The AI AGENT Act discussion draft builds a registration, disclosure, and revocation architecture for AI agents acting on a person's behalf. The Name Standard℠ asks the board-facing question the draft leaves open: who authorized the agent to act, under what conditions, and who remains accountable when it selects its own path?
On June 29, 2026, Senator Mark R. Warner (D-VA) released a discussion draft of the Artificial Intelligence Access, Gatekeeper Exchange, and Nondiscriminatory Transfer Act — the AI AGENT Act — proposing a federal framework for AI agents that act on a person’s behalf online. The draft creates a new legal category, the “custodial user agent,” and builds registration, documented delegation, record-keeping, and revocation requirements around it, administered by the Federal Trade Commission.
Most content aimed at board secretaries, corporate governance officers, and reporting executives falls into one of two categories: dense legal compliance checklists or software feature pitches. Our focus is the operational reality of mapping a new AI law or discussion draft to internal accountability before it becomes board-facing evidence. We begin every evaluation using Disclosure-Independent Governance℠ — Lozen Advisory’s methodology for identifying systemic risks that legacy measurement systems are structurally blind to. The Name Standard℠ turns “who is accountable” into a testable board-facing question.
Why this matters for board readiness and reporting
If your organization operates a custodial user agent, provides one to consumers, or relies on third-party custodial agents to manage delegated online activity, the duties in Section 3(g) may become board-facing evidence questions — usually after an incident, not before one.
The draft specifies what a compliant agent must do. It does not specify who inside the organization authorized its operating domain, accepted its permissions and limits, approved the conditions under which it could act, or retained responsibility when the agent selected an unauthorized path. That is the reporting gap the organization inherits.
Mapping the Name Standard℠ to the AI AGENT Act
| Name Standard℠ Pillar | AI AGENT Act Provision | Board-Facing Evidence Question |
|---|---|---|
| Time Allocation | No direct statutory anchor. Sec. 3(g)(1)(D) sets an ordinarily-prudent-person standard of care for the agent’s conduct — it does not require that any human be assigned verification time or responsibility. | Sec. 3(g)(1)(D) sets a standard. It does not assign the review time needed to verify whether the agent remains within its authorized domain. Has your organization allocated verification time, or is the standard-of-care clause carrying weight the statute never assigns to it? |
| Review Capacity & Tools | Sec. 3(d)(4) — Recognized Certification Bodies may maintain standards and conduct periodic assessments of conformity with custodial user-agent duties. | A certification body can create external conformity evidence, but it is not a standing internal review function. Who has the tools, source data, subject-matter competence, and intervention authority to evaluate agent conduct between assessment cycles? |
| Information Access | Sec. 3(g)(1)(A), (C) — user-data safeguarding and limits on collection, use, sharing, retention, and secondary commercial use. | The Act protects user-data use, but it does not create a model-provenance or operating-conditions record. Who can identify the models, vendors, permissions, tools, data sources, and environmental changes that shaped the agent’s conduct? |
| Documentation Infrastructure | Sec. 3(g)(1)(E) — real-time records of actions taken on the user’s behalf, available to the user on request, except records the user has directed the agent to delete. | Are the agent’s actions logged in real time, and can the record reconstruct the objective, permissions, tool access, system path, intervention points, and human decisions that allowed the conduct to occur? |
| Formal Right of Refusal | Sec. 3(c)(2) — user revocation of delegation; Sec. 3(f) — platform revocation or denial of agent access. | The Act lets a user revoke delegation and a platform revoke or deny access in specified circumstances. It does not create a named internal role with standing authority to pause, restrict, escalate, or terminate agent activity. Who can stop the system, and is that authority usable under operational pressure? |
For the board-level argument on why the Act’s behavioral duties cannot be evidenced through policy language alone — including sycophancy, confabulation, and drift — see The AI Agent Act: The Board Evidence Gap in AI Loyalty.
When the agent selects the action
The Name Standard℠ cannot stop at asking whose name appeared on a final decision. In agentic systems, no human may have selected the specific action that caused the incident.
The more precise question is:
Who authorized the system to act within this domain, under these capabilities, permissions, objectives, and limits — and who remained responsible when it selected an unauthorized path?
Human and institutional attribution may attach to several distinct governance acts:
- authorization to deploy or run the agent;
- acceptance of its operating environment and containment design;
- approval of its permissions, tools, and safeguards;
- monitoring responsibility;
- intervention and shutdown authority;
- acceptance of residual risk;
- incident-response ownership.
The agent may be the immediate actor. That does not eliminate human or institutional accountability. It moves the accountability inquiry upstream, to the conditions of delegated agency and the people or bodies that authorized, constrained, monitored, and retained control over those conditions.
The Lozen Advisory view
Measured against the Name Standard℠, this AI AGENT Act draft is strongest where it is most concrete: Sec. 3(g)(1)(E)‘s real-time record requirement gives Documentation Infrastructure a genuine statutory home. That is one pillar out of five.
The Act sets a standard of care for agent conduct without assigning verification time or responsibility. It allows certification bodies to create external conformity evidence without creating a standing internal review function. It protects user-data use without creating a record of the full operating conditions that shaped agent behavior. It allows user or platform revocation without creating an internal refusal and intervention authority inside the custodial user-agent provider.
For board secretaries and governance officers, that asymmetry is the real takeaway. A certification, a data-security policy, and a real-time log can all exist correctly while leaving the board’s central question unanswered: who authorized this agent to act, who could intervene, and who remains accountable when it exceeds the path anyone intended?
For four of five pillars, this draft does not answer that question. The answer must come from the organization’s own governance structure, not the statute.
For the broader board governance gaps this legislation enters, see Four AI Governance Gaps Boards Are Missing Right Now.
Lozen Advisory’s Board AI Name Standard Advisory evaluates whether delegated AI authority remains attributable, reviewable, interruptible, and supported by evidence the board can rely on.