STANDARDSMarch 2026
Response to NIST RFI on Security Considerations for AI Agents
Contribution to the NIST RFI examining the security architecture required for consequential agentic systems.
This contribution responds to the NIST Request for Information on security considerations for AI agents.
It sets out the security consequences of delegated action: authority that outlives the intent behind it, credentials that remain valid through behavioral change, and the absence of evidence sufficient to reconstruct why an agent acted. It recommends that agent security be specified at the authority layer, with bounded mandates, action-time checks and verifiable records.
