Guidance

NIST Agent Identity (draft, Feb 2026)

NIST NCCoE: Software and AI Agent Identity and Authorization

7 guidance propositions · 12 connected unified controls

Open NIST Agent Identity (draft, Feb 2026) in the map
Version
February 2026 draft concept paper
Published
2026-02-05
Reviewed
2026-09-10
Amendments
Initial concept paper; comments closed 2026-04-02; project reviewing comments as of 2026-09-10

Read the source

Draft concept paper seeking input on a proposed NCCoE project. The seven selected topics below summarize questions and areas of exploration, not final requirements or a completed implementation guide. NIST-AGI identifiers are local catalog references, not NIST control numbers. The project focuses on enterprise agents; external agents from untrusted sources are outside its initial scope. The NIST AI Agent Standards Initiative, launched 2026-02-17, is a standards-development program rather than a certifiable standard: https://www.nist.gov/artificial-intelligence/ai-agent-standards-initiative

Guidance propositions

“Informs” records a guidance relationship. It does not claim that a unified control satisfies a mandatory requirement.

Agent Identity and Authorization Topics

PropositionUnified control and mapping
NIST-AGI-01Distinct agent identities and identity boundaries
Source pages: Concept paper pp. 4, 6: Identification; Areas of Interest
NIST-AGI-02Agent authentication and credential lifecycle
Source pages: Concept paper pp. 4, 7: Authentication; Relevant Standards and Guidelines
NIST-AGI-03Context-sensitive authorization and least privilege
Source pages: Concept paper pp. 4, 6: Authorization; Areas of Interest
NIST-AGI-04Delegated authority and human accountability
Source pages: Concept paper pp. 4, 6: Authorization; Access Delegation
NIST-AGI-05Verifiable agent action logs and authorization traceability
Source pages: Concept paper pp. 4, 6: Auditing and non-repudiation; Logging and Transparency
NIST-AGI-06Prompt-injection prevention and limits on resulting harm
Source pages: Concept paper p. 4: Prompt Injection prevention and mitigation
NIST-AGI-07Prompt provenance and data-flow tracking
Source pages: Concept paper p. 6: Tracking Data Flows of an AI System