Guidance

NIST TEVV-Athlon (draft, Aug 2026)

NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems

6 guidance propositions · 8 connected unified controls

Open NIST TEVV-Athlon (draft, Aug 2026) in the map
Version
NIST AI 200-2 ipd (Initial Public Draft), August 2026
Published
2026-08-07
Reviewed
2026-09-10
Amendments
Initial public draft; public comments close 2026-10-06

Read the source

Initial public draft of a general AI evaluation framework, applicable to agentic systems. These six selected topics cover evaluation design and agent security testing; they are not a complete crosswalk of the publication. NIST-TEVV identifiers are local catalog references, not NIST control numbers. The confidentiality, injection, and tool-abuse topics relate to the lethal trifecta, but the draft does not prescribe an architecture that makes that combination safe or a required testing frequency.

Guidance propositions

“Informs” records a guidance relationship. It does not claim that a unified control satisfies a mandatory requirement.

AI Evaluation and Agent Security Testing

PropositionUnified control and mapping
NIST-TEVV-01Define evaluation objectives, context, and measurements
Source pages: NIST AI 200-2 ipd sections 2.1-2.2, pp. 3-6
NIST-TEVV-02Run evaluations and examine results and limitations
Source pages: NIST AI 200-2 ipd sections 2.3-2.4, pp. 6-7
NIST-TEVV-03Evaluate AI systems in realistic operating settings
Source pages: NIST AI 200-2 ipd section 4.3.2, pp. 14-15; Appendix C, pp. 25-26
NIST-TEVV-04Test for disclosure of confidential information
Source pages: NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Confidentiality attacks
NIST-TEVV-05Test direct and indirect prompt injection
Source pages: NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Integrity attacks
NIST-TEVV-06Test agent tool misuse and unauthorized external actions
Source pages: NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Agent / tool abuse testing