What NCCoE released
On 5 February 2026, the NIST National Cybersecurity Center of Excellence (NCCoE) published a concept paper titled Accelerating the Adoption of Software and Artificial Intelligence Agent Identity and Authorization. The NIST announcement described it as a proposal exploring how existing identity standards and best practices can be applied to AI agent deployments. This document is a concept paper proposing a potential project, not a final standard or published guidance.
Scope and key questions
The concept paper sought public input on several areas, as listed in the announcement:
- Use cases: how organisations are currently deploying or planning to deploy AI agents.
- Challenges: what problems AI agents introduce that differ from conventional software.
- Standards: which identity and access management standards teams are applying.
- Technologies: what tooling supports AI agent identity and authorisation.
- Specific questions on the identification, authorisation, auditing and non-repudiation of AI agents, and on controls to prevent and mitigate prompt injection.
The framing centres on applying existing standards rather than proposing new ones. The explicit inclusion of auditing, non-repudiation, and prompt injection controls in the same list is notable for those following agent security. Our reading is that an audit should examine both an agent's granted permissions and the evidence that connects those permissions to its actions.
Status as of September 2026
The public comment period ran through 2 April 2026 and is now closed. The NCCoE project page, checked 16 September 2026, lists the project status as Reviewing Comments and states that the comment period is closed. Readers should treat the concept paper as a record of the questions NCCoE considers important for this domain, with the project's next steps subject to that review.
- NIST announcement: 5 February 2026
- NCCoE project page: nccoe.nist.gov
Follow Audit Commons
Keep up with new reporting, practical guides, and resources in your feed reader.