Skip to main content
v2026.11,858 entries · CC-BY 4.0

NIST’s AI Agent Standards Initiative: What It Covers and Its Current Status

NIST’s Center for AI Standards and Innovation launched the AI Agent Standards Initiative in February 2026 to cover AI agent security, identity, and authorization — separate from the AI RMF. Here is what it actually covers and its current status.

Written and maintained by CASRAI Editorial Board

Last updated

In February 2026, NIST’s Center for AI Standards and Innovation (CAISI) formally launched the AI Agent Standards Initiative — a dedicated program for AI agent security, identity, and authorization, distinct from NIST’s broader AI Risk Management Framework (AI RMF). As of this writing, the Initiative has moved past its opening request for public input but has not yet published a finalized standard or set of guidelines; its identity-and-authorization work is running as an active NCCoE concept-paper project. This page covers what the Initiative actually covers, its timeline so far, and how it differs from the AI RMF.

What the AI Agent Standards Initiative covers

NIST describes the Initiative’s purpose as ensuring “a trusted, interoperable, and secure agentic frontier.” Its published scope centers on three areas: agent security, agent identity and authorization infrastructure, and reliable agent-to-system and multi-agent interactions. NIST’s own framing states that it “conducts fundamental research into agent authentication and identity infrastructure to enable secure human-agent and multi-agent interactions” — language that ties the Initiative directly to the mechanics of letting an autonomous agent act on a person’s or organization’s behalf: proving who (or what) it is, and constraining what it is authorized to do.

That scope is narrower and more technical than it might sound. It is not a governance framework for deciding whether to deploy agents, and it is not a risk-management process. It is a standards-and-research effort aimed at the identity, authentication, and security plumbing that agentic systems need to interoperate safely.

The timeline so far

The Initiative did not appear as a single announcement; it has developed through a specific, dated sequence of NIST and CAISI actions:

  • January 12, 2026 — CAISI issued a Request for Information (RFI) on securing AI agent systems (docket NIST-2025-0035), asking industry, academia, and security researchers for input on five areas: security threats unique to AI agents, securing development and deployment, gaps in existing cybersecurity approaches, security measurement, and deployment-time interventions such as constraining and monitoring agent access in production.
  • March 9, 2026 — the RFI’s public comment window closed.
  • February 5, 2026 — NIST’s National Cybersecurity Center of Excellence (NCCoE) announced a draft concept paper, “Accelerating the Adoption of Software and AI Agent Identity and Authorization,” describing a demonstration project on applying identity standards and best practices to software agents, with a focus on agentic AI applications.
  • February 17, 2026 — NIST formally announced the AI Agent Standards Initiative as an umbrella program tying this work together.
  • May 18, 2026 — CAISI published “Analysis of Responses to the Request for Information Regarding Security Considerations for AI Agents,” summarizing what respondents told NIST during the RFI comment period.

That sequence matters for assessing where the Initiative actually stands: the RFI-and-response-analysis step is complete, but the identity-and-authorization work is documented as a draft concept paper and demonstration project, not a finished standard.

The three pillars

NIST organizes the Initiative’s ongoing work around three stated pillars:

  • Industry-led standards. NIST convenes technical discussions and gap analyses with industry, and represents U.S. interests in international standards-setting bodies working on agent interoperability.
  • Community-led open protocols. The National Science Foundation is investing in this pillar through its “Pathways to Enable Secure Open-Source Ecosystems” program, aimed at supporting open-source agent protocols rather than NIST authoring a protocol itself.
  • Targeted research. NIST and NCCoE are funding and conducting research on agent authentication, identity infrastructure, and security evaluation methods — the strand that produced the identity-and-authorization concept paper above.

How this differs from the AI Risk Management Framework

The AI Agent Standards Initiative is easy to confuse with the NIST AI Risk Management Framework (AI RMF), since both are voluntary, both come from NIST, and both now get discussed under the same “agentic AI” heading. They are not the same effort:

  • The AI RMF 1.0 was released January 26, 2023, led by NIST’s Information Technology Laboratory (ITL) AI Program. It is a general-purpose framework — organized around the Govern, Map, Measure, and Manage functions — for managing risk across AI systems broadly. It does not specifically address agent identity, authentication, or authorization infrastructure.
  • The AI Agent Standards Initiative sits under CAISI, not the ITL AI Program, and is scoped specifically to agentic systems: their security, their identity and authorization mechanisms, and their ability to interoperate safely with other agents and systems. It works through RFIs, NCCoE demonstration projects, and industry/open-source standards engagement rather than through a risk-management lifecycle document.

In short: an organization using the AI RMF to structure general AI governance is not thereby covering agent identity and authorization — that work, as NIST currently defines it, sits in a separate, newer, and still-developing initiative.

Current status

As of this writing, NIST has not published a finalized AI Agent Standards Initiative document, standard, or set of guidelines. What exists publicly is: a completed RFI and published analysis of the responses it received, an NCCoE draft concept paper on agent identity and authorization that is running as a demonstration project rather than a finished deliverable, and an NSF-funded open-source-protocols track. Organizations should treat the Initiative as an active, early-stage standards effort to track — not yet as a publishable compliance reference the way the AI RMF or ISO/IEC 42001 already are.

For the institution running the Initiative, see our companion guide: CAISI: NIST’s Center for AI Standards and Innovation, Explained.

Frequently asked questions

Is the AI Agent Standards Initiative a finished standard?

No. As of this writing it is an active, early-stage program. Its RFI on agent security has closed and NIST has published an analysis of the responses, but its agent identity-and-authorization work is documented as a draft concept paper and NCCoE demonstration project, not a finalized standard or set of voluntary guidelines.

Who runs the Initiative?

NIST’s Center for AI Standards and Innovation (CAISI), working with NIST’s National Cybersecurity Center of Excellence (NCCoE) on the identity-and-authorization strand and the National Science Foundation on open-source protocol funding.

Does it replace or update the AI RMF?

No. The AI RMF is a separate, earlier framework led by NIST’s Information Technology Laboratory AI Program, covering AI risk management broadly. The AI Agent Standards Initiative is a narrower, newer effort under CAISI focused specifically on agent security, identity, and authorization.

What is the NCCoE concept paper about?

“Accelerating the Adoption of Software and AI Agent Identity and Authorization” is a draft NCCoE project describing how existing identity standards and best practices can be applied to software agents, with a particular focus on agentic AI applications.

Can organizations still submit input?

The initial RFI’s comment period closed March 9, 2026, and NIST has published its analysis of the responses received. Later stages of the Initiative, including the NCCoE concept paper process, may open further comment periods; organizations should check NIST’s and NCCoE’s own pages for current opportunities rather than assume the March 2026 window is still open.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · free to try

Ask about NIST’s AI Agent Standards Initiative: What It Covers and Its Current Status

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

Ask CASRAI answers research-administration questions and cites the passages behind every claim. When our sources don't cover a question, it says so.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →