NIST: AI Agent Standards Initiative
Echoing our previous input on NIST's AI 600-1 Generative AI Profile and the AI Risk Management Framework, we contributed input to NIST's AI Agent Standards Initiative, including components related to the adoption of AI Agent identity and authorization and security. Launched February 17, 2026 by NIST's Center for AI Standards and Innovation (CAISI), the Initiative marks the first federal programmatic effort specifically targeting the governance of autonomous AI agents, systems capable of planning and taking real-world action rather than simply generating content.
Update: We have also joined CAISI's Listening Sessions on Barriers to AI Adoption, held as part of the Initiative.
Related
NIST AI Agent Standards Initiative
The Initiative is organized around three strategic pillars. The first is facilitating industry-led development of agent standards and asserting U.S. leadership within international standards bodies such as ISO/IEC JTC 1. The second is fostering community-led, open-source protocol development for agent interoperability, co-invested with the National Science Foundation. The third is advancing research on agent security and identity to enable trusted adoption across sectors. CAISI, working alongside NIST's Information Technology Laboratory (ITL), framed the effort as necessary because AI agents can now operate autonomously for extended periods, calling external tools, spawning sub-agents, and persisting state across sessions, use cases that fall outside the scope of NIST's existing published guidance.
The Initiative builds directly on prior NIST work rather than starting from a blank slate. AI RMF 1.0, published as voluntary guidance in January 2023, and AI 600-1, the Generative AI Profile published in July 2024, together established over 200 risk actions across twelve categories, but were designed around systems that generate text, images, or recommendations rather than systems that autonomously execute multi-step workflows with real-world consequences.
The Initiative's components address that gap directly. CAISI's Request for Information on securing AI agent systems, issued January 12, 2026, sought input on threats such as indirect prompt injection, data poisoning, and specification gaming. The NCCoE's concept paper on Software and AI Agent Identity and Authorization proposed adapting identity standards, including OAuth 2.0 extensions, to treat agents as distinct non-human principals requiring lifecycle management. The draft NIST AI 800-2, opened for comment, set out preliminary best practices for automated benchmark evaluations of language models and agent systems. Together with the sector-specific listening sessions on barriers to AI adoption launched the same February, these components form a coordinated effort to extend the GOVERN/MAP/MEASURE/MANAGE structure of the AI RMF into the distinct risk profile of autonomous agents.
References
¹ National Institute of Standards and Technology. "Announcing the AI Agent Standards Initiative for Interoperable and Secure Innovation." NIST. February 17, 2026.
² National Institute of Standards and Technology, National Cybersecurity Center of Excellence. "Accelerating the Adoption of Software and AI Agent Identity and Authorization." Concept Paper. February 2026.
³ National Institute of Standards and Technology. "CAISI Issues Request for Information About Securing AI Agent Systems." NIST. January 12, 2026.
⁴ National Institute of Standards and Technology. "Towards Best Practices for Automated Benchmark Evaluations: NIST AI 800-2 (Initial Public Draft)." NIST. January 30, 2026.
⁵ National Institute of Standards and Technology. "AI Risk Management Framework (AI RMF 1.0)." NIST. January 2023.
⁶ National Institute of Standards and Technology. "Generative AI Profile (NIST AI 600-1)." NIST. July 2024.