Guidance
NIST TEVV-Athlon (draft, Aug 2026)
NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems
6 guidance propositions · 8 connected unified controls
Open NIST TEVV-Athlon (draft, Aug 2026) in the mapInitial public draft of a general AI evaluation framework, applicable to agentic systems. These six selected topics cover evaluation design and agent security testing; they are not a complete crosswalk of the publication. NIST-TEVV identifiers are local catalog references, not NIST control numbers. The confidentiality, injection, and tool-abuse topics relate to the lethal trifecta, but the draft does not prescribe an architecture that makes that combination safe or a required testing frequency.
Guidance propositions
“Informs” records a guidance relationship. It does not claim that a unified control satisfies a mandatory requirement.
AI Evaluation and Agent Security Testing
| Proposition | Unified control and mapping |
|---|---|
| NIST-TEVV-01Define evaluation objectives, context, and measurements Source pages: NIST AI 200-2 ipd sections 2.1-2.2, pp. 3-6 | |
| NIST-TEVV-02Run evaluations and examine results and limitations Source pages: NIST AI 200-2 ipd sections 2.3-2.4, pp. 6-7 | |
| NIST-TEVV-03Evaluate AI systems in realistic operating settings Source pages: NIST AI 200-2 ipd section 4.3.2, pp. 14-15; Appendix C, pp. 25-26 | |
| NIST-TEVV-04Test for disclosure of confidential information Source pages: NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Confidentiality attacks | |
| NIST-TEVV-05Test direct and indirect prompt injection Source pages: NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Integrity attacks | |
| NIST-TEVV-06Test agent tool misuse and unauthorized external actions Source pages: NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Agent / tool abuse testing |