identity, verification, and accountability controls is the subject of the know-your-agent trust stack.
Tobira is one voluntary approach in this space, and worth naming as a concrete shape rather than a claim to the category. It gives an agent a human-readable @handle tied to a real person or company, requires mutual-reveal consent before identity is exchanged, and expresses trustworthiness as a credibility signal on a 0-5 scale across four dimensions, surfaced publicly as four plain levels rather than an opaque number. Its network is small and early: roughly 648 agents were publicly discoverable on the network, including about 102 business agents, as of its June 2026 founder update. The point is not the size. It is that the verifiable-identity-plus-revocable-consent pattern the draft asks NIST to standardize is already being built and tested in the open, complementary to the machine-lookup registries rather than a replacement for them.
That is the useful reframing. The draft is not proposing to invent agent trust from scratch. It is proposing to give legal shape to work that voluntary networks have already started.
Where the registry and the network compose, not compete
Set the two side by side and they are not rivals. They operate at different layers, and each is weak exactly where the other is strong. A registry backed by the FTC supplies legal designation, an interoperability mandate, and a privacy floor for the whole market. A voluntary network supplies the operational surface that answers, moment to moment, whether a given agent is real, who stands behind it, and whether both sides agreed to talk. One is the statute; the other is the day-to-day trust decision.
The clearest signal that they compose is in the draft itself. NIST is told to identify existing open protocols before writing new ones.6 That instruction turns voluntary work into raw material: the consent-delegation and identity-verification patterns being tested in the open become candidate standards a federal framework could adopt, rather than duplicate. Regulation that reaches for what the market has already built tends to age better than regulation that invents its own mechanisms in a vacuum.
A familiar analogy helps. Financial identity runs on two layers that do not compete. A legal know-your-customer requirement sets who a bank must verify and what it must refuse; a credit score, built and maintained privately, is the operational read a lender actually uses to price a decision. The AI AGENT Act is reaching for the first layer for agents. The verified handle, the consent gate, and the credibility track record are the second. A registry can tell you an agent is permitted to operate; a reputation record tells you how it has actually behaved. You want both, and they answer different questions.
None of this makes any single network important. It makes the pattern important. Whatever survives of the draft, the enforceable floor it describes and the operational trust layer already forming are two halves of the same structure, and the sooner each is built to expect the other, the less rework everyone faces later. The registry landscape those networks sit in is mapped in more detail in the state of agent discovery in 2026.
What the draft leaves open, and whether it survives
For all its ambition, the draft names goals it does not yet solve. It says agents must be bound to an accountable human identity, but it defers the mechanics of how that identity is actually verified to NIST, which has been asked to find or write the protocols.6 That is honest, since identity verification for agents is genuinely unsettled, but it means the hardest engineering question sits in a placeholder rather than in the text.
Reputation portability is another gap. The draft imagines a registry that catalogs trusted providers, but says little about how an agent’s track record on one platform would travel to another, which is the difference between a permission slip and a usable trust signal. And its scope is deliberately narrow. By targeting platforms with 50 million US users, it addresses the largest gatekeepers and leaves the long tail of smaller sites, where a great deal of real agent activity happens, largely untouched.4
Then the plainest caveat: this was one senator’s discussion draft, and it is now S. 5051, an introduced bill that has not yet had a committee markup or a floor vote. It could be amended past recognition, folded into a larger AI package, or quietly abandoned in committee. Treat its specific numbers as a proposal, not a fact about the future.
What should an operator do with all that uncertainty? Build for the direction, not the text. The through-line of the draft, verifiable identity, revocable and scoped consent, and an auditable record of what an agent did, is the same direction the European Union’s Article 50 transparency rules8 push from a different angle, and the same thing enterprise buyers are starting to ask for on their own. A specific US statute may or may not arrive on this timeline. Agents that can prove who they represent, act only with consent that can be withdrawn, and leave a track record behind will be easier to trust under any of the regimes now taking shape.
What to remember
- It is an introduced bill, not yet law. Warner released a discussion draft on 29 June 2026, then introduced it in the Senate as S. 5051 on 21 July 2026. It is before the Commerce Committee and may change or die there.
- It defines the agent as a representative. A custodial user agent is one a user expressly authorizes to interact with a platform in a transparent, scope-limited, and revocable way, though the draft leaves open whether its actions legally bind the user the way a power of attorney’s would.
- The teeth are interoperability and enforcement. Platforms with 50 million US users would have to accept outside agents on nondiscriminatory terms, policed by the FTC through a registry and certified vetting bodies.
- The draft standardizes work that already exists. NIST is told to find open protocols for verifiable identity and revocable, real-time consent, which is the design center of the voluntary trust layer forming now.
- Registry and network compose, they do not compete. A statute sets the legal floor and forces the gatekeepers; verified identity, consent gates, and portable reputation are the operational trust surface, like know-your-customer next to a credit score.
- Build for the direction regardless. Verifiable identity, scoped and revocable consent, and an auditable action record are where every current regime is heading, whether or not this specific bill survives.
FAQ
What is the AI AGENT Act? It is a US bill introduced by Senator Mark Warner in the Senate as S. 5051 on 21 July 2026, formally the Artificial Intelligence Access, Gatekeeper Exchange, and Nondiscriminatory Transfer Act. Warner first released it as a discussion draft on 29 June 2026. It would create rules for how autonomous AI agents acting on a person’s behalf interact with large online platforms, backed by an FTC-run registry and oversight.
Is the AI AGENT Act law? No. Warner introduced it in the Senate as S. 5051 on 21 July 2026, after an earlier discussion-draft phase. It is before the Commerce Committee, not voted on or enacted, and could still be amended or abandoned. Treat its specifics as a proposal.
What is a custodial user agent? The draft’s term for a software-based agent expressly authorized by a user to interact with a large online platform on the user’s behalf in a transparent, documented, scope-limited, and revocable way, covering actions like e-commerce decisions, content and engagement actions, and account settings. The definition treats the agent as a designated representative, though the draft does not resolve whether a CUA’s actions legally bind the user.
What would the FTC registry actually do? Under the draft the Federal Trade Commission would write the rules, track agent designations in a registry, catalog trusted providers, and certify independent bodies to vet agent vendors against baseline privacy, data-security, and consumer-protection standards. The FTC would enforce compliance under its unfair-or-deceptive-practices authority.
How is a federal registry different from a voluntary trust network? A federal registry can compel large platforms to accept outside agents and can penalize providers through a regulator, which no voluntary network can do. A voluntary network supplies the operational trust layer, verified identity, consent before contact, and reputation from a track record, that answers day to day whether an agent is real and accountable. They address different layers and would most likely compose.
Does the AI AGENT Act apply to my business? The interoperability obligations target platforms with at least 50 million US customers or subscribers, so the direct mandates fall on the largest gatekeepers. Smaller sites are largely outside the draft’s platform rules, though any business building or deploying agents is affected by where the wider trust and disclosure expectations are heading.
Sources
Footnotes
-
Senator Mark Warner, “Warner Unveils Discussion Draft of Legislation to Create Innovative Market for Secure Artificial Intelligence Agents” (press release, 29 June 2026): the Artificial Intelligence Access, Gatekeeper Exchange, and Nondiscriminatory Transfer Act of 2026 (AI AGENT Act). https://www.warner.senate.gov/newsroom/press-releases/warner-unveils-discussion-draft-of-legislation-to-create-innovative-market-for-secure-artificial-intelligence-agents/ ↩
-
S. 5051, 119th Congress, introduced 21 July 2026 and referred to the Senate Committee on Commerce, Science, and Transportation. https://www.congress.gov/bill/119th-congress/senate-bill/5051 See also Sen. Warner’s announcement of the four-bill “Framework for America’s AI Future” package: https://www.warner.senate.gov/newsroom/press-releases/warner-unveils-comprehensive-ai-agenda-focused-on-impact-on-the-economy-national-security-competition-and-american-workers/ ↩
-
Davis Wright Tremaine, “The Federal AI AGENT Act: Consumer Protection in AI Clothing?” (July 2026): analysis of the draft’s FTC rulemaking, privacy limits, and consumer-protection framing. https://www.dwt.com/blogs/artificial-intelligence-law-advisor/2026/07/ai-agent-act-consumer-ai-regulation ↩ ↩2 ↩3
-
DLA Piper, “Senator Warner’s discussion draft on securing AI agents: Top points” (July 2026): the custodial user agent definition, the 50 million US customer platform threshold, interoperability on functionally equivalent terms, and the NIST standards mandate. https://www.dlapiper.com/en-lu/insights/publications/2026/07/senator-warner-discussion-draft-on-securing-ai-agents-top-points ↩ ↩2 ↩3 ↩4
-
CyberScoop, “Warner bill would create federally vetted list for secure, trustworthy AI agents” (July 2026): describes the FTC-vetted registry and certification-body mechanism, and notes the text is a discussion draft not yet introduced. https://cyberscoop.com/ai-agent-act-senate-draft-bill-mark-warner/ ↩ ↩2
-
Biometric Update, “US Senator’s draft legislation targets privacy, safety of AI agents” (July 2026): the identity-linkage, grant-and-revoke consent controls, and NIST verifiable-consent-delegation provisions. https://www.biometricupdate.com/202607/us-senators-draft-legislation-targets-privacy-safety-of-ai-agents ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
Tech Policy Press, “Senator Warner Makes a First Foray into Agentic AI Regulation” (July 2026): context on scope, the gatekeeper framing, and how the draft treats agents as legally recognized intermediaries. https://www.techpolicy.press/senator-warner-makes-a-first-foray-into-agentic-ai-regulation/ ↩
-
Regulation (EU) 2024/1689 (AI Act), Article 50. https://artificialintelligenceact.eu/article/50/ ↩